The airport security program requirements in 49 CFR Part 1542 obligate every operator of a commercial-service airport to classify its operations into one of three program tiers, adopt a written security program approved by the TSA, and then run the airport to that document: a designated security coordinator on call around the clock, controlled access zones staffed only by vetted badge holders, law enforcement in numbers adequate to the operation, contingency plans for threats against civil aviation, immediate reporting of unlawful interference, and records held for at least 180 days after they cease to be active. The TSA verifies compliance through announced and unannounced inspections, and civil penalties for aviation security violations can exceed $17,000 per violation.1eCFR. 49 CFR 1503.401 – Maximum Penalty Amounts
Which Program Tier Applies to Your Airport
Everything else in Part 1542 flows from the tier your operation falls into, so this classification is the first question to answer. The rule sorts airports into Complete, Supporting, and Partial programs based on the type of airline operations regularly hosted and the size of the aircraft involved.2eCFR. 49 CFR 1542.103 – Content
A Complete program is required at airports that regularly serve scheduled passenger or public charter operations using aircraft with 61 or more passenger seats.3eCFR. 49 CFR 1544.101 – Adoption and Implementation Every element of Part 1542 applies at this level: passenger and property screening infrastructure, perimeter security, full access control across restricted zones, and adequate law enforcement staffing.
A Supporting program covers airports hosting smaller scheduled operations or certain foreign air carrier flights below the 61-seat threshold. These operators still need a security coordinator, law enforcement support, a contingency plan, incident management procedures, and recordkeeping, but they are not required to build out the full screening and perimeter infrastructure of a Complete program.
A Partial program is the lightest tier, for airports that serve certain unscheduled commercial operations or smaller carriers. Required elements are a security coordinator, law enforcement response capability, basic recordkeeping, and incident management. A standalone contingency plan is not required at this tier, though the airport still must have emergency response procedures for threats against civil aviation.
The Written Airport Security Program
The Airport Security Program is the binding document that ties every requirement together. It describes the physical facility, defines each security zone, and commits the operator to specific procedures for access control, law enforcement response, training, and incident management. The TSA provides a standardized template so programs follow a consistent format nationwide.
Building it means assembling detailed information: boundary descriptions for the Secured Area and Air Operations Area, maps showing fences, gates, and camera placements, badge issuance and revocation procedures, methods for searching persons and property in restricted zones, employee training programs, and internal audit procedures. Coordination with local law enforcement, including response times, patrol schedules, and communication protocols, must be documented. The final program has to be signed by the airport director or another official with authority to commit the airport’s resources.
Once submitted, the TSA’s designated official has 30 days to approve the program or send back written notice specifying what needs to change.4eCFR. 49 CFR 1542.105 – Approval and Amendments After written approval, any deviation from the program’s contents can trigger enforcement action.
Amendments
When a planned change will affect the security program, the operator must file a proposed amendment with the TSA at least 45 days before the change takes effect.4eCFR. 49 CFR 1542.105 – Approval and Amendments Shorter timelines are possible only if the designated official authorizes them.
Unplanned changes on the ground, such as a fence breach, a staffing shortfall, or a physical layout alteration, must be reported to the TSA within six hours of discovery, or within any shorter window the security program specifies. The TSA can also push amendments unilaterally through Emergency Amendments or Security Directives, which take effect immediately when the agency identifies an urgent threat.
The Airport Security Coordinator
Every airport operating under Part 1542 must designate at least one Airport Security Coordinator (ASC), the operator’s primary point of contact with the TSA on all security matters. At least one ASC has to be reachable 24 hours a day, and a designated alternate must be in place so coverage never lapses.5eCFR. 49 CFR 1542.3 – Airport Security Coordinator
The ASC coordinates with law enforcement, oversees access control, responds to incidents, and keeps the written security program current. Training must cover the regulatory framework of Part 1542, the specific contents of the airport’s own security program, access control and credentialing procedures, and incident management. Documentation of that training has to be kept until at least 180 days after an individual is no longer designated as an ASC.6eCFR. 49 CFR Part 1542 – Airport Security
Access Control Zones and Badging
Part 1542 divides an airport into distinct security zones, each with its own access rules. These zones are the backbone of physical airport security and appear in nearly every inspection.
Secured Area
The Secured Area covers where passengers board and exit aircraft. It requires physical barriers, locked or monitored access points, and electronic systems that log every entry and exit. Only individuals who have passed a full background check and hold a valid credential can enter without an escort.
Air Operations Area (AOA)
The AOA covers runways, taxiways, and aircraft parking ramps. Access is limited to people with a demonstrated operational need, and every entry point must be continuously monitored or secured with a lock.
Security Identification Display Area (SIDA)
Anyone inside the SIDA must visibly wear an airport-issued identification badge at all times. Before receiving a SIDA badge, an applicant must clear two layers of vetting: a fingerprint-based Criminal History Records Check (CHRC) against FBI criminal databases, and a name-based Security Threat Assessment (STA) conducted by the TSA against federal terrorist watchlists and immigration records.7Department of Homeland Security. Privacy Impact Assessment for the Security Threat Assessment for Airport Badge and Credential Holders
Certain criminal convictions automatically disqualify an applicant, including espionage, treason, murder, and felonies involving weapons or explosives. Operators must track every active badge and immediately revoke access when someone no longer meets eligibility or leaves their job. Records tied to an individual’s unescorted access authority must be kept until 180 days after that access is terminated.
Escorts
Vendors, construction crews, and visiting officials may need temporary access to secured zones. Part 1542 does not set a numerical escort-to-visitor ratio. It requires that each escorted individual be continuously accompanied or monitored by someone with unescorted access authority, and that the escort be able to identify whether the visitor is doing anything beyond what was authorized.8eCFR. 49 CFR Part 1542 Subpart C – Operations Unscreened visitors escorted into a sterile area must remain under escort until they leave or are screened. The written security program has to spell out how escort procedures work in practice.
Law Enforcement Support
Airports with Complete or Supporting programs must provide uniformed law enforcement personnel in numbers adequate to support both the overall security program and any passenger screening operations.9eCFR. 49 CFR 1542.215 – Law Enforcement Support These officers need the legal authority to arrest, search, seize, and use force within the airport’s jurisdiction. There is no fixed number in the rule; the TSA evaluates adequacy against the airport’s size, layout, and threat profile.
Partial-program airports do not need officers stationed on site, but they must ensure that law enforcement is available and committed to respond when an air carrier operating at the airport requests them.
Officers assigned to airport security must complete specialized training on federal aviation security regulations, the airport’s physical layout, and emergency response procedures. Records of that training have to be kept until 180 days after the officer leaves the assignment.
Contingency and Incident Response
Complete and Supporting programs must include a contingency plan for bomb threats, sabotage threats, hijacking, and other interference with civil aviation. When a credible threat comes in, the operator initiates the response procedures laid out in the Airport Emergency Plan required under 14 CFR 139.325.10eCFR. 49 CFR Part 1542 Subpart D – Contingency Measures Partial-program airports that are not certificated under 14 CFR Part 139 still have to develop their own emergency procedures for the same threat categories.
When an incident happens, the reporting duty is immediate. Airport operators must notify the TSA at once of any acts or suspected acts of unlawful interference with civil aviation, including specific bomb threats against aircraft or airport facilities.6eCFR. 49 CFR Part 1542 – Airport Security The regulation uses the word “immediately” without setting a specific number of hours.
Recordkeeping: The 180-Day Rule
Part 1542 imposes a consistent 180-day retention rule across several categories of records, though the clock starts at different trigger points:
- Background check records: kept until 180 days after the individual’s unescorted access authority ends.
- Security training records: kept until 180 days after the individual’s unescorted access authority is terminated.
- Law enforcement training documentation: kept until 180 days after the officer leaves the airport security assignment.
- Law enforcement action records: kept for a minimum of 180 days from the date of the action.
- ASC training records: kept until 180 days after the individual is no longer designated as a coordinator.
Missing or incomplete records are among the most common inspection findings and are straightforward for the TSA to prove.
Cybersecurity Obligations
Cyber threats to airport operational technology are now within the TSA’s compliance focus. Under 49 CFR 1570.203, airport owners and operators must report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency (CISA) within 72 hours of identification. The TSA encourages, but does not currently require, separate notification to TSA within 12 hours of discovering a significant cyber incident.
In March 2023, the TSA issued Joint Emergency Amendment 23-01, which requires covered aviation stakeholders to implement performance-based cybersecurity measures aimed at preventing disruption to critical systems. The specific technical requirements of that amendment are classified as Sensitive Security Information and are not publicly available.11Federal Register. Recommendation Regarding Emergency Action in Aviation Operators should expect this area to grow as TSA rulemaking continues.
Inspections, Penalties, and Response Deadlines
TSA inspectors conduct both announced and unannounced visits to verify that an airport’s operations match its written security program. They check physical barriers, test access control systems, review badge issuance records, confirm law enforcement staffing, and examine training documentation. A gap between what the program says and what happens on the ground is the fastest route to enforcement.
Sanctions follow a progressive model, calibrated by aggravating and mitigating factors including the severity of the security risk created, whether the violation was inadvertent or deliberate, the operator’s violation history, and whether corrective action was taken.12Transportation Security Administration. Enforcement Sanction Guidance Policy Fraud and intentional concealment push penalties toward the top of the range.
For aviation-related violations by individuals or small businesses, the TSA can impose up to $17,062 per violation, capped at $100,000 per enforcement action. For larger entities, general violation penalties reach $14,602 per violation, with an aggregate cap of $584,078 per action.1eCFR. 49 CFR 1503.401 – Maximum Penalty Amounts These figures are adjusted periodically for inflation. After receiving a Notice of Violation, the operator has 30 days to respond.13Transportation Security Administration. What Do I Do After Receiving a Notice of Violation?
Persistent noncompliance can lead to suspension or revocation of the airport’s security program, which effectively ends commercial airline service at the facility. That outcome is rare, but it is the reason the rest of Part 1542 gets taken seriously.