GAO: Canceled TWIC cards may still allow port access
A new Government Accountability Office report says federal agencies have not fully closed a security gap that could allow people carrying Transportation Worker Identification Credential cards on the Transportation Security Administrationโs Canceled Card List to enter secure areas at regulated maritime facilities.
GAO publicly released report GAO-26-107521 on July 28, 2026. The finding identifies a control weakness and security risk. It does not establish that a specific person recently used a canceled card to breach a named U.S. port or facility.
The report also says the Coast Guard did not provide field inspectors with all of the TWIC-related inspection data it collected. GAOโs review of fiscal years 2019 through 2024 identified 888 TWIC-related deficiencies and 83 violations.
Why TWIC cards matter
TWIC is the federal credential used by eligible maritime workers who need unescorted access to designated secure areas at facilities and vessels regulated under the Maritime Transportation Security Act. TSA oversees enrollment and background checks, while the Coast Guard enforces certain TWIC requirements and inspects facilities and vessels for compliance.
About 2 million people held TWIC credentials as of June 2025, according to GAO. Coast Guard guidance says personnel who need access to secure areas generally must have a valid TWIC or be escorted during their duties. Whether and how an individual is escorted is handled under applicable Coast Guard guidance and the facility or vessel operatorโs procedures.
The program is intended to provide a tamper-resistant biometric credential for workers who require unescorted access. Electronic readers can help authenticate a card and identify credentials that should not provide access, but reader requirements have been delayed for certain facilities.
What GAO found
GAO said TSA and the Coast Guard have not developed a method that reliably mitigates the risk of unauthorized individuals with cards on TSAโs Canceled Card List accessing secure areas of facilities regulated under the Maritime Transportation Security Act.
GAO also found that TSA relies on an ad hoc approach to communicating program information with stakeholders rather than a documented communication plan. Some stakeholders told auditors they experienced declining engagement with TSA and delays receiving important program updates.
At the Coast Guard, GAO found that inspection data on deficiencies and violations was not fully shared with the inspectors responsible for enforcing TWIC requirements. A deficiency is a less severe form of noncompliance. A violation is more serious and can result in a notice of violation or civil penalty.
The 888 deficiencies included examples such as facility operators failing to ensure that personnel with security duties were qualified for their roles. GAO also cited violations involving conduct such as unescorted individuals entering a secure area.
The figures cover fiscal years 2019 through 2024. They are not a count of canceled-card entries, successful unauthorized breaches or affected facilities nationwide.
Seven recommendations remain open
GAO made seven recommendations, and the Department of Homeland Security concurred with all of them. GAO lists each recommendation as open.
The recommendations call for TSA to create a systematic communication plan and for the Coast Guard to share TWIC-related deficiency and violation data with field inspectors. GAO also recommended that the Coast Guard include deficiency data in its TWIC performance reporting.
Most directly tied to the security gap, GAO recommended that the Coast Guard develop a method to mitigate the risk posed by cards on the Canceled Card List. Two related recommendations call for TSA and the Coast Guard, through DHS, to coordinate on acquiring TWIC readers for use during inspections.
Finally, GAO recommended that the Coast Guard develop and implement a plan for issuing final regulations specifying which facilities must have TWIC card readers.
What happens next
The report does not announce a nationwide TWIC recall or an immediate change for ordinary travelers. Its practical effect is on maritime workers, facility operators, Coast Guard inspectors and the security systems used to protect ports, vessels and related infrastructure.
Facility operators and workers should watch for future TSA and Coast Guard guidance on reader use, access checks and compliance procedures. The Coast Guardโs separate regulatory timeline remains relevant: a 2024 final rule delayed implementation of certain reader requirements for some facilities until May 8, 2029. That date is regulatory context, not a new mandate created by the GAO report.
Sources
- Government Accountability Office report on TWIC maritime-security risks
- U.S. Coast Guard TWIC requirements
- U.S. Coast Guard notice on TWIC reader requirements
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.