Skip to main content

Transportation Worker Identification Credential: Actions Needed to Address Maritime Security Risks

GAO-26-107521 Published: Jul 28, 2026. Publicly Released: Jul 28, 2026.
Jump To:

Fast Facts

The Transportation Worker Identification Credential, also referred to as the TWIC® card, helps protect U.S. ports from terrorist attacks. The Transportation Security Administration runs background checks on card applicants to ensure that they do not pose a threat to port facilities. About 2 million people had a TWIC® card as of June 2025, authorizing them to enter port facilities without an escort.

The U.S. Coast Guard inspects TWIC® cards at port facilities to help prevent unauthorized access. But we found a risk of people with revoked TWIC® cards entering port facilities.

Our recommendations address this and more.

U.S. Coast Guard Inspector Checking a Transportation Worker Identification Credential

Coast Guard inspector checking credential

Coast Guard inspector checking credential

Skip to Highlights

Highlights

What GAO Found

TSA has taken some steps to communicate Transportation Worker Identification Credential (TWIC®) program information with stakeholders. However, TSA relies on an ad hoc communication approach rather than a documented communication plan to determine how to share information with stakeholders. This has contributed to some stakeholders reporting that they experienced declining engagement with and delays receiving key program updates from TSA. Developing and implementing a communication plan could help TSA ensure that all stakeholders receive the information necessary to effectively operate the TWIC® program and reduce security risks.

The Coast Guard does not share or analyze all of the data it collects during inspections to oversee how facility operators implement the TWIC® program. For example, the Coast Guard collects data on deficiencies, a less severe form of noncompliance, and violations, a more severe form of noncompliance that can result in notices of violation or civil penalties. GAO’s assessment of inspection findings for fiscal years 2019 through 2024 showed:

  • 888 TWIC®-related deficiencies, such as operators not ensuring that facility personnel with security duties were qualified to perform their roles, and
  • 83 TWIC® violations, such as unescorted individuals entering a secure area, highlighting areas that may warrant improvement.

However, the Coast Guard does not provide the data to TWIC® inspectors. According to officials, this is because the data did not relate to areas that would require a change to the program. However, by communicating the data with inspectors, regardless of their effect on the program, the Coast Guard could improve inspectors’ awareness of TWIC®-related risks.

Total Number of Transportation Worker Identification Credential (TWIC®)-related Deficiencies and Violations, Fiscal Years 2019–2024

Total Number of Transportation Worker Identification Credential (TWIC®)-related Deficiencies and Violations, Fiscal Years 2019–2024

Why GAO Did This Study

The TWIC® program aims to provide a tamper-resistant biometric card to maritime workers who require unescorted access to designated secure areas of facilities and vessels under Maritime Transportation Security Act of 2002 regulations. As of August 2025, more than 2 million individuals held a TWIC® credential.

TSA oversees TWIC® applicants’ enrollment and background checks. The Coast Guard enforces certain TWIC® regulatory requirements, including by inspecting facilities for compliance.

The Transportation Security Screening Modernization Act of 2024 includes a provision for us to review TSA’s security threat assessment programs and we were asked to review other aspects of TWIC® operations. This report examines (1) the extent to which TSA communicates TWIC® program information to stakeholders, and (2) the extent to which the Coast Guard has overseen the implementation of the TWIC® program by facility operators, among other objectives.

GAO also examined TSA and Coast Guard policy and data for fiscal years 2019 through 2024. In addition, GAO interviewed agency officials and port stakeholders. To obtain a range of TWIC® perspectives, these stakeholders included TWIC® operators at facilities selected in part for diversity in size and geographic regions.

Recommendations

GAO is making seven recommendations, including that the TSA Administrator implement a plan to communicate TWIC® information to stakeholders and that the Coast Guard communicate TWIC®-related violation and deficiency data with inspectors. The Department of Homeland Security concurred with these recommendations.

Recommendations for Executive Action

Agency Affected Recommendation Status
Transportation Security Administration The TSA Administrator should develop and implement a communication plan to systematically relay TWIC® program updates to stakeholders. (Recommendation 1)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
United States Coast Guard The Commandant of the Coast Guard should communicate TWIC®-related violation and deficiency data with inspectors in the field who enforce TWIC® requirements. (Recommendation 2)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
United States Coast Guard The Commandant of the Coast Guard should include deficiency data in its TWIC® performance measure reporting. (Recommendation 3)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
United States Coast Guard The Commandant of the Coast Guard should develop a method to mitigate the risks of unauthorized individuals with TWIC® cards on the Canceled Card List accessing secure areas of MTSA-regulated facilities. (Recommendation 4)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
United States Coast Guard The Commandant of the Coast Guard should coordinate with TSA, through DHS, to acquire TWIC® reader devices for use during inspections. (Recommendation 5)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Transportation Security Administration The TSA Administrator should coordinate with the Coast Guard, through DHS, to acquire TWIC® readers for use during inspections, as appropriate. (Recommendation 6)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
United States Coast Guard The Commandant of the Coast Guard should develop and implement a plan on how it will issue final regulations to specify which facilities must have TWIC® card readers. (Recommendation 7)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Full Report

GAO Contacts

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

Transportation workersMarine transportationMaritime securityRegulatory noncomplianceCompliance oversightSecure areasHomeland securityTransportation securityGovernment procurementFacility security