Expert Guide: Building a Practical Hazmat Security Plan

Back

August 25, 2026

Expert Guide: Building a Practical Hazmat Security Plan

Step-by-step framework for creating a concise, audit-ready security plan tailored to shippers and carriers

Who needs a WSP and why tailored plans pass audits


Under 49 CFR §172.800 you must have a written transportation security plan when you offer for transport certain hazardous materials.


A cookie-cutter plan won't survive an audit. Per 49 CFR §172.802, a compliant plan must address personnel security, unauthorized access, and en-route security. A defensible WSP ties those elements to a documented risk assessment, incident procedures, and records, and must be available to implementing employees and inspectors.

  • A scoped assessment identifying materials, quantities, and routes.
  • A risk-assessment framework mapping threats to mitigations.
  • Controls mapping that links physical and operational measures to risks.
  • Personnel and training requirements tied to job functions and schedules.
  • Incident response steps and audit-ready recordkeeping practices.

This guide includes actionable checklists and editable templates you can adapt. For regulatory context and a downloadable template, see our detailed guidance.


Close-up section image for


How to decide whether your shipments or sites fall under the WSP requirement


Not sure if your operation needs a written security plan? Start with the law: under 49 CFR §172.800 a WSP is required when you offer for transportation certain high‑consequence hazardous materials.


Key triggers include any quantity of Division 1.1, 1.2, or 1.3 explosives, materials poisonous by inhalation, temperature‑controlled Division 5.2 organic peroxides, select agents, and IAEA Category 1 and 2 radioactive materials. Placarded shipments under 49 CFR Part 172 Subpart F also trigger the requirement, as do certain large bulk packages that exceed the defined thresholds.


If you ship by more than one mode you must reconcile U.S. rules with IATA and IMDG requirements. Build a single WSP that meets the strictest applicable requirements, and add short mode‑specific overlays for air, ocean, or ground operations.

  • Identify the exact materials and quantities you move, and flag items listed in high‑consequence categories.
  • List every origin, consolidation point, and customer site where shipments may be stored incidental to movement.
  • Record the transport modes and typical routes so you can add mode‑specific controls where needed.
  • Note carrier or terminal requirements that add extra controls or documentation for a specific leg.
  • Set an annual review date and tie updates to changes in quantities, new routes, or regulatory shifts.

The key difference? Treat the WSP as a single, company‑level framework that uses short appendices for mode specifics. For a ready template and checklist that maps scope to controls, see our detailed guide at Developing a Hazmat Security Plan Template.


Image for


Map threats to controls: a step‑by‑step assessment workflow


Want an assessment that stands up to auditors and directly drives the controls in your WSP? Under 49 CFR §172.802 a written security plan must be based on a documented transportation security risk assessment. Use a simple, repeatable workflow so every chosen control ties back to a specific risk.

  1. Scope operations first: list materials, quantities, origins, consolidation points, and modes of transport so you know what to assess.
  2. Collect operational facts: gather manifests, schedules, route maps, facility access logs, driver rosters, and existing security procedures.
  3. Identify threat vectors: look for theft, sabotage, insider misuse, unauthorized access at facilities, and en‑route risks like hijacking or tampering.
  4. Score risks: assign likelihood and consequence scores, then multiply to rank vulnerabilities so you can prioritize mitigations.
  5. Translate results into controls and record the rationale linking each control to the risk it reduces.
  6. Verify and review: schedule annual reviews, update after route or quantity changes, and keep the assessment traceable for audits.

Scoring, evidence to collect, and how to record findings


Use a simple risk matrix, like a 1-to-3 likelihood against a 1-to-3 consequence scale. Multiply the two scores to get a risk index and group items as low, medium, or high priority.

  • Collect shipment records and packing lists to prove quantities and packaging during an audit.
  • Save GPS or telematics logs to show route history and to support en‑route control choices.
  • Keep access logs, CCTV snapshots, and visitor records to document unauthorized access risk and mitigation effectiveness.
  • Retain background check confirmations, training rosters, and signed SOP acknowledgments to support personnel security controls.
  • Use standardized incident report forms and security spot‑check records to show ongoing verification.

Turn each assessed risk into engineering, administrative, and operational controls

  • Personnel Security: add background checks and role-based access logs as administrative controls, and keep training completion records as evidence.
  • Unauthorized Access: install improved locks or badge readers as engineering controls, and use visitor checklists and spot audits as administrative controls.
  • En‑Route Security: adopt GPS tracking and tamper-evident seals as engineering controls, and use vetted carrier lists and alternate low-risk routes as operational controls.

Record everything in a single audit file that links each risk ID to the scoring, the evidence collected, and the specific control chosen. Mark the assessment as restricted and include a review date so you meet annual update requirements. For multi‑modal operations, harmonize procedures to the strictest applicable standard so one WSP covers all transport modes.


For editable templates and checklists you can adapt, see our templates and audit checklist. We provide a detailed WSP checklist that maps scope to controls and a downloadable assessment template.


Why companies need a Written Hazmat Security Plan now


How to build an audit-ready Written Security Plan template and checklist


Image for


Make personnel, training, and carrier controls operational and auditable


Who on your team needs to be named in the WSP, and what checks actually hold up in an audit?


We recommend identifying roles by job title, not by individual, so the plan remains durable through staffing changes. A defensible WSP names the senior manager who owns the plan and each implementation role with clear duties.


Who to identify and how to document duties


List titles that touch covered materials or WSP actions. Include operations leads, security coordinators, packaging personnel, shipping clerks, drivers, and transportation managers.


For each title, write two things: the specific WSP duties and the expected decision points they control. Keep that language short, role-focused, and attached to the WSP so auditors can trace responsibility quickly.


Vetting: reasonable pre-hire and access checks


Vet anyone who will access covered materials or implementation details. The level of vetting should match the risk of the role.

  • Verify employment history and references to confirm claimed experience.
  • Run criminal-history checks when roles involve custody or unsupervised access to hazmat.
  • Check motor-vehicle records for drivers and apply DOT drug and alcohol rules where applicable.
  • For roles requiring a Hazardous Materials Endorsement, follow the TSA HME program fingerprint-based vetting process.

Document vetting results in a personnel security file and tie each check to a documented access decision. Keep proof of checks available for inspectors, but protect sensitive data on a need-to-know basis.


Training cadence, delivery, and records to retain


Initial training must be completed within 90 days of hire or job change. Recurrent training is required at least every three years for DOT-regulated roles.


Deliver training via public seminars, live webinars, or on-site instruction depending on complexity. Use written tests or competency checks to verify understanding.

  • Retain the employee name and most recent completion date.
  • Save a brief course description and the materials used.
  • Keep the test or assessment result and any remedial training notes.
  • Automate recurrent reminders so certifications never lapse.

Credentialing and oversight of carriers and subcontractors


Treat carrier credentialing as ongoing due diligence, not a one-time checkbox.

  • Verify USDOT/MC authority and insurance limits before onboarding.
  • Use the FMCSA Safety Measurement System to review safety history and flag high-risk carriers. See the FMCSA SMS for carrier data.
  • Require copies of hazmat registrations, driver certifications, and proof of specific training.
  • Monitor performance with periodic audits, incident tracking, and verification of emergency contacts.

Record all vetting and oversight actions in your audit file so each transport decision is traceable. That documentation is exactly what inspectors look for during a WSP review.


Image for


Incident response, required notifications, and audit-ready records


When an event happens, your priority is people and evidence, not paperwork. At the same time, regulators expect timely notices and retrievable records. Design your response so safety, legal preservation, and reporting happen together.


Immediate notifications and who must call


Who reports varies by mode and custody, but the party in physical control of the material usually has the duty to notify regulators. We recommend naming a single Security Coordinator in the WSP to make initial calls and log actions.

  • Call the U.S. National Response Center as soon as practical, but no later than 12 hours for qualifying incidents. See 49 CFR reporting rules.
  • Submit a DOT Hazardous Materials Incident Report, DOT Form F 5800.1, to PHMSA within 30 days for reportable incidents. Use the PHMSA incident page for instructions. PHMSA incident reporting
  • Report significant security concerns to TSA within 24 hours and notify local law enforcement immediately when criminal activity is suspected.

Preserve evidence and coordinate with authorities


If you suspect theft, sabotage, or other criminal conduct, preserve the scene and limit access until law enforcement arrives. Document who entered the scene, take photos, and avoid moving potential evidence.


Designate one point of contact to liaise with responding agencies. That person should keep a chronological incident log and collect statements and supporting files for the audit record.


Records to keep, retention periods, and version control


Maintain training files, background checks, risk assessments, incident logs, and copies of every WSP version in your audit file. Make those records accessible for inspection within a reasonable time and location.

  • Keep hazmat training records for the employee’s tenure plus 90 days, including name, completion date, materials used, trainer, and certification.
  • Retain a copy of any filed DOT incident report for two years and make it available at your principal place of business upon request.
  • Mark each WSP page with a version number and date, maintain a master revision log, and remove obsolete copies from circulation.

We recommend limiting WSP access to a need-to-know list and protecting digital copies with access controls. Schedule an annual formal review and trigger an interim revision whenever shipments, facilities, personnel, threat intelligence, or regulations change.


For a practical, editable roadmap that ties incident steps to audit evidence, see our 30‑day internal audit program. How to build an internal hazmat self-audit program in 30 days

Practical next steps to an audit‑ready WSP


Start by confirming whether 49 CFR applies to your operation and scope which materials, quantities, origins, and routes are covered. Then perform a documented transportation security risk assessment and tie each identified risk to a specific control.


Translate controls into operations by naming roles by job title, delivering in‑depth and awareness training, and setting clear incident response and reporting steps. Keep training logs, vetting records, risk assessments, and a versioned WSP in a single audit file so evidence is retrievable.


Make the plan site‑ and shipment‑specific. Retain it at your business and make it available for inspection when requested; you do not submit it for federal pre‑approval.


Work iteratively: fix the highest‑risk gaps first, document each change, and expand the plan until it is audit‑ready.


If you want help developing or reviewing a Written Security Plan, TMGI can assist. Call us at (866) 572-8644 or email twagner@tmgihazmat.com.


Practical. Defensible. Ready for inspection.

You might also like: