WJ Editorial: TWIC: From Boondoggle To Threat?
From the moment of its inception, no one in the maritime industry has had much good to say about the Transportation Workers Identification Credential (TWIC) program.
In the wake of the 9/11 attacks, the TWIC program was pushed as a way to increase maritime port security by storing biometric information on a tamper-proof card for those who required port access without escort. It was supposed to be jointly administered by the Department of Homeland Security and U.S. Coast Guard.
No one wanted to be on record as opposing anything that was supposed to increase port security, but numerous problems and delays were apparent from the start. The first TWIC cards were issued by the Transportation Security Administration as long ago as 2007. For many years after its introduction, there were no card readers for TWICs, making their biometric information useless and relegating them to redundant “flash cards” with pictures. Equipment makers were hesitant to commit to the card reader program.
Communication between the Transportation Security Agency and Coast Guard — and between both and other federal agencies — was poor. Although the FBI was supposed to vet TWIC applicants to make sure they didn’t appear on any no-fly or terrorist watch lists, a 2019 report by the Office of the Inspector General (OIG) found many instances of failures. Few FBI agents understood what the TWIC program was or what it was intended to do. As costs and delays mounted, many industry voices, including this publication, were urging the administration to “end it, don’t mend it.”
In 2022, the effective implementation date for the Coast Guard’s final rule for TWIC reader requirements was pushed to May 8, 2029, after many postponements.
Despite issues, about two million people have TWIC cards today, according to a July report issued by the Government Accountability Office. Now comes word that many of those TWICs are expired. The report was authorized by the Transportation Security Screening Modernization Act of 2024, which asked the GAO to review TSA’s security threat assessment programs and other aspects of the TWIC program. Those expired cards might be used by unauthorized individuals to gain access to restricted port areas.
The GAO found that the familiar issue of “siloization,” lack of communication between federal agencies, continues to dog the TWIC program.
The report found that TSA still doesn’t communicate “systematically” to other stakeholders about the program. Additionally, gaps remain in the Coast Guard’s oversight of facility operators’ implementation of TWIC. The Coast Guard and TSA have not coordinated their acquisition of card readers. The Coast Guard has not taken steps to lessen the risk of individuals on a “canceled card list” from accessing facilities. Finally, the Coast Guard still doesn’t have a plan for determining which facilities must have TWIC readers.
The GAO recommends seven actions, two by the TSA and five by the Coast Guard. The TSA administrator should systematically relay TWIC program updates to stakeholders. The commandant of the Coast Guard should communicate TWIC-related violation and deficiency data with inspectors in the field who enforce TWIC requirements. The commandant of the Coast Guard should include deficiency data in its TWIC performance measure reporting. The commandant of the Coast Guard should develop a method to mitigate the risks of unauthorized individuals with TWIC cards on the Canceled Card List accessing secure areas of MTSA-regulated facilities. The commandant of the Coast Guard should coordinate with TSA, through DHS, to acquire TWIC reader devices for use during inspections. The TSA administrator should coordinate with the Coast Guard, through DHS, to acquire TWIC readers for use during inspections, as appropriate. The commandant of the Coast Guard should develop and implement a plan on how it will issue final regulations to specify which facilities must have TWIC card readers.
These all seem like common-sense recommendations that should have happened long ago. The GAO report does not impose deadlines, but Congress can and should — or cut the program entirely.

