6 minute read

Most hazmat carriers fixate on placarding. They verify label placement, confirm load segregation, and double-check shipping paper entries — and then walk straight past one of the most frequently cited deficiencies in comprehensive hazmat audits: the security plan. Under 49 CFR Part 172 Subpart I, the obligation to maintain a documented, implemented hazmat security plan is a standalone regulatory requirement with its own violation codes, its own audit triggers, and enforcement consequences that compound quickly when inspectors find gaps.

This post dissects what the regulation actually demands, where carriers fail, and why treating the security plan as a paperwork afterthought produces serious SMS exposure.


Understanding the Hazmat Security Plan 172.800 Requirements

Who Is Covered

Section 172.800(b) does not apply universally. The security plan requirement attaches to offerors and carriers of materials that meet specific hazard thresholds. These include:

  • Any quantity of a material designated as a select agent or toxin under 42 CFR Part 73
  • Highway route-controlled quantities of radioactive materials (§173.403)
  • More than 25 kg of a Division 1.1, 1.2, or 1.3 explosive
  • More than 1 liter per package of a PIH (poison inhalation hazard) material, including anhydrous ammonia and chlorine
  • A hazardous material in a bulk packaging with a capacity ≥ 3,500 gallons for liquids or gases, or ≥ 468 cubic feet for solids
  • A shipment of a quantity of hazardous materials requiring placarding under Subpart F of Part 172

That last criterion is the one most carriers underestimate. If your load requires hazmat placarding, you are almost certainly within the security plan mandate. The two obligations are directly linked, yet enforcement data consistently shows carriers that have their placarding protocols buttoned up failing the security plan audit entirely.

The Three Core Components the Regulation Mandates

Section 172.802 specifies that a compliant security plan must address three functional areas without exception:

Personnel security — procedures to confirm the identity and employment suitability of persons with unescorted access to hazmat shipments. This is not an HR function; it is a documented pre-employment and ongoing review process tied specifically to hazmat access.

Unauthorized access — measures to reduce the risk that unauthorized personnel can access hazmat during preparation, loading, transport, and unloading. Physical controls, staging protocols, and lock/seal procedures all fall here.

En route security — procedures for protecting shipments in transit, including protocols for stops, parking, and communication with dispatch when the vehicle is unattended.

The regulation does not prescribe a specific format, but §172.802(a) requires the plan to be “in writing” and “specific to the carrier’s operations.” Generic, downloaded templates that have not been tailored to the carrier’s routes, commodities, and facilities are audit liabilities — inspectors are trained to identify plans that don’t reflect actual operational practice.


Training, Awareness, and the §172.704 Intersection

Security Awareness Training Is a Separate Line Item

Many carriers fold hazmat training into a single onboarding module and consider the obligation satisfied. That is insufficient. Section 172.704(a)(4) requires security awareness training for all employees who handle hazmat, and §172.704(a)(5) requires in-depth security training for employees subject to the §172.800 security plan. These are two distinct training elements with separate documentation requirements.

In-depth security training under §172.704(a)(5) must cover the security plan itself — its components, the employee’s specific responsibilities under it, and actions to take when a security threat is identified. Training records must be retained for as long as the employee remains in the position plus 90 days post-separation.

High-turnover fleets face compounding exposure here. When driver attrition is elevated, the window between onboarding and first hazmat assignment narrows, and training documentation frequently lags. The compliance risk profile of high-turnover operations makes the security training requirement particularly acute — each new driver is a potential documentation gap during an audit.


How Violations Are Coded and How They Surface

FMCSA Violation Codes and SMS Weight

Security plan violations under Part 172 Subpart I are captured in the FMCSA’s Motor Carrier Management Information System (MCMIS) and score into the Hazardous Materials BASIC within CSA’s SMS framework. The Hazmat BASIC carries some of the highest severity weights in the SMS model.

Key violation codes inspectors write for security plan deficiencies include:

  • 172.800 — Failure to develop and implement a security plan for hazmat subject to the requirement
  • 172.802 — Security plan does not include required elements (personnel security, unauthorized access, en route security)
  • 172.704 — Failure to provide security awareness or in-depth security training
  • 172.820 — Failure to comply with additional planning requirements for transportation by rail (applicable to intermodal carriers)

A single 172.800 violation during a compliance review — particularly a Focused or Comprehensive audit — can trigger an Unsatisfactory safety rating proposal when combined with other hazmat deficiencies. FMCSA enforcement data available through FMCSA’s public safety statistics portal shows hazmat violations appearing in roughly 18–22% of all comprehensive compliance reviews in recent audit cycles, with security plan and training deficiencies among the top recurring findings.


Operational Gaps That Become Audit Findings

The Shipping Paper Connection

A security plan that does not address document handling is incomplete. Shipping papers for hazmat shipments are themselves a security-sensitive component — they identify the commodity, quantity, and routing. Section 172.200 governs hazmat shipping paper requirements, and when auditors find shipping papers improperly stored, accessible to unauthorized personnel, or retained beyond disposal protocols, it connects directly back to the adequacy of the security plan’s unauthorized access provisions.

What Annual Review Actually Means

Section 172.800 does not use the word “annual,” but FMCSA’s enforcement posture treats a plan that has not been reviewed and updated to reflect current operations as non-compliant. If a carrier has added new commodities, new routes, or new facilities since the plan was last revised, that plan no longer meets the “specific to operations” standard. Document the review date, who conducted it, and what — if anything — was changed. That version-control record is the difference between a compliant plan and a citation.


Crash Preventability and the Secondary Enforcement Risk

Carriers operating under active hazmat security plan violations face a compounding problem: any incident involving a hazmat load gets scrutinized at a higher level. The FMCSA Crash Preventability Determination Program can reclassify crash data in ways that affect SMS scores, but pre-existing hazmat compliance deficiencies undermine a carrier’s position when contesting preventability findings. Auditors and investigators use the totality of compliance posture when making adverse determinations.


Practical Steps for Carriers Operating Under §172.800

Review your security plan against the full regulatory text of 49 CFR Part 172 Subpart I using this checklist:

  • Written plan exists and is specific to current operations, commodities, and facilities
  • All three §172.802 components are addressed with operational specificity — not generic language
  • In-depth security training records exist for every employee covered by the plan
  • Training records for separated employees are retained for the required post-separation period
  • A documented review has been conducted within the past 12 months with version dating
  • Shipping paper handling and storage procedures align with unauthorized access provisions

The security plan is not a background document. It is an active compliance instrument that auditors pull, read, and compare against observed operations. Carriers that treat it as such have measurably fewer Hazmat BASIC violations and a defensible audit posture.


Data sourced from 49 CFR Part 172 Subpart I and FMCSA public records. Verify current enforcement thresholds at fmcsa.dot.gov.

Updated: