By: Bill Carrick
You Can't Secure What You Can't See: Why TSA's 2026 Cyber Mandates Made Your EAM System Transit's First Line of Defense
For decades, transit asset managers and operations directors have justified their enterprise asset management (EAM) investments in the language of reliability: fewer breakdowns, longer asset life, a smaller state-of-good-repair backlog. That language is about to change. As of January 2026, the most consequential reason to keep a complete, accurate, and continuously updated asset register may no longer be maintenance at all. It may be cybersecurity compliance — and the agencies that recognize this convergence first will spend far less money meeting two mandates that have quietly become one.
The 2026 Mandate That Changed the Question
On January 16, 2026, the Transportation Security Administration’s Security Directive 1580-21-01E took effect, running through January 15, 2027. The directive requires covered rail and rail-transit owner-operators to do four things: designate a Cybersecurity Coordinator, report cybersecurity incidents to the Cybersecurity and Infrastructure Security Agency (CISA), maintain a Cybersecurity Incident Response Plan, and conduct a Cybersecurity Vulnerability Assessment.
Running underneath the directive is a larger and more permanent effort. TSA’s proposed rule, “Enhancing Surface Cyber Risk Management,” would require higher-risk operators to build and maintain a comprehensive cyber risk management program modeled on NIST and CISA frameworks. The rule reaches roughly 300 entities, including 34 public transportation systems, 73 freight railroads, 71 intercity bus operators, and 115 pipeline facilities. The comment period closed February 5, 2025, putting finalization squarely on a 2026 track. TSA estimates the industry’s compliance costs, plus its own oversight, at $2.1 billion over ten years.
Buried inside both the directive and the proposed rule is a requirement that looks deceptively technical: before an agency can assess its vulnerabilities or manage its cyber risk, it must first know exactly what operational technology it owns. You cannot patch, segment, or monitor a device you have not inventoried. And that, for a transit agency, is not fundamentally a security problem. It is an asset management problem.
Why an OT Asset Inventory Is Really an EAM Problem
Cybersecurity teams talk about “asset visibility” as if it were a new discipline. For transit asset managers, it is anything but. Every vulnerability assessment begins with the same question your EAM system was built to answer: what do we own, where is it, how old is it, what condition is it in, and who is responsible for it?
The operational technology that TSA cares about — signaling and train control, traction power and substations, SCADA, automated fare collection, and the building systems that keep stations and yards running — is the same equipment your maintenance teams already track as physical assets. The difference is that the cyber team needs additional attributes for each record: firmware version, network segment, patch status, end-of-support date, and connectivity. Those are not a separate database. They are columns your asset register can carry.
When agencies treat the OT cyber inventory as a standalone effort, they pay twice: once to build a maintenance asset register, and again to build a parallel security inventory that drifts out of sync the moment a part is replaced in the field. When they converge the two in the EAM, a single work order that swaps a controller updates both the maintenance history and the cyber posture at the same time.
The Four Requirements, Mapped to Your Asset Register
Consider how directly each TSA requirement maps to capabilities your EAM already provides. The Cybersecurity Coordinator needs a single authoritative source of truth for what assets exist — that is your asset hierarchy. The Incident Response Plan depends on knowing which assets are affected and what they connect to — that is your asset relationships and location data. The Vulnerability Assessment requires a complete OT inventory with condition and configuration detail — that is your asset register, extended. Even incident reporting to CISA is faster when responders can pull an asset’s full lifecycle and maintenance history in seconds rather than reconstructing it from spreadsheets.
The agencies furthest along are not buying a second platform. They are extending the EAM they already run.
The Hidden OT Assets Your CMMS Already Tracks
What the $2.1 Billion Compliance Bill Actually Buys
The cost estimates should focus the mind. TSA projects that mid-sized operators will incur average annual costs exceeding $1 million to comply, while smaller short-line and regional operators may see roughly $100,000 per year. Much of that spend goes to building and maintaining exactly the inventory and configuration data that a mature EAM already holds.
For agencies still tracking critical OT in spreadsheets and tribal knowledge, the bill will be larger and the audit risk higher. For agencies that have invested in a clean asset register, much of the compliance work is a configuration project, not a greenfield build. The convergence does not eliminate the cost, but it can sharply reduce the duplicated effort — and it produces one defensible system of record instead of two that disagree.
Lessons From SFMTA, TTC, and SEPTA
Transit does not have to imagine the consequences of poor OT visibility; it has already lived them. In November 2016, ransomware crippled the San Francisco Municipal Transportation Agency, locking roughly 900 to 2,000 workstations and forcing the agency to open fare gates and offer free rides while it recovered. Toronto’s TTC was hit by ransomware in October 2021, and SEPTA in Philadelphia suffered a disruptive attack in August 2020. In each case, the organizations most able to respond were those that knew precisely which systems were affected and how they connected. The ones that struggled were reconstructing their own environments under pressure — discovering their inventory during the incident rather than before it.
The lesson regulators drew is the lesson EAM has taught for years: visibility purchased in advance is cheap; visibility purchased during a crisis is ruinous.
The Audit Trap: When Self-Reported Data Isn’t Verified
There is a second, quieter risk in 2026, and it also runs through asset data. In December 2025, the DOT Office of Inspector General reported that the Federal Transit Administration had not independently verified agencies’ self-reported transit asset management performance data before awarding Capital Investment Grants. The OIG found the progress requirement was treated as not applying to 5 of 19 grants it reviewed — roughly $7.3 billion, more than half the funds awarded between January 2023 and January 2025. Separately, GAO’s report GAO-25-107947 concluded that while TSA is taking steps on surface cybersecurity, additional actions are still needed.
The throughline is unmistakable. Whether the auditor is checking your funding eligibility or your cyber posture, unverified, self-reported asset data is now a liability. A system of record that produces a defensible, timestamped audit trail is no longer a nice-to-have. It is the difference between passing an inspection and explaining one.
A Convergence Playbook for 2026
Agencies that want to turn this mandate into an advantage can start with five concrete moves. First, declare the EAM the single system of record for OT assets, and stop maintaining parallel security spreadsheets. Second, extend your asset schema with the cyber-relevant attributes — firmware, network segment, patch status, end-of-support date — so a maintenance update and a cyber update become the same transaction. Third, integrate passive OT discovery tools such as Claroty, Cylus, or Dragos to feed newly detected devices straight into the asset register rather than into a separate console. Fourth, wire your incident response plan to pull asset relationships and history directly from the EAM, whether you run IBM Maximo, Octave Attune EAM, or another platform. Fifth, treat data quality as a compliance control, with the same verification rigor the OIG now expects of grant reporting.
Where to Start
The transit agencies that thrive in 2026 will be the ones that stop asking whether asset management and cybersecurity are separate budgets and start treating them as one capability built on one source of truth. If your OT inventory still lives in spreadsheets, or your EAM does not yet carry the cyber attributes the new rules demand, now is the moment to close that gap — before the directive’s clock, the audit, or the incident closes it for you.
21Tech helps transit agencies turn their EAM into a compliance-grade system of record — converging OT asset visibility, TSA and FTA requirements, and reliability into a single platform your teams already use. Contact us to assess where your asset data stands against the 2026 mandates, and to build the convergence roadmap before the deadline does it for you.