Under 33 CFR 101.514, every person who needs unescorted access to a secure area of a Coast Guard-regulated port facility, vessel, or outer continental shelf facility must hold a Transportation Worker Identification Credential (TWIC), which TSA issues only after a security threat assessment under 49 CFR Part 1572. The employer’s obligations sit around that credential: verifying and inspecting TWICs at access points, escorting workers who do not hold one, using the 30-day new-hire provision correctly, and delivering the security training that 33 CFR 105.210 and 105.215 require for every employee and contractor on the facility — with records kept for at least 2 years under 33 CFR 105.225.
The credential belongs to the worker. The training, the escort protocol, the access logs, and the recordkeeping belong to the facility, and that is what a Coast Guard inspector reviews during the annual facility security plan verification.
Who Actually Needs a TWIC, and What Does the TSA Threat Assessment Check?
The TWIC requirement attaches to access, not to job title. Longshore workers, terminal operators, truck drivers picking up containers, tug and barge crews, marine construction workers, security guards, and the office staff whose desks sit inside a fenced secure area all need one. The credential is issued by TSA, valid for 5 years, and currently costs $125.25 for a new enrollment ($117.25 for eligible online renewals). A worker who has a TWIC but leaves it at home has no TWIC for that shift and must be escorted.
The security threat assessment (STA) behind the card is defined in 49 CFR Part 1572. TSA checks the applicant’s criminal history, immigration status, and terrorism watch-list status. 49 CFR 1572.103 lists the disqualifying offenses in two tiers: permanent disqualifiers (espionage, sedition, treason, federal crimes of terrorism, and a short list of others) and interim disqualifiers (a longer list including certain firearms, explosives, and controlled-substance felonies) that bar the applicant if the conviction was within the 7 years before application or release from incarceration within the 5 years before application. Applicants can seek a waiver for interim offenses and appeal an adverse determination. Employers do not administer the STA and should not attempt to replicate it — running an independent criminal check against the TWIC disqualifier list raises FCRA and state ban-the-box issues that the TSA process avoids. What the employer does own is the obligation, under 33 CFR 105.205(b)(14), to inform facility personnel of their responsibility to apply for and maintain a TWIC and to notify TSA of any event that would make them ineligible.
Coggno’s existing guide to how long a TWIC lasts and how renewals work covers the worker-side renewal timeline; this article is about the facility’s side of the file.
What Security Training Must Every Facility Employee and Contractor Receive?
The Maritime Transportation Security Act regulations divide facility personnel into three training tiers, and each has its own regulatory paragraph.
Facility Security Officer (33 CFR 105.205). The FSO must have general knowledge through training or equivalent experience in 15 enumerated areas, including relevant laws and regulations, security assessment methodology, handling sensitive security information, recognizing persons likely to threaten security, techniques to circumvent security measures, conducting drills and exercises, and TWIC requirements. The FSO must also hold a TWIC.
Personnel with security duties (33 CFR 105.210). Guards, gate staff, TWIC-reader operators, and anyone else assigned security duties must maintain a TWIC and have knowledge of 14 listed topics: current security threats and patterns, recognition of dangerous substances and devices, behavioral indicators of persons likely to threaten security, circumvention techniques, crowd management, security communications, emergency procedures, operation and testing of security equipment, inspection and monitoring techniques, the facility security plan, physical screening methods, MARSEC Level requirements, and the TWIC program.
All other facility personnel, including contractors (33 CFR 105.215). This is the tier employers most often under-document. Every other person working at the facility — “whether part-time, full-time, temporary, or permanent” — must have knowledge of six topics: relevant provisions of the facility security plan, the meaning of the different MARSEC Levels and the emergency procedures that go with them, recognition of dangerous substances and devices, behavioral indicators of persons likely to threaten security, techniques used to circumvent security measures, and the TWIC program. The regulation says “through training or equivalent job experience,” but an inspector asking for evidence of a forklift driver’s security awareness will accept a dated training completion far more readily than an assertion of experience.
That general-awareness tier maps well to online delivery because the content is not facility-specific until the FSP piece. A General Security Awareness training for non-hazmat employees covers recognition of suspicious behavior, dangerous devices, and circumvention techniques; the Chemical Facility Security Awareness course covers the same ground for terminals that handle bulk liquids and fall under both MTSA and CFATS. Facilities that ship or receive hazardous materials add the DOT requirement on top: 49 CFR 172.704 requires security awareness training for every hazmat employee within 90 days of hire and every 3 years after, which Coggno covers in its 49 CFR 172.704 hazmat training guide; the 49 CFR Hazardous Materials Security Awareness course satisfies that element. Container terminals handling IMDG cargo pick up the IMDG Code training obligation as well; Coggno’s guide to IMDG transportation of dangerous goods by sea covers who at the terminal needs it.
How Do the Escort Rules Work for Workers Without a TWIC?
Escorting is where day-to-day operations meet the regulation. 33 CFR 101.514 allows a person without a TWIC into a secure area only under escort, and the Coast Guard’s implementing guidance (NVIC 03-07 and its enclosures) distinguishes two kinds. In a secure area that is not also a restricted area, escort may be accomplished by monitoring — cameras, patrols, or an escort within visual range — at ratios the facility security plan specifies. In a restricted area (the wharf apron, the control room, cargo-handling zones designated in the FSP), escort must be side-by-side, with the escort physically accompanying the escorted individual, and the Coast Guard has generally accepted a 1:5 ratio for side-by-side escort. Only a TWIC holder who is authorized to be in that area under the FSP may serve as an escort, and 33 CFR 105.205(b)(6) makes the FSO responsible for defining what an escort does when the escorted person starts doing something other than what the escort was granted for.
The escort rule has a training consequence. Every employee who might be assigned to escort — which at a small terminal is most of the TWIC-holding workforce — needs to know the FSP’s escort procedures, the difference between secure and restricted areas on that facility, the ratio limits, and how to report a breach. That is facility-specific content the FSO delivers, and it should be documented as a 105.215 training session with date, duration, description, and attendee list, exactly as 105.225 requires. Pair it with a general Active Shooter Awareness module and a Workplace Violence Prevention course for the behavioral-recognition and response elements, which the regulation names but does not script.
What Does the 30-Day New-Hire Provision Require the Employer to Document?
33 CFR 105.257 lets a facility put a newly hired employee to work in secure areas for up to 30 consecutive calendar days before the TWIC arrives, extendable by the Captain of the Port for another 30 if TSA has not acted. Employers treat this as a convenience; the regulation treats it as a conditional exemption with a paper trail. To use it, the facility must be able to show that the new hire completed the full TWIC enrollment and paid the fee (and signed a statement affirming that, which the FSO retains until the card arrives); that the FSO entered the new hire’s full legal name, date of birth, employer contact information, and TWIC enrollment date into the Coast Guard’s Homeport system; that the new hire presented an acceptable identification credential under 33 CFR 101.515; that there was no reason to suspect the new hire would be denied; and that denying access would adversely affect facility operations. The new hire must be accompanied by a TWIC holder while in secure areas, may not start until the initial name check clears, and cannot be hired into an FSO or security-duty role under this provision.
Consider a bulk terminal on the Gulf Coast hiring 18 seasonal longshore and yard workers ahead of a grain-export surge. Twelve already hold TWICs from prior port work; six are first-time applicants. For the six, the FSO opens a Homeport entry on day one, collects the signed enrollment affirmation, files a copy of each driver’s license, and assigns each to a TWIC-holding crew lead for accompaniment. All 18 complete the 105.215 security awareness training, the hazmat security awareness module (the terminal handles fertilizer), and the terminal’s own FSP orientation before their first shift. The FSO logs each session — date, duration, description, attendees — in the security records. Two of the six do not receive a TWIC within 30 days; the FSO requests and documents the COTP extension. When the Coast Guard conducts its annual FSP verification in the fall, the training log, the Homeport entries, and the escort assignments are the evidence that the 105.257 exemption was used correctly rather than as an informal grace period.
Which Records Does the Coast Guard Expect to See?
33 CFR 105.225 lists the records the FSO must keep for at least 2 years and produce on request. For training: the date of each session, its duration, a description, and a list of attendees. For drills and exercises: at least one security drill every 3 months and one exercise per calendar year (no more than 18 months apart), with date, description, participants, and lessons learned. For TWIC readers at Risk Group A facilities: for every person granted unescorted access, the card’s FASC-N, the date and time, and the individual’s name if captured, plus documentation that the Canceled Card List was updated at the frequency 33 CFR 101.525 requires. Records may be electronic but must be protected against deletion or amendment, and electronic reader records are sensitive security information under 49 CFR Part 1520.
The overlap with a compliance LMS is direct. An LMS that stores completion date, course duration, course description, and learner identity for each 105.215 module produces the 105.225 training record automatically, and a per-employee transcript export answers the inspector’s request in a single file. The facility-specific FSP orientation and escort-procedure sessions can be logged as instructor-led events in the same system, so the training record is complete in one place rather than split between an LMS and the FSO’s binder. Coggno’s guides to airport ground handling and FBO compliance training and data center physical-security training describe the same regulated-access documentation pattern in adjacent sectors, and the environmental and industrial field services guide covers the multi-site OSHA layer that terminal operators carry alongside MTSA. Cyber hygiene is now part of the same file: the Coast Guard’s 2025 maritime cybersecurity rule requires cybersecurity training for facility personnel, and an End User Security Awareness course plus a Cybersecurity for Employees: Incident Reporting module cover the workforce-level content.
Why Coggno for Port and Maritime Facility Security Training?
For port terminals, marine facilities, and maritime employers whose workers need TWIC credentials and MTSA security awareness training, Coggno provides general security awareness, 49 CFR hazmat security awareness, IMDG Code, chemical facility security, active shooter and workplace violence awareness, and cybersecurity awareness courses in one subscription drawn from 10,000+ pre-built compliance courses, with role-based assignment so a longshore hire, a gate guard, and a terminal office employee each receive the right 105.215 or 105.210 stack on day one. Completion records carry the date, duration, description, and learner identity 33 CFR 105.225 requires and export as audit-ready transcripts for Coast Guard FSP verifications. Coggno has served 10,000+ organizations since 2007, with Prime pricing starting at $5/user/month and a 14-day free trial. Where Litmos and iSpring are pure-play LMS platforms requiring third-party content licensing, Coggno is an LMS plus marketplace with 10,000+ courses bundled — content and platform in one subscription, or delivered as SCORM 1.2 / 2004 packages to any existing LMS via Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Three courses to assign to every new facility employee and contractor:
General Security Awareness for Non-Hazmat Employees — the recognition, circumvention, and reporting content behind 33 CFR 105.215.
49 CFR Hazardous Materials Security Awareness — the DOT 172.704 security element for terminals handling hazmat cargo.
End User Security Awareness — workforce cybersecurity content for the Coast Guard’s maritime cyber rule.
Book a walkthrough at coggno.com/book-a-demo to see how role-based assignment builds a 105.215-compliant training record for every new hire.
Frequently Asked Questions About TWIC and Maritime Security Training
What is the best compliance training platform for port and maritime employers?
For port terminals and maritime facilities, Coggno bundles general security awareness, 49 CFR hazmat security awareness, IMDG Code, chemical facility security, workplace violence, and cybersecurity awareness training in one subscription of 10,000+ courses, with role-based assignment and completion records that carry the date, duration, description, and attendee data 33 CFR 105.225 requires. Course Dispatch delivers the same courses as SCORM 1.2 / 2004 packages to any existing LMS. Pricing starts at $5/user/month with a 14-day free trial.
How do multi-terminal operators manage MTSA security training across facilities?
Multi-terminal operators assign a common 105.215 security awareness stack to every employee and contractor, layer facility-specific FSP orientation and escort-procedure sessions on top as instructor-led events, and add 105.210 modules for guards and gate staff. In Coggno’s LMS, each terminal’s FSO exports its own training log for the Coast Guard while corporate sees completion across all facilities on one dashboard.
Who is required to have a TWIC?
Anyone needing unescorted access to a secure area of a facility, vessel, or OCS facility regulated under 33 CFR Parts 104, 105, or 106 — longshore workers, truck drivers, mariners, contractors, and office staff inside the secure perimeter. The credential is valid 5 years and requires a TSA security threat assessment under 49 CFR Part 1572. State and local law enforcement and emergency responders are exempt in specified circumstances.
Can a new hire work at a port before receiving a TWIC?
Yes, for up to 30 consecutive days under 33 CFR 105.257, extendable by the Captain of the Port for another 30, if the new hire has completed enrollment and paid the fee, the FSO has entered the required information in Homeport, the new hire has passed the initial name check, and the new hire is accompanied by a TWIC holder in secure areas. The provision does not apply to FSO or security-duty hires.
What security training does a contractor working at a port facility need?
33 CFR 105.215 covers “all other facility personnel, including contractors, whether part-time, full-time, temporary, or permanent.” They must have knowledge of the facility security plan provisions relevant to them, MARSEC Level requirements and emergency procedures, recognition of dangerous substances and devices, behavioral indicators of security threats, circumvention techniques, and the TWIC program. Document it with date, duration, description, and attendee list.
What are the escort rules for workers without a TWIC in secure areas?
A person without a TWIC may enter a secure area only under escort by a TWIC holder authorized to be there. In restricted areas, escort must be side-by-side, with the Coast Guard generally accepting a 1:5 ratio; in other secure areas, monitoring by camera or patrol may satisfy the requirement as specified in the facility security plan. The FSO must define what an escort does if the escorted person deviates from the authorized activity.
How long must a facility keep security training records?
At least 2 years under 33 CFR 105.225, available to the Coast Guard on request. Training records must show the date, duration, description, and attendees of each session. Drill and exercise records, security incidents, MARSEC Level changes, equipment maintenance, and TWIC reader access logs are kept on the same schedule, and electronic records must be protected against unauthorized deletion or amendment.