By Wesley Alexander • September 4, 2026 • 8 min read

Tactical Summary

TSA has opened a narrow industry-input window that deserves more attention than another general Part 108 panel. The agency is recruiting qualified BVLOS operators and operator associations for closed technical roundtables intended to inform model language for TSA-approved UAS security programs. Requests to participate are due October 19, 2026.[1]

This is not a public comment period, and it is not an announcement that Part 108 is final. The FAA/TSA BVLOS rule remains a proposal. TSA says the roundtables will occur after the FAA and TSA final rules are published, when participants can evaluate the rules that actually apply to them.[1][2]

The opportunity is still immediate. TSA specifically says existing procedures used by operators flying under BVLOS waivers or exemptions may already satisfy parts of a future security program. The agency wants operational evidence from people who have been doing the work—not another stack of aspirational slides.[1]

What TSA Is Actually Building

The joint Part 108 proposal separated the security problem into two broad pieces: security threat vetting for certain covered personnel and TSA-approved security programs for certain operators.[1][2] The September 4 notice focuses on the second piece.

TSA wants to hear which organizational, structural, technological, and physical controls real BVLOS programs already use. The agency says individual input may inform model approaches that operators could use to meet future security-program requirements.[1]

That distinction matters. TSA is not convening a committee to vote on one industry recommendation. The meetings will not seek consensus, and participants will present individual views and information.[1] A large operator with a national delivery network and a small infrastructure-inspection team may solve the same risk differently. Model language that recognizes several defensible approaches would be far more useful than a one-size-fits-all manual.

Part 108 Will Be a Framework, Not an Operating System

FAA officials made the same broader point at Commercial UAV Expo this week: moving away from one-off approvals is necessary, but the rule itself will not finish the integration work. Scaled BVLOS will also depend on operational data, information sharing, airspace modernization, security, and the ability to distinguish legitimate operations from anomalous activity.[3]

For operators, the practical lesson is simple: regulatory authority and operational readiness are different products.

A permit or certificate can authorize an operation. It cannot create mature access control, reliable configuration records, a tested cyber-incident response, disciplined payload custody, or an accountable security organization. Those systems have to exist inside the operator before they can appear in a credible TSA security program.

Who Can Ask to Participate

TSA is inviting representatives from two groups:

Industry associations representing those operators are also eligible. TSA says participation will generally be limited to entities potentially and directly affected by the final rule, with no more than two people per association or company.[1]

Every participant must be approved for access to Sensitive Security Information and sign a nondisclosure agreement. The duty to protect SSI continues after the roundtables end.[1] These are closed working sessions, not conference panels whose details can be turned into marketing content afterward.

What a Serious Operator Should Prepare Now

The notice does not prescribe an application form or demand a finished security manual. It does, however, make the selection logic fairly clear: TSA wants current practices from organizations that can explain how their controls work in real BVLOS operations.

A credible preparation package should include the following seven elements.

1. Security governance. Identify who owns the security program, who can approve changes, who receives incident reports, and how responsibility flows across operations, maintenance, IT, vendors, and executive leadership.

2. Personnel and access control. Map which roles can reach aircraft, control stations, command links, mission-planning systems, payloads, flight-path data, software releases, and operating sites. Separate physical access from digital privilege; they fail differently.

3. Aircraft, C2, and ground-system security. Document how the program manages device identity, software and firmware configuration, authentication, remote access, credential revocation, network segmentation, logging, and recovery from suspected compromise.

4. Third-party service dependencies. List the external services that can affect dispatch, strategic deconfliction, conformance monitoring, communications, navigation, weather, or operational decision-making. Record what the crew does when a service is degraded, unavailable, or inconsistent with another source.

5. Payload and custody controls. For delivery or sensitive-payload operations, describe who accepts, screens, stages, loads, releases, and reconciles payloads. For inspection and public-safety work, apply the same discipline to sensors, collected data, removable media, and evidence handling.

6. Detection, reporting, and response. Show how the program identifies unauthorized access, cyber events, suspicious behavior, missing equipment, anomalous flight performance, and compromised data. Then show who can stop operations and how corrective action is tracked to closure.

7. Evidence. Bring records that prove the controls operate: training completions, access reviews, configuration histories, exercise results, incident logs, vendor assessments, audit findings, and closed corrective actions. A policy that cannot be demonstrated is a promise, not a control.

These are preparation categories, not a claim about the final rule's requirements. Until final text is published, keep a clear boundary between current obligations, proposed Part 108 language, TSA roundtable preparation, and internal best practice.

How to Request a Seat Without Creating a Security Problem

TSA directs participation requests to BVLOS@tsa.dhs.gov and sets October 19 as the receipt deadline.[1] The notice does not publish a mandatory request template.

A concise initial request should identify:

Do not turn the initial email into an uncontrolled data dump. Describe capabilities at a high level and ask TSA how protected material should be transmitted before sending information that may be sensitive, proprietary, or security-relevant.

The Operator Takeaway

The October 19 window is not a chance to rewrite the FAA's proposed flight rules. It is a chance for operators to help TSA avoid writing security-program models in an operational vacuum.

The strongest participants will not be the companies with the loudest policy teams. They will be the programs that can explain, with evidence, how they control people, aircraft, data, facilities, payloads, vendors, and abnormal events across a real BVLOS operation.

Even if TSA does not select your organization, preparing that evidence is not wasted work. It is the same readiness stack a mature operator needs for a customer audit, insurer review, waiver renewal, permit or certificate application, or incident investigation.

For a structured way to build that stack without treating the NPRM as final law, use the Part 108 BVLOS Readiness Playbook. It turns the readiness problem into a working set of operational documents, evidence trails, and review gates your team can improve before the rule lands.

Wesley Alexander is a former Insitu/Boeing ScanEagle Commercial Chief Test Pilot and former UAS DPE for Insitu ScanEagle pilots and instructors. UAVHQ provides operator-focused intelligence on regulatory and safety developments in the commercial UAV industry.

Sources

[1] https://www.federalregister.gov/documents/2026/09/04/2026-18124/notice-soliciting-representatives-for-technical-roundtables-on-security-of-unmanned-aircraft-systems — TSA Notice: BVLOS Security Technical Roundtables [2] https://www.federalregister.gov/documents/2025/08/07/2025-14992/normalizing-unmanned-aircraft-systems-beyond-visual-line-of-sight-operations — FAA/TSA Part 108 BVLOS NPRM [3] https://dronelife.com/2026/09/02/faa-drone-integration-bvlos-advanced-aviation — FAA Drone Integration: Scaling BVLOS and Advanced Aviation