TSA, the Closed Door, and the Security Blueprint That Will Define BVLOS at Scale
The TSA is convening closed-door industry sessions to build model security programs for beyond visual line of sight drone operations, a framework that will reshape U.S. airspace for every pilot.
The Transportation Security Administration (TSA) is convening a series of closed-door sessions with industry representatives to develop model security programs for expanded drone operations beyond visual line of sight (BVLOS). According to reporting from AVweb, these sessions will produce a compliance framework that operators can adopt as the basis for seeking large-scale BVLOS authority. The decisions made in these rooms will define the security architecture of a fundamentally different airspace - one every pilot will eventually share.
What the TSA Is Building and Why It Is Different from the FAA’s Role
Currently, flying a drone beyond visual line of sight in the United States requires a waiver from the Federal Aviation Administration (FAA). That process demands documentation of detect-and-avoid capability, a detailed operational plan, and FAA review. Most commercial operators who have achieved BVLOS authority have spent months or years working through it.
The FAA’s focus is operational and safety-centered: command-and-control integrity, communication link reliability, airspace conflict avoidance. The TSA’s mandate is different. It covers what happens when a drone becomes a weapon, a surveillance tool, or a probe against protected infrastructure. Until now, TSA had limited formal involvement in the BVLOS regulatory picture. That is changing.
Model security programs are an established TSA mechanism - already in use for indirect air carriers, repair stations with aircraft access, and cargo facilities. What is new is applying the framework to unmanned systems operating beyond visual line of sight at scale.
What a BVLOS Security Program Will Likely Cover
The specific content of these sessions is not public, but the probable pillars can be inferred from existing TSA frameworks and FAA guidance on BVLOS operations.
Physical security is foundational. A BVLOS drone may operate miles from its ground control station, meaning the ground infrastructure, communication links, and data systems sustaining command and control all become potential targets. Expect requirements around access control, facility protection, and incident response procedures.
Cybersecurity presents a distinct and technically complex challenge. A remotely piloted aircraft is a network-connected device in shared airspace. The command-and-control link, the data link, and the fleet management software coordinating dozens of aircraft simultaneously all present attack surfaces. TSA cybersecurity guidance built around conventional airline and cargo operations does not map cleanly onto UAS architecture.
Personnel security addresses who operates these systems and who accesses the data they generate. Manned aviation has an established framework: certificates, medicals, background checks. The equivalent structure for drone operators at scale is still being assembled.
Geofencing and coordination with existing security systems is the fourth element. BVLOS operations near airports, sensitive facilities, or already-protected infrastructure require formal coordination with the authorities responsible for those sites. The model program will need to define exactly how that happens.
The Closed-Door Format: Efficiency Against Accountability
Aviation rulemaking in the United States is normally public. The FAA publishes a notice of proposed rulemaking, a comment period opens, and the agency must respond to substantive input before issuing a final rule. That process is slow, but it gives affected parties - including individual pilots - a formal voice.
The TSA’s approach is different. A selected group of industry stakeholders, presumably companies already active in the BVLOS space or with significant investment in it, will help shape these programs before anything becomes public record. The rationale is genuine: operators running infrastructure inspection, package delivery, and medical supply transport have operational knowledge that is difficult to acquire from the outside. A security program that has to work in the real world needs input from the people building and flying these systems.
The risk is equally genuine. Industry-shaped security frameworks have, historically, sometimes ended up shaped more around industry interests than public protection. Whether these sessions thread that needle correctly will become clearer once their output is visible.
Why This Matters for General Aviation Pilots
Drone regulation can appear to be someone else’s problem if you fly manned aircraft. It is not.
The national airspace system is shared infrastructure. BVLOS operations at scale will expand into the same airspace where general aviation operates - below Class Bravo, in corridors between cities, and in the terminal environment around airports. A well-constructed security framework will include provisions for conflict avoidance with manned traffic, coordination with air traffic control, and robust Remote ID requirements that let both ATC and airborne pilots identify drone traffic. A poorly constructed one will not.
The current drone traffic most general aviation pilots encounter operates under visual line of sight rules, below 400 feet AGL, with a nearby operator who can intervene immediately. The BVLOS traffic arriving under expanded authority will fly longer distances, potentially higher within the low-altitude structure, and under operators who may be hundreds of miles away. That is a categorically different operational environment.
Practical steps for manned pilots now:
- Enable Remote ID data in your electronic flight bag application if the feature is available
- Monitor temporary flight restriction (TFR) status in your area - BVLOS operations with special authority often carry associated airspace management
- Use the FAA Aviation Safety Hotline to report airspace anomalies, which voluntary reporting systems are specifically designed to catch during periods of rapid regulatory change
The Industry Stakes
The companies pressing hardest for BVLOS clarity have made substantial bets on it. Wing, Amazon Prime Air, Zipline, and UPS Flight Forward - along with a growing number of smaller operators - have built business models that depend on large-scale, predictable BVLOS authority. Every year the framework remains fragmented and waiver-dependent is a year of compounding uncertainty for those models.
If the TSA’s model security programs integrate cleanly with the FAA’s existing operational structure - Part 107, the Remote ID rule, LAANC (Low Altitude Authorization and Notification Capability), and the waiver pathways - the path to scalable BVLOS authority becomes clearer and the timeline compresses. That is the inflection point these sessions represent.
For Commercial Drone Operators: Where to Focus Attention
The model security programs emerging from these sessions will likely form the baseline for what TSA compliance requires when formal guidance is published. Operators who understand that framework early - or help shape it through industry representation - are in a stronger position.
The organizations active in these policy conversations include:
- American Institute of Aeronautics and Astronautics (AIAA)
- Association for Unmanned Vehicle Systems International (AUVSI)
- Commercial Drone Alliance
For manned aircraft pilots engaged through AOPA (Aircraft Owners and Pilots Association) or EAA (Experimental Aircraft Association), those affiliations provide earlier visibility into what is coming before it reaches the Federal Register. In a period of rapid airspace change, that lead time has real value.
Key Takeaways
- The TSA is developing model security programs for BVLOS drone operations through closed-door industry sessions, creating a scalable compliance framework for the first time.
- Model security programs are a proven TSA tool - already applied to cargo facilities, repair stations, and indirect air carriers - now being extended to unmanned systems operating beyond visual line of sight.
- The four likely pillars of any BVLOS security program: physical security of ground infrastructure, cybersecurity of command-and-control links, personnel vetting, and geofencing coordination with protected facilities and airports.
- The closed-door format accelerates development but raises legitimate questions about whether public and pilot interests are adequately represented in the final framework.
- BVLOS expansion directly affects every pilot who flies in shared airspace. Monitor Remote ID data in your EFB, track TFR activity, use voluntary reporting systems, and stay connected to pilot advocacy organizations tracking these regulatory developments.
Radio Hangar. Aviation talk, built by pilots. Listen live | More articles