Empire Protection

MTOFSA · Maritime security · Critical infrastructure

MTOFSA: what maritime security actually requires of you

Security levels, a security plan the Secretary approves, and MSICs for anyone with unmonitored access. What the Maritime Transport and Offshore Facilities Security Act asks operators to hold.

Published 31 August 2026 · 3 min read

Ports, port facilities, ships and offshore facilities sit under their own security regime: the Maritime Transport and Offshore Facilities Security Act 2003. Operators who come to it from a general security background are usually surprised by two things: how prescriptive the plan is, and how much of the burden falls on who is allowed to walk where.

Security levels, and who sets them

The Act runs on three maritime security levels. Level 1 is the ordinary state of operations and is where you sit unless told otherwise. Levels 2 and 3 are declared by the Secretary, not chosen by the operator, and they raise the measures you are required to have in place.

The practical consequence is that your plan cannot only describe how you operate today. It has to describe what changes at Level 2 and at Level 3, and those changes have to be things you could actually do at short notice with the people and equipment you have, which is a different question from whether they read well on the page.

The security plan is the obligation

Compliance under the Act is achieved through security plans and security directions. For most participants the plan is the centre of gravity: it is assessed and approved, it binds you to what it says, and it is what an inspection is measured against.

A plan written to be approved and a plan written to be operated are not the same document, and the gap between them is where findings come from. If the people on shift have never read it, or it describes a gate procedure nobody follows because it does not work at 3am, the plan is a liability rather than an asset.

MSICs, and the part that catches people out

A Maritime Security Identification Card is required for a person who needs unmonitored access to a maritime security zone at least once a year. The card is not a competency qualification. It is the outcome of a background check.

Those checks run through AusCheck, in the Department of Home Affairs, and cover identity along with criminal and national security background checking. Eligibility turns on security relevant offences, graded in tiers.

  • Work out who genuinely needs unmonitored access, rather than carding everyone for convenience; each card is a check, a cost and a renewal.
  • Know that a conviction during the life of a card must be self reported in writing, within seven days of being convicted and sentenced.
  • Build the renewal cycle into a system rather than a person’s memory: an expired card is an access control failure, and it happens on a date you could have known about years in advance.

It rarely arrives alone

Maritime operators are frequently caught by more than one regime at once. A port can be a critical infrastructure asset with obligations under the Security of Critical Infrastructure Act as well, and an operator in the defence supply chain may carry DISP obligations on top.

Treating them as three separate programmes is how organisations end up with three risk registers that disagree. The controls overlap heavily across access control, personnel security and incident reporting, and the sensible structure is one programme that can produce three different reports.

Obligations under MTOFSA and its Regulations depend on what kind of maritime industry participant you are, and they change. Treat this as an orientation, not as the authority: confirm what applies to you against the current instrument before you rely on it.

Empire Protection works with maritime operators on the plan behind the approval, the personnel security process behind the cards, and the single programme underneath whichever regimes you carry.

General information, not advice for your circumstances. Obligations change: confirm anything you intend to rely on against the current instrument.