Security patrols

Bomb threat checklist: what to ask, what to write down, and how the building is ready for it

A bomb threat checklist is a card, published free by CISA, that the person who receives a threat fills in during or right after the call, recording the answers to set questions, the exact words of the threat and what the caller sounded like.

By SiteClaraPublished 14 minute read

A receptionist answering a desk phone at an office lobby front desk, with a laminated card lying beside the handset.

Most bomb threats arrive by phone, at a front desk or a switchboard, and most prove to be false. The few minutes on the call decide how much the building's decision maker and the police have to work with. The checklist is what turns those minutes into usable information. This guide covers what the checklist asks, where to keep it, what happens after it is filled in, and the routine checks that make a search or an evacuation easier when a threat is taken seriously.

01

What the bomb threat checklist is, and who publishes it

The CISA Bomb Threat Checklist is a two-sided card from the Office for Bombing Prevention at the Cybersecurity and Infrastructure Security Agency (CISA), part of the Department of Homeland Security. The current version is dated August 2025. CISA describes it as providing "instructions on how to respond to a bomb threat and a comprehensive list of information that will assist law enforcement in a bomb threat investigation." One side is the procedure for a threat received by phone, in writing, or by email or social media; the other is the checklist itself, the questions to ask and the boxes to check while the caller is still talking.

Below its statement of purpose, the card sets the tone: "Most bomb threats are received by phone. Bomb threats are serious until proven otherwise. Act quickly, but remain calm and obtain information with the checklist on the reverse of this card."

No federal law requires a private building to keep this particular card. It is voluntary guidance: CISA's companion Bomb Threat Guide (Version 1, August 2025) says DHS "does not mandate or prescribe practices" in it. Where an OSHA standard requires an emergency action plan, 29 CFR 1910.38, Emergency action plans, sets the minimum: procedures for reporting emergencies, evacuation and exit route assignments, critical operations, accounting for everyone, rescue and medical duties, and a contact who can explain the plan. OSHA's emergency action plan eTool lists the emergencies that may force an evacuation, including explosions, civil disturbances and workplace violence. A bomb threat procedure fits naturally inside that plan (see emergency action plans).

Two cautions. In states with OSHA-approved state plans, the state's standard applies in place of the federal one. And the decisions during a real threat belong to your own decision maker working with local law enforcement, not to a card: the checklist itself says to "refer to your local bomb threat management plan for evacuation criteria."

02

What the checklist asks, and what the caller's side records

The checklist side has a header for the date, the time, the time the caller hung up, and the phone number where the call was received. Then come the questions to ask the caller, in the card's own words:

  • Where is the bomb located? (building, floor, room, etc.)
  • When will it go off?
  • What does it look like?
  • What kind of bomb is it?
  • What will make it explode?
  • Did you place the bomb? Yes or No.
  • Why?
  • What is your name?

Below the questions is a box for the exact words of the threat, which matter most, because the wording is what the decision maker assesses. Then information about the caller: where the caller seems to be (background and level of noise), estimated age, whether the voice is familiar and who it sounds like, and other points.

The rest is check boxes, so a receptionist with a phone in one hand can work through them: 26 descriptions of the caller's voice (calm, angry, disguised, accent, slurred and so on), background sounds (street noises, PA system, music, office or factory machinery, static, local or long distance), and the threat language (incoherent, message read, taped message, irrational, profane, well-spoken), with space for other information.

The procedure side covers threats that do not come by phone. For a written threat: handle the document as little as possible; note the date, time and location it was found; secure it and do not alter it in any way; notify the site decision maker. For a social media or email threat: do not turn off or log out of the account; leave the message open on the device; take a screenshot, or copy the message and subject line; note the date and time; notify the site decision maker.

And there is a short DO NOT list for a suspicious item, such as a suspicious package found after a threat: do not use two-way radios or cellular phones in close proximity to a suspicious item, and do not touch or move a suspicious item. The procedure side closes with a banner: "If a suspicious item is found, call 911."

03

Before a threat: where the checklist lives, and the plan behind it

A checklist in a binder in the facility manager's office is no use to the person who answers the call. The Bomb Threat Guide notes that most bomb threats are answered by someone on a phone with a publicly listed number, and that because anyone in the organization could receive one, everyone must be trained in the procedure. In practice that means a printed card at every position that takes outside calls: the lobby and security desks, the guard booth, the switchboard and any call center, the school front office, the facilities help desk and the property management or leasing office. Fill in who to call before it goes out, and check the cards now and then; a missing card, or a photocopy of an old version, is easy to miss unless someone looks.

The card sits inside a bomb threat management (BTM) plan. CISA's guide says the BTM plan should be part of the site's overall emergency response planning and lists the core elements every plan should include: a procedure for handling a bomb threat, a procedure for assessing the threat level, a procedure for response (a search and evacuation plan), and instructions for restoring normal operations afterward. It names the roles to settle in advance, with alternates for turnover, vacations and illness: the receiving party, the decision maker, a law enforcement liaison, a search team leader and search team, an evacuation team leader and evacuation team, and runners who carry equipment or messages. For colleges and universities, CISA publishes a Bomb Threat Management Annex Template with template language for the plan.

The guide also suggests a portable command post kit: copies of the emergency response plans, contact numbers, a complete set of master keys with a printed key list, floor plans marked with evacuation routes and search zones, charged cell phones and flashlights. Like the checklist, the kit is only as good as its last check.

04

Receiving a threat, and how the decision maker assesses it

For a phone threat, the checklist card gives six steps:

  1. Remain calm and do not hang up; keep the caller on the line for as long as possible.
  2. If possible, signal other staff members to listen and notify the site decision maker.
  3. If the phone has a display, copy the number and/or letters on the display.
  4. Write down the exact wording of the threat.
  5. Record the call, if possible.
  6. Fill out the Bomb Threat Checklist immediately.

If the caller hangs up before every question has been asked, fill in what you have right away, including the time the caller hung up, which has its own box at the top of the card.

The Bomb Threat Guide adds listening for background noises and being available for interviews with law enforcement. For a written threat it adds copying the wording exactly onto another sheet and noting the full names of anyone who saw it. For a threat made in person: keep your distance, contact the police immediately, note which way the person went, and write down the threat and a description of the person.

The completed card then goes to the decision maker, who assesses the threat. The guide says that "most threats prove to be false," and asks the decision maker to weigh the level of realism, plausibility, directness, immediacy and the exact wording, noting that a threat showing knowledge of the site makes a device more likely. It sets out three levels:

  • Low risk: the threat lacks realism, is vague and indirect, is inconsistent or implausible, was delivered indirectly (found on a wall or sent by email), or comes from a known or repeat caller. The probable motive is disruption.
  • Moderate risk: the threat is direct and feasible, suggests some forethought, may give a place and time, but shows no strong sign of preparatory steps.
  • High risk: the threat is direct, specific and realistic, may name people, times or the device's location, suggests concrete steps have been taken, and poses an immediate and serious danger.

The response options follow: assess and monitor; assess and search, partial or full; assess, search and lock down, partial or full; or assess and evacuate, partial or full, after priority searches. The guide is explicit that evacuation is not automatic: "Even if a threat seems adequately credible, do not automatically evacuate. This could place evacuees in greater danger of an attack." Mass bomb threats, sent to many sites at once by email or automated call, typically lack specificity; each site still assesses its own.

A security officer checking a stairwell exit door on a quiet parking garage level during a routine round.

05

Search, evacuation and re-entry: where the routine pays off

Whatever the decision, the search team searches as the decision maker directs; the guide recommends naming its members in advance, and after an evacuation the decision maker also decides whether staff search their own work areas on their return. The guide recommends that every search team member has the floor plan with evacuation routes marked, and prioritizes evacuation areas, hazardous areas and the locations named in the threat. Its search rules include minimizing wireless communications, marking and recording every area searched, and searching public areas, assembly locations and exterior evacuation routes before any evacuation. Never assume only one device is present, never trust the time given in the threat, and never touch, move or cover a suspicious object. "If anyone can see the object, they are too close."

Searchers are looking for what is out of place, and this is where everyday familiarity counts. The guide separates an unattended item from a suspicious one with the H.O.T. test: is it intentionally Hidden, Obviously suspicious, or not Typical for your environment? An unattended bag in a lobby is treated with caution, its owner looked for and it is reported. A suspicious one calls for R.A.I.N.: recognize the indicators, avoid the item, isolate the area, and notify emergency services. The officer who walks the garage every night and the custodian on the morning restroom round know best what is typical.

The DHS-DOJ Bomb Threat Stand-Off Card gives evacuation distances by type of device. For a pipe bomb (5 lbs), the mandatory evacuation distance is 70 ft and the preferred evacuation distance is 1,200 ft or more; for a car (500 lbs), 320 ft and 1,900 ft or more. The card says the stand-off data should be used together with your emergency evacuation plan, which is one reason assembly points need thought in advance.

If the decision maker orders an evacuation, the guide's steps include choosing routes and assembly areas away from any suspicious item, announcing the evacuation only after they have been searched, notifying police, fire and EMS, telling evacuees to take their bags, accounting for everyone and confirming the building is empty. Re-entry is phased where crowding is a risk: security back in place before operations restart, employees before the public.

Afterward, the records matter. The completed checklist and any written note, screenshot or recording go to law enforcement as evidence, and the site keeps its own account of what was done: who received the threat, when the decision maker was told, what was searched and cleared, and when people went back in. That account belongs with the security incident report and feeds the plan review, since CISA's guide calls for ongoing evaluation and revisions circulated to everyone involved.

06

Where bomb threat readiness fails in practice, and where SiteClara fits

The plan is written and the checklist was printed. Then a threat comes in on a Saturday. The card at the front desk has been gone since the lobby was redecorated, the floor plan in the command post kit shows the old tenant layout, and nobody can say whether the exits the evacuation depends on were clear this week. None of that is about the threat itself; it is about whether the routine that makes a response work was kept up, and whether anyone can show it.

SiteClara is built for that routine. A printed QR poster, with an optional NFC tag behind it, goes at each place the building's own plan names: the desks where a checklist card should be, the command post kit, the emergency exits, the loading dock, the parking garage and the public spaces walked every day. The person doing the round scans the code or taps the tag on their own phone, with no app to install, sees the checks due at that point, such as checklist card present, local numbers filled in or exit clear, door closes and latches, and marks them done, or says what stopped them. The time and the named person are recorded as it happens, with a photo when one is asked for. Something wrong found on the round, a missing card or a blocked exit, is reported there and goes onto the team's list of jobs until someone closes it.

The security supervisor or facility manager sees what was due, done and missed, with the reason where one was given, and a job that needs the building manager can be escalated to them to answer. Each day the supervisor reviews the day's checks and photos, adds a note and approves a report that goes to nominated management or client contacts at 8 a.m. the next morning, showing how the scheduled checks went and what is still open.

07

Questions people ask

What is a bomb threat checklist?

It is a quick reference card for recording a threat while it is happening. The CISA Bomb Threat Checklist (August 2025) says it is "designed to help employees and decision makers of commercial facilities, schools, etc. respond to a bomb threat in an orderly and controlled manner with the first responders and other stakeholders." One side gives the procedures for a threat by phone, in writing, or by email or social media; the other lists the questions to ask the caller, with boxes for the caller's voice, background sounds and threat language.

What questions should you ask in a bomb threat?

The CISA Bomb Threat Checklist lists eight, in this order: where is the bomb located (building, floor, room, etc.), when will it go off, what does it look like, what kind of bomb is it, what will make it explode, did you place the bomb, why, and what is your name. It then asks for the exact words of the threat and what you can tell about the caller: where they seem to be, their estimated age, and whether the voice is familiar.

What are the procedures for a bomb threat?

For a phone threat, the CISA Bomb Threat Checklist says to remain calm and not hang up, keep the caller on the line for as long as possible, signal other staff to listen and notify the site decision maker, copy the number from any display, write down the exact wording of the threat, record the call if possible, and fill out the checklist immediately. A written threat is handled as little as possible and secured; an email or social media threat is left open on the device and captured with a screenshot or a copy of the message and subject line. The card adds: "If a suspicious item is found, call 911."

What are the three levels of bomb threat risk assessment?

Low, moderate and high risk. CISA's Bomb Threat Guide (Version 1, August 2025) asks the decision maker to place every threat in one of the three because "most threats prove to be false." A low-risk threat lacks realism; a moderate-risk threat is feasible and more specific about methods and places; a high-risk threat is direct, specific and realistic. The level points to a response: assess and monitor, assess and search, assess, search and lock down, or assess and evacuate, the last three each partial or full.

08

Where to read the official guidance, and a short list to take away

The primary sources, all free to read:

Local law enforcement is the other source: CISA's guide says to coordinate with them and first responders where possible.

A short list to take away:

  • Print the current CISA checklist for every phone that takes outside calls, and fill in who to call before it goes out.
  • Train everyone who answers a public line: stay calm, keep the caller talking, write down the exact words, fill in the card immediately.
  • Keep the bomb threat procedure inside the emergency action plan, with named decision makers and alternates.
  • Agree search zones, assembly points and re-entry rules with local law enforcement in advance, using the stand-off distances.
  • Check the cards, the command post kit, exits and floor plans on a routine, and keep a record that shows it was done.
  • After any threat, hand the card and evidence to law enforcement, write up what was done, and review the plan.

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. CISA Bomb Threat Checklist cisa.gov
  2. Bomb Threat Guide cisa.gov
  3. 29 CFR 1910.38, Emergency action plans osha.gov
  4. Emergency action plan eTool osha.gov
  5. Bomb Threat Management Annex Template cisa.gov
  6. DHS-DOJ Bomb Threat Stand-Off Card cisa.gov
  7. CISA's bomb threats page cisa.gov
  8. What to Do: Bomb Threat video cisa.gov