Presidential Policy Directive 21 (PPD-21), issued February 12, 2013, was the Obama-era directive that set the federal framework for protecting the physical and digital systems the country relies on, organizing that work around sixteen critical infrastructure sectors, assigning lead agencies to each, and setting three strategic goals for resilience.1The White House. Presidential Policy Directive – Critical Infrastructure Security and Resilience It replaced an earlier directive from 2003 and was itself officially superseded on April 30, 2024, when the White House issued National Security Memorandum 22 (NSM-22).2Congress.gov. The 2024 National Security Memorandum on Critical Infrastructure Security and Resilience The organizational architecture PPD-21 created still runs current federal programs, so the directive continues to matter even though it is no longer the operative policy document.
The Sixteen Critical Infrastructure Sectors
PPD-21 designated sixteen sectors whose disruption or destruction could cripple national security, the economy, or public health.3Cybersecurity and Infrastructure Security Agency. Critical Infrastructure Sectors These categories remain in effect under the successor memorandum:
- Chemical
- Commercial Facilities
- Communications
- Critical Manufacturing
- Dams
- Defense Industrial Base
- Emergency Services
- Energy
- Financial Services
- Food and Agriculture
- Government Facilities
- Healthcare and Public Health
- Information Technology
- Nuclear Reactors, Materials, and Waste
- Transportation Systems
- Water and Wastewater Systems
PPD-21 was the first federal directive to explicitly build its framework around the cascading risks between these sectors rather than treating each one in isolation. A prolonged power outage does not stay in the energy sector; it moves into communications, healthcare, water treatment, and financial services within hours.
Which Federal Agencies Lead Each Sector
PPD-21 gave the Secretary of Homeland Security the lead role in coordinating infrastructure protection across the federal government. That coordination responsibility now runs through the Cybersecurity and Infrastructure Security Agency (CISA), which acts as the national coordinator for sector risk management work.4Cybersecurity and Infrastructure Security Agency. National Security Memorandum on Critical Infrastructure Security and Resilience
Each sector has a designated federal department to understand its unique risks and coordinate protection. PPD-21 originally called these Sector-Specific Agencies. Under the current framework they are Sector Risk Management Agencies (SRMAs), a name change that reflects a broadened mission to actively manage risk rather than only advise.5Cybersecurity and Infrastructure Security Agency. Sector Risk Management Agencies The current designations:
- Department of Homeland Security: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Emergency Services, Information Technology, and Nuclear Reactors, Materials, and Waste.
- Department of Energy: Energy.
- Department of the Treasury: Financial Services.
- Department of Defense: Defense Industrial Base.
- Department of Health and Human Services: Healthcare and Public Health, and Food and Agriculture (co-managed with the Department of Agriculture).
- Environmental Protection Agency: Water and Wastewater Systems.
- Department of Homeland Security and General Services Administration, jointly: Government Facilities.
- Department of Homeland Security and Department of Transportation, jointly: Transportation Systems.
The practical effect is that a water utility dealing with a cyber threat works through the EPA, while a hospital facing the same threat contacts HHS. Both agencies coordinate through CISA, which keeps the broader picture in view.
The Voluntary Public-Private Partnership Model
Private companies own and operate the majority of the nation’s critical infrastructure, and PPD-21 built its approach around voluntary cooperation rather than top-down regulation. Two types of organized groups make that work. Sector Coordinating Councils (SCCs) bring together private-sector owners, operators, and trade associations within each sector.6Cybersecurity and Infrastructure Security Agency. Sector Coordinating Councils Government Coordinating Councils (GCCs) serve as the federal counterpart, enabling coordination across agencies and jurisdictions for each sector.7Cybersecurity and Infrastructure Security Agency. Government Coordinating Councils
Protection for Information Shared With the Government
A company sharing details about its security weaknesses with federal officials has real concerns about that information becoming public or being used against it. The Protected Critical Infrastructure Information (PCII) program, established under the Critical Infrastructure Information Act of 2002, addresses that directly. Vulnerability data voluntarily submitted through PCII is shielded from public records disclosure, state and local open-records laws, and use in civil lawsuits. The information also cannot be used as the basis for regulatory enforcement against the submitting entity.8Department of Defense. Protected Critical Infrastructure Program Access is limited to trained, authorized government users with a specific security-related need.
Three Strategic Objectives
PPD-21 organized federal work around three strategic priorities.9Federal Emergency Management Agency. Presidential Policy Directive 21 – Critical Infrastructure Security and Resilience
- Clarify federal roles so every agency knew its lane, eliminating confusion and duplication and producing a “national unity of effort.”
- Enable effective information exchange by identifying the baseline data and system requirements needed to share threat and vulnerability information quickly.
- Build a centralized integration and analysis function to combine data across sectors, model cross-sector dependencies, and feed the analysis into operational planning.
The third objective was the most ambitious. Before PPD-21, no single office was charged with looking across all sixteen sectors to model how a disruption in one area might cascade into others. That analytical function is now part of CISA’s core mission.
The Companion Executive Order on Cybersecurity
The same day PPD-21 was issued, the White House also released Executive Order 13636 on improving critical infrastructure cybersecurity. Where PPD-21 set the broad organizational framework, EO 13636 directed the National Institute of Standards and Technology (NIST) to develop a voluntary cybersecurity framework that infrastructure operators could use to assess and improve their cyber defenses. The executive order also expanded classified threat information sharing with the private sector and required the identification of infrastructure where a cyberattack could cause catastrophic consequences.
The NIST Cybersecurity Framework that emerged became one of the most widely adopted products of the entire effort. Many companies that would never read PPD-21 itself use the NIST framework as their cybersecurity baseline.
What Changed When NSM-22 Replaced PPD-21
NSM-22 preserved the core architecture PPD-21 created: the same sixteen sectors, the same SRMA structure, and the same public-private partnership councils all carry forward.2Congress.gov. The 2024 National Security Memorandum on Critical Infrastructure Security and Resilience What changed is the policy philosophy. NSM-22 concluded that voluntary approaches had not been successful enough and that mandatory minimum requirements were necessary. The most significant shifts:
- SRMAs are directed to develop sector-specific minimum security and resilience requirements and to use existing regulatory authorities to implement them, rather than only offering voluntary guidance.
- Each SRMA must designate a senior official at the assistant secretary level or above who is personally accountable for the agency’s infrastructure protection performance. Sector-specific risk management plans are due every two years.
- CISA is directed to maintain a non-public list of Systemically Important Entities whose disruption could cause cascading failures on a national scale, helping prioritize federal resources and intelligence.
- The Secretary of Homeland Security must produce a National Infrastructure Risk Management Plan every two years, combining cross-sector and sector-specific risk assessments into a single document for the President.
Mandatory Cyber Incident Reporting Under CIRCIA
Congress separately passed the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in 2022, adding a statutory reporting mandate that goes beyond anything PPD-21 contemplated. Under CIRCIA, covered entities that experience a significant cyber incident must report it to CISA within 72 hours of reasonably believing the incident occurred. If a covered entity makes a ransomware payment, the report is due within 24 hours of the payment.10Office of the Law Revision Counsel. United States Code Title 6 – Section 681b Required Reporting of Certain Cyber Incidents
The definition of “covered entity” is not based on a simple employee count or revenue threshold. CISA’s final rule is expected to define covered entities based on the consequences that disrupting the entity could cause to national security, economic security, or public health; the likelihood the entity may be targeted by a foreign adversary or other malicious actor; and the extent to which compromising it could cascade into broader infrastructure failures. The final rule is expected to be published in mid-2026.
If a covered entity fails to report a qualifying incident, CISA can issue a formal request for information and, if that goes unanswered, a subpoena. Ignoring the subpoena can lead to federal court enforcement, contempt findings, and referral to the suspension and debarment process for entities holding federal contracts. Knowingly filing a false report carries penalties under federal false-statements law, including up to five years in prison.11Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements For any organization operating in one of the sixteen sectors PPD-21 established, determining whether it qualifies as a covered entity is now a near-term legal question, not a voluntary one.