The 16 critical infrastructure sectors are the categories of physical and virtual systems that the federal government has designated as so vital that their disruption would seriously harm national security, the economy, or public health. The list was set by Presidential Policy Directive 21 in 2013 and later reinforced by statute, with each sector assigned to a lead federal agency responsible for coordinating its security.
The underlying legal definition comes from the USA PATRIOT Act, codified at 42 U.S.C. § 5195c(e), and quoted in PPD-21: “systems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”1The White House. Presidential Policy Directive – Critical Infrastructure Security and Resilience The definition is deliberately broad. It reaches dams and power plants, and it also reaches banking networks and data centers.
The 16 Sectors
Each sector covers a distinct category of assets and systems. Some overlap in practice, but the government treats them separately for oversight purposes.
- Chemical. Manufacturing, storage, and transport of industrial chemicals, from fertilizers to specialty plastics.
- Commercial Facilities. Sites where large groups gather, including shopping centers, hotels, stadiums, and entertainment venues.2Cybersecurity and Infrastructure Security Agency. Commercial Facilities Sector
- Communications. The backbone for internet, telephone, and satellite services that virtually every other sector depends on.
- Critical Manufacturing. Production of heavy machinery, electrical equipment, and transportation equipment that keeps supply chains moving.
- Dams. Flood control, water storage, hydroelectric generation, navigation locks, and levee systems.
- Defense Industrial Base. Private companies that research, develop, and manufacture military weapon systems and components.
- Emergency Services. Police, fire, emergency medical services, and public works teams that respond to disasters.
- Energy. Production and distribution of electricity, oil, and natural gas through power plants, pipelines, and the electrical grid.
- Financial Services. Banks, credit unions, exchanges, and payment systems that allow money to move securely.
- Food and Agriculture. Farming, food processing, and the distribution networks that keep the food supply intact.
- Government Facilities. Federal buildings, military installations, and nationally significant monuments and icons.
- Healthcare and Public Health. Hospitals, pharmaceutical manufacturing, disease surveillance, and medical supply chains.
- Information Technology. Hardware manufacturers, software developers, and operators of large-scale data centers.
- Nuclear Reactors, Materials, and Waste. Facilities generating nuclear power and managing radioactive byproducts, subject to Nuclear Regulatory Commission oversight.3Nuclear Regulatory Commission. Backgrounder on Byproduct Materials
- Transportation Systems. Aviation, rail, maritime shipping, highways, and pipelines moving people and goods domestically and internationally.
- Water and Wastewater Systems. Drinking water treatment and distribution, plus sewage collection and treatment facilities.
The Four Foundational Sectors
Not all 16 sectors are equally interconnected. CISA identifies Communications, Energy, Transportation, and Water as foundational because virtually every other sector depends on them to function. The Energy sector powers everything else. Communications networks carry the monitoring and control signals that keep those systems running. When one foundational sector fails, the damage cascades into the others.4Cybersecurity and Infrastructure Security Agency. Infrastructure Dependency Primer – Learn
These dependencies often run in both directions. Energy systems need communications networks to operate, and communications networks need energy to stay on.
Which Federal Agency Oversees Each Sector
Under 6 U.S.C. § 652a, each sector has a designated Sector Risk Management Agency (SRMA) responsible for coordinating risk identification, security planning, and collaboration with private-sector partners.5Office of the Law Revision Counsel. 6 U.S.C. 652a – Sector Risk Management Agencies The SRMA is not a regulator with direct enforcement power over every company in its sector. It is the federal government’s main point of contact for that industry, sharing threat intelligence, developing security guidelines, and identifying systemic vulnerabilities.
The full mapping, as designated in PPD-21 and codified by statute:6Cybersecurity and Infrastructure Security Agency. Sector Risk Management Agencies
- Department of Homeland Security: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Emergency Services, Information Technology, and Nuclear Reactors, Materials, and Waste.
- Department of Energy: Energy.
- Department of Defense: Defense Industrial Base.
- Department of the Treasury: Financial Services.
- Department of Agriculture and Department of Health and Human Services jointly: Food and Agriculture.
- Department of Health and Human Services: Healthcare and Public Health.
- DHS and General Services Administration jointly: Government Facilities.
- DHS and Department of Transportation jointly: Transportation Systems.
- Environmental Protection Agency: Water and Wastewater Systems.
DHS carries the heaviest load, managing eight sectors directly. The statute requires the Secretary of Homeland Security to review the sector designations and SRMA assignments at least every five years and recommend any needed changes to the President.5Office of the Law Revision Counsel. 6 U.S.C. 652a – Sector Risk Management Agencies
What Compliance Obligations Apply
Federal cybersecurity rules for these sectors are a patchwork. Some carry binding requirements today; others rely on voluntary cooperation or await final rulemaking.
CIRCIA Reporting Across All Sectors
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) creates mandatory reporting obligations for “covered entities” across all 16 sectors. Under 6 U.S.C. § 681b, a covered entity that experiences a significant cyber incident must report it to CISA within 72 hours of reasonably believing the incident occurred. If the entity makes a ransomware payment, it must report that payment within 24 hours, regardless of whether the attack otherwise qualifies as a covered incident.7Office of the Law Revision Counsel. 6 U.S.C. 681b – Required Reporting of Certain Cyber Incidents
These reporting requirements are not yet enforceable. CISA must complete a rulemaking process before the obligations kick in, and appropriations delays have pushed the final rule’s timeline back. As of early 2026, CISA has published a proposed rule but not a final one, so no entity is currently required to submit reports under CIRCIA.8Cybersecurity and Infrastructure Security Agency. Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) CISA encourages voluntary reporting in the meantime.
The proposed rule defines “covered entity” broadly. Any entity in a critical infrastructure sector that exceeds its industry’s Small Business Administration size standard would qualify. Even small entities can be covered if they meet sector-specific criteria, such as hospitals with 100 or more beds, community water systems serving over 3,300 people, or emergency service providers serving populations of 50,000 or more.9Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements
TSA Directives for Pipelines and Rail
Some sectors already face binding cybersecurity requirements. The Transportation Security Administration has issued security directives for hazardous liquid and natural gas pipeline operators requiring them to designate a cybersecurity coordinator available to TSA and CISA around the clock, report cyber incidents to CISA within 72 hours, complete vulnerability assessments against TSA’s pipeline security guidelines, and develop cybersecurity incident response plans.10Transportation Security Administration. Security Directive Pipeline-2021-01G – Enhancing Pipeline Cybersecurity
TSA has imposed parallel requirements on freight railroad carriers, including the same 72-hour incident reporting window, mandatory cybersecurity coordinators, annual exercises to test incident response plans, and vulnerability assessments with remediation timelines.11Transportation Security Administration. Security Directive 1580-21-01E – Rail Cybersecurity These directives are conditions of operating in a TSA-regulated space, not voluntary guidelines.
Water Systems: Mandatory Risk Assessments
Community water systems serving more than 3,300 people must conduct risk and resilience assessments under Section 1433 of the Safe Drinking Water Act. These assessments must evaluate vulnerabilities across the entire system, including electronic and automated control systems. Within six months of completing the assessment, each system must prepare or update an emergency response plan that specifically addresses both physical security and cybersecurity.12Environmental Protection Agency. AWIA Section 2013/SDWA Section 1433 – Risk and Resilience Assessments and Emergency Response Plans Unlike CIRCIA, this requirement is already fully in effect.
Chemical Sector: A Current Gap
The Chemical Facility Anti-Terrorism Standards (CFATS) program, which required high-risk chemical facilities to submit security plans and undergo inspections, lost its statutory authority in July 2023 when Congress failed to reauthorize it. CISA can no longer enforce compliance, require chemical inventory reporting, perform security inspections, or compel facilities to implement site security plans.13Cybersecurity and Infrastructure Security Agency. Chemical Facility Anti-Terrorism Standards (CFATS) Covered Chemical Facilities Bipartisan reauthorization efforts have been introduced in multiple legislative vehicles, but as of early 2026 none has been enacted. CISA encourages chemical facilities to maintain their security measures voluntarily through its ChemLock program.
Healthcare: Voluntary Goals
The Department of Health and Human Services publishes Cybersecurity Performance Goals for the Healthcare and Public Health sector. These goals are voluntary. They divide into “essential” goals covering basic protections like multifactor authentication and email security, and “enhanced” goals addressing more advanced defenses like network segmentation and centralized log collection. HHS frames these as a floor that healthcare organizations should meet, but compliance is not currently enforceable.
Penalties Where Rules Are Binding
Once CIRCIA’s final rule takes effect, CISA will have a graduated enforcement toolkit for entities that fail to report cyber incidents or ransomware payments. CISA can issue a request for information, and if the entity doesn’t respond within 72 hours, CISA can issue a subpoena. If the entity ignores the subpoena, CISA can refer the matter to the Attorney General for civil enforcement, and a court can hold the entity in contempt. CISA can also refer noncompliant entities for suspension or debarment from government contracts. Anyone who knowingly makes a false statement in a CIRCIA report faces criminal penalties under 18 U.S.C. § 1001, including up to five years in prison.9Federal Register. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements State, local, tribal, and territorial government entities are exempt from CIRCIA enforcement.
The Energy sector faces some of the steepest penalties through a separate framework. The Federal Energy Regulatory Commission can impose civil penalties on any user, owner, or operator of the bulk-power system that violates mandatory reliability standards, including the NERC Critical Infrastructure Protection (CIP) standards. The statute requires penalties to be proportional to the seriousness of the violation.14Office of the Law Revision Counsel. 16 U.S.C. 824o – Electric Reliability In practice, FERC has set these penalties at over $1.5 million per violation per day.
Why Most of This Is Privately Owned
The federal government sets standards for these 16 sectors, but it does not own most of the systems inside them. Ownership varies enormously by sector: in energy and communications, private companies dominate; in water systems, public ownership by local governments is common. That ownership split is the central challenge of critical infrastructure protection. The federal government can set standards and share intelligence, but it cannot directly secure assets it doesn’t control. That is why the SRMA framework emphasizes collaboration with private-sector partners rather than top-down regulation, and why mechanisms like CIRCIA had to be enacted by Congress to create binding obligations on private owners.