Presidential Policy Directive 21, signed by President Obama on February 12, 2013, was the federal framework for protecting the country’s most vital physical and digital systems. It identified sixteen critical infrastructure sectors, assigned a lead federal agency to each, and named the Secretary of Homeland Security as the national coordinator for the whole effort. PPD-21 shaped U.S. infrastructure policy for more than a decade before being formally replaced by National Security Memorandum 22 (NSM-22) in April 2024.1The American Presidency Project. National Security Memorandum on Critical Infrastructure Security and Resilience
What PPD-21 Did
PPD-21 revoked Homeland Security Presidential Directive 7 (HSPD-7), which had governed critical infrastructure protection since December 2003.2The White House Archives. Presidential Policy Directive – Critical Infrastructure Security and Resilience By 2013, cyber threats had grown more sophisticated and sector interdependencies more complex than the older directive had anticipated. PPD-21 arrived alongside Executive Order 13636, which focused on cybersecurity and directed NIST to build what became the Cybersecurity Framework. The two documents worked as a pair, with PPD-21 handling the broader organizational structure for protecting infrastructure against all types of threats.
Its stated goals were security and resilience. Security meant reducing risks to physical and digital assets through protective measures and deterrence. Resilience meant preparing for disruptions, adapting during them, and recovering quickly afterward. The distinction matters because security alone cannot prevent every failure. Resilience keeps damage contained when something does go wrong.
The Sixteen Critical Infrastructure Sectors
PPD-21 formally designated sixteen sectors whose disruption or destruction could have a debilitating effect on national security, economic stability, or public health and safety. That definition was carried over from the USA PATRIOT Act.2The White House Archives. Presidential Policy Directive – Critical Infrastructure Security and Resilience The sectors are:
- Chemical: facilities that manufacture, store, or distribute hazardous materials.
- Commercial Facilities: stadiums, hotels, theme parks, retail centers, and entertainment complexes.
- Communications: networks and systems that carry information across the country.
- Critical Manufacturing: production of metals, machinery, electrical equipment, and other essential goods.
- Dams: water retention and flood control infrastructure.
- Defense Industrial Base: research, development, and production of military weapons systems and components.
- Emergency Services: police, fire, EMS, and public works.
- Energy: electric power generation, transmission, and fuel supply.
- Financial Services: payment processing, clearing, and settlement.
- Food and Agriculture: the safety and security of the food supply chain.
- Government Facilities: buildings and operations supporting all three branches.
- Healthcare and Public Health: hospitals, public health agencies, and essential medical services.
- Information Technology: digital infrastructure for communications, data storage, and processing.
- Nuclear Reactors, Materials, and Waste: nuclear power generation and waste storage.
- Transportation Systems: movement of people and goods by air, rail, road, and water.
- Water and Wastewater Systems: drinking water treatment and wastewater disposal.
These sixteen categories have remained unchanged through every policy update since 2013, including NSM-22 in 2024.3Congress.gov. The 2024 National Security Memorandum on Critical Infrastructure Security and Resilience The classification drives everything downstream: which federal agency is responsible for a sector, where grant money flows, and which private companies get specialized federal assistance.
Who Coordinates and Who Runs Each Sector
PPD-21 placed the Secretary of Homeland Security at the center of the framework as the National Coordinator for critical infrastructure security and resilience.2The White House Archives. Presidential Policy Directive – Critical Infrastructure Security and Resilience The Secretary issued strategic guidance, identified which assets mattered most based on risk and cascading-failure potential, and maintained the National Infrastructure Protection Plan (NIPP) that set out how the pieces fit together. In practice, the Secretary’s office was the central clearinghouse for infrastructure information across the federal government, meant to keep departments like Energy and Transportation working from the same picture rather than in isolation.
Each sector was also assigned a dedicated federal agency to serve as the day-to-day point of contact, originally called a Sector-Specific Agency under PPD-21 and later renamed Sector Risk Management Agency under NSM-22.4Cybersecurity and Infrastructure Security Agency. Sector Risk Management Agencies The assignments are:
- Department of Homeland Security: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Dams, Emergency Services, Information Technology, and Nuclear Reactors, Materials, and Waste.
- Department of Defense: Defense Industrial Base.
- Department of Energy: Energy.
- Department of the Treasury: Financial Services.
- Department of Agriculture and Department of Health and Human Services: Food and Agriculture (shared).
- Department of Homeland Security and General Services Administration: Government Facilities (shared).
- Department of Health and Human Services: Healthcare and Public Health.
- Department of Homeland Security and Department of Transportation: Transportation Systems (shared).
- Environmental Protection Agency: Water and Wastewater Systems.
DHS handles the largest share, which fits its overall coordinating role. Where responsibility is shared, agencies typically split along functional lines. For Food and Agriculture, USDA focuses on farming and production while HHS handles food safety from the public health side. These agencies provide technical assistance to private operators and state and local governments in their sectors, and during an incident they act as the bridge between private operators and the broader federal response. Because most U.S. critical infrastructure is privately owned, the model relied heavily on voluntary participation, encouraged through information sharing, grant funding, and technical expertise rather than mandates.
How Information Sharing Was Supposed to Work
One of PPD-21’s central goals was breaking down the information silos that had hampered earlier infrastructure protection efforts. The directive required a standardized framework for exchanging threat data, vulnerability assessments, and incident reports between the government and private-sector partners.2The White House Archives. Presidential Policy Directive – Critical Infrastructure Security and Resilience
The flow ran both directions. Federal intelligence agencies were to share analyzed threat data with infrastructure operators so they could adjust their defenses. Operators were to share incident reports and operational data back to the government, feeding into national risk assessments and revealing patterns no single company could see on its own. The NIPP formalized these procedures, including protections for sensitive business information and privacy safeguards.
Making it work proved harder than the directive made it sound. Private companies were often reluctant to share incident data for fear of regulatory or reputational consequences, and federal agencies sometimes could not declassify threat intelligence quickly enough to be useful. Those friction points persisted throughout PPD-21’s tenure and were among the issues NSM-22 later tried to address.
How PPD-21 Was Replaced by NSM-22
On April 30, 2024, the Biden administration issued National Security Memorandum 22, which formally rescinded and replaced PPD-21.1The American Presidency Project. National Security Memorandum on Critical Infrastructure Security and Resilience The sixteen sectors and their assigned agencies stayed the same, but NSM-22 changed the operating approach in three main ways.
First, it pushed federal agencies away from purely voluntary cooperation and toward minimum security and resilience requirements. Each Sector Risk Management Agency was directed to develop sector-specific minimum standards and to implement them using existing authorities. For over a decade under PPD-21, most sectors had operated under voluntary guidelines; NSM-22 signaled that voluntary compliance alone was not producing adequate protection.
Second, it created a category of Systemically Important Entities. The National Coordinator was directed to identify organizations whose disruption could cause nationally significant cascading failures. The list is classified, but designation affects the level of federal attention and support an organization receives. The concept acknowledged what had been obvious for years: not all critical infrastructure is equally critical.
Third, it formalized the cross-sector risk analysis PPD-21 had envisioned but never fully built out, and required a recurring National Infrastructure Risk Management Plan updated every two years and submitted to the President.
Where Things Stand Now
In January 2025, the incoming Trump administration ordered a review of all national security memoranda issued between January 2021 and January 2025, with recommendations for rescission due within 45 days.5The White House. Initial Rescissions of Harmful Executive Orders and Actions No public confirmation exists that NSM-22 has been formally rescinded, and the sixteen sector designations and SRMA assignments listed on CISA’s website remain in place.4Cybersecurity and Infrastructure Security Agency. Sector Risk Management Agencies Whether the current administration will issue its own replacement, revive PPD-21’s voluntary approach, or leave NSM-22 largely intact is unresolved. The underlying statutory authority for infrastructure protection, including the Homeland Security Act and the USA PATRIOT Act definitions both directives rely on, exists independently of any presidential memorandum and continues to apply regardless of which directive is in force.