Critical infrastructure security is the protection of the physical and digital systems, such as power, water, ports, and communications, whose loss would seriously disrupt public safety, the economy, or national security. The category is broader than any single site type. A water treatment plant, a port terminal, and a regional power substation are all critical infrastructure, and each faces a mix of physical intrusion risk and, increasingly, cyber-physical risk where an intruder’s goal is to reach a control system rather than steal physical property.
Key takeaways
- CISA designates 16 critical infrastructure sectors under Presidential Policy Directive 21, spanning energy, water, transportation, and healthcare among others.
- Each sector carries its own regulatory framework: NERC CIP-014-3 for electric substations, the ISPS Code and 33 CFR Part 105 for maritime facilities, and 10 CFR Part 73 for nuclear sites, among others.
- NDAA Section 889 restricts certain named vendors’ video and communications equipment from federally funded critical infrastructure systems.
- IEC 62443 is the standard most commonly referenced for securing the industrial control systems that sit behind a critical infrastructure site’s physical perimeter.
- Most critical infrastructure sites are large and geographically spread out, which is the structural reason staffing alone cannot cover them continuously.
How the Sectors Are Officially Defined
In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) designates 16 critical infrastructure sectors, defining them as assets, systems, and networks “so vital to the United States that their incapacitation or destruction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof,” under Presidential Policy Directive 21, part of the broader U.S. critical infrastructure protection program.
The 16 Sectors
- Chemical
- Commercial Facilities
- Communications
- Critical Manufacturing
- Dams
- Defense Industrial Base
- Emergency Services
- Energy
- Financial Services
- Food and Agriculture
- Government Facilities
- Healthcare and Public Health
- Information Technology
- Nuclear Reactors, Materials, and Waste
- Transportation Systems
- Water and Wastewater Systems
Why the Sector List Matters Operationally
Sector designation is not just a classification exercise. It generally determines which federal agency acts as the sector risk management agency, which regulatory framework applies to physical security at a given site, and in some cases which equipment vendors are permitted under federal procurement rules. A site that does not know which sector it falls under, or falls under more than one, cannot reliably determine which of the frameworks below actually apply to it.
Sector-Specific Regulatory Frameworks
Critical infrastructure security is not governed by one uniform rulebook. Each sector carries its own physical security framework, layered on top of the general CISA sector designation.
| Sector | Primary Framework | What It Covers |
|---|---|---|
| Energy (electric) | NERC CIP-014-3, CIP-006 | Substation physical security and control-center physical access |
| Water and Wastewater | America’s Water Infrastructure Act risk and resilience assessments | Utility-conducted risk and resilience self-assessment |
| Maritime and Ports | ISPS Code, 33 CFR Part 105, MTSA | Facility security plans and TWIC credentialing |
| Nuclear | 10 CFR Part 73 (NRC) | Design-basis threat and physical protection of plants and materials |
| Government and Federal Facilities | FIPS 201, NDAA Section 889 | Personnel credentialing and restricted-vendor equipment rules |
What Physical Security Looks Like at This Scale
Common Requirements
- Perimeter intrusion detection around fence lines and access points
- Access control layered with video verification, not badge access alone
- Continuous camera coverage of areas that cannot be staffed around the clock
- Audit-ready records of who and what was near a sensitive asset, and when
Why Headcount Alone Does Not Scale
Most critical infrastructure sites are large, geographically spread out, and operate with lean security staff relative to their footprint, which is exactly the condition that makes a facility depend on camera-based detection to extend what a small team can watch continuously.
Cyber-Physical Convergence
A growing share of critical infrastructure risk sits at the intersection of physical access and control-system compromise, where the physical breach is a means to an end rather than the objective itself. Reaching a substation control cabinet, a water treatment SCADA panel, or a port terminal operations room in person can bypass network-level defenses entirely. IEC 62443 is the standard most commonly referenced for securing the industrial automation and control systems behind that perimeter, and it is increasingly treated as a companion framework to physical security rather than a separate discipline, since a fence line and a firewall are now understood to be protecting the same asset from two different directions. A physical security review that stops at the fence line, without asking what a successful breach would let an intruder reach inside, leaves that convergence point unassessed.
How a Site Determines Which Frameworks Apply
Sector Risk Management Agencies
Each of the 16 CISA sectors has a designated federal Sector Risk Management Agency responsible for coordinating with operators in that sector. The Department of Energy holds that role for the energy sector, the Department of Transportation for transportation systems, and the Environmental Protection Agency for water and wastewater systems, among others. A facility operator’s first practical step in determining its obligations is usually identifying which agency, and which sector, its specific site falls under, since that determines which physical security framework applies before any equipment or staffing decision is made.
Sites That Span More Than One Sector
Some facilities do not sit neatly inside a single sector. A port terminal that also generates or distributes power on-site, for example, can face overlapping obligations from both the maritime framework and an energy-sector framework, and a site in that position generally has to satisfy both rather than choosing the less demanding one. Identifying every applicable sector, not just the most obvious one, is part of correctly scoping a site’s physical security requirements. This is also where the CISA sector designation and the more granular sector-specific frameworks in the table above serve different purposes: the sector designation establishes that a site falls under federal critical infrastructure policy at all, while the specific framework, such as NERC CIP or the ISPS Code, sets the actual physical security obligations an operator has to meet day to day.
Frequently Asked Questions
What counts as critical infrastructure?
In the United States, critical infrastructure is defined by falling within one of the 16 sectors CISA designates under Presidential Policy Directive 21: assets, systems, or networks whose incapacitation would have a debilitating effect on security, the economy, public health, or safety. The designation is sector-based, not based on a single site’s size or ownership.
Are privately owned facilities subject to critical infrastructure security rules?
Yes, in many sectors. The large majority of U.S. critical infrastructure, including most of the electric grid and many water utilities, is privately or municipally owned rather than federally owned, and sector-specific frameworks such as NERC CIP apply directly to those private and municipal operators, not only to federal government sites.
What is Presidential Policy Directive 21?
Presidential Policy Directive 21, issued in 2013, is the directive that establishes national policy on critical infrastructure security and resilience and designates the 16 sectors CISA now oversees. It is the underlying authority behind the sector list referenced throughout this page.
Do all 16 critical infrastructure sectors face the same physical security requirements?
No. Each sector operates under its own regulatory framework, for example NERC CIP for electric utilities and the ISPS Code and 33 CFR Part 105 for maritime facilities, which set different specific requirements even though all 16 sectors share the same general CISA designation. A facility manager evaluating a physical security upgrade should confirm the specific framework for their own sector rather than assuming a solution built for one sector, such as an electric substation, transfers directly to a different one, such as a water treatment plant, without adjustment.
What is the difference between critical infrastructure security and critical infrastructure protection?
The two terms are largely used interchangeably in practice, though critical infrastructure protection is the more common formal name for the overarching U.S. federal program and policy framework, while critical infrastructure security is often used to describe the physical and cyber-physical security measures applied at an individual site or sector level.
The specific security requirements differ meaningfully across these sectors. Argu’s utilities and homeland security and federal facility pages look at what those requirements mean in practice for each of those two sectors specifically, including ports among the sites utilities-style perimeter requirements commonly apply to. Equipment sourcing rules under Section 889 are covered in more detail in NDAA compliance for video and security equipment, and the perimeter detection challenges common across large, spread-out sites are covered in why perimeter intrusion detection fails in the field.
Last updated: September 2026



