What Counts as Critical Infrastructure? A Primer on the 16 CISA Sectors
The U.S. government organizes critical infrastructure into 16 distinct sectors, each with its own federal coordinating agency. Here is what each one actually covers, in plain language, with examples.
Critical infrastructure is the term the U.S. government uses for the physical and virtual systems so vital that losing them would seriously damage national security, the economy, public health, or public safety. That definition traces back to the USA PATRIOT Act and was formalized in February 2013 under Presidential Policy Directive 21 (PPD-21), which also did the actual sorting: it split the country's critical infrastructure into 16 distinct sectors, each covering a different slice of the economy, from the electric grid to hospitals to the networks the internet runs on.
PPD-21 was formally superseded by a White House National Security Memorandum in April 2024, but the Cybersecurity and Infrastructure Security Agency (CISA), the federal agency that coordinates critical infrastructure protection, still organizes its own sector pages around that original 16-sector structure. Each sector is assigned a Sector Risk Management Agency (SRMA): the federal department responsible for day-to-day coordination with that sector's owners and operators. The Department of Energy is the SRMA for Energy, the Department of the Treasury for Financial Services, and so on down the list below. One detail that surprises a lot of newcomers to this field: the federal government doesn't own or run most of this infrastructure, private companies do, which is exactly why SRMAs exist. Protecting critical infrastructure mostly means government agencies and private owner-operators coordinating with each other, not the government directly controlling the assets.
Four of the 16, Energy, Water, Transportation, and Communications, are singled out by CISA as "lifeline" sectors, because the other twelve depend on them just to function day to day. A hospital cannot run without electricity, water, and a working data connection, no matter how well its own sector is protected. That kind of dependency is why a failure in one sector rarely stays contained to that sector. What follows is a plain-language walkthrough of all 16, with a short definition and a few concrete examples for each, listed in the order CISA itself lists them.
Chemical Sector
The Chemical Sector covers the facilities that manufacture, store, and distribute chemicals, spanning basic industrial chemicals and agricultural chemicals like fertilizers and pesticides through specialty chemicals and pharmaceuticals. The Department of Homeland Security (DHS), through CISA, serves as the sector's SRMA. Examples include chemical manufacturing plants, chemical distributors and storage terminals, and fertilizer producers. Because many of the chemicals involved are also inputs to other sectors, agriculture and healthcare especially, disruptions here tend to ripple outward.
Commercial Facilities Sector
The Commercial Facilities Sector covers sites built to draw large numbers of people for shopping, entertainment, lodging, or business, organized by CISA into eight subsectors: Entertainment and Media, Gaming, Lodging, Outdoor Events, Public Assembly, Real Estate, Retail, and Sports Leagues. DHS/CISA is the sector's SRMA. Examples include shopping malls, casinos, hotels, and sports stadiums. Unlike most of the other 15 sectors, it is defined less by a shared physical system, like a grid or a network, and more by a shared risk profile: large, publicly accessible crowds.
Communications Sector
The Communications Sector covers the infrastructure that carries voice, data, and video: wireline and wireless networks, satellite systems, cable systems, and broadcasting. CISA is the sector's SRMA. Examples include telecommunications carriers, internet service providers, satellite operators, and broadcast television and radio networks. It's one of the four lifeline sectors, since nearly every other sector, from emergency dispatch to financial transactions, depends on some form of communications infrastructure staying up.
Critical Manufacturing Sector
The Critical Manufacturing Sector covers industries that produce goods essential to other critical infrastructure sectors, organized around four industry groups: primary metals, machinery manufacturing, electrical equipment and components, and transportation equipment. CISA is the sector's SRMA. Examples include steel and aluminum producers, industrial machinery manufacturers, and motor vehicle and aerospace parts manufacturers. It exists as its own sector because so much of what the other 15 sectors run on, transformers, turbines, vehicles, specialized equipment, gets built here first.
Dams Sector
The Dams Sector covers dam projects, navigation locks, levees, hurricane barriers, and other water retention or control facilities. DHS/CISA is the sector's SRMA. Examples include hydroelectric dams, flood-control levees, and navigation locks on major waterways. Many dams serve more than one function at once, generating power, supplying water, and controlling flooding, which is part of why a single facility can matter to several sectors simultaneously.
Defense Industrial Base Sector
The Defense Industrial Base Sector covers the worldwide network of companies that research, design, produce, deliver, and maintain military weapons systems and equipment for the U.S. armed forces. The Department of Defense (DoD) is the sector's SRMA, the only sector where DoD itself holds that role directly. Examples include defense contractors, shipyards building naval vessels, and manufacturers of military aircraft and munitions.
Emergency Services Sector
The Emergency Services Sector covers the people and systems that respond to emergencies: law enforcement, fire and rescue, emergency medical services, emergency management, and public works. DHS/CISA is the sector's SRMA. Examples include police and fire departments, 911 call centers, and emergency operations centers. It's one of the sectors the other 15 lean on hardest during an actual crisis, since it's the response mechanism for failures happening elsewhere.
Energy Sector
The Energy Sector covers the production, refining, storage, and distribution of electricity, oil, and natural gas. The Department of Energy (DOE) is the sector's SRMA. Examples include power plants, electric transmission and distribution utilities, oil refineries, and natural gas pipelines and storage facilities. It's one of the four lifeline sectors: electricity in particular underpins the operation of nearly every other sector on this list, which is a large part of why it draws outsized attention in critical infrastructure security discussions.
Financial Services Sector
The Financial Services Sector covers depository institutions, investment product providers, insurance companies, and the financial utilities (payment, clearing, and settlement systems) that support them. The Department of the Treasury is the sector's SRMA. Examples include commercial banks, stock exchanges, payment processors, and insurance carriers. Because so much of the sector's actual value is data and transactions rather than physical assets, its risk profile skews more toward cyber than most of the other sectors on this list.
Food and Agriculture Sector
The Food and Agriculture Sector covers farms, food and beverage manufacturing, processing and storage, and the restaurants and retailers that get food to consumers. It's jointly overseen by the U.S. Department of Agriculture (USDA) and the Department of Health and Human Services (HHS), acting through the Food and Drug Administration (FDA), which split responsibility roughly along farm-versus-processed-food lines. Examples include commercial farms, meat and poultry processing plants, and food distribution centers.
Government Facilities Sector
The Government Facilities Sector covers buildings owned or leased by federal, state, local, and tribal governments, along with the Election Infrastructure Subsector added in 2017. CISA's current site labels it the "Government Services and Facilities Sector." DHS/CISA and the General Services Administration (GSA) jointly serve as SRMA. Examples include federal office buildings and courthouses, national laboratories, and state and local election systems: voter registration databases, polling places, and vote-tabulation equipment.
Healthcare and Public Health Sector
The Healthcare and Public Health Sector covers direct patient care, health insurance and payer systems, pharmaceuticals, medical laboratories, and the blood supply chain. HHS is the sector's SRMA. Examples include hospitals and health systems, health insurers, pharmaceutical manufacturers, and diagnostic laboratories. It's also often framed as the sector that protects every other sector from a specific class of threat, infectious disease and public health emergencies, not just direct attacks on healthcare facilities themselves.
Information Technology Sector
The Information Technology Sector covers the hardware, software, systems, and services that keep information technology, including the internet, functioning: domain name system operators, cloud computing providers, and enterprise software vendors among them. CISA is the sector's SRMA. Examples include cloud service providers, software companies, data centers, and internet domain registries. It overlaps closely with the Communications Sector, but where Communications is mostly the physical and network layer moving data around, Information Technology is more the systems and software running on top of it.
Nuclear Reactors, Materials, and Waste Sector
The Nuclear Reactors, Materials, and Waste Sector covers commercial nuclear power plants, research and test reactors, the nuclear fuel cycle, and the radioactive materials used in medical, industrial, and academic settings. CISA is the sector's SRMA. Examples include commercial nuclear power plants, university research reactors, and facilities that produce medical radioisotopes. It's a narrower sector than most on this list, but the consequences of a serious failure here are severe enough that it's treated as its own dedicated category rather than folded into Energy.
Transportation Systems Sector
The Transportation Systems Sector covers seven modes: aviation, highway and motor carrier, maritime, mass transit and passenger rail, freight rail, pipeline systems, and postal and shipping. DHS/CISA and the Department of Transportation (DOT) jointly serve as SRMA. Examples include airports and air traffic control, ports and shipping terminals, and mass transit and freight rail systems. It's the fourth lifeline sector, since the goods, fuel, and people moving through the other sectors mostly move through this one first.
Water and Wastewater Systems Sector
The Water and Wastewater Systems Sector covers the drinking water and wastewater treatment systems that supply, treat, and return water safely. The Environmental Protection Agency (EPA) is the sector's SRMA. Examples include municipal drinking water treatment plants, wastewater treatment facilities, and the pipe networks connecting them to homes and businesses. It's the last of the four lifeline sectors: alongside energy, transportation, and communications, water is a baseline dependency almost every other sector, and everyday life generally, can't function without.
The Sectors Don’t Operate in Isolation
These 16 categories are useful for assigning federal responsibility and organizing security programs, but real incidents rarely respect the boundaries between them. A single failure, a cyberattack on a pipeline, a storm that takes down transmission lines, a compromised software vendor, routinely crosses sector lines: the 2021 Colonial Pipeline ransomware incident, for instance, disrupted Energy Sector operations badly enough to cause regional fuel shortages that touched Transportation Systems within days.
Understanding the 16 sectors is really the starting point for understanding critical infrastructure risk, not the end of it. For most of these sectors, the more useful follow-up question is how much of their day-to-day operation runs on operational technology (OT) and industrial control systems, and how automation and AI are changing what that operation looks like.
Sources
- CISA, "Critical Infrastructure Sectors"
- PPD-21, full text (whitehouse.gov archive)
- CISA, "Sector Risk Management Agencies"
- CISA, "What is Critical Infrastructure?" fact sheet (PDF)
- CISA, Chemical Sector
- CISA, Commercial Facilities Sector
- CISA, Communications Sector
- CISA, Critical Manufacturing Sector
- CISA, Dams Sector
- CISA, Defense Industrial Base Sector
- CISA, Emergency Services Sector
- CISA, Energy Sector
- CISA, Financial Services Sector
- CISA, Food and Agriculture Sector
- CISA, Government Services and Facilities Sector
- CISA, Healthcare and Public Health Sector
- CISA, Information Technology Sector
- CISA, Nuclear Reactors, Materials, and Waste Sector
- CISA, Transportation Systems Sector
- CISA, Water and Wastewater Sector