Skip to main content
Federal statuteCII Act

Critical Infrastructure Information Act of 2002

The Critical Infrastructure Information Act protects qualifying voluntarily submitted critical-infrastructure information from public disclosure and certain regulatory uses.

Last reviewedJune 28, 2026Version v1

The Critical Infrastructure Information Act protects qualifying voluntarily submitted critical-infrastructure information from public disclosure and certain regulatory uses.

In plain terms. The Critical Infrastructure Information Act protects qualifying voluntarily submitted critical-infrastructure information from public disclosure and certain regulatory uses.

Who it applies to. It applies to critical-infrastructure owners, operators, contractors, and vendors that submit Protected Critical Infrastructure Information (PCII) to the Department of Homeland Security (DHS) or handle PCII under DHS rules.

What it requires. In practice, contractors should submit information through the PCII program when protection is sought; mark and handle PCII according to DHS rules; restrict disclosure; and maintain controls when PCII is shared for homeland-security purposes.

Why it matters. For GovConCyber, the key is to translate the law into contract-performance terms without overstating the source. The page should tell readers whether the requirement affects eligibility, representations, contract performance, flowdowns, data handling, incident response, or enforcement exposure.

Citation. Critical Infrastructure Information Act of 2002, 6 U.S.C. §§ 671–674; 6 C.F.R. part 29.