---
kind: "section"
citation: "6 U.S.C. § 652a"
title: "6"
title_heading: "Domestic Security"
number: "652a"
heading: "Sector Risk Management Agencies"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/6/652a"
units:
  - "Chapter 1 — Homeland Security Organization"
  - "Subchapter XVIII — Cybersecurity and Infrastructure Security Agency"
  - "Part A — Cybersecurity and Infrastructure Security"
---

# §652a. Sector Risk Management Agencies

- (a) **Definitions—** In this section:
  - (1) **Appropriate congressional committees—** The term “[appropriate congressional committees](/usc/6/650.md?p=2)” means—
    - (A) the Committee on [Homeland](/usc/6/101.md?p=1) Security and the Committee on Armed Services in the House of Representatives; and
    - (B) the Committee on [Homeland](/usc/6/101.md?p=1) Security and Governmental Affairs and the Committee on Armed Services in the Senate.
  - (2) **Critical infrastructure—** The term “[critical infrastructure](/usc/6/101.md?p=4)” has the meaning given that term in [section 5195c(e) of title 42](/usc/42/5195c.md?p=e).
  - (3) **Department—** The term “[Department](/usc/6/641.md?p=1)” means the [Department](/usc/6/641.md?p=1) of [Homeland](/usc/6/101.md?p=1) Security.
  - (4) **Director—** The term “[Director](/usc/6/650.md?p=10)” means the [Director](/usc/6/650.md?p=10) of the Cybersecurity and Infrastructure Security [Agency](/usc/6/650.md?p=1) of the [Department](/usc/6/641.md?p=1).
  - (5) **Secretary—** The term “[Secretary](/usc/6/641.md?p=3)” means the [Secretary](/usc/6/641.md?p=3) of [Homeland](/usc/6/101.md?p=1) Security.
  - (7) **1 Sector Risk Management Agency—** The term “[Sector Risk Management Agency](/usc/6/650.md?p=23)” has the meaning given the term in [section 650 of this title](/usc/6/650.md).
- (b) **Critical infrastructure sector designation—**
  - (1) **Initial review—** Not later than 180 days after January 1, 2021, the [Secretary](/usc/6/641.md?p=3), in consultation with the heads of [Sector Risk Management Agencies](/usc/6/650.md?p=23), shall—
    - (A) review the current framework for securing [critical infrastructure](/usc/6/101.md?p=4), as described in [section 652(c)(4) of this title](/usc/6/652.md?p=c-4) and Presidential Policy Directive 21; and
    - (B) submit to the President and [appropriate congressional committees](/usc/6/650.md?p=2) a report that includes—
      - (i) information relating to—
        - (I) the analysis framework or methodology used to—
          - (aa) evaluate the current framework for securing [critical infrastructure](/usc/6/101.md?p=4) referred to in [subparagraph (A)](#b-1-A); and
          - (bb) develop recommendations to—
            - (AA) revise the current list of [critical infrastructure sectors](/usc/6/601.md?p=3) designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
            - (BB) identify and designate any subsectors of such sectors;
        - (II) the data, metrics, and other information used to develop the recommendations required under [clause (ii)](#b-1-B-ii); and
      - (ii) recommendations relating to—
        - (I) revising—
          - (aa) the current framework for securing [critical infrastructure](/usc/6/101.md?p=4) referred to in [subparagraph (A)](#b-1-A);
          - (bb) the current list of [critical infrastructure sectors](/usc/6/601.md?p=3) designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
          - (cc) the identification and designation of any subsectors of such sectors; and
        - (II) any revisions to the list of designated Federal [departments](/usc/6/641.md?p=1) or [agencies](/usc/6/650.md?p=1) that serve as the [Sector Risk Management Agency](/usc/6/650.md?p=23) for a sector or subsector of such section, necessary to comply with [paragraph (3)(B)](#b-3-B).
  - (2) **Periodic evaluation by the Secretary—** At least once every five years, the [Secretary](/usc/6/641.md?p=3), in consultation with the [Director](/usc/6/650.md?p=10) and the heads of [Sector Risk Management Agencies](/usc/6/650.md?p=23), shall—
    - (A) evaluate the current list of designated [critical infrastructure sectors](/usc/6/601.md?p=3) and subsectors of such sectors and the appropriateness of [Sector Risk Management Agency](/usc/6/650.md?p=23) designations, as set forth in Presidential Policy Directive 21, any successor or related document, or policy; and
    - (B) recommend, as appropriate, to the President—
      - (i) revisions to the current list of designated [critical infrastructure sectors](/usc/6/601.md?p=3) or subsectors of such sectors; and
      - (ii) revisions to the designation of any Federal [department](/usc/6/641.md?p=1) or [agency](/usc/6/650.md?p=1) designated as the [Sector Risk Management Agency](/usc/6/650.md?p=23) for a sector or subsector of such sector.
  - (3) **Review and revision by the President—** Not later than 180 days after the [Secretary](/usc/6/641.md?p=3) submits a recommendation pursuant to paragraph [(1)](#b-1) or [(2)](#b-2), the President shall—
    - (A) review the recommendation and revise, as appropriate, the designation of a [critical infrastructure](/usc/6/101.md?p=4) sector or subsector or the designation of a [Sector Risk Management Agency](/usc/6/650.md?p=23); and
    - (B) submit to the [appropriate congressional committees](/usc/6/650.md?p=2), the Majority and Minority Leaders of the Senate, and the Speaker and Minority Leader of the House of Representatives, a report that includes—
      - (i) an explanation with respect to the basis for accepting or rejecting the recommendations of the [Secretary](/usc/6/641.md?p=3); and
      - (ii) information relating to the analysis framework, methodology, metrics, and data used to—
        - (I) evaluate the current framework for securing [critical infrastructure](/usc/6/101.md?p=4) referred to in [paragraph (1)(A)](#b-1-A); and
        - (II) develop—
          - (aa) recommendations to revise—
            - (AA) the list of [critical infrastructure sectors](/usc/6/601.md?p=3) designated pursuant to Presidential Policy Directive 21, any successor or related document, or policy; or
            - (BB) the designation of any subsectors of such sectors; and
          - (bb) the recommendations of the [Secretary](/usc/6/641.md?p=3).
  - (4) **Publication—** Any designation of [critical infrastructure sectors](/usc/6/601.md?p=3) shall be published in the Federal Register.
- (c) **Sector Risk Management Agencies—**
  - (1) **Omitted—**
  - (2) **Omitted—**
  - (3) **References—** Any reference to a Sector Specific [Agency](/usc/6/650.md?p=1) (including any permutations or conjugations thereof) in any law, regulation, map, document, record, or other paper of the [United States](/usc/6/101.md?p=19-A) shall be deemed to—
    - (A) be a reference to the [Sector Risk Management Agency](/usc/6/650.md?p=23) of the relevant [critical infrastructure](/usc/6/101.md?p=4) sector; and
    - (B) have the meaning given such term in [section 650 of this title](/usc/6/650.md).
  - (4) **Omitted—**
- (d) **Report and auditing—** Not later than two years after January 1, 2021 and every four years thereafter for 12 years, the Comptroller General of the [United States](/usc/6/101.md?p=19-A) shall submit to the Committee on [Homeland](/usc/6/101.md?p=1) Security of the House of Representatives and the Committee on [Homeland](/usc/6/101.md?p=1) Security and Governmental Affairs of the Senate a report on the effectiveness of [Sector Risk Management Agencies](/usc/6/650.md?p=23) in carrying out their responsibilities under [section 665d of this title](/usc/6/665d.md).

## Footnotes

[^1]: So in original. Probably should be “(6)”.

## Source credit

(Pub. L. 116–283, div. H, title XC, § 9002, Jan. 1, 2021, 134 Stat. 4768; Pub. L. 117–263, div. G, title LXXI, § 7143(d)(5), Dec. 23, 2022, 136 Stat. 3663.)

## Notes

### Editorial Notes

### Codification

Section was enacted as part of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 and not as part of the Homeland Security Act of 2002 which comprises this chapter.

Section is comprised of section 9002 of Pub. L. 116–283. Subsec. (c)(1) of section 9002 of Pub. L. 116–283 enacted section 665d of this title. Subsec. (c)(2) of section 9002 of Pub. L. 116–283 amended sections 195f, 321m, 651, 652, and 664 of this title. Subsec. (c)(4) of section 9002 of Pub. L. 116–283 amended the table of contents in section 1(b) of the Homeland Security Act of 2002.

### Amendments

2022—Subsec. (a)(5). Pub. L. 117–263, § 7143(d)(5)(A)(i), (ii), redesignated par. (6) as (5) and struck out former par. (5). Prior to amendment, text of par. (5) read as follows: “The term ‘information sharing and analysis organization’ has the meaning given that term in section 671(5) of this title.”

Subsec. (a)(6), (7). Pub. L. 117–263, § 7143(d)(5)(A)(ii), (iii), which redesignated par. (7) as (6) and then directed the general amendment of par. (7), was executed by making the redesignation and generally amending par. (6) as redesignated, to reflect the probable intent of Congress. As amended, such par. remained designated as (7). Prior to amendment, text of par. (7) read as follows: “The term ‘sector risk management agency’ has the meaning given the term ‘Sector-Specific Agency’ in section 651(5) of this title.”

Subsec. (c)(3)(B). Pub. L. 117–263, § 7143(d)(5)(B), which directed substitution of “given such term in section 650 of this title” for “given such term in section 651(5) of this title”, was executed by making the substitution for “give such term in section 651(5) of this title”, to reflect the probable intent of Congress.

Subsec. (d). Pub. L. 117–263, § 7143(d)(5)(C), made technical amendment to reference in original act which appears in text as reference to section 665d of this title.
