PART 29—PROTECTED CRITICAL INFRASTRUCTURE INFORMATION Authority: 6 U.S.C. 671-674; Section 2222-2225 of the Homeland Security Act of 2002, Pub. L. 107-296, 116 Stat. 2135, as amended by Subtitle B of the Cybersecurity and Infrastructure Security Act of 2018, Pub. L. 115-278, 132 Stat. 4184. 5 U.S.C. 301. Source: 71 FR 52271, Sept. 1, 2006, as amended at 87 FR 77972, Dec. 21, 2022, unless otherwise noted. § 29.1 Purpose and scope. (a) Purpose of this part. (1) The acknowledgment of receipt by CISA of voluntarily submitted CII; (2) The receipt, validation, handling, storage, proper marking, and use of information as PCII; (3) The safeguarding and maintenance of the confidentiality of such information and appropriate sharing of such information with State and Local governments or government agencies pursuant to 6 U.S.C. 673(a)(1)(E); and (4) The issuance of advisories, notices, and warnings related to the protection of critical infrastructure or protected systems in such a manner to protect, as appropriate, from unauthorized disclosure the source of critical infrastructure information that forms the basis of the warning, and any information that is proprietary or business sensitive, might be used to identify the submitting person or entity, or is otherwise not appropriately in the public domain. (b) Scope. § 29.2 Definitions. For purposes of this part: Critical Infrastructure Critical Infrastructure Information or CII (1) Actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or Local law, harms interstate commerce of the United States, or threatens public health or safety; (2) The ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk-management planning, or risk audit; or (3) Any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation. CII Act CISA Department or DHS Director Executive Assistant Director Information Sharing and Analysis Organization or ISAO (1) Gathering and analyzing CII, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure and protected systems, so as to ensure the availability, integrity, and reliability thereof; (2) Communicating or disclosing CII, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of an interference, compromise, or an incapacitation problem related to critical infrastructure or protected systems; and (3) Voluntarily disseminating CII, including cybersecurity risks and incidents, to its members, Federal, State, and Local governments, or any other entities that may be of assistance in carrying out the purposes specified in paragraphs (h)(1) and (2) of this section. In the public domain Local government (1) A county, municipality, city, town, township, local public authority, school district, special district, intrastate district, council of governments (regardless of whether the council of governments is incorporated as a nonprofit corporation under State law), regional or interstate government entity, or agency or instrumentality of a Local government; (2) An Indian tribe or authorized tribal organization, or in Alaska, a Native village or Alaska Regional Native Corporation; and (3) A rural community, unincorporated town or village, or other public entity. Protected Critical Infrastructure Information or PCII PCII Program Manager PCII Program Manager's Designee Protected Critical Infrastructure Information Program Office or PCII Program Office PCII Program Officer Protected Critical Infrastructure Information Program or PCII Program Protected Critical Infrastructure Information Management System or PCIIMS Protected system Purposes of the CII Act Regulatory proceeding, State Submission Submitted in good faith Voluntary or voluntarily, i.e., (1) In the case of any action brought under the securities laws—as is defined in 15 U.S.C. 78c(a)(47)—the term “voluntary” or “voluntarily” does not include: (i) Information or statements contained in any documents or materials filed pursuant to 15 U.S.C. 78l(i) with the U.S. Securities and Exchange Commission or with federal banking regulators; or (ii) A writing that accompanied the solicitation of an offer or a sale of securities; and (2) Information or statements previously submitted to DHS in the course of a regulatory proceeding or a licensing or permitting determination are not “voluntarily submitted.” In addition, the submission of information to DHS for purposes of seeking a federal preference or benefit, including CII submitted to support an application for a DHS grant to secure critical infrastructure will be considered a voluntary submission of information. Applications for Support Anti-terrorism by Fostering Effective Technologies Act of 2002 filed pursuant to 6 U.S.C. 441 et seq., Used directly by such agency, any other Federal, State, or Local authority, or any third party, in any civil action arising under Federal or State law § 29.3 FOIA exemptions and restrictions on use of PCII. (a) Freedom of Information Act disclosure exemptions. (b) Restriction on use of PCII by regulatory agencies and other Federal, State, and Local agencies. § 29.4 PCII Program administration. (a) Cybersecurity and Infrastructure Security Agency. (b) Appointment of a PCII Program Manager. (1) Appoint a PCII Program Manager serving under the Executive Assistant Director who is responsible for the administration of the PCII Program; (2) Commit resources necessary for the effective implementation of the PCII Program; (3) Ensure that sufficient personnel, including detailees or assignees from other federal national security, homeland security, or law enforcement entities, as the Director deems appropriate, are assigned to the PCII Program to facilitate secure information sharing with appropriate authorities; and (4) Promulgate implementing directives and prepare training materials, as appropriate, for the proper treatment of PCII. (c) Appointment of PCII Program Officers. (d) Responsibilities of PCII Program Officers. (1) Oversee the handling, use, and storage of PCII; (2) Ensure the secure sharing of PCII with appropriate authorities and individuals, as set forth in § 29.1(a), and paragraph (b)(3) of this section; (3) Establish and maintain an ongoing self-inspection program including periodic review and assessment of compliance with handling, use, and storage of PCII; (4) Establish additional procedures, measures, and penalties, as necessary, to prevent unauthorized access to PCII; and (5) Ensure prompt and appropriate coordination with the PCII Program Manager regarding any request, challenge, or complaint arising out of the implementation of these regulations. (e) Protected Critical Infrastructure Information Management System or PCIIMS. § 29.5 Requirements for protection. (a) CII receives the protections of the CII Act when: (1) Such information is voluntarily submitted, directly or indirectly, to the PCII Program Office or a PCII Program Manager's Designee; (2) The information is submitted for protected use regarding the security of critical infrastructure or protected systems, analysis, warning, interdependency study, recovery, reconstitution, or other appropriate purposes including, without limitation, for the identification, analysis, prevention, preemption, disruption, defense against and/or mitigation of terrorist threats to the homeland; (3) The information is labeled with an express statement as follows: (i) Documentary submissions. (ii) Oral submissions. (A) Through an oral statement, made at the time of the oral submission or within a reasonable period of time thereafter, indicating an expectation of protection from disclosure as provided by the provisions of the CII Act; and (B) Through a written statement substantially similar to the one specified above in paragraph (a)(3)(i) of this section accompanied by a document that memorializes the nature of the oral submission initially provided to the PCII Program Office or the PCII Program Manager's Designee within a reasonable period of time after making the oral submission; or (iii) Electronic submissions. (A) Through an electronically submitted statement made within a reasonable period of time after making the electronic submission, indicating an expectation of protection from disclosure as provided by the provisions of the CII Act; or (B) Through a non-electronically submitted written statement substantially similar to the one specified in paragraph (a)(3)(i) of this section accompanied by a document that memorializes the nature of the electronic submission initially provided to the PCII Program Office or the PCII Program Manager's Designee within a reasonable period after making the electronic submission; and (4) The documentary, electronic, or oral submission is accompanied by a statement, signed by the submitting person or an authorized person on behalf of an entity identifying the submitting person or entity, containing such contact information as is considered necessary by the PCII Program Office, and certifying that the information being submitted is not customarily in the public domain. (b) Information that is not submitted to the PCII Program Office or the PCII Program Manager's Designees will not qualify for protection under the CII Act. Only the PCII Program Office or a PCII Program Manager's Designee are authorized to acknowledge receipt of information submitted for consideration of protection under the CII Act. (c) All Federal, State, and Local government entities must protect and maintain information as required by this part and by the provisions of the CII Act when that information is provided to the entity by the PCII Program Manager or a PCII Program Manager's Designee and is marked as required in § 29.6(c). (d) All submissions seeking PCII status are presumed to have been submitted in good faith until validation or a determination not to validate is made pursuant to this part. § 29.6 Acknowledgment of receipt, validation, and marking. (a) Authorized officials. (b) Presumption of protection. (c) Marking of information. (d) Acknowledgement of receipt of information. (1) Contact the submitting person or entity, within thirty calendar days of receipt of the submission of CII, by the means of delivery prescribed in procedures developed by the PCII Program Manager. In the case of oral submissions, receipt will be acknowledged in writing within thirty calendar days after receipt by the PCII Program Office or a PCII Program Manager's Designee of a written statement, certification, and documents that memorialize the oral submission, as referenced in § 29.5(a)(3)(ii); (2) Enter the appropriate data into the PCIIMS as required in § 29.4(e); and (3) Provide the submitting person or entity with a unique tracking number that will accompany the information from the time it is received by the PCII Program Office or a PCII Program Manager's Designee. (e) Validation of information. (2) If the PCII Program Office makes an initial determination that the information submitted does not meet the requirements for protection under the CII Act, the PCII Program Office will: (i) Notify the submitting person or entity of the initial determination that the information is not considered to be PCII. This notification also will, as necessary: (A) Request that the submitting person or entity complete the requirements of § 29.5(a) or further explain the nature of the information and the submitting person or entity's basis for believing the information qualifies for protection under the CII Act; (B) Advise the submitting person or entity that the PCII Program Office will review any further information provided before rendering a final determination; (C) Advise the submitting person or entity that the submission can be withdrawn at any time before a final determination is made; (D) Notify the submitting person or entity that until a final determination is made the submission will be treated as PCII; (E) Notify the submitting person or entity that any response to the notification must be received by the PCII Program Office no later than thirty calendar days after the date of the notification; and (F) Request the submitting person or entity to state whether, in the event the PCII Program Office makes a final determination that any such information is not PCII, the submitting person or entity prefers that the information be maintained without the protections of the CII Act, returned to the submitting person or entity, or destroyed. If a request for return is made, all such information will be returned to the submitting person or entity. (ii) If the information submitted has not been withdrawn by the submitting person or entity, the PCII Program Office will return the information to the submitter in accordance with the submitting person or entity's written preference and the procedures set forth in paragraph (e)(2)(i) of this section within thirty calendar days of making a final determination that the information submitted is not eligible for protections under the CII Act. If the submitting person or entity cannot be notified or the submitting person or entity's response is not received within thirty calendar days of the date of the notification as provided in paragraph (e)(2)(i) of this section, the PCII Program Office will make the initial determination final and return the information to the submitter. If return to the submitter is impractical, the PCII Program Office will destroy the information within thirty calendar days. This process is consistent with the appropriate National Archives and Records Administration-approved records disposition schedule. (f) Categorical Inclusions of Certain Types of CII as PCII. (g) Changing the status of PCII to non-PCII. § 29.7 Safeguarding of PCII. (a) Safeguarding. (b) Background checks on persons with access to PCII. (c) Use and storage. (d) Reproduction. (e) Disposal of information. (f) Transmission of information. (g) Automated Information Systems. § 29.8 Disclosure of PCII. (a) Authorization of access. (b) Federal, State, and Local government sharing. (c) Disclosure of information to Federal, State, and Local government contractors. (d) Further use or disclosure of information by State and Local governments. (2) State and Local governments may use PCII only for the purpose of protecting critical infrastructure or protected systems, or as set forth elsewhere in these rules. (e) Disclosure of information to appropriate entities or to the general public. (f) Disclosure for law enforcement purposes and communication with submitters; access by Congress, the Comptroller General, and the Inspector General; and whistleblower protection. (1) Exceptions for disclosure. (i) PCII will not, without the written consent of the person or entity submitting such information, be used or disclosed for purposes other than the purposes of the CII Act, except: (A) In furtherance of the investigation or prosecution of a criminal act by the federal government, or by a State, Local, or foreign government, when such disclosure is coordinated by a federal law enforcement official; (B) To communicate with a submitting person or an authorized person on behalf of a submitting entity, about a submittal of information by that person or entity when authorized to do so by the PCII Program Manager or a PCII Program Manager's Designee; or (C) When disclosure of the information is made by any officer or employee of the United States; (1) To either House of Congress, or to the extent of matter within its jurisdiction, any committee or subcommittee thereof, any joint committee thereof or subcommittee of any such joint committee; or (2) To the Comptroller General, or any authorized representative of the Comptroller General, in the course of the performance of the duties of the Government Accountability Office. (ii) If any officer or employee of the United States makes any disclosure pursuant to these exceptions, contemporaneous written notification must be provided to CISA through the PCII Program Manager. (2) Consistent with the authority to disclose information for any of the purposes of the CII Act, disclosure of PCII may be made, without the written consent of the person or entity submitting such information, to the DHS Office of Inspector General. (g) Responding to requests made under the Freedom of Information Act or State and Local government information access laws. (h) Ex parte communications with decision-making officials. (i) Restriction on use of PCII in civil actions. § 29.9 Investigation and reporting of violation of PCII procedures. (a) Reporting of possible violations. (b) Review and investigation of written report. (c) Notification to originator of PCII. (d) Criminal and administrative penalties. (2) In addition to the penalties set forth in paragraph (d)(1) of this section, if the PCII Program Manager determines that an entity or person who has received PCII has violated the provisions of this part or used PCII for an inappropriate purpose, the PCII Program Manager may disqualify that entity or person from future receipt of any PCII or future receipt of any sensitive homeland security information under 6 U.S.C. 482, provided, however, that any such decision by the PCII Program Manager may be appealed to the Director.