Critical Infrastructure Classification Frameworks
Critical Infrastructure Classification Frameworks
Detailed Explanation With Case Laws
1. Introduction
Critical infrastructure classification frameworks are legal and regulatory systems used by governments to identify infrastructure that is especially important for society, the economy, national security, or public safety. Examples include electricity grids, gas pipelines, oil facilities, telecommunications, water systems, transport networks, hospitals and digital infrastructure.
The purpose of classification is not simply to create a list. Once an asset or operator is classified as critical, additional duties may apply, such as security standards, risk assessments, incident reporting, emergency planning, audits and government supervision.
In energy law, classification is particularly important because failure of electricity or gas infrastructure can affect many other sectors.
2. Main Elements of Classification
A classification framework normally considers several factors:
A. Importance of the Service
The first question is whether the infrastructure provides an essential service. Electricity transmission, electricity distribution, gas supply and water supply are common examples.
B. Impact of Failure
Authorities consider what would happen if the infrastructure stopped working. Factors can include:
number of people affected;
economic damage;
geographical impact;
effect on public safety;
duration of disruption;
effect on other critical services.
The UK NIS framework, for example, considers whether an incident could have a significant effect on continuity of an essential service. (GOV.UK)
C. Interdependency
Modern infrastructure is interconnected. Electricity supports telecommunications and water systems, while telecommunications support electricity control systems. Therefore, classification frameworks increasingly consider cross-sector dependencies.
D. Cyber and Physical Risk
Classification is no longer limited to physical assets. Digital control systems, communication networks and information systems can also be critical because cyber failure may interrupt physical infrastructure.
3. European Union Framework
The European Union has developed a more structured approach through the CER Directive 2022/2557 and the NIS2 Directive 2022/2555.
The CER framework requires Member States to identify critical entities in specified sectors, taking account of national risk assessments and the importance of essential services. (EUR-Lex)
The NIS2 framework separately identifies essential and important entities. Its high-criticality sectors include energy, transport, banking, health, drinking water, wastewater and digital infrastructure. (EUR-Lex)
For energy, the framework expressly covers electricity undertakings, transmission and distribution system operators, producers, electricity market operators and certain energy-storage and demand-response participants. (EUR-Lex)
This shows a movement from classifying only physical infrastructure toward classifying operators, services, networks and digital systems together.
4. UK Framework
In the UK, the Network and Information Systems Regulations 2018 (NIS Regulations) provide a framework for protecting network and information systems supporting essential services. Energy, transport, water, health and digital infrastructure are among the sectors covered. (GOV.UK)
For the energy sector, government and Ofgem guidance identifies requirements for Operators of Essential Services (OES) and focuses on security and resilience of systems supporting essential electricity and gas services. (GOV.UK)
The UK approach therefore combines:
sector classification;
identification of essential operators;
risk-based assessment;
security obligations;
incident reporting; and
regulatory supervision.
The framework continues to develop. For example, 2026 UK policy materials propose bringing certain large load controllers into the NIS framework where they control 300 MW or more of relevant electrical load. (GOV.UK)
5. Case Laws
Hikvision USA, Inc. v FCC (D.C. Circuit, 2024)
This case is important because the court examined the FCC's use of different government definitions of critical infrastructure. The FCC relied on the Patriot Act definition, Presidential Policy Directive 21 and CISA's National Critical Functions.
The court accepted that using these sources could be reasonable, but held that the FCC's interpretation became too broad when it treated virtually anything connected to the listed sectors as critical infrastructure. The case demonstrates that regulators must provide a legally rational basis when defining the scope of critical infrastructure. (Justia Law)
Bharti Airtel Ltd. v Maharashtra Electricity Regulatory Commission (2020)
This Indian electricity-law decision illustrates the broader legal principle that regulatory classification should be based on relevant statutory criteria rather than arbitrary distinctions. The tribunal discussed Section 62(3) of the Electricity Act 2003 and emphasised rationality and consistency in electricity classification. (Indian Kanoon)
Although the case concerned consumer tariff classification rather than national critical infrastructure, its reasoning is useful when studying how electricity regulators should construct legally defensible categories.
6. Importance in Energy Law
Classification determines which infrastructure receives enhanced legal protection. A transmission network, major power station, gas pipeline or control centre may require stronger cybersecurity, physical protection, emergency planning and reporting obligations than ordinary commercial infrastructure.
However, classification must remain clear, evidence-based and proportionate. Overly broad definitions can impose unnecessary regulatory burdens, while overly narrow definitions can leave important infrastructure outside the protection system.
7. Conclusion
Critical infrastructure classification frameworks provide the legal foundation for identifying infrastructure whose failure could seriously affect society or the economy. Modern frameworks increasingly use a risk-based, service-based and interdependency-based approach rather than focusing only on physical assets.
For energy law, the major trend is toward treating electricity generation, transmission, distribution, digital control systems, storage, market operations and other interconnected services as part of a wider critical infrastructure system. The relevant case law also shows that classification should have a clear legal basis and rational connection with the risks being regulated.

comments