Access Control and Security Design for US Critical Infrastructure (CISA guidelines)
Access Control — ASDV Consultant

Physical security design for critical infrastructure facilities in the US — utilities, water systems, transit, energy — sits under the influence of the Cybersecurity and Infrastructure Security Agency (CISA), which publishes physical security guidance covering active-shooter, vehicle-ramming, and UAS/drone threats, alongside its broader mandate around cyber and supply-chain security. CISA's role is guidance and resource-provision more than direct regulatory enforcement of hardware choices, though funding programs (DOE grid security grants, EPA water utility grants, FTA transit grants, DHS grants) frequently attach compliance conditions, including federal supply-chain restrictions.

The most consequential of those conditions is NDAA Section 889, which restricts federal agencies — and, through flow-down clauses, many federally-funded critical infrastructure projects — from using certain named Chinese manufacturers' video surveillance and telecommunications equipment. Camera and related equipment selection has to be screened against the current restricted manufacturer list and their OEM/subsidiary relationships. CISA separately runs a "Secure by Design" pledge program manufacturers can sign onto voluntarily, increasingly used by owners as a practical vetting signal alongside mandatory Section 889 screening.

Why this matters specifically for US projects

Security design for critical infrastructure elsewhere typically centers on physical resilience without an equivalent federal supply-chain restriction regime attached to funding. In the US, a technically excellent camera or access control system can be entirely disqualified from a federally funded project if its manufacturer appears on the restricted list, verified at the specific model and supply-chain level, not just the surface brand level.

ConsiderationStandard commercial security designUS critical infrastructure design
Governing guidanceOwner requirements, insurance, local codeCISA physical security guidance layered on top, often grant-conditioned
Supply-chain restrictionsGenerally none beyond standard procurementNDAA Section 889 screening where federal funding/flow-down applies
Manufacturer vettingPerformance, warranty, support-basedPerformance plus Section 889 screening plus CISA Secure by Design pledge status
Threat scope consideredIntrusion, theft, life safetyBroader: active shooter, vehicle ramming, IED, UAS/drone threats

Practical guidance

ASDV treats federal funding/grant status as a design-input question asked at project kickoff, since it determines whether Section 889 screening is mandatory. We reference CISA's published physical security guidance as a design-quality benchmark and track manufacturer participation in the Secure by Design pledge as one vetting input.

Common mistakes

Assuming Section 889 screening only applies to direct federal agency projects, missing flow-down clauses in grant agreements; screening only the visible brand name without checking OEM manufacturing relationships; treating CISA guidance as optional reading.

Future outlook

Expect continued tightening of federal supply-chain restrictions and growing adoption of the Secure by Design pledge as a market differentiator. Any specific project should have its funding source and applicable flow-down clauses verified directly against current federal guidance.

Frequently Asked Questions

Not directly. CISA provides guidance and tools, but funding programs frequently attach compliance conditions including supply-chain restrictions such as NDAA Section 889.
No. Flow-down clauses in federal grant agreements can extend restrictions to state, municipal, or private critical infrastructure projects receiving that funding.
A voluntary manufacturer commitment to practices like eliminating default passwords, increasingly used by owners as a vendor-vetting signal alongside mandatory screening.
Active shooter incidents, vehicle ramming, IEDs, and UAS/drone threats, framing cameras, sensors, alarms, and guarding as complementary layered controls.
We confirm the funding source and flow-down clauses at kickoff, then screen equipment against the current Section 889 restricted list at the model and OEM/subsidiary level.