On July 1, the Cybersecurity and Infrastructure Security Agency (CISA) published a seven-page notice in the Federal Register establishing ANCHOR-CI — a new structure that will govern how the federal government and private partners collaborate on critical infrastructure for at least the next two years.
CISA's July 1 Federal Register notice and the promise of ANCHOR-CI
The notice, titled “Establishment of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI),” sets out a new framework for public‑private councils that replace the two‑decade arrangement formerly known as the Critical Infrastructure Partnership Advisory Council (CIPAC). The document is seven pages long and lays a foundation for CISA to build a refreshed set of advisory structures intended to let private partners advise the government on cybersecurity and critical‑infrastructure issues.
Why this matters: CIPAC’s end and the immediate gap it left
When former Homeland Security Secretary Kristi Noem terminated CIPAC in March of last year, Congress and private‑sector partners objected, and a practical gap opened. The 16 sector‑coordinating councils (SCCs) that had provided a steady, confidential forum for each critical infrastructure sector lost the legal mechanism to meet with the federal government under the previous model. Without CIPAC’s exemptions, SCCs risked triggering laws CIPAC had previously exempted, and thus could not reliably provide group consensus recommendations to federal counterparts.
CISA and other entities retained some collaborative tools — for example, the Joint Cyber Defense Collaborative, the Department of Energy’s Energy Threat Analysis Center, and the National Security Agency’s Cybersecurity Collaboration Center — but none of those, the notice argues, replaced the steady, cross‑sector forums SCCs represented.
The four council types ANCHOR-CI creates
- Critical Infrastructure Sector Councils: Functionally similar to the old SCCs, but with a key procedural change: the CISA director now has authority to approve or remove any council member directly.
- Cross‑Sector Councils: Designed to tackle “current and emerging threats, interdependencies, or other issues impacting multiple critical infrastructure sectors or industries.” The notice specifically suggests these councils as the vehicle to address issues that cross traditional sector lines.
- Critical Infrastructure Industry Councils: Intended for issues that span sectors in ways that don’t map neatly to a single sector — for example, an industry‑focused Operational Technology council that brings together original equipment manufacturers, software providers, and infrastructure owners.
- Regional Coordinating Councils: Framed as a way to help state and local governments tackle regional risks; CISA offers options for how these might be organized, including tying councils to regional offices or targeting councils at geographically specific hazards.
How ANCHOR-CI aims to address cross‑sector threats — and examples cited
The notice explicitly moves away from the sector‑by‑sector lock that critics say hamstrung the older model. CISA highlights cross‑sector problems such as threats posed by unmanned aerial systems, AI, supply‑chain dependencies, and the potential to revive and expand the Space Systems Critical Infrastructure Working Group. The op‑ed supplying the notice uses a concrete example: after the campaign known as Volt Typhoon — described as a Chinese campaign that installed malicious malware in critical infrastructure — CISA could establish an Operational Technology council that unites equipment makers, software vendors, and infrastructure owners to address the operational threat.
These examples reflect a recognition in the notice: vulnerabilities in cloud services or industrial software platforms can cascade across hospitals, pipelines, manufacturers, utilities, and financial institutions simultaneously, and the old sector‑specific lens was insufficient to manage that reality.
What this means for CISA, SCCs/private critical infrastructure partners, and state and local governments
- CISA: Gains a more centralized authority over council membership and structure — the CISA director’s new power to approve or remove members is an explicit change to governance that will shape who gets a seat at the table.
- SCCs and private critical infrastructure partners: Regain a formal path to advise the federal government, but with new procedural rules and oversight; membership selection and the quality of recommendations will hinge on how CISA implements ANCHOR‑CI, addressing past shortcomings like stagnant membership and variable recommendation quality.
- State and local governments: Are offered regional coordinating councils intended to focus on geographic risks — though the notice leaves open whether CISA will tie councils to regional offices or organize them around concrete hazards such as Cascadia‑area earthquake risk, Southwest drought, or Atlantic hurricane exposure.
ANCHOR‑CI carries forward CIPAC’s core procedural advantages — the federal exemption from FACA’s public meeting and recordkeeping requirements — while reminding readers that those FACA exemptions do not exempt records from the Freedom of Information Act, a common misconception the notice addresses. Ultimately, the notice itself acknowledges that policy is only as effective as its execution: “If CISA runs ANCHOR‑CI thoughtfully and with transparency, it could become the biggest upgrade in public‑private cybersecurity collaboration work in two decades.” For at least the next two years, ANCHOR‑CI will dictate how government and industry collaborate on the protection of critical infrastructure — and the outcome will depend on how CISA wields its new authorities and how quickly the newly structured councils can produce timely, cross‑sector operational advice.




