Skip to main content
Category: Foundational Concepts

Critical Activities

Also known as: Critical Activity, Critical Path Activities
Simply put

A critical activity is a scheduled task that sits on the critical path of a project, meaning it has no slack time to spare. If it is delayed, the entire project's finish date slips by the same amount. Together, all critical activities form the sequence that determines when a project can be completed.

Formal definition

In project scheduling and the Critical Path Method (CPM), a critical activity is a schedule activity lying on the critical path and carrying zero total float, such that any change to its duration shifts the overall project duration correspondingly. The critical path is the longest sequence of dependent activities that must be completed on time for the project to finish by its planned date. This entry covers the project-scheduling sense of the term only; it does not address the separate business-continuity and operational-resilience usage, in which 'critical activities' (or critical/essential functions) denote organizational processes whose disruption would cause unacceptable harm, and which are identified through a Business Impact Analysis and associated with recovery objectives. Practitioners should confirm which domain sense applies in a given context, as the two meanings are unrelated despite the shared phrasing.

Why it matters

In project scheduling, critical activities are the tasks that determine whether a project finishes on time. Because a critical activity carries zero total float, any delay to it pushes the project's completion date out by the same amount, with no buffer to absorb the slip. This makes the set of critical activities the primary focus for schedule managers: understanding which tasks lie on the critical path tells a team where delays will do the most damage and where added attention, resources, or expediting will actually move the finish date.

For third-party and supply chain contexts, this distinction matters because externally delivered work packages, vendor milestones, or supplier deliverables frequently sit on a project's critical path. When a supplier's task has no float, a slip in that supplier's performance directly delays the whole project, which is why schedule-level visibility into vendor-dependent critical activities is often as important as the contract terms themselves. Activities with float, by contrast, can typically tolerate some delay without affecting the end date.

A note of caution is warranted: the phrase "critical activities" is also used in an entirely separate business-continuity and operational-resilience sense to mean essential organizational functions identified through a Business Impact Analysis. That usage is unrelated to the project-scheduling meaning covered here, and guidance from one domain should not be applied to the other. Practitioners should confirm which sense is intended in a given document before acting on it.

Who it's relevant to

Project and program managers
Those responsible for delivering projects on schedule use critical activities to focus attention where delays translate directly into a slipped finish date. Identifying the critical path helps prioritize resources, sequence work, and decide where expediting or added oversight will actually protect the completion date.
Procurement and vendor managers
When supplier deliverables or vendor milestones sit on the critical path, a delay in that third party's performance delays the whole project by the same amount. Knowing which vendor-dependent tasks carry zero float helps focus contract monitoring and escalation on the relationships that most affect schedule outcomes, as distinct from those with float to absorb minor slips.
Schedulers and planning analysts
Practitioners who build and maintain CPM schedules calculate total float to distinguish critical from non-critical activities. Because the critical path can shift as work progresses, they must keep the schedule current so that the set of critical activities reflects actual status rather than the original baseline.
Readers reconciling terminology across domains
Risk, compliance, and resilience professionals should be aware that "critical activities" also denotes essential organizational functions in the business-continuity and operational-resilience domain, a meaning unrelated to the project-scheduling sense described here. Confirming which usage a source intends prevents misapplying scheduling logic to continuity concepts, or vice versa.

Inside Critical Activities

Essential organizational functions
The processes, products, or services an organization identifies as most important to its mission, customers, or regulatory obligations. In a TPRM context, these functions frame which external dependencies matter most, but the identification is organization-specific and not universal across firms or sectors.
Business Impact Analysis (BIA) linkage
Critical activities are typically identified through a BIA, which estimates the consequences of disruption over time. The BIA informs which suppliers support critical activities; however, a BIA is a point-in-time exercise and can become stale as the business and its supplier base change.
Supplier and dependency mapping
The exercise of tracing which third parties support each critical activity. This commonly captures direct (third-party) relationships and, where visibility allows, fourth-party or Nth-party dependencies. Visibility beyond the first tier is often limited, so maps may understate concentration and single-source exposures.
Recovery and continuity objectives
Targets such as recovery time and recovery point expectations, and estimates of maximum tolerable disruption, that organizations may set for critical activities. These are planning parameters, not guarantees; a supplier's stated objective is an attestation unless independently verified through testing.
Criticality tiering
The classification of activities (and by extension the suppliers supporting them) by importance, which drives the depth and frequency of due diligence and ongoing monitoring. Tiering criteria vary between programs and should be documented and periodically revisited.
Scope boundaries
Identifying a critical activity addresses which functions to prioritize for resilience; it does not by itself assess information security, financial, geopolitical, or ESG risk in the supporting suppliers, each of which typically requires separate evaluation.

Common questions

Answers to the questions practitioners most commonly ask about Critical Activities.

In a third-party or supply chain risk context, does 'critical activities' refer to tasks on a project's critical path?
No. Within third-party and supply chain risk management, 'critical activities' refers to the essential organizational functions whose disruption would have serious consequences for the enterprise, its customers, or its obligations. This is the business-continuity and operational-resilience sense of the term. It should not be confused with the project-scheduling meaning, where 'critical activities' are tasks on the critical path with zero float. The two usages come from unrelated disciplines, and applying scheduling concepts such as float or path duration to resilience analysis would be a category error. When you encounter the phrase, confirm which domain the source is working in before applying any associated guidance.
Are critical activities the same as critical suppliers?
Not directly. A critical activity is an internal function the organization must sustain, while a critical supplier is an external party. They are related but distinct: a supplier typically becomes critical because it underpins one or more critical activities. Identifying critical activities usually comes first, after which programs map which third parties support them. Treating the two as interchangeable can cause a program to over-scope some vendors and overlook others whose failure would impair an essential function, so many programs keep the activity inventory and the supplier tiering as separate but linked artifacts.
How do organizations identify which activities qualify as critical?
Many programs derive critical activities through a business impact analysis, which examines the consequences of disruption over time against factors such as customer harm, financial loss, legal or regulatory obligations, and reputational damage. Depending on the framework used, thresholds like a maximum tolerable period of disruption may inform whether an activity is deemed critical. Criticality is a judgment relative to defined tolerance criteria rather than a fixed attribute, so the resulting list should be reviewed periodically as the business changes.
How does identifying critical activities connect to third-party monitoring?
Once critical activities are defined, programs typically map the external suppliers, service providers, and business partners that support each one. This mapping helps prioritize due diligence and ongoing monitoring toward the third parties whose disruption would most affect essential functions. In many programs it also informs contractual resilience requirements and monitoring frequency by risk tier. The value of this linkage depends on visibility, which is often strong for direct third parties but weaker for fourth-party and Nth-party dependencies that also underpin the same activities.
How often should the inventory of critical activities be reviewed?
Because criticality reflects the current business model, product mix, and dependency structure, the inventory can become stale. Many programs review it on a periodic cadence and also after material changes such as reorganizations, new product lines, acquisitions, or significant shifts in supplier arrangements. A point-in-time designation carries the limitation of any snapshot: it may not reflect emerging dependencies or newly onboarded third parties until the next review.
Do regulatory expectations around critical activities apply uniformly across sectors and regions?
No. Expectations for identifying and protecting critical or important functions vary by jurisdiction and sector, and the specific terminology, thresholds, and obligations differ accordingly. Some financial and other regulated sectors set out particular requirements for identifying important business services and their supporting third parties, while other contexts leave the approach largely to the organization. Programs should map their critical-activity practices to the regimes that actually apply to them rather than assuming a single global standard governs.

Common misconceptions

'Critical activities' means the same thing in every discipline, so scheduling guidance and resilience guidance are interchangeable.
The phrase has two unrelated meanings. In project scheduling it denotes zero-float tasks on the critical path; in continuity and resilience it denotes essential organizational functions. Zero-float logic does not apply to the continuity sense used in TPRM, and mixing the two leads to misapplied guidance.
Once critical activities are identified through a BIA, the list and its supplier map stay valid.
A BIA is a point-in-time exercise. Business priorities, contracts, and supplier arrangements change, so criticality designations and dependency maps can become stale and typically require periodic review.
A supplier's stated recovery objectives or continuity attestations confirm that critical activities can actually be recovered on time.
Stated objectives and self-reported attestations are not independent verification. Confidence typically comes from testing, exercises, or independent validation, and even then covers only the conditions tested.

Best practices

State clearly, in internal documentation and any shared assessments, which meaning of 'critical activities' is intended so scheduling and continuity usages are not conflated.
Derive critical activities from a documented Business Impact Analysis and revisit them on a defined cadence and after material business or supplier changes, rather than treating the list as static.
Map each critical activity to the suppliers that support it, and where feasible extend the map to fourth-party and Nth-party dependencies, while recording where visibility beyond the first tier is limited.
Use criticality tiering to set the depth and frequency of due diligence and ongoing monitoring, so that suppliers supporting the most important activities receive the most scrutiny.
Assess suppliers to critical activities across multiple risk domains (information security, financial, operational, geopolitical, and ESG) rather than assuming a single control or questionnaire covers all of them.
Corroborate supplier continuity and recovery claims through testing, exercises, or independent validation instead of relying on attestations alone, and note that recovery objectives such as recovery time expectations can vary by jurisdiction, sector, and regulatory expectation.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps