Full Report
As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.Key takeawaysWhile the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps. Community water systems serving 3,301 to 49,999 people, the vast majority of U.S. systems, must certify their Risk and Resilience Assessments (RRAs) by June 30, 2026, under AWIA 2013. New York has already finalized binding cybersecurity regulations for wastewater facilities, setting a regulatory template that other states are expected to follow in 2026 and 2027. Under CIRCIA, utilities will soon be legally required to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Federal grant programs (SLCGP) and liability protections have been extended through Sept. 30, 2026, but remain tied to unpredictable budget cycles while targeted cyber threats continue to rise.Navigating the new reality of water cyber regulationIn 2023, the U.S. EPA made an initial push to fold cybersecurity evaluations into state sanitary surveys. While that effort was stayed in court and subsequently withdrawn, the underlying federal statutory requirements and enforcement drivers remain fully active. Instead of relying on new survey rules, federal and state regulators are actively using existing statutory authority and technical guidance to shift water cybersecurity from voluntary recommendations to enforceable compliance deadlines.The urgency to strengthen cybersecurity for water facilities is underscored by a recent coordinated cyber attack that disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026. Utility cyber regulations and mandates moving forwardAmerica’s Water Infrastructure Act (AWIA) 2013 / Safe Drinking Water Act (SDWA) 1433 is still very much in force. Community water systems serving more than 3,300 people are legally required to certify a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP) to EPA on a five-year recertification cycle, and that cycle explicitly covers cyber threats, not just physical and natural hazards. Recertification deadlines:Systems serving 100,000-plus people: March 31, 202550,000–99,999 tier: Dec. 31, 20253,301–49,999 tier, the vast majority of U.S. water systems: June 30, 2026, with ERPs due six months after.The EPA hasn’t stopped pushing on cyber. It’s just doing it through guidance, technical assistance, and enforcement of existing authority rather than new rulemaking. In May 2024, the EPA issued an enforcement alert warning it would step up inspections tied to cybersecurity gaps found in drinking water systems. On Oct. 23, 2025, the EPA released an updated package of cyber tools: Revised Emergency Response Plan guideCybersecurity Incident Response Plan (CIRP) templateIncident-specific checklistsCybersecurity procurement checklistThese tools are designed to help utilities fold cybersecurity directly into the RRA/ERP process they’re already required to complete.States are stepping in where EPA stepped backWith the EPA’s national sanitary-survey mandate dead, states have started writing their own cybersecurity rules for water systems. New York is the clearest example: In March 2026, the New York State Department of Environmental Conservation finalized amendments to six New York Codes, Rules and Regulations (NYCRR) Parts 616, 650 and 750, adding binding cybersecurity regulations for wastewater treatment facilities, including mandatory incident reporting and access-control requirements built around EPA’s own cybersecurity guidance, incorporated into the rule by reference. Reporting requirements took effect March 26, 2026.It’s a template other states are watching closely. Expect more state environmental and public utility regulators to follow New York’s lead in 2026 and 2027, particularly for wastewater systems, which (unlike drinking water) aren’t covered by AWIA and have largely operated without any federal cyber requirement at all.Incident reporting is coming, whether or not utilities are readyThe U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require covered entities, including water and wastewater utilities, to report significant cyber incidents to CISA within 72 hours from the time the organization reasonably believes the incident has occurred, and report ransom payments within 24 hours of disbursement. Updated rules are expected to be finalized later in 2026. Utilities that wait for the rule to be finalized before building an incident response and reporting process will be scrambling; the smarter move is treating CIRCIA as if it is already in effect operationally.Utility funding and information-sharing protections are back, for nowTwo other pieces of the federal picture utilities lean on lapsed and were restored, but neither is fully settled:The State and Local Cybersecurity Grant Program (SLCGP), which many states use to help fund cybersecurity work at smaller water systems, expired Sept. 30, 2025, along with the Cybersecurity Information Sharing Act of 2015 (CISA 2015), the law that gives utilities liability protection when they share threat intelligence with the Cybersecurity and Infrastructure Security Agency (CISA) and peers. Both were reinstated Nov. 12, 2025, as part of the deal to end the government shutdown, lapsed again briefly, and were most recently extended through Sept. 30, 2026, under the Consolidated Appropriations Act, 2026. Utilities relying on SLCGP dollars or CISA information-sharing protections should treat this as a program to watch, not a permanent fixture, and should plan cyber investments so they aren’t solely dependent on a grant cycle that keeps landing on the continuing-resolution chopping block.The Drinking Water and Clean Water State Revolving Funds still carry the additional $11.7 billion each provided by the Bipartisan Infrastructure Law, and the EPA continues to explicitly encourage states to use that funding for cybersecurity resilience projects. New competitive grant programs, like the EPA’s Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program, have also opened additional funding paths specifically for cyber-related hazard mitigation.The threat picture hasn’t waited for policy to catch upThe U.S. Government Accountability Office’s (GAO) 2024 review found nearly 170,000 U.S. water systems face cyber risk, and are increasingly automated. An EPA Inspector General report identified critical- or high-severity vulnerabilities at 97 drinking water systems serving 27 million people, meanwhile Iranian-affiliated actors have continued targeting U.S. water infrastructure, including this reported breach claim against a California water utility earlier this year. Recent malicious activity also includes the coordinated cyberattack on Minnesota water utilities, as detailed in our latest blog post Coordinated cyberattack on Minnesota water utilities: What you need to know. The pattern since 2023 has kept on rising while the regulatory framework caught up.How Tenable can helpWhether a utility’s driver is an RRA/ERP recertification deadline, a state mandate like New York’s, CIRCIA readiness, or simply defending against an increasingly aggressive threat landscape, the underlying work is the same: know what’s on the network, know what’s vulnerable, and be able to prove it.Tenable One OT Exposure gives water and wastewater utilities:Deep visibility across converged IT/OT environments by replacing the spreadsheet-based inventories EPA and state auditors increasingly ask utilities to move past, and giving utilities the documented OT/IT asset baseline that RRAs, state cyber rules, and CIRCIA readiness all assume exists.Vulnerability management purpose-built for OT/ICS via Tenable’s proprietary hybrid discovery approach, including passive network monitoring and Safe Active Query capabilities to identify and prioritize exposed ports, default credentials, and outdated firmware that inspectors look for.Continuous threat detection and monitoring through policy, anomaly, and signature-based detection tuned to OT protocols, giving utilities the evidence base (not just a policy on paper) that EPA’s updated guidance and state regulators now ask for.Documentation utilities can hand to an auditor or regulator, including configuration change tracking, centralized log storage, and network topology documentation that maps directly to RRA, ERP, and CIRCIA reporting requirements.The City of Raleigh, for example, uses Tenable One OT Exposure to spend less time chasing asset inventory manually and more time investigating real threats and remediating vulnerabilities across its water systems.Tenable is recognized as a leader in industrial control systems security and trusted by more than 40,000 organizations worldwide. As the compliance landscape shifts from “encouraged” to “required,” deadline by deadline, state by state, Tenable gives water and wastewater utilities the visibility and evidence they need to stay ahead of it.Learn moreTenable OT security solutions for water utilitiesState and Local Cybersecurity Grant Program (SLCGP)City of Raleigh case studyEPA cybersecurity for the water sector
Analysis Summary
# Regulation/Compliance: Cybersecurity Mandates for Water and Wastewater Utilities
## Overview
This regulatory landscape covers the transitioning requirements for U.S. water and wastewater infrastructure, moving from voluntary guidance to enforceable federal and state mandates. It encompasses drinking water risk assessments, mandatory incident reporting, and emerging state-level regulations for wastewater facilities.
## Key Details
- **Issuing Authority:** U.S. EPA (Environmental Protection Agency), CISA (Cybersecurity and Infrastructure Security Agency), and State Agencies (e.g., NY DEC).
- **Effective Date:** Multiple rolling deadlines (2025–2026).
- **Jurisdiction:** United States (Federal and specific states like New York).
- **Status:** Finalized and In Effect (AWIA/SDWA), Proposed/Rules Pending (CIRCIA).
## Requirements
### Mandatory Requirements
1. **Risk and Resilience Assessment (RRA):** Systems must assess cyber threats and automate asset inventories.
2. **Emergency Response Plan (ERP):** Systems must update plans to include cyber-specific response actions.
3. **Certification:** Formal legal certification of RRAs and ERPs to the EPA every five years.
4. **Incident Reporting (CIRCIA):** Reporting significant cyber incidents within 72 hours and ransom payments within 24 hours.
5. **State-Specific Mandates (NY):** Hard requirements for wastewater incident reporting and access controls.
### Recommended Practices
1. **Tool Adoption:** Utilizing EPA’s Cybersecurity Incident Response Plan (CIRP) templates and procurement checklists.
2. **Grant Utilization:** Applying for SLCGP and BIL funds for resilience projects.
3. **Continuous Monitoring:** Moving beyond static spreadsheets to automated OT/IT asset discovery.
## Affected Organizations
- **Industries:** Community Water Systems (CWS) and Wastewater Treatment Facilities.
- **Organization Size:** Systems serving >3,300 people (under AWIA).
- **Geographic Scope:** National (USA), with intensified requirements in New York.
## Compliance Timeline
- **March 31, 2025:** RRA Recertification for systems serving >100,000 people.
- **December 31, 2025:** RRA Recertification for systems serving 50,000–99,999 people.
- **March 26, 2026:** New York mandatory wastewater reporting takes effect.
- **June 30, 2026:** RRA Recertification for systems serving 3,301–49,999 people.
- **September 30, 2026:** Expiration of current SLCGP funding and CISA liability protections.
- **Late 2026:** Expected finalization of CIRCIA reporting rules.
## Implementation Guidance
### Assessment Phase
- Identify all IT/OT converged assets and identify "cyber gaps" using EPA technical guidance.
### Implementation Phase
- Develop/Update RRA to include cyber-physical risks; integrate EPA’s Oct 2025 cyber tool package into ERPs.
### Validation Phase
- Submit formal certification to the EPA; retain documentation (configuration logs, network topology) for potential inspections.
## Technical Requirements
- **Asset Inventory:** Documented baseline of OT/IT assets.
- **Access Control:** Mandatory controls for wastewater (NY model).
- **Vulnerability Management:** Identification of exposed ports, default credentials, and outdated firmware.
- **Audit Trails:** Centralized log storage and configuration change tracking for regulatory inspection.
## Penalties & Enforcement
- **Fines:** Potential for administrative orders and civil penalties under SDWA Section 1433.
- **Other Consequences:** Loss of liability protections for non-sharing; disqualification from grant funding.
- **Enforcement:** EPA "Enforcement Alerts" signal increased on-site inspections specifically targeting cybersecurity gaps.
## Related Standards
- **AWIA 2013 / SDWA 1433:** The statutory backbone for drinking water assessments.
- **CIRCIA:** The federal framework for cross-sector incident reporting.
- **NIST/EPA Guidance:** State rules (like NY) are incorporating EPA technical guidance by reference.
## Resources
- **Official Documentation:** epa[.]gov/waterresilience
- **Guidance Documents:** EPA Revised ERP Guide; Cybersecurity Incident Response Plan (CIRP) Template.
- **Tools:** Tenable One OT Exposure (for asset inventory and vulnerability management).
## Practical Recommendations
- **Avoid "Compliance Scrambling":** Treat CIRCIA reporting timelines as operational requirements today, even before the final 2026 deadline.
- **Monitor Funding Cycles:** SLCGP and BIL funds are tied to unpredictable budget cycles; prioritize high-impact cyber investments before the Sept 2026 cliff.
- **Automate Inventory:** Move away from manual spreadsheets to automated OT monitoring to meet the evidentiary standards of new EPA inspections.