What water utilities need to know about cybersecurity compliance
As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.
Key takeaways
- While the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps.
- Community water systems serving 3,301 to 49,999 people, the vast majority of U.S. systems, must certify their Risk and Resilience Assessments (RRAs) by June 30, 2026, under AWIA 2013.
- New York has already finalized binding cybersecurity regulations for wastewater facilities, setting a regulatory template that other states are expected to follow in 2026 and 2027.
- Under CIRCIA, utilities will soon be legally required to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
- Federal grant programs (SLCGP) and liability protections have been extended through Sept. 30, 2026, but remain tied to unpredictable budget cycles while targeted cyber threats continue to rise.
Navigating the new reality of water cyber regulation
In 2023, the U.S. EPA made an initial push to fold cybersecurity evaluations into state sanitary surveys. While that effort was stayed in court and subsequently withdrawn, the underlying federal statutory requirements and enforcement drivers remain fully active. Instead of relying on new survey rules, federal and state regulators are actively using existing statutory authority and technical guidance to shift water cybersecurity from voluntary recommendations to enforceable compliance deadlines.
The urgency to strengthen cybersecurity for water facilities is underscored by a recent coordinated cyber attack that disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026.
Utility cyber regulations and mandates moving forward
America’s Water Infrastructure Act (AWIA) 2013 / Safe Drinking Water Act (SDWA) 1433 is still very much in force.
Community water systems serving more than 3,300 people are legally required to certify a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP) to EPA on a five-year recertification cycle, and that cycle explicitly covers cyber threats, not just physical and natural hazards.
Recertification deadlines:
- Systems serving 100,000-plus people: March 31, 2025
- 50,000–99,999 tier: Dec. 31, 2025
- 3,301–49,999 tier, the vast majority of U.S. water systems: June 30, 2026, with ERPs due six months after.
The EPA hasn’t stopped pushing on cyber. It’s just doing it through guidance, technical assistance, and enforcement of existing authority rather than new rulemaking.
In May 2024, the EPA issued an enforcement alert warning it would step up inspections tied to cybersecurity gaps found in drinking water systems.
On Oct. 23, 2025, the EPA released an updated package of cyber tools:
- Revised Emergency Response Plan guide
- Cybersecurity Incident Response Plan (CIRP) template
- Incident-specific checklists
- Cybersecurity procurement checklist
These tools are designed to help utilities fold cybersecurity directly into the RRA/ERP process they’re already required to complete.
States are stepping in where EPA stepped back
With the EPA’s national sanitary-survey mandate dead, states have started writing their own cybersecurity rules for water systems. New York is the clearest example: In March 2026, the New York State Department of Environmental Conservation finalized amendments to six New York Codes, Rules and Regulations (NYCRR) Parts 616, 650 and 750, adding binding cybersecurity regulations for wastewater treatment facilities, including mandatory incident reporting and access-control requirements built around EPA’s own cybersecurity guidance, incorporated into the rule by reference. Reporting requirements took effect March 26, 2026.
It’s a template other states are watching closely. Expect more state environmental and public utility regulators to follow New York’s lead in 2026 and 2027, particularly for wastewater systems, which (unlike drinking water) aren’t covered by AWIA and have largely operated without any federal cyber requirement at all.
Incident reporting is coming, whether or not utilities are ready
The U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require covered entities, including water and wastewater utilities, to report significant cyber incidents to CISA within 72 hours from the time the organization reasonably believes the incident has occurred, and report ransom payments within 24 hours of disbursement. Updated rules are expected to be finalized later in 2026.
Utilities that wait for the rule to be finalized before building an incident response and reporting process will be scrambling; the smarter move is treating CIRCIA as if it is already in effect operationally.
Utility funding and information-sharing protections are back, for now
Two other pieces of the federal picture utilities lean on lapsed and were restored, but neither is fully settled:
- The State and Local Cybersecurity Grant Program (SLCGP), which many states use to help fund cybersecurity work at smaller water systems, expired Sept. 30, 2025, along with the Cybersecurity Information Sharing Act of 2015 (CISA 2015), the law that gives utilities liability protection when they share threat intelligence with the Cybersecurity and Infrastructure Security Agency (CISA) and peers. Both were reinstated Nov. 12, 2025, as part of the deal to end the government shutdown, lapsed again briefly, and were most recently extended through Sept. 30, 2026, under the Consolidated Appropriations Act, 2026.
- Utilities relying on SLCGP dollars or CISA information-sharing protections should treat this as a program to watch, not a permanent fixture, and should plan cyber investments so they aren’t solely dependent on a grant cycle that keeps landing on the continuing-resolution chopping block.
- The Drinking Water and Clean Water State Revolving Funds still carry the additional $11.7 billion each provided by the Bipartisan Infrastructure Law, and the EPA continues to explicitly encourage states to use that funding for cybersecurity resilience projects. New competitive grant programs, like the EPA’s Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program, have also opened additional funding paths specifically for cyber-related hazard mitigation.
The threat picture hasn’t waited for policy to catch up
- The U.S. Government Accountability Office’s (GAO) 2024 review found nearly 170,000 U.S. water systems face cyber risk, and are increasingly automated.
- An EPA Inspector General report identified critical- or high-severity vulnerabilities at 97 drinking water systems serving 27 million people, meanwhile Iranian-affiliated actors have continued targeting U.S. water infrastructure, including this reported breach claim against a California water utility earlier this year.
- Recent malicious activity also includes the coordinated cyberattack on Minnesota water utilities, as detailed in our latest blog post Coordinated cyberattack on Minnesota water utilities: What you need to know.
The pattern since 2023 has kept on rising while the regulatory framework caught up.
How Tenable can help
Whether a utility’s driver is an RRA/ERP recertification deadline, a state mandate like New York’s, CIRCIA readiness, or simply defending against an increasingly aggressive threat landscape, the underlying work is the same: know what’s on the network, know what’s vulnerable, and be able to prove it.
Tenable One OT Exposure gives water and wastewater utilities:
- Deep visibility across converged IT/OT environments by replacing the spreadsheet-based inventories EPA and state auditors increasingly ask utilities to move past, and giving utilities the documented OT/IT asset baseline that RRAs, state cyber rules, and CIRCIA readiness all assume exists.
- Vulnerability management purpose-built for OT/ICS via Tenable’s proprietary hybrid discovery approach, including passive network monitoring and Safe Active Query capabilities to identify and prioritize exposed ports, default credentials, and outdated firmware that inspectors look for.
- Continuous threat detection and monitoring through policy, anomaly, and signature-based detection tuned to OT protocols, giving utilities the evidence base (not just a policy on paper) that EPA’s updated guidance and state regulators now ask for.
- Documentation utilities can hand to an auditor or regulator, including configuration change tracking, centralized log storage, and network topology documentation that maps directly to RRA, ERP, and CIRCIA reporting requirements.
The City of Raleigh, for example, uses Tenable One OT Exposure to spend less time chasing asset inventory manually and more time investigating real threats and remediating vulnerabilities across its water systems.
Tenable is recognized as a leader in industrial control systems security and trusted by more than 40,000 organizations worldwide. As the compliance landscape shifts from “encouraged” to “required,” deadline by deadline, state by state, Tenable gives water and wastewater utilities the visibility and evidence they need to stay ahead of it.
Learn more
Learn more
- OT Security
- SCADA
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success