AWIA Section 2013 requires community water systems serving more than 3,300 people to complete and certify a Risk and Resilience Assessment to the EPA, and electronic control systems (SCADA, PLCs, and their networks) are explicitly in scope, not just physical infrastructure. Systems then prepare an Emergency Response Plan and recertify on a recurring cycle.
What AWIA actually requires
America's Water Infrastructure Act (2018), Section 2013, amended Section 1433 of the Safe Drinking Water Act. Community water systems above the 3,300-person threshold must:
- Complete a Risk and Resilience Assessment covering malevolent acts and natural hazards.
- Certify completion to the EPA by the applicable deadline for their size tier.
- Prepare an Emergency Response Plan that incorporates the assessment findings.
- Recertify on a recurring basis, roughly every five years.
The cybersecurity part
The assessment is not limited to fences and pumps. It must consider the resilience of electronic, computer, or other automated systems the utility uses, which means SCADA, PLCs, HMIs, and the networks connecting them. In practice that pulls in the same questions a cybersecurity review would: how is the control network accessed remotely, is it segmented from business IT, who can reach the controllers, and is that access controlled and logged.
How to satisfy it
Assess how your control systems are reached and segmented, then close the recurring gaps: flat remote access, shared credentials, and an unsegmented OT network. An on-premise access gateway that controls and records access to the control network addresses the remote-access finding; segmenting the OT network and removing shared credentials are separate steps alongside it. For many systems the work is grant-eligible. See our water and wastewater cybersecurity solution.