TroutTrout
Back to Blog
WaterCompliance

AWIA Risk and Resilience Certification: The Cybersecurity Part

Trout Team2 min read

AWIA Section 2013 requires community water systems serving more than 3,300 people to complete and certify a Risk and Resilience Assessment to the EPA, and electronic control systems (SCADA, PLCs, and their networks) are explicitly in scope, not just physical infrastructure. Systems then prepare an Emergency Response Plan and recertify on a recurring cycle.

What AWIA actually requires

America's Water Infrastructure Act (2018), Section 2013, amended Section 1433 of the Safe Drinking Water Act. Community water systems above the 3,300-person threshold must:

  • Complete a Risk and Resilience Assessment covering malevolent acts and natural hazards.
  • Certify completion to the EPA by the applicable deadline for their size tier.
  • Prepare an Emergency Response Plan that incorporates the assessment findings.
  • Recertify on a recurring basis, roughly every five years.

The cybersecurity part

The assessment is not limited to fences and pumps. It must consider the resilience of electronic, computer, or other automated systems the utility uses, which means SCADA, PLCs, HMIs, and the networks connecting them. In practice that pulls in the same questions a cybersecurity review would: how is the control network accessed remotely, is it segmented from business IT, who can reach the controllers, and is that access controlled and logged.

How to satisfy it

Assess how your control systems are reached and segmented, then close the recurring gaps: flat remote access, shared credentials, and an unsegmented OT network. An on-premise access gateway that controls and records access to the control network addresses the remote-access finding; segmenting the OT network and removing shared credentials are separate steps alongside it. For many systems the work is grant-eligible. See our water and wastewater cybersecurity solution.

FAQ

Frequently Asked Questions

What does AWIA require?
Section 2013 of America's Water Infrastructure Act (2018) amended the Safe Drinking Water Act to require community water systems serving more than 3,300 people to complete a Risk and Resilience Assessment, certify its completion to the EPA, and prepare an Emergency Response Plan. Both must be reviewed and recertified on a recurring basis, roughly every five years.
Is cybersecurity part of the AWIA assessment?
Yes. The assessment must consider the resilience of electronic, computer, and automated control systems (SCADA, PLCs, and the networks around them), not only physical infrastructure. Remote access, segmentation, and access control to those systems are squarely in scope.
How do you satisfy the cybersecurity part?
Assess how control systems are accessed and segmented, close the obvious gaps (flat remote access, shared credentials, unsegmented OT), and keep evidence. An on-premise access gateway that controls and records access to the control network covers the core of it, and the work is often grant-eligible.