TroutTrout
Back to Blog
UtilitiesWaterComplianceEPA

EPA Cybersecurity Requirements for Water and Wastewater Systems

Trout Team11 min read

The single most common misconception about water utility cybersecurity is that there is no federal requirement. There is. It does not look like a dedicated cybersecurity rule, which is why people miss it, but it is enforceable, EPA is actively enforcing it, and the penalties are real. This post lays out exactly what federal law requires, what it does not, and how the picture changed between 2023 and today.

The short answer: it lives in the Safe Drinking Water Act

There is no standalone EPA cybersecurity regulation for water utilities. The enforceable federal requirement lives in Section 1433 of the Safe Drinking Water Act, which was rewritten by America's Water Infrastructure Act (AWIA) in 2018. It requires every community water system serving more than 3,300 people to do two things and certify both to EPA:

  1. Complete a Risk and Resilience Assessment (RRA).
  2. Prepare an Emergency Response Plan (ERP) based on that assessment.

Cybersecurity is not optional inside these documents. The statute requires the RRA to evaluate the system's electronic, computer, and other automated systems, which is cybersecurity by another name. The ERP must then include the strategies and resources to detect, respond to, and recover from a cyber incident. So while nobody hands you a checklist labeled "EPA cybersecurity rule," the law already obligates you to assess your cyber risk and plan your cyber response, and to attest that you did.

Why people think the rule was cancelled

The confusion is understandable, because EPA did try to create something more prescriptive and then had to pull it back.

In March 2023, EPA issued an interpretive memorandum telling states they must evaluate the cybersecurity of operational technology when conducting sanitary surveys, the periodic on-site inspections every public water system receives. It would have made cyber a graded part of routine state audits. Industry groups and several states objected that EPA had effectively created a new rule without going through formal rulemaking. Missouri, Arkansas, and Iowa sued. The 8th Circuit Court of Appeals stayed the memorandum in July 2023, and on October 11, 2023, EPA withdrew it.

Here is the part that gets lost: only the sanitary survey memo went away. The underlying AWIA requirements never did. Section 1433 is statute, not a discretionary memo, and it remains fully in force. Withdrawing the memo removed one enforcement mechanism. It did not remove the obligation to assess cyber risk and plan for a cyber incident.

EPA is enforcing, and the compliance rate is poor

If the withdrawal left any impression that water cybersecurity had gone quiet at the federal level, EPA's May 20, 2024 enforcement alert ended it. The alert reported that, based on recent inspections, more than 70 percent of water systems inspected were not fully compliant with Safe Drinking Water Act Section 1433, and that some had critical cybersecurity vulnerabilities, specifically calling out default passwords that were never changed and single shared logins that are trivial to compromise.

EPA's stated response was to increase inspections and to pursue civil and criminal enforcement where warranted, using its existing Section 1433 authority. The message to operators is direct: the requirement is not new, most systems are not meeting it, and the agency is now looking. A missing or stale RRA or ERP, or an assessment that never seriously examined the OT network, is now an enforcement exposure, not just a paperwork gap.

The deadlines you are actually on the hook for

AWIA compliance runs on a five-year cycle, and the Risk and Resilience Assessment and the Emergency Response Plan have separate clocks. The ERP is due six months after the RRA is certified, so a system that certified early has an earlier ERP date than the table implies. Deadlines are set by population served:

Population servedRRA recertificationERP recertification
100,000 or moreMarch 31, 2025 (passed)September 30, 2025 (passed)
50,000 to 99,999December 31, 2025 (passed)June 30, 2026 (passed)
3,301 to 49,999June 30, 2026 (passed)December 31, 2026

If you serve between 3,301 and 49,999 people, the RRA recertification deadline passed on June 30, 2026. The obligation did not move with it, so if you missed the date the exposure is live now. The ERP recertification for the same tier is due December 31, 2026, and that is the next federal deadline on the calendar.

Both documents are certified to EPA separately: EPA Form 8170-1 for the Risk and Resilience Assessment and EPA Form 8170-2 for the Emergency Response Plan. If your first-round assessment treated cybersecurity as a paragraph rather than a real evaluation of your control systems, recertification is the moment to fix it, before an inspector does it for you.

What a credible RRA and ERP look like on the cyber side

EPA and its partners publish tooling for this, including the Vulnerability Self-Assessment Tool (VSAT), the Baseline Information on Malevolent Acts reference, the Small System Risk and Resilience Assessment Checklist, and an ERP template. The tools are useful, but they only produce a credible result if the underlying controls exist. In practice, an assessment that survives scrutiny can answer three questions with evidence rather than assertion:

  • Do you know your OT assets? A Risk and Resilience Assessment that has never enumerated the RTUs, PLCs, engineering laptops, and vendor modems on the control network is assessing a system it cannot see. The inventory is the foundation.
  • Is access to control systems attributable? Default passwords and shared logins are the exact failures EPA named. The fix is not a stronger password policy on equipment that barely supports one, it is an identity-bound access layer in front of the OT, so every connection maps to a named person and is protected by MFA. We cover the mechanics in How to Implement MFA in Legacy OT Environments Without Breaking Operations.
  • Can you prove response and recovery? The ERP requirement is not satisfied by a document. EPA's emphasis has shifted toward evidence: you do it, you can prove it, and you have tested recovery. A tamper-evident audit trail and a rehearsed incident response plan are what turn a written ERP into a defensible one.

For the full architecture that ties these controls together for a utility OT network, see our reference whitepaper, Zero Trust for Utility OT.

Where federal meets state: New York went further

The federal floor is AWIA. A growing number of states are building above it, and several got there before New York did.

You will read almost everywhere that New York is "first in the nation." That is not accurate, and it matters if you operate outside New York and concluded you were unregulated. Pennsylvania has required utilities to report a cyber attack since 2005. Oklahoma added immediate incident reporting in 2019, Missouri a cyber risk plan in 2020, New Jersey a full program requirement in 2021, Tennessee a written cyber security plan in 2022, and New Hampshire cyber breach procedures in every community water system ERP in 2024. Maryland and Indiana both landed binding requirements in 2025. The defensible version of the New York claim is narrower: it is the first state to adopt a detailed, OT-specific regulation covering both drinking water and wastewater.

States with binding water or wastewater cyber requirements

State law is the fastest-moving part of this picture. These are the regimes in force as of August 2026.

StateInstrumentCore dutyNext or most recent date
New York10 NYCRR App. 5-E (DOH); 6 NYCRR 750 (DEC)MFA or compensating controls, IT/OT account separation, no OT default passwords, cyber asset inventory, annual vulnerability analysis, 24h incident reportTraining and reporting live since March 2026; full DOH compliance Jan 1, 2027; DEC controls Mar 11, 2027
New JerseyWQAA, N.J.S.A. 58:31-1, as amended by P.L.2021 c.262Cyber program across all ICS conforming to NIST CSF, CIS or ISO 27000; NJCCIC membership; cyber insurance; annual officer-signed certificationIn force since 2022, certification recurring
MarylandCh. 495 of 2025 (SB 871), Env. §§9-2701 to 9-2708Cyber POC, annual training, ERP cyber revision; larger systems add zero trust commitment and a biennial third-party OT and IT maturity assessment. Incident report to the State SOC in 1 hourMaturity assessment due Jul 1, 2026 (passed); DoIT certification collection begins Oct 1, 2026
IndianaSEA 459 (2025), IC 13-18-16.5Annual vulnerability assessment, named incident reporter, 24h reporting, biennial certificationFirst assessment and certification Dec 31, 2026
TennesseePub. Ch. 1111 (2022); Rule 1220-04-15Written cyber security plan reassessed every two years; annual filing with sworn CEO statement. The rule names ICS, SCADA, DCS and PLC explicitlyAnnual filing every July 1
Rhode Island250-RICR-150-10-4Wastewater O&M plan must carry a cyber risk management plan and a named Risk and Resiliency Coordinator; 24h verbal notice, 5-day written reportCompliance Oct 16, 2026
New HampshireEnv-Dw 503.24(b)(17)ERP must include cyber breach procedures, including manual operation of equipment if control systems are compromised. No population thresholdFiled Mar 31, 2026, next cycle 2031
MissouriRSMo 640.142, 640.145 (2020)Cyber risk plan with risk assessments and controls. Exempts systems with no internet-connected control systems and cities over 30,000In force since 2021
Texas30 TAC §290.46(w)Immediate notification of an unauthorised attempt to probe or access systems supporting safe drinking water. No population thresholdIn force
Pennsylvania52 Pa. Code §65.2, Ch. 101Immediate telephone report of a cyber attack causing service interruption or over $50,000 damage; written cyber and continuity plans, annual self-certificationFeb 28 annually. A rulemaking that would replace both was approved June 2026

Wastewater is the structural gap. AWIA covers drinking water only, and a May 2026 GAO report (GAO-26-109159) found EPA identified critical gaps in its own legal authority, specifically the absence of cyber risk assessment requirements for wastewater systems. Where wastewater is covered, it is a state doing it: New York, Maryland, Indiana, Rhode Island, Tennessee, West Virginia and Nevada all reach it.

New York's program is deliberately aligned with the federal baseline, so the assessment work you do for AWIA feeds directly into state compliance, and vice versa. The same is broadly true elsewhere: every one of these regimes is asking for some combination of an asset inventory, attributable access, and evidence you can produce on demand.

What EPA has done since the 2024 alert

Nothing binding. In October 2025 EPA published voluntary resources: a revised ERP guide, a cybersecurity incident response plan template, incident-specific checklists, and a procurement checklist. EPA has stated it lacks explicit statutory authority to mandate cybersecurity measures, which is the same conclusion GAO reached in May 2026. The 2023 sanitary survey memorandum has not been reinstated. Practically, this means the federal picture is unlikely to tighten soon, and the movement you need to track is at state level.

If you operate in New York, treat AWIA and Part 5 as one program, not two. Our New York water cybersecurity hub maps the state requirements in detail, and the DOH Part 5 deep dive walks through exactly what the state adds on top of the federal floor.

The bottom line

Federal water cybersecurity is often described as unregulated. It is not. AWIA Section 1433 requires every community water system over 3,300 people to assess its cyber risk and plan its cyber response, every Risk and Resilience Assessment recertification deadline has now passed with the Emergency Response Plan round closing December 31, 2026, and EPA has said plainly that it is inspecting and enforcing against systems that fall short. The withdrawn 2023 memo changed one enforcement path, not the obligation. Build a real OT asset inventory, put attributable and MFA-protected access in front of your control systems, and keep evidence you can show an inspector. That satisfies the federal requirement, prepares you for whatever your state adopts next, and, more to the point, actually protects the water.

FAQ

Frequently Asked Questions

Is there a federal cybersecurity regulation for water utilities?
There is no standalone EPA cybersecurity rule. The enforceable federal requirement lives in Safe Drinking Water Act section 1433, added by America's Water Infrastructure Act (AWIA) in 2018. It requires community water systems serving more than 3,300 people to complete a Risk and Resilience Assessment and an Emergency Response Plan that both address cybersecurity.
What happened to the EPA cybersecurity sanitary survey rule?
In March 2023, EPA issued a memorandum requiring states to evaluate operational technology cybersecurity during sanitary surveys. Missouri, Arkansas, and Iowa challenged it, the 8th Circuit stayed it in July 2023, and EPA withdrew the memorandum on October 11, 2023. The AWIA risk assessment and emergency response plan requirements remain fully in force.
Does AWIA require water utilities to address cybersecurity?
Yes. A Risk and Resilience Assessment under AWIA must evaluate the utility's electronic, computer, and other automated systems, which is cybersecurity. The Emergency Response Plan must include strategies and resources to respond to a cyber incident. Both must be certified to EPA.
When are the AWIA recertification deadlines?
Risk and Resilience Assessment recertification: systems serving 100,000 or more by March 31, 2025, systems serving 50,000 to 99,999 by December 31, 2025, and systems serving 3,301 to 49,999 by June 30, 2026. All three have passed. The Emergency Response Plan is due six months after the RRA, so the next federal deadline is December 31, 2026, the ERP recertification for systems serving 3,301 to 49,999. Recertification runs on a five-year cycle.
Which states have their own water cybersecurity regulations?
As of August 2026, states with binding water or wastewater cybersecurity requirements include New York, New Jersey, Maryland, Indiana, Tennessee, Rhode Island, New Hampshire, Missouri, Texas, Pennsylvania, Oklahoma, West Virginia and Nevada. Contrary to widespread reporting, New York was not first: Pennsylvania has required cyber attack reporting since 2005, Oklahoma since 2019, Missouri since 2020, New Jersey since 2021, Tennessee since 2022 and New Hampshire since 2024. New York is the first state with a detailed OT-specific rule covering both drinking water and wastewater.
Are wastewater systems covered by federal cybersecurity requirements?
No. AWIA Section 1433 applies to community drinking water systems only. A May 2026 GAO report, GAO-26-109159, found that EPA had identified critical gaps in its legal authority, specifically the absence of cybersecurity risk assessment requirements for wastewater systems. Where wastewater is regulated, it is by states: New York, Maryland, Indiana, Rhode Island, Tennessee, West Virginia and Nevada all reach wastewater utilities.
What is the next water cybersecurity compliance deadline?
October 1, 2026, when Maryland's Department of Information Technology begins collecting certifications. Then October 16, 2026 for Rhode Island wastewater operations and maintenance plans, and December 31, 2026 for three at once: the federal AWIA Emergency Response Plan recertification for systems serving 3,301 to 49,999, Indiana's first vulnerability assessment and certification, and Nevada's annual filing. New York's DOH Appendix 5-E full compliance follows on January 1, 2027.
Is EPA actually enforcing water cybersecurity?
Yes. In a May 2024 enforcement alert, EPA reported that more than 70 percent of inspected systems were not fully compliant with Safe Drinking Water Act section 1433, some with critical vulnerabilities such as default passwords. EPA said it would increase inspections and pursue civil and criminal enforcement where warranted.