The single most common misconception about water utility cybersecurity is that there is no federal requirement. There is. It does not look like a dedicated cybersecurity rule, which is why people miss it, but it is enforceable, EPA is actively enforcing it, and the penalties are real. This post lays out exactly what federal law requires, what it does not, and how the picture changed between 2023 and today.
The short answer: it lives in the Safe Drinking Water Act
There is no standalone EPA cybersecurity regulation for water utilities. The enforceable federal requirement lives in Section 1433 of the Safe Drinking Water Act, which was rewritten by America's Water Infrastructure Act (AWIA) in 2018. It requires every community water system serving more than 3,300 people to do two things and certify both to EPA:
- Complete a Risk and Resilience Assessment (RRA).
- Prepare an Emergency Response Plan (ERP) based on that assessment.
Cybersecurity is not optional inside these documents. The statute requires the RRA to evaluate the system's electronic, computer, and other automated systems, which is cybersecurity by another name. The ERP must then include the strategies and resources to detect, respond to, and recover from a cyber incident. So while nobody hands you a checklist labeled "EPA cybersecurity rule," the law already obligates you to assess your cyber risk and plan your cyber response, and to attest that you did.
Why people think the rule was cancelled
The confusion is understandable, because EPA did try to create something more prescriptive and then had to pull it back.
In March 2023, EPA issued an interpretive memorandum telling states they must evaluate the cybersecurity of operational technology when conducting sanitary surveys, the periodic on-site inspections every public water system receives. It would have made cyber a graded part of routine state audits. Industry groups and several states objected that EPA had effectively created a new rule without going through formal rulemaking. Missouri, Arkansas, and Iowa sued. The 8th Circuit Court of Appeals stayed the memorandum in July 2023, and on October 11, 2023, EPA withdrew it.
Here is the part that gets lost: only the sanitary survey memo went away. The underlying AWIA requirements never did. Section 1433 is statute, not a discretionary memo, and it remains fully in force. Withdrawing the memo removed one enforcement mechanism. It did not remove the obligation to assess cyber risk and plan for a cyber incident.
EPA is enforcing, and the compliance rate is poor
If the withdrawal left any impression that water cybersecurity had gone quiet at the federal level, EPA's May 20, 2024 enforcement alert ended it. The alert reported that, based on recent inspections, more than 70 percent of water systems inspected were not fully compliant with Safe Drinking Water Act Section 1433, and that some had critical cybersecurity vulnerabilities, specifically calling out default passwords that were never changed and single shared logins that are trivial to compromise.
EPA's stated response was to increase inspections and to pursue civil and criminal enforcement where warranted, using its existing Section 1433 authority. The message to operators is direct: the requirement is not new, most systems are not meeting it, and the agency is now looking. A missing or stale RRA or ERP, or an assessment that never seriously examined the OT network, is now an enforcement exposure, not just a paperwork gap.
The deadlines you are actually on the hook for
AWIA compliance runs on a five-year cycle, and the Risk and Resilience Assessment and the Emergency Response Plan have separate clocks. The ERP is due six months after the RRA is certified, so a system that certified early has an earlier ERP date than the table implies. Deadlines are set by population served:
| Population served | RRA recertification | ERP recertification |
|---|---|---|
| 100,000 or more | March 31, 2025 (passed) | September 30, 2025 (passed) |
| 50,000 to 99,999 | December 31, 2025 (passed) | June 30, 2026 (passed) |
| 3,301 to 49,999 | June 30, 2026 (passed) | December 31, 2026 |
If you serve between 3,301 and 49,999 people, the RRA recertification deadline passed on June 30, 2026. The obligation did not move with it, so if you missed the date the exposure is live now. The ERP recertification for the same tier is due December 31, 2026, and that is the next federal deadline on the calendar.
Both documents are certified to EPA separately: EPA Form 8170-1 for the Risk and Resilience Assessment and EPA Form 8170-2 for the Emergency Response Plan. If your first-round assessment treated cybersecurity as a paragraph rather than a real evaluation of your control systems, recertification is the moment to fix it, before an inspector does it for you.
What a credible RRA and ERP look like on the cyber side
EPA and its partners publish tooling for this, including the Vulnerability Self-Assessment Tool (VSAT), the Baseline Information on Malevolent Acts reference, the Small System Risk and Resilience Assessment Checklist, and an ERP template. The tools are useful, but they only produce a credible result if the underlying controls exist. In practice, an assessment that survives scrutiny can answer three questions with evidence rather than assertion:
- Do you know your OT assets? A Risk and Resilience Assessment that has never enumerated the RTUs, PLCs, engineering laptops, and vendor modems on the control network is assessing a system it cannot see. The inventory is the foundation.
- Is access to control systems attributable? Default passwords and shared logins are the exact failures EPA named. The fix is not a stronger password policy on equipment that barely supports one, it is an identity-bound access layer in front of the OT, so every connection maps to a named person and is protected by MFA. We cover the mechanics in How to Implement MFA in Legacy OT Environments Without Breaking Operations.
- Can you prove response and recovery? The ERP requirement is not satisfied by a document. EPA's emphasis has shifted toward evidence: you do it, you can prove it, and you have tested recovery. A tamper-evident audit trail and a rehearsed incident response plan are what turn a written ERP into a defensible one.
For the full architecture that ties these controls together for a utility OT network, see our reference whitepaper, Zero Trust for Utility OT.
Where federal meets state: New York went further
The federal floor is AWIA. A growing number of states are building above it, and several got there before New York did.
You will read almost everywhere that New York is "first in the nation." That is not accurate, and it matters if you operate outside New York and concluded you were unregulated. Pennsylvania has required utilities to report a cyber attack since 2005. Oklahoma added immediate incident reporting in 2019, Missouri a cyber risk plan in 2020, New Jersey a full program requirement in 2021, Tennessee a written cyber security plan in 2022, and New Hampshire cyber breach procedures in every community water system ERP in 2024. Maryland and Indiana both landed binding requirements in 2025. The defensible version of the New York claim is narrower: it is the first state to adopt a detailed, OT-specific regulation covering both drinking water and wastewater.
States with binding water or wastewater cyber requirements
State law is the fastest-moving part of this picture. These are the regimes in force as of August 2026.
| State | Instrument | Core duty | Next or most recent date |
|---|---|---|---|
| New York | 10 NYCRR App. 5-E (DOH); 6 NYCRR 750 (DEC) | MFA or compensating controls, IT/OT account separation, no OT default passwords, cyber asset inventory, annual vulnerability analysis, 24h incident report | Training and reporting live since March 2026; full DOH compliance Jan 1, 2027; DEC controls Mar 11, 2027 |
| New Jersey | WQAA, N.J.S.A. 58:31-1, as amended by P.L.2021 c.262 | Cyber program across all ICS conforming to NIST CSF, CIS or ISO 27000; NJCCIC membership; cyber insurance; annual officer-signed certification | In force since 2022, certification recurring |
| Maryland | Ch. 495 of 2025 (SB 871), Env. §§9-2701 to 9-2708 | Cyber POC, annual training, ERP cyber revision; larger systems add zero trust commitment and a biennial third-party OT and IT maturity assessment. Incident report to the State SOC in 1 hour | Maturity assessment due Jul 1, 2026 (passed); DoIT certification collection begins Oct 1, 2026 |
| Indiana | SEA 459 (2025), IC 13-18-16.5 | Annual vulnerability assessment, named incident reporter, 24h reporting, biennial certification | First assessment and certification Dec 31, 2026 |
| Tennessee | Pub. Ch. 1111 (2022); Rule 1220-04-15 | Written cyber security plan reassessed every two years; annual filing with sworn CEO statement. The rule names ICS, SCADA, DCS and PLC explicitly | Annual filing every July 1 |
| Rhode Island | 250-RICR-150-10-4 | Wastewater O&M plan must carry a cyber risk management plan and a named Risk and Resiliency Coordinator; 24h verbal notice, 5-day written report | Compliance Oct 16, 2026 |
| New Hampshire | Env-Dw 503.24(b)(17) | ERP must include cyber breach procedures, including manual operation of equipment if control systems are compromised. No population threshold | Filed Mar 31, 2026, next cycle 2031 |
| Missouri | RSMo 640.142, 640.145 (2020) | Cyber risk plan with risk assessments and controls. Exempts systems with no internet-connected control systems and cities over 30,000 | In force since 2021 |
| Texas | 30 TAC §290.46(w) | Immediate notification of an unauthorised attempt to probe or access systems supporting safe drinking water. No population threshold | In force |
| Pennsylvania | 52 Pa. Code §65.2, Ch. 101 | Immediate telephone report of a cyber attack causing service interruption or over $50,000 damage; written cyber and continuity plans, annual self-certification | Feb 28 annually. A rulemaking that would replace both was approved June 2026 |
Wastewater is the structural gap. AWIA covers drinking water only, and a May 2026 GAO report (GAO-26-109159) found EPA identified critical gaps in its own legal authority, specifically the absence of cyber risk assessment requirements for wastewater systems. Where wastewater is covered, it is a state doing it: New York, Maryland, Indiana, Rhode Island, Tennessee, West Virginia and Nevada all reach it.
New York's program is deliberately aligned with the federal baseline, so the assessment work you do for AWIA feeds directly into state compliance, and vice versa. The same is broadly true elsewhere: every one of these regimes is asking for some combination of an asset inventory, attributable access, and evidence you can produce on demand.
What EPA has done since the 2024 alert
Nothing binding. In October 2025 EPA published voluntary resources: a revised ERP guide, a cybersecurity incident response plan template, incident-specific checklists, and a procurement checklist. EPA has stated it lacks explicit statutory authority to mandate cybersecurity measures, which is the same conclusion GAO reached in May 2026. The 2023 sanitary survey memorandum has not been reinstated. Practically, this means the federal picture is unlikely to tighten soon, and the movement you need to track is at state level.
If you operate in New York, treat AWIA and Part 5 as one program, not two. Our New York water cybersecurity hub maps the state requirements in detail, and the DOH Part 5 deep dive walks through exactly what the state adds on top of the federal floor.
The bottom line
Federal water cybersecurity is often described as unregulated. It is not. AWIA Section 1433 requires every community water system over 3,300 people to assess its cyber risk and plan its cyber response, every Risk and Resilience Assessment recertification deadline has now passed with the Emergency Response Plan round closing December 31, 2026, and EPA has said plainly that it is inspecting and enforcing against systems that fall short. The withdrawn 2023 memo changed one enforcement path, not the obligation. Build a real OT asset inventory, put attributable and MFA-protected access in front of your control systems, and keep evidence you can show an inspector. That satisfies the federal requirement, prepares you for whatever your state adopts next, and, more to the point, actually protects the water.