Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070
7-minute read Jul 30 2026

What water utilities need to know about cybersecurity compliance

Water utility cybersecurity compliance 2026 deadlines regulations

As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.

Key takeaways

  1. While the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps.
     
  2. Community water systems serving 3,301 to 49,999 people, the vast majority of U.S. systems, must certify their Risk and Resilience Assessments (RRAs) by June 30, 2026, under AWIA 2013.
     
  3. New York has already finalized binding cybersecurity regulations for wastewater facilities, setting a regulatory template that other states are expected to follow in 2026 and 2027.
     
  4. Under CIRCIA, utilities will soon be legally required to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
     
  5. Federal grant programs (SLCGP) and liability protections have been extended through Sept. 30, 2026, but remain tied to unpredictable budget cycles while targeted cyber threats continue to rise.

Navigating the new reality of water cyber regulation

In 2023, the U.S. EPA made an initial push to fold cybersecurity evaluations into state sanitary surveys. While that effort was stayed in court and subsequently withdrawn, the underlying federal statutory requirements and enforcement drivers remain fully active. Instead of relying on new survey rules, federal and state regulators are actively using existing statutory authority and technical guidance to shift water cybersecurity from voluntary recommendations to enforceable compliance deadlines.

The urgency to strengthen cybersecurity for water facilities is underscored by a recent coordinated cyber attack that disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026. 

Utility cyber regulations and mandates moving forward

America’s Water Infrastructure Act (AWIA) 2013 / Safe Drinking Water Act (SDWA) 1433 is still very much in force. 

Community water systems serving more than 3,300 people are legally required to certify a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP) to EPA on a five-year recertification cycle, and that cycle explicitly covers cyber threats, not just physical and natural hazards. 

Recertification deadlines:

  • Systems serving 100,000-plus people: March 31, 2025
  • 50,000–99,999 tier: Dec. 31, 2025
  • 3,301–49,999 tier, the vast majority of U.S. water systems: June 30, 2026, with ERPs due six months after.

The EPA hasn’t stopped pushing on cyber. It’s just doing it through guidance, technical assistance, and enforcement of existing authority rather than new rulemaking. 

In May 2024, the EPA issued an enforcement alert warning it would step up inspections tied to cybersecurity gaps found in drinking water systems. 

On Oct. 23, 2025, the EPA released an updated package of cyber tools: 

These tools are designed to help utilities fold cybersecurity directly into the RRA/ERP process they’re already required to complete.

States are stepping in where EPA stepped back

With the EPA’s national sanitary-survey mandate dead, states have started writing their own cybersecurity rules for water systems. New York is the clearest example: In March 2026, the New York State Department of Environmental Conservation finalized amendments to six New York Codes, Rules and Regulations (NYCRR) Parts 616, 650 and 750, adding binding cybersecurity regulations for wastewater treatment facilities, including mandatory incident reporting and access-control requirements built around EPA’s own cybersecurity guidance, incorporated into the rule by reference. Reporting requirements took effect March 26, 2026.

It’s a template other states are watching closely. Expect more state environmental and public utility regulators to follow New York’s lead in 2026 and 2027, particularly for wastewater systems, which (unlike drinking water) aren’t covered by AWIA and have largely operated without any federal cyber requirement at all.

Incident reporting is coming, whether or not utilities are ready

The U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require covered entities, including water and wastewater utilities, to report significant cyber incidents to CISA within 72 hours from the time the organization reasonably believes the incident has occurred, and report ransom payments within 24 hours of disbursement. Updated rules are expected to be finalized later in 2026. 

Utilities that wait for the rule to be finalized before building an incident response and reporting process will be scrambling; the smarter move is treating CIRCIA as if it is already in effect operationally.

Utility funding and information-sharing protections are back, for now

Two other pieces of the federal picture utilities lean on lapsed and were restored, but neither is fully settled:

The threat picture hasn’t waited for policy to catch up

The pattern since 2023 has kept on rising while the regulatory framework caught up.

How Tenable can help

Whether a utility’s driver is an RRA/ERP recertification deadline, a state mandate like New York’s, CIRCIA readiness, or simply defending against an increasingly aggressive threat landscape, the underlying work is the same: know what’s on the network, know what’s vulnerable, and be able to prove it.

Tenable One OT Exposure gives water and wastewater utilities:

  • Deep visibility across converged IT/OT environments by replacing the spreadsheet-based inventories EPA and state auditors increasingly ask utilities to move past, and giving utilities the documented OT/IT asset baseline that RRAs, state cyber rules, and CIRCIA readiness all assume exists.
  • Vulnerability management purpose-built for OT/ICS via Tenable’s proprietary hybrid discovery approach, including passive network monitoring and Safe Active Query capabilities to identify and prioritize exposed ports, default credentials, and outdated firmware that inspectors look for.
  • Continuous threat detection and monitoring through policy, anomaly, and signature-based detection tuned to OT protocols, giving utilities the evidence base (not just a policy on paper) that EPA’s updated guidance and state regulators now ask for.
  • Documentation utilities can hand to an auditor or regulator, including configuration change tracking, centralized log storage, and network topology documentation that maps directly to RRA, ERP, and CIRCIA reporting requirements.

The City of Raleigh, for example, uses Tenable One OT Exposure to spend less time chasing asset inventory manually and more time investigating real threats and remediating vulnerabilities across its water systems.

Tenable is recognized as a leader in industrial control systems security and trusted by more than 40,000 organizations worldwide. As the compliance landscape shifts from “encouraged” to “required,” deadline by deadline, state by state, Tenable gives water and wastewater utilities the visibility and evidence they need to stay ahead of it.

Learn more

Author

Learn more