Water Systems
EPA requirements and SCADA security for water utilities
42 U.S.C. 300i-2(a)(4), text in effect 19 August 2026: a certification shall contain only information identifying the community water system, the date of the certification, and a statement that the system has conducted, reviewed or revised the assessment.
Water and wastewater systems provide essential services requiring robust cybersecurity for industrial control systems. Thalorin supports water utilities with compliance infrastructure addressing EPA requirements, AWIA, and the operational technology security controls critical for water system operations.
On 22 July 2026 the FBI, CISA, NSA, EPA, the Department of Energy, the Cyber National Mission Force and the Treasury updated joint advisory AA26-097A, first published on 7 April 2026, on Iranian-affiliated actors exploiting internet-connected programmable logic controllers — disruption caused by malicious interaction with PLC project files and manipulation of the values shown on HMI and SCADA displays. The update widened the named manufacturers beyond Rockwell Automation and Allen-Bradley to Schneider Electric and Siemens, and added detection guidance for tampered reusable code modules. Water and Wastewater Systems is one of three sectors it addresses.
What binds a water utility federally is narrower than the threat. Section 1433 of the Safe Drinking Water Act, as amended by section 2013 of America's Water Infrastructure Act, reaches community drinking water systems serving more than 3,300 people and requires a risk and resilience assessment and an emergency response plan. Publicly owned treatment works run comparable control systems under the Clean Water Act with no equivalent duty. Nor is there an EPA cybersecurity standard behind either: the March 2023 sanitary survey memorandum was stayed by the Eighth Circuit in July 2023 and rescinded that October.
The certification is the part consistently misread. Section 1433(a)(4) limits it to three things — information identifying the system, the date, and a statement that the assessment has been conducted, reviewed or revised — and section 1433(a)(5) bars state or local law from compelling the assessment itself on the strength of that filing. EPA states plainly that it requires no designated standard, method or tool. No federal reader ever sees whether the assessment found anything, so a system can be entirely current on its certification and still unknown to anyone outside the utility.
The distance that opens up is between a document certified once in five years and an estate of controllers, HMIs and cellular telemetry links that changes every month. Thalorin holds that inventory as the object the assessment is computed from — each device with its make, model and exposure — so recertification reads the plant as it currently stands, and an advisory naming a controller family resolves to the sites running it rather than to a fortnight of asking around.
Critical infrastructure is under constant threat
A certification that carries three fields
Section 1433(a)(4) permits only the system's identity, the date and a statement that the assessment was done. No federal reviewer sees the method or the finding, so the certification says nothing about the posture.
Wastewater sits outside the statute
Section 1433 covers community drinking water systems above 3,300 people. Treatment works running the same controllers under the Clean Water Act carry no such duty, leaving a combined utility regulated on half of one network.
No federal incident reporting path yet
EPA runs no cyber incident reporting structure of its own. CIRCIA would create a 72-hour duty, but CISA states it is still working on the final rule after funding lapses, so nothing under it is required.
Controllers reachable from the open internet
The second key action in advisory AA26-097A is to remove PLCs from direct internet exposure behind a secure gateway and firewall. Remote intakes, lift stations and booster sites are where that exposure outlives the inventory.
How Thalorin helps
AWIA compliance support
Carry the risk and resilience assessment and the emergency response plan as dated artifacts on the statutory cycle, including the six months section 1433(b) allows between certifying the assessment and certifying the plan.
EPA cybersecurity requirements
Work against the artifacts EPA actually publishes — the Cybersecurity Incident Action Checklist, the Top 8 Cyber Actions for Securing Water Systems, the Water Cyber Assessment Tool — since no rule exists to certify against.
SCADA system security
Map every route into the SCADA and HMI layer — cellular telemetry, vendor dial-in, remote sessions — and hold the OT ports advisory AA26-097A names, 44818, 2222, 102 and 502, as attributes of the site.
Water sector risk assessment
Assess against the six categories section 1433(a)(1) names, including electronic, computer or other automated systems and the security of those systems — EPA designates no method, so the method is the utility's to defend.
ICS security controls
Project one control state into NIST CSF 2.0 and WaterISAC's 12 Cybersecurity Fundamentals for Water and Wastewater Utilities rather than maintaining a separate evidence set for each.
Small utility compliance
For systems between 3,301 and 49,999 people, build the assessment from an inventory one operator can maintain, not from a consultancy engagement reconstructed every fifth year.
Water Systems: common questions
When is our AWIA recertification actually due?
Five years after the statutory deadline for your size tier, not five years after the day you filed. Section 1433(a)(3)(B) sets the review at least once every five years after the applicable deadline for the original certification, putting the current cycle at 31 March 2025 for systems serving 100,000 or more, 31 December 2025 for 50,000 to 99,999, and 30 June 2026 for 3,301 to 49,999. The plan follows six months later.
Is there a mandatory federal cybersecurity standard for water utilities?
No, as of August 2026. EPA withdrew its 2023 attempt to read cybersecurity into sanitary survey reviews after the Eighth Circuit stayed it, and has issued nothing in its place. What binds is section 1433, which requires the assessment to cover electronic, computer or other automated systems including the security of those systems, and the emergency response plan to include strategies for the physical security and cybersecurity of the system. State law can go further; New Jersey's Water Quality Accountability Act does.
Do wastewater utilities have to complete a risk and resilience assessment?
Not under section 1433, which reaches community drinking water systems only. EPA encourages the work and publishes material for wastewater systems — the RRA and ERP Primer for Very Small Drinking Water and Wastewater Systems, the Vulnerability Self-Assessment Tool — but no certification obligation attaches to it. Most combined utilities do the work regardless, because the same operators, the same control network and often the same controller families sit on both sides of that boundary.
What should a small utility do about the Iranian PLC activity?
Follow the key actions in advisory AA26-097A. Take controllers off direct internet exposure behind a secure gateway and firewall; query available logs against the published indicators and for suspicious traffic on the ports associated with OT devices, including 44818, 2222, 102 and 502, especially from foreign hosting providers; and on Rockwell Automation devices, place the physical mode switch on the controller into the run position. The advisory was updated on 22 July 2026 to add Schneider Electric and Siemens.
Who do we report a water system cyber incident to?
There is no reporting mandate specific to water in force as of August 2026. CIRCIA directs CISA to require covered entities to report substantial incidents within 72 hours and ransom payments within 24 hours, but the final rule has not issued, so nothing under it is yet required. Reporting today runs to CISA, your state primacy agency and WaterISAC. The liability protections that make such sharing safe run only to 30 September 2026 under 6 U.S.C. 1510.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Water Systems.
See how one evidence artifact satisfies Water Systems requirements alongside every other framework you carry.