Which states impose water utility cyber liability?
- Authority
- New Jersey Department of Environmental Protection; New York Department of Health and Department of Environmental Conservation; Maryland General Assembly
- Rule type
- statute / regulation
- Jurisdiction scope
- US state (New Jersey, New York, Maryland)
- Source text
- Read primary rule text ↗
Cybersecurity programs, training, incident reporting, assessments, and cyber insurance for covered water and wastewater utilities in NJ, NY, and MD.
For legal liability after a water-system cyberattack, states matter more than federal vocabulary. As of mid-2026, the enforceable state map is short: New Jersey, New York, and Maryland impose enacted cybersecurity duties on covered water utilities; the other 47 states have no comparable water-utility cybersecurity statute identified in the record reviewed here. New Jersey’s Water Quality Accountability Act is the oldest of the three and was updated in 2021; New York adopted drinking-water and wastewater cybersecurity regulations on March 11, 2026; Maryland’s SB 871 was signed on May 13, 2025.[1][2][3]
That does not mean the rest of the country is unregulated in every sense. Utilities may still face procurement terms, grant conditions, insurance warranties, state public-utility oversight, common-law negligence claims, and federal risk-assessment duties. But when counsel asks what a regulator, plaintiff, or insurer can point to as a binding cybersecurity duty imposed on the utility because it is a water utility, the answer is uneven and state-specific.

The three-state obligations map
The useful comparison is not “who has a cybersecurity policy.” It is jurisdictional scope, covered entity, required conduct, and the document trail that survives an incident. On that measure, New Jersey, New York, and Maryland are not interchangeable.
| State | Covered water entities in the cited record | Core cybersecurity duties | Liability significance |
|---|---|---|---|
| New Jersey | Water purveyors subject to the Water Quality Accountability Act, including systems above the 500-service-connection threshold described in the implementation materials. | Cybersecurity program; conformance with a recognized framework such as NIST, CIS, or ISO; cyber insurance requirement; broader accountability obligations for covered drinking-water systems.[1] | Creates a concrete statutory baseline for negligence allegations, state enforcement, board oversight, and insurance disputes over whether the utility maintained the required program and coverage. |
| New York | Drinking-water systems under Department of Health rules and wastewater systems under Department of Environmental Conservation rules adopted March 11, 2026. | Mandatory cybersecurity training for operators, incident reporting, and related implementation support including the $2.5 million SECURE grant program described by the governor’s office.[2] | Important because it reaches wastewater as well as drinking water; training and reporting rules create dated compliance records that can become evidence after an intrusion. |
| Maryland | Public water and wastewater systems covered by SB 871 / Chapter 495. | Cybersecurity point of contact; annual cybersecurity training; zero-trust architecture requirement; biennial cybersecurity assessments; reporting to the state Security Operations Center.[3] | Turns governance, training, architecture, assessment, and incident-reporting choices into statutory compliance questions rather than discretionary best practices. |
The chronology matters. New York and Maryland have both been described in public materials with “first-in-the-nation” framing, but New Jersey’s Water Quality Accountability Act predates both, with cybersecurity added through the 2021 update. New York’s distinctive contribution is not that it was the first state ever to put water-sector cybersecurity into enforceable law; it is that its March 2026 rules extend the binding model to wastewater in a way the other cited state mandates do not.
New Jersey: framework conformance and insurance are the legal hooks
New Jersey is the cleanest example of a state converting cybersecurity from a voluntary program into a water-utility compliance obligation. The Water Quality Accountability Act applies to covered water purveyors and, in the materials reviewed, uses a service-connection threshold above 500 connections. The 2021 update requires a cybersecurity program, conformance with a recognized framework such as NIST, CIS, or ISO, and cyber insurance.[1]
For liability purposes, the framework requirement is more useful than a general admonition to be “secure.” It gives an investigator or plaintiff a place to start: which framework did the utility select, who approved it, when was the gap assessment done, what controls were deferred, and whether the board was told that deferral created statutory nonconformance. The statute does not need to recite a private cause of action to become relevant in a negligence case. A plaintiff can use the statutory duty as evidence of what a reasonable covered utility should have been doing, while the utility will want records showing selection, implementation, review, and budget escalation.
The insurance requirement deserves equal attention. Cyber insurance is often treated as a finance-office renewal problem until a carrier asks whether the insured complied with mandatory controls. In New Jersey, the coverage question can become statutory as well as contractual: did the covered water purveyor carry the required cyber insurance, did its application representations match its actual program, and did exclusions or conditions turn on framework conformance?
New York: the wastewater rule changes the jurisdictional answer
New York’s March 11, 2026 rules matter because the state did not stop at drinking water. The governor’s office described coordinated Department of Health and Department of Environmental Conservation regulations requiring cybersecurity training and incident reporting for water and wastewater operators, along with $2.5 million in SECURE grant funding to help regulated entities implement the requirements.[2]
The operator-training requirement is not a decorative compliance item. In litigation, training failures are easy to translate into ordinary negligence language: the utility had a duty to train covered operators; the training either occurred or did not; attendance, curriculum, and refresh dates either exist or do not. After a cyber incident that interrupts service or exposes customer information, those records can become the simplest exhibit in the file.
Incident reporting has a different function. It creates a timestamped state notice obligation. That may help regulators respond, but it also fixes what the utility knew, when it knew it, and how quickly it characterized the event. Counsel should assume those reports may later be compared against board minutes, customer notices, forensic timelines, insurance submissions, and public statements.
The grant program is not a liability shield. It may, however, affect how excuses sound after the fact. A small municipal system that documents its request for assistance, its procurement delays, and its interim controls is in a different litigation posture from a utility that treated the mandate as aspirational because implementation was inconvenient.
Maryland: governance, zero trust, assessments, and the state SOC
Maryland’s SB 871, signed May 13, 2025, is more prescriptive about cybersecurity governance. The cited bill materials identify duties for covered public water and wastewater systems, including designation of a cybersecurity point of contact, annual cybersecurity training, zero-trust architecture, biennial cybersecurity assessments, and reporting to the state Security Operations Center.[3]
Those terms will not all litigate the same way. A point of contact is a governance assignment: if a warning, grant notice, incident alert, or insurer request arrived, there should be an identifiable person responsible for receiving and routing it. Annual training is a personnel record. Biennial assessments produce a dated list of known weaknesses, remediation decisions, and unresolved risks. Reporting to the state SOC creates another external timestamp.
The zero-trust requirement is the broadest and likely the most contested. “Zero trust” can be a procurement slogan, an architecture principle, or a control set depending on who is selling it. Once it appears in a signed state statute, the legal question changes. Counsel should ask what implementation standard the utility adopted, what systems are in scope, which legacy systems cannot meet the architecture target, and who accepted the residual risk. The statute supplies the duty; the record supplies or defeats the defense.
Federal law does not fill the gap
The America’s Water Infrastructure Act is often cited too broadly. Section 2013, codified in Safe Drinking Water Act section 1433, requires community water systems serving more than 3,300 people to conduct risk and resilience assessments and prepare emergency response plans on a tiered schedule. The smallest covered tier in the cited materials—systems serving 3,301 to 49,999 people—had a June 30, 2026 deadline.[4]
That is a federal baseline, not a federal water-sector cybersecurity code. It does not create the same kind of direct, control-by-control cyber mandate that New Jersey, New York, and Maryland have enacted for covered utilities. It also does not solve the drinking-water versus wastewater distinction. For a wastewater operator outside New York or Maryland, AWIA is not the missing federal answer.
EPA tried another route in 2023 by issuing a memorandum that would have pushed cybersecurity into sanitary surveys. That effort did not become a durable direct mandate. After litigation in the 8th Circuit and objections from states and water-sector groups, EPA withdrew the March 2023 memorandum.[5]
CIRCIA may eventually add another reporting layer for critical infrastructure entities, but the materials reviewed here treat its final rule timing as still developing later in 2026. That is not a present substitute for an enacted state water-utility cybersecurity statute, and counsel should verify final rule text against the Federal Register before treating it as an operative water-sector duty.
The exposure is broad; the binding duty set is thin
The narrowness of enacted law is uncomfortable because the risk evidence is not narrow. GAO reported that nearly 170,000 U.S. water systems face cybersecurity risk and found that EPA had not conducted a sector-wide risk assessment until January 2025.[6]
EPA’s Office of Inspector General reached a similarly practical conclusion from a different angle. In Report 25-N-0004, the OIG identified critical or high-risk vulnerabilities at 97 drinking-water systems serving about 27 million people.[7]

Those findings are pressure evidence, not self-executing law. They show why a board cannot responsibly treat cyber risk as exotic or remote. They do not tell a plaintiff which state statute was violated, or tell an insurer which mandatory control was a condition of coverage. That is the practical gap: the national risk record is large, but the enforceable state-law record remains concentrated in three jurisdictions.
How the duties translate after an incident
A water-utility cyberattack does not need a specialized cyber-liability statute to become a lawsuit. Menichini v. American Water Works Company, filed in the District of New Jersey on October 14, 2024, is useful as a template because it frames the alleged cybersecurity failure in ordinary civil-litigation terms: duty, breach, causation, and damages. The complaint is an allegation, not a finding, but it shows how plaintiffs can translate a utility cyber event into familiar negligence and data-security claims.[8]
State cybersecurity statutes sharpen that translation. In New Jersey, a complaint can ask whether the utility maintained the required cybersecurity program, conformed to the selected recognized framework, and carried the required cyber insurance. In New York, it can ask whether covered operators received mandatory training and whether the utility reported the incident as required. In Maryland, it can ask whether the utility designated the point of contact, completed annual training, implemented zero-trust architecture, performed biennial assessments, and reported to the state SOC.
That is a legal-risk inference, not a claim that any one statute automatically establishes tort liability. The statutes supply concrete conduct that a court, regulator, carrier, or expert can compare against the utility’s actual record. A covered utility that missed a statutory duty will have to explain not only why the lapse occurred, but why that lapse did not matter to the incident or the claimed loss.
State enforcement
State enforcement exposure is the most direct consequence. If a statute or regulation requires a cybersecurity program, training, reporting, assessment, point of contact, or insurance, the state does not need to prove that a catastrophic cyberattack occurred before it can ask whether the utility complied. The regulated conduct exists independently of the incident.
The uncomfortable files are usually mundane: no board adoption of the cybersecurity program, no documented framework choice, no training roster, no current assessment, no incident-reporting procedure, no one assigned to receive state cyber communications, or an insurance application that says controls exist when the utility’s own assessment says they do not.
Negligence claims
In negligence litigation, the statutory duty becomes a source of standard-of-care evidence. Plaintiffs still have to deal with causation and damages. A missed training session, stale assessment, or imperfect zero-trust implementation does not prove that the same incident would have been avoided. But the presence of an enacted duty reduces the abstraction. The argument is no longer that the utility should have followed some preferred industry practice; it is that the utility failed to do something state law required of that class of utility.
Utilities in the other 47 states are not immune. They simply fight on less statutory terrain. Plaintiffs may point to AWIA assessments, EPA materials, industry frameworks, internal policies, insurance applications, or prior warnings. Those sources can matter, but they do not carry the same force as a state statute or rule that names the utility class and commands the conduct.
Cyber-insurance disputes
Insurance is where statutory cybersecurity duties can become expensive without waiting for a final judgment. A carrier evaluating coverage may ask whether the utility complied with mandatory controls, whether representations in the application were accurate, and whether the claimed loss falls within an exclusion tied to failure to maintain required safeguards. New Jersey’s express cyber-insurance requirement makes that inquiry especially obvious, but the same practical review can arise in New York and Maryland when statutory training, reporting, assessment, or architecture duties are relevant to the loss.
For public systems, this is also a board record problem. If counsel advised that a state mandate applied, the budget record should show whether the governing body funded compliance, deferred it, or accepted a documented residual risk. Silence rarely ages well after a breach notice, a boil-water event, or a carrier reservation-of-rights letter.
The questions counsel should answer first
The practical review starts with classification, not software. A utility cannot know its legal cyber exposure until it knows which legal bucket it occupies.
- Is the entity a drinking-water system, wastewater system, or both?
- Is it located in New Jersey, New York, or Maryland, or operating across one of those state lines?
- If in New Jersey, does the Water Quality Accountability Act threshold apply, and which recognized framework has the utility selected?
- If in New York, which operators must receive training, and what is the incident-reporting procedure?
- If in Maryland, who is the cybersecurity point of contact, when was the last assessment, and what does the utility mean by zero trust in its own environment?
- Does the cyber-insurance application match the actual program, training, assessment, and control records?
- Do board minutes show funding decisions, deferred remediation, and risk acceptance in a way that can be defended later?
Small and mid-sized public systems deserve realistic implementation schedules. They do not deserve legal advice that calls an enacted state mandate a best practice. Once a state has required the conduct, the budget problem is real, but it is no longer a defense by itself.
The mid-2026 operating conclusion is therefore narrow and consequential. For water utilities, the legally useful cybersecurity standard of care is now state-specific, source-dependent, and uneven. New Jersey, New York, and Maryland do most of the enforceable work; federal law and national risk reports explain why the issue matters, but they do not erase the state-by-state liability map.
References
- Water Quality Accountability Act — New Jersey Department of Environmental Protection
- Governor Hochul Announces New Cybersecurity Regulations to Protect New York’s Water and Wastewater Systems — New York State Governor’s Office — March 11, 2026
- Maryland Senate Bill 871 / Chapter 495 — Maryland General Assembly — May 13, 2025
- America’s Water Infrastructure Act: Risk and Resilience Assessments and Emergency Response Plans — Nossaman
- EPA withdraws water sector cybersecurity memo after lawsuits — The Record
- Critical Infrastructure Protection: EPA Urgently Needs a Strategy to Address Cybersecurity Risks to Water and Wastewater Systems — U.S. Government Accountability Office
- EPA Needs to Conduct a Risk Assessment and Develop a Strategy to Secure the Water and Wastewater Sector Against Cyber Threats — EPA Office of Inspector General — Report 25-N-0004
- American Water Works Hit with Class Action After Data Breach — ClassAction.org
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →