Skip to content

Risk Digest

Water utility OT cyberattack compliance deadlines for 2026

A dated compliance calendar for U.S. community water systems: which AWIA Section 2013 certification deadlines, EPA enforcement risks, CIRCIA incident-reporting expectations, and New York state requirements govern OT/ICS cybersecurity as of Q3 2026 — each tied to its primary source and stamped last-verified.

By Editorial TeamUpdated Aug 5, 2026Verified Aug 5, 2026
CONFIRMED (AWIA); PENDING/PROPOSED (CIRCIA, NY)
Jurisdiction
U.S. federal; New York
Court
No court (regulatory compliance)
AI tool named
No AI tool named
Ruling date
Aug 5, 2026
Source document
View primary court order ↗
Last verified
Aug 5, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

For water utility operational technology cyberattack prevention compliance, the first question in Q3 2026 is not which framework is sensible. It is whether the system is a community water system serving more than 3,300 people, where it sits in the America’s Water Infrastructure Act recertification cycle, and whether anyone is about to certify a risk and resilience assessment or emergency response plan that the utility cannot defend.

Last verified: August 5, 2026. Federal AWIA Section 2013 obligations are binding now. CIRCIA cyber incident and ransom-payment reporting is expected, but not yet final. New York has separate wastewater and drinking-water tracks that should not be collapsed into a single “New York water rule.”

Stylized water treatment facility with calendar and OT network deadline rings

Q3 2026 compliance map

Status record as of August 5, 2026. Dates and legal status should be rechecked before a certification, board vote, enforcement response, or procurement representation.
TrackWho is in scopeCurrent legal statusDate or deadlineCompliance actionConsequence or riskLast verified
AWIA Section 2013 / SDWA Section 1433Community water systems serving more than 3,300 peopleBinding federal statutory requirementFive-year RRA and ERP recertification cycle; current round dates vary by population bandCertify completion of a risk and resilience assessment and emergency response planEPA enforcement exposure; false-certification risk if the filing cannot be supportedAugust 5, 2026 [1][2]
AWIA Round 2: 100,000 or more servedCommunity water systems serving 100,000+ peopleBinding for systems in this bandRRA: March 31, 2025; ERP: September 30, 2025Second-round certifications should already be completeLate, unsupported, or inaccurate certification may be reviewed in enforcement or inspection contextAugust 5, 2026 [3]
AWIA Round 2: 50,000–99,999 servedCommunity water systems serving 50,000 to 99,999 peopleBinding for systems in this bandRRA: December 31, 2025; ERP: June 30, 2026Second-round RRA and ERP certifications should be complete by Q3 2026Missed ERP deadline is no longer a future-planning itemAugust 5, 2026 [3]
AWIA Round 2: 3,301–49,999 servedCommunity water systems serving 3,301 to 49,999 peopleBinding for systems in this bandRRA: June 30, 2026; ERP: December 31, 2026RRA certification should be complete; ERP certification is the next federal AWIA deadlineSmall and midsize systems are now in the live filing windowAugust 5, 2026 [3]
EPA SDWA enforcement posturePublic water systems subject to SDWA inspection and enforcement authoritiesActive enforcement posture; figures cited here are from secondary reports that describe EPA materialsEPA enforcement alert issued May 2024 and updated July 24, 2025, as reported by secondary sourcesInspectors are treating cyber weaknesses as drinking-water compliance and emergency-risk issues where facts support itReported deficiencies include default passwords, shared logins, and former-employee access not revokedAugust 5, 2026 [4][5]
CIRCIA incident and ransom-payment reportingCovered entities to be defined by the final CISA ruleExpected but not yet binding as of this recordFinal rule expected September 2026; proposed reporting concepts include 72 hours for covered cyber incidents and 24 hours for ransom paymentsPrepare reporting workflows, but do not describe the obligation as final until the rule is issuedPremature certification language may overstate current legal dutiesAugust 5, 2026 [6]
CISA Act liability protections and SLCGP fundingEntities relying on federal cyber information-sharing protections or state and local cyber grant fundingTemporary window, not a water-utility-specific AWIA dutyReinstated November 12, 2025; extended only through September 30, 2026Use the window for planning, information-sharing, and funding decisionsExpiration affects risk allocation and funding strategy, not the AWIA certification dates themselvesAugust 5, 2026 [7]
New York wastewater cybersecurity rulesNew York wastewater utilities covered by DEC rulesReported as finalized; verify against the State Register and current DEC text before relying on adoption statusReporting effective March 26, 2026; core controls reported due one year after adoptionTrack wastewater compliance separately from drinking-water proposalsState enforcement overlay may apply in addition to federal dutiesAugust 5, 2026 [8][9]
New York drinking-water cybersecurity rulesNew York drinking-water systems covered by proposed DOH rulesProposed, not treated here as finalCompliance reported as expected January 1, 2027, subject to final adoptionMonitor adoption before board packets or certification language state a final dutyDo not merge proposed drinking-water requirements with finalized wastewater requirementsAugust 5, 2026 [8][9]

AWIA Section 2013 is the binding federal center

AWIA Section 2013 amended the Safe Drinking Water Act by adding risk and resilience assessment and emergency response plan requirements for community water systems serving more than 3,300 people. EPA’s 2019 Federal Register notice placed those duties in Section 1433 of the SDWA, 42 U.S.C. 300i-2, and identified cybersecurity as part of the covered assessment of system resilience, including electronic, computer, and automated systems used by the water system [1].

The population threshold matters. A system serving 3,300 people or fewer is not in the AWIA Section 2013 certification regime described here. A community water system serving 3,301 people is. That line is often more useful to counsel than a broad statement that “water is critical infrastructure,” because it tells the signer whether the federal certification duty exists.

EPA’s AWIA Section 2013 page states the recurring rule directly: community water systems subject to the requirement must review their risk and resilience assessment and emergency response plan at least every five years and submit certifications to EPA [2]. The certification is not a request for EPA to approve a particular control set. It is the utility’s representation that the required assessment and plan have been completed, reviewed, and updated on the statutory cycle.

AWIA Round 2 deadline table, last verified August 5, 2026.
Population servedRound 2 RRA certification deadlineRound 2 ERP certification deadlineQ3 2026 status
100,000 or moreMarch 31, 2025September 30, 2025Both deadlines have passed [3]
50,000 to 99,999December 31, 2025June 30, 2026Both deadlines have passed [3]
3,301 to 49,999June 30, 2026December 31, 2026RRA deadline has passed; ERP deadline is next [3]

For the smallest in-scope band, Q3 2026 is not an early-warning period. The RRA certification deadline has already passed, and the ERP certification is due December 31, 2026. That makes the board packet different from a general cyber-readiness memo. It should identify who completed the review, what materials support the certification, which OT and ICS dependencies were considered, and whether any known access-control failures contradict the representation being made.

What EPA enforcement changes about the certification

A certification deadline is easy to misfile as an administrative chore. EPA’s enforcement posture makes that a poor habit. Cybersecurity Dive reported that EPA’s May 2024 enforcement alert warned drinking-water systems about cybersecurity vulnerabilities and said EPA had taken more than 100 Safe Drinking Water Act enforcement actions against water systems since 2020 [4]. ABA Business Law Today later summarized EPA’s warning in similar enforcement terms, including the possibility that false certifications may create criminal exposure [5].

The same secondary reporting described EPA inspection findings since September 2023 in which more than 70% of inspected systems were out of compliance with cybersecurity-related requirements, with observed failures including default passwords, single shared logins, and access not revoked for former employees [4][5]. Those are not listed here as a generic controls checklist. They matter because EPA has identified them in an enforcement setting, where they may call into question whether a system’s assessment and emergency planning were real enough to support the filing.

Counsel should treat those figures with source discipline. The figures cited here were cross-checked through secondary sources because some EPA pages render through JavaScript. Before filing a formal response, enforcement submission, or board certification packet, re-confirm the current EPA alert and any updated enforcement figures directly against EPA materials.

EPA’s theory is not limited to whether a password rule exists in an IT policy. The reported enforcement materials connect cyber weakness to the agency’s Safe Drinking Water Act authorities, including emergency-power concerns under Section 1431 where a cyber condition may present an imminent and substantial endangerment [5]. In practical terms, the utility director may experience the inspection as a review of ordinary operational facts: who can reach the PLC interface, whether former employees still have credentials, whether remote access is logged, and whether emergency response planning assumes loss or manipulation of operational technology.

That is why the signer’s file should not contain only a consultant slide deck and a certification receipt. A defensible AWIA file should be able to show the population band, the due date, the date of the last RRA review, the date of the ERP review, the internal approver, the OT/ICS scope considered, and the known exceptions that were either remediated or carried into the emergency response plan.

CIRCIA is close, but it is not yet the filing rule

CIRCIA belongs on the Q3 2026 calendar, but it should not be described as a current binding reporting duty until CISA issues the final rule. Federal News Network reported on July 7, 2026, that major cyber rules, including CIRCIA, were expected to be finalized in the fall, with the CIRCIA final rule expected in September 2026 [6].

The expected CIRCIA reporting structure is materially important: covered entities would report covered cyber incidents within 72 hours and ransom payments within 24 hours [6]. Those time periods should already be built into incident intake forms, outside-counsel call trees, insurance notice playbooks, and vendor escalation language. They should not be written into a compliance certification as if the final rule has already landed.

Converging regulatory timeline tracks over water ripple and circuit patterns

The timing collision is real even if the legal statuses differ. Nossaman reported that Congress reinstated CISA Act liability protections and the State and Local Cybersecurity Grant Program on November 12, 2025, but only through September 30, 2026 [7]. For a municipal utility, that date affects information-sharing risk tolerance and funding strategy. It does not replace the AWIA schedule, and it does not make CIRCIA final by implication.

New York: keep wastewater finalization separate from drinking-water proposals

New York deserves attention because it is moving from broad cyber concern into sector-specific utility obligations. Governor Kathy Hochul announced new cybersecurity regulations and a grant program for water and wastewater systems on July 22, 2025 [8]. Tenable’s July 30, 2026 regulatory roundup reported that New York’s Department of Environmental Conservation wastewater rules had been finalized, with reporting effective March 26, 2026 and core controls due one year after adoption, while Department of Health drinking-water rules remained proposed with compliance expected January 1, 2027 [9].

That distinction should survive every board memo. Wastewater rules reported as adopted by DEC are not the same legal object as proposed DOH drinking-water rules. A combined water-and-sewer authority may need both tracks in one calendar, but not under one status label. Before counsel states that a New York drinking-water cybersecurity requirement is final, the adoption status should be checked against the current New York State Register and the operative agency text.

It is reasonable to watch New York as a possible state template. It is not reasonable to turn that possibility into a rule for utilities in other states. For non-New York systems, the federal AWIA calendar remains the binding baseline unless another state-specific requirement applies.

Incident context, with attribution left where the agencies left it

The July 2026 PLC activity is relevant to inspection posture and board urgency, but it does not change the statutory deadlines. On July 30, 2026, the FBI and EPA issued a public service announcement warning that malicious cyber actors were targeting water and wastewater sector internet-facing programmable logic controllers and causing operational disruptions [10]. CISA issued a same-day alert urging water and wastewater systems to protect OT against activity targeting PLCs [11].

Secondary reporting also notes reports of more than 30 Minnesota systems affected and incidents in at least seven states, but the agency materials cited here should be read carefully: no U.S. agency source in this record formally attributes the campaign to a named state actor. For compliance purposes, the useful point is narrower. Internet-facing PLCs are now a current inspection and governance fact, not an abstract OT risk.

For an in-scope community water system, the legal file should be organized around the duty being certified, not around a maturity model. The following items are the minimum documentary anchors counsel will want before the next filing, inspection, enforcement response, or board vote:

  • Population served, with the source used to place the system in the AWIA band.
  • Current AWIA Round 2 RRA and ERP deadline, with the applicable population band.
  • Date the RRA was last reviewed or revised, and who approved it.
  • Date the ERP was last reviewed or revised, and who approved it.
  • A short OT/ICS scope statement identifying SCADA, PLC, remote-access, vendor-access, and emergency operations assumptions considered in the RRA and ERP.
  • A list of known access-control exceptions, especially default passwords, shared accounts, and former-employee access, with remediation status.
  • A CIRCIA placeholder workflow marked “expected, not final,” unless and until the final rule is issued.
  • For New York utilities, separate wastewater and drinking-water entries with adoption status checked against current state materials.

This is also the point at which procurement language should stop promising more than the utility can prove. If a vendor manages remote access to a PLC environment, the utility still needs a record showing how that access was considered in the RRA and ERP. If the utility’s emergency response plan assumes manual operation, someone should be able to identify who can perform it, under what conditions, and whether that assumption has been tested or merely repeated.

Status conclusion as of August 5, 2026

As of Q3 2026, the enforceable federal map for U.S. community water systems is compact: AWIA Section 2013 applies to community water systems serving more than 3,300 people, runs on a five-year RRA and ERP recertification cycle, and is backed by EPA enforcement risk. For systems serving 50,000 to 99,999 people, the current ERP deadline has already passed. For systems serving 3,301 to 49,999 people, the current RRA deadline has already passed and the ERP deadline is December 31, 2026.

The map is also close to change. CIRCIA reporting is expected in September 2026 but is not yet binding. CISA Act liability protections and SLCGP funding currently expire September 30, 2026. New York’s wastewater and proposed drinking-water requirements add a state-law overlay that must be tracked by rule status, not by headline. That is enough work for one calendar without pretending that every voluntary OT cybersecurity recommendation is already a legal requirement.

References

  1. New Risk Assessment and Emergency Response Plan Requirements for Community Water Systems, Federal Register, March 27, 2019.
  2. AWIA Section 2013, U.S. Environmental Protection Agency.
  3. AWIA Resources, Minnesota Rural Water Association.
  4. EPA ramps up enforcement against water utilities with poor cyber practices, Cybersecurity Dive.
  5. EPA Warns Water Utilities Against Cyberattacks, ABA Business Law Today, November 2025.
  6. CIRCIA, other big cyber rules expected to get finalized this fall, Federal News Network, July 7, 2026.
  7. Water Utilities: Congress Temporarily Extends Cyber Laws; EPA Releases New Guidance, Nossaman, November 19, 2025.
  8. Governor Hochul Announces New Nation-Leading Cybersecurity Regulations, Launches Grant Program, New York Governor’s Office, July 22, 2025.
  9. Water Utilities Cybersecurity Regulatory Compliance, Tenable, July 30, 2026.
  10. Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers Causing Operational Disruptions, Federal Bureau of Investigation, July 30, 2026.
  11. CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs, Cybersecurity and Infrastructure Security Agency, July 30, 2026.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory