惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
博客园 - Franky
MyScale Blog
MyScale Blog
L
LangChain Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
Stack Overflow Blog
Stack Overflow Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 司徒正美
量子位
A
About on SuperTechFans
C
Check Point Blog
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
小众软件
小众软件
Apple Machine Learning Research
Apple Machine Learning Research
I
InfoQ
V
Visual Studio Blog
Vercel News
Vercel News
B
Blog
爱范儿
爱范儿
aimingoo的专栏
aimingoo的专栏
U
Unit 42

Tenable Blog

Oracle September 2026 Critical Security Patch Update | Tenable® ASD Essential Eight is changing: What you need to know How it works: Inside the agentic harness for Tenable Hexa AI Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI September 2026 Microsoft Patch Tuesday | Tenable® Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View” CVE-2026-75650: StyleSmuggler Adobe Commerce FAQ | Tenable® Why post-quantum defense starts with crypto visibility Building an exposure management program the business tr Tenable & SentinelOne: 93 CVEs Expose Edge Risk | Tenable® Siemens S7 PLC threat: What you need to know | Tenable® Oracle Critical Security Patch Update August 2026 | Tenable® How to detect & respond to cloud ransomware attacks in Azure Agentic AI Threat Cluster: What It Means for Your Exposure August 2026 Microsoft Patch Tuesday | Tenable® Agentic AI for Cybersecurity: See Security Teams Built at Black Hat USA 2026 An inside look at code security with Claude Mythos Preview Watch Tenable Hexa AI automate remediation with agentic routines How Claude Mythos Preview is changing code security at Tenable What Canada’s Bill C-8 means for critical infrastructure security Minnesota Water Cyber Attack and CISA Advisory AA26-097A Oracle July 2026 Critical Patch Update 1235 CVEs | Tenable® AI agent config attacks: How attackers turn trusted Dev harness files into payloads wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs
What do federal & state cyber rules mean for water utilit...
Kate Boronkay · 2026-07-31 · via Tenable Blog

What water utilities need to know about cybersecurity compliance

Water utility cybersecurity compliance 2026 deadlines regulations

As federal enforcement tightens and states begin stepping in with their own cybersecurity mandates, water and wastewater utilities face a looming wave of hard compliance deadlines, compounded by recent cyber attacks on state water utilities.

Key takeaways

  1. While the EPA’s national sanitary-survey mandate stalled in court, the agency is aggressively using existing authority, technical guidance, and enforcement alerts to inspect cyber gaps.
     
  2. Community water systems serving 3,301 to 49,999 people, the vast majority of U.S. systems, must certify their Risk and Resilience Assessments (RRAs) by June 30, 2026, under AWIA 2013.
     
  3. New York has already finalized binding cybersecurity regulations for wastewater facilities, setting a regulatory template that other states are expected to follow in 2026 and 2027.
     
  4. Under CIRCIA, utilities will soon be legally required to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours.
     
  5. Federal grant programs (SLCGP) and liability protections have been extended through Sept. 30, 2026, but remain tied to unpredictable budget cycles while targeted cyber threats continue to rise.

Navigating the new reality of water cyber regulation

In 2023, the U.S. EPA made an initial push to fold cybersecurity evaluations into state sanitary surveys. While that effort was stayed in court and subsequently withdrawn, the underlying federal statutory requirements and enforcement drivers remain fully active. Instead of relying on new survey rules, federal and state regulators are actively using existing statutory authority and technical guidance to shift water cybersecurity from voluntary recommendations to enforceable compliance deadlines.

The urgency to strengthen cybersecurity for water facilities is underscored by a recent coordinated cyber attack that disrupted water and wastewater utility operations across more than 30 Minnesota communities in late July 2026. 

Utility cyber regulations and mandates moving forward

America’s Water Infrastructure Act (AWIA) 2013 / Safe Drinking Water Act (SDWA) 1433 is still very much in force. 

Community water systems serving more than 3,300 people are legally required to certify a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP) to EPA on a five-year recertification cycle, and that cycle explicitly covers cyber threats, not just physical and natural hazards. 

Recertification deadlines:

  • Systems serving 100,000-plus people: March 31, 2025
  • 50,000–99,999 tier: Dec. 31, 2025
  • 3,301–49,999 tier, the vast majority of U.S. water systems: June 30, 2026, with ERPs due six months after.

The EPA hasn’t stopped pushing on cyber. It’s just doing it through guidance, technical assistance, and enforcement of existing authority rather than new rulemaking. 

In May 2024, the EPA issued an enforcement alert warning it would step up inspections tied to cybersecurity gaps found in drinking water systems. 

On Oct. 23, 2025, the EPA released an updated package of cyber tools: 

These tools are designed to help utilities fold cybersecurity directly into the RRA/ERP process they’re already required to complete.

States are stepping in where EPA stepped back

With the EPA’s national sanitary-survey mandate dead, states have started writing their own cybersecurity rules for water systems. New York is the clearest example: In March 2026, the New York State Department of Environmental Conservation finalized amendments to six New York Codes, Rules and Regulations (NYCRR) Parts 616, 650 and 750, adding binding cybersecurity regulations for wastewater treatment facilities, including mandatory incident reporting and access-control requirements built around EPA’s own cybersecurity guidance, incorporated into the rule by reference. Reporting requirements took effect March 26, 2026.

It’s a template other states are watching closely. Expect more state environmental and public utility regulators to follow New York’s lead in 2026 and 2027, particularly for wastewater systems, which (unlike drinking water) aren’t covered by AWIA and have largely operated without any federal cyber requirement at all.

Incident reporting is coming, whether or not utilities are ready

The U.S. Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) will require covered entities, including water and wastewater utilities, to report significant cyber incidents to CISA within 72 hours from the time the organization reasonably believes the incident has occurred, and report ransom payments within 24 hours of disbursement. Updated rules are expected to be finalized later in 2026. 

Utilities that wait for the rule to be finalized before building an incident response and reporting process will be scrambling; the smarter move is treating CIRCIA as if it is already in effect operationally.

Utility funding and information-sharing protections are back, for now

Two other pieces of the federal picture utilities lean on lapsed and were restored, but neither is fully settled:

The threat picture hasn’t waited for policy to catch up

The pattern since 2023 has kept on rising while the regulatory framework caught up.

How Tenable can help

Whether a utility’s driver is an RRA/ERP recertification deadline, a state mandate like New York’s, CIRCIA readiness, or simply defending against an increasingly aggressive threat landscape, the underlying work is the same: know what’s on the network, know what’s vulnerable, and be able to prove it.

Tenable One OT Exposure gives water and wastewater utilities:

  • Deep visibility across converged IT/OT environments by replacing the spreadsheet-based inventories EPA and state auditors increasingly ask utilities to move past, and giving utilities the documented OT/IT asset baseline that RRAs, state cyber rules, and CIRCIA readiness all assume exists.
  • Vulnerability management purpose-built for OT/ICS via Tenable’s proprietary hybrid discovery approach, including passive network monitoring and Safe Active Query capabilities to identify and prioritize exposed ports, default credentials, and outdated firmware that inspectors look for.
  • Continuous threat detection and monitoring through policy, anomaly, and signature-based detection tuned to OT protocols, giving utilities the evidence base (not just a policy on paper) that EPA’s updated guidance and state regulators now ask for.
  • Documentation utilities can hand to an auditor or regulator, including configuration change tracking, centralized log storage, and network topology documentation that maps directly to RRA, ERP, and CIRCIA reporting requirements.

The City of Raleigh, for example, uses Tenable One OT Exposure to spend less time chasing asset inventory manually and more time investigating real threats and remediating vulnerabilities across its water systems.

Tenable is recognized as a leader in industrial control systems security and trusted by more than 40,000 organizations worldwide. As the compliance landscape shifts from “encouraged” to “required,” deadline by deadline, state by state, Tenable gives water and wastewater utilities the visibility and evidence they need to stay ahead of it.

Learn more

Learn more

  • OT Security
  • SCADA