Water and wastewater utilities in the U.S. face a converging set of cybersecurity compliance deadlines in 2026. Community water systems serving 3,301–49,999 people must certify Risk and Resilience Assessments (RRAs) by June 30, 2026 under AWIA. New York has finalized binding cybersecurity rules for wastewater facilities, setting a template other states are expected to follow. CIRCIA will soon require utilities to report significant cyber incidents to CISA within 72 hours and ransom payments within 24 hours. Federal grant programs (SLCGP) and liability protections have been extended through September 30, 2026, but remain tied to uncertain budget cycles. The threat landscape is worsening, with nearly 170,000 U.S. water systems identified as cyber-vulnerable and recent coordinated attacks on Minnesota water utilities. Tenable promotes its OT Security platform as a tool to help utilities achieve visibility, vulnerability management, and audit-ready documentation across IT/OT environments.

7m read timeFrom tenable.com
Post cover image
Table of contents
Key takeawaysNavigating the new reality of water cyber regulationUtility cyber regulations and mandates moving forwardStates are stepping in where EPA stepped backIncident reporting is coming, whether or not utilities are readyUtility funding and information-sharing protections are back, for nowThe threat picture hasn’t waited for policy to catch upHow Tenable can help
68 Impressions