Why It Matters
More than 70% of water systems inspected by the Environmental Protection Agency (EPA) since September 2023 violate basic cybersecurity assessment requirements, according to a Congressional Research Service (CRS) report released on August 27. The report examined the implications of July 2026 cyberattacks on water utilities in at least seven states, where attackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The attacks exposed a stark vulnerability: 97 water systems serving approximately 26.6 million users have either critical or high-risk cybersecurity vulnerabilities.
Community water systems serve more than 324 million people across the country. An attack on a large system could disrupt service for millions, though water systems are not interconnected, so disruptions remain locally contained.
The Big Picture
The regulatory framework already exists. In 2018, Congress required community water systems serving more than 3,300 individuals to conduct risk-and-resilience assessments and prepare emergency response plans under the Safe Drinking Water Act (SDWA) Section 1433. The America's Water Infrastructure Act mandated that water systems evaluate electronic, computer, and automated systems in those assessments. Systems must self-certify compliance every five years.
Nearly 49,500 community water systems serve the country. Less than 10% serve populations of 10,000 or more, yet those larger systems serve 84% of all community water system customers. Risk-and-resilience assessment and emergency response plan requirements are voluntary for small water systems.
Between 2020 and 2024, EPA conducted enforcement actions for violations of the assessment requirements. Yet more than 70% of systems inspected by EPA since September 2023 remain in violation. In March 2023, EPA issued an interpretive memorandum requiring states to evaluate water system cybersecurity during routine sanitary surveys, and EPA rescinded that memorandum in October 2023.
The Trump administration's Infrastructure Investment and Jobs Act added a grant program for systems serving 10,000 or more to improve resilience and reduce cybersecurity vulnerabilities. It also authorized grants for advanced technologies including cybersecurity and required EPA and the Cybersecurity and Infrastructure Security Agency (CISA) to develop a framework identifying critical water systems and a Technical Cybersecurity Support Plan. Congress has not specified appropriations for cybersecurity technical assistance and grants under SDWA Section 1433(g) or for advanced technology grants under SDWA Section 1459G.
The Bottom Line
The July 2026 attacks revealed that regulatory requirements alone have not ensured compliance. With more than 70% of inspected systems still in violation and 97 systems identified as having critical vulnerabilities, Congress faces a choice: increase enforcement resources and appropriations for technical assistance, or rely on voluntary compliance and grant programs that remain unfunded.
Access the Legis1 platform for comprehensive political news, data, and insights
Spot something wrong? Report an issue with this article