- Cyberattacks were reported at water systems in at least seven states in July.
- More than 324 million people receive water from community water systems.
- Most community water systems are small and face different cybersecurity requirements.
- Federal inspectors have found problems with cybersecurity planning and compliance.
- Congress is considering grants, training and possible new cybersecurity standards.
Saturday, August 29, 2026 — Cyberattacks reported at water systems in at least seven states during July 2026 are putting a new spotlight on something most people rarely think about when they turn on a faucet: cybersecurity.
A new Congressional Research Service report
, released August 27, says the incidents have raised questions about how well the nation’s municipal water infrastructure is protected from cyber threats.
Water and wastewater systems are considered critical infrastructure. But the federal government’s cybersecurity efforts in the water sector have focused primarily on drinking water systems.
The issue is complicated because America’s water systems range from very small operations serving a few dozen people to large utilities serving millions.
Nearly 144,000 Public Water Systems.
The federal Safe Drinking Water Act applies to nearly 144,000 privately and publicly owned public water systems.
A public water system generally provides piped water to at least 15 service connections or regularly serves at least 25 people.
Nearly 49,500 are community water systems, meaning they serve the same residences year-round. Together, those systems provide water to more than 324 million people.
Most community water systems are relatively small.
The U.S. Environmental Protection Agency classifies 81 percent of them as small systems serving 3,300 people or fewer. Those small systems account for only about 7 percent of the population served by community water systems.
At the other end of the scale, fewer than 10 percent of community water systems serve populations of 10,000 or more. Those larger systems provide water to 84 percent of community water system customers.
That difference in size is important when it comes to federal cybersecurity requirements.
Larger Systems Must Assess Their Risks.
Community water systems serving more than 3,300 people are required to assess risks that could impair their ability to provide safe and reliable water.
Federal law requires those systems to conduct risk and resilience assessments and prepare emergency response plans.
Those assessments must consider threats from intentional acts as well as natural hazards. They also must evaluate infrastructure that includes electronic, computer and other automated systems and the security of those systems.
Water systems must then develop emergency response plans based on the risks they identify.
Every five years, they must review their assessments, revise them if necessary, and again certify their compliance to the Environmental Protection Agency.
For small systems, however, risk and resilience assessments and emergency response plans are voluntary.
Small Systems Face a Different Challenge.
The Congressional report
notes that federal cybersecurity policy has generally placed more requirements on larger water systems because disruptions there could affect far more people.
Larger utilities also may have greater financial and technical resources. The Congressional Research Service noted that their size can give them more ability to update technology, adopt new practices or hire security specialists.
Federal law also provides several forms of technical and financial assistance intended to help water systems improve their ability to withstand emergencies and cyber threats.
Congress has authorized programs for technical assistance, cybersecurity improvements, advanced technologies, and emergency response.
Some programs specifically address larger systems, while others can assist smaller community water systems.
Federal Reviews Have Found Problems.
Existing requirements have not eliminated concerns about cybersecurity.
The Congressional Research Service
cited a 2024 Environmental Protection Agency enforcement notice that identified significant compliance problems among larger systems.
According to the notice, more than “70% of systems inspected by EPA since September 2023 are in violation of basic SDWA Section 1433 requirements.”
Between 2020 and 2024, the Environmental Protection Agency conducted at least 100 enforcement actions involving violations of those requirements.
Another federal review found cybersecurity vulnerabilities at some large water systems.
In 2024, the Environmental Protection Agency’s Office of Inspector General assessed 1,062 water systems serving populations of 50,000 or more.
It identified 97 water systems serving approximately 26.6 million people as having critical or high-risk cybersecurity vulnerabilities.
Federal Oversight Has Faced Pushback.
Determining how far federal cybersecurity oversight should go has also created legal and policy disputes.
In March 2023, the Environmental Protection Agency issued a memorandum requiring states to evaluate the cybersecurity of water system operational technology during inspections known as sanitary surveys.
Stakeholders challenged that approach in court.
They argued that the agency had not complied with the federal Administrative Procedure Act when it issued the memorandum and that the expanded inspections exceeded the agency’s authority under the Safe Drinking Water Act.
The Environmental Protection Agency withdrew the memorandum and its requirements in October 2023.
Congress Considers New Cybersecurity Measures.
Members of the current Congress have introduced several proposals addressing water system cybersecurity.
The Water Resources Development Act of 2026 includes provisions that would expand or continue several cybersecurity programs.
Among other provisions, the bill would reauthorize funding authority for an existing resilience grant program, allow cybersecurity improvements under a grant program for small and disadvantaged communities, and add cybersecurity training to an existing water infrastructure workforce program.
It also would authorize wastewater cybersecurity grants and digital infrastructure grants.
Other bills before Congress take different approaches.
Some would create new grant programs. Others would continue funding authority for existing programs, expand oversight of water system vulnerability assessments or establish similar requirements for wastewater systems.
One proposal would establish a new system under which an independent organization would develop cybersecurity standards that water systems would be required to adopt.
Several water associations support that approach, according to the Congressional Research Service
.
More Rules Could Bring New Questions.
Congress faces several questions as lawmakers consider additional cybersecurity measures.
One is whether new grant programs would provide additional help or simply duplicate existing programs.
Funding is another issue.
The Congressional Research Service noted that Congress has not specifically appropriated funds for certain authorized cybersecurity technical assistance and grant programs. Other water resilience programs have received federal funding.
Congress also could consider establishing more specific cybersecurity standards for water system risk assessments and emergency planning.
But such standards could create challenges for systems already struggling to meet existing requirements.
There is also the question of who should oversee cybersecurity standards. Water agencies have expertise in drinking water, but questions have been raised about whether that expertise extends to cybersecurity.
Protecting Cybersecurity Information Is Another Concern.
More oversight could require water systems to share additional information about their weaknesses.
That creates a separate security concern.
If water systems were required to send vulnerability assessments to federal agencies, states, or another organization, those records could create a collection of information about weaknesses in water infrastructure.
According to the Congressional Research Service
, such a repository could itself become a target for cyberattack.
Third-party organizations providing cybersecurity assistance would also need to protect sensitive information about the systems they help.
Water Systems Are Different From the Electric Grid.
Congress is also considering whether the water sector could use a cybersecurity model similar to the one used by the electric industry.
There is an important difference between the two.
Electric systems are interconnected. An attack affecting part of the transmission network can potentially create problems across multiple states.
Water systems generally are not interconnected in the same way.
A cyberattack against a water system would therefore generally affect a single community rather than disrupt water service across several states.
That does not mean the consequences would necessarily be small.
Some individual water systems serve millions of people, and the Congressional Research Service noted that an attack resulting in problems such as water contamination could have significant effects.
The cyber incidents reported in July have now placed those risks before Congress as lawmakers consider whether the existing combination of local responsibility, federal requirements, voluntary measures, technical assistance and grants provides sufficient protection for the nation’s water systems.




