CRS maps three paths for water-sector cyber standards
Voluntary coordination failed, the 2023 EPA memo got sued out of existence, and now Congress is staring at three bills with no shared theory of how to set standards, fund compliance, or enforce either.
TL;DR
A new Congressional Research Service report catalogs the legislative options for water-sector cybersecurity after July 2026 attacks hit utilities in seven states. Three competing approaches are on the table: Capito's WRDA bill funds technical assistance under existing SDWA authorities; the Schiff-Klobuchar package directs EPA to set baseline cybersecurity standards through rulemaking; and the Trahan-Markey bill creates a wastewater cyber grant program. The CRS report flags unresolved questions on whether standards would apply uniformly to the roughly 170,000 U.S. water systems (many already struggling with existing SDWA requirements) and whether EPA or state regulators have the expertise to oversee them.
The Congressional Research Service published a report last week that does what CRS does best: lays out the menu without picking from it. The report, dated August 27, reviews every legislative proposal currently in play for strengthening water-sector cybersecurity, and the picture it draws is one of genuine fragmentation, not the performative kind, but three distinct theories of what the problem is and who should fix it.
Three bills, three theories of the problem
The bills fall into three camps. Senate EPW Chair Shelley Moore Capito's WRDA bill (advanced out of committee July 15) treats the gap as a funding and coordination problem: it provides cybersecurity technical assistance and workforce training through existing SDWA authorities without imposing new mandates. The Schiff-Klobuchar package, introduced August 10, treats the gap as a regulatory vacuum: it directs EPA to promulgate baseline cybersecurity standards through rulemaking and authorizes the agency to conduct assessments of water utilities, with states allowed to volunteer for enforcement. The Trahan-Markey bill treats the gap as a resource problem: it creates a wastewater cybersecurity grant program under SDWA.
CRS doesn't rank them, but it does surface the tensions a legislator would have to resolve to pick any one path. The report asks whether new grant programs duplicate existing ones, EPA announced $9.5 million in competitive grants for midsize and large drinking water systems in 2025, and Congress has never specified appropriations for cybersecurity technical assistance under SDWA. It asks whether EPA or state regulators actually have the expertise to develop or oversee cybersecurity standards. And it asks whether uniform baseline standards make sense for a sector where 170,000 systems range from municipal utilities serving millions to rural districts with a handful of employees.
The 2023 memo is the ghost at this table
The report anchors the urgency in the July 2026 attacks, CISA linked them to increased threat activity targeting internet-exposed programmable logic controllers in a July 30 advisory, and the FBI and EPA published a concurrent alert detailing operational disruptions. But the structural story is older. In 2023, EPA issued an interpretive memorandum directing states to include cybersecurity assessments in sanitary surveys under the SDWA. Three states plus the American Water Works Association and the National Rural Water Association sued, and EPA withdrew the memo, leaving the agency with no explicit statutory authority to mandate cybersecurity assessments. The GAO had already flagged this in its August 2024 report, finding that EPA hadn't conducted a sector-wide risk assessment and was relying on voluntary cooperation. GAO's May 2026 testimony to the House Environment Subcommittee reiterated the finding.
Vulnerability assessments and the information-sharing paradox
CRS raises a specific structural tension that none of the bills fully resolves. Proposals requiring water systems to submit vulnerability assessments to EPA, states, or an independent organization would create, in CRS's words, "a repository of water system vulnerabilities that could be targeted for a cyberattack." The same concern extends to third-party technical assistance providers. This isn't hypothetical, it's the same dynamic that has shaped CISA's information-sharing architecture for years, and CRS is effectively warning that a mandatory assessment regime designed to reduce risk could concentrate it instead.
The energy-sector model and its limits
The report also examines the Water Risk and Resilience Organization Establishment Act from Rep. Rick Crawford, backed by water-sector trade associations, which would create an industry-driven standards body modeled on the North American Electric Reliability Corporation in the electricity sector. CRS notes the structural difference that limits the analogy: water systems aren't interconnected the way the electric grid is. An attack on one utility disrupts a community, not several states. But the report undercuts the comfort that fact might provide, noting that "some systems serve millions of people."
The CRS report doesn't resolve which path Congress takes. What it does (and does well) is document that the current regime relies on voluntary coordination that GAO has repeatedly found insufficient, that the one attempt at regulatory action through existing authority was successfully litigated into withdrawal, and that the legislative response is proceeding on three parallel tracks with no shared framework for standards, funding, or enforcement.
Published ·Deep Fathom