Water Cyber Shield Act Gives EPA $300M for Water Utility Cyber Rules
The bill bakes state flexibility and industry consultation into its design, answering the litigation that killed the Biden EPA's 2023 regulatory push.
TL;DR
Sens. Schiff and Klobuchar introduced the Water Cyber Shield Act, which would authorize $300 million annually from Drinking Water and Clean Water State Revolving Funds for EPA-led cybersecurity assessments, corrective-action mandates, and CIRCIA incident reporting at water and wastewater utilities. Systems would be tiered by size, with states deciding whether to self-regulate or let the EPA step in. It's the second major federal attempt to regulate water-sector cybersecurity after the Biden EPA's effort was sued and abandoned, and its drafters consulted those same groups to head off a repeat.
The Water Cyber Shield Act, introduced Monday by Sens. Adam Schiff (D-Calif.) and Amy Klobuchar (D-Minn.), is the second major federal attempt to impose cybersecurity requirements on the nation's water and wastewater utilities, and it's been designed to survive where the last one didn't. The bill would amend the Safe Drinking Water Act and the Clean Water Act to give the EPA authority to conduct cybersecurity assessments and mandate corrective action, backed by $300 million annually from Drinking Water and Clean Water State Revolving Funds. Utilities would also need to comply with incident reporting under CIRCIA once that rule is finalized.
The structure is the story. Requirements are tiered by system size. States decide whether to self-regulate or let the EPA step in. A technical advisory committee, staffed jointly by industry and government, would develop the cybersecurity standards, with CISA coordinating on threat information. Cybersecurity data submitted by utilities is exempt from public disclosure. Smaller systems get compliance flexibility and priority for federal financial assistance.
That architecture is a direct response to what happened the last time the EPA tried this. In 2023, the Biden administration moved to add cybersecurity checks to annual water system sanitary surveys under existing EPA authority. Water industry groups and multiple states sued, arguing the move would force rate increases on customers. The administration backed down. Since then, Iranian-linked groups and ransomware actors have hit at least 30 water and wastewater systems across roughly a dozen states, forcing some to operate manually. A Schiff spokesperson told The Record the office consulted those same industry groups and regulators during drafting. It was a preemptive move to close the legal exposure that sank the prior rule.
For the municipal IT director or compliance officer at a mid-sized utility, the bill is still far from operational reality. No committee markup is scheduled. CIRCIA's final rule isn't out. Remediation timelines, specific assessment standards, non-compliance penalties, and enforcement mechanisms aren't defined. What's on the table is the architecture: a federal mandate with state-level off-ramps, funded through existing channels, built explicitly to survive where its predecessor couldn't. That's more than the sector has had. It's also not yet law.
Published ·Deep Fathom