Water Systems: New Cybersecurity Oversight Organization
This bill is currently in the hands of the House Committee on Transportation and Infrastructure and the Committee on Energy and Commerce. It has not moved since April 2025. These committees must review the proposal before it can move forward, but no action has occurred in over a year.
While protecting water from hackers is a popular goal, creating a new private organization with the power to fine local utilities may face pushback from some lawmakers and local governments.
Scores run from -100 (strongly harmful) to +100 (strongly beneficial) for each group, combining impact, certainty, scope, and duration ratings of 1-5. How impact scoring works
Owners and operators of covered water and wastewater systems, including smaller private utilities, face new mandatory cybersecurity requirements, annual self-attestations, five-year audits, and penalties of up to $25,000 per day for noncompliance. This creates new compliance costs and legal exposure for utility operators, particularly smaller systems near the 3,300-person threshold that may lack dedicated cybersecurity staff.
“A penalty imposed under paragraph (1) shall not exceed $25,000 per day the applicable owner or operator is in violation of a cybersecurity risk and resilience requirement approved by the Administrator under subsection (d).”
Referred to the Committee on Transportation and Infrastructure, and in addition to the Committee on Energy and Commerce, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Sent to a congressional committee for expert review. The committee decides whether this bill moves forward.
Referred to the Subcommittee on Water Resources and Environment.
Sent to a congressional committee for expert review. The committee decides whether this bill moves forward.
Introduced in House
The bill was officially filed and given a number. It now enters the legislative queue.
Lawmakers introduced legislation to authorize a collaborative approach to water sector cybersecurity through a new Water Risk and Resilience Organization. The bill seeks to leverage technical expertise from utilities and experts while maintaining federal oversight via the EPA.
Water industry groups are urging Congress to pass the Water Risk and Resilience Organization Establishment Act following a series of cyberattacks that disrupted physical operations in multiple states. The bill would create a NERC-like body for water systems under EPA oversight.
Federal authorities are investigating cyberattacks against municipal water systems in multiple states. The incidents have led to renewed support for legislation that would create an independent organization to develop mandatory cybersecurity requirements for the sector.
No votes or related bills recorded for this bill yet.
Document Type
Congressional Bill
Official Title
To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.
Analysis generated by AI. Always verify with official sources.