Wastewater cybersecurity is no longer only an IT issue. For utilities across New York and New Jersey, SCADA systems, programmable logic controllers (PLCs), remote-access tools, network architecture, incident reporting, and emergency response plans now sit directly inside the regulatory conversation.
The requirements are not identical from one jurisdiction to the next. Some are legally binding. Others are federal guidance that regulators increasingly use as the baseline for reasonable controls.
The practical takeaway is straightforward: your utility needs to know which rules apply, who receives an incident report, and whether your OT environment can be restored safely if a system is compromised.
“Both the ability to supply water and manage wastewater are considered National Critical Functions.” : CISA, Water and Wastewater Systems Sector
The federal baseline: EPA, CISA, AWIA, and CIRCIA
There is not yet one standalone EPA cybersecurity regulation that applies uniformly to every wastewater facility in the United States. Instead, federal expectations come from several overlapping programs.
EPA cybersecurity guidance
EPA’s Guidance on Improving Cybersecurity at Drinking Water and Wastewater Systems is voluntary. EPA specifically states that the guidance does not impose legally binding requirements.
That does not make it irrelevant.
The guidance is built around the CISA Cybersecurity Performance Goals and identifies priority practices for water and wastewater systems, including:
- Maintaining a current inventory of IT and OT assets, reviewed at least quarterly.
- Eliminating unnecessary public-facing services and direct internet connections to OT.
- Changing default passwords and requiring multifactor authentication for remote access.
- Segmenting IT and OT networks through firewalls, jump boxes, or demilitarized zones.
- Backing up PLC logic, network configurations, engineering drawings, and critical records.
- Collecting and protecting system and network logs.
- Developing and exercising a cybersecurity incident response and recovery plan.
- Providing annual cybersecurity awareness training.
Utilities can use EPA’s Water Cybersecurity Assessment Tool to identify gaps and create a mitigation plan.
AWIA applies to certain drinking water systems
Section 1433 of the Safe Drinking Water Act, as amended by the America’s Water Infrastructure Act, applies to community water systems serving more than 3,300 people. It requires a Risk and Resilience Assessment (RRA) and Emergency Response Plan (ERP).
The RRA must address “electronic, computer, or other automated systems,” including the security of those systems. The ERP must incorporate strategies and resources for cybersecurity.
This requirement applies to covered drinking water systems, not standalone wastewater-only utilities. However, many combined water and wastewater utilities operate shared networks, staff, vendors, or remote-access platforms. In those cases, the cyber risk assessment should account for the full operational environment.
CIRCIA is coming, but timing matters
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 will establish mandatory federal reporting requirements for covered entities. The Water and Wastewater Systems Sector is one of the critical infrastructure sectors included in the law.
The commonly discussed reporting windows are:
- 72 hours to report a covered cyber incident after the entity reasonably believes it occurred.
- 24 hours to report a ransomware payment.
As of August 17, 2026, the final CIRCIA rule is not yet in effect. Utilities should monitor CISA’s CIRCIA page and prepare for the expected reporting structure, but should not describe the federal 72-hour or 24-hour CIRCIA deadlines as currently operative.
That distinction matters. New York already has its own enforceable wastewater incident reporting requirements.

New York: immediate reporting duties and 2027 POTW controls
New York has moved faster than most states by adding wastewater cybersecurity requirements to its SPDES program.
All SPDES permittees: report incidents within 24 hours
Under 6 NYCRR 750-2.7(h), all SPDES permittees must report cybersecurity incidents affecting systems or data relevant to SPDES-regulated activities.
The requirements include:
- An oral report to the DEC Regional Water Engineer as soon as possible, and no later than 24 hours after becoming aware of the incident.
- A written follow-up report within 30 days.
- Information such as the discovery date and time, affected systems, incident description, and known or suspected impacts, to the extent known.
The incident reporting requirement took effect on March 26, 2026. It applies to municipal, industrial, and other SPDES permittees: not only publicly owned treatment works.
Review the NYSDEC wastewater cybersecurity resources and your facility’s SPDES permit conditions before an incident occurs. A reporting process that exists only in someone’s memory is not a reliable compliance process.
POTWs: ERP and cybersecurity incident response plans
Publicly Owned Treatment Works have additional obligations under 6 NYCRR 750-2.9.
POTWs must maintain an Emergency Response Plan that addresses wastewater emergencies and incorporates cybersecurity response. The cybersecurity Incident Response Plan must be integrated into the overall ERP rather than maintained as a disconnected IT document.
The required controls include:
- Written access control and authentication procedures.
- Vulnerability management procedures.
- A written description of secure network architecture and external connections.
- An incident response plan coordinated with the ERP.
- Controls addressing OT, IT, remote access, and operational continuity.
These requirements take effect on March 11, 2027, with the first annual certification of compliance due on or before March 28, 2027.
POTWs with a design flow of 10 million gallons per day or more also face network monitoring and logging requirements for relevant OT and SCADA environments.
New York’s rules also connect cybersecurity to operator training. Certified wastewater treatment plant operators must complete cybersecurity-related continuing education within the existing certification renewal framework.

New Jersey: know whether the utility falls under BPU jurisdiction
New Jersey’s requirements depend heavily on the utility’s regulatory status.
BPU-regulated water and wastewater utilities
The New Jersey Board of Public Utilities Cyber Security Program Order, Docket AO16030196, applies to regulated water and wastewater utilities and covers two categories of critical systems:
- Industrial control systems, including SCADA.
- Customer information systems containing personal information.
The order requires a formal Cyber Security Program with:
- Defined executive oversight and accountability.
- An annual inventory of critical systems.
- An annual cyber risk assessment.
- Risk-based administrative, technical, physical, and compensating controls.
- Monitoring of critical-system logs and threat information.
- Timely vulnerability and patch management.
- Cyber incident reporting through the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC).
- A Cyber Security Incident Response Plan covering identification, response, and recovery.
- A plan exercise at least once every 24 months.
- Security awareness and role-specific training.
- Annual executive-level certification of compliance.
For specified ICS events, the BPU order requires reporting through NJCCIC within six hours of detection. Utilities should confirm their current reporting contacts, submission format, and internal escalation procedure rather than relying on an outdated copy of the order.
WQAA applies primarily to drinking water systems
The New Jersey Water Quality Accountability Act applies to public community water systems with more than 500 service connections. It requires a cybersecurity program aligned with NJCCIC requirements and recognized frameworks such as NIST, CIS Controls, or the ISO/IEC 27000 family.
The WQAA is directed at drinking water purveyors. It should not automatically be treated as a wastewater-only requirement. However, if a utility operates both drinking water and wastewater systems: or shares control networks, vendors, or personnel: the programs should be coordinated.
Review the NJDEP Water Quality Accountability Act resources and confirm whether the utility is also subject to BPU jurisdiction.
What a defensible 2026–2027 program looks like
A wastewater utility in New York or New Jersey should be able to answer these questions without opening a dozen disconnected files:
- What PLCs, HMIs, servers, sensors, VPNs, and remote-access tools connect to the OT environment?
- Which systems can affect treatment, pumping, disinfection, discharge monitoring, or alarm functions?
- Is OT separated from business IT and the public internet?
- Who can access the system, from where, and with what authentication?
- Which vendor accounts remain active?
- Where are backups of PLC logic, configurations, and network diagrams stored?
- Who contacts DEC, NJCCIC, CISA, law enforcement, insurers, and management?
- When was the incident response plan last exercised?
- Can operators run the facility safely in manual mode if SCADA becomes unavailable?

Do not treat cybersecurity as a separate binder
The strongest programs connect cybersecurity to operations, engineering, compliance, and capital planning.
That means documenting the actual plant: not a generic template. It means coordinating with operators, IT personnel, automation vendors, engineers, attorneys, and regulators. It also means updating the plan when a pump station, PLC, telemetry connection, or remote monitoring platform changes.
This is where a field-first, regulator-facing approach matters. Envicon Group helps clients coordinate complex environmental, civil, compliance, and infrastructure work across New York and New Jersey. We bring direct project leadership, clean documentation, regional agency familiarity, and real-time project visibility rather than sending your facility into a national consultant’s queue.
For utilities planning upgrades, permit work, emergency planning, or infrastructure improvements, cybersecurity should be built into the project from the start: not added after the design is complete.
The takeaway
For NY/NJ wastewater utilities, the compliance path is already moving:
- EPA guidance establishes the federal technical baseline.
- AWIA requires cybersecurity consideration for covered community drinking water systems.
- CIRCIA is expected to create mandatory federal reporting after its final rule becomes effective.
- New York requires 24-hour oral and 30-day written reporting for all SPDES permittees.
- New York POTWs must implement integrated ERP, incident response, network, and cybersecurity controls by March 2027.
- New Jersey BPU-regulated water and wastewater utilities must maintain formal cybersecurity programs for SCADA, ICS, and customer information systems.
The goal is not to produce another oversized report. The goal is to know what controls exist, who owns each decision, and how the facility keeps operating when technology fails.
Secure systems support compliant operations. Clear ownership keeps projects moving.
Sources and regulatory references
- EPA Cybersecurity Assessments for Drinking Water and Wastewater Systems
- EPA Cybersecurity Guidance for Drinking Water and Wastewater Systems
- CISA Water and Wastewater Systems Sector
- CISA, EPA, and FBI Top Cyber Actions for Securing Water Systems
- NYSDEC Wastewater Cybersecurity Resources
- New Jersey BPU Utility Cyber Security Program Order
- NJDEP Water Quality Accountability Act Resources
Talk with Envicon Group
Visit the Envicon Group website to learn how our environmental, civil engineering, compliance, and infrastructure teams help NY/NJ clients resolve complex project risks.
Call Envicon Group at (917) 764-2171 to speak with our team.
Request a free consultation and start building a clear compliance and project path.
![]()