The Conventional Wisdom
Many water utility leaders view cybersecurity compliance as a mere checklist. Complete your Risk and Resilience Assessment (RRA) by the deadline. File your Emergency Response Plan (ERP) with the EPA. Check the boxes on the sanitary survey. Attend the webinar. You're compliant, so you're secure, right?
This mindset has persisted for years, bolstered by voluntary guidance and the assumption that federal regulators would continue to move slowly. When the EPA's 2023 sanitary survey mandate stalled in court and was withdrawn, many utility managers relaxed and returned to business as usual.
Why Compliance Isn't Enough
Believing compliance equals security is risky because it confuses paperwork with actual protection. You might certify a flawless RRA but still have default credentials on your SCADA system. You could file an ERP yet lack the visibility to detect intrusions promptly.
The compliance-first mindset also misreads regulatory changes. The EPA didn't retreat after its court loss; it changed tactics. The May 2024 enforcement alert clarified that the agency will aggressively inspect cyber gaps using its authority under the Safe Drinking Water Act. When New York finalized binding cybersecurity regulations for wastewater facilities in March 2026, it didn't wait for federal action. It incorporated EPA guidance by reference and made it enforceable at the state level.
You're not in a static compliance environment. States are crafting their own rules, federal agencies are reinterpreting existing authority, and CIRCIA will soon require you to report significant incidents to CISA within 72 hours.
The Evidence
Consider what regulators are inspecting. The EPA Inspector General found critical or high-severity vulnerabilities at 97 drinking water systems serving 27 million people. These weren't policy failures but operational gaps: exposed ports, outdated firmware, weak access controls.
The October 2025 EPA guidance package outlines agency expectations: a Cybersecurity Incident Response Plan template, incident-specific checklists, and a procurement checklist. These documents are the framework EPA inspectors will use during inspections.
The Minnesota coordinated attack in July 2026 disrupted operations across more than 30 communities. Iranian-affiliated actors continue targeting U.S. water infrastructure. The threat has been rising since 2023 and doesn't care if you filed your paperwork on time.
Here's the uncomfortable truth: compliance deadlines create urgency but not capability. Community water systems serving 3,301 to 49,999 people must certify their RRAs by June 30, 2026. If you're treating this as a documentation sprint rather than an operational transformation, you'll meet the deadline and still be vulnerable.
Strategic Actions for Utility Leaders
Assume your network is larger and more complex than you think. Most utilities underestimate their IT/OT convergence. You need continuous asset discovery that captures not just what's in your CMMS database, but what's actually communicating on your network. Passive monitoring combined with safe active queries will find forgotten devices and shadow IT deployed by operators.
Build your incident response process now, before CIRCIA's final rules are published. Don't wait for the 72-hour reporting requirement to become official. If you can't detect an incident, classify its severity, and escalate it to your leadership within 72 hours today, you won't develop that capability when the rule takes effect. Test your runbooks. Document your notification tree. Know who calls CISA and under what threshold.
Treat state regulations as the floor, not the ceiling. New York's wastewater rules are a template other states will follow. If you operate across multiple jurisdictions, map your program to the most stringent state requirement you're likely to face, not the federal baseline. You'll avoid the compliance whiplash of retrofitting your program every time another state publishes its own rule.
Align your vendor selection with operational needs, not just grant cycles. The State and Local Cybersecurity Grant Program (SLCGP) has lapsed and been reinstated twice in the past year. If your security roadmap depends entirely on SLCGP funding, you're building on sand. Identify the capabilities you need regardless of grant availability: vulnerability management, network segmentation, log aggregation, threat detection. Then pursue grants as accelerators, not enablers.
Stop treating vulnerability management as a quarterly scan. You need continuous monitoring with context. A critical vulnerability on an internet-facing HMI is not the same risk as the same vulnerability on an air-gapped historian. Prioritization matters. So does evidence. When an auditor asks how you're addressing the risks in your RRA, "we run Nessus once a quarter" won't satisfy them if you can't show what you did with the results.
When Compliance Matters
Compliance does matter if you treat it as a starting point for building real capabilities.
The RRA/ERP cycle is useful if approached honestly. The requirement to assess cyber threats alongside physical and natural hazards forces you to think holistically about resilience. The five-year recertification cycle gives you a structured opportunity to revisit assumptions and update your threat model.
Federal guidance, even when not mandatory, reflects real-world lessons. The EPA's October 2025 CIRP template incorporates years of incident response experience from across the sector. You don't have to start from scratch. Use it.
Grant funding, while unreliable, is still funding. If SLCGP dollars are available and your state is allocating them to water systems, take them. Just don't let the grant cycle dictate your security architecture.
And yes, meeting the June 30, 2026 deadline matters. Certification isn't optional. The utilities that ignore it will face enforcement action. But meeting the deadline while ignoring the operational gaps the RRA is supposed to surface is worse than being late. You'll be compliant on paper and compromised in practice.
The shift from voluntary to mandatory isn't a compliance problem. It's a capability problem. Treat it that way.



