Water Utility SCADA Compliance:
AWIA, EPA & IEC 62443
Water and wastewater utilities run some of the most targeted - and most thinly staffed - SCADA systems in critical infrastructure. Water utility SCADA compliance is a patchwork: America's Water Infrastructure Act mandates risk assessments and emergency response plans, EPA publishes guidance and checklists, a handful of states impose their own requirements, and voluntary frameworks like AWWA G430, NIST CSF, and IEC 62443 fill the gaps. This guide untangles which requirements actually bind you, walks the AWIA process and its five-year recertification cycle step by step, gives honest cost and effort ranges for utilities of every size, and lists exactly what to demand from a SCADA vendor before you connect it to a treatment plant or lift station.
From the Merobix industrial security hub - every security, compliance & certification guide in one place.
Why Water SCADA Is in the Regulatory Crosshairs
The driver behind every water-sector cyber rule is the same uncomfortable fact: treatment and distribution are now operated through remotely accessible control systems, and those systems have been repeatedly probed and, in publicly reported cases, manipulated. Incidents at water utilities - including the widely reported 2021 attempt to raise chemical dosing setpoints at a Florida treatment plant through remote-access software - showed regulators that a compromised SCADA session is a public-health event, not an IT inconvenience. Federal advisories since then have repeatedly warned of exposed HMIs, default credentials, and unpatched remote access at utilities of every size.
Congress responded with America's Water Infrastructure Act (AWIA) of 2018, EPA responded with guidance, assessment tools, technical assistance, and (briefly) an attempt at sanitary-survey enforcement, and states began layering their own requirements on top. The result is not one standard but a stack - and understanding which layer is mandatory for your utility is the first compliance task.
AWIA: The One Federal Mandate
AWIA Section 2013 is the binding core. It requires every community water system serving more than 3,300 people to:
- Conduct a Risk and Resilience Assessment (RRA) covering malevolent acts and natural hazards - including, explicitly, the resilience of "electronic, computer, or other automated systems," which means your SCADA, instrumentation, and remote access.
- Develop or update an Emergency Response Plan (ERP) within six months of certifying the RRA, incorporating what the assessment found - response strategies, mitigation actions, and detection capabilities for cyber events included.
- Certify completion to EPA on a population-based schedule, and review and recertify every five years.
The original certification deadlines fell in 2020 and 2021, staggered by size (systems serving 100,000 or more first, then 50,000 to 99,999, then 3,301 to 49,999). That means the second five-year cycle came due across 2025 and 2026 - large systems recertified by March 2025, mid-size by the end of 2025, and the smallest covered systems by mid-2026. If your recertification just passed or is imminent, this cycle is the natural moment to fix what the first assessment only documented.
Two important boundaries: AWIA prescribes assessment, not specific controls - it does not mandate MFA or segmentation, it mandates that you honestly evaluate whether their absence is a risk. And it covers drinking water only; wastewater systems are not covered by the Section 2013 mandate, though everything else in this guide applies to them operationally.
EPA Guidance, the Sanitary Survey Episode, and What Is Actually Enforceable
EPA supports the mandate with free tools and guidance: the VSAT assessment tool, a small-system RRA checklist, a water-sector cybersecurity checklist and technical-assistance program, and funding channels through state revolving funds. In March 2023, EPA went further and issued a memorandum requiring states to evaluate cybersecurity during sanitary surveys - effectively making cyber hygiene enforceable. After litigation from several states and industry associations, EPA withdrew that memorandum in October 2023. As of 2026, the federal posture remains assessment-based: AWIA binds, EPA guidance strongly recommends, and CISA advisories warn.
Do not read "withdrawn" as "over." Several states impose their own cybersecurity requirements on utilities - New Jersey, for example, requires covered water systems to implement cybersecurity programs, and other states fold cyber questions into permits, surveys, or funding conditions. Cyber insurers now ask utilities the same questions a regulator would. And further federal legislation for the water sector is a perennial live possibility. Utilities that build to the voluntary frameworks now are, in effect, pre-complying with whatever binding rule arrives next.
The Voluntary Stack: AWWA, NIST CSF, CISA Goals, and IEC 62443
Because AWIA does not tell you which controls to implement, the sector leans on a recognizable set of frameworks. The AWWA J100 standard supplies the risk-assessment methodology most consultants use for RRAs; AWWA G430 defines security practices for operations management; AWWA's cybersecurity guidance and assessment tool map controls specifically for water; NIST CSF provides the organizing functions (identify, protect, detect, respond, recover); CISA's Cross-Sector Cybersecurity Performance Goals give a prioritized minimum baseline; and the IEC 62443 series published by ISA and IEC supplies the OT-specific engineering detail - zones and conduits, security levels, and component requirements. For how 62443 security levels work and what to ask vendors about them, see our secure SCADA for OT networks guide.
| Standard / Rule | Issued By | Mandatory? | What It Gives a Water Utility |
|---|---|---|---|
| AWIA Section 2013 | US Congress / EPA | Yes - CWS serving 3,300+ | RRA + ERP obligation, certification deadlines, 5-year cycle |
| EPA guidance, VSAT, checklists | EPA | No (recommended) | Free assessment tooling, control checklists, technical assistance |
| AWWA J100 / G430 / cyber guidance | AWWA | No (industry standard) | RRA methodology, management practices, water-specific control mapping |
| CISA Cybersecurity Performance Goals | CISA | No (baseline) | Prioritized minimum controls: MFA, unique accounts, backups, no exposed services |
| NIST CSF / NIST SP 800-82 | NIST | No (framework) | Program structure and ICS-specific security engineering guidance |
| IEC 62443 | IEC / ISA | No (contractual/procurement) | OT security levels, zones and conduits, vendor and component requirements |
| State requirements | Individual states | Varies by state | Binding programs in some states (e.g., New Jersey); survey and permit conditions elsewhere |
The Compliance Process, Step by Step
- Confirm applicability. Community water system? Population served above 3,300? Note your size tier and next recertification date.
- Inventory the cyber estate. SCADA servers, HMIs, PLCs and RTUs at remote sites, radios and cellular links, remote-access paths, vendor connections, and who has credentials. Most utilities are surprised by what this list contains.
- Run the RRA using J100 methodology, VSAT, or the EPA small-system checklist - assessing malevolent-act risk (including cyber) and natural-hazard resilience across assets, and documenting consequences and countermeasures.
- Certify the RRA to EPA by your deadline; keep the assessment itself internal and protected.
- Update the ERP within six months - including cyber-incident response: who isolates the SCADA system, how you run the plant manually, who you notify (state, CISA, WaterISAC), and how you recover from backups.
- Remediate by priority. Close exposed remote access first, then MFA and unique accounts, then segmentation, monitored alarming, backups, and logging - the CISA goals are a sensible ordering.
- Exercise and review. Tabletop the cyber scenario annually, review access quarterly, and treat the five-year recertification as a re-baseline, not a paperwork ritual.
How Much Does AWIA Compliance Cost - and How Long Does It Take?
Ranges vary with system size, consultant rates, and how much you self-perform - treat these as planning figures. A small system using EPA's free checklist and VSAT can complete a credible self-assessment in a few dozen staff hours over four to eight weeks. Mid-size utilities engaging consultants for a J100-based RRA plus ERP update typically spend 15,000 to 60,000 dollars over two to five months; large multi-plant utilities can spend well into six figures. Remediation is where budgets actually move: enforcing MFA and killing exposed remote access can be nearly free, while historian upgrades, network segmentation, or SCADA replacement are capital projects. State revolving funds and periodic federal grant programs can offset both assessment and remediation costs - ask your state primacy agency what is currently open.
It is worth noting that modernizing the SCADA platform itself often costs less than armor-plating a legacy one. Our runs those numbers, and our water utility SCADA monitoring guide covers the operational side for treatment, distribution, and lift stations.
How Small Water Utilities Stay Secure Without a Security Engineer
Most US water systems are small, and many are operated by a handful of people who also fix pumps and read meters. Nobody at a 5,000-population system is hiring a security engineer - which is exactly why the platform choice carries so much of the security load. A cloud SCADA platform with an outbound-only gateway removes the exposed-port problem categorically: nothing at the plant listens for inbound connections, so there is nothing for scanners to find. Vendor-managed patching removes the unpatched-server problem. Built-in MFA, per-user accounts, and audit trails arrive as defaults instead of projects. This is the honest calculus for small operators: buy the controls as platform properties rather than trying to staff them - a theme we expand in SCADA security for small operators.
What to Look For in a SCADA Vendor for Water and Wastewater
Whatever vendor you evaluate - Merobix included - require evidence of the controls that map to the sector's actual failure patterns:
- No inbound exposure. Outbound-only gateway connectivity; no VNC, RDP, or port forwarding anywhere in the reference architecture.
- MFA and unique named accounts for every operator and contractor, with roles that separate viewing from control, and immediate revocation when people leave.
- Setpoint protection. Explicitly configured writable tags, bounds checking so a dosing setpoint cannot be commanded outside safe limits, and full audit records of every command - the direct countermeasure to the Florida-style scenario.
- Alarm delivery you can trust, with retry and failure visibility, because a missed high-chlorine alarm is the consequence that matters.
- Resilient telemetry - store-and-forward buffering for flaky rural cellular links, so outages produce late data rather than lost data.
- Evidence on demand. Exportable audit trails and access lists that drop straight into your RRA, ERP annexes, and insurer questionnaires.
Merobix was engineered around precisely this list: an outbound-only gateway with TLS and signed telemetry envelopes, TOTP and FIDO2 MFA with brute-force lockout, role- and site-scoped authorization, control-tag allowlists with setpoint bounds checking and command audit records, store-and-forward buffering, and immutable chained audit logs - with security-event delivery to email, SMS, webhooks, or your SIEM. On assurance, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and includes independent penetration testing in its ongoing validation program. The full architecture is documented on our security page, and you can pressure-test it against your RRA findings in a live demo.
Key takeaway: For a US water utility, only AWIA (and in some states, state law) binds you - but the assessment it mandates will surface the same gaps every framework targets: exposed remote access, shared logins, no MFA, unverified alarms, and untested backups. Close those five and you have satisfied the spirit of every guidance document in the stack; the five-year recertification cycle is your ready-made schedule for proving it stays closed.
Water systems run heavily on DNP3, and it is one of the few industrial protocols with a real authentication story - see what DNP3 Secure Authentication does and doesn’t solve.
Frequently Asked Questions
What does AWIA require from water utilities?
America's Water Infrastructure Act of 2018 (Section 2013) requires community water systems serving more than 3,300 people to conduct a Risk and Resilience Assessment covering malevolent acts and natural hazards - explicitly including the resilience of electronic, computer, and automated systems such as SCADA - and to develop or update an Emergency Response Plan within six months of certifying the assessment. Utilities certify completion to EPA on a schedule tied to population served, and must review and recertify every five years. The second five-year certification cycle ran through 2025 and 2026, so most covered utilities have recently recertified or are doing so now.
Does AWIA apply to wastewater systems?
No. AWIA Section 2013 covers community drinking water systems serving more than 3,300 people; wastewater utilities are not covered by that mandate. Wastewater cybersecurity is driven instead by voluntary frameworks (EPA guidance, CISA advisories, NIST CSF, WaterISAC resources), by state-level requirements in some states, and increasingly by cyber-insurance conditions. That said, wastewater SCADA has been repeatedly targeted in publicly reported incidents, and most utilities apply the same controls - MFA, no exposed remote access, audit logging, backups - across both water and wastewater operations because the attack surface is identical.
Is there a mandatory water utility SCADA compliance standard in the US?
Mostly no, as of 2026. AWIA mandates assessing cyber risk but does not prescribe specific controls. EPA attempted to add cybersecurity to sanitary surveys in 2023 but withdrew the memorandum after litigation, leaving federal requirements assessment-based rather than control-based. A few states have gone further with their own requirements, and federal legislation proposals continue to circulate. In practice, utilities build programs from EPA guidance and checklists, CISA cross-sector performance goals, AWWA standards (G430 and the J100 risk methodology), NIST CSF, and IEC 62443 - and funding, insurance, and state regulators increasingly expect evidence of those controls.
How much does AWIA compliance cost a utility?
It varies widely with system size and approach. EPA's VSAT tool and small-system checklists are free, and a small utility doing a self-assessment may spend mostly staff time - often a few dozen hours. Mid-size utilities using consultants for a J100-based Risk and Resilience Assessment plus Emergency Response Plan update commonly spend in the range of 15,000 to 60,000 dollars; large or complex utilities can spend six figures. Remediation is the bigger number: fixing findings like exposed remote access, missing MFA, flat networks, or unmonitored alarms can range from nearly free (configuration changes) to significant capital projects. These ranges are honest estimates and vary by region and scope.
What should a water utility require from a SCADA vendor?
Require the controls that close the failure patterns behind publicly reported water-sector incidents: no internet-exposed remote access (outbound-only gateway connectivity, no VNC or RDP), multi-factor authentication on every remote login, unique named accounts with role-based permissions, alarm delivery that is monitored and verified, audit trails of every setpoint change, setpoint bounds checking so a compromised session cannot command dangerous values, and store-and-forward buffering for unreliable rural links. Also ask how the vendor supports your AWIA evidence needs - exportable audit records, access reviews, and documentation - and how their own security program is validated.
Sources & Further Reading
- America's Water Infrastructure Act (AWIA) Section 2013: Risk and Resilience Assessments and Emergency Response Plans - US EPA
- Vulnerability Self-Assessment Tool (VSAT Web) - US EPA
- Cybersecurity in Sanitary Surveys (March 2023 memorandum and October 2023 withdrawal) - US EPA
- Advisory AA21-042A: Compromise of U.S. Water Treatment Facility - CISA
- Water and Wastewater Cybersecurity - CISA
- Cross-Sector Cybersecurity Performance Goals - CISA
- SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security - NIST
- ISA/IEC 62443 Series of Standards (overview) - ISA (full standards available for purchase from ISA/IEC)
Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.