Compliance & Certifications • Water Sector

Water Utility SCADA Compliance:
AWIA, EPA & IEC 62443

Merobix Engineering • • 11 min read

Water and wastewater utilities run some of the most targeted - and most thinly staffed - SCADA systems in critical infrastructure. Water utility SCADA compliance is a patchwork: America's Water Infrastructure Act mandates risk assessments and emergency response plans, EPA publishes guidance and checklists, a handful of states impose their own requirements, and voluntary frameworks like AWWA G430, NIST CSF, and IEC 62443 fill the gaps. This guide untangles which requirements actually bind you, walks the AWIA process and its five-year recertification cycle step by step, gives honest cost and effort ranges for utilities of every size, and lists exactly what to demand from a SCADA vendor before you connect it to a treatment plant or lift station.

Back to Blog

From the Merobix industrial security hub - every security, compliance & certification guide in one place.

3,300+Population Served Triggers AWIA
6Months to ERP After RRA Certification
5Year Review & Recertification Cycle

Why Water SCADA Is in the Regulatory Crosshairs

The driver behind every water-sector cyber rule is the same uncomfortable fact: treatment and distribution are now operated through remotely accessible control systems, and those systems have been repeatedly probed and, in publicly reported cases, manipulated. Incidents at water utilities - including the widely reported 2021 attempt to raise chemical dosing setpoints at a Florida treatment plant through remote-access software - showed regulators that a compromised SCADA session is a public-health event, not an IT inconvenience. Federal advisories since then have repeatedly warned of exposed HMIs, default credentials, and unpatched remote access at utilities of every size.

Congress responded with America's Water Infrastructure Act (AWIA) of 2018, EPA responded with guidance, assessment tools, technical assistance, and (briefly) an attempt at sanitary-survey enforcement, and states began layering their own requirements on top. The result is not one standard but a stack - and understanding which layer is mandatory for your utility is the first compliance task.

AWIA: The One Federal Mandate

AWIA Section 2013 is the binding core. It requires every community water system serving more than 3,300 people to:

The original certification deadlines fell in 2020 and 2021, staggered by size (systems serving 100,000 or more first, then 50,000 to 99,999, then 3,301 to 49,999). That means the second five-year cycle came due across 2025 and 2026 - large systems recertified by March 2025, mid-size by the end of 2025, and the smallest covered systems by mid-2026. If your recertification just passed or is imminent, this cycle is the natural moment to fix what the first assessment only documented.

Two important boundaries: AWIA prescribes assessment, not specific controls - it does not mandate MFA or segmentation, it mandates that you honestly evaluate whether their absence is a risk. And it covers drinking water only; wastewater systems are not covered by the Section 2013 mandate, though everything else in this guide applies to them operationally.

EPA Guidance, the Sanitary Survey Episode, and What Is Actually Enforceable

EPA supports the mandate with free tools and guidance: the VSAT assessment tool, a small-system RRA checklist, a water-sector cybersecurity checklist and technical-assistance program, and funding channels through state revolving funds. In March 2023, EPA went further and issued a memorandum requiring states to evaluate cybersecurity during sanitary surveys - effectively making cyber hygiene enforceable. After litigation from several states and industry associations, EPA withdrew that memorandum in October 2023. As of 2026, the federal posture remains assessment-based: AWIA binds, EPA guidance strongly recommends, and CISA advisories warn.

Do not read "withdrawn" as "over." Several states impose their own cybersecurity requirements on utilities - New Jersey, for example, requires covered water systems to implement cybersecurity programs, and other states fold cyber questions into permits, surveys, or funding conditions. Cyber insurers now ask utilities the same questions a regulator would. And further federal legislation for the water sector is a perennial live possibility. Utilities that build to the voluntary frameworks now are, in effect, pre-complying with whatever binding rule arrives next.

The Voluntary Stack: AWWA, NIST CSF, CISA Goals, and IEC 62443

Because AWIA does not tell you which controls to implement, the sector leans on a recognizable set of frameworks. The AWWA J100 standard supplies the risk-assessment methodology most consultants use for RRAs; AWWA G430 defines security practices for operations management; AWWA's cybersecurity guidance and assessment tool map controls specifically for water; NIST CSF provides the organizing functions (identify, protect, detect, respond, recover); CISA's Cross-Sector Cybersecurity Performance Goals give a prioritized minimum baseline; and the IEC 62443 series published by ISA and IEC supplies the OT-specific engineering detail - zones and conduits, security levels, and component requirements. For how 62443 security levels work and what to ask vendors about them, see our secure SCADA for OT networks guide.

Standard / Rule Issued By Mandatory? What It Gives a Water Utility
AWIA Section 2013US Congress / EPAYes - CWS serving 3,300+RRA + ERP obligation, certification deadlines, 5-year cycle
EPA guidance, VSAT, checklistsEPANo (recommended)Free assessment tooling, control checklists, technical assistance
AWWA J100 / G430 / cyber guidanceAWWANo (industry standard)RRA methodology, management practices, water-specific control mapping
CISA Cybersecurity Performance GoalsCISANo (baseline)Prioritized minimum controls: MFA, unique accounts, backups, no exposed services
NIST CSF / NIST SP 800-82NISTNo (framework)Program structure and ICS-specific security engineering guidance
IEC 62443IEC / ISANo (contractual/procurement)OT security levels, zones and conduits, vendor and component requirements
State requirementsIndividual statesVaries by stateBinding programs in some states (e.g., New Jersey); survey and permit conditions elsewhere

The Compliance Process, Step by Step

  1. Confirm applicability. Community water system? Population served above 3,300? Note your size tier and next recertification date.
  2. Inventory the cyber estate. SCADA servers, HMIs, PLCs and RTUs at remote sites, radios and cellular links, remote-access paths, vendor connections, and who has credentials. Most utilities are surprised by what this list contains.
  3. Run the RRA using J100 methodology, VSAT, or the EPA small-system checklist - assessing malevolent-act risk (including cyber) and natural-hazard resilience across assets, and documenting consequences and countermeasures.
  4. Certify the RRA to EPA by your deadline; keep the assessment itself internal and protected.
  5. Update the ERP within six months - including cyber-incident response: who isolates the SCADA system, how you run the plant manually, who you notify (state, CISA, WaterISAC), and how you recover from backups.
  6. Remediate by priority. Close exposed remote access first, then MFA and unique accounts, then segmentation, monitored alarming, backups, and logging - the CISA goals are a sensible ordering.
  7. Exercise and review. Tabletop the cyber scenario annually, review access quarterly, and treat the five-year recertification as a re-baseline, not a paperwork ritual.

How Much Does AWIA Compliance Cost - and How Long Does It Take?

Ranges vary with system size, consultant rates, and how much you self-perform - treat these as planning figures. A small system using EPA's free checklist and VSAT can complete a credible self-assessment in a few dozen staff hours over four to eight weeks. Mid-size utilities engaging consultants for a J100-based RRA plus ERP update typically spend 15,000 to 60,000 dollars over two to five months; large multi-plant utilities can spend well into six figures. Remediation is where budgets actually move: enforcing MFA and killing exposed remote access can be nearly free, while historian upgrades, network segmentation, or SCADA replacement are capital projects. State revolving funds and periodic federal grant programs can offset both assessment and remediation costs - ask your state primacy agency what is currently open.

It is worth noting that modernizing the SCADA platform itself often costs less than armor-plating a legacy one. Our runs those numbers, and our water utility SCADA monitoring guide covers the operational side for treatment, distribution, and lift stations.

How Small Water Utilities Stay Secure Without a Security Engineer

Most US water systems are small, and many are operated by a handful of people who also fix pumps and read meters. Nobody at a 5,000-population system is hiring a security engineer - which is exactly why the platform choice carries so much of the security load. A cloud SCADA platform with an outbound-only gateway removes the exposed-port problem categorically: nothing at the plant listens for inbound connections, so there is nothing for scanners to find. Vendor-managed patching removes the unpatched-server problem. Built-in MFA, per-user accounts, and audit trails arrive as defaults instead of projects. This is the honest calculus for small operators: buy the controls as platform properties rather than trying to staff them - a theme we expand in SCADA security for small operators.

What to Look For in a SCADA Vendor for Water and Wastewater

Whatever vendor you evaluate - Merobix included - require evidence of the controls that map to the sector's actual failure patterns:

Merobix was engineered around precisely this list: an outbound-only gateway with TLS and signed telemetry envelopes, TOTP and FIDO2 MFA with brute-force lockout, role- and site-scoped authorization, control-tag allowlists with setpoint bounds checking and command audit records, store-and-forward buffering, and immutable chained audit logs - with security-event delivery to email, SMS, webhooks, or your SIEM. On assurance, Merobix runs a SOC 2 readiness program, maps its controls to IEC 62443, and includes independent penetration testing in its ongoing validation program. The full architecture is documented on our security page, and you can pressure-test it against your RRA findings in a live demo.

Key takeaway: For a US water utility, only AWIA (and in some states, state law) binds you - but the assessment it mandates will surface the same gaps every framework targets: exposed remote access, shared logins, no MFA, unverified alarms, and untested backups. Close those five and you have satisfied the spirit of every guidance document in the stack; the five-year recertification cycle is your ready-made schedule for proving it stays closed.

Water systems run heavily on DNP3, and it is one of the few industrial protocols with a real authentication story - see what DNP3 Secure Authentication does and doesn’t solve.

Frequently Asked Questions

What does AWIA require from water utilities?

America's Water Infrastructure Act of 2018 (Section 2013) requires community water systems serving more than 3,300 people to conduct a Risk and Resilience Assessment covering malevolent acts and natural hazards - explicitly including the resilience of electronic, computer, and automated systems such as SCADA - and to develop or update an Emergency Response Plan within six months of certifying the assessment. Utilities certify completion to EPA on a schedule tied to population served, and must review and recertify every five years. The second five-year certification cycle ran through 2025 and 2026, so most covered utilities have recently recertified or are doing so now.

Does AWIA apply to wastewater systems?

No. AWIA Section 2013 covers community drinking water systems serving more than 3,300 people; wastewater utilities are not covered by that mandate. Wastewater cybersecurity is driven instead by voluntary frameworks (EPA guidance, CISA advisories, NIST CSF, WaterISAC resources), by state-level requirements in some states, and increasingly by cyber-insurance conditions. That said, wastewater SCADA has been repeatedly targeted in publicly reported incidents, and most utilities apply the same controls - MFA, no exposed remote access, audit logging, backups - across both water and wastewater operations because the attack surface is identical.

Is there a mandatory water utility SCADA compliance standard in the US?

Mostly no, as of 2026. AWIA mandates assessing cyber risk but does not prescribe specific controls. EPA attempted to add cybersecurity to sanitary surveys in 2023 but withdrew the memorandum after litigation, leaving federal requirements assessment-based rather than control-based. A few states have gone further with their own requirements, and federal legislation proposals continue to circulate. In practice, utilities build programs from EPA guidance and checklists, CISA cross-sector performance goals, AWWA standards (G430 and the J100 risk methodology), NIST CSF, and IEC 62443 - and funding, insurance, and state regulators increasingly expect evidence of those controls.

How much does AWIA compliance cost a utility?

It varies widely with system size and approach. EPA's VSAT tool and small-system checklists are free, and a small utility doing a self-assessment may spend mostly staff time - often a few dozen hours. Mid-size utilities using consultants for a J100-based Risk and Resilience Assessment plus Emergency Response Plan update commonly spend in the range of 15,000 to 60,000 dollars; large or complex utilities can spend six figures. Remediation is the bigger number: fixing findings like exposed remote access, missing MFA, flat networks, or unmonitored alarms can range from nearly free (configuration changes) to significant capital projects. These ranges are honest estimates and vary by region and scope.

What should a water utility require from a SCADA vendor?

Require the controls that close the failure patterns behind publicly reported water-sector incidents: no internet-exposed remote access (outbound-only gateway connectivity, no VNC or RDP), multi-factor authentication on every remote login, unique named accounts with role-based permissions, alarm delivery that is monitored and verified, audit trails of every setpoint change, setpoint bounds checking so a compromised session cannot command dangerous values, and store-and-forward buffering for unreliable rural links. Also ask how the vendor supports your AWIA evidence needs - exportable audit records, access reviews, and documentation - and how their own security program is validated.

Sources & Further Reading

Safety & engineering notice. This article is general educational information, not site-specific engineering, safety, or legal advice, and it does not reflect any particular facility. Standards and regulations (for example OSHA, API, IEC, ISO, NFPA, NIST, and NERC CIP requirements) change and vary by edition, jurisdiction, and application. SCADA and remote monitoring cannot verify physical isolation, atmosphere, lockout/tagout, permit status, or a safe go/no-go decision. Qualified personnel must perform site-specific engineering, hazard analysis, and safety review, and confirm current requirements with the authority having jurisdiction, before acting.

Close Your RRA Findings, Not Just File Them

Outbound-only gateways, MFA by default, setpoint bounds, and audit evidence on demand - see how Merobix fits water and wastewater operations of any size.

Request a Demo → See Our Security Architecture
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →