The bill strengthens cybersecurity for medium-and-larger water systems through standardized requirements and centralized technical support, but imposes new costs and fines, concentrates regulatory power in a non‑governmental body, and leaves smaller systems near the population threshold with uneven protection.
Water systems serving ≥3,300 people (and their customers) receive standardized cybersecurity and resilience requirements, reducing the risk of service disruptions from cyberattacks.
Owners and operators of covered systems get clear compliance schedules and phased rollouts, making implementation planning and budgeting easier.
Smaller and rural systems gain access to a single certified technical body that develops best-practice cybersecurity standards and technical support, helping systems that lack in‑house capacity upgrade defenses.
Owners and operators of covered water systems face fines up to $25,000 per day for violations, creating substantial potential financial liabilities.
Covered systems serving ≥3,300 people will incur ongoing compliance costs (including implementation and five‑year assessments), which may raise rates or strain local budgets.
Smaller systems just below the 3,300-population threshold may be excluded despite similar risks, producing uneven cybersecurity protection across communities.
Based on analysis of 2 sections of legislative text.
Establishes an EPA-certified Water Risk and Resilience Organization to develop, file, and help enforce cybersecurity and resilience requirements for drinking water and wastewater systems serving ≥3,300 people.
Official title: To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.
Introduced April 2, 2025 by Rick Crawford · Last progress April 2, 2025
Creates a new EPA-certified Water Risk and Resilience Organization (WRRO) that will set, propose, and help enforce cybersecurity and resilience requirements for drinking water and wastewater systems serving 3,300 people or more. The EPA Administrator must issue a final rule within 270 days to establish selection and certification procedures, and may certify one organization that meets technical, procedural, and independence criteria to develop and file cybersecurity risk and resilience requirements for covered systems.