Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    • Environmental Topics
    • Air
    • Bed Bugs
    • Cancer
    • Chemicals, Toxics, and Pesticide
    • Emergency Response
    • Environmental Information by Location
    • Health
    • Land, Waste, and Cleanup
    • Lead
    • Mold
    • Radon
    • Research
    • Science Topics
    • Water Topics
    • A-Z Topic Index
    • Laws & Regulations
    • By Business Sector
    • By Topic
    • Compliance
    • Enforcement
    • Laws and Executive Orders
    • Regulations
    • Report a Violation
    • Environmental Violations
    • Fraud, Waste or Abuse
    • About EPA
    • Our Mission and What We Do
    • Headquarters Offices
    • Regional Offices
    • Labs and Research Centers
    • Planning, Budget, and Results
    • Organization Chart
    • EPA History

Breadcrumb

  1. Home
  2. Water Resilience
  3. Cybersecurity

Cybersecurity Assessments

Learn about cybersecurity assessment resources available for drinking water and wastewater systems.

On this page: 

  • Cybersecurity Guidance for Drinking Water and Wastewater
  • Cybersecurity Risk Self-Assessment Resources
  • Cybersecurity Risk Third-Party Assessment Resources
  • Cybersecurity Vulnerability Assessment Resources
  • Identifying OT at Water Systems
  • Addressing Cybersecurity in your America’s Water Infrastructure Act Emergency Response Plan
  • Technical Assistance

Resources to Conduct Cybersecurity Assessment

Cybersecurity Guidance for Drinking Water and Wastewater 

  • EPA Guidance on Improving Cybersecurity at Drinking Water and Wastewater Systems (pdf) (447.51 KB)

Cybersecurity Risk Self-Assessment Resources

  • EPA: Water Cybersecurity Assessment Tool and Risk Mitigation Template (xlsx) (248.09 KB)
    • EPA: Water Cybersecurity Checklist Fact Sheets
  • CISA: Cyber Resilience Review
  • CISA: Cross-Sector Cybersecurity Performance Goals
  • CISA: Cybersecurity Evaluation Tool
  • NIST: Cybersecurity Framework
  • Critical Security Controls 

Cybersecurity Risk Third-Party Assessment Resources

  • EPA: Water Sector Cybersecurity Evaluation Program
    • Cybersecurity Evaluation Program Fact Sheet (pdf) (443.46 KB, February 2024, 810-F-24-001)
  • CISA: CISA Cybersecurity Advisor

Cybersecurity Vulnerability Assessment Resources

  • CISA: Cyber Vulnerability Scanning for Water Utilities

Identifying OT at Water Systems

  • Assessing if a Water & Wastewater System has Operational Technology (pdf) (366.06 KB, 03-15-2024, 810-F-23-031)

Addressing Cybersecurity in your America’s Water Infrastructure Act Risk and Resilience Assessment

Safe Drinking Water Act (SDWA) section 1433, which was amended by America’s Water Infrastructure Act (AWIA) section 2013 in 2018, requires community water systems (CWS) serving more than 3,300 people to prepare or revise risk and resilience assessments (RRAs) and certify to EPA that this work has been completed. SDWA section 1433(a) states that the RRA must include “electronic, computer, or other automated systems (including the security of such systems),” otherwise known as cybersecurity. Therefore, a cybersecurity assessment must be included in the required RRA. EPA provides the free resources to described above to support utilities in conducting a cybersecurity assessment, from a third-party option where a contractor conducts the assessment, using EPA’s Water Sector Evaluation Program to a do-it-yourself option, using the free Water Cybersecurity Assessment Tool.

Technical Assistance

Sign Up for Cybersecurity Technical Assistance: Primacy agencies, drinking water and wastewater systems, circuit riders, and technical assistance providers can submit a question and/or a request for consultation regarding cybersecurity.

EPA Technical Assistance and Evaluation Program

  • Cybersecurity Technical Assistance
  • Cybersecurity Evaluation Program

Water Resilience

  • Basics of Water Resilience
  • Water Resilience Tools
  • America's Water Infrastructure Act (AWIA)
    • AWIA Section 2013
    • AWIA Section 2018
  • Cybersecurity
    • Cybersecurity Assessments
    • Cybersecurity Planning
    • Cybersecurity Exercises and Technical Assistance
    • Cybersecurity Response
    • Cybersecurity Funding
  • Contamination
  • Supply Chain Resilience
    • Chemical Suppliers and Manufacturers Locator Tool
    • Defense Production Act
    • Safe Drinking Water Act Section 1441
  • Interdependencies
    • Emergency Services Sector
    • Energy Sector
    • Healthcare Sector
  • Preparedness Exercises
  • EPA Events
Contact Us about Water Resilience
Contact Us to ask a question, provide feedback, or report a problem.
Last updated on December 2, 2024
  • Assistance
  • Spanish
  • Arabic
  • Chinese (simplified)
  • Chinese (traditional)
  • French
  • Haitian Creole
  • Korean
  • Portuguese
  • Russian
  • Tagalog
  • Vietnamese
United States Environmental Protection Agency

Discover.

  • Accessibility Statement
  • Budget & Performance
  • Contracting
  • EPA www Web Snapshot
  • Grants
  • No FEAR Act Data
  • Plain Writing
  • Privacy
  • Privacy and Security Notice

Connect.

  • Data
  • Inspector General
  • Jobs
  • Newsroom
  • Regulations.gov
  • Subscribe
  • USA.gov
  • White House

Ask.

  • Contact EPA
  • EPA Disclaimers
  • Hotlines
  • FOIA Requests
  • Frequent Questions
  • Site Feedback

Follow.