The America's Water Infrastructure Act of 2018 (AWIA) changed what most U.S. community water systems must do to plan for hazards, from natural disasters to deliberate attacks and cyber incidents. If your system serves more than 3,300 people, you are already inside a recurring certification cycle that does not end after the first filing. Check your water system's compliance status free at orevant.com before you read on, because the five-year review clock is tied to your own filing date, not a national calendar. This article is compliance information, not legal advice. Confirm the deadlines that apply to your system with your state primacy agency.

The two requirements, plainly

AWIA added two sections to the Safe Drinking Water Act (SDWA): section 1433 (42 U.S.C. §300i-2) for the risk and resilience assessment, and section 1434 (42 U.S.C. §300i-3) for the emergency response plan.

See exactly what your system is up against

Search by system name or PWSID and get your EPA violation history, open requirements, and upcoming deadlines in under a minute. Free, no account, no obligation.

Risk and Resilience Assessment (RRA). A community water system must assess risks to the system from malevolent acts and natural hazards. The assessment must consider, at minimum, the physical security of the system; the cybersecurity of electronic, computer, and automated systems including industrial control systems and business systems; source water; monitoring practices; financial infrastructure; chemical storage, handling, and use; and operation and maintenance.

Emergency Response Plan (ERP). Within six months of certifying the RRA, the system must certify an emergency response plan that incorporates the assessment's findings and describes the strategies and resources to improve resilience and mitigate identified risks.

Who has to comply

The certification requirement applies to community water systems serving more than 3,300 people. The original filing deadlines were staggered by population: systems serving 100,000 or more certified their RRA by March 31, 2020 and ERP by September 30, 2020; systems serving 50,000 to 99,999 by December 31, 2020 and June 30, 2021; and systems serving 3,301 to 49,999 by June 30, 2021 and December 31, 2021. Systems serving 3,300 or fewer are not required to certify, though EPA and state primacy agencies strongly encourage it, and a state may impose stricter requirements of its own.

The five-year cycle most operators miss

The first filing was not the end. EPA requires each covered system to review, and update as necessary, its emergency response plan at least once every five years, and to recertify the plan to EPA. Systems that certified in the 2020 to 2021 window are now inside or approaching their second review cycle, with third-cycle deadlines following on the same rolling basis. Because the recertification is tied to the system's own prior filing date rather than a single national date, it is easy for a system to lose track of exactly when its own review is due. The practical risk is silent noncompliance: the obligation is ongoing, but the trigger date is specific to each system.

Why cybersecurity is now the headline risk

AWIA explicitly includes the cybersecurity of electronic, computer, and automated systems in the assessment scope. In 2021 a Florida water treatment plant was accessed remotely in an attempted poisoning incident, and since 2023 federal agencies have attributed a series of compromises of U.S. water and wastewater utility control systems to state-sponsored actors. EPA has since made clear that cybersecurity must be evaluated as part of the routine sanitary survey and that states should include it in their oversight.

For a small system, this does not mean running a dedicated security team. It means the RRA and ERP must actually document which systems are internet-exposed, who has remote access, how changes and backups are handled, and what the operator does first if a control system behaves unexpectedly. That documentation is what an inspector or an agency expects to see. See the Water Cyber Shield Act and small water systems for the newer obligations layered on top.

How a gap becomes a problem

An AWIA certification gap does not usually surface as a dramatic event. It surfaces during a state sanitary survey or an agency records review, when the system is asked to produce a current ERP and cannot. Missing, stale, or unrecertified plans are the kind of finding that can lead to a significant deficiency and required corrective action, on a schedule the system does not control.

What to do next

Confirm whether your system serves more than 3,300 people and is subject to AWIA certification. Locate your most recent RRA and ERP certifications and the date each was filed. Check the five-year review clock against your own last filing date, not a national calendar. Verify the ERP still reflects current staff, contacts, and the systems you actually operate. And confirm the cybersecurity portion covers remote access, internet-facing systems, backups, and incident response.

Orevant gives operators a system-specific view of the public compliance record tied to their PWS ID, so an AWIA review starts from the facts rather than a guess. The $199 compliance scan turns that record into a regulation-linked, prioritized action plan, and the $87 per month monitoring plan keeps the deadlines you are already inside from going silent.

Get Your Compliance Roadmap — $199 at orevant.com, so the next survey finds a current plan instead of a gap.

FAQ

Does my small water system have to certify an AWIA risk and resilience assessment?

Community water systems serving more than 3,300 people must certify. Systems at or below 3,300 are not required to, but states may impose their own requirements and EPA encourages a voluntary assessment and plan regardless.

How often do I have to update the emergency response plan?

At least once every five years, with recertification to EPA after each review. The clock is tied to your system's own prior filing date, so it does not fall on a single national date.

Does AWIA cover cybersecurity for a small system?

Yes. The assessment must consider the cybersecurity of electronic, computer, and automated systems, including industrial control systems and business systems, regardless of system size once the threshold applies.