The Water Cyber Shield Act, introduced in the Senate on August 17, 2026 by Senators Adam Schiff (CA) and Amy Klobuchar (MN), would create a federal cybersecurity mandate for water and wastewater utilities — a direct response to the recent cyberattacks on Minnesota water systems that disrupted operations. For the roughly 50,000 small and mid-sized public water systems in the United States, the headline is simple: cybersecurity is no longer a large-utility problem. If you run a community water system, the obligations that matter are already partially on your books under the America’s Water Infrastructure Act (AWIA), and this bill builds directly on them. Check your water system’s compliance status free at orevant.com before you read on.

What the Water Cyber Shield Act would do

The bill would require water and wastewater systems to adopt baseline cybersecurity practices and to report cyber incidents to federal authorities. Its sponsors framed it around the reality that utilities serving small populations run on the same SCADA and remote-monitoring technology as large cities, but with a fraction of the IT staff — which makes them the soft target an attacker reaches first. While the exact thresholds and timelines will be set through rulemaking if the bill becomes law, the direction is unambiguous: cybersecurity readiness is moving from a best practice toward a compliance obligation.

See exactly what your system is up against

Search by system name or PWSID and get your EPA violation history, open requirements, and upcoming deadlines in under a minute. Free, no account, no obligation.

The obligation you already carry: AWIA Risk and Resilience Assessment

The part most small operators have not acted on is not the new bill — it is AWIA, which has been federal law since 2018. Under 42 U.S.C. §300i-2, every community water system serving more than 3,300 people must conduct a Risk and Resilience Assessment (RRA) covering both physical and cyber threats, submit a certification to the U.S. EPA, and then prepare or update an Emergency Response Plan (ERP) that incorporates the RRA findings. The certification deadlines were staggered by system size — 100,000+ by March 31, 2020; 50,000–99,999 by December 31, 2020; and 3,301–49,999 by June 30, 2021 — and the RRA and ERP must be reviewed and recertified every five years.

In practice, thousands of systems that crossed those deadlines years ago still have not completed the work or cannot locate their certification. That is a live gap, and it is exactly the gap a cyber-focused bill puts back under the microscope. See how to prepare for a state drinking water inspection.

Why small systems are the target now

The Minnesota incidents that prompted the bill were not attacks on a major metropolitan utility — they hit smaller systems, and the attackers gained access through routine remote-access and control-system pathways that were never locked down. A small system that loses remote access to its pumps, or that has its water-quality data encrypted and held, cannot deliver safe water and cannot prove compliance until it recovers. For a part-time operator or a volunteer board, that is not an IT inconvenience; it is an operational emergency with a public record.

What to do now, before the bill becomes law

Four actions put a small system ahead of whatever this bill becomes. First, confirm whether your AWIA RRA and ERP are current and certified — if you serve more than 3,300 people and cannot find the certification, treat it as overdue. Second, inventory your remote-access points: who can reach your SCADA, and is that access multi-factor and logged. Third, make sure an offline copy of your most recent sampling and reporting data exists so a cyber incident cannot erase your compliance record. Fourth, document all of it — the state inspector and the federal reviewer both ask for evidence, not intentions.

How Orevant maps this for your system

Orevant reads your system’s official EPA record and turns it into a plain-English compliance action plan: open violations, risk score, next deadlines, and the AWIA and cyber obligations that apply to your system size and type. The free lookup shows you the problem; the $199 compliance scan gives you the prioritized plan to close it.

Check your water system — free at orevant.com. When you are ready, get your compliance action plan for a one-time $199 fee.

FAQ

Does AWIA apply to my system?

It applies to every community water system serving more than 3,300 people, regardless of whether your state has primacy. Systems below that threshold are not covered by the RRA/ERP requirement, but many states apply similar expectations during sanitary surveys.

Is the Water Cyber Shield Act law yet?

No. As of its introduction in August 2026 it is proposed legislation. The requirements do not take effect unless and until it is enacted and implementing rules are issued — but the AWIA obligations it builds on are already federal law and already enforceable.

We completed our RRA years ago. Are we done?

No. AWIA requires a review and recertification every five years, and the ERP must be updated to reflect the current RRA. A certification from 2020 is expired, not current.