US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements
The US Environmental Protection Agency (EPA) enforces cybersecurity requirements for public water systems under the Safe Drinking Water Act (SDWA). Key requirements include: America's Water Infrastructure Act (AWIA, 2018) Section 2013 mandating risk and resilience assessments including cyber risks, EPA enforcement actions for cybersecurity failures (using SDWA Section 1433), and EPA's 2023 memorandum requiring states to include cybersecurity in public water system sanitary surveys. EPA works with CISA to provide technical assistance. Applies to approximately 151,000 public water systems in the United States.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Certification and Compliance
Certification process and ongoing requirements
| Code | Title |
|---|---|
| CERT-1 | RRA Certification to EPA |
| CERT-2 | ERP Certification to EPA |
| CERT-3 | Five-Year Review and Recertification |
| CERT-4 | Record Retention |
| KR-CSAP-CC-01 | Certification Assessment |
| KR-CSAP-CC-02 | Continuous Compliance |
| KR-CSAP-CC-03 | Incident Reporting |
Cybersecurity-Specific Requirements
| Code | Title |
|---|---|
| CYBER-1 | Cybersecurity Assessment |
| CYBER-2 | Access Control Practices |
| CYBER-3 | Network Security |
| CYBER-4 | Cybersecurity Incident Response |
Emergency Response Plan (ERP)
| Code | Title |
|---|---|
| SDWA1433(b)(1) | Incorporate RRA Findings |
| SDWA1433(b)(2) | Strategies for Resilience |
| SDWA1433(b)(3) | Plans and Procedures for Response |
| SDWA1433(b)(4) | Actions and Equipment |
Enforcement and Penalties
CRTC enforcement, private right of action, and penalties
| Code | Title |
|---|---|
| BSA-ENF-1 | Anti-Structuring Prohibition |
| BSA-ENF-2 | Civil Money Penalties |
| BSA-ENF-3 | Criminal Penalties |
| CASL-ENF-01 | Administrative Monetary Penalties |
| CASL-ENF-02 | Compliance and Due Diligence |
| CASL-ENF-03 | Address Harvesting |
| ENF-1 | EPA Inspection Authority |
| ENF-2 | Civil Penalties |
| ENF-3 | Enforcement Actions |
| ENF-4 | Technical Assistance |
| RA10175-S10 | Law Enforcement Authority |
| RA10175-S21 | Jurisdiction |
| RA10175-S8 | Penalties |
| RIDTPPA-10 | Deceptive Trade Practice |
| RIDTPPA-11 | Unauthorized Disclosure Penalty |
| RIDTPPA-9 | AG Enforcement |
| UKTSA-ENF-01 | Ofcom Information Powers |
| UKTSA-ENF-02 | Ofcom Inspection Powers |
| UKTSA-ENF-03 | Enforcement Notices |
| UKTSA-ENF-04 | Financial Penalties |
| UKTSA-ENF-05 | Security Breach Notification |
| ZMDPA-ENF-01 | Data Protection Commissioner Powers |
| ZMDPA-ENF-02 | Penalties for Non-Compliance |
| s.11 | Forfeiture of Vehicles, Ships or Aircraft |
| s.5 | Facilitating Building Safety |
| s.7 | Building Advisory Committee |
| s.8 | Slavery and Trafficking Reparation Orders |
Risk and Resilience Assessment (RRA)
| Code | Title |
|---|---|
| SDWA1433(a)(1) | Physical Infrastructure Assessment |
| SDWA1433(a)(2) | Electronic and Automated Systems |
| SDWA1433(a)(3) | Monitoring Practices |
| SDWA1433(a)(4) | Chemical Handling Assessment |
| SDWA1433(a)(5) | Financial Infrastructure |
| SDWA1433(a)(6) | Operations and Maintenance Assessment |
Maps to 551 other frameworks
Frequently Asked Questions
What is US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements?
US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements is a compliance framework from United States (EPA) with 5 domains and 48 controls. The US Environmental Protection Agency (EPA) enforces cybersecurity requirements for public water systems under the Safe Drinking Water Act (SDWA). Key requirements include: America's Water Infrastructure Act (AWIA, 2018) Section 2013 mandating risk and resilience assessments including cyber risks, EPA enforcement actions for cybersecurity failures (using SDWA Section 1433), and EPA's 2023 memorandum requiring states to include cybersecurity in public water system sanitary surveys. EPA works with CISA to provide technical assistance. Applies to approximately 151,000 public water systems in the United States. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements have?
US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements has 48 controls organised across 5 domains. The largest domains are Enforcement and Penalties (27 controls), Certification and Compliance (7 controls), Risk and Resilience Assessment (RRA) (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements map to?
US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements maps to 551 other compliance frameworks. The top mapping partners are CSA CCM v4 (25% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (23% coverage), FTC Safeguards Rule (16 CFR Part 314) (23% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements compliance?
Start your US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US EPA Safe Drinking Water Act (SDWA) — Cybersecurity Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 48 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required