US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
The US Environmental Protection Agency (EPA) enforces cybersecurity requirements for public water systems under the Safe Drinking Water Act (SDWA). Key requirements include: America's Water Infrastructure Act (AWIA, 2018) Section 2013 mandating risk and resilience assessments including cyber risks, EPA enforcement actions for cybersecurity failures (using SDWA Section 1433), and EPA's 2023 memorandum requiring states to include cybersecurity in public water system sanitary surveys. EPA works with CISA to provide technical assistance. Applies to approximately 151,000 public water systems in the United States.
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements is a compliance framework from United States (EPA) with 4 domains and 7 controls that map to 185 other frameworks. The largest domains are AWIA Section 2013 Certification and Records (4 controls), Cybersecurity (1 controls), Reporting (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
AWIA Section 2013 Certification and Records
Cybersecurity
| Code | Title |
|---|---|
| USSDWA-2 | Cybersecurity Practices (Assessment, Access, Network, IR) |
Reporting
| Code | Title |
|---|---|
| USSDWA-3 | EPA Reporting and Inspection |
Risk Assessment
| Code | Title |
|---|---|
| USSDWA-1 | AWIA Section 2013 Risk and Resilience Assessment |
Your Compliance Coverage
If you comply with US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements, you already cover:
NIST Privacy Framework
29%
2 controls mapped
Compare →Protective Security Policy Framework (PSPF) Release 2024
29%
2 controls mapped
Compare →PSD2 SCA
29%
2 controls mapped
Compare →+ 182 more: OSFI B-13 (29%), Open Banking Security (29%)
See all 185 mapped frameworks ↓Maps to 185 other frameworks
What is US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements and who does it apply to?
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements is a compliance framework from United States (EPA) with 4 domains and 7 controls. The US Environmental Protection Agency (EPA) enforces cybersecurity requirements for public water systems under the Safe Drinking Water Act (SDWA). Key requirements include: America's Water Infrastructure Act (AWIA, 2018) Section 2013 mandating risk and resilience assessments including cyber risks, EPA enforcement actions for cybersecurity failures (using SDWA Section 1433), and EPA's 2023 memorandum requiring states to include cybersecurity in public water system sanitary surveys. EPA works with CISA to provide technical assistance. Applies to approximately 151,000 public water systems in the United States. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements actually require?
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements has 7 controls organised across 4 domains. The largest domains are AWIA Section 2013 Certification and Records (4 controls), Cybersecurity (1 controls), Reporting (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements do I already cover?
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements maps to 185 other compliance frameworks. The top mapping partners are NIST Privacy Framework (29% coverage), Protective Security Policy Framework (PSPF) Release 2024 (29% coverage), PSD2 SCA (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements?
Start your US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 7 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required