S-5368-119
Read twice and referred to the Committee on Environment and Public Works.
Sponsored by Adam Schiff (D-CA)
What it does
This bill would amend the Safe Drinking Water Act and Clean Water Act to require community water systems and large wastewater treatment works to assess cybersecurity risks, develop emergency response plans covering cyber threats, and submit certain findings to state regulators (or EPA) for review and approval. It would direct EPA to establish baseline cybersecurity standards in consultation with technical experts, create a state primacy process for enforcement, exempt submitted cyber-risk information from public disclosure laws, and authorize $300 million per year for fiscal years 2027-2032 for each of drinking water and wastewater cybersecurity assistance.
Who benefits
Water and wastewater utility customers who could face reduced risk of service disruption from cyberattacks; state environmental agencies gaining new grant funding and enforcement authority; cybersecurity vendors and consultants serving the water sector; small and under-resourced utilities that would receive prioritized technical assistance and grants.
Who is hurt
Community water systems and large treatment works (especially smaller and midsize utilities) that would bear new compliance costs for assessments, inspections, and countermeasure adoption; ratepayers who may see rate increases to cover compliance costs; state agencies that must build cybersecurity assessment capacity; transparency and government-watchdog groups affected by the new FOIA and state open-records exemptions for submitted assessments.
Supporters argue
Supporters argue that water and wastewater systems are critical infrastructure increasingly targeted by cyberattacks, citing incidents like the 2021 Oldsmar, Florida water treatment hack, and that current law does not require systematic cybersecurity risk assessment. They contend the bill's phased, risk-based approach—with EPA-developed standards, technical assistance, and $1.8 billion in total authorized funding—gives utilities of all sizes the tools and support needed to close cybersecurity gaps without imposing one-size-fits-all mandates.
Opponents argue
Opponents argue the bill imposes new mandatory assessments, inspections, and reporting obligations on thousands of utilities, many of which are small systems that already struggle with limited budgets and technical staff, and that compliance costs could ultimately fall on ratepayers. They contend the broad FOIA and state open-records exemptions for cybersecurity submissions reduce public accountability and oversight of how utilities and states handle known vulnerabilities, even though the bill preserves congressional access.