Water utilities get to write their own cybersecurity rules—with EPA's blessing
H.R. 2594 — To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector. · Filed by Rick Crawford (R-AR) · 3 cosponsors · Introduced Apr 2, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill creates a new Water Risk and Resilience Organization (WRRO) certified by the EPA to develop cybersecurity standards for large water systems (serving 3,300+ people). The WRRO would propose requirements, the EPA would approve them with deference to the WRRO's technical expertise, and water systems would face penalties up to $25,000/day for non-compliance. The bill funds this with $10 million and explicitly preserves state authority.
Why we flagged it
The bill's core function is to delegate authority for developing water-sector cybersecurity standards to a private, EPA-certified organization rather than having EPA or Congress set them directly. This is a structural choice about who writes the rules, not a direct regulatory mandate.
What the text implies
- The WRRO is a private organization with 'balanced stakeholder representation' but includes water-system owners/operators on its board—creating potential conflicts of interest in setting standards that affect their own compliance costs.
- EPA 'deference to technical expertise' language may limit meaningful EPA review of proposed standards, shifting rule-making power away from elected officials to an industry-influenced body.
The full analysis lists 5 implications of this text.
Who stands to gain
water utilities and treatment operators; cybersecurity consulting and software vendors; large municipal water systems (economies of scale in compliance)