QuorumCivic. Hidden in plain sight Get the app
Bill intelligence

Water systems must now defend against cyberattacks—with federal help and secrecy

S. 5368 — Water Cyber Shield Act of 2026 · Filed by Adam Schiff (D-CA) · 1 cosponsor · Introduced Aug 7, 2026 · Referred to committee

72%
Transparency
Typical bill: 82%
18/100
Hidden-provision risk
Typical bill: 15/100
Critical Infrastructure Cybersecurity…

Your members of Congress

Enter a ZIP to see where your representative and both senators stood on this bill.

Looked up on this device — your ZIP is never stored on our servers.

What it does

This bill amends federal drinking water and wastewater laws to require water systems to conduct cybersecurity risk assessments, develop emergency response plans addressing cyber threats, and meet baseline cybersecurity standards set by the EPA. It authorizes $300 million annually (2027–2032) for each sector to help systems build resilience, requires states to assume enforcement responsibility, and mandates reporting of cyber incidents to federal authorities. Ordinary citizens benefit from stronger protections against water system disruptions caused by cyberattacks, though the bill also shields sensitive security assessments from public disclosure.

Why we flagged it

The bill's core function is to impose mandatory cybersecurity assessments, standards, and incident reporting on drinking water and wastewater systems—a regulatory expansion justified by national security. It is not a subsidy, carve-out, or deregulation; it is a protective mandate with federal funding support.

What the text implies

  • FOIA exemption for water system security assessments is broad and permanent—citizens cannot access detailed vulnerability data even after threats are mitigated, potentially reducing transparency in how systems spend federal cybersecurity funds.
  • States assume enforcement authority but must meet EPA capacity standards; states that fail to qualify remain under federal EPA enforcement, creating a two-tier system that may disadvantage smaller or less-resourced states.

The full analysis lists 5 implications of this text.

Who stands to gain

IT and operational technology service providers (cybersecurity consultants and vendors); Water system contractors and engineering firms (implementing assessments and upgrades); Cybersecurity software and hardware vendors (CISA, NIST collaboration may favor certain standards)

Correlative observation from public records — not evidence of coordination or wrongdoing, and not financial advice.
This page is the record as of today. The app tells you when it changes.
Quorum analysis of the full bill text · 119th Congress · public record