Water systems must now defend against cyberattacks—with federal help and secrecy
S. 5368 — Water Cyber Shield Act of 2026 · Filed by Adam Schiff (D-CA) · 1 cosponsor · Introduced Aug 7, 2026 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill amends federal drinking water and wastewater laws to require water systems to conduct cybersecurity risk assessments, develop emergency response plans addressing cyber threats, and meet baseline cybersecurity standards set by the EPA. It authorizes $300 million annually (2027–2032) for each sector to help systems build resilience, requires states to assume enforcement responsibility, and mandates reporting of cyber incidents to federal authorities. Ordinary citizens benefit from stronger protections against water system disruptions caused by cyberattacks, though the bill also shields sensitive security assessments from public disclosure.
Why we flagged it
The bill's core function is to impose mandatory cybersecurity assessments, standards, and incident reporting on drinking water and wastewater systems—a regulatory expansion justified by national security. It is not a subsidy, carve-out, or deregulation; it is a protective mandate with federal funding support.
What the text implies
- FOIA exemption for water system security assessments is broad and permanent—citizens cannot access detailed vulnerability data even after threats are mitigated, potentially reducing transparency in how systems spend federal cybersecurity funds.
- States assume enforcement authority but must meet EPA capacity standards; states that fail to qualify remain under federal EPA enforcement, creating a two-tier system that may disadvantage smaller or less-resourced states.
The full analysis lists 5 implications of this text.
Who stands to gain
IT and operational technology service providers (cybersecurity consultants and vendors); Water system contractors and engineering firms (implementing assessments and upgrades); Cybersecurity software and hardware vendors (CISA, NIST collaboration may favor certain standards)