Sourcepass Blog

New York Drinking Water Cybersecurity Compliance Checklist

Written by Robert Villano | Sep 24, 2026

New York’s drinking water cybersecurity requirements establish specific cybersecurity obligations for community water systems serving more than 3,300 people. Covered systems must maintain a Cybersecurity Vulnerability Analysis (CVA), establish a cybersecurity program, report certain vulnerabilities within 48 hours, report qualifying cybersecurity incidents within 24 hours, address qualifying vulnerabilities within 120 days, and maintain incident response and recovery capabilities. Most requirements must be in place by January 1, 2027.

For water system executives, operators, and IT leaders, the practical question is not simply whether the organization is compliant. It is whether the organization can demonstrate that cybersecurity risks are identified, prioritized, assigned, remediated, and monitored over time.

This New York drinking water cybersecurity compliance checklist provides a practical framework for assessing readiness against the requirements in Appendix 5-E.

 

New York Drinking Water Cybersecurity Compliance Checklist

The checklist below follows the major activities a covered water system should address:

  1. Determine whether your system is covered
  2. Inventory IT and OT assets
  3. Complete or update the Cybersecurity Vulnerability Analysis
  4. Identify and prioritize vulnerabilities
  5. Establish the cybersecurity program
  6. Document incident response and recovery
  7. Establish reporting procedures
  8. Train drinking water operators
  9. Establish ongoing review and governance

The New York State Department of Health also provides a drinking water system cybersecurity requirements table that identifies required actions, responsible parties, frequency, documentation, and effective dates.

 

1. Determine Whether Your Water System Is Covered

The first step in New York drinking water cybersecurity compliance is determining which requirements apply to your organization.

Appendix 5-E generally applies to community water systems serving more than 3,300 people. Additional provisions apply to covered systems serving a combined wholesale and retail population of more than 50,000. The cybersecurity training requirements apply to certified drinking water operators.

 

Confirm your system's population and classification

Document:

  • Whether the organization operates a community water system
  • The population served
  • Whether the system serves more than 50,000 people
  • Whether the system has qualifying IT/OT and OT/external network separation
  • Which Appendix 5-E requirements apply
  • Who is responsible for coordinating compliance

New York also provides for certain exclusions where a covered system has documented separation between operational technology and information technology and between operational technology and external networks. Those exclusions do not eliminate every requirement, including training, emergency response planning, and reporting obligations.

Do not assume that an exclusion applies simply because systems appear to be separated. The separation needs to meet the regulatory criteria and be documented.

 

2. Inventory IT and OT Assets

You cannot effectively assess cybersecurity risk without knowing what technology supports the water system.

New York's cybersecurity program requirements specifically include maintaining a cyber asset inventory.

 

Build an inventory that reflects the operational environment

The inventory should extend beyond traditional business IT.

Consider documenting:

  • Servers and workstations
  • Network infrastructure
  • Firewalls and remote access systems
  • Microsoft 365 and identity infrastructure
  • Engineering workstations
  • SCADA and control systems
  • Programmable logic controllers and related equipment
  • Monitoring systems
  • Pumps, valves, and electronically controlled equipment
  • Cloud applications
  • Vendor connections
  • Remote administration tools
  • Backup and recovery systems
  • Internet-connected devices

For each asset, identify its owner, purpose, location, connectivity, access requirements, criticality, and dependencies.

The objective is not to create an inventory that exists only for compliance. It should provide enough visibility to answer a practical question: If this system were compromised or unavailable, what would be affected?

 

Pay particular attention to IT/OT connections

New York's regulation specifically addresses operational technology and its connections to IT and external networks. The Department of Health also identifies documented OT/IT and OT/external network separation as a factor in certain regulatory exclusions.

Understanding these connections can reveal cybersecurity pathways that are easy to overlook when IT and operations are assessed separately.

 

3. Complete or Update the Cybersecurity Vulnerability Analysis

The Cybersecurity Vulnerability Analysis (CVA) is a central component of New York drinking water cybersecurity compliance.

Covered systems must prepare a CVA that incorporates the requirements of Appendix 5-E and review and update it annually. The Department of Health's requirements table also specifies submission to the Department every five years and within 30 days after qualifying major water infrastructure changes.

New York explains that many water systems already address cybersecurity as part of their emergency response planning and that Appendix 5-E builds on that existing process.

 

Assess more than vulnerabilities on a scan

A useful CVA should connect technical findings to operational consequences.

Evaluate:

  • Cyber assets and their criticality
  • Authentication and access controls
  • Privileged access
  • Remote access
  • Network architecture
  • IT/OT connectivity
  • External network connections
  • Known software and hardware vulnerabilities
  • Unsupported or outdated systems
  • Vendor access
  • Monitoring capabilities
  • Backup and recovery capabilities
  • Incident response procedures
  • Dependencies between business and operational systems

The goal is to understand which weaknesses matter most to the water system's ability to operate safely and reliably.

 

4. Identify and Prioritize Cybersecurity Vulnerabilities

Not every cybersecurity finding has the same operational significance.

New York requires covered systems to report vulnerabilities that may affect the system's ability to comply with Subpart 5-1 or that may pose a risk to public health. Those vulnerabilities must be reported within 48 hours of identification.

 

Establish a consistent prioritization process

A practical vulnerability management process should consider:

  • Potential impact on water operations
  • Potential public health implications
  • Exploitability
  • Exposure to external networks
  • Privileged access
  • Availability of compensating controls
  • Asset criticality
  • Existing monitoring
  • Remediation complexity

This creates a more useful hierarchy than simply sorting vulnerabilities by a technical severity score.

For example, a high-severity vulnerability on an isolated system with strong compensating controls may require a different response than a moderate vulnerability affecting a highly connected system used to support critical operations.

 

Track remediation to completion

The regulation requires corrective action to start or be completed within 120 days for qualifying vulnerabilities, with consultation with the Department within 30 days to identify mitigation steps.

Your vulnerability management process should therefore capture:

  • Finding
  • Affected asset
  • Risk assessment
  • Owner
  • Required action
  • Target date
  • Mitigation or compensating control
  • Status
  • Evidence of remediation
  • Validation that the issue was resolved

The measurable outcome is not the number of vulnerabilities identified. It is the percentage of material vulnerabilities that have a documented owner, remediation plan, and verified resolution.

 

5. Establish the Cybersecurity Program

New York requires covered water systems to establish a cybersecurity program that incorporates the findings of the CVA. The program must address areas including cyber asset inventory, access control, detection and incident response, recovery, and a review schedule.

 

Make the program operational

A cybersecurity program should define:

  • Who owns cybersecurity
  • Who can access critical systems
  • How access is approved and removed
  • How privileged accounts are managed
  • How vulnerabilities are identified and remediated
  • How suspicious activity is detected
  • How incidents are escalated
  • How regulatory reporting decisions are made
  • How critical systems are recovered
  • How third-party access is controlled
  • How cybersecurity risks are reported to leadership
  • How the program is reviewed and updated

This is where cybersecurity moves from a collection of tools and assessments into an operating process.

 

Include Microsoft 365 and identity security where applicable

For water systems using Microsoft 365, the cybersecurity program should account for the security of the organization's identity environment as part of its broader IT architecture.

Relevant controls may include:

  • Multifactor authentication
  • Conditional access
  • Privileged identity management
  • Administrative account separation
  • Access reviews
  • Endpoint security
  • Email security
  • Identity monitoring
  • Logging and alerting

These controls do not replace OT security requirements, but they can reduce risk across the business systems and identities that support the organization.

 

6. Document Incident Response and Recovery

New York requires covered water systems to maintain the ability to recover from cybersecurity incidents using an incident response plan.

This is particularly important because the regulation creates a 24-hour reporting requirement for qualifying cybersecurity incidents.

 

Define what happens when an incident is detected

The incident response process should establish:

  1. How an alert or suspected incident is reported
  2. Who evaluates the event
  3. Who has authority to escalate it
  4. How the organization determines whether the event meets reporting criteria
  5. Who contacts the New York Department of Health
  6. How affected systems are contained
  7. How critical operations continue
  8. How systems are restored
  9. How the incident is documented
  10. How lessons learned are incorporated into the cybersecurity program

New York's existing emergency response guidance identifies cyber attacks among the emergencies that water systems should plan for and recommends predefined response actions and current emergency contact information.

 

Test the recovery process

A documented recovery plan is useful only if the people responsible for executing it understand their roles.

Consider periodically testing scenarios such as:

  • Compromised administrator credentials
  • Ransomware affecting business systems
  • Loss of remote access
  • Compromise of an engineering workstation
  • Loss of SCADA or automated controls
  • Network disruption
  • Vendor account compromise

The objective is to identify gaps before they affect operations.

 

7. Establish Cybersecurity Reporting Procedures

The regulation creates two important reporting timelines.

 

24-hour incident reporting

Qualifying cybersecurity incidents must be reported to the New York Department of Health within 24 hours of identification.

 

48-hour vulnerability reporting

Qualifying cybersecurity vulnerabilities must be reported within 48 hours of identification.

These timelines make pre-established decision-making especially important.

 

Create a reporting decision tree

Document:

  • What constitutes a cybersecurity incident for purposes of the regulation
  • What constitutes a reportable vulnerability
  • Who makes the determination
  • Who is authorized to submit the report
  • Where the report is submitted
  • Who must be notified internally
  • What information must be documented
  • How the event is added to the CVA and remediation process

Do not make regulatory reporting decisions dependent on finding the right person after an incident occurs.

 

8. Train Drinking Water Operators

Certified drinking water operators must receive one hour of cybersecurity training every three years. The requirement became effective immediately upon adoption of Appendix 5-E and has no exclusions.

 

Connect training to actual behavior

The most useful training should reinforce behaviors that operators can apply to their work.

Topics can include:

  • Recognizing phishing and suspicious communications
  • Protecting credentials
  • Using multifactor authentication
  • Reporting suspicious activity
  • Secure remote access
  • Handling removable media
  • Recognizing unauthorized changes
  • Escalating potential cybersecurity incidents
  • Protecting sensitive system information

New York's cybersecurity guidance emphasizes that water systems depend on computer-based and electronically operated equipment, including control systems, pumps, valves, and data.

Training should therefore connect cybersecurity concepts to the actual systems operators interact with.

 

9. Establish Ongoing Review and Governance

New York's drinking water cybersecurity requirements are designed around an ongoing program rather than a one-time assessment.

The CVA must be reviewed and updated annually, while the cybersecurity program should be updated when changes in technology, staff, or other aspects of the water system could affect cybersecurity.

 

Establish a recurring cybersecurity review

At minimum, leadership should periodically review:

  • Open material vulnerabilities
  • Remediation progress
  • Cyber asset inventory changes
  • Privileged access
  • Vendor and remote access
  • Security incidents and near misses
  • Backup and recovery readiness
  • Operator training status
  • Incident response testing
  • Changes to IT/OT architecture
  • Regulatory reporting
  • Overall cybersecurity risk

For systems serving more than 50,000 people, the designated cybersecurity individual must also provide an annual confidential written report to the governing body summarizing the cybersecurity program and significant cybersecurity risks.

 

Protect sensitive cybersecurity documentation

Water system vulnerability information can contain operationally sensitive details. New York provides specific guidance for protecting sensitive information within vulnerability assessments and emergency response plans, including limiting access and separating sensitive information from materials intended for public review.

Cybersecurity governance should therefore address not only how information is created, but also who can access it, where it is stored, and how it is protected.

 

A Practical Readiness Test

A water system can use the following questions as a high-level readiness assessment:

Area Readiness question
Applicability Have we documented which Appendix 5-E requirements apply to our system?
Asset inventory Do we have an accurate inventory of critical IT and OT cyber assets?
IT/OT Do we understand and document connections between IT, OT, and external networks?
CVA Is our Cybersecurity Vulnerability Analysis current and actionable?
Vulnerabilities Do material findings have owners, remediation plans, and deadlines?
Cybersecurity program Is there a documented program that incorporates CVA findings?
Identity Are privileged accounts and access to critical systems appropriately controlled?
Monitoring Can we detect relevant suspicious activity?
Incident response Does everyone know what happens when a cybersecurity incident is identified?
Reporting Can we make and execute a 24-hour incident or 48-hour vulnerability reporting decision?
Recovery Can we restore critical operations after a cybersecurity incident?
Training Have covered operators completed the required cybersecurity training?
Governance Does leadership have visibility into material cybersecurity risks?
Continuous improvement Is there a defined cadence for reviewing and updating the program?

 

The New York Department of Health provides a cybersecurity checklist and program resources for public water systems that can be used alongside this framework.

 

What Water Systems Should Do Now

For covered water systems, January 1, 2027 is the general compliance date for the Appendix 5-E requirements, while certain provisions, including cybersecurity incident reporting and operator training, became effective immediately.

A practical sequence is:

1. Confirm applicability
Determine which requirements apply and identify the responsible parties.

2. Validate your asset inventory
Include both IT and OT and document important connections and dependencies.

3. Complete the CVA
Identify vulnerabilities and connect technical findings to operational risk.

4. Build the remediation plan
Assign owners, deadlines, mitigation strategies, and verification steps.

5. Establish the cybersecurity program
Document access controls, detection, response, recovery, asset management, and review procedures.

6. Test incident response
Make sure the organization can identify, escalate, report, contain, and recover from a qualifying event.

7. Train operators
Complete the required training and reinforce the behaviors most relevant to the organization's environment.

8. Establish governance
Create a recurring process for reviewing cybersecurity risk and updating the program as the environment changes.

The goal is not simply to check each regulatory box. A mature program should make it easier to answer three questions at any point in time: What are our most important cybersecurity risks? Who owns them? What are we doing to reduce them?

 

FAQ

What is the New York drinking water cybersecurity compliance checklist?

A practical New York drinking water cybersecurity compliance checklist should cover applicability, IT and OT asset inventory, the Cybersecurity Vulnerability Analysis, vulnerability management, the cybersecurity program, incident response and recovery, regulatory reporting, operator training, and ongoing governance. These areas align with the requirements in New York Appendix 5-E.

Who needs to comply with New York drinking water cybersecurity requirements?

Appendix 5-E generally applies to community water systems serving more than 3,300 people. Additional requirements apply to systems serving a combined wholesale and retail population of more than 50,000. The cybersecurity training requirements apply to certified drinking water operators.

When is New York drinking water cybersecurity compliance required?

Covered water systems generally have until January 1, 2027, to comply with Appendix 5-E. The cybersecurity incident reporting and operator training provisions became effective immediately upon adoption of the regulation.

What is a Cybersecurity Vulnerability Analysis for a water system?

A Cybersecurity Vulnerability Analysis, or CVA, assesses cybersecurity vulnerabilities affecting the technology and information that support a covered water system. It must incorporate the requirements of Appendix 5-E and be reviewed and updated annually.

How often does a water system need to update its cybersecurity vulnerability analysis?

The CVA must be reviewed and updated at least annually. The New York Department of Health also requires submission to the Department every five years and within 30 days after qualifying major water infrastructure changes.

What are the New York water cybersecurity reporting deadlines?

Qualifying cybersecurity incidents must be reported to the New York Department of Health within 24 hours of identification. Qualifying cybersecurity vulnerabilities must be reported within 48 hours of identification.

How long does a water system have to address a cybersecurity vulnerability?

For vulnerabilities subject to the regulation's reporting requirements, corrective action must start or be completed within 120 days of notification. The Department of Health states that the water system should consult with the Department within 30 days to identify mitigation steps.

Does New York require water system cybersecurity training?

Yes. Certified drinking water operators must receive one hour of cybersecurity training every three years. The requirement became effective immediately upon adoption of Appendix 5-E.

Does the regulation apply to Microsoft 365?

The regulation is not limited to Microsoft 365 or any other specific technology platform. A water system using Microsoft 365 should consider identity, access, email, endpoint, monitoring, and other Microsoft 365 security controls as part of its broader cybersecurity program. The organization must also address operational technology, network infrastructure, remote access, and other cyber assets that support water operations.

What should a water system do first to prepare for New York cybersecurity compliance?

Start by confirming which requirements apply, identifying the people responsible for compliance, and validating the organization's IT and OT asset inventory. From there, complete or update the Cybersecurity Vulnerability Analysis and use its findings to establish a prioritized remediation plan and cybersecurity program.

Where can water systems find the official New York cybersecurity requirements?

The New York State Department of Health provides the official cybersecurity requirements and resources for public water systems, including its requirements table, cybersecurity program resources, and vulnerability assessment checklist. The official regulatory text is available in Appendix 5-E of the New York State Sanitary Code.

Use this checklist to assess your water system's cybersecurity readiness and identify the areas that need attention before the January 1, 2027 compliance deadline.