New York’s drinking water cybersecurity requirements establish specific cybersecurity obligations for community water systems serving more than 3,300 people. Covered systems must maintain a Cybersecurity Vulnerability Analysis (CVA), establish a cybersecurity program, report certain vulnerabilities within 48 hours, report qualifying cybersecurity incidents within 24 hours, address qualifying vulnerabilities within 120 days, and maintain incident response and recovery capabilities. Most requirements must be in place by January 1, 2027.
For water system executives, operators, and IT leaders, the practical question is not simply whether the organization is compliant. It is whether the organization can demonstrate that cybersecurity risks are identified, prioritized, assigned, remediated, and monitored over time.
This New York drinking water cybersecurity compliance checklist provides a practical framework for assessing readiness against the requirements in Appendix 5-E.
The checklist below follows the major activities a covered water system should address:
The New York State Department of Health also provides a drinking water system cybersecurity requirements table that identifies required actions, responsible parties, frequency, documentation, and effective dates.
The first step in New York drinking water cybersecurity compliance is determining which requirements apply to your organization.
Appendix 5-E generally applies to community water systems serving more than 3,300 people. Additional provisions apply to covered systems serving a combined wholesale and retail population of more than 50,000. The cybersecurity training requirements apply to certified drinking water operators.
Document:
New York also provides for certain exclusions where a covered system has documented separation between operational technology and information technology and between operational technology and external networks. Those exclusions do not eliminate every requirement, including training, emergency response planning, and reporting obligations.
Do not assume that an exclusion applies simply because systems appear to be separated. The separation needs to meet the regulatory criteria and be documented.
You cannot effectively assess cybersecurity risk without knowing what technology supports the water system.
New York's cybersecurity program requirements specifically include maintaining a cyber asset inventory.
The inventory should extend beyond traditional business IT.
Consider documenting:
For each asset, identify its owner, purpose, location, connectivity, access requirements, criticality, and dependencies.
The objective is not to create an inventory that exists only for compliance. It should provide enough visibility to answer a practical question: If this system were compromised or unavailable, what would be affected?
New York's regulation specifically addresses operational technology and its connections to IT and external networks. The Department of Health also identifies documented OT/IT and OT/external network separation as a factor in certain regulatory exclusions.
Understanding these connections can reveal cybersecurity pathways that are easy to overlook when IT and operations are assessed separately.
The Cybersecurity Vulnerability Analysis (CVA) is a central component of New York drinking water cybersecurity compliance.
Covered systems must prepare a CVA that incorporates the requirements of Appendix 5-E and review and update it annually. The Department of Health's requirements table also specifies submission to the Department every five years and within 30 days after qualifying major water infrastructure changes.
New York explains that many water systems already address cybersecurity as part of their emergency response planning and that Appendix 5-E builds on that existing process.
A useful CVA should connect technical findings to operational consequences.
Evaluate:
The goal is to understand which weaknesses matter most to the water system's ability to operate safely and reliably.
Not every cybersecurity finding has the same operational significance.
New York requires covered systems to report vulnerabilities that may affect the system's ability to comply with Subpart 5-1 or that may pose a risk to public health. Those vulnerabilities must be reported within 48 hours of identification.
A practical vulnerability management process should consider:
This creates a more useful hierarchy than simply sorting vulnerabilities by a technical severity score.
For example, a high-severity vulnerability on an isolated system with strong compensating controls may require a different response than a moderate vulnerability affecting a highly connected system used to support critical operations.
The regulation requires corrective action to start or be completed within 120 days for qualifying vulnerabilities, with consultation with the Department within 30 days to identify mitigation steps.
Your vulnerability management process should therefore capture:
The measurable outcome is not the number of vulnerabilities identified. It is the percentage of material vulnerabilities that have a documented owner, remediation plan, and verified resolution.
New York requires covered water systems to establish a cybersecurity program that incorporates the findings of the CVA. The program must address areas including cyber asset inventory, access control, detection and incident response, recovery, and a review schedule.
A cybersecurity program should define:
This is where cybersecurity moves from a collection of tools and assessments into an operating process.
For water systems using Microsoft 365, the cybersecurity program should account for the security of the organization's identity environment as part of its broader IT architecture.
Relevant controls may include:
These controls do not replace OT security requirements, but they can reduce risk across the business systems and identities that support the organization.
New York requires covered water systems to maintain the ability to recover from cybersecurity incidents using an incident response plan.
This is particularly important because the regulation creates a 24-hour reporting requirement for qualifying cybersecurity incidents.
The incident response process should establish:
New York's existing emergency response guidance identifies cyber attacks among the emergencies that water systems should plan for and recommends predefined response actions and current emergency contact information.
A documented recovery plan is useful only if the people responsible for executing it understand their roles.
Consider periodically testing scenarios such as:
The objective is to identify gaps before they affect operations.
The regulation creates two important reporting timelines.
Qualifying cybersecurity incidents must be reported to the New York Department of Health within 24 hours of identification.
Qualifying cybersecurity vulnerabilities must be reported within 48 hours of identification.
These timelines make pre-established decision-making especially important.
Document:
Do not make regulatory reporting decisions dependent on finding the right person after an incident occurs.
Certified drinking water operators must receive one hour of cybersecurity training every three years. The requirement became effective immediately upon adoption of Appendix 5-E and has no exclusions.
The most useful training should reinforce behaviors that operators can apply to their work.
Topics can include:
New York's cybersecurity guidance emphasizes that water systems depend on computer-based and electronically operated equipment, including control systems, pumps, valves, and data.
Training should therefore connect cybersecurity concepts to the actual systems operators interact with.
New York's drinking water cybersecurity requirements are designed around an ongoing program rather than a one-time assessment.
The CVA must be reviewed and updated annually, while the cybersecurity program should be updated when changes in technology, staff, or other aspects of the water system could affect cybersecurity.
At minimum, leadership should periodically review:
For systems serving more than 50,000 people, the designated cybersecurity individual must also provide an annual confidential written report to the governing body summarizing the cybersecurity program and significant cybersecurity risks.
Water system vulnerability information can contain operationally sensitive details. New York provides specific guidance for protecting sensitive information within vulnerability assessments and emergency response plans, including limiting access and separating sensitive information from materials intended for public review.
Cybersecurity governance should therefore address not only how information is created, but also who can access it, where it is stored, and how it is protected.
A water system can use the following questions as a high-level readiness assessment:
| Area | Readiness question |
|---|---|
| Applicability | Have we documented which Appendix 5-E requirements apply to our system? |
| Asset inventory | Do we have an accurate inventory of critical IT and OT cyber assets? |
| IT/OT | Do we understand and document connections between IT, OT, and external networks? |
| CVA | Is our Cybersecurity Vulnerability Analysis current and actionable? |
| Vulnerabilities | Do material findings have owners, remediation plans, and deadlines? |
| Cybersecurity program | Is there a documented program that incorporates CVA findings? |
| Identity | Are privileged accounts and access to critical systems appropriately controlled? |
| Monitoring | Can we detect relevant suspicious activity? |
| Incident response | Does everyone know what happens when a cybersecurity incident is identified? |
| Reporting | Can we make and execute a 24-hour incident or 48-hour vulnerability reporting decision? |
| Recovery | Can we restore critical operations after a cybersecurity incident? |
| Training | Have covered operators completed the required cybersecurity training? |
| Governance | Does leadership have visibility into material cybersecurity risks? |
| Continuous improvement | Is there a defined cadence for reviewing and updating the program? |
The New York Department of Health provides a cybersecurity checklist and program resources for public water systems that can be used alongside this framework.
For covered water systems, January 1, 2027 is the general compliance date for the Appendix 5-E requirements, while certain provisions, including cybersecurity incident reporting and operator training, became effective immediately.
A practical sequence is:
1. Confirm applicability
Determine which requirements apply and identify the responsible parties.
2. Validate your asset inventory
Include both IT and OT and document important connections and dependencies.
3. Complete the CVA
Identify vulnerabilities and connect technical findings to operational risk.
4. Build the remediation plan
Assign owners, deadlines, mitigation strategies, and verification steps.
5. Establish the cybersecurity program
Document access controls, detection, response, recovery, asset management, and review procedures.
6. Test incident response
Make sure the organization can identify, escalate, report, contain, and recover from a qualifying event.
7. Train operators
Complete the required training and reinforce the behaviors most relevant to the organization's environment.
8. Establish governance
Create a recurring process for reviewing cybersecurity risk and updating the program as the environment changes.
The goal is not simply to check each regulatory box. A mature program should make it easier to answer three questions at any point in time: What are our most important cybersecurity risks? Who owns them? What are we doing to reduce them?
A practical New York drinking water cybersecurity compliance checklist should cover applicability, IT and OT asset inventory, the Cybersecurity Vulnerability Analysis, vulnerability management, the cybersecurity program, incident response and recovery, regulatory reporting, operator training, and ongoing governance. These areas align with the requirements in New York Appendix 5-E.
Appendix 5-E generally applies to community water systems serving more than 3,300 people. Additional requirements apply to systems serving a combined wholesale and retail population of more than 50,000. The cybersecurity training requirements apply to certified drinking water operators.
Covered water systems generally have until January 1, 2027, to comply with Appendix 5-E. The cybersecurity incident reporting and operator training provisions became effective immediately upon adoption of the regulation.
A Cybersecurity Vulnerability Analysis, or CVA, assesses cybersecurity vulnerabilities affecting the technology and information that support a covered water system. It must incorporate the requirements of Appendix 5-E and be reviewed and updated annually.
The CVA must be reviewed and updated at least annually. The New York Department of Health also requires submission to the Department every five years and within 30 days after qualifying major water infrastructure changes.
Qualifying cybersecurity incidents must be reported to the New York Department of Health within 24 hours of identification. Qualifying cybersecurity vulnerabilities must be reported within 48 hours of identification.
For vulnerabilities subject to the regulation's reporting requirements, corrective action must start or be completed within 120 days of notification. The Department of Health states that the water system should consult with the Department within 30 days to identify mitigation steps.
Yes. Certified drinking water operators must receive one hour of cybersecurity training every three years. The requirement became effective immediately upon adoption of Appendix 5-E.
The regulation is not limited to Microsoft 365 or any other specific technology platform. A water system using Microsoft 365 should consider identity, access, email, endpoint, monitoring, and other Microsoft 365 security controls as part of its broader cybersecurity program. The organization must also address operational technology, network infrastructure, remote access, and other cyber assets that support water operations.
Start by confirming which requirements apply, identifying the people responsible for compliance, and validating the organization's IT and OT asset inventory. From there, complete or update the Cybersecurity Vulnerability Analysis and use its findings to establish a prioritized remediation plan and cybersecurity program.
The New York State Department of Health provides the official cybersecurity requirements and resources for public water systems, including its requirements table, cybersecurity program resources, and vulnerability assessment checklist. The official regulatory text is available in Appendix 5-E of the New York State Sanitary Code.
Use this checklist to assess your water system's cybersecurity readiness and identify the areas that need attention before the January 1, 2027 compliance deadline.