New York has established new drinking water cybersecurity requirements for community water systems serving more than 3,300 people. The requirements establish a baseline cybersecurity program, require a Cybersecurity Vulnerability Analysis (CVA), set incident and vulnerability reporting timelines, and require certified drinking water operators to complete cybersecurity training.
The regulation, found in Appendix 5-E of New York's drinking water regulations, took effect March 11, 2026. Covered water systems generally have until January 1, 2027, to comply, although certain training and reporting provisions took effect immediately.
For water system leaders, the regulation is more than a compliance exercise. It requires organizations to understand the technology supporting their operations, identify cybersecurity weaknesses, establish processes for responding to incidents, and maintain the ability to recover when something goes wrong.
This guide explains who is covered, what the New York drinking water cybersecurity requirements include, and what water systems should be doing now to prepare.
The regulation applies to community water systems serving more than 3,300 people. Additional requirements apply to covered systems serving a combined wholesale and retail population of more than 50,000.
New York refers to organizations within the scope of the regulation as "covered water systems."
The requirements generally fall into several areas:
The New York State Department of Health maintains a summary of drinking water system cybersecurity requirements that outlines the required actions, responsible parties, documentation, and timing.
The regulation takes a risk-management approach. Covered water systems must understand their cybersecurity exposure, establish a program to address identified risks, and maintain processes for detecting, reporting, responding to, and recovering from cybersecurity events.
A Cybersecurity Vulnerability Analysis (CVA) is a central component of the requirements.
Covered water systems must prepare a CVA that addresses the cybersecurity requirements in Appendix 5-E. The analysis must be reviewed and updated at least annually and when major changes to water infrastructure could affect cybersecurity.
The purpose is not simply to produce a document. The CVA should provide a practical understanding of where cybersecurity weaknesses exist across the systems that support the water system's operations.
That means the assessment should help answer questions such as:
The New York Department of Health provides a Cybersecurity Vulnerability Assessment Checklist and other resources to help covered water systems evaluate their cybersecurity posture.
Covered water systems must establish a cybersecurity program that incorporates the findings of the CVA.
According to the New York Department of Health, the program must address areas including:
For systems serving more than 50,000 people, additional requirements include network activity monitoring and designated cybersecurity personnel.
The practical implication is important: identifying vulnerabilities is only the first step. The organization needs a repeatable process for deciding what to address, who owns it, how remediation is tracked, and how the cybersecurity program changes as technology, personnel, and infrastructure change.
One of the most operationally important aspects of the regulation is its reporting timelines.
Covered water systems must notify the New York Department of Health within 24 hours of identifying a cybersecurity incident that may affect the system's ability to comply with Subpart 5-1 or that may pose a risk to public health.
This makes incident detection and escalation an important part of compliance.
A water system cannot respond within 24 hours if it does not know who is responsible for evaluating an alert, determining whether an incident meets the reporting threshold, and initiating the required response.
Covered water systems must report qualifying cybersecurity vulnerabilities to the Department of Health within 48 hours of identification.
The requirement applies to vulnerabilities that may affect the water system's ability to comply with Subpart 5-1 or that identify a situation that may pose a public health risk.
This creates an important distinction between a routine vulnerability and one that requires regulatory reporting.
Organizations should have a documented process for determining when a discovered vulnerability meets the reporting criteria rather than making that decision from scratch during an incident.
Qualifying vulnerabilities must have corrective action started or completed within 120 days of notification. The Department of Health's requirements table also states that covered systems should consult with the Department within 30 days to identify mitigation steps.
The practical takeaway is that vulnerability management needs to connect identification, risk assessment, reporting, remediation, and documentation.
A vulnerability scan by itself does not create compliance. The organization needs a process that moves findings toward documented remediation.
New York's regulation also establishes cybersecurity training requirements for drinking water operators.
Certified drinking water operators must receive one hour of cybersecurity training every three years. The Department of Health states that this training requirement became effective immediately when Appendix 5-E was adopted and that there are no exclusions.
Training should be viewed as one component of a broader security program rather than a standalone compliance activity.
For example, training can reinforce behaviors related to:
The goal is to make sure the people operating and supporting the water system understand their role in protecting the technology and information on which those operations depend.
Water systems serving a combined wholesale and retail population of more than 50,000 face additional cybersecurity requirements.
The system must designate an individual who is considered qualified by the system's owner and who has demonstrable knowledge of cybersecurity principles and practical experience in system protection or risk management.
That individual is responsible for the system's cybersecurity program.
The designated individual must certify every five years that the water system has an active cybersecurity program that meets the applicable requirements.
The designated individual must also provide a confidential written report to the system's governing body annually. The report must summarize the cybersecurity program and significant cybersecurity risks.
This creates a formal connection between cybersecurity operations and organizational governance.
Cybersecurity should therefore be treated as an ongoing risk-management responsibility, not solely as an IT function.
Systems serving more than 50,000 people must monitor and log network activity.
Effective monitoring can help organizations establish visibility into authentication events, unusual activity, unauthorized access attempts, and other indicators that may require investigation.
Many water systems rely on Microsoft 365 for email, collaboration, identity, document management, and administrative operations. Securing that environment can be an important part of an overall cybersecurity program, but Microsoft 365 security alone does not address the full scope of a water system's technology environment.
Water systems may also depend on operational technology, control systems, remote access tools, network infrastructure, engineering workstations, and other systems that interact with physical water infrastructure.
The security strategy therefore needs to account for both IT and operational technology (OT).
Identity is an important security control across both administrative and operational environments.
For Microsoft 365 environments, organizations should evaluate controls such as:
These controls can reduce the opportunity for compromised credentials to become a pathway into sensitive systems.
A water system's business technology and operational technology do not necessarily have the same security requirements or risk profiles.
An assessment should identify:
The objective is not to apply identical controls everywhere. It is to understand dependencies and reduce unnecessary pathways between systems.
Covered water systems have a defined compliance deadline, but waiting until the deadline to begin preparation can make the process more difficult.
The New York Department of Health states that covered water systems generally have until January 1, 2027, to comply with Appendix 5-E, while the cybersecurity training and certain reporting requirements became effective immediately upon adoption.
A practical preparation process can be organized into five steps.
Determine whether the organization is a covered community water system and whether the additional requirements for systems serving more than 50,000 people apply.
Document who owns cybersecurity responsibility and who will coordinate compliance activities.
Identify the technology supporting the water system.
The inventory should extend beyond laptops, servers, and Microsoft 365. Consider operational technology, network infrastructure, remote access solutions, engineering workstations, control systems, applications, and third-party connections.
You cannot effectively manage cybersecurity risk if critical assets and dependencies are unknown.
Use the CVA to identify vulnerabilities and assess their potential impact.
Prioritize findings based on their operational and public health implications rather than treating every vulnerability as equally urgent.
Document how the organization will:
The response process should be clear enough that staff know what to do before an incident occurs.
Cybersecurity compliance is not a one-time assessment.
The CVA must be reviewed and updated annually, and the cybersecurity program should change as technology, personnel, vendors, and infrastructure change.
A regular governance process can help leadership track open risks, remediation progress, changes to the technology environment, training status, and incident-response readiness.
The value of the New York drinking water cybersecurity requirements is not simply producing another compliance document. The more useful question is whether the organization can demonstrate that its cybersecurity risk is being actively managed.
Leadership should be able to answer:
These questions turn a regulatory requirement into an operational cybersecurity program with measurable outcomes.
For organizations that rely on Microsoft 365, identity security, managed security services, or third-party technology providers, the same principle applies: each technology should be evaluated based on how it supports the water system's broader security, resilience, and compliance objectives.
New York requires community water systems serving more than 3,300 people to establish a cybersecurity program, conduct and maintain a Cybersecurity Vulnerability Analysis, report qualifying cybersecurity incidents and vulnerabilities, address qualifying vulnerabilities, provide cybersecurity training to drinking water operators, and maintain an incident response and recovery capability. Additional requirements apply to systems serving more than 50,000 people.
The regulation generally applies to community water systems serving more than 3,300 people. Certain provisions, including requirements related to cybersecurity personnel and network monitoring, apply specifically to systems serving a combined wholesale and retail population of more than 50,000.
Appendix 5-E became effective March 11, 2026. Covered water systems generally have until January 1, 2027, to comply, while the cybersecurity training requirement and certain reporting requirements became effective immediately upon adoption.
A Cybersecurity Vulnerability Analysis, or CVA, is an assessment required under New York's drinking water cybersecurity regulation. It must address the requirements established in Appendix 5-E and be reviewed and updated annually. The analysis is intended to identify cybersecurity vulnerabilities that could affect regulatory compliance or pose a public health risk.
The CVA must be reviewed and updated at least annually. The New York Department of Health's requirements table also states that the CVA must be submitted to the Department every five years and within 30 days after major water facility infrastructure changes, subject to the applicable regulatory requirements.
A covered water system must notify the New York Department of Health within 24 hours of identifying a cybersecurity incident that may affect the system's ability to comply with applicable drinking water requirements or that may pose a public health risk.
Qualifying cybersecurity vulnerabilities must be reported to the New York Department of Health within 48 hours of identification. The requirement applies to vulnerabilities that may affect compliance with Subpart 5-1 or identify a situation that may pose a public health risk.
For qualifying vulnerabilities subject to the regulation, corrective action must start or be completed within 120 days of notification. The Department of Health also states that the system should consult with the Department within 30 days to identify appropriate mitigation steps.
Certified drinking water operators must complete one hour of cybersecurity training every three years. The New York Department of Health states that this requirement became effective immediately upon adoption of Appendix 5-E and has no exclusions.
Systems serving more than 50,000 people must designate a qualified individual responsible for the cybersecurity program, have that individual certify the program every five years, provide an annual confidential cybersecurity report to the governing body, and monitor and log network activity.
No single technology platform satisfies the full New York drinking water cybersecurity requirements. Microsoft 365 can provide important identity, access, collaboration, and security controls, but a water system must consider its broader IT and operational technology environment, including control systems, network infrastructure, remote access, cyber assets, incident response, and recovery processes.
The New York State Department of Health provides an overview of the cybersecurity regulation for public water systems, while the New York Codes, Rules and Regulations provides the official applicability requirements for Appendix 5-E. The Department of Health also provides a detailed cybersecurity requirements table.