Sourcepass Blog

New York’s Drinking Water Cybersecurity Requirements | Sourcepass

Written by Robert Villano | Sep 24, 2026

New York has established new drinking water cybersecurity requirements for community water systems serving more than 3,300 people. The requirements establish a baseline cybersecurity program, require a Cybersecurity Vulnerability Analysis (CVA), set incident and vulnerability reporting timelines, and require certified drinking water operators to complete cybersecurity training.

The regulation, found in Appendix 5-E of New York's drinking water regulations, took effect March 11, 2026. Covered water systems generally have until January 1, 2027, to comply, although certain training and reporting provisions took effect immediately.

For water system leaders, the regulation is more than a compliance exercise. It requires organizations to understand the technology supporting their operations, identify cybersecurity weaknesses, establish processes for responding to incidents, and maintain the ability to recover when something goes wrong.

This guide explains who is covered, what the New York drinking water cybersecurity requirements include, and what water systems should be doing now to prepare.

 

Who Is Covered by New York’s Drinking Water Cybersecurity Requirements?

The regulation applies to community water systems serving more than 3,300 people. Additional requirements apply to covered systems serving a combined wholesale and retail population of more than 50,000.

New York refers to organizations within the scope of the regulation as "covered water systems."

The requirements generally fall into several areas:

  • Cybersecurity Vulnerability Analysis
  • Cybersecurity program development
  • Vulnerability and incident reporting
  • Vulnerability remediation
  • Cybersecurity incident response and recovery
  • Operator cybersecurity training
  • Additional governance and monitoring requirements for systems serving more than 50,000 people

The New York State Department of Health maintains a summary of drinking water system cybersecurity requirements that outlines the required actions, responsible parties, documentation, and timing.

 

What Do New York Water Systems Need to Do?

The regulation takes a risk-management approach. Covered water systems must understand their cybersecurity exposure, establish a program to address identified risks, and maintain processes for detecting, reporting, responding to, and recovering from cybersecurity events.

 

Conduct a Cybersecurity Vulnerability Analysis

A Cybersecurity Vulnerability Analysis (CVA) is a central component of the requirements.

Covered water systems must prepare a CVA that addresses the cybersecurity requirements in Appendix 5-E. The analysis must be reviewed and updated at least annually and when major changes to water infrastructure could affect cybersecurity.

The purpose is not simply to produce a document. The CVA should provide a practical understanding of where cybersecurity weaknesses exist across the systems that support the water system's operations.

That means the assessment should help answer questions such as:

  • What technology and cyber assets support water operations?
  • Who has access to those systems?
  • Which systems are connected to external networks?
  • Where are privileged accounts used?
  • How is remote access controlled?
  • What vulnerabilities could affect the system's ability to comply with drinking water requirements?
  • What vulnerabilities could create a public health risk?
  • How would the organization detect and respond to a cybersecurity incident?
  • How would critical systems and operations be restored?

The New York Department of Health provides a Cybersecurity Vulnerability Assessment Checklist and other resources to help covered water systems evaluate their cybersecurity posture.

 

Establish a Cybersecurity Program

Covered water systems must establish a cybersecurity program that incorporates the findings of the CVA.

According to the New York Department of Health, the program must address areas including:

  • Inventory of cyber assets
  • Access control procedures
  • Detection and incident response procedures
  • Recovery plans
  • A defined review schedule

For systems serving more than 50,000 people, additional requirements include network activity monitoring and designated cybersecurity personnel.

The practical implication is important: identifying vulnerabilities is only the first step. The organization needs a repeatable process for deciding what to address, who owns it, how remediation is tracked, and how the cybersecurity program changes as technology, personnel, and infrastructure change.

 

Cybersecurity Reporting Deadlines for New York Water Systems

One of the most operationally important aspects of the regulation is its reporting timelines.

 

Cybersecurity incidents: 24 hours

Covered water systems must notify the New York Department of Health within 24 hours of identifying a cybersecurity incident that may affect the system's ability to comply with Subpart 5-1 or that may pose a risk to public health.

This makes incident detection and escalation an important part of compliance.

A water system cannot respond within 24 hours if it does not know who is responsible for evaluating an alert, determining whether an incident meets the reporting threshold, and initiating the required response.

 

Cybersecurity vulnerabilities: 48 hours

Covered water systems must report qualifying cybersecurity vulnerabilities to the Department of Health within 48 hours of identification.

The requirement applies to vulnerabilities that may affect the water system's ability to comply with Subpart 5-1 or that identify a situation that may pose a public health risk.

This creates an important distinction between a routine vulnerability and one that requires regulatory reporting.

Organizations should have a documented process for determining when a discovered vulnerability meets the reporting criteria rather than making that decision from scratch during an incident.

 

Corrective action: 120 days

Qualifying vulnerabilities must have corrective action started or completed within 120 days of notification. The Department of Health's requirements table also states that covered systems should consult with the Department within 30 days to identify mitigation steps.

The practical takeaway is that vulnerability management needs to connect identification, risk assessment, reporting, remediation, and documentation.

A vulnerability scan by itself does not create compliance. The organization needs a process that moves findings toward documented remediation.

 

Cybersecurity Training Requirements

New York's regulation also establishes cybersecurity training requirements for drinking water operators.

Certified drinking water operators must receive one hour of cybersecurity training every three years. The Department of Health states that this training requirement became effective immediately when Appendix 5-E was adopted and that there are no exclusions.

Training should be viewed as one component of a broader security program rather than a standalone compliance activity.

For example, training can reinforce behaviors related to:

  • Phishing and credential protection
  • Password and authentication practices
  • Suspicious activity reporting
  • Secure use of remote access
  • Physical security of operational technology
  • Incident escalation procedures

The goal is to make sure the people operating and supporting the water system understand their role in protecting the technology and information on which those operations depend.

 

Additional Requirements for Water Systems Serving More Than 50,000 People

Water systems serving a combined wholesale and retail population of more than 50,000 face additional cybersecurity requirements.

 

Designated cybersecurity responsibility

The system must designate an individual who is considered qualified by the system's owner and who has demonstrable knowledge of cybersecurity principles and practical experience in system protection or risk management.

That individual is responsible for the system's cybersecurity program.

 

Five-year cybersecurity program certification

The designated individual must certify every five years that the water system has an active cybersecurity program that meets the applicable requirements.

 

Annual reporting to the governing body

The designated individual must also provide a confidential written report to the system's governing body annually. The report must summarize the cybersecurity program and significant cybersecurity risks.

This creates a formal connection between cybersecurity operations and organizational governance.

Cybersecurity should therefore be treated as an ongoing risk-management responsibility, not solely as an IT function.

 

Network activity monitoring and logging

Systems serving more than 50,000 people must monitor and log network activity.

Effective monitoring can help organizations establish visibility into authentication events, unusual activity, unauthorized access attempts, and other indicators that may require investigation.

 

How Microsoft 365 Fits Into Water System Cybersecurity

Many water systems rely on Microsoft 365 for email, collaboration, identity, document management, and administrative operations. Securing that environment can be an important part of an overall cybersecurity program, but Microsoft 365 security alone does not address the full scope of a water system's technology environment.

Water systems may also depend on operational technology, control systems, remote access tools, network infrastructure, engineering workstations, and other systems that interact with physical water infrastructure.

The security strategy therefore needs to account for both IT and operational technology (OT).

 

Protect identity and access

Identity is an important security control across both administrative and operational environments.

For Microsoft 365 environments, organizations should evaluate controls such as:

  • Multifactor authentication
  • Conditional access policies
  • Privileged account management
  • Administrative account separation
  • User access reviews
  • Secure remote access
  • Monitoring of authentication activity

These controls can reduce the opportunity for compromised credentials to become a pathway into sensitive systems.

 

Understand the boundary between IT and OT

A water system's business technology and operational technology do not necessarily have the same security requirements or risk profiles.

An assessment should identify:

  • Which systems control or monitor physical operations
  • Which systems communicate with external networks
  • Where remote access exists
  • How vendors access operational environments
  • Which administrative systems can communicate with operational systems
  • Where network segmentation is appropriate
  • What happens if a critical system becomes unavailable

The objective is not to apply identical controls everywhere. It is to understand dependencies and reduce unnecessary pathways between systems.

 

What Water Systems Should Do Before January 2027

Covered water systems have a defined compliance deadline, but waiting until the deadline to begin preparation can make the process more difficult.

The New York Department of Health states that covered water systems generally have until January 1, 2027, to comply with Appendix 5-E, while the cybersecurity training and certain reporting requirements became effective immediately upon adoption.

A practical preparation process can be organized into five steps.

 

1. Confirm applicability

Determine whether the organization is a covered community water system and whether the additional requirements for systems serving more than 50,000 people apply.

Document who owns cybersecurity responsibility and who will coordinate compliance activities.

 

2. Build or validate the cyber asset inventory

Identify the technology supporting the water system.

The inventory should extend beyond laptops, servers, and Microsoft 365. Consider operational technology, network infrastructure, remote access solutions, engineering workstations, control systems, applications, and third-party connections.

You cannot effectively manage cybersecurity risk if critical assets and dependencies are unknown.

 

3. Complete the Cybersecurity Vulnerability Analysis

Use the CVA to identify vulnerabilities and assess their potential impact.

Prioritize findings based on their operational and public health implications rather than treating every vulnerability as equally urgent.

 

4. Establish the cybersecurity program and response processes

Document how the organization will:

  • Manage access
  • Monitor for suspicious activity
  • Identify and report qualifying incidents
  • Identify and report qualifying vulnerabilities
  • Remediate vulnerabilities
  • Respond to cybersecurity incidents
  • Recover critical operations
  • Review and update the program

The response process should be clear enough that staff know what to do before an incident occurs.

 

5. Establish an ongoing review cadence

Cybersecurity compliance is not a one-time assessment.

The CVA must be reviewed and updated annually, and the cybersecurity program should change as technology, personnel, vendors, and infrastructure change.

A regular governance process can help leadership track open risks, remediation progress, changes to the technology environment, training status, and incident-response readiness.

 

Turning Compliance Into Measurable Risk Reduction

The value of the New York drinking water cybersecurity requirements is not simply producing another compliance document. The more useful question is whether the organization can demonstrate that its cybersecurity risk is being actively managed.

Leadership should be able to answer:

  • Do we know what technology supports our water operations?
  • Do we know where our highest-risk vulnerabilities are?
  • Do we know who has privileged access?
  • Can we identify suspicious activity quickly?
  • Can we determine whether an incident requires regulatory reporting?
  • Can we meet a 24-hour incident reporting requirement?
  • Can we meet a 48-hour vulnerability reporting requirement?
  • Do we have documented remediation plans for significant vulnerabilities?
  • Can we recover critical operations following a cybersecurity incident?
  • Are operators receiving the required training?
  • Does leadership have visibility into material cybersecurity risks?

These questions turn a regulatory requirement into an operational cybersecurity program with measurable outcomes.

For organizations that rely on Microsoft 365, identity security, managed security services, or third-party technology providers, the same principle applies: each technology should be evaluated based on how it supports the water system's broader security, resilience, and compliance objectives.

 

FAQ

What are the New York drinking water cybersecurity requirements?

New York requires community water systems serving more than 3,300 people to establish a cybersecurity program, conduct and maintain a Cybersecurity Vulnerability Analysis, report qualifying cybersecurity incidents and vulnerabilities, address qualifying vulnerabilities, provide cybersecurity training to drinking water operators, and maintain an incident response and recovery capability. Additional requirements apply to systems serving more than 50,000 people.

Who must comply with New York's drinking water cybersecurity regulation?

The regulation generally applies to community water systems serving more than 3,300 people. Certain provisions, including requirements related to cybersecurity personnel and network monitoring, apply specifically to systems serving a combined wholesale and retail population of more than 50,000.

When do New York drinking water cybersecurity requirements take effect?

Appendix 5-E became effective March 11, 2026. Covered water systems generally have until January 1, 2027, to comply, while the cybersecurity training requirement and certain reporting requirements became effective immediately upon adoption.

What is a Cybersecurity Vulnerability Analysis?

A Cybersecurity Vulnerability Analysis, or CVA, is an assessment required under New York's drinking water cybersecurity regulation. It must address the requirements established in Appendix 5-E and be reviewed and updated annually. The analysis is intended to identify cybersecurity vulnerabilities that could affect regulatory compliance or pose a public health risk.

How often must a water system update its cybersecurity vulnerability analysis?

The CVA must be reviewed and updated at least annually. The New York Department of Health's requirements table also states that the CVA must be submitted to the Department every five years and within 30 days after major water facility infrastructure changes, subject to the applicable regulatory requirements.

How quickly must a New York water system report a cybersecurity incident?

A covered water system must notify the New York Department of Health within 24 hours of identifying a cybersecurity incident that may affect the system's ability to comply with applicable drinking water requirements or that may pose a public health risk.

How quickly must a water system report a cybersecurity vulnerability?

Qualifying cybersecurity vulnerabilities must be reported to the New York Department of Health within 48 hours of identification. The requirement applies to vulnerabilities that may affect compliance with Subpart 5-1 or identify a situation that may pose a public health risk.

How long does a water system have to remediate a cybersecurity vulnerability?

For qualifying vulnerabilities subject to the regulation, corrective action must start or be completed within 120 days of notification. The Department of Health also states that the system should consult with the Department within 30 days to identify appropriate mitigation steps.

What cybersecurity training is required for drinking water operators in New York?

Certified drinking water operators must complete one hour of cybersecurity training every three years. The New York Department of Health states that this requirement became effective immediately upon adoption of Appendix 5-E and has no exclusions.

What additional cybersecurity requirements apply to water systems serving more than 50,000 people?

Systems serving more than 50,000 people must designate a qualified individual responsible for the cybersecurity program, have that individual certify the program every five years, provide an annual confidential cybersecurity report to the governing body, and monitor and log network activity.

Does Microsoft 365 security satisfy New York's drinking water cybersecurity requirements?

No single technology platform satisfies the full New York drinking water cybersecurity requirements. Microsoft 365 can provide important identity, access, collaboration, and security controls, but a water system must consider its broader IT and operational technology environment, including control systems, network infrastructure, remote access, cyber assets, incident response, and recovery processes.

Where can water systems find the official New York cybersecurity requirements?

The New York State Department of Health provides an overview of the cybersecurity regulation for public water systems, while the New York Codes, Rules and Regulations provides the official applicability requirements for Appendix 5-E. The Department of Health also provides a detailed cybersecurity requirements table.