An ERO for Water: What H.R. 2594 Borrows From NERC, and What It Leaves Behind
By Patrick Miller
Water utilities in at least seven states reported cyber incidents this summer, and Congress now has two answers that point in opposite directions. One bill gives EPA direct authority. The other certifies a sector-led body to write and enforce the requirements, modeled on the electric sector. A close read of what H.R. 2594 borrows from the Federal Power Act, where it departs, and what twenty years inside that model cost.
Overview
Since late July, water and wastewater utilities in at least seven confirmed states have reported cyber incidents to the Federal Bureau of Investigation (FBI), and some of that activity degraded water operations. The spread of it has been the story of the month. The FBI and the Environmental Protection Agency (EPA) put out a joint public service announcement on July 30. The Cybersecurity and Infrastructure Security Agency (CISA) updated its internet exposure guidance three weeks later. Both documents describe programmable logic controllers (PLCs) sitting on the public internet, reachable, with passwords that could be changed by whoever got there first.
Several numbers are in circulation and they count different things. The FBI and EPA announcement says utilities in at least seven states reported incidents to the FBI since 27 July. CISA's exposure guidance refers to more than 100 internet-exposed systems observed in the water sector during July. Minnesota IT Services said on July 28 that a coordinated attack hit operational technology at more than 30 community water systems in that state on July 26 and 27, and told reporters that the nature and extent of the impact varied by system and that the investigation was still working out how many had actually experienced operational disruption. Trade reporting in late August put the spread at a dozen states. Those figures do not stack on top of each other. Reports made to the FBI are not the same as systems affected, a count of exposed devices is not a count of intrusions, and the Minnesota activity partly predates the window the FBI describes. What holds up is that the activity was coordinated, that it reached at least several dozen systems, and that nobody has published a complete accounting.
Attribution is looser than the coverage around it suggests. The FBI and EPA announcement refers only to malicious cyber actors and names nobody. Minnesota did not name anyone either, though it said the timing, methods of access, and targeted infrastructure shared characteristics with incidents its federal partners were seeing in other states. Reuters noted the activity resembles earlier intrusions that officials have previously attributed to Iranian-affiliated actors, and reporting at the end of July described a preliminary investigative view pointing the same way. That is a working hypothesis rather than a finding, and for the argument in this post it does not much matter, since the regulatory question is the same either way.
On August 13, Senators Adam Schiff and Amy Klobuchar iintroduced the Water Cyber Shield Act of 2026, which would give EPA explicit authorityto assess water systems and require them to fix what it finds. That bill is now the one getting written about. But it isn't the only model on the table, and it isn't the more interesting one for anybody who has spent time in the electric sector. Sitting in committee since April 2025 is a bill that proposes to build, for water, more or less the institution we have been living inside since 2005.
That bill is H.R. 2594, and it would create a Water Risk and Resilience Organization (WRRO). The coverage of it has been thin, so what follows is a reasonably close read of what got copied from the electric model, what didn't, and what the differences will probably feel like in about ten years. I have a lot of history with the electric version of this, which probably makes me both more useful and more biased than average on the question.
The Two Models on the Table
The two bills answer the same question in opposite ways. The Water Cyber Shield Act of 2026 (S. 5368) puts the authority in the agency. EPA would develop tiered cybersecurity standards in consultation with CISA, the National Institute of Standards and Technology (NIST), states, and sector stakeholders. It would authorize EPA to conduct assessments and require corrective action where it identifies significant vulnerabilities. It would extend federal incident reporting to state and locally owned systems that are currently exempt, protect submitted security information from disclosure, and let states with enough capacity take primary enforcement while EPA leads elsewhere. It also carries money, an additional $300 million a year to the Drinking Water and Clean Water State Revolving Funds, earmarked for cybersecurity.
H.R. 2594 puts the authority in a certified organization made up largely of the regulated community, with EPA approving what that organization writes. If you have read section 215 of the Federal Power Act, you already know the shape of it.
Neither bill has moved. H.R. 2594 was referred to Transportation and Infrastructure and to Energy and Commerce on April 2, 2025, and has picked up three cosponsors since, the most recent in September 2025. No hearing, no markup, no Senate companion. S. 5368 was introduced two weeks ago and has one cosponsor. A Schiff spokesperson has said he may look to attach it to a larger package before the end of the year, without naming one.
So the state of play is that the sector-led model has been available the entire time the water sector was getting attacked, and it went nowhere, and now there is a competing bill that would do it the other way.
What H.R. 2594 Actually Does
Within 270 days of enactment, EPA issues a final rule covering the selection and certification of the organization. After that, any organization may apply, and EPA certifies not more than one. To be certified, the applicant has to demonstrate advanced technical knowledge of covered water system operations, include one or more members with experience owning or operating covered systems, show it can develop and implement requirements that deliver an adequate level of cyber risk and resilience, and show it can protect sensitive security information from public disclosure.
Once certified, the WRRO writes the requirements and files each one with EPA, along with an implementation plan and schedule. The schedule can be phased, and the bill says outright that a requirement need not apply in totality to all covered systems. EPA approves if it finds the requirement just, reasonable, and not unduly discriminatory or preferential.
If EPA disapproves, it has to remand within 90 days and provide specific recommendations that would lead to approval. The WRRO can then accept those recommendations and refile, explain why it did not accept them, or withdraw the requirement. If the WRRO explains why not, EPA's options are to approve the requirement as filed or to invite the WRRO into negotiations to reach consensus. Separately, EPA can order the WRRO to file a requirement addressing a specific matter if EPA concludes there is a reasonable basis to think the existing requirements are insufficient.
Compliance monitoring runs on annual self-attestations by covered systems, plus an assessment by the WRRO or a designated third party at least once every five years. The WRRO reports to EPA annually, in aggregated or anonymized form only, with no sensitive security information.
Enforcement sits with the WRRO, subject to notice, an opportunity for consultation and a hearing, and the right to bring counsel. Penalties cap at $25,000 per day per violation. They take effect no earlier than 31 days after the WRRO files notice with EPA, and EPA can review, affirm, set aside, reinstate, or modify them.
The bill authorizes $10,000,000 to carry all of this out, available to the WRRO until expended, alongside the dues and fees the organization would allocate among end users.
The WRRO Against the ERO Model
| Element | WRRO under H.R. 2594 | Electric ERO under FPA section 215 |
|---|---|---|
| Certifying authority | EPA Administrator, following a final rule due within 270 days of enactment | FERC |
| Organizations certified | Not more than one | One |
| Independence requirement | Independent of users, owners, and operators, with balanced stakeholder representation in director selection and balanced committee decision making | Substantially the same language |
| Approval standard | Just, reasonable, and not unduly discriminatory or preferential | Just, reasonable, and not unduly discriminatory or preferential |
| Deference on technical content | Directed by statute. The Administrator shall defer to the WRRO's technical expertise | Extended through Commission practice and orders rather than compelled by the statute |
| On disapproval | Remand within 90 days with specific recommendations that would lead to approval | Remand for further consideration, no statutory clock of this kind |
| If the organization declines | EPA approves as filed, or invites the WRRO into negotiations to reach consensus | FERC may order the ERO to submit a new or modified standard |
| Regulator can compel a topic | Yes, where EPA finds a reasonable basis that existing requirements are insufficient | Yes |
| Compliance monitoring | Annual self-attestation, plus assessment by the WRRO or a designated third party at least every five years | Compliance Monitoring and Enforcement Program: audits, self-certifications, spot checks, self-reports, investigations, and periodic data submittals |
| Evidence standard | Attestation | Evidence retained and produced across the audit period |
| Maximum penalty | $25,000 per violation, per day | $1,000,000 per violation, per day as enacted, adjusted annually for inflation. Currently $1,584,648 |
| Collected penalties | Returned to the WRRO for training initiatives and other resource capabilities | Placed in an Assessment Stabilization Reserve and released to offset future assessments, with NERC and Commission approval |
| Startup funding | $10,000,000 authorized, available until expended, plus dues and fees allocated among end users | Annual assessments allocated across the industry, in budgets approved by FERC |
| Legal status | Not a department, agency, or instrumentality of the United States Government | Same posture |
Where the Text Follows Section 215
Whoever drafted this knew the electric model well, and in places the language has been carried across almost intact. The independence provisions require that the organization be independent of the users, owners, and operators of covered water systems, with balanced and objective stakeholder representation in the selection of directors and balanced decision making in any committee or subordinate structure. They require reasonable dues, fees, and other charges allocated among end users. They require just and reasonable enforcement procedures. They require reasonable notice and opportunity for public comment, due process, openness, and balancing of interests in developing requirements. Read section 215(c) of the Federal Power Act next to that and the family resemblance is obvious.
The approval standard, just and reasonable and not unduly discriminatory or preferential, is the Federal Power Act standard. Certifying exactly one organization is the ERO approach. And the bill states that the WRRO is not a department, agency, or instrumentality of the United States Government, which is the same posture NERC occupies.
None of that is a criticism. Borrowing a structure that has already survived two decades of litigation and practice is a sensible thing to do. Where the drafters chose not to borrow is a different matter.
Where It Departs
Five things in the text depart from the electric model in ways that seem likely to matter.
Deference is written into the statute. The bill says the Administrator shall defer to the technical expertise of the WRRO on the content of a proposed requirement. In the electric sector, deference to NERC's technical judgment developed through practice and through Commission orders, and it has always been deference that FERC extends rather than deference the statute compels. Making it a statutory instruction changes the starting position of every disagreement, and it does so in a single sentence that reads like boilerplate.
The disapproval loop has a softer ending. When EPA remands and the WRRO declines the recommendation and explains why, EPA can approve or it can invite negotiation. FERC's position in the equivalent standoff is not enormously stronger, since FERC also cannot write a reliability standard itself and can only direct NERC to submit one. But "invite the WRRO to engage in negotiations with the Administrator to reach consensus" is different in tone and probably in practice from an order, and tone is a lot of what determines how these relationships actually run.
The penalty ceiling is far lower, and it does not move. H.R. 2594 caps penalties at $25,000 per day per violation. Congress set the electric figure at $1,000,000 per day per violation in the Energy Policy Act of 2005, forty times higher, and that figure is adjusted annually for inflation. The currently codified maximum under section 316A is $1,584,648 per violation per day, which puts the water ceiling at roughly one sixtieth of the electric one. There is a real argument that a municipal system serving four thousand people should not face electric-utility exposure, and I think that argument is a decent one. The WRRO can also impose non-monetary sanctions, including limitations on activities, functions, or operations, which may matter more in practice than the dollar figure does.
H.R. 2594 also contains no inflation adjustment at all. The electric ceiling was written to hold its value and the water ceiling was not, so $25,000 erodes every year it sits on the books. If the intent is a penalty that stays consequential rather than becoming a cost of doing business, the drafting doesn't get there.
Penalties are returned to the organization that imposed them. Under the bill, penalties collected go back to the WRRO to support training initiatives and other resource capabilities. The electric model does close to the opposite. Penalty monies go into an Assessment Stabilization Reserve and, with NERC and Commission approval under Section 1107.4 of the NERC Rules of Procedure, are released to offset assessments in future years. The money comes off what industry pays the following cycle rather than funding the enforcement body, and the regional business plans show it working that way at real scale. WECC alone released roughly $10.1 million of penalty money against its 2024 assessments.
Whoever drafted H.R. 2594 borrowed a great deal from section 215 and then inverted this one particular thing. I understand the intent, since a thinly funded organization needs money and the sector would probably rather that money stay in the sector. It still creates an incentive question, and somebody is going to raise it in the first contested case. Probably a state attorney general, or a utility's outside counsel who has noticed that the body assessing the penalty is also the body that banks it.
Compliance monitoring is lighter than most electric people would expect. Annual self-attestation plus an assessment at least every five years is a different instrument from the Compliance Monitoring and Enforcement Program. Self-attestation is not self-certification against retained evidence, and there is a real gap between the two. In my auditing years, the thing that consistently produced findings was not entities lying on a form. It was entities that believed they were compliant, in good faith, and could not produce evidence that the control had operated continuously across the audit period. An attestation asks whether you think you are compliant. An audit asks you to prove it. Those questions surface very different things, and a five-year interval means a gap can persist a long time before anybody looks.
The Threshold Question
The bill defines a covered water system as a community water system or a treatment works serving 3,300 or more people. That number is not invented. It's the threshold already in section 1433 of the Safe Drinking Water Act, as amended by section 2013 of America's Water Infrastructure Act, which requires community water systems serving more than 3,300 people to complete risk and resilience assessments covering their electronic, computer, and other automated systems including the security of those systems, and to recertify every five years. So H.R. 2594 inherits both the population line and, roughly, the five-year cadence from water law that already exists.
That approach has real advantages. Every covered system already knows whether it is above or below the line, the reporting relationship exists, and nobody has to litigate a new categorization scheme. Compared to what CIP-002 went through, and is arguably still going through, that's worth something.
It also means population served does the work that consequence should be doing. The electric sector spent years arguing its way from a size-and-voltage view toward criteria keyed to what happens if the thing fails, and the argument is not finished. A system serving 3,500 people that feeds a hospital, a data center, or a generating station's cooling water is a different risk than a system serving 40,000 people with tested manual fallback and no downstream dependencies. A flat population threshold cannot see that difference. Whether that matters depends on whether the requirements the WRRO writes are graduated inside the covered population, and the bill does leave room for that by permitting phased implementation and requirements that don't apply in totality to every covered system.
The scale matters here too. The Congressional Research Service puts community water systems at nearly 50,000, with roughly 81 percent serving fewer than 3,300 people, and 84 percent of those above the line operated by local governments. That's on the order of 9,500 drinking water systems, most of them municipal, before you add wastewater treatment works. The bill authorizes $10 million to stand up an organization to write standards for, monitor, and enforce against all of them.
The States Did Not Wait
Whatever Congress does will land on top of state regimes that already exist. New York's water cybersecurity regulation took effect on March 11, 2026, after a proposal we commented on at the time, and it applies to community water systems serving more than 3,300 people, with heavier requirements above 50,000. That is the same line H.R. 2594 draws. We wrote about it when the rule was proposed and again when it came into force. New York now has vulnerability assessments, executive accountability, continuous monitoring, and 24-hour incident reporting on the books for exactly the population these federal bills would cover. New Jersey got there earlier by a different route, starting with a Board of Public Utilities order in 2016 and building out through the Water Quality Accountability Act and its 2021 amendments.
The federal side has a harder history. EPA tried to reach water cybersecurity in 2023 through sanitary survey guidance rather than rulemaking, and withdrew it after Missouri, Arkansas, Iowa, and several water associations challenged the authority. That withdrawal is the gap the Water Cyber Shield Act is written to close, and it explains why the sponsors went after explicit statutory authority instead of a reinterpretation of what EPA already had.
H.R. 2594 handles the overlap with a savings provision. Nothing in it preempts state authority to ensure the safety, adequacy, and resilience of water service, so long as the state action is not inconsistent or in conflict with a WRRO requirement. That reads as accommodating and mostly is, though it puts the WRRO in the position of setting a ceiling on state action in every area it eventually writes a requirement for. A New York system already reporting incidents inside 24 hours would want to know early whether a future WRRO requirement is a floor it comfortably clears or a pattern it has to conform to.
Where the Sector Itself Stands
One thing that separates H.R. 2594 from most cybersecurity legislation is that the regulated community asked for it. The approach traces back to a 2021 report the American Water Works Association (AWWA) commissioned from Paul Stockton, the former assistant secretary of defense for homeland defense, and AWWA has pushed the sector-led model ever since. When the bill was introduced, AWWA backed it publicly and roughly 200 of its members went to Capitol Hill during its annual fly-in to argue for it. The Association of Metropolitan Water Agencies told the Senate Environment and Public Works Committee in February 2026 testimony that the WRRO should be explored further, describing it as a way to give direction on specific actions without one-size-fits-all mandates. After the attacks, the National Association of Water Companies restated the position on August 5, with its president saying the absence of uniform standards leaves too many systems vulnerable.
That support is worth weighing carefully in both directions. A framework the regulated community actively wants is more likely to be implemented well and less likely to be litigated, which is not a small thing given that the last federal attempt died in court. It is also, by construction, a framework the regulated community expects to be able to live with, and the reason to read the monitoring and penalty provisions closely is that those are the parts where wanting to live with something and being held to it can pull apart.
Some of us have been watching this argument for a while. AWWA was pointing at the NERC CIP structure as a model back in 2021, which came up when I talked through that year's stories with Dale Peterson, and the question of whether water needed enforceable rules came around again in 2023 after an earlier round of water system intrusions. The argument has not changed much. What changed is that the attacks got specific enough to move it.
What Twenty Years of the Electric Model Actually Taught
I don't think there's a clean verdict here. The record runs in both directions and probably always will. What the ERO structure delivered. Mandatory, enforceable requirements with real consequences attached, which changed budget conversations at a lot of utilities in a way that voluntary guidance never did. A standards development process with genuine due process, where the people who have to implement a requirement get to argue about it before it binds them. Technical expertise located inside the body writing the standards rather than only inside the agency reviewing them, which produced requirements that were more implementable than they would otherwise have been. A compliance monitoring program that found real problems, including a lot of problems the entities themselves did not know they had.
What it cost, which comes up less often. The lag from identified risk to enforceable requirement is measured in years, sometimes many. Internal network security monitoring is one example, where the gap between FERC first directing the work and the obligation actually landing on medium impact systems outside control centers runs most of a decade. A compliance function grew up alongside the security function and, at some organizations, competed with it for the same people and the same money, which is not what anybody intended. And the categorization question consumed an enormous amount of sector attention that could have gone into controls.
If water adopts this model, my guess is it inherits both halves. The enforceability is the point and it will probably work. The lag is structural, not a defect of NERC specifically, and a five-year assessment interval layered on top of a multi-year standards process is a slower loop than the one the electric sector runs. Against an adversary that took control of PLCs in seven states inside a couple of weeks, a slower loop is a real cost, and I don't think the electric model is obviously the right import without accounting for it.
Questions Worth Asking Now
| Who | Questions worth asking |
|---|---|
| Water and wastewater systems above the 3,300 line | Could you produce evidence today that a control operated continuously over the past year, or only attest that you believe it did? Which of your existing AWIA risk and resilience assessment content would survive an assessor reading it as a compliance document? If a requirement landed with a three-year implementation period, what would you have to start now? |
| Systems below the line | Neither bill reaches you directly, so what does your state intend to do? If your integrator serves systems on both sides of the threshold, does their standard build change based on which customer they are serving? |
| State primacy agencies | Under the Water Cyber Shield Act, do you have the staff to take primary enforcement, and what does the assessment workload look like at your system count? Under H.R. 2594, what is left for you, given that the bill preserves state authority only where it does not conflict with a WRRO requirement? |
| Electric sector observers | If a second sector adopts the ERO structure, which parts of our experience would you actually recommend, and which would you tell them to fix in the enabling statute rather than discover later? What would you have changed in 2005 if you had known how the categorization debate would go? |
| Trade associations and their members | Support for the model is on the record and current. Does it extend to this specific text, including the statutory deference, the $25,000 uncapped-for-inflation ceiling, and penalties returned to the enforcing body? Who is expected to apply for certification, and is that organization prepared to enforce against its own members? |
What Water Systems Should Do Regardless
Neither bill has moved, and none of the work below waits on legislation. Most of it is what the FBI, EPA, CISA, and their international partners have already asked for.
Find out what you actually have connected. Scan your own public address ranges, including addresses you are not currently using, and treat anything you find as at risk until you have investigated it.
Ask your integrator for the external addresses of everything they installed, ask to be told when those addresses change, and verify independently rather than taking the answer on faith.
Get remote access off the controller. Route it through a gateway, firewall, or jump host in a separate segment, not directly to a PLC, human machine interface (HMI), or remote terminal unit (RTU).
Change default passwords, and require phishing-resistant multifactor authentication on remote access wherever the equipment supports it.
Confirm you have a known good backup of the controller program, and validate project files against known good logic before you trust them.
Test whether you can actually run manually, with a written procedure and people who have done it recently.
None of that is new advice, and most of it has been in federal guidance for years. What the last month showed is how much of it was not actually in place.
Where This Goes
The water sector is going to get a cybersecurity framework. The attacks in July made that close to certain, and the only real questions are which model, how soon, and whether it arrives as a considered choice or as whatever can be attached to a moving vehicle after the next incident.
Those of us in the electric sector have a stake in that, because if the WRRO model is adopted it will be adopted partly on our reputation, and because the next sector to be offered this structure will look at how water fares. It would be worth our while to be candid about what the model does well and what it costs, rather than flattered that somebody wants to copy it.