WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 The Cyber Incident Reporting for Critical Infrastructure Act of 2022 and its Applicability to Water and Wastewater Systems
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 and its Applicability to Water and Wastewater Systems

Author: WaterISAC Analyst

Created: Tuesday, March 15, 2022 - 16:56

Categories: Cybersecurity, Security Preparedness

Approved by the House of Representatives on March 9, 2022 and the Senate on March 10 as Division Y of H.R. 2471, the Consolidated Appropriations Act of 2022.

Brief summary:

This legislation amends the Homeland Security Act of 2002 (6 U.S.C. 651) to require covered critical infrastructure owners and operators to report defined cyber incidents to DHS’ Cybersecurity Information and Security Agency (CISA) within 72 hours of having a reasonable belief that an incident has occurred. Covered entities would also have to report to CISA within 24 of making a ransom payment related to a cyber incident, after considering alternatives to making the ransom payment. CISA will conduct rulemaking to develop the details of the program, including precise definitions of “covered entities” subject to the reporting requirements.

Applicability to water systems:

While the legislation makes no reference to drinking water or wastewater utilities, it is highly likely that at least some systems will meet the definition of “covered entities” subject to the law, when CISA completes its rulemaking. However, the water sector and other stakeholders will have an opportunity to engage with CISA and submit comments on the proposed rule as it is developed and finalized. The legislation could also present opportunities for WaterISAC to serve as a conduit for cyber threat information between CISA and water systems, and to aid water systems in submitting required incident and ransom reports to the agency. Read the attachment for a summary of specific additions to the Homeland Security Act.

Attached Files:

The Cyber Incident Reporting for Critical Infrastructure Act of 2022

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar