Indiana water and wastewater utilities face Dec. 31 cybersecurity deadline
Indiana water and wastewater facilities covered by state cybersecurity requirements have until Dec. 31, 2026, to complete a vulnerability assessment of their plant digital infrastructure and submit a certification showing that the work was completed, identified vulnerabilities were mitigated or scheduled for mitigation, and emergency response plans were updated.
The deadline applies to facilities that use computerized systems to monitor and control processes from a central location. The Indiana Department of Environmental Management identifies publicly owned treatment works and semipublic facilities classified as Class III or Class IV among the facilities covered by the requirements.
The state’s requirements are already in effect. Incident-notification provisions began July 1, 2025, meaning the December deadline is a scheduled compliance step under an existing regime, not a new law enacted in 2026.
What utilities must complete
Covered facilities must assess the cybersecurity vulnerabilities of the digital infrastructure used in their plants. The assessment must be completed by Dec. 31, 2026, and annually thereafter.
Facilities must also submit a certification by the same Dec. 31, 2026, deadline. The certification must confirm three elements: that the vulnerability assessment was completed, that vulnerabilities were mitigated or are scheduled for mitigation, and that the facility’s emergency response plan was updated.
After the initial certification, facilities must provide certifications every other year. The Indiana Department of Environmental Management’s guidance says the vulnerability assessment itself does not have to be submitted to the state. The certification, rather than the full assessment, is the document covered facilities must provide.
That distinction allows utilities to document their review and planned corrective work without treating the full technical assessment as a public filing. The requirements nevertheless create a statewide deadline for utilities to identify and address risks in systems that monitor or control water operations.
Short timelines for cyber incidents
The law also establishes reporting deadlines when covered facilities experience cyber incidents that fall within the requirements. Facilities must report incidents to the Indiana Office of Technology when required by the law.
An incident that disrupts operations must be reported within 24 hours after discovery. An incident that does not affect operations must be reported within two business days after discovery.
Those deadlines distinguish between an operationally disruptive event and one that does not affect operations. The packet does not establish that Indiana water systems were hacked, and it does not identify a newly announced August 2026 incident connected to the requirements.
Why the deadline matters
Water and wastewater utilities rely on computerized systems to monitor and control plant processes. A vulnerability assessment is intended to help a covered facility document risks in that digital infrastructure, determine whether those risks have been addressed or require planned mitigation, and connect the work to an updated emergency response plan.
For residents, the requirement creates a statewide infrastructure-security issue to watch before the end of 2026. It applies to specified public and semipublic facilities, not automatically to every private or household water provider. Completing an assessment also does not guarantee that a facility will be protected from future cyberattacks.
The cybersecurity deadline is separate from another IDEM performance target for 2026. The agency’s 2025-2027 Performance Partnership Agreement includes a goal of reducing the number of community water systems in noncompliance with health-based standards by Sept. 30, 2026. That water-quality compliance target is not the same as the cybersecurity assessment and certification deadline.
IDEM’s guidance does not establish how many covered facilities have completed the required cybersecurity work or whether any utility has been penalized. The next known step for covered facilities is to complete their assessments, address or schedule mitigation for identified vulnerabilities, update emergency response plans and submit the required certifications by Dec. 31, 2026.
Sources
- Cybersecurity for Water and Wastewater Facilities, Indiana Department of Environmental Management
- IDEM Performance Partnership Agreement 2025-2027, Indiana Department of Environmental Management
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.