Notice of Proposed Rule Making
Wastewater Cybersecurity Rules
DEC published a Notice of Proposed Rule Making with the New York State Department of State on June 25, 2025 to amend 6 NYCRR Parts 616, 650 and 750. The proposed rules would add cybersecurity regulations for wastewater treatment facilities including:
- A requirement that SPDES permittees report cybersecurity incidents;
- A requirement that POTWs establish, maintain, and implement an Emergency Response Plan that includes a Cybersecurity Incident Response Plan;
- Minimum cybersecurity controls for POTWs;
- New cybersecurity-related definitions, incorporation by reference of cybersecurity documents; and annual certifications of compliance; and
- Mandated cybersecurity trainings for certified wastewater operators*.
Copies of the documents for the proposed rulemaking, along with the Express Terms (text of proposed rule) are available on the DEC's website. Comments will be accepted until September 3, 2025.
Find more information in the June 25th Environmental Notice Bulletin.
This information was initially broadcast by the DEC via the Division of Water's new email Cybersecurity bulletin. To receive timely updates on cybersecurity from the DEC, click here to join the email bulletin.
*The proposed rule would require that certified Grade 1/1A and Grade 2/2A operators secure 2 contact hours of cybersecurity training in their five-year renewal period; Grade 3/3A and Grade 4/4A would be required to secure 4 cybersecurity training contact hours. The total contact hours for each grade will remain the same. For example, for a Grade 3A operator, 4 of the 60 contact hours submitted would be required to be approved cybersecurity training. If adopted, this change would go into effect for certificates that expire on or after January 1, 2027. We'll keep you posted.
FYI - Free cybersecurity assessments and training opportunities previously reported in Thru the Barscreen are available on the DEC's Wastewater Cybersecurity Resources Page.
|