1 | 1 | | I |
---|
2 | 2 | | 119THCONGRESS |
---|
3 | 3 | | 1 |
---|
4 | 4 | | STSESSION H. R. 2594 |
---|
5 | 5 | | To establish a Water Risk and Resilience Organization to develop risk and |
---|
6 | 6 | | resilience requirements for the water sector. |
---|
7 | 7 | | IN THE HOUSE OF REPRESENTATIVES |
---|
8 | 8 | | APRIL2, 2025 |
---|
9 | 9 | | Mr. C |
---|
10 | 10 | | RAWFORDintroduced the following bill; which was referred to the Com- |
---|
11 | 11 | | mittee on Transportation and Infrastructure, and in addition to the Com- |
---|
12 | 12 | | mittee on Energy and Commerce, for a period to be subsequently deter- |
---|
13 | 13 | | mined by the Speaker, in each case for consideration of such provisions |
---|
14 | 14 | | as fall within the jurisdiction of the committee concerned |
---|
15 | 15 | | A BILL |
---|
16 | 16 | | To establish a Water Risk and Resilience Organization to |
---|
17 | 17 | | develop risk and resilience requirements for the water sector. |
---|
18 | 18 | | Be it enacted by the Senate and House of Representa-1 |
---|
19 | 19 | | tives of the United States of America in Congress assembled, 2 |
---|
20 | 20 | | SECTION 1. WATER RISK AND RESILIENCE ORGANIZATION. 3 |
---|
21 | 21 | | (a) D |
---|
22 | 22 | | EFINITIONS.—In this section: 4 |
---|
23 | 23 | | (1) A |
---|
24 | 24 | | DMINISTRATOR.—The term ‘‘Adminis-5 |
---|
25 | 25 | | trator’’ means the Administrator of the Environ-6 |
---|
26 | 26 | | mental Protection Agency. 7 |
---|
27 | 27 | | (2) C |
---|
28 | 28 | | OVERED WATER SYSTEM .—The term ‘‘cov-8 |
---|
29 | 29 | | ered water system’’ means— 9 |
---|
30 | 30 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
31 | 31 | | ssavage on LAPJG3WLY3PROD with BILLS 2 |
---|
32 | 32 | | •HR 2594 IH |
---|
33 | 33 | | (A) a community water system (as defined 1 |
---|
34 | 34 | | in section 1401 of the Safe Drinking Water Act 2 |
---|
35 | 35 | | (42 U.S.C. 300f)) that serves a population of 3 |
---|
36 | 36 | | 3,300 or more persons; or 4 |
---|
37 | 37 | | (B) a treatment works (as defined in sec-5 |
---|
38 | 38 | | tion 212 of the Federal Water Pollution Control 6 |
---|
39 | 39 | | Act (33 U.S.C. 1292)) that serves a population 7 |
---|
40 | 40 | | of 3,300 or more persons. 8 |
---|
41 | 41 | | (3) C |
---|
42 | 42 | | YBER RESILIENT.— 9 |
---|
43 | 43 | | (A) I |
---|
44 | 44 | | N GENERAL.—The term ‘‘cyber resil-10 |
---|
45 | 45 | | ient’’ means the ability of a covered water sys-11 |
---|
46 | 46 | | tem to withstand or reduce the magnitude or 12 |
---|
47 | 47 | | duration of cybersecurity incidents that disrupt 13 |
---|
48 | 48 | | the ability of the covered water system to func-14 |
---|
49 | 49 | | tion normally. 15 |
---|
50 | 50 | | (B) I |
---|
51 | 51 | | NCLUSION.—The term ‘‘cyber resil-16 |
---|
52 | 52 | | ient’’ includes the ability of a covered water sys-17 |
---|
53 | 53 | | tem to anticipate, absorb, adapt to, or rapidly 18 |
---|
54 | 54 | | recover from cybersecurity incidents. 19 |
---|
55 | 55 | | (4) C |
---|
56 | 56 | | YBERSECURITY INCIDENT .—The term ‘‘cy-20 |
---|
57 | 57 | | bersecurity incident’’ means a malicious act or sus-21 |
---|
58 | 58 | | picious event that disrupts, or attempts to disrupt, 22 |
---|
59 | 59 | | the operation of programmable electronic devices 23 |
---|
60 | 60 | | and communication networks, including hardware, 24 |
---|
61 | 61 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
62 | 62 | | ssavage on LAPJG3WLY3PROD with BILLS 3 |
---|
63 | 63 | | •HR 2594 IH |
---|
64 | 64 | | software, and data that are essential to the cyber re-1 |
---|
65 | 65 | | silient operation of a covered water system. 2 |
---|
66 | 66 | | (5) C |
---|
67 | 67 | | YBERSECURITY RISK AND RESILIENCE RE -3 |
---|
68 | 68 | | QUIREMENT.—The term ‘‘cybersecurity risk and re-4 |
---|
69 | 69 | | silience requirement’’ means a requirement that pro-5 |
---|
70 | 70 | | vides for the cyber resilient operation of a covered 6 |
---|
71 | 71 | | water system and the cyber resilient design of 7 |
---|
72 | 72 | | planned additions or modifications to a covered 8 |
---|
73 | 73 | | water system. 9 |
---|
74 | 74 | | (6) W |
---|
75 | 75 | | ATER RISK AND RESILIENCE ORGANIZA -10 |
---|
76 | 76 | | TION; WRRO.—The terms ‘‘Water Risk and Resil-11 |
---|
77 | 77 | | ience Organization’’ and ‘‘WRRO’’ mean the organi-12 |
---|
78 | 78 | | zation certified by the Administrator under sub-13 |
---|
79 | 79 | | section (c). 14 |
---|
80 | 80 | | (b) A |
---|
81 | 81 | | PPLICABILITY.—Not later than 270 days after 15 |
---|
82 | 82 | | the date of enactment of this Act, the Administrator shall 16 |
---|
83 | 83 | | issue a final rule to carry out this section, including regu-17 |
---|
84 | 84 | | lations for the selection and certification of the WRRO 18 |
---|
85 | 85 | | under subsection (c). 19 |
---|
86 | 86 | | (c) C |
---|
87 | 87 | | ERTIFICATION.— 20 |
---|
88 | 88 | | (1) I |
---|
89 | 89 | | N GENERAL.—Following the issuance of 21 |
---|
90 | 90 | | the final rule under subsection (b)(1), any organiza-22 |
---|
91 | 91 | | tion may submit an application to the Adminis-23 |
---|
92 | 92 | | trator, at such time, in such manner, and containing 24 |
---|
93 | 93 | | such information as the Administrator may require, 25 |
---|
94 | 94 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
95 | 95 | | ssavage on LAPJG3WLY3PROD with BILLS 4 |
---|
96 | 96 | | •HR 2594 IH |
---|
97 | 97 | | for certification as the Water Risk and Resilience 1 |
---|
98 | 98 | | Organization. 2 |
---|
99 | 99 | | (2) R |
---|
100 | 100 | | EQUIREMENTS.—The Administrator shall 3 |
---|
101 | 101 | | certify not more than 1 organization that submitted 4 |
---|
102 | 102 | | an application under paragraph (1) as the Water 5 |
---|
103 | 103 | | Risk and Resilience Organization if the Adminis-6 |
---|
104 | 104 | | trator determines that the organization— 7 |
---|
105 | 105 | | (A) demonstrates advanced technical 8 |
---|
106 | 106 | | knowledge and expertise in the operations of 9 |
---|
107 | 107 | | covered water systems; 10 |
---|
108 | 108 | | (B) is comprised of 1 or more members 11 |
---|
109 | 109 | | with relevant experience as owners or operators 12 |
---|
110 | 110 | | of covered water systems; 13 |
---|
111 | 111 | | (C) has demonstrated the ability to develop 14 |
---|
112 | 112 | | and implement cybersecurity risk and resilience 15 |
---|
113 | 113 | | requirements that provide for an adequate level 16 |
---|
114 | 114 | | of cybersecurity risk and resilience for a covered 17 |
---|
115 | 115 | | water system; 18 |
---|
116 | 116 | | (D) is capable of establishing measures, in 19 |
---|
117 | 117 | | line with prevailing best practices, to secure 20 |
---|
118 | 118 | | sensitive information and to protect sensitive 21 |
---|
119 | 119 | | security information from public disclosure; and 22 |
---|
120 | 120 | | (E) has established rules that— 23 |
---|
121 | 121 | | (i) require that the organization be 24 |
---|
122 | 122 | | independent of the users, owners, and op-25 |
---|
123 | 123 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
124 | 124 | | ssavage on LAPJG3WLY3PROD with BILLS 5 |
---|
125 | 125 | | •HR 2594 IH |
---|
126 | 126 | | erators of a covered water system, with 1 |
---|
127 | 127 | | balanced and objective stakeholder rep-2 |
---|
128 | 128 | | resentation in the selection of directors of 3 |
---|
129 | 129 | | the organization and balanced decision 4 |
---|
130 | 130 | | making in any committee or subordinate 5 |
---|
131 | 131 | | organizational structure; 6 |
---|
132 | 132 | | (ii) require that the organization allo-7 |
---|
133 | 133 | | cate reasonable dues, fees, and other 8 |
---|
134 | 134 | | charges among end-users for all activities 9 |
---|
135 | 135 | | under this section; 10 |
---|
136 | 136 | | (iii) provide just and reasonable pro-11 |
---|
137 | 137 | | cedures for enforcement of cybersecurity 12 |
---|
138 | 138 | | risk and resilience requirements and the 13 |
---|
139 | 139 | | imposition of penalties in accordance with 14 |
---|
140 | 140 | | subsection (f), including limitations on ac-15 |
---|
141 | 141 | | tivities, functions, or operations, or other 16 |
---|
142 | 142 | | appropriate sanctions; and 17 |
---|
143 | 143 | | (iv) provides for reasonable notice and 18 |
---|
144 | 144 | | opportunity for public comment, due proc-19 |
---|
145 | 145 | | ess, openness, and balancing of interests in 20 |
---|
146 | 146 | | developing cybersecurity risk and resilience 21 |
---|
147 | 147 | | requirements and otherwise exercising du-22 |
---|
148 | 148 | | ties described in this section. 23 |
---|
149 | 149 | | (d) C |
---|
150 | 150 | | YBERSECURITY RISK ANDRESILIENCERE-24 |
---|
151 | 151 | | QUIREMENTS.— 25 |
---|
152 | 152 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
153 | 153 | | ssavage on LAPJG3WLY3PROD with BILLS 6 |
---|
154 | 154 | | •HR 2594 IH |
---|
155 | 155 | | (1) IN GENERAL.— 1 |
---|
156 | 156 | | (A) P |
---|
157 | 157 | | ROPOSED REQUIREMENTS .—The 2 |
---|
158 | 158 | | WRRO shall file with the Administrator each 3 |
---|
159 | 159 | | cybersecurity risk and resilience requirement or 4 |
---|
160 | 160 | | modification to such a requirement that the 5 |
---|
161 | 161 | | WRRO proposes to be made effective under this 6 |
---|
162 | 162 | | section. 7 |
---|
163 | 163 | | (B) I |
---|
164 | 164 | | MPLEMENTATION PLAN .— 8 |
---|
165 | 165 | | (i) I |
---|
166 | 166 | | N GENERAL.—For each proposed 9 |
---|
167 | 167 | | cybersecurity risk and resilience require-10 |
---|
168 | 168 | | ment or modification to such a require-11 |
---|
169 | 169 | | ment filed pursuant to subparagraph (A), 12 |
---|
170 | 170 | | the WRRO shall file an implementation 13 |
---|
171 | 171 | | plan, including the schedule for implemen-14 |
---|
172 | 172 | | tation, which may include a specified date, 15 |
---|
173 | 173 | | by which covered water systems shall 16 |
---|
174 | 174 | | achieve compliance with all of the cyberse-17 |
---|
175 | 175 | | curity risk and resilience requirement or 18 |
---|
176 | 176 | | modification to such a requirement. The 19 |
---|
177 | 177 | | implementation schedule may account for a 20 |
---|
178 | 178 | | phased rollout of the requirement, recog-21 |
---|
179 | 179 | | nizing that the requirement may not apply, 22 |
---|
180 | 180 | | in totality, to all covered water systems. 23 |
---|
181 | 181 | | (ii) R |
---|
182 | 182 | | EASONABLE DEADLINES .—The 24 |
---|
183 | 183 | | enforcement date proposed by the WRRO 25 |
---|
184 | 184 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00006 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
185 | 185 | | ssavage on LAPJG3WLY3PROD with BILLS 7 |
---|
186 | 186 | | •HR 2594 IH |
---|
187 | 187 | | in the implementation plan under clause (i) 1 |
---|
188 | 188 | | shall provide a reasonable implementation 2 |
---|
189 | 189 | | period for covered water systems to meet 3 |
---|
190 | 190 | | the requirements under the implementation 4 |
---|
191 | 191 | | plan. 5 |
---|
192 | 192 | | (2) A |
---|
193 | 193 | | PPROVAL.— 6 |
---|
194 | 194 | | (A) I |
---|
195 | 195 | | N GENERAL.—Notwithstanding para-7 |
---|
196 | 196 | | graph (3)(A), the Administrator shall approve a 8 |
---|
197 | 197 | | proposed cybersecurity risk and resilience re-9 |
---|
198 | 198 | | quirement or modification to such a require-10 |
---|
199 | 199 | | ment, including the accompanying implementa-11 |
---|
200 | 200 | | tion plan filed under paragraph (1), if the Ad-12 |
---|
201 | 201 | | ministrator determines that the requirement is 13 |
---|
202 | 202 | | just, reasonable, and not unduly discriminatory 14 |
---|
203 | 203 | | or preferential. 15 |
---|
204 | 204 | | (B) D |
---|
205 | 205 | | EFERENCE TO WRRO .—The Adminis-16 |
---|
206 | 206 | | trator shall defer to the technical expertise of 17 |
---|
207 | 207 | | the WRRO with respect to the content of a pro-18 |
---|
208 | 208 | | posed cybersecurity risk and resilience require-19 |
---|
209 | 209 | | ment or modification to such a requirement. 20 |
---|
210 | 210 | | (3) D |
---|
211 | 211 | | ISAPPROVAL OF REQUIREMENT .— 21 |
---|
212 | 212 | | (A) I |
---|
213 | 213 | | N GENERAL.—Notwithstanding para-22 |
---|
214 | 214 | | graph (2)(A), if the Administrator disapproves, 23 |
---|
215 | 215 | | in whole or in part, a filed cybersecurity risk 24 |
---|
216 | 216 | | and resilience requirement or modification to 25 |
---|
217 | 217 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00007 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
218 | 218 | | ssavage on LAPJG3WLY3PROD with BILLS 8 |
---|
219 | 219 | | •HR 2594 IH |
---|
220 | 220 | | such a requirement, the Administrator shall re-1 |
---|
221 | 221 | | mand such requirement to the WRRO and pro-2 |
---|
222 | 222 | | vide to the WRRO specific recommendations 3 |
---|
223 | 223 | | that would lead to the approval of the cyberse-4 |
---|
224 | 224 | | curity risk and resilience requirement or modi-5 |
---|
225 | 225 | | fication to such requirement under paragraph 6 |
---|
226 | 226 | | (2). 7 |
---|
227 | 227 | | (B) T |
---|
228 | 228 | | IMELINE.—The Administrator shall 8 |
---|
229 | 229 | | remand to the WRRO a proposed cybersecurity 9 |
---|
230 | 230 | | risk and resilience requirement or modification 10 |
---|
231 | 231 | | to such a requirement disapproved under sub-11 |
---|
232 | 232 | | paragraph (A), including the submission of the 12 |
---|
233 | 233 | | specific recommendations required under that 13 |
---|
234 | 234 | | subparagraph, not later than 90 days after the 14 |
---|
235 | 235 | | date on which the WRRO filed the requirement 15 |
---|
236 | 236 | | or modification with the Administrator under 16 |
---|
237 | 237 | | paragraph (1)(A). 17 |
---|
238 | 238 | | (C) R |
---|
239 | 239 | | ESPONSE AND APPROVAL .— 18 |
---|
240 | 240 | | (i) I |
---|
241 | 241 | | N GENERAL.—On receipt of the 19 |
---|
242 | 242 | | remand of a proposed cybersecurity risk 20 |
---|
243 | 243 | | and resilience requirement or modification 21 |
---|
244 | 244 | | to such a requirement and receipt of the 22 |
---|
245 | 245 | | specific recommendations of the Adminis-23 |
---|
246 | 246 | | trator pursuant to subparagraph (A), the 24 |
---|
247 | 247 | | WRRO shall— 25 |
---|
248 | 248 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00008 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
249 | 249 | | ssavage on LAPJG3WLY3PROD with BILLS 9 |
---|
250 | 250 | | •HR 2594 IH |
---|
251 | 251 | | (I) accept the recommendations 1 |
---|
252 | 252 | | of the Administrator and resubmit an 2 |
---|
253 | 253 | | amended proposed cybersecurity risk 3 |
---|
254 | 254 | | and resilience requirement or modi-4 |
---|
255 | 255 | | fication to such a requirement con-5 |
---|
256 | 256 | | sistent with those recommendations; 6 |
---|
257 | 257 | | (II) provide to the Administrator 7 |
---|
258 | 258 | | and a reason why the recommendation 8 |
---|
259 | 259 | | was not accepted; or 9 |
---|
260 | 260 | | (III) withdraw the proposed cy-10 |
---|
261 | 261 | | bersecurity risk and resilience require-11 |
---|
262 | 262 | | ment or modification to such a re-12 |
---|
263 | 263 | | quirement. 13 |
---|
264 | 264 | | (ii) A |
---|
265 | 265 | | MENDED REQUIREMENT .—If the 14 |
---|
266 | 266 | | WRRO files an amended proposed cyberse-15 |
---|
267 | 267 | | curity risk and resilience requirement or 16 |
---|
268 | 268 | | modification to such a requirement under 17 |
---|
269 | 269 | | clause (i)(I) the Administrator shall review 18 |
---|
270 | 270 | | such proposed requirement or modification 19 |
---|
271 | 271 | | and determine whether to approve such 20 |
---|
272 | 272 | | amended requirement or modification in 21 |
---|
273 | 273 | | accordance with paragraph (2)(A). 22 |
---|
274 | 274 | | (iii) R |
---|
275 | 275 | | ESPONSE BY WRRO.—On receipt 23 |
---|
276 | 276 | | of a response from the WRRO pursuant to 24 |
---|
277 | 277 | | clause (i)(II), the Administrator shall— 25 |
---|
278 | 278 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00009 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
279 | 279 | | ssavage on LAPJG3WLY3PROD with BILLS 10 |
---|
280 | 280 | | •HR 2594 IH |
---|
281 | 281 | | (I) approve the proposed cyberse-1 |
---|
282 | 282 | | curity risk and resilience requirement 2 |
---|
283 | 283 | | or modification to such a requirement; 3 |
---|
284 | 284 | | or 4 |
---|
285 | 285 | | (II) invite the WRRO to engage 5 |
---|
286 | 286 | | in negotiations with the Administrator 6 |
---|
287 | 287 | | to reach consensus to address the spe-7 |
---|
288 | 288 | | cific recommendation made by the Ad-8 |
---|
289 | 289 | | ministrator under subparagraph (A). 9 |
---|
290 | 290 | | (4) E |
---|
291 | 291 | | FFECTIVE DATE.—The effective date of an 10 |
---|
292 | 292 | | approved cybersecurity risk and resilience require-11 |
---|
293 | 293 | | ment or modification to such a requirement pro-12 |
---|
294 | 294 | | posed under this subsection shall be set by the Ad-13 |
---|
295 | 295 | | ministrator in accordance with the proposed imple-14 |
---|
296 | 296 | | mentation plan submitted by the WRRO under para-15 |
---|
297 | 297 | | graph (1). 16 |
---|
298 | 298 | | (5) S |
---|
299 | 299 | | UBMISSION OF SPECIFIC REQUIREMENT .— 17 |
---|
300 | 300 | | The Administrator, on the motion of the Adminis-18 |
---|
301 | 301 | | trator or on complaint may, following consultation 19 |
---|
302 | 302 | | with the WRRO, order the WRRO to file with the 20 |
---|
303 | 303 | | Administrator under paragraph (1) a proposed cy-21 |
---|
304 | 304 | | bersecurity risk and resilience requirement or modi-22 |
---|
305 | 305 | | fication to such as requirement that addresses a spe-23 |
---|
306 | 306 | | cific matter if the Administrator determines there is 24 |
---|
307 | 307 | | a reasonable basis to conclude the existing cyberse-25 |
---|
308 | 308 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00010 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
309 | 309 | | ssavage on LAPJG3WLY3PROD with BILLS 11 |
---|
310 | 310 | | •HR 2594 IH |
---|
311 | 311 | | curity risk and resilience requirements are insuffi-1 |
---|
312 | 312 | | cient, when implemented by covered water systems, 2 |
---|
313 | 313 | | to protect, defend, or recover from or mitigate a cy-3 |
---|
314 | 314 | | bersecurity incident. 4 |
---|
315 | 315 | | (6) C |
---|
316 | 316 | | ONFLICT.— 5 |
---|
317 | 317 | | (A) I |
---|
318 | 318 | | N GENERAL.—The final rule adopted 6 |
---|
319 | 319 | | under subsection (b)(2) shall include specific 7 |
---|
320 | 320 | | processes for the identification and timely reso-8 |
---|
321 | 321 | | lution of any conflict between a cybersecurity 9 |
---|
322 | 322 | | risk and resilience requirement and any func-10 |
---|
323 | 323 | | tion, rule, order, tariff, or agreement accepted, 11 |
---|
324 | 324 | | approved, or ordered by the Administrator that 12 |
---|
325 | 325 | | is applicable to a covered water system. 13 |
---|
326 | 326 | | (B) C |
---|
327 | 327 | | OMPLIANCE.—A covered water sys-14 |
---|
328 | 328 | | tem shall continue to comply with a function, 15 |
---|
329 | 329 | | rule, order, tariff, or agreement described in 16 |
---|
330 | 330 | | subparagraph (A) unless— 17 |
---|
331 | 331 | | (i) the Administrator finds a conflict 18 |
---|
332 | 332 | | exists between a cybersecurity risk and re-19 |
---|
333 | 333 | | silience requirement and any function, 20 |
---|
334 | 334 | | rule, order, tariff, or agreement approved 21 |
---|
335 | 335 | | or otherwise accepted or ordered by the 22 |
---|
336 | 336 | | Administrator; 23 |
---|
337 | 337 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00011 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
338 | 338 | | ssavage on LAPJG3WLY3PROD with BILLS 12 |
---|
339 | 339 | | •HR 2594 IH |
---|
340 | 340 | | (ii) the Administrator orders a change 1 |
---|
341 | 341 | | to that function, rule, order, tariff, or 2 |
---|
342 | 342 | | agreement; and 3 |
---|
343 | 343 | | (iii) the ordered change becomes effec-4 |
---|
344 | 344 | | tive. 5 |
---|
345 | 345 | | (C) M |
---|
346 | 346 | | ODIFICATION.—If the Administrator 6 |
---|
347 | 347 | | determines that a cybersecurity risk and resil-7 |
---|
348 | 348 | | ience requirement needs to be changed as a re-8 |
---|
349 | 349 | | sult of a conflict identified under this para-9 |
---|
350 | 350 | | graph, the Administrator shall direct the 10 |
---|
351 | 351 | | WRRO to propose and file with the Adminis-11 |
---|
352 | 352 | | trator a modified cybersecurity risk and resil-12 |
---|
353 | 353 | | ience requirement pursuant to paragraphs (1) 13 |
---|
354 | 354 | | through (4) of this section. 14 |
---|
355 | 355 | | (e) W |
---|
356 | 356 | | ATERSYSTEMMONITORING AND ASSESS-15 |
---|
357 | 357 | | MENT.—To aid in the development and adoption of appro-16 |
---|
358 | 358 | | priate and necessary cybersecurity risk and resilience re-17 |
---|
359 | 359 | | quirements and modifications to such requirements, the 18 |
---|
360 | 360 | | WRRO shall— 19 |
---|
361 | 361 | | (1) routinely monitor and conduct periodic as-20 |
---|
362 | 362 | | sessments of the implementation of cybersecurity 21 |
---|
363 | 363 | | risk and resilience requirements approved by the Ad-22 |
---|
364 | 364 | | ministrator under subsection (d) and the effective-23 |
---|
365 | 365 | | ness of cybersecurity risk and resilience require-24 |
---|
366 | 366 | | ments for covered systems, including by requiring— 25 |
---|
367 | 367 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00012 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
368 | 368 | | ssavage on LAPJG3WLY3PROD with BILLS 13 |
---|
369 | 369 | | •HR 2594 IH |
---|
370 | 370 | | (A) annual self-attestations of compliance 1 |
---|
371 | 371 | | with such cybersecurity risk and resilience re-2 |
---|
372 | 372 | | quirements by covered water systems; and 3 |
---|
373 | 373 | | (B) assessments of the covered water sys-4 |
---|
374 | 374 | | tem by the WRRO or by a third party des-5 |
---|
375 | 375 | | ignated by the WRRO not less frequently than 6 |
---|
376 | 376 | | every 5 years of compliance by covered water 7 |
---|
377 | 377 | | systems with such cybersecurity risk and resil-8 |
---|
378 | 378 | | ience requirements; and 9 |
---|
379 | 379 | | (2) annually submit to the Administrator a re-10 |
---|
380 | 380 | | port describing the implementation of cybersecurity 11 |
---|
381 | 381 | | risk and resilience requirements approved by the Ad-12 |
---|
382 | 382 | | ministrator under subsection (d) and the effective-13 |
---|
383 | 383 | | ness of cybersecurity risk and resilience require-14 |
---|
384 | 384 | | ments for covered water systems subject to the re-15 |
---|
385 | 385 | | quirements that reports under this paragraph— 16 |
---|
386 | 386 | | (A) shall only include aggregated or 17 |
---|
387 | 387 | | anonymized findings, observations, and data; 18 |
---|
388 | 388 | | and 19 |
---|
389 | 389 | | (B) shall not contain any sensitive security 20 |
---|
390 | 390 | | information. 21 |
---|
391 | 391 | | (f) E |
---|
392 | 392 | | NFORCEMENT.— 22 |
---|
393 | 393 | | (1) I |
---|
394 | 394 | | N GENERAL.—The WRRO may, subject to 23 |
---|
395 | 395 | | paragraphs (2) through (5), impose a penalty on the 24 |
---|
396 | 396 | | owner or operator of a covered water system for a 25 |
---|
397 | 397 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00013 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
398 | 398 | | ssavage on LAPJG3WLY3PROD with BILLS 14 |
---|
399 | 399 | | •HR 2594 IH |
---|
400 | 400 | | violation of a cybersecurity risk and resilience re-1 |
---|
401 | 401 | | quirement if the WRRO, after notice and an oppor-2 |
---|
402 | 402 | | tunity for a consultation and a hearing— 3 |
---|
403 | 403 | | (A) finds that the owner or operator of a 4 |
---|
404 | 404 | | covered system has violated or failed to comply 5 |
---|
405 | 405 | | with the cybersecurity risk and resilience re-6 |
---|
406 | 406 | | quirement; and 7 |
---|
407 | 407 | | (B) files notice of the finding under sub-8 |
---|
408 | 408 | | paragraph (A) and the record of the proceeding 9 |
---|
409 | 409 | | with the Administrator. 10 |
---|
410 | 410 | | (2) N |
---|
411 | 411 | | OTICE.— 11 |
---|
412 | 412 | | (A) I |
---|
413 | 413 | | N GENERAL.—The WRRO may not 12 |
---|
414 | 414 | | impose a penalty on the owner or operator of a 13 |
---|
415 | 415 | | covered water system under paragraph (1) un-14 |
---|
416 | 416 | | less the WRRO provides the owner or operator 15 |
---|
417 | 417 | | with— 16 |
---|
418 | 418 | | (i) notice of the alleged violation of or 17 |
---|
419 | 419 | | failure to comply with a cybersecurity risk 18 |
---|
420 | 420 | | and resilience requirement; and 19 |
---|
421 | 421 | | (ii) an opportunity for a consultation 20 |
---|
422 | 422 | | and a hearing prior to finding that the 21 |
---|
423 | 423 | | owner or operator has violated or failed to 22 |
---|
424 | 424 | | comply with the applicable cybersecurity 23 |
---|
425 | 425 | | risk and resilience requirement under para-24 |
---|
426 | 426 | | graph (1)(A). 25 |
---|
427 | 427 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00014 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
428 | 428 | | ssavage on LAPJG3WLY3PROD with BILLS 15 |
---|
429 | 429 | | •HR 2594 IH |
---|
430 | 430 | | (B) ACCESS TO COUNSEL.—The owner or 1 |
---|
431 | 431 | | operator of a covered water system may engage 2 |
---|
432 | 432 | | legal counsel to take part in the consultation 3 |
---|
433 | 433 | | and hearing described in subparagraph (A)(ii). 4 |
---|
434 | 434 | | (3) E |
---|
435 | 435 | | FFECTIVE DATE OF PENALTY .—A penalty 5 |
---|
436 | 436 | | imposed under paragraph (1) may take effect not 6 |
---|
437 | 437 | | earlier than 31 days after the date on which the 7 |
---|
438 | 438 | | WRRO files with the Administrator notice of the 8 |
---|
439 | 439 | | penalty and the record of proceedings under sub-9 |
---|
440 | 440 | | paragraph (B) of that paragraph. 10 |
---|
441 | 441 | | (4) I |
---|
442 | 442 | | MPOSITION OF PENALTY .— 11 |
---|
443 | 443 | | (A) M |
---|
444 | 444 | | AXIMUM AMOUNT .—A penalty im-12 |
---|
445 | 445 | | posed under paragraph (1) shall not exceed 13 |
---|
446 | 446 | | $25,000 per day the applicable owner or oper-14 |
---|
447 | 447 | | ator is in violation of a cybersecurity risk and 15 |
---|
448 | 448 | | resilience requirement approved by the Adminis-16 |
---|
449 | 449 | | trator under subsection (d). 17 |
---|
450 | 450 | | (B) L |
---|
451 | 451 | | IMITATION.—No penalty may be im-18 |
---|
452 | 452 | | posed on a covered water system under any 19 |
---|
453 | 453 | | other provision of law for a violation of a cyber-20 |
---|
454 | 454 | | security risk and resilience requirement ap-21 |
---|
455 | 455 | | proved by the Administrator under subsection 22 |
---|
456 | 456 | | (d). 23 |
---|
457 | 457 | | (C) U |
---|
458 | 458 | | SE OF PENALTY FUNDS .—Any pen-24 |
---|
459 | 459 | | alties collected under this subsection shall be re-25 |
---|
460 | 460 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00015 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
461 | 461 | | ssavage on LAPJG3WLY3PROD with BILLS 16 |
---|
462 | 462 | | •HR 2594 IH |
---|
463 | 463 | | turned to the WRRO to support training initia-1 |
---|
464 | 464 | | tives and other resource capabilities of the 2 |
---|
465 | 465 | | WRRO in carrying out the duties of the WRRO 3 |
---|
466 | 466 | | under this section. 4 |
---|
467 | 467 | | (5) R |
---|
468 | 468 | | EVIEW BY ADMINISTRATOR .— 5 |
---|
469 | 469 | | (A) I |
---|
470 | 470 | | N GENERAL.—The Administrator may 6 |
---|
471 | 471 | | review a penalty imposed under paragraph (1). 7 |
---|
472 | 472 | | (B) A |
---|
473 | 473 | | PPLICATION FOR REVIEW .—The Ad-8 |
---|
474 | 474 | | ministrator may conduct a review under sub-9 |
---|
475 | 475 | | paragraph (A) on the motion of the Adminis-10 |
---|
476 | 476 | | trator or on application by an owner or oper-11 |
---|
477 | 477 | | ator of a covered water system that is the sub-12 |
---|
478 | 478 | | ject of a penalty imposed under paragraph (1), 13 |
---|
479 | 479 | | if such application is filed not later than 30 14 |
---|
480 | 480 | | days after the date on which the notice of that 15 |
---|
481 | 481 | | penalty is filed with the Administrator. 16 |
---|
482 | 482 | | (C) S |
---|
483 | 483 | | TAY OF PENALTY.—A penalty under 17 |
---|
484 | 484 | | review by the Administrator under this para-18 |
---|
485 | 485 | | graph may only be stayed if, on the motion of 19 |
---|
486 | 486 | | the Administrator or on application by the 20 |
---|
487 | 487 | | owner or operator of the covered water system 21 |
---|
488 | 488 | | that is the subject of the penalty, the Adminis-22 |
---|
489 | 489 | | trator separately orders the stay of the penalty. 23 |
---|
490 | 490 | | (D) P |
---|
491 | 491 | | ROCEEDINGS.— 24 |
---|
492 | 492 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00016 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
493 | 493 | | ssavage on LAPJG3WLY3PROD with BILLS 17 |
---|
494 | 494 | | •HR 2594 IH |
---|
495 | 495 | | (i) IN GENERAL.—In any proceeding 1 |
---|
496 | 496 | | to review a penalty imposed under para-2 |
---|
497 | 497 | | graph (1), the Administrator, after notice 3 |
---|
498 | 498 | | and, subject to clause (ii), opportunity for 4 |
---|
499 | 499 | | a hearing, shall by order affirm, set aside, 5 |
---|
500 | 500 | | reinstate, or modify the penalty, and, if ap-6 |
---|
501 | 501 | | propriate, remand to the WRRO for fur-7 |
---|
502 | 502 | | ther proceedings. 8 |
---|
503 | 503 | | (ii) R |
---|
504 | 504 | | ECORD BELOW .—A hearing 9 |
---|
505 | 505 | | under clause (i) may consist solely of the 10 |
---|
506 | 506 | | record before the WRRO and an oppor-11 |
---|
507 | 507 | | tunity for the presentation of supporting 12 |
---|
508 | 508 | | reasons to affirm, modify, or set aside the 13 |
---|
509 | 509 | | applicable penalty. 14 |
---|
510 | 510 | | (iii) E |
---|
511 | 511 | | XPEDITED PROCEDURES .—The 15 |
---|
512 | 512 | | Administrator shall act expeditiously in ad-16 |
---|
513 | 513 | | ministering all proceedings under this 17 |
---|
514 | 514 | | paragraph. 18 |
---|
515 | 515 | | (g) S |
---|
516 | 516 | | AVINGSPROVISIONS.— 19 |
---|
517 | 517 | | (1) A |
---|
518 | 518 | | UTHORITY.—Nothing in this section au-20 |
---|
519 | 519 | | thorizes the WRRO or the Administrator to develop 21 |
---|
520 | 520 | | binding cybersecurity risk and resilience require-22 |
---|
521 | 521 | | ments for covered water systems, except as specifi-23 |
---|
522 | 522 | | cally provided for in this Act. 24 |
---|
523 | 523 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00017 Fmt 6652 Sfmt 6201 E:\BILLS\H2594.IH H2594 |
---|
524 | 524 | | ssavage on LAPJG3WLY3PROD with BILLS 18 |
---|
525 | 525 | | •HR 2594 IH |
---|
526 | 526 | | (2) RULE OF CONSTRUCTION .—Nothing in this 1 |
---|
527 | 527 | | section preempts any authority of any State to take 2 |
---|
528 | 528 | | action to ensure the safety, adequacy, and resilience 3 |
---|
529 | 529 | | of water service within that State, as long as such 4 |
---|
530 | 530 | | action is not inconsistent with or in conflict with any 5 |
---|
531 | 531 | | cybersecurity risk and resilience requirement. 6 |
---|
532 | 532 | | (h) S |
---|
533 | 533 | | TATUS OFWRRO.—The WRRO is not a depart-7 |
---|
534 | 534 | | ment, agency, or instrumentality of the United States 8 |
---|
535 | 535 | | Government. 9 |
---|
536 | 536 | | (i) A |
---|
537 | 537 | | UTHORIZATION OF APPROPRIATIONS.—There is 10 |
---|
538 | 538 | | authorized to be appropriated to carry out this section 11 |
---|
539 | 539 | | $10,000,000 to remain available to the WRRO until ex-12 |
---|
540 | 540 | | pended. 13 |
---|
541 | 541 | | Æ |
---|
542 | 542 | | VerDate Sep 11 2014 22:29 Apr 07, 2025 Jkt 059200 PO 00000 Frm 00018 Fmt 6652 Sfmt 6301 E:\BILLS\H2594.IH H2594 |
---|
543 | 543 | | ssavage on LAPJG3WLY3PROD with BILLS |
---|