<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-05-22-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>2040-AG20</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202110</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>2040</CODE>
            <NAME>Office of Water</NAME>
            <ACRONYM>OW</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>2000</CODE>
            <NAME>Environmental Protection Agency</NAME>
            <ACRONYM>EPA</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Cybersecurity in Public Water Systems</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>EPA is evaluating regulatory approaches to ensure improved cybersecurity at public water systems. EPA plans to offer separate guidance, training, and technical assistance to states and public water systems on cybersecurity. This action will provide regulatory clarity and certainty and promote the adoption of cybersecurity measures by public water systems.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Other Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>First Time Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>No</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>40 CFR 142.16</CFR>
            <CFR>40 CFR 142.2</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>5 U.S.C. 553(b)(3)(A)</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>A cyber-attack can degrade the ability of a public water system to produce and distribute safe drinking water. The risk of a cyber-attack can be reduced through the adoption of cybersecurity best practices by public water systems. Sanitary surveys, which states, tribes, or the EPA typically conduct every 3 to 5 years on all public water systems, should include an evaluation of cybersecurity to identify significant deficiencies. EPA recognizes, however, that many states currently do not assess cybersecurity practices during public water system sanitary surveys. This action is necessary to convey to states that EPA interprets existing regulations for public water system sanitary surveys as including the possible identification of significant deficiencies in cybersecurity practices.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The Administrative Procedure Act exempts interpretive rules from its notice and comment requirements. 5 U.S.C.&nbsp;section 553(b)(3)(A). The term is not defined in the APA, but the Attorney General&rsquo;s Manual on the APA, often considered to be akin to legislative history, describes them as &ldquo;rules or statements issued by an agency to advise the public of the agency&rsquo;s construction of the statutes and rules which it administers.&rdquo;</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>Provide guidance to states, tribes, and EPA on evaluating cybersecurity practices during public water system sanitary surveys without issuing an interpretive rule.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This action is an interpretation of existing responsibilities under current regulations. It establishes no new regulatory requirements and, hence, has no regulatory costs or benefits.</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The purpose of this action is to reduce the risks associated with cyber-attacks on public water systems. Because this action is not establishing new regulatory requirements, EPA has not quantified costs and benefits for it. Accordingly, EPA has not estimated the current level of risk or the possible reduction in risk due to this action.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Final Rule</TTBL_ACTION>
                <TTBL_DATE>04/00/2022</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <ADDITIONAL_INFO>.</ADDITIONAL_INFO>
        <RFA_REQUIRED>No</RFA_REQUIRED>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Undetermined</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <NAICS_LIST>
            <NAICS>
                <NAICS_CD>924110</NAICS_CD>
                <NAICS_DESC>Administration of Air and Water Resource and Solid Waste Management Programs</NAICS_DESC>
            </NAICS>
        </NAICS_LIST>
        <PRINT_PAPER>No</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Stephanie</FIRST_NAME>
                <LAST_NAME>Flaharty</LAST_NAME>
                <AGENCY>
                    <CODE>2040</CODE>
                    <NAME>Office of Water</NAME>
                    <ACRONYM>OW</ACRONYM>
                </AGENCY>
                <PHONE>202 564-5072</PHONE>
                <EMAIL>flaharty.stephanie@epa.gov</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>4601M, 1200 Pennsylvania Avenue NW,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20460</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
