<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HE33A5FCCC6DE41B884D7C6298FA420EC" public-private="public" key="H" bill-type="olc">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 7922 IH: To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-04-10</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code>
<congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session>
<legis-num display="yes">H. R. 7922</legis-num>
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
<action display="yes">
<action-date date="20240410">April 10, 2024</action-date>
<action-desc><sponsor name-id="C001087">Mr. Crawford</sponsor> (for himself and <cosponsor name-id="D000633">Mr. Duarte</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HPW00">Committee on Transportation and Infrastructure</committee-name>, and in addition to the Committee on <committee-name committee-id="HIF00">Energy and Commerce</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc>
</action>
<legis-type>A BILL</legis-type>
<official-title display="yes">To establish a Water Risk and Resilience Organization to develop risk and resilience requirements for the water sector.</official-title>
</form>
<legis-body id="H255974FDBD0B4E0DA888177DEAB8B3A2" style="OLC"> 
<section id="H11727D1013EF4E96AF4354D4F8B6911E" section-type="section-one"><enum>1.</enum><header>Water risk and resilience organization</header> 
<subsection id="HCC812DC0F9D34C3597FB90E6F0FAD8AA"><enum>(a)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="HFE422F9927134AACAF705A4F80387ED5"><enum>(1)</enum><header>Administrator</header><text>The term <term>Administrator</term> means the Administrator of the Environmental Protection Agency.</text></paragraph> 
<paragraph id="H2242CDFFAC64474D8A3EABB5AAF8287D"><enum>(2)</enum><header>Agency</header><text>The term <term>Agency</term> means the Environmental Protection Agency.</text></paragraph> <paragraph id="H27EA1654B6D64030B74E0D13111996D4"><enum>(3)</enum><header>Covered water system</header><text>The term <term>covered water system</term> means—</text> 
<subparagraph id="H314D2F7855ED4EF394F6F0F36A1CC07D"><enum>(A)</enum><text>a community water system (as defined in section 1401 of the Safe Drinking Water Act (<external-xref legal-doc="usc" parsable-cite="usc/42/300f">42 U.S.C. 300f</external-xref>)) that serves a population of 3,300 or more persons; or</text></subparagraph> <subparagraph id="HA6FD7E8BEC0C4604817EB2C067AA7CAC"><enum>(B)</enum><text>a treatment works (as defined in section 212 of the Federal Water Pollution Control Act (<external-xref legal-doc="usc" parsable-cite="usc/33/1292">33 U.S.C. 1292</external-xref>)) that serves a population of 3,300 or more persons.</text></subparagraph></paragraph> 
<paragraph id="HFE656B40A3C04A9AB5D2C6ED3A6BA75C"><enum>(4)</enum><header>Cyber resilient</header><text>The term <term>cyber resilient</term> means the ability of a covered water or wastewater system to withstand or reduce the magnitude or duration of cybersecurity incidents that disrupt the covered system’s ability to function normally and which includes the capability to anticipate, absorb, adapt to, or rapidly recover from cybersecurity incidents.</text></paragraph> <paragraph id="HF145AC4049374706A3AE4CC5F6C6A6AE"><enum>(5)</enum><header>Cybersecurity incident</header><text>The term <term>cybersecurity incident</term> means a malicious act or suspicious event that disrupts, or attempts to disrupt, the operation of programmable electronic devices and communication networks including hardware, software, and data that are essential to the cyber resilient operation of a covered water system.</text></paragraph> 
<paragraph id="HADABED7F69454C3AA71F7AC53A975542"><enum>(6)</enum><header>Cybersecurity risk and resilience requirement</header><text>The term <term>cybersecurity risk and resilience requirement</term> means a cybersecurity requirement approved by the Administrator under subsection (d) to provide for the cyber resilient operation of a covered water system and the cyber resilient design of planned additions or modifications to such system.</text></paragraph> <paragraph id="H20FF2CA42209426EAA9EB386EA50CBA7"><enum>(7)</enum><header>Water risk and resilience organization</header><text>The terms <term>Water Risk and Resilience Organization</term> and <term>WRRO</term> mean the organization certified by the Agency under subsection (c).</text></paragraph></subsection> 
<subsection id="HC97D380A42AF414BBCD1DB5FD9DE46FF"><enum>(b)</enum><header>Jurisdiction and applicability</header> 
<paragraph id="H046425EE2BCC43A5BA49CECB0F8C48A2"><enum>(1)</enum><header>Jurisdiction</header><text>The Administrator shall have jurisdiction, within the United States, over the WRRO certified by the Agency under subsection (c).</text></paragraph> <paragraph id="H2438F0F30F6B4588B015D99F78DFB16B"><enum>(2)</enum><header>Regulations</header><text>Not later than 270 days after the date of enactment of this Act, the Administrator shall issue a final rule to implement this section to certify the WRRO.</text></paragraph></subsection> 
<subsection id="H6700ECE956F340EC9C2BDF696C4974D6"><enum>(c)</enum><header>Certification</header> 
<paragraph id="HBE9A1E9415F94142A0CC9B22E276F74D"><enum>(1)</enum><header>In general</header><text>Following the issuance of a rule under subsection (b)(2), any person may submit an application to the Administrator for certification as a Water Risk and Resilience Organization.</text></paragraph> <paragraph id="H50DCA402CB4E48EAA1FF0C13C4537D9F"><enum>(2)</enum><header>Requirements</header><text>The Administrator shall certify one Water Risk and Resilience Organization if the Administrator determines that such organization—</text> 
<subparagraph id="HC33A13B467264D8BA733A2C05C978CD3"><enum>(A)</enum><text>demonstrates advanced technical knowledge and expertise in the operations of covered water systems;</text></subparagraph> <subparagraph id="H37AED12EDBC1490692DEA0EC61324264"><enum>(B)</enum><text>is comprised of 1 or more members with relevant experience as owners or operators of covered water systems;</text></subparagraph> 
<subparagraph id="HB0955185D7F64A0481CCF7B8AD87FAB9"><enum>(C)</enum><text>has demonstrated the ability to develop and implement cybersecurity risk and resilience requirements that provide for an adequate level of cybersecurity risk and resilience for a covered water system;</text></subparagraph> <subparagraph id="H8361A7FEE014409EA552D5D4B4651105"><enum>(D)</enum><text>is capable of establishing measures, in line with prevailing best practices, to secure sensitive information and to protect sensitive security information from public disclosure; and</text></subparagraph> 
<subparagraph id="H8E0D2AC837E34D418F5B950A0A27D4B6"><enum>(E)</enum><text>has established rules that require that—</text> <clause id="H5A805195322F45DD821E0B8F809B7742"><enum>(i)</enum><text>it is independent of the users, owners, and operators of a covered water system, with balanced and objective stakeholder representation in the selection of directors of the organization and balanced decision making in any committee or subordinate organizational structure;</text></clause> 
<clause id="H6CF1FD57003146638B4B6AFB30563EDE"><enum>(ii)</enum><text>it allocate reasonable dues, fees, and other charges among end-users for all activities under this section;</text></clause> <clause id="HC4C4F0342C6A4A0990E495D6A2FB3743"><enum>(iii)</enum><text>provide just and reasonable procedures for enforcement of cybersecurity risk and resilience requirements and the imposition of penalties in accordance with subsection (f) (including limitations on activities, functions, or operations, or other appropriate sanctions); and</text></clause> 
<clause id="HEBC83054A1614AC0BAB42FB8C1C64124"><enum>(iv)</enum><text>provide for reasonable notice and opportunity for public comment, due process, openness, and balance of interests in developing cybersecurity risk and resilience requirements and otherwise exercising duties.</text></clause></subparagraph></paragraph></subsection> <subsection id="H3ECFC678174A4A16A60472DDEC8E9420"><enum>(d)</enum><header>Cybersecurity risk and resilience requirements</header> <paragraph id="HCE9A3C23DE134EC892647B73D8EB6D6B"><enum>(1)</enum><header>In general</header> <subparagraph id="HB44EA21E37A249B5A2A704EF2148F87D"><enum>(A)</enum><header>Proposed requirements</header><text>The WRRO shall propose and file with the Administrator each cybersecurity risk and resilience requirement or modification to a requirement that it proposes to be made effective under this section.</text></subparagraph> 
<subparagraph id="H23D65C6834E4408A8F9D1B8A90286C52"><enum>(B)</enum><header>Implementation plan</header><text>For each cybersecurity risk and resilience requirement or modification to such a requirement proposed pursuant to subparagraph (A), the WRRO shall also propose an implementation plan, including the schedule by which covered water systems must achieve compliance with all or parts of the cybersecurity risk and resilience requirement or modification to such a requirement. The enforcement date must provide a reasonable implementation period for covered water systems to meet the requirements under the implementation plan.</text></subparagraph></paragraph> <paragraph id="H310321A0AC674174935962946AAFEDE8"><enum>(2)</enum><header>Approval</header> <subparagraph id="H07B6406A15B3445FA7A6CB91319D7FC1"><enum>(A)</enum><header>In general</header><text>Notwithstanding paragraph (3)(A), the Administrator shall approve, by rule or order, a proposed cybersecurity risk and resilience requirement or modification to such a requirement if the Administrator determines that the requirement is just, reasonable, not unduly Discriminatory, or preferential.</text></subparagraph> 
<subparagraph id="H1AB8A96635AD4ACE945BC88F384D1F55"><enum>(B)</enum><header>Deference to WRRO</header><text>The Administrator shall defer to the technical expertise of the WRRO with respect to the content of a proposed cybersecurity risk and resilience requirement or modification to such a requirement.</text></subparagraph></paragraph> <paragraph id="HA6AB6AFD985046C191C807DE44780761"><enum>(3)</enum><header>Disapproval of requirement</header> <subparagraph id="H59D2D6DDD77E436C82064A020D4521BA"><enum>(A)</enum><header>In general</header><text>Notwithstanding paragraph (2)(A), the Administrator shall remand to the WRRO a proposed cybersecurity risk and resilience requirement or modification to such a requirement for which the Administrator disapproves, in whole or in part, and provide 1 or more specific recommendations that would cause the proposed requirement or modification to be approved under paragraph (2).</text></subparagraph> 
<subparagraph id="HB964A7B7F9A04A4B9FDC91183F7DFDDA"><enum>(B)</enum><header>Response and approval</header> 
<clause id="H68523A5D99CC48F6A562905C20C30DCC"><enum>(i)</enum><header>In general</header><text>Upon remand of a proposed cybersecurity risk and resilience requirement or modification to such a requirement and receipt of the Administrator’s recommendation pursuant to subparagraph (A), the WRRO shall—</text> <subclause id="HE469EC4209E24A8CAF88E635B0011E97"><enum>(I)</enum><text>accept the Administrator’s recommendation and resubmit an amended proposed cybersecurity risk and resilience requirement or modification to such a requirement consistent with the Administrator’s recommendation;</text></subclause> 
<subclause id="H497D951F33D24625833CE328ED8CD739"><enum>(II)</enum><text>respond to the Administrator and provide a reason why the recommendation was not accepted; or</text></subclause> <subclause id="HEA0FFA5264E74C02BD1DCF6ACD335035"><enum>(III)</enum><text>withdraw the proposed cybersecurity risk and resilience requirement or modification to such a requirement.</text></subclause></clause> 
<clause id="HB987F489487D4E07B10F5A257ACD0EAF"><enum>(ii)</enum><header>Amended requirement</header><text>If the WRRO resubmits a requirement or modification, the Administrator shall review an amended proposed cybersecurity risk and resilience requirement or modification to such requirement submitted by the WRRO pursuant to clause (i)(I) and determine whether to approve such amended requirement in accordance with paragraph (2)(A).</text></clause> <clause id="HECB3449F72F44C138C48AE82DB16C68F"><enum>(iii)</enum><header>Response by WRRO</header><text>Upon receipt of a response from the WRRO pursuant to clause (i)(II), the Administrator shall—</text> 
<subclause id="H60CD04A7219A41E18AE43874DB62E699"><enum>(I)</enum><text>approve the proposed cybersecurity risk and resilience requirement or modification to such a requirement; or</text></subclause> <subclause id="H0780FFD8AB2840C49E41718229EC3A1F"><enum>(II)</enum><text>invite the WRRO to engage in negotiations with the Administrator to reach consensus to address the specific recommendation made by the Administrator under subparagraph (A).</text></subclause></clause></subparagraph></paragraph> 
<paragraph id="HE67B2D07F57043D8A282EB2C43BF2702"><enum>(4)</enum><header>Effective date</header><text>The effective date of a cybersecurity risk and resilience requirement or modification to such a requirement proposed under this subsection shall be set by the Administrator in accordance with the proposed implementation plan submitted by the WRRO under paragraph (1).</text></paragraph> <paragraph id="H0E89DE41570C40DA8DFB4C8866601517"><enum>(5)</enum><header>Submission of specific requirement</header><text>The Administrator, upon the Administrator’s own motion or upon complaint and having a reasonable basis to conclude existing recommendations under the WRRO are insufficient, when implemented by covered water systems, to protect, defend, mitigate, or recover from a cybersecurity incident, may, following consultation with the WRRO, order the WRRO to submit to the Agency a proposed cybersecurity risk and resilience requirement or a modification to such a requirement that addresses a specific matter if the Administrator considers such a requirement or modified requirement necessary to protect, defend, mitigate, or recover from a cybersecurity incident.</text></paragraph> 
<paragraph id="H9DF3DE8F41B343FD85E549B192A67FCA"><enum>(6)</enum><header>Conflict</header> 
<subparagraph id="HD2B2F84139B34C34B9C7CBADB079DCF3"><enum>(A)</enum><header>In general</header><text>The final rule adopted under subsection (b)(2) shall include specific processes for the identification and timely resolution of any conflict between a cybersecurity risk and resilience requirement and any function, rule, order, tariff, or agreement accepted, approved, or ordered by the Administrator applicable to a covered water system.</text></subparagraph> <subparagraph id="H8848C61A244048B79E14213EC15BC1C7"><enum>(B)</enum><header>Compliance</header><text>A water system shall continue to comply with such function, rule, order, tariff, or agreement approved, or otherwise accepted or ordered by the Administrator unless—</text> 
<clause id="H3D9E50DCAEAB447B880F15B19257F3C4"><enum>(i)</enum><text>the Administrator finds a conflict exists between cybersecurity risk and resilience requirement and any such provision;</text></clause> <clause id="H84E29E7813E34B99A42D18ED7323756F"><enum>(ii)</enum><text>the Administrator orders a change to such provision; and</text></clause> 
<clause id="HBB5B586E8C9B49129EC974E6230D3EC7"><enum>(iii)</enum><text>the ordered change becomes effective.</text></clause></subparagraph> <subparagraph id="H9D228202B440459BA4FACB92760F593A"><enum>(C)</enum><header>Modification</header><text>If the Administrator determines that a cybersecurity risk and resilience requirement needs to be changed as a result of a conflict identified under this paragraph, the Administrator shall direct the WRRO to develop and file with the Administrator a modified cybersecurity risk and resilience requirement under this subsection, undertaken pursuant to the processes in paragraphs (1) through (4) above.</text></subparagraph></paragraph></subsection> 
<subsection id="HCD20D4F5DF6D4CA68B4ED522185521DA"><enum>(e)</enum><header>Water system monitoring and assessment</header><text>To aid in the development and adoption of appropriate and necessary cybersecurity risk and resilience requirements and modifications to requirements, the WRRO shall—</text> <paragraph id="HD5CA6A8F83E94672B7F523D83A383B0A"><enum>(1)</enum><text>routinely monitor and conduct periodic assessments, including requiring self-attestations of compliance from covered water systems annually and assessments of the covered water system by the WRRO or a designated third party not less than every five years, of the implementation of cybersecurity risk and resilience requirements, and the effectiveness of cybersecurity risk and resilience requirements for covered water systems in the United States; and</text></paragraph> 
<paragraph id="HA74C58AE6C4143869C91F43359BB6DF6"><enum>(2)</enum><text>annually submit to the Administrator a report on the implementation of cybersecurity risk and resilience requirements, the effectiveness of cybersecurity risk and resilience requirements for covered water systems in the United States, provided that such reports shall only include aggregated or anonymized findings, observations, and data, and shall not contain any sensitive security information.</text></paragraph></subsection> <subsection id="H8AAFB1F3852A409D802BC1341887EB8A"><enum>(f)</enum><header>Enforcement</header> <paragraph id="H3E63AD18F4DE403C88F28BB048580906"><enum>(1)</enum><header>In general</header><text>The WRRO may impose, subject to paragraphs (2) and (4), a penalty on an owner or operator of a covered water system for a violation of a cybersecurity risk and resilience requirement approved by the Administrator under subsection (d) if the WRRO, after notice and an opportunity for a hearing—</text> 
<subparagraph id="H3BDA1CA47AEB4D2EB8E712D6E4C9D246"><enum>(A)</enum><text>finds that the owner or operator of a covered system has violated or failed to comply with a requirement approved by the Administrator under subsection (d); and</text></subparagraph> <subparagraph id="H8A6D677D52EA4E57B4DC97D0BC2A634C"><enum>(B)</enum><text>files notice and the record of the proceeding with the Administrator.</text></subparagraph></paragraph> 
<paragraph id="H3DBE42E6C16F4826B6D67F51D66B8C25"><enum>(2)</enum><header>Notice</header><text>The WRRO may not impose a penalty on an owner or operator of a covered system under paragraph (1) unless the WRRO provides the owner or operator with notice of the alleged violation or failure to comply with a cybersecurity risk and resilience requirement and an opportunity for a consultation and a hearing prior to finding that the owner or operator has violated such requirement under paragraph (1)(A). The owner or operator of a covered water system may engage legal Counsel to take part in the consultation and hearing Requirements.</text></paragraph> <paragraph id="HE31B2DE39F54489F9539EE52C6AB48DF"><enum>(3)</enum><header>Effective date of penalty</header><text>A penalty imposed under paragraph (1) may take effect not earlier than the 31st day after the WRRO files with the Administrator notice of the penalty and the record of proceedings.</text></paragraph> 
<paragraph id="HBCE9272514454DD5969626E018574AD6"><enum>(4)</enum><header>Imposition of penalty</header><text>A penalty imposed under paragraph (1) shall not exceed $25,000 per day the entity is in violation of a cybersecurity risk and resilience requirement.</text> <subparagraph id="HEAE1A17D335F4CB48764DAA2111F26CB"><enum>(A)</enum><text>A penalty imposed under this subsection shall be the only penalty imposed for the violation. The Administrator is barred from imposing additional penalties on the covered water System for the same violation.</text></subparagraph> 
<subparagraph id="H46EC99A096EA4A0A86343684686DCECB"><enum>(B)</enum><text>Any penalties collected will be returned to the WRRO to support training initiatives and support other resource capabilities of the WRRO in carrying out its duties under this Act.</text></subparagraph></paragraph> <paragraph id="H6A0EA2B0641140D7A0EE178DF781C645"><enum>(5)</enum><header>Review by administrator</header> <subparagraph id="HA8C9239453A648408B3B3C4F31E748BA"><enum>(A)</enum><header>In general</header><text>A penalty imposed under paragraph (1) may be subject to review by the Administrator.</text></subparagraph> 
<subparagraph id="HB30DF5062E4847D5868F4481A9A76D5F"><enum>(B)</enum><header>Application for review</header><text>The Administrator may conduct a review under subparagraph (A) on the Administrator’s own motion or upon application by an owner or operator of a covered water system that is the subject of a penalty imposed under paragraph (1) filed not later than 30 days after notice of such penalty is filed with the Administrator.</text></subparagraph> <subparagraph id="HC9FC5EC3434F4C759A3EB68101B7726C"><enum>(C)</enum><header>Stay of penalty</header><text>A penalty under review by the Administrator under this paragraph may not be stayed unless the Administrator otherwise orders that such penalty be stayed upon the Administrator’s own motion or upon application by the owner or operator of the covered water system owner or operator that is the subject of such penalty.</text></subparagraph> 
<subparagraph id="H69ED57D2C52741BDAE44A12269BD786D"><enum>(D)</enum><header>Proceeding</header> 
<clause id="H3A685B0980CA4BED91805279C7319E87"><enum>(i)</enum><header>In general</header><text>In any proceeding to review a penalty imposed under paragraph (1), the Administrator, after notice and opportunity for hearing (which hearing may consist solely of the record before the WRRO and opportunity for the presentation of supporting reasons to affirm, modify, or set aside the penalty), shall by order affirm, set aside, reinstate, or modify the penalty, and, if appropriate, remand to the WRRO for further proceedings.</text></clause> <clause id="H19BC11F6508F411C86B699909ED9A187"><enum>(ii)</enum><header>Expedited procedures</header><text>The Administrator shall act expeditiously in administering all hearings under this section.</text></clause></subparagraph></paragraph></subsection> 
<subsection id="H1EAC43E729CB464EB42822AE67868F3D"><enum>(g)</enum><header>Savings provision</header> 
<paragraph id="H83598E9EFCD14EB4B151B0C1CD708F79"><enum>(1)</enum><header>Authority</header><text>Nothing in this Act authorizes the WRRO or the EPA Administrator to develop cybersecurity binding risk and resilience requirements for covered water systems, except as defined by this act.</text></paragraph> <paragraph id="H74B464455228441E9619FD91794AF6C0"><enum>(2)</enum><header>Rule of construction</header><text>Nothing in this section may be construed to preempt any authority of any State to take action to ensure the safety, adequacy, and resilience of water service within that State, as long as such action is not inconsistent with or conflicts with any cybersecurity risk and resilience requirement.</text></paragraph></subsection> 
<subsection id="HD98661273F7C4B679FA2C86400DB5F72"><enum>(h)</enum><header>Status of WRRO</header><text>The WRRO certified under subsection (c) is not a department, agency, or instrumentality of the United States Government.</text></subsection> <subsection id="HDF980BFBC82545178D293755E64D8D4D"><enum>(i)</enum><header>Authorization of appropriations</header><text>There is authorized to be appropriated to carry out this subsection $5,000,000 for each of fiscal years 2024 and 2025, to remain available to the WRRO until expended.</text></subsection></section> 
</legis-body>
</bill> 


