NIS2 water sector compliance — cybersecurity for drinking water and wastewater utilities

NIS2 Water Sector Compliance Checklist: Drinking Water vs. Wastewater — Different Thresholds, Different Supervisors

Wastewater utilities didn’t exist in NIS1. Annex I Sector 7 of NIS2 Directive 2022/2555 brings wastewater collection, discharge, and treatment into EU cybersecurity law for the first time. That’s not a minor technical update — it means thousands of wastewater operators across the EU now face the same Article 21 obligations that energy and banking sectors have carried since 2023.

The complication most compliance guides skip is that Sector 6 (drinking water) and Sector 7 (wastewater) are structurally different in ways that matter for scoping, registration, and supervision. Drinking water regulation covers suppliers and distributors. Wastewater regulation covers only those collecting, disposing of, or treating waste — no distribution equivalent. The competent authority for your drinking water operations may be a different regulator than the one overseeing your wastewater side.

This checklist covers both sectors. Where the obligations diverge, you’ll find them flagged clearly. Where they are identical — which is most of Article 21 — the checklist applies to both.

Annex I Scope: Two Sectors, Two Regulatory Paths

NIS2 Annex I lists eleven highly critical sectors. Drinking water sits at Sector 6, wastewater at Sector 7. Both carry the higher supervision burden of Annex I entities, as opposed to the lighter-touch Annex II. But their scope definitions reference different EU directives and cover different operator types.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Dimension Sector 6 — Drinking Water Sector 7 — Wastewater
Reference directive Directive (EU) 2020/2184 (Drinking Water Directive) Council Directive 91/271/EEC (Urban Wastewater Treatment Directive)
Entity types covered Suppliers AND distributors of water intended for human consumption Undertakings collecting, disposing of, or treating urban, domestic, or industrial wastewater
Key exclusion Distributors for whom water distribution is a non-essential part of their main activity (e.g. a supermarket delivering bottled water) No equivalent — all qualifying undertakings of sufficient size are in scope
Present in NIS1? Yes No — entirely new in NIS2
Essential entity threshold 250+ employees OR €50M+ annual turnover 250+ employees OR €50M+ annual turnover
Important entity threshold 50–249 employees OR €10M–€50M annual turnover 50–249 employees OR €10M–€50M annual turnover
Supervisor (examples) Netherlands: Ministry of Infrastructure and Water Management; Ireland: NCSC Germany (BSI Act, Dec 2025): separate from drinking water; many states: environment ministry or dedicated water authority

The reference directive matters because it defines which specific operations you must protect. A Sector 6 operator covers the entire supply chain from abstraction and treatment through to distribution mains. A Sector 7 operator’s obligation starts where sewage enters the collection network and ends at the discharge point. For utilities running both services under one legal entity, Article 21 applies to both sets of operations but may be reported to two different national authorities.

For a full breakdown of how NIS2 defines essential and important entities across all sectors, see the NIS2 scope guide.

The 50-Employee Threshold for Small and Cooperative Water Utilities

The standard NIS2 size thresholds — 50 employees or €10 million annual turnover to qualify as an Important Entity — are assessed at the individual legal entity level, not at group or consortium level. For a water cooperative structured as a holding company with a separate operating subsidiary, the threshold is measured against the operating entity that actually delivers the service, not the parent.

Small water cooperatives with fewer than 50 direct employees frequently assume they fall below the threshold. This is the most dangerous assumption in water sector NIS2 scoping. Article 2(2) of the directive gives member states discretionary power to designate any entity — regardless of size — as an essential or important entity if it is the sole provider of a service essential to critical societal or economic activities in that member state.

For water utilities, this provision is not theoretical. A cooperative supplying drinking water to 40,000 residents with no backup provider can be — and in several member states already has been — designated as an important entity despite having 30 employees and €6 million in annual revenue. The designation is made by the national competent authority, typically in consultation with the sectoral regulator, and the operator is notified.

Three scenarios trigger mandatory designation review regardless of size:

  • Sole provider status: your utility is the only supplier of drinking water or wastewater services in a defined geographic area with no practical substitute
  • Public health dependency: disruption to your services would carry a direct and immediate public health risk (chemical dosing failure, contamination propagation)
  • Cross-border impact: your infrastructure or water source crosses a member state border, creating transnational disruption potential

If any of these apply to your organisation, do not rely on employee count to determine scope. Contact your national competent authority or consult the member state’s published entity list (required to be established by April 17, 2025 under Article 3(3)) to confirm your status before assuming you are out of scope.

Wastewater Scope Boundary: What Falls Outside Sector 7

Sector 7 scope is defined by reference to Article 2(1) to (3) of Council Directive 91/271/EEC. This means the entities covered are those dealing with urban wastewater (household and light commercial effluent), domestic wastewater, and industrial wastewater where it enters the same treatment system. What it does not cover is worth stating explicitly.

Sector 7 is not the same as waste management. Waste management — solid waste, hazardous waste logistics, landfill operations — sits in Annex II Sector 4, not Annex I Sector 7. An industrial facility that discharges process water to its own closed-loop system without connecting to a municipal sewer network is also outside Sector 7 scope. The trigger is the act of collecting, treating, or discharging wastewater in a way that constitutes a service to third parties or to the public.

For utilities that operate both a wastewater treatment facility and a composting or biogas facility using treated sludge, the NIS2 obligations apply to the wastewater treatment side of the operation. The composting facility is not in scope unless it separately qualifies under another Annex II sector (waste management). This distinction matters for asset inventory: only the IT and OT systems supporting the wastewater treatment function need to be assessed under Article 21.

The Water Sector NIS2 Compliance Checklist: 10 Domains Mapped to Article 21

Article 21(2) requires all essential and important entities to implement an all-hazards approach across ten specific domains. The checklist below maps each domain to the water sector operational reality. Items marked [DW] apply specifically to drinking water (Sector 6) operators; items marked [WW] apply specifically to wastewater (Sector 7); items with no marker apply to both.

Domain 1: Risk Analysis and Information Security Policies [Article 21(2)(a)]
Conduct an annual all-hazards risk assessment covering IT systems, OT networks (SCADA, PLCs, RTUs), third-party access paths, and physical security interfaces. Document the risk methodology. Obtain management board sign-off on the methodology and the resulting risk register. Water-sector risk assessments must explicitly address contamination events — not only data loss or system downtime — as the consequence category.
Evidence required: Risk assessment methodology document, completed risk register (XLSX), board approval record.

Domain 2: Incident Handling [Article 21(2)(b)]
Document an incident response procedure covering detection, triage, containment, eradication, recovery, and post-incident review. For significant incidents, the reporting chain is: 24-hour early warning to the competent authority or CSIRT, 72-hour detailed notification, final report within one month. A cyber event affecting water quality controls constitutes a public health incident — coordinate with the national water quality authority in parallel with NIS2 notification. For combined DW/WW utilities, identify which competent authority receives each notification before an incident occurs.
Evidence required: Incident response policy, notification forms pre-completed for the 24h/72h/1-month timeline, incident log (XLSX).

For incident response templates specific to water infrastructure, see the water incident response guide.

Domain 3: Business Continuity, Backup, and Crisis Management [Article 21(2)(c)]
Document a business continuity plan that includes manual fallback procedures for SCADA-dependent processes. Chemical dosing, pressure regulation, and chlorination controls operated via PLC must have manual override procedures that are tested at least annually. Backup coverage must extend to OT historian data and SCADA configuration files, not only IT systems. [DW] Continuity plans must address public water supply alternatives (tankering, emergency interconnects) in addition to system recovery timelines.
Evidence required: BCP with OT scope, manual override procedure, testing report with date of last test, backup schedule including OT systems.

Domain 4: Supply Chain Security [Article 21(2)(d)]
Classify all direct suppliers by criticality. For water utilities, the highest-criticality suppliers are typically: SCADA and DCS integrators, chemical dosing suppliers, remote access solution providers, and industrial network equipment vendors. Obtain security declarations from Tier 1 suppliers. Contractual security clauses should require vulnerability disclosure and incident notification.
Evidence required: Supplier register (XLSX) with criticality classification, security declarations, contractual clauses.

See the water supply chain security guide for a detailed supplier classification framework.

Domain 5: Secure Development and Vulnerability Management [Article 21(2)(e)]
Establish a vulnerability management programme covering both IT and OT assets. Active scanning of OT networks can crash legacy PLCs — use passive monitoring (SPAN port taps or network taps on industrial switches) to enumerate devices and detect anomalous commands without interrupting operations. Patch management for OT must account for vendor-certified update windows and system downtime constraints.
Evidence required: Vulnerability management policy, asset inventory (see Domain 9), patching log with OT exceptions documented and risk-accepted.

Domain 6: Effectiveness Assessment [Article 21(2)(f)]
Conduct at least annual testing of your cybersecurity controls. For OT environments, this includes testing network segmentation boundaries (can traffic cross from the corporate LAN to SCADA level without going through a controlled gateway?) and testing remote access restrictions. Document test results and remediation actions.
Evidence required: Cybersecurity assessment report, test log, remediation tracking.

Domain 7: Cyber Hygiene and Training [Article 21(2)(g)]
Deliver cybersecurity awareness training to all staff with access to IT or OT systems. For water utilities, this means including operations staff who run control room systems, not only IT personnel. [DW] Operators of drinking water treatment systems have a specific duty of care: training must cover the signs of SCADA compromise (unexpected chemical dosing changes, unexplained pressure variations) and the immediate reporting chain.
Evidence required: Training register with dates, roles, and completion status. Training content covering OT-specific threat scenarios.

Domain 8: Cryptography and Protocol Hardening [Article 21(2)(h)]
Document cryptography policies covering data at rest and in transit. In practice, most water sector OT protocols (Modbus/TCP, DNP3, IEC 60870-5-104) lack native encryption or authentication — retrofitting encryption to legacy PLCs is often impractical due to processing constraints and downtime costs. The policy must document these limitations, apply compensating controls (network segmentation, unidirectional gateways for internet-facing historian data), and risk-accept residual exposure with management sign-off.
Evidence required: Cryptography policy, OT protocol risk acceptance with management sign-off, network architecture diagram showing compensating controls.

Domain 9: Human Resources Security, Access Control, and Asset Management [Article 21(2)(i)]
Maintain a comprehensive asset inventory covering both IT and OT systems. A mid-sized utility typically operates 25 treatment sites, 300+ remote pumping and chlorination stations, and 500+ PLCs and RTUs — most of which were never designed to be catalogued or monitored. Asset inventory is the prerequisite for every other domain in this checklist; without it, you cannot accurately assess risk, scope vulnerabilities, or verify segmentation.
Evidence required: Asset register (XLSX) listing every device, firmware version, protocol, network zone, and responsible owner. For OT: include SCADA servers, historians, HMIs, PLCs, RTUs, and remote terminal units at unmanned pumping stations.

Domain 10: Multi-Factor Authentication and Secure Communications [Article 21(2)(j)]
Enforce MFA for all remote access to network and information systems, including remote access to SCADA environments and historian servers. Vendor remote access — commonly used by SCADA integrators and chemical dosing suppliers for maintenance — must use MFA-protected, session-monitored connections, not permanent VPN accounts. [WW] Wastewater utilities with industrial discharge monitoring connections must apply the same controls to any remote telemetry paths that could accept commands, not only those used for monitoring.
Evidence required: Access control policy, MFA configuration evidence, remote access session log showing vendor connections.

OT Asset Inventory: The Foundation Every Water Operator Needs First

Every domain in the compliance checklist depends on OT asset inventory. You cannot assess risk for systems you haven’t catalogued. You cannot patch devices you don’t know exist. You cannot segment networks you haven’t mapped. Yet OT asset inventory is consistently the control water utilities complete last — because it requires on-site fieldwork at unmanned remote locations, not desk-based documentation.

Active network scanning — the standard approach for IT asset discovery — creates real operational risk in OT environments. Sending unsolicited packets to a legacy PLC running Modbus/TCP can trigger unexpected behaviour, including control loop interruption. The correct approach is passive monitoring: place a network tap or configure a SPAN port on your industrial switches, capturing a copy of traffic without touching the PLCs themselves. A passive sensor can identify every device communicating on the network, its protocol, firmware version, and whether it is issuing or receiving commands.

Three categories of water sector OT assets are routinely missing from initial inventories:

  • Undocumented vendor access paths: SCADA integrators often establish permanent remote access accounts during installation and fail to remove or document them. These appear in traffic captures but not in access control logs.
  • Legacy RTUs at remote pumping stations: Many water utilities have 20-year-old remote terminal units at unmanned pumping stations communicating via DNP3 or IEC 60870-5-104. These were installed before cybersecurity documentation was a requirement and rarely appear in CMMS systems.
  • Cross-sector connections: [DW] Drinking water treatment facilities that also discharge to wastewater networks may have control interfaces that cross both operating domains. These inter-system connections must be inventoried under both Sector 6 and Sector 7 obligations if the utility falls under both.

The asset inventory does not need to be perfect before compliance work begins. Establish an initial inventory from available documentation (P&ID diagrams, CMMS data, SCADA topology drawings), then run passive discovery to fill the gaps. Treat the inventory as a living register updated after every asset change, not a one-time project. Article 21(2)(i) does not specify a minimum inventory completeness level — but a competent authority inspecting your documentation will expect to see a methodology, a version-controlled register, and evidence that you know what is connected to your critical networks.

Where Drinking Water and Wastewater Obligations Diverge in Practice

For the majority of Article 21 obligations, drinking water and wastewater operators face identical requirements. The practical divergence lies in three areas.

Competent authority and registration. Drinking water supervision is typically assigned to health or water regulators: in the Netherlands, the Ministry of Infrastructure and Water Management; in Ireland, the National Cyber Security Centre (NCSC). Wastewater supervision is more often assigned to environment ministries or separate water authorities. Germany’s NIS2 BSI Act entered into force in December 2025 and keeps drinking water and wastewater as separate sectors, each with its own regulatory path under BSI oversight.

For utilities operating both a drinking water and a wastewater service under the same legal entity, check whether your member state assigns both to a single authority. Many member states have designated different bodies for each sector. If so, you may need to register twice — once per sector — and report significant incidents to two different regulatory bodies.

Public health notification coupling. A cybersecurity incident affecting a drinking water treatment facility is simultaneously a potential public health event under the Drinking Water Directive 2020/2184. This means NIS2 Article 23 notification to the cybersecurity competent authority must be coordinated with notification to the water quality regulator — even if these are different organisations. Wastewater incidents have an equivalent coupling with the environmental regulator for events involving unauthorised discharge. Building dual-notification workflows into your incident response plan before an incident occurs is not optional.

OT risk profile. Drinking water systems operate with chemical dosing feedback loops where a control system compromise can directly affect water quality. This creates a public safety consequence that wastewater control system failures typically do not. As a result, drinking water utilities generally require tighter network segmentation between the operational technology network and the corporate IT network, more frequent manual fallback testing, and more stringent controls on who can issue commands to chemical dosing PLCs.

See the drinking water NIS2 compliance guide for a detailed technical breakdown of OT security controls for Sector 6 operators.

Penalties, Audit Deadlines, and Director Liability for Water Operators

Essential entities in Annex I sectors — which includes water utilities meeting the large-enterprise threshold — face maximum fines of €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover. These are maximum figures; competent authorities are directed to apply proportional penalties taking into account the nature, gravity, and duration of the infringement.

Article 20 of the directive creates personal liability for management bodies. Board members and senior executives can be held personally accountable for approving — or failing to oversee — the organisation’s cybersecurity risk-management measures. This is a direct departure from the NIS1 framework, which treated cybersecurity as an operational matter without personal executive accountability. In practice, this means the board must formally approve the risk assessment methodology and the resulting risk management plan, and evidence of that approval must be documented.

Enforcement timelines differ by member state. NIS2 transposition was due by October 17, 2024. Several member states completed transposition and are actively enforcing; others are still building their supervisory infrastructure. Regardless of your member state’s enforcement pace, the directive’s obligations apply from the date of transposition. Supervisory audits of essential entities — which water utilities at the large-enterprise threshold qualify as — are conducted proactively, without waiting for an incident to occur.

Frequently Asked Questions

Is my small water cooperative in scope for NIS2?
Not automatically — the standard threshold is 50 employees or €10 million annual turnover. But if your cooperative is the sole drinking water or wastewater provider in its area, your national competent authority has the power to designate you as an important entity regardless of size. Contact your national authority or check the entity list published under Article 3(3) to confirm your status before assuming you are excluded.

Does Sector 7 cover industrial wastewater discharge from a manufacturing facility?
Only if the manufacturer’s wastewater enters the urban wastewater treatment system (i.e., they connect to a municipal network). A facility managing its own closed-loop industrial wastewater system without discharging to a public sewer is not a Sector 7 entity. The entity collecting and treating that manufacturer’s wastewater (the wastewater utility) is the Sector 7 entity.

We run both drinking water and wastewater services under the same legal entity. Do we need two registrations?
It depends on your member state’s transposition. Some states assign both sectors to a single competent authority; others split supervision between a water or health regulator (for drinking water) and an environment or separate water authority (for wastewater). Germany’s BSI Act keeps them as separate regulated sectors. Check which competent authority is designated for each sector in your national transposition law or on the entity list published under Article 3(3).

What does a significant incident look like for a water utility?
Under Article 23, a significant incident is one that causes or is capable of causing severe operational disruption, financial loss, or harm to other persons. For water utilities, this includes: loss of control over chemical dosing systems, ransomware affecting SCADA or historian systems, confirmed unauthorised access to the operational technology network, or an incident causing supply interruption above the thresholds defined in your member state’s transposition law.

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

[1] European Parliament and Council. Directive (EU) 2022/2555 (NIS2) — EUR-Lex.

[2] NIS2 Directive. Article 3 — Essential and Important Entities — nis-2-directive.com.

[3] NIS2 Directive. Article 21 — Cybersecurity Risk-Management Measures — nis-2-directive.com.

[4] NIS2 Templates. Who Must Comply with NIS2: Scope, Sectors, and Size Thresholds.

[5] Jimber. SASE for Water Utilities: NIS2 SCADA Security 2026.

[6] European Commission. NIS2 Directive Implementation in the Netherlands.

[7] Netguardia. Germany’s NIS2 Implementation Law — BSI Act in Force December 2025.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: