Skip to main content
Back to overview

NIS2 for the Water Sector: What Drinking Water and Wastewater Utilities Must Prove

By NIS2Certify
nis2water-sectorot-securitycritical-infrastructurecer-directive
NIS2 for the Water Sector: What Drinking Water and Wastewater Utilities Must Prove

On 17 July 2026 the deadline passed for Member States to identify critical entities under the CER Directive (EU) 2022/2557. Drinking water and waste water are both in scope of that directive. Any water operator that got identified is now automatically an essential entity under NIS2 — Article 3(1)(e) says so directly, and no employee count or turnover figure changes that outcome.

If you advise water utilities, that letter has already landed on some of your clients' desks. Most of them have not told you.

The NIS2 water sector problem is not that the rules are unclear. It is that water operators run twenty-year-old process control networks, employ two or three people who understand them, and have never been supervised by a cybersecurity regulator before. The gap between what Article 21 asks for and what a regional utility can evidence today is the widest of any sector I work in.

Annex I puts water in the highest supervisory tier

NIS2 lists drinking water as sector 6 and waste water as sector 7 of Annex I — the sectors of high criticality. That placement decides how hard your client gets supervised, not just whether they are in scope.

Annex I entities above the large-enterprise ceiling — more than 250 staff, or turnover above €50 million and a balance sheet total above €43 million — are essential entities. Annex I entities in the medium bracket are important entities.

The difference is not cosmetic. Essential entities face ex-ante supervision under Article 32: on-site inspections, regular and targeted security audits, and security scans that the regulator can order without any incident having occurred. Important entities are supervised ex-post under Article 33 — the regulator acts on evidence of non-compliance, usually after something has gone wrong.

For a water utility, ex-ante means an auditor can walk into the treatment plant next quarter. There is no incident to wait for.

Two exclusions are worth knowing. Distributors for whom water distribution is a non-essential part of a broader commodity business fall outside sector 6. Undertakings for whom waste water handling is a non-essential part of their general activity fall outside sector 7 — which is how many industrial sites with on-site treatment stay out.

Size thresholds do not settle scope for water utilities

This is where most consultants get it wrong. They run the headcount test, find 38 employees, and close the file.

Article 2(2) overrides the size-cap rule in several cases that hit water operators specifically:

  • Article 2(2)(b) — the entity is the sole provider in a Member State of a service essential for the maintenance of critical societal or economic activities. A municipality's only drinking water supplier meets this routinely.
  • Article 2(2)(c) — disruption of the service could have a significant impact on public safety, public security or public health. Contaminated or interrupted drinking water is the textbook case.
  • Article 2(2)(d) — disruption could induce systemic risk, particularly for sectors where it could have a cross-border impact.
  • Article 3(1)(e) — the entity has been identified as a critical entity under the CER Directive.

In the water sector these are not edge cases. They are the normal path into scope for small operators. A 30-person municipal water board can be an essential entity while a 400-person software company stays out entirely.

Does NIS2 Apply to Your Organisation?

1

Does your organisation operate in an essential or important sector (energy, transport, health, digital infrastructure, etc.)?

YesNo
2

Does your organisation have 50 or more employees, or an annual turnover exceeding €10 million?

YesNo
3

Is your organisation a critical infrastructure provider or a qualified trust service provider?

YesNo

NIS2 does not directly apply to your organisation.

NIS2 applies to your organisation as an Essential or Important Entity.

!

NIS2 may apply to your organisation — seek legal advice to confirm your status.

Applies
Possibly applies
Does not apply

Before you tell a water client they are out of scope, check whether the national authority has designated them. In several Member States the designation list is not public, and the operator only finds out by letter. Ask to see the correspondence. Then check which regulator actually holds jurisdiction — for multi-site operators that is not always obvious, and we covered the Article 26 logic in which regulator supervises you.

There is no EU implementing act for water — and that cuts both ways

Commission Implementing Regulation (EU) 2024/2690 sets out detailed technical and methodological requirements for the Article 21 measures. It applies to DNS providers, TLD registries, cloud and data centre providers, CDNs, managed service providers, managed security service providers, online marketplaces, search engines, social networks and trust service providers.

It does not apply to water.

Article 21(5) obliged the Commission to adopt that act for the digital categories. For every other sector, including water, it may adopt one. So far it has not.

The practical consequence: your water clients are held to Article 21(2) as written, interpreted by their national authority, with no EU-level baseline telling them what "appropriate and proportionate" means in a pumping station. Some regulators have published sector guidance. Others point at IEC 62443 and leave it there.

That ambiguity is a risk during an audit and an opportunity in a proposal. The utility cannot buy a certified answer off the shelf. Someone has to write the risk-based justification for each control — and defend it. That is billable work, and it is the work that determines whether the audit goes well.

Article 21 for a water utility means OT, not the office network

Every one of the ten measures in Article 21(2) has to reach the process control environment. Most utility documentation stops at the corporate firewall.

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control

Where water operators fail in practice:

Asset inventory. Article 21(2)(i) requires asset management. Ask a utility for a list of every PLC, RTU, HMI and engineering workstation across its sites, with firmware versions. In my experience fewer than one in five can produce it without a discovery project. You cannot risk-assess what you have not counted.

Network segmentation. SCADA networks running Modbus, DNP3 and IEC 60870-5-104 have no native authentication. Anything that reaches the segment can command it. The control the auditor wants to see is a documented, enforced boundary between IT and OT with an inventory of every permitted flow — the same battle we described for manufacturers and the IT/OT boundary.

Remote access. Integrator VPNs into the control network are the single most common finding. Article 21(2)(j) covers secured voice, video and text communications and multi-factor authentication. A shared vendor credential with permanent access is indefensible.

Patching. Article 21(2)(e) covers vulnerability handling. A plant that cannot take downtime needs compensating controls and a written justification for the deferral, not silence.

Business continuity. Article 21(2)(c) covers backup and crisis management. For a water utility this includes the manual fallback: can the plant run on local control if SCADA is lost, and has anyone tested it this year? Our backup and continuity breakdown sets out what evidence looks like.

Reporting starts when the process is affected, not when IT notices

Article 23 gives three deadlines for a significant incident: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.

NIS2 Incident Reporting Timeline

24h

Early Warning

Notify the competent authority (CSIRT/NCA) within 24 hours of becoming aware of a significant incident.

72h

Incident Notification

Submit a detailed notification within 72 hours with an initial assessment of severity, impact and indicators of compromise.

1mo

Final Report

Deliver a comprehensive final report within one month covering root cause, remediation taken and cross-border impact.

The trap in the water sector is the trigger. A significant incident under Article 23(3) is one that has caused or is capable of causing severe operational disruption of the services, or financial loss, or that has affected other persons by causing considerable material or non-material damage.

For a utility, "capable of causing" includes a chemical dosing anomaly, a lost telemetry link to a remote reservoir, or a workstation compromise on the engineering network. None of those look like a cyber incident to a plant operator. They look like Tuesday.

If the plant team does not know that a dosing anomaly of unclear origin starts a 24-hour clock, the entity misses the deadline regardless of how good the security stack is. The control that fixes this is not technical. It is a written trigger list, agreed with operations, sitting next to the SCADA console.

Write it in their language. "Unexplained setpoint change" beats "integrity violation" every time.

Most water operators now carry two regimes at once

CER and NIS2 were designed as a pair. CER covers physical resilience — site security, personnel vetting, continuity of the physical service. NIS2 covers the cyber side. Drinking water and waste water sit in the annexes of both.

An operator identified as a critical entity under CER must appoint a point of contact, carry out a risk assessment, take resilience measures and report disruptive incidents — while simultaneously meeting Article 21 and Article 23 under NIS2, with a different regulator in several Member States.

Do not run these as two projects. The risk assessment, the asset register, the incident procedure and the exercise programme should be one set of artefacts serving both regimes. Utilities that separate them end up with two contradictory risk registers and an auditor who finds the contradiction first.

Where to start

Three things, in this order.

First, establish scope in writing. Size test, Article 2(2) designation grounds, CER identification status, and which national authority holds jurisdiction. Get it on paper and have the client's management body sign it.

Second, inventory the OT estate. Every device, every network path, every remote access route, every third party that can reach the control network. Nothing downstream works without this.

Third, map what exists against the ten Article 21 measures and record the gaps with an owner and a date. That document is what a supervisor asks for first, as we set out in the supervisory audit evidence checklist.

If you want a fast read on where a water client stands before you scope the engagement, run them through our NIS2 quick scan. It takes a few minutes and gives you a structured gap picture to build the proposal on.

The water sector got the strictest supervisory tier in NIS2 and the least implementation guidance. That combination is why these clients need you — and why the ones who wait for their regulator to explain the requirements will be explaining themselves instead.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.

    NIS2 for the Water Sector: What Drinking Water and Wastewater Utilities Must Prove — NIS2Certify