Department of the Environment - Community Water and Sewerage Systems - Cybersecurity Planning and Assessments
SB 871 creates a new cybersecurity framework for Maryland’s community water systems and community sewerage systems. It directs the Department of the Environment, working with the Department of Information Technology and the Maryland Department of Emergency Management, to coordinate cybersecurity efforts in the water and wastewater sector, update regulations, establish minimum cybersecurity standards, and promote training and awareness for operators and superintendents. The bill also requires affected providers to designate cybersecurity points of contact, attend annual training, adopt or plan toward a zero-trust cybersecurity approach, and undergo periodic third-party maturity assessments.
The bill further requires covered systems to report cybersecurity incidents to the State Security Operations Center under a process to be established by the State Chief Information Security Officer. It also requires the Department of Information Technology to publish aggregate, non-identifying incident reports and to support sector-specific guidance, information sharing, and resources. In addition, the bill expands public records protections by barring inspection of records relating to the security of information systems, operational technology, and critical infrastructure, including records of community water and sewerage systems. The Department of Emergency Management’s Cyber Preparedness Unit is also tasked with added water-sector planning, tabletop exercises, and emergency communication guidance.
SB 871 adds a new subtitle to the Environment Article governing community water and sewerage system cybersecurity, amends the Public Information Act’s public records exemption in the General Provisions Article, and expands the Cyber Preparedness Unit’s duties in the Public Safety Article. It imposes new compliance, reporting, training, and assessment obligations on community water and sewerage system providers, especially larger systems serving more than 3,300 customers or those using information technology and operational technology. The bill also creates new state-level coordination, reporting, and oversight responsibilities for the Department of the Environment, the Department of Information Technology, and the Maryland Department of Emergency Management.
The bill appears to have broad bipartisan support and was passed unanimously in both chambers, with 42 yeas and 0 nays in the Senate and 139 yeas and 0 nays in the House. The overall tone of the legislation is preventive and security-focused, emphasizing preparedness, resilience, and coordination rather than enforcement or penalties. The absence of recorded committee transcript opposition suggests the measure was generally viewed favorably as a critical infrastructure protection bill.
There is little visible opposition in the available record, but the bill’s main policy burdens fall on community water and sewerage system providers, particularly larger systems and those with IT/OT operations. Potential points of concern include the cost and administrative effort of adopting minimum cybersecurity standards, conducting recurring third-party assessments, implementing zero-trust planning, and maintaining incident reporting and training requirements. Another notable issue is the expanded confidentiality protection for security-related records, which may raise transparency concerns even as it is intended to protect critical infrastructure.