This bill addresses security at drinking water facilities.
This bill:
AI-generated summary, not yet reviewed by Better Utah staff. Please consult the bill text.
Community water systems across Utah — the utilities that pipe drinking water to homes and businesses — would be required to complete emergency response plans addressing cybersecurity threats to their computerized control systems, with larger systems (serving 3,300 or more people) meeting an initial deadline of December 31, 2026, and smaller systems following by July 1, 2027, and both renewing these plans annually thereafter. These plans must include measures such as keeping control-system software updated, training employees on cybersecurity, conducting internal vulnerability assessments, promptly cutting off system access for terminated employees, and ensuring automated systems can be operated manually if needed. If a security breach occurs, the water system would have to report it to the Utah Cyber Center within two hours, and the Utah Cyber Center would then notify the state's Division of Drinking Water within one day; the Division would also be required to report annually to two legislative committees on security conditions across the state's water systems. Emergency response plans and related incident reports would be classified as protected records under Utah's public records law, meaning they would be shielded from public disclosure requests to prevent the information from being used to target water system vulnerabilities.
Introduction
Jan 20
House Rules
House Committee
Skipped
House Floor Vote
Jan 20
Senate Rules
Jan 21
Senate Committee
Jan 27
Senate 2nd Reading
Feb 4
Senate 3rd Reading
Feb 5
Governor Signed
Feb 27
IntroductionJan 20
House Rules
House CommitteeSkipped
House Floor VoteJan 20
Senate RulesJan 21
Senate CommitteeJan 27
Senate 2nd ReadingFeb 4
Senate 3rd ReadingFeb 5
Governor SignedFeb 27
This bill addresses security at drinking water facilities.
This bill:
AI-generated summary, not yet reviewed by Better Utah staff. Please consult the bill text.
Community water systems across Utah — the utilities that pipe drinking water to homes and businesses — would be required to complete emergency response plans addressing cybersecurity threats to their computerized control systems, with larger systems (serving 3,300 or more people) meeting an initial deadline of December 31, 2026, and smaller systems following by July 1, 2027, and both renewing these plans annually thereafter. These plans must include measures such as keeping control-system software updated, training employees on cybersecurity, conducting internal vulnerability assessments, promptly cutting off system access for terminated employees, and ensuring automated systems can be operated manually if needed. If a security breach occurs, the water system would have to report it to the Utah Cyber Center within two hours, and the Utah Cyber Center would then notify the state's Division of Drinking Water within one day; the Division would also be required to report annually to two legislative committees on security conditions across the state's water systems. Emergency response plans and related incident reports would be classified as protected records under Utah's public records law, meaning they would be shielded from public disclosure requests to prevent the information from being used to target water system vulnerabilities.
Motion: Favorable Recommendation
Governor Signed
Lieutenant Governor's office for filing
House/ to Governor
Executive Branch - Governor
House/ received enrolled bill from Printing
Clerk of the House
House/ enrolled bill to Printing
Clerk of the House
Enrolled Bill Returned to House or Senate
Clerk of the House
Last updated Aug 29, 2026, 5:26 PM