---
kind: "section"
citation: "42 U.S.C. § 300g–10"
title: "42"
title_heading: "The Public Health and Welfare"
number: "300g–10"
heading: "Cybersecurity support for public water systems"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/42/300g-10"
units:
  - "Chapter 6A — Public Health Service"
  - "Subchapter XII — Safety of Public Water Systems"
  - "Part B — Public Water Systems"
---

# §300g–10. Cybersecurity support for public water systems

- (a) **Definitions—** In this section:
  - (1) **Appropriate Congressional committees—** The term “appropriate Congressional committees” means—
    - (A) the Committee on Environment and Public Works of the Senate;
    - (B) the Committee on Homeland Security and Governmental Affairs of the Senate;
    - (C) the Committee on Energy and Commerce of the House of Representatives; and
    - (D) the Committee on Homeland Security of the House of Representatives.
  - (2) **Director—** The term “[Director](/usc/42/11851.md?p=5)” means the [Director](/usc/42/11851.md?p=5) of the Cybersecurity and Infrastructure Security [Agency](/usc/42/8262.md?p=1).
  - (3) **Incident—** The term “incident” has the meaning given the term in [section 3552 of title 44](/usc/44/3552.md).
  - (4) **Prioritization Framework—** The term “Prioritization Framework” means the prioritization framework developed by the [Administrator](/usc/42/4005.md?p=1) under [subsection (b)(1)(A)](#b-1-A).
  - (5) **Support Plan—** The term “Support Plan” means the Technical Cybersecurity Support Plan developed by the [Administrator](/usc/42/4005.md?p=1) under [subsection (b)(2)(A)](#b-2-A).
- (b) **Identification of and support for public water systems—**
  - (1) **Prioritization Framework—**
    - (A) **In general—** Not later than 180 days after November 15, 2021, the [Administrator](/usc/42/4005.md?p=1), in coordination with the [Director](/usc/42/11851.md?p=5), shall develop a prioritization framework to identify public water systems (including sources of water for those public water systems) that, if degraded or rendered inoperable due to an incident, would lead to significant impacts on the health and safety of the public.
    - (B) **Considerations—** In developing the Prioritization Framework, to the extent practicable, the [Administrator](/usc/42/4005.md?p=1) shall incorporate consideration of—
      - (i) whether cybersecurity vulnerabilities for a public water system have been identified under [section 300i–2 of this title](/usc/42/300i–2.md);
      - (ii) the capacity of a public water system to remediate a cybersecurity vulnerability without additional Federal support;
      - (iii) whether a public water system serves a defense installation or critical national security asset; and
      - (iv) whether a public water system, if degraded or rendered inoperable due to an incident, would cause a cascading failure of other critical infrastructure.
  - (2) **Technical Cybersecurity Support Plan—**
    - (A) **In general—** Not later than 270 days after November 15, 2021, the [Administrator](/usc/42/4005.md?p=1), in coordination with the [Director](/usc/42/11851.md?p=5) and using existing authorities of the [Administrator](/usc/42/4005.md?p=1) and the [Director](/usc/42/11851.md?p=5) for providing voluntary support to public water systems and the Prioritization Framework, shall develop a Technical Cybersecurity Support Plan for public water systems.
    - (B) **Requirements—** The Support Plan—
      - (i) shall establish a methodology for identifying specific public water systems for which cybersecurity support should be prioritized;
      - (ii) shall establish timelines for making voluntary technical support for cybersecurity available to specific public water systems;
      - (iii) may include public water systems identified by the [Administrator](/usc/42/4005.md?p=1), in coordination with the [Director](/usc/42/11851.md?p=5), as needing technical support for cybersecurity;
      - (iv) shall include specific capabilities of the [Administrator](/usc/42/4005.md?p=1) and the [Director](/usc/42/11851.md?p=5) that may be utilized to provide support to public water systems under the Support Plan, including—
        - (I) site vulnerability and risk assessments;
        - (II) penetration tests; and
        - (III) any additional support determined to be appropriate by the [Administrator](/usc/42/4005.md?p=1); and
      - (v) shall only include plans for providing voluntary support to public water systems.
  - (3) **Consultation required—** In developing the Prioritization Framework pursuant to [paragraph (1)](#b-1) and the Support Plan pursuant to [paragraph (2)](#b-2), the [Administrator](/usc/42/4005.md?p=1) shall consult with such Federal or non-Federal entities as determined to be appropriate by the [Administrator](/usc/42/4005.md?p=1).
  - (4) **Reports required—**
    - (A) **Prioritization Framework—** Not later than 190 days after November 15, 2021, the [Administrator](/usc/42/4005.md?p=1) shall submit to the appropriate Congressional committees a report describing the Prioritization Framework.
    - (B) **Technical Cybersecurity Support Plan—** Not later than 280 days after November 15, 2021, the [Administrator](/usc/42/4005.md?p=1) shall submit to the appropriate Congressional committees—
      - (i) the Support Plan; and
      - (ii) a list describing any public water systems identified by the [Administrator](/usc/42/4005.md?p=1), in coordination with the [Director](/usc/42/11851.md?p=5), as needing technical support for cybersecurity during the development of the Support Plan.
- (c) **Rules of construction—** Nothing in this section—
  - (1) alters the existing authorities of the [Administrator](/usc/42/4005.md?p=1); or
  - (2) compels a public water system to accept technical support offered by the [Administrator](/usc/42/4005.md?p=1).

## Source credit

(July 1, 1944, ch. 373, title XIV, § 1420A, as added Pub. L. 117–58, div. E, title I, § 50113, Nov. 15, 2021, 135 Stat. 1155.)
