NIS2 in Water and Waste Management: Municipal Utilities

Practitioner note: This is not legal advice. For specific situations, consult a qualified attorney or compliance officer.

TL;DR

  • Water suppliers in scope from 50 employees and EUR 10M turnover
  • KRITIS-Water threshold: serving 22 million citizens (KRITIS Ordinance Section 5)
  • Wastewater facilities follow comparable thresholds
  • SCADA security is the dominant risk surface (pump control, chlorine dosing, network monitoring)
  • Dual reporting: BSI plus the state water authority on a significant incident

1. Who is in scope?

Water suppliers and waste-management operators are in scope from 50 employees and EUR 10M turnover. KRITIS-Water thresholds (KRITIS Ordinance Section 5) trigger above 22 million citizens served. Many small municipal utilities remain below threshold; mid-size municipal utilities are typically in scope.

2. SCADA security for water plants

Pump control, chlorine dosing, and network monitoring are SCADA-driven. A cyber incident can affect public water supply directly. Reference standards: ISA / IEC 62443 for industrial control systems, BSI ICS-Compendium, and AWWA water-sector guidance.

3. Supply-chain audit

Prioritize SCADA vendors (Siemens Water, Schneider Electric, Endress+Hauser), IT service providers, and on-site maintenance contractors. Patch SLAs and remote-access controls are the must-haves; many incidents start through unmonitored maintenance VPNs.

4. Reference incidents

5. Dual supervision

Water and waste utilities answer to BSI under NIS2 and to the state water authority under sector law. On a significant incident, both must be notified, often within different timeframes. A unified incident-response form keeps the two notifications consistent.

Summary

Water and waste management combine high public-impact stakes with legacy SCADA estates. The defensible NIS2 program centers on IEC 62443 for OT, segmentation of remote-access paths, and a tested dual-notification playbook for BSI plus the state water authority.

View NIS2 Kit →

Frequently Asked Questions

Are small municipal utilities affected?
From 50 employees + EUR 10 million. Many small municipal utilities fall below the threshold, while larger mid-sized municipal utilities are affected.
Cybersecurity standards?
ISA/IEC 62443 for Industrial Control Systems. WAF (Water Application Firewall) recommended.

Sources

Tools & self-assessments

NIS2 Readiness Check Assess your NIS2 maturity in 10 minutes. Fining Calculator Estimate the potential fine exposure for your organisation. NIS2 Self-Test Am I in scope? Check thresholds and sector membership. NIS2 Mandatory Measures Audit 10 mandatory measures under Section 30 BSIG with maturity assessment.