Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens if a small public water system…
Governance, Ownership & Risk

What happens if a small public water system is subject to the new requirements but has no internal security capability?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

The system will likely struggle to meet survey expectations unless it quickly adopts outside support. The article points to state assessors, third-party assessors, EPA evaluation services, training, and technical assistance as ways to close the gap. Without that support, the likely result is delayed compliance, inconsistent controls, and a higher chance of missing vulnerabilities or patching obligations.

What the new requirements mean for a small water system without internal security staff

A small public water system can still be expected to show that it understands and is addressing the new requirements, even if it does not have a dedicated security team. In practice, that means the work shifts from in-house execution to obtaining documented outside help, using assessors, training, and technical assistance to build the minimum control and evidence base needed for compliance.

Without that external support, the system is likely to fall behind on surveys, control implementation, and vulnerability tracking. The practical failure mode is not just paperwork, it is an inability to demonstrate that basic security obligations are being met on a consistent timeline.

Where the compliance gap usually appears first

The first gap is usually visibility. A small utility with no internal capability often cannot reliably inventory assets, review exposures, or track whether remediation is actually complete. That makes it difficult to answer survey questions with confidence, and it also makes it harder to separate a one-time fix from an ongoing control.

The second gap is ownership. New requirements often assume someone is responsible for assigning work, chasing closure, and preserving evidence. When that responsibility is not clearly assigned, patching, configuration changes, and control testing can drift past deadlines even when the system is trying to comply.

Using an outside assessor or technical assistance provider helps because it creates a repeatable decision point: what was reviewed, what was found, what was fixed, and what still needs follow-up. That matters more than simply having informal advice available.

Why outside support changes the outcome

External support changes the outcome because it gives the system a practical way to meet expectations it cannot staff internally. A state assessor or third-party assessor can provide structured review, EPA evaluation services can help close capability gaps, and training can make the system less dependent on a single person. For a baseline explanation of control expectations around authentication, access, and verification, OWASP ASVS is a useful reference point even though the setting here is a utility, not a software product.

The key issue is not whether the support is internal or external. The key issue is whether it produces timely evidence that the system can identify obligations, apply controls, and show progress. If the answer is no, the utility may still be operating, but it is not yet operating in a way that is likely to satisfy the new requirements.

Risk and Threat Considerations

Small water systems with no internal security capability face a predictable exposure pattern: delayed fixes, missed vulnerabilities, and weak follow-through on required controls. That creates compliance risk first, but it can also create operational risk if exposed systems or overdue patching are left unaddressed for too long.

Failure mechanism: The system lacks the staff, process, and evidence trail needed to identify gaps, assign remediation, and confirm closure, so controls remain partial or stale.

Impact: Survey responses become unreliable, remediation stretches out, and weaknesses can persist long enough to increase the chance of preventable compromise or service disruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV6 — AuthenticationThe answer concerns evidence of access and verification controls.
Recommendation — Verify authentication and access control requirements are documented and tested.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyThe system must set a practical approach to handling compliance and security gaps.
Recommendation — Define a risk strategy that includes external support when internal capability is limited.
NIST SP 800-53 Rev 5RA-5 — Vulnerability Monitoring and ScanningThe answer centers on missing vulnerabilities and follow-up on remediation.
Recommendation — Establish recurring vulnerability discovery and closure tracking.

Practitioner Guidance

What to prioritise: Establish outside coverage first, not perfect internal capability. The immediate goal is to have a named assessor, a training path, and a documented assistance channel so the system can respond to surveys and findings on time.

What to verify: Confirm that the support arrangement produces evidence the utility can keep, not just advice it can hear. If a recommendation cannot be tracked to an owner, a due date, and a closure record, it will not help under inspection.

What practitioners underestimate: A small system is not judged by its size alone; it is judged by whether it can demonstrate control. The most important decision is whether to build a minimal, repeatable compliance process quickly or accept a higher-risk gap while waiting for internal capability to appear.

Practitioner takeaway: For a small public water system, outside support is not a convenience, it is the mechanism that turns a compliance expectation into something the system can actually evidence and sustain.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org