Cyber risk and resilience annex
A review draft covering the agreed cyber scope, findings, source references, and gaps for the utility’s broader risk and resilience assessment.

01 / OT CYBERSECURITY
Connect the cybersecurity review of your treatment, distribution, or wastewater systems to a documented assessment. SSX360 scopes SCADA and access reviews, prepares cyber annex material, and organizes signed evidence for utility reviewers.
Review the agreed inventory of controllers, operator interfaces, remote stations, vendor access paths, and supporting IT connections. Examine backup, recovery, and response records around the operating constraints of the utility.
Select the deliverables around your facility, review objective, and available records. Scope and acceptance criteria are agreed before work begins.
A review draft covering the agreed cyber scope, findings, source references, and gaps for the utility’s broader risk and resilience assessment.
Cyber response inputs, prioritized findings, and proposed action owners for review with operations and the emergency-planning team.
An indexed handoff of agreed findings and signed records, with source handling and offline verification instructions.
ML-DSA-87 / MATRIX SCROLL / SCROLL CONSOLE
Matrix Scroll signs records with ML-DSA-87. Scroll Console organizes imported evidence, supports comparison with retained sources, and prepares controlled handoffs. These are private SSX360 tools used within an agreed engagement.
Explore the evidence workflowSOURCE REVIEW / OCT 09, 2026
AWIA Section 2013 applies to community drinking-water systems serving more than 3,300 people. The 2025–2026 risk-assessment deadlines have passed. For systems serving 3,301–49,999, the latest ERP certification date is December 31, 2026; it may be earlier based on the RRA certification date.
Read the official sourceNew York gives covered community water systems until January 1, 2027 for most Appendix 5-E requirements. Applicability, exclusions, population thresholds, and immediately effective provisions require facility-specific review.
Read the official sourceIndiana requires qualifying water and wastewater facilities using covered computerized systems to complete an annual cybersecurity assessment and submit the initial certification by December 31, 2026. Facility type and technology use determine applicability.
Read the official sourceThe federal AWIA Section 2013 certification requirement concerns qualifying community drinking-water systems. Wastewater facilities may have separate state obligations and can still scope an OT cybersecurity assessment.
The cyber annex addresses the agreed cybersecurity portion. The utility integrates it with the remaining risk, resilience, and emergency-response work and retains responsibility for its certification.
Share the facility type, general systems in scope, review objective, and target date. Keep network diagrams, credentials, CUI, and other sensitive records out of the first inquiry.