NIS2 · Sector deep-dive
NIS2 for Waste Water Operators
Waste water is its own Annex I sector, separate from drinking water, and it is the one most often missed. Operators tend to assume that because nobody drinks the output, the consequences of a control-system incident are limited. The regulator's view is the opposite: a treatment works that stops treating discharges into a river, and that is exactly the kind of societal and environmental impact the directive is written around.
What makes waste water different from drinking water
The two sectors share technology — the same SCADA platforms, the same PLC vendors, often the same integrator and the same control room — but they fail differently. A drinking water incident is contained by the fact that supply can usually continue on manual operation while monitoring is restored. A waste water incident has nowhere to pause: sewage keeps arriving. When aeration, dosing or pumping is lost, the plant has hours, not days, before it either backs up into the network or passes through under-treated.
Collection networks add a second problem that drinking water does not have at the same scale. Hundreds of pumping stations, combined sewer overflow gates and storm tanks are spread across a municipality, connected by cellular telemetry, and largely unattended. They are cheap to install and easy to forget, and they are frequently absent from the asset register that the security programme is built on.
The consequence profile is environmental and reputational rather than immediately life-threatening, which historically kept security investment low. NIS2 changes the calculation by attaching management accountability and administrative fines to the same failure, and by placing the sector under the essential-entity supervisory regime.
Where waste water operators typically have the biggest gaps
- Unmapped remote assets. Pumping stations and overflow monitors installed project by project over thirty years, with no single list of what is connected, over which network, and who maintains it.
- Shared municipal IT boundaries. Process control frequently sits behind the municipality's general IT infrastructure, so a compromise of the office network reaches the plant, and nobody owns the segmentation.
- Environmental reporting mistaken for incident reporting. Teams have a well-drilled process for notifying the environmental regulator about a discharge, and no process at all for the 24-hour NIS2 early warning.
- Laboratory and dosing systems. Analysers, chemical dosing controllers and sampling systems are treated as instruments rather than as computers, so they are unpatched, unmonitored and vendor-managed.
- No tested control-system restore. PLC logic and SCADA configuration backups exist on the integrator's laptop rather than in a controlled, offline, verified repository owned by the utility.
What this means for the Article 21 measures
- Risk analysis and system security policy — Article 21(2)(a). The risk assessment has to treat an under-treated discharge as a primary loss scenario, not a side effect, and cover the collection network as well as the treatment works.
- Incident handling — Article 21(2)(b). One procedure that triggers both the NIS2 notification chain and the environmental permit notification, with named roles and both deadlines written into the same runbook. See the reporting timeline.
- Business continuity and backup — Article 21(2)(c). Offline, restore-tested backups of PLC programs and SCADA configuration, plus a rehearsed procedure for running key process stages manually while control is rebuilt.
- Supply chain security — Article 21(2)(d). Automation integrators and telemetry providers on named individual accounts with time-boxed, logged access — never a shared engineering password reused across the municipalities they serve.
- Basic cyber hygiene — Article 21(2)(g). Remove internet-exposed HMIs, enforce MFA on every remote access route, and segment the process network from municipal IT.
The full measure list is on the Article 21 requirements page. Operators also identified under the CER Directive should maintain a single evidence base that serves both regimes.
Documentation
The NIS2 Starter Kit gives a lean utility team the risk assessment, asset register, continuity plan and incident procedure without a consulting engagement.
