Public Water Suppliers Cybersecurity Improvements Grant Program
This program provides financial support to small public water suppliers and those in Disadvantaged Communities in Massachusetts to improve their cybersecurity and resilience against cyber threats.
The Public Water Suppliers Cybersecurity Improvements Grant Program is offered through the Massachusetts Drinking Water State Revolving Fund in partnership with the Massachusetts Department of Environmental Protection Drinking Water Program and the Massachusetts Clean Water Trust. The program is intended to improve the cybersecurity and resilience of public water suppliers. Massachusetts drinking water requirements provide that cybersecurity must be addressed in a public water supplier's Emergency Response Plan under 310 CMR 22.04(13). Public water suppliers must assess their systems, including cybersecurity, and maintain plans addressing vandalism, sabotage, and cyber incidents that could affect the quality or quantity of available water. The grant specifically supports improvements that strengthen cybersecurity defenses, mitigate cyberattack risks, improve overall resiliency, and support compliance. Eligibility is limited to qualifying public water suppliers. An applicant must either be a small system serving fewer than 10,000 people or be located in a Disadvantaged Community as defined by the Massachusetts Clean Water Trust. In addition, every applicant must satisfy both program prerequisites. The public water supplier must have operational technology equipment presenting a cybersecurity risk, such as equipment connected or potentially connected to a computer or network or equipment that can be remotely accessed for control or monitoring. The supplier must also have completed a cybersecurity assessment or evaluation within the past two years. The assessment may have been performed by the public water supplier itself or by a qualified entity such as the U.S. Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, or another qualified third party. The assessment report must identify cybersecurity findings, gaps, and vulnerabilities and propose potential recommendations for addressing or mitigating the identified issues. The Massachusetts State Revolving Fund is offering up to $2 million for the program. Grant amounts vary according to public water supplier population and other factors, including system type, size, and findings in the cybersecurity assessment report. Systems serving fewer than 3,300 people may receive up to $15,000. Systems serving 3,300 to 10,000 people may receive up to $30,000. Systems serving more than 10,000 people may receive up to $50,000, but this highest population tier is available only to public water suppliers located in Disadvantaged Communities. No matching or cost-share requirement is stated in the supplied program information. Grant funding may support operational technology cybersecurity improvement projects that proactively mitigate vulnerabilities to cyberattacks and strengthen a public water supplier's overall cybersecurity posture. Projects are expected to respond to findings in the applicant's cybersecurity assessment. Examples include upgrading, replacing, or removing unsupported or end-of-life hardware, software, and operating systems; incident response planning; employee training; network segmentation; improving remote access security; implementing encryption; developing or updating an Emergency Response Plan or Cybersecurity Incident Response Plan; and penetration testing after all assessment findings have been addressed. Annual software subscriptions may not be eligible, and grant funds may not be used for operation and maintenance activities. Public water suppliers are encouraged to use contractors available under the OSD ITS78 Statewide Contract for Data, Cybersecurity, and Related Audit Compliance and Incident Response Services. An existing qualified contractor or consultant may alternatively be used with prior written approval from MassDEP/DWP. Applications opened March 22, 2024 and are accepted on a rolling, first-come, first-served basis until all program funds are expended. Applicants must complete the application and Scope of Work forms and include the statements required by Appendix A in the initial application submission. Supplemental materials in Appendices B, C, and D do not have to accompany the initial application, but they must be submitted before the applicable deadline in order for the applicant to be awarded a Cybersecurity Improvements Grant. Applications are submitted securely to the MassDEP Drinking Water Program. Questions concerning submission of sensitive information may be directed to program.director-dwp@mass.gov. After an application is submitted, MassDEP reviews it and may contact the public water supplier to verify eligibility. If MassDEP determines that additional review is necessary, it may arrange a project review meeting through an in-person or other secure method to discuss project needs, costs, and schedule before approval. Eligible projects approved by MassDEP receive a Project Approval Certificate. MassDEP then forwards the certificate to the Massachusetts Clean Water Trust for review and approval through a vote of the Trust's Board of Trustees. The Trust reviews required financial documentation and, if acceptable, enters into a Grant Agreement with the public water supplier. Once the Grant Agreement is fully executed, a grant account is created and funds may be drawn by submitting invoices for MassDEP approval. Eligible expenses incurred from the date of the Project Approval Certificate through the contract end date may be submitted for reimbursement, with final payment held until grant closeout conditions are satisfied.
Award Range
Not specified - $50,000
Total Program Funding
$2,000,000
Number of Awards
Not specified
Matching Requirement
No
Additional Details
Maximum awards vary by PWS population and other factors including PWS type, size, and cybersecurity assessment findings. Systems serving fewer than 3,300 people may receive up to $15,000; systems serving 3,300 to 10,000 may receive up to $30,000; systems serving more than 10,000 may receive up to $50,000 only if they are Disadvantaged Community PWSs.
Eligible Applicants
Additional Requirements
Eligible applicants are public water suppliers that either serve fewer than 10,000 people or are located in a Disadvantaged Community as defined by the Massachusetts Clean Water Trust. Applicants must also satisfy both prerequisites: they must have operational technology equipment presenting a cybersecurity risk and must have completed a cybersecurity assessment within the past two years. The assessment may be performed by the PWS or a qualified entity such as EPA, CISA, or another qualified third-party organization and must identify cybersecurity findings, gaps, vulnerabilities, and potential recommendations for mitigation.
Geographic Eligibility
All
Apply while funds remain because applications are reviewed first-come, first-served; ensure the cybersecurity assessment was completed within the past two years and documents findings, gaps, vulnerabilities, and mitigation recommendations; align the proposed project with assessment findings; include required Appendix A statements in the initial submission; address assessment findings before proposing penetration testing
Application Opens
March 22, 2024
Application Closes
Not specified
Grantor
Massachusetts Clean Water Trust
Subscribe to view contact details

