Historical analysis: this article examines information published by the source on June 24, 2026. Check the latest vendor guidance before acting.
What was published
On June 24, 2026, the NIST National Cybersecurity Center of Excellence (NCCoE) released the final version of Special Publication 1800-45, titled “Cybersecurity for the Water and Wastewater Sector: Build Architecture.”
Status and scope
This publication is a final NCCoE practice guide. It was previously available as draft NIST Technical Note 2283 before being revised based on community feedback. The scope of the guidance is specifically focused on enabling secure remote access to operational technology (OT) for organizations within the water and wastewater systems sector.
What the guidance covers
The publication addresses the cybersecurity risks introduced by the digital transformation of water utilities, such as the integration of internet-connected sensors, network devices, and analytic software. To address these risks, NIST developed reference architectures and sample implementations using commercially available technologies. These were built and demonstrated in a lab environment through collaboration with technology vendors, industry experts, and water utilities to ensure the approaches are practical for organizations of varying sizes and resource levels.
How organizations can use it
Asset owners and OT security leaders can use SP 1800-45 as a technical blueprint to evaluate their current remote access methods against demonstrated secure patterns. Rather than providing a single mandatory configuration, the guide offers architectures that allow utilities to select an approach that aligns with their specific operational needs and available resources.
Decisions and next steps
Our analysis suggests that organizations should use this guidance as a baseline for a gap analysis of their remote access perimeter. Decision-makers should consider the following steps:
- Architecture Review: Compare existing remote access paths (e.g., VPNs, jump hosts) against the NIST reference architectures to identify structural weaknesses.
- Resource Alignment: Determine which of the demonstrated implementations matches the organization’s current scale and budget constraints.
- Engineering Validation: Before deploying any architecture described in the guide, perform a site-specific engineering review to ensure that the proposed remote access controls do not interfere with critical process availability or safety functions.
Limits and open questions
It is important to note that these guidelines are not mandatory regulations or legal requirements. Because the reference architectures were developed and tested in a lab environment, there is no guarantee they will function identically in every production environment. Implementation requires site-specific tailoring; following the guide does not provide an absolute guarantee of immunity from cyberattacks. The extent to which these architectures integrate with legacy proprietary protocols not covered in the lab implementations remains a point for individual site verification.
Source and editorial note
NIST Guidelines for Secure Remote Access in Water and Wastewater Systems · Source date: June 24, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: June 27, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 02, 2026 at 04:38 UTC.
Request an OT security assessment
Protect the systems your operations depend on.
Discuss your industrial environment, prioritize exposure, and establish evidence that safeguards work.
Request an OT assessment ↗