Pages

Wednesday, August 19, 2026

Program Manager's Message: Secondary Maximum Contaminant Levels (SMCLs)


Colorado’s Primary Drinking Water Regulations (Regulation 11) match EPA’s federal Safe Drinking Water Act in setting both Maximum Contaminant Levels (MCLs) and Secondary Maximum Contaminant Levels (SMCLs). Contaminants with MCLs are often referred to as primary contaminants with primary standards. Contaminants with SMCLs are often referred to as secondary contaminants with secondary standards. Public water systems are required to test for primary contaminants to address situations where primary MCLs are exceeded, ensuring drinking water quality does not exceed any primary contaminant standards. It’s a far different picture for secondary contaminants.

Generally, public water systems are not required to test for secondary contaminants, except for fluoride, which also has a primary MCL. When fluoride levels exceed the SMCL of 2.0 mg/L but not the MCL of 4.0 mg/L, public water systems are required to issue a special public notice due to the risk of dental fluorosis (discoloration and pitting of teeth in children while they are growing under the gums). This is thought to impact the appearance of the teeth but not impact health. 

Manganese is also handled a bit differently. There is a health advisory for manganese in drinking water. The lifetime health advisory to protect against chronic neurologic impacts is at 0.3 mg/L. This lifetime advisory is also used for short-term exposure to infants and children due to their sensitive life stage. The acute exposure advisory for adults is 1.0 mg/L. These levels are significantly above the 0.05 mg/L SMCL for manganese. When the department sees results for manganese above one or both of these health advisory levels, we utilize our authority under the public notice rule to require water systems to notify the public about the health risks. But because there is no primary MCL for manganese, we do not require compliance with the health advisory levels.

However, manganese levels above the secondary standard, which are often accompanied by high iron levels, can make drinking water quality very problematic for customers and water utilities. Customers may sometimes experience black or dark-colored water with sediment. The water can cause problems with appliances and laundry, via staining clothes. For water utilities, high iron and manganese levels can clog distribution piping, reducing available pipe volume and increasing the need for flushing and maintenance. We have seen situations where high manganese and iron levels impact distribution systems so much that significant deficiencies are created. 

In general, customers do not trust or want drinking water that exceeds secondary standards, especially when they can see, smell, or taste the problems. But water utilities and their customers share concerns for the potential cost of addressing this problem. One thing to consider is that problems like this tend to only get worse and more expensive to address over time. Another consideration is pursuing funding assistance. Manganese is considered an emerging contaminant, and we have dedicated funding to help address this issue. If your water utility has manganese, iron, or other problems with SMCLs please reach out and work with us to explore options to address the situation.

Again, thanks for all you do to keep tap water safe in Colorado.

Ron Falco, P.E, Safe Drinking Water Program Manager


Thursday, August 6, 2026

Federal agencies warn U.S. organizations about cyber attacks on water sector

The Water Quality Control Division is partnering with the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency to issue this urgent warning.

The Cybersecurity and Infrastructure Security Agency and partners are issuing an urgent warning regarding a sharp increase in cyber attacks targeting programmable logic controllers (PLCs) in water and wastewater systems. Attackers are exploiting internet-exposed equipment to change passwords and alter system settings, sometimes triggering boil-water notices.

Water and wastewater suppliers should take the following actions immediately:

  • Disconnect PLCs from the internet. Remote access for operational purposes should go through a VPN (virtual private network) or gateway device, not directly to the PLC.
  • Enable password protection and change default passwords.
  • Establish a protocol so that only specific, approved computers can access the PLCs. To do this, work with IT to set up Allowlist IPs = every computer has an ID number (an IP address). "Allowlisting" means making an exclusive list of the ID numbers you trust.
  • Review CISA’s Known Exploited Vulnerabilities (KEV) list and Industrial Control Systems (ICS) Advisories and take action to address any potential vulnerabilities.

How can cybercriminals use a PLC? 

  • Locking out operators: Hackers change the PLC's internal passwords and IP addresses. This locks the real workers out and leaves them blind to what is happening.
  • Flooding: Attackers can force valves to stay open or pumps to run non-stop, causing sewage or water tanks to overflow and flood the facility.
  • Water pressure loss: Forcing water pumps to shut down drops pressure in pipes, which can compromise water quality and require cities to issue emergency boil-water notices.
  • Chemical manipulation: Attackers can alter chemical dosing rules and make the water unsafe to drink.
  • Falsifying information: Sophisticated hackers can feed fake "normal" data to the SCADA screens. While the computer screen shows everything is fine, the physical PLC is actively damaging the equipment on the floor.

What can systems do to protect themselves? 

After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password.

Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity.

To securely enable remote access to your OT systems, CISA recommends system owners, operators, and integrators see the following resources for guidance:

For additional support, contact the Environmental Protection Agency’s Cybersecurity Technical Assistance Program for the Water Sector or your CISA Regional Office.

What should I do if my system is affected? 

Regulatory requirements: 

  1. Contact the department for any type of cybersecurity event including any tampering to computers, operating technology, or cyber assets. Notify the department as soon as possible, but no later than 10 a.m. of the calendar day following any cybersecurity event (see Regulation 11 for details).
  2. Provide written notice within five calendar days to the department explaining the circumstances of the occurrence and setting forth the action(s) taken to ensure the ability of the system to maintain critical operations and to prevent any recurrence. The Tampering Threat and Incident Report Form described below will satisfy this requirement.

Highly recommended: