Bipartisan Senate bill would set voluntary cyber standards for telecom carriers
Two Senate committee leaders introduced a bipartisan bill that would create voluntary cybersecurity standards for telecom providers and an independent certification process. The measure follows the Salt Typhoon campaign, in which Chinese hackers breached U.S. communications systems, including those used for lawful surveillance requests. A Commerce Department working group would develop the practices within 18 months.
The measure, called the Telecommunications Cybersecurity and Resilience Act, is led by Sen. Mark Warner, the Intelligence Committee’s vice chairman, and Sen. Ted Cruz, who chairs Commerce. It would convene telecom firms, equipment suppliers, cyber specialists and federal agencies under NTIA to draft sector-specific guidance within a year and a half.
The proposal follows Salt Typhoon, a Chinese campaign that penetrated U.S. communications systems, including those tied to lawful surveillance requests, and reached political figures and networks abroad. It also comes after the FCC withdrew a Biden-era safeguard last November; Chairman Brendan Carr cited legal-authority concerns and voluntary carrier fixes, a reversal Warner criticized.
If enacted, the framework may shape how telecom providers assess and improve defenses, potentially affecting customers, government agencies and political figures who rely on those networks. Voluntary participation could mean uneven adoption, leaving some regions or smaller carriers less protected. Independent certification may give businesses and consumers clearer signals about security practices, though its practical effect would depend on uptake and enforcement.