Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Senators Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on September 24, 2026, a bipartisan bill that replaces the FCC's mandatory regulatory approach with a voluntary framework of best practices and third-party certification. The move comes 11 months after the Federal Communications Commission repealed the Biden administration's imposed cybersecurity rules, and just months after revelations about the Salt Typhoon operation, which compromised at least 8-9 major U.S. telecommunications carriers.
- The bill establishes a Telecommunications Cybersecurity Working Group within the NTIA, with representatives from carriers, vendors, cybersecurity experts, and federal officials
- The group has 18 months from enactment to develop sector-specific best practices, with mandatory review every 2 years and after significant cyber incidents
- The certification system is entirely voluntary: no obligation for carriers to participate, no penalties for non-participation
- Salt Typhoon hit approximately 150 high-profile targets including staff of Trump, Vance, Harris, and Schumer, with access to Call Detail Records and, in some cases, interception of audio and text content
The Framework Structure: Collaboration Over Mandate
The bill's central mechanism is a working group hosted at the NTIA, the National Telecommunications and Information Administration. Members will include telephone operators, infrastructure vendors, cybersecurity experts, and federal administration representatives. The group has 18 months to produce an initial set of best practices, focusing on identification, response, mitigation, prevention, and remediation of incidents and vulnerabilities.
Third-party certification will assess actual implementation by individual companies. However, participation remains voluntary: no source in the dossier indicates enforcement mechanisms or consequences for carriers that decline to participate. Best practices will be updated every 2 years and following significant cyber incidents, a cadence sources describe as necessary to keep pace with evolving threats.
Political Context: From Mandate to Industry Trust
The voluntary pivot follows the FCC's decision 11 months earlier, under the new administration, to repeal the Biden-era mandatory telecom cybersecurity rules. The agency's official justification was that carriers were already voluntarily collaborating with CISA and the FBI, rendering federal prescriptions superfluous.
That collaboration is contested by recent episodes. Senator Maria Cantwell reported that AT&T and Verizon blocked Mandiant from providing the security assessments she had requested in the context of the Salt Typhoon investigations. The discrepancy between the collaboration narrative offered to the FCC and the documented obstruction of Congress fuels the tension underpinning the new bill.
"The Salt Typhoon intrusion was the worst telecom hack in our nation's history and showed how vulnerable our critical infrastructure is, but it doesn't have to be this way" — Sen. Mark Warner (D-VA)
Salt Typhoon: The Data Driving Urgency
The Chinese group's operation hit at least 8-9 major U.S. carriers including Verizon, AT&T, and Lumen. Attackers gained access to Call Detail Records and, in some cases, managed to intercept audio and text content. The number of specific high-profile targets hovers around 150, including figures from the staff of Donald Trump, JD Vance, Kamala Harris, and Chuck Schumer.
A Biden administration official stated that the minimum practices eliminated by the FCC would have made Salt Typhoon "much riskier, harder, and more expensive" for the attackers. FBI official Michael Machtinger warned that Beijing may retain the stolen information indefinitely, a residual access that no longer requires active presence in compromised systems.
What to Do Now
For enterprise CISOs, the bill introduces three concrete variables to monitor in telecom service procurement.
Verify carrier certification status. The voluntary framework does not compel participation, but carriers that obtain third-party certification could use it as a commercial differentiator. In RFPs, explicitly ask whether the provider has joined the NTIA working group and completed certification.
Recalibrate contractual clauses on metadata. Salt Typhoon exfiltrated Call Detail Records: communication metadata remains outside typical encrypted-content protections. Assess whether carrier contracts explicitly cover liability for metadata protection, not just payload.
Monitor the Senate Commerce Committee calendar. The bill was just introduced; no source indicates markup or hearing dates. Carrier participation in hearings, if requested, will signal who intends to join voluntarily and who resists.
Why It Matters
The dossier does not specify which carriers will join the voluntary framework, nor whether the certification system will become a criterion in government procurement. Without enforcement mechanisms, the actual impact on security practices remains indeterminate: a carrier that has already obstructed external audits can technically ignore the working group without legal consequences.
For enterprise CISOs, third-party certification, if adopted by major carriers, could become a procurement discriminator. But the extent to which a voluntary label replaces mandatory regulatory audit remains the open question Congress must confront during committee debate.
The Bipartisan Line and Congress's Test
Cross-aisle support — Warner, a Virginia progressive, and Cruz, a Texas conservative — reflects the perception that telecom security has transcended partisan polarization. But convergence on principles does not guarantee legislative speed.
Cruz explicitly framed the text as an alternative to "rigid federal mandates that quickly become obsolete," a formulation aligning the bill with the FCC's deregulatory philosophy. Warner emphasized conditionality: "If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient." In a voluntary framework, that conditional "if" is the entire betting field.
The challenge for business decision-makers is assessing whether voluntary certification can generate sufficient market pressure to overcome the incentive for opacity that Salt Typhoon exposed. Without data on participation, enforcement, or integration into federal procurement, the answer remains open.
Sources
- https://therecord.media/lawmakers-introduce-bill-for-voluntary-telecom-cyber-rules
- https://cyberscoop.com/senate-telecom-cybersecurity-resilience-act-salt-typhoon/
- https://www.nextgov.com/cybersecurity/2026/09/senators-propose-voluntary-telecom-security-framework-after-salt-typhoon-hacks/416201/
- https://www.commerce.senate.gov/press/rep/release/cruz-warner-introduce-bipartisan-bill-to-strengthen-telecommunications-cybersecurity/
- https://therecord.media/fcc-removes-biden-era-cybersecurity-rules-telecoms-salt-typhoon
- https://therecord.media/eight-telcos-breached-salt-typhoon-nsc
Information verified against cited sources and current as of publication.
Sources
- https://cms.therecord.media/uploads/DSC_0283_1_a6f4e4e315.jpg
- https://www.warner.senate.gov/wp-content/uploads/2026/09/Artificial-Intelligence-Risk-Management-and-Security-Act.pdf
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.