Warner and Cruz Introduce the Telecommunications Cybersecurity and Resilience Act
Sen. Mark Warner (D-Va.), Vice Chairman of the Senate Intelligence Committee, and Sen. Ted Cruz (R-Texas), Chairman of the Senate Commerce, Science, and Transportation Committee, introduced bipartisan legislation this month titled the Telecommunications Cybersecurity and Resilience Act. The bill would create a government-industry working group under the National Telecommunications and Information Administration (NTIA) tasked with writing voluntary cybersecurity best practices for telecom carriers, arriving nearly two years after the Salt Typhoon espionage campaign was first disclosed publicly.
Details
| Attribute | Value |
|---|---|
| Bill Name | Telecommunications Cybersecurity and Resilience Act |
| Lead Sponsors | Sen. Mark Warner (D-Va.), Sen. Ted Cruz (R-Texas) |
| Committees | Senate Intelligence (Warner, Vice Chairman); Senate Commerce, Science, and Transportation (Cruz, Chairman) |
| Chamber | U.S. Senate |
| Status | Introduced; has not cleared committee or received a floor vote |
| Core Mechanism | Voluntary, industry-developed best practices — not federal mandates |
| Administering Body | New telecom cybersecurity working group housed at NTIA |
| Best-Practices Deadline | 18 months after enactment |
| Review Cadence | Every 2 years, or sooner after a major incident |
| Certification | Optional third-party certification program for participating companies |
| Triggering Event | Salt Typhoon — Chinese state-linked telecom espionage campaign |
What the Bill Does
A government-industry working group at NTIA
The bill's central provision creates a telecom cybersecurity working group inside NTIA that would bring together carriers, network equipment suppliers, independent security experts, and relevant federal agencies. The group's mandate is to identify, respond to, and mitigate cybersecurity incidents and vulnerabilities affecting telecommunications infrastructure, and to publish industry-wide best practices within 18 months of the bill becoming law. Those practices would be revisited on a two-year cycle, or immediately following a major security incident, and companies could pursue an optional third-party certification to demonstrate compliance.
Voluntary standards, not mandates
Warner and Cruz built the bill around voluntary adoption rather than binding federal requirements. Cruz described it as a "sensible bill" that "brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated." Warner struck a similar note, arguing that "if telecommunications companies adopt cybersecurity best practices, our networks can be more resilient," and called the bill "a good start in protecting our nation and strengthening the communications networks Americans rely on every day."
Friction with the FCC's rule rollback
The bill lands amid an unresolved fight over the opposite approach: mandatory rules. The Federal Communications Commission (FCC) has moved to reverse Biden-era telecom cybersecurity requirements that were adopted in the immediate aftermath of Salt Typhoon's discovery. Warner has publicly criticized that rollback, stating that "the Salt Typhoon intrusion made clear that existing voluntary measures alone have not been sufficient to prevent sophisticated, state-sponsored actors from gaining long-term, covert access to critical networks. While collaboration with industry is essential, it must be paired with clear, enforceable expectations that reflect the scale of the threat." That tension — a voluntary-standards bill advancing while the FCC unwinds mandatory ones — has drawn scrutiny from some cybersecurity officials, who have also warned that public apathy toward Salt Typhoon has sapped momentum for stricter telecom security rules generally.
The Salt Typhoon backdrop
Salt Typhoon is the name given to a multiyear, Chinese state-linked espionage campaign that penetrated major U.S. telecom carriers, including AT&T, Verizon, and T-Mobile, reportedly affecting networks serving hundreds of millions of subscribers. Warner has repeatedly called it "the worst telecom hack in our nation's history," while former FBI Director Christopher Wray previously described it as the most significant cyber espionage campaign ever uncovered against U.S. infrastructure. CosmicBytez Labs covered the fallout in February when Senate Commerce Committee leadership demanded that AT&T and Verizon executives testify over withheld Mandiant assessment reports tied to the intrusions. Federal officials say the underlying access gained by the threat actors during the campaign remains an active concern.
Impact Assessment
| Impact Area | Description |
|---|---|
| Regulatory direction | Signals a voluntary, industry-led approach at the same moment the FCC is rolling back mandatory post-Salt Typhoon rules, creating two competing federal tracks |
| Carrier obligations | No new compliance burden until (and unless) the bill passes and the NTIA working group publishes best practices — participation and certification remain optional |
| National security | Working group formation and any resulting practices would not take effect for up to 18 months after passage, well after the confirmed Salt Typhoon intrusions |
| Industry engagement | Carriers and equipment suppliers gain a formal seat in shaping the standards that would eventually apply to them |
| Legislative outlook | Bill has bipartisan committee-leadership sponsorship but has not advanced past introduction; passage timeline is uncertain |
| Public confidence | Comes amid concern from cybersecurity officials that public attention to Salt Typhoon has faded, reducing pressure for stronger action |
Recommendations
For telecom carriers and network operators
- Do not wait for the working group's output to act — treat the 18-month best-practices timeline as a floor, not a target, given Salt Typhoon actors reportedly retain footholds in some networks.
- Begin internally documenting current detection, segmentation, and lawful-intercept-system hardening practices now, since any future NTIA framework will likely draw on documented industry baselines.
- Track both this bill and the FCC's parallel rulemaking closely; carriers may ultimately face a voluntary NTIA framework layered on top of, or in place of, whatever the FCC finalizes.
For security teams and CISOs
- Continue to prioritize monitoring for the tactics, techniques, and procedures (TTPs) publicly attributed to Salt Typhoon, including access to call detail records, lawful-intercept infrastructure, and network routing data, regardless of the legislative outcome.
- Evaluate exposure to shared telecom infrastructure and vendor dependencies, since a working group covers carriers and equipment suppliers together.
- Push for internal adoption of hardening measures aligned with the bill's stated goals even before any formal best-practices document exists.
For policymakers and oversight staff
- Reconcile the voluntary NTIA framework proposed here with the FCC's separate rulemaking to avoid duplicative or contradictory expectations for carriers.
- Monitor whether optional certification sees meaningful industry uptake, since a voluntary program's effectiveness depends heavily on participation rates.
- Continue oversight of outstanding Salt Typhoon transparency questions, including the Mandiant report disputes raised earlier this year, independent of this bill's progress.
Key Takeaways
- Sens. Mark Warner (D-Va.) and Ted Cruz (R-Texas) introduced the Telecommunications Cybersecurity and Resilience Act, creating an NTIA-housed working group to write voluntary telecom cybersecurity best practices.
- The bill sets an 18-month deadline for the working group to publish initial best practices, with reviews every two years or after major incidents, plus an optional third-party certification program.
- The legislation deliberately avoids binding mandates, favoring collaborative, evolving standards over what Cruz called "rigid federal mandates that quickly become outdated."
- It arrives as the FCC moves in the opposite direction, rolling back mandatory Biden-era telecom cybersecurity rules that were adopted after Salt Typhoon — a tension Warner has publicly criticized.
- Salt Typhoon, the Chinese state-linked campaign that compromised AT&T, Verizon, T-Mobile, and other carriers, remains the direct catalyst nearly two years after its public disclosure, with some access reportedly still active.
- The bill has bipartisan committee-leadership backing but is only at the introduction stage — its practical impact on carrier security depends on eventual passage and how the resulting best practices are written.