Warner, Cruz Introduce Voluntary Telecom Cybersecurity Bill
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, September 24, 2026, arguing the legislation was necessary in light of the Salt Typhoon attacks, in which Chinese state-linked hackers breached nearly all of the major U.S. telecommunications carriers over the span of several years. The bill would direct the National Telecommunications and Information Administration (NTIA) to convene carriers, equipment suppliers, cybersecurity experts, and federal agencies to develop voluntary, telecom-specific best practices — stopping short of the binding federal mandates some lawmakers and security officials have pushed for since Salt Typhoon came to light nearly two years ago.
Details
| Attribute | Value |
|---|---|
| Bill Name | Telecommunications Cybersecurity and Resilience Act |
| Lead Sponsors | Sen. Mark Warner (D-VA), Vice Chairman, Senate Intelligence Committee; Sen. Ted Cruz (R-TX), Chairman, Senate Commerce, Science, and Transportation Committee |
| Introduced | September 24, 2026 |
| Chamber | U.S. Senate |
| Status | Introduced; not yet through committee markup or a floor vote |
| Core Mechanism | Voluntary, industry-developed best practices — not mandatory federal rules |
| Administering Body | New telecom cybersecurity working group convened by the NTIA |
| Working Group Members | Carriers, network equipment suppliers, independent cybersecurity experts, relevant federal agencies |
| Best-Practices Deadline | 18 months after enactment |
| Review Cadence | Every 2 years, or sooner following a major cyber incident |
| Reporting | Annual report to Congress on the working group's progress |
| Certification | Optional, independent third-party certification for adopting providers |
| Triggering Event | Salt Typhoon — Chinese state-linked telecom espionage campaign |
What the Bill Would Do
An NTIA-led working group, not a regulator
The bill's central mechanism is a working group housed at the NTIA that brings carriers, suppliers, outside security experts, and government agencies to the same table. Rather than writing rules itself, the NTIA would be tasked with facilitating the group's work and aligning whatever best practices emerge with existing federal risk-management frameworks. The group must publish its initial recommendations within 18 months of enactment, revisit them on a two-year cycle (or immediately after a major incident), and file an annual report to Congress documenting its progress.
Certification without a mandate
Providers that adopt the resulting best practices could pursue voluntary certification from independent third-party assessors — a way to publicly demonstrate compliance without the government imposing a compliance requirement. Cruz framed the approach as intentionally flexible: "This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated." Warner struck a similar note, saying, "If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day."
Landing amid a rollback of mandatory rules
The bill arrives months after the Federal Communications Commission (FCC) reversed a Biden-era security requirement — adopted in direct response to Salt Typhoon — that sought to protect telecom networks handling lawful-surveillance requests from unauthorized access. That reversal has drawn criticism from cybersecurity officials and some lawmakers who argue voluntary measures alone were already shown to be insufficient against a sophisticated, persistent, state-sponsored actor. Some officials have also warned that fading public attention to Salt Typhoon has sapped momentum for stronger telecom security rules generally, even as CISA has yet to release a long-pending report on sector-wide telecom vulnerabilities despite bipartisan pressure, including a Senate resolution and letters from Sens. Ron Wyden and Warner.
The Salt Typhoon backdrop
Salt Typhoon is the designation for a multiyear, China-attributed espionage campaign that compromised systems handling lawful-intercept requests at major U.S. carriers, including AT&T, Verizon, and T-Mobile, while also targeting prominent political figures and expanding to telecom operators globally. U.S. officials have warned Beijing could retain the stolen data indefinitely for future surveillance or exploitation. Warner has repeatedly called it "the worst telecom hack in our nation's history." CosmicBytez Labs covered the fallout in February 2026, when Senate Commerce Committee leadership pressed AT&T and Verizon executives to testify over withheld Mandiant assessment reports tied to the intrusions.
Impact Assessment
| Impact Area | Description |
|---|---|
| Regulatory direction | Advances a voluntary, industry-led model at the same time the FCC is unwinding mandatory post-Salt Typhoon rules, leaving two federal tracks pointed in opposite directions |
| Carrier obligations | No new compliance burden takes effect unless and until the bill passes and the NTIA working group publishes best practices; participation and certification remain optional throughout |
| National security timeline | Even under an optimistic passage scenario, initial best practices would not arrive until up to 18 months after enactment — well after the confirmed Salt Typhoon intrusions and any residual adversary access |
| Industry engagement | Carriers and equipment suppliers get a formal seat in shaping standards that would eventually apply to them, which critics may view as reducing the odds of stringent requirements |
| Legislative outlook | Bipartisan committee-leadership sponsorship improves its odds relative to typical bills, but it has not advanced past introduction and faces a crowded fall legislative calendar |
| Public and oversight pressure | Introduced alongside a broader package of bipartisan cybersecurity and AI-related bills, amid concern that public attention to Salt Typhoon has faded since its 2024 disclosure |
Recommendations
For telecom carriers and network operators
- Do not treat the 18-month best-practices timeline as a reason to wait — document current detection, network segmentation, and lawful-intercept system hardening now, since any eventual NTIA framework will likely draw on documented industry baselines.
- Track both this bill and the FCC's parallel rulemaking simultaneously; a voluntary NTIA framework could end up layered on top of, or substituting for, whatever mandatory rules the FCC ultimately finalizes or leaves rolled back.
- Weigh the value of eventual third-party certification early, particularly for carriers serving government, defense, or critical-infrastructure customers who may come to expect it as a baseline signal of due diligence.
For security teams and CISOs
- Continue monitoring for tactics, techniques, and procedures publicly attributed to Salt Typhoon — including access to call detail records, lawful-intercept infrastructure, and network routing data — regardless of how the legislation proceeds.
- Assess exposure through shared telecom infrastructure and vendor dependencies, since the working group's scope spans both carriers and equipment suppliers.
- Push for internal adoption of hardening measures consistent with the bill's stated goals well before any formal best-practices document exists; regulatory timelines should be treated as a floor, not a target.
For policymakers and oversight staff
- Reconcile the voluntary NTIA framework with the FCC's separate telecom security rulemaking to avoid sending carriers conflicting or duplicative expectations.
- Track whether the optional certification program achieves meaningful industry uptake, since a voluntary regime's real-world effect depends almost entirely on participation rates.
- Maintain pressure for the still-unreleased CISA report on telecom sector vulnerabilities, independent of this bill's progress through committee.
Key Takeaways
- Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on September 24, 2026, creating an NTIA-housed working group to develop voluntary telecom cybersecurity best practices.
- The working group must publish initial best practices within 18 months of enactment, review them every 2 years (or after a major incident), and report annually to Congress, with an optional third-party certification program for adopting carriers.
- The bill deliberately avoids binding mandates, with Cruz describing the goal as avoiding "rigid federal mandates that quickly become outdated" in favor of collaborative, evolving standards.
- It arrives as the FCC moves in the opposite direction, having rolled back mandatory Biden-era telecom cybersecurity requirements adopted after Salt Typhoon — creating two competing federal approaches.
- Salt Typhoon, the China-attributed campaign that compromised AT&T, Verizon, T-Mobile, and other carriers, remains the direct catalyst nearly two years after its disclosure, with officials warning stolen data and possible network access could persist.
- The bill has bipartisan committee-leadership backing but is only at the introduction stage; its practical effect on carrier security depends entirely on eventual passage and how the resulting best practices are written.
Sources
- Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks — The Record
- Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks — CyberScoop
- Cruz, Warner Introduce Bipartisan Bill to Strengthen Telecommunications Cybersecurity — Senate Commerce Committee
- Senators propose voluntary telecom security framework after Salt Typhoon hacks — Nextgov/FCW