US cybersecurity policy

Congress Answers Salt Typhoon With a Working Group, Not a Mandate — That's Defensible, But It Needs Teeth

Warner and Cruz's new bill trades the FCC's scrapped telecom cyber mandate for voluntary standards — the right instinct, missing a disclosure mechanism.

The Voluntary Reset on Telecom Cybersecurity People of Internet Research · US 2–1 FCC vote to repeal cyber rule Chairman Carr and Commissioner Tru… 18 months NTIA deadline for standards The new working group must draft v… Since 2019 Salt Typhoon activity span CISA says the PRC-linked actor has… peopleofinternet.com
The Voluntary Reset on Telecom Cyberse… People of Internet Research · US 2–1 FCC vote to repeal cyber rule 18 months NTIA deadline for standards Since 2019 Salt Typhoon activity span peopleofinternet.com

Key Takeaways

A bipartisan bill, a year after the mandate it replaces

On September 24, 2026, Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act, which would create a Telecommunications Cybersecurity Working Group inside the National Telecommunications and Information Administration (NTIA). The group — carriers, equipment suppliers, cybersecurity experts, and federal, state, and local officials — would spend up to 18 months writing voluntary best practices for telecom network security, revisit them every two years or after major incidents, offer companies an optional third-party certification, and report to Congress annually (The Record; Nextgov/FCW).

The timing is not incidental. The bill lands ten months after the FCC voted 2-1 to rescind its own January 2025 Declaratory Ruling, which had required telecom carriers to adopt and annually certify cybersecurity risk-management plans under the Communications Assistance for Law Enforcement Act (CALEA). Chairman Brendan Carr and Commissioner Olivia Trusty called the original ruling "unlawful and ineffective," arguing it misconstrued CALEA and that carriers had "demonstrated a strengthened cybersecurity posture" through voluntary engagement since Salt Typhoon. Commissioner Anna Gomez dissented alone (FCC order, DOC-415455A1). Warner-Cruz is, in effect, Congress deciding it doesn't fully trust either the old mandate or the deregulated status quo, and is trying a third path.

What Salt Typhoon actually showed

Salt Typhoon is the name given to a People's Republic of China state-sponsored hacking campaign that CISA, the NSA, and the FBI say has targeted telecommunications and other critical-infrastructure networks worldwide since at least 2019, primarily by exploiting unpatched router and edge-device vulnerabilities at carriers to gain persistent, largely undetected access (CISA joint advisory). By the time it was publicly disclosed in late 2024, the intrusion had reached nearly every major U.S. telecom carrier. Warner has called it "the worst telecom hack in our nation's history."

Steelmanning the mandate camp

The case for keeping a binding requirement is genuinely strong, and this bill's critics are not wrong to make it. Voluntary regimes rely on carriers self-reporting both their adoption and their incidents, and the Salt Typhoon episode gave Congress direct evidence that self-reporting can fail: Nextgov reports that AT&T and Verizon resisted independent security assessments by the firm Mandiant that Sen. Maria Cantwell had requested — the exact opacity problem a mandate is designed to solve. A market that already failed to self-police before the breach has little reason to police itself more rigorously now that the certification requirement tied to CALEA is gone. Gomez's dissent and Cantwell's objections rest on that plausible read: without a floor, "strengthened posture" is a claim carriers make about themselves, not one anyone outside the company can verify.

Why voluntary-but-structured is still the better bet

That argument earns a serious response, not a mandate reflex. CALEA-based rulemaking was designed for wiretap compliance, not network-security engineering, which is why the FCC's own order calls it a poor legal vehicle regardless of the underlying policy goal — a rare case where the deregulatory and pro-security arguments actually point the same direction. Rigid, prescriptive federal cybersecurity rules also age badly against an adversary that adapts faster than notice-and-comment rulemaking; the NIST Cybersecurity Framework's decade of iterative, industry-informed updates is the better model than a static CALEA certification. A standing NTIA working group with mandated two-year (or incident-triggered) refresh cycles borrows that logic, and pairing it with sector expertise from suppliers and outside researchers — rather than leaving it to a single regulator — is a genuine improvement over both the old FCC rule and today's vacuum.

But "voluntary" only works as regulation if the market can see who opted in and who didn't. As written, nothing in the bill requires carriers to disclose whether they sought certification, let alone whether they passed. Congress doesn't need to resurrect a CALEA mandate to fix that: it could require carriers to state their certification status in FCC filings or SEC cyber-risk disclosures, turning the annual report to Congress into a genuine market signal rather than an internal compliance memo. That single addition — public disclosure, not federal mandate — would answer Gomez's and Cantwell's real objection without recreating the rigidity that made the original rule vulnerable to reversal in the first place.

The bottom line

The Telecommunications Cybersecurity and Resilience Act is a proportionate response to a genuine regulatory gap, and its structure — expert-driven standards, periodic review, optional certification — is more durable policy design than the mandate it implicitly replaces. Its weakness isn't that it's voluntary; it's that voluntary compliance without public disclosure asks Americans to trust exactly the self-assessment that failed to stop Salt Typhoon the first time.

Sources & Citations

  1. The Record: Lawmakers introduce bill for voluntary telecom cyber rules
  2. Nextgov/FCW: Senators propose voluntary telecom security framework
  3. FCC Order rescinding Jan. 2025 CALEA Declaratory Ruling (DOC-415455A1)
  4. CISA joint advisory on PRC state-sponsored telecom compromises