SenateS. 5508119th Congress

Telecommunications Cybersecurity and Resilience Act

Full Text

Official text as published. Use Ctrl+F / Cmd+F to search within the document.

[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5508 Introduced in Senate (IS)]

<DOC>

119th CONGRESS
  2d Session
                                S. 5508

 To establish a public-private working group to develop cybersecurity 
best practices for telecommunications carriers and related supply chain 
                 participants, and for other purposes.

_______________________________________________________________________

                   IN THE SENATE OF THE UNITED STATES

                           September 24, 2026

 Mr. Warner (for himself and Mr. Cruz) introduced the following bill; 
    which was read twice and referred to the Committee on Commerce, 
                      Science, and Transportation

_______________________________________________________________________

                                 A BILL

 
 To establish a public-private working group to develop cybersecurity 
best practices for telecommunications carriers and related supply chain 
                 participants, and for other purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Telecommunications Cybersecurity and 
Resilience Act''.

SEC. 2. DEFINITIONS.

    In this Act:
            (1) Assistant secretary.--The term ``Assistant Secretary'' 
        means the Assistant Secretary of Commerce for Communications 
        and Information.
            (2) Eligible entity.--The term ``eligible entity'' means--
                    (A) a telecommunications carrier; or
                    (B) any other telecommunications sector or related 
                supply chain stakeholder for which Industry Best 
                Practices are developed under section 4.
            (3) CISA.--The term ``CISA'' means the Cybersecurity and 
        Infrastructure Security Agency.
            (4) Commission.--The term ``Commission'' means the Federal 
        Communications Commission.
            (5) CSRMA.--The term ``CSRMA'' means Communications Sector 
        Risk Management Agency.
            (6) CSRIC.--The term ``CSRIC'' means the Communications 
        Security, Reliability, and Interoperability Council Federal 
        advisory committee to the Commission.
            (7) Industry best practices.--The term ``Industry Best 
        Practices'' means voluntary cybersecurity frameworks and best 
        practices for eligible entities described in section 4(a).
            (8) NIST.--The term ``NIST'' means the National Institute 
        of Standards and Technology.
            (9) NIST csf.--The term ``NIST CSF'' means the latest 
        version of the NIST Cybersecurity Framework.
            (10) NSA.--The term ``NSA'' means the National Security 
        Agency.
            (11) NTIA.--The term ``NTIA'' means the National 
        Telecommunications and Information Administration.
            (12) ODNI.--The term ``ODNI'' means the Office of the 
        Director of National Intelligence.
            (13) ONCD.--The term ``ONCD'' means the Office of the 
        National Cyber Director.
            (14) Relevant congressional committees.--The term 
        ``relevant congressional committees'' means the Committee on 
        Commerce, Science, and Transportation of the Senate and the 
        Committee on Energy and Commerce of the House of 
        Representatives.
            (15) Telecommunications carrier.--The term 
        ``telecommunications carrier'' has the meaning given that term 
        in section 3 of the Communications Act of 1934 (47 U.S.C. 153).
            (16) Working group.--The term ``Working Group'' means the 
        Telecommunications Cybersecurity Working Group established 
        under section 3(a).

SEC. 3. TELECOMMUNICATIONS CYBERSECURITY WORKING GROUP.

    (a) Establishment.--There is established, within NTIA, a public-
private advisory body to be known as the ``Telecommunications 
Cybersecurity Working Group'' that shall--
            (1) develop Industry Best Practices, including associated 
        adoption instructions and materials as outlined in section 4;
            (2) create a network of independent third-party assessors 
        eligible to certify implementation and maintenance of best 
        practices under section 5, including criteria for such 
        assessors; and
            (3) provide and advise on technical feedback and 
        implementation guidance relating to Industry Best Practices 
        developed pursuant to paragraph (1).
    (b) Membership.--
            (1) In general.--The Working Group shall include 
        representatives from NTIA, CISA, NIST, ODNI, ONCD, NSA, the 
        Commission, and industry members appointed in accordance with 
        paragraph (2).
            (2) Initial appointment of industry members.--The Assistant 
        Secretary shall appoint initial members of the Working Group 
        that, to the extent practicable, represent the following 
        stakeholder categories:
                    (A) National telecommunications carriers.
                    (B) Regional and rural telecommunications carriers, 
                including small and medium-sized telecommunications 
                providers.
                    (C) Communications sector suppliers, including 
                network infrastructure and equipment manufacturers.
                    (D) Software and systems providers that offer cloud 
                services, network management, or cybersecurity tools.
                    (E) State and local government communications or 
                emergency network operators.
                    (F) Independent cybersecurity experts and 
                representatives of academia.
                    (G) Other relevant supply chain stakeholders, as 
                jointly determined by the co-chairs.
            (3) Terms and vacancies of industry members.--
                    (A) Terms.--Each industry member of the Working 
                Group shall serve 1 term of not longer than 2 years and 
                may be reappointed for 1 successive term.
                    (B) Vacancy replacement.--The Working Group shall 
                develop a vacancy replacement procedure that includes--
                            (i) for vacancies occurring due to the end 
                        of an industry member's term, a vote not later 
                        than 90 days before the last day of the 
                        industry member's term; and
                            (ii) for vacancies occurring under 
                        paragraph (4) or for any other reason, joint 
                        nomination of a replacement by the co-chairs 
                        from the same stakeholder category under 
                        paragraph (2), to the extent practicable, as 
                        the industry member creating the vacancy, 
                        subject to approval by a majority vote of the 
                        members of the Working Group.
            (4) Removal.--Any member that fails to comply with the 
        conflict of interest policy adopted pursuant to subsection 
        (c)(4) shall be removed from the Working Group.
            (5) Co-chairs.--The Working Group shall have 2 co-chairs, 
        of which--
                    (A) 1 shall be the Assistant Secretary; and
                    (B) 1 shall be selected by a majority vote among a 
                quorum of the industry members appointed in accordance 
                with paragraph (2).
            (6) Member access to classified information.--
                    (A) Access.--
                            (i) In general.--Not later than 60 days 
                        after the date on which a member is first 
                        selected to the Working Group and before the 
                        member is granted access to any classified 
                        information necessary to participate in a 
                        closed session pursuant to subsection (c)(6), 
                        the Assistant Secretary shall determine, for 
                        the purposes of the Working Group, if the 
                        member should be restricted from reviewing, 
                        discussing, or possessing classified 
                        information.
                            (ii) Management.--Access to classified 
                        materials shall be managed in accordance with 
                        Executive Order 13526 (50 U.S.C. 3161 note; 
                        relating to classified national security 
                        information), or any subsequent corresponding 
                        Executive order.
                    (B) Protection of information.--A member of the 
                Working Group granted access to classified information 
                shall protect the classified information in accordance 
                with the applicable requirements for the particular 
                level of classification of the information.
                    (C) Rule of construction.--Nothing in this 
                paragraph shall be construed to affect the security 
                clearance of a member of the Working Group or the 
                authority of a Federal agency to provide a member of 
                the Working Group access to classified information.
    (c) Procedures.--
            (1) Designated federal officer.--The Assistant Secretary 
        shall designate a Federal officer or employee to serve as the 
        Designated Federal Officer of the Working Group, consistent 
        with the requirements of chapter 10 of title 5, United States 
        Code (commonly known as the ``Federal Advisory Committee 
        Act'').
            (2) Initial meeting and bylaws.--Not later than 120 days 
        after the date of enactment of this Act, the Working Group 
        shall convene and establish bylaws that--
                    (A) govern quorum and voting rules;
                    (B) set deliverable timelines and meeting 
                schedules; and
                    (C) create procedures for recommending third-party 
                certification assessors, including conflict-of-interest 
                protocols.
            (3) Operating procedures.--Unless otherwise specified, the 
        Working Group shall adopt written procedures governing its 
        meetings, consistent with chapter 10 of title 5, United States 
        Code, that include--
                    (A) requirements for public notice of meetings and 
                the maintenance of records and minutes;
                    (B) decision making by majority vote of those 
                present and voting, or in accordance with the voting 
                rules established in the bylaws;
                    (C) authorization for the establishment of 
                subgroups as necessary, subject to the approval of the 
                co-chairs; and
                    (D) approval of the meeting agendas by the co-chair 
                described in subsection (b)(5)(A), in consultation with 
                the co-chair described in subsection (b)(5)(B) and the 
                Designated Federal Officer of the Working Group to 
                ensure compliance with applicable laws.
            (4) Conflict-of-interest policy.--
                    (A) In general.--The Working Group shall adopt and 
                enforce a written conflict of interest policy to ensure 
                that members have a fiduciary responsibility to the 
                Working Group, a duty to report conflicts of interest, 
                including the appearance of a conflict of interest, and 
                do not participate in deliberations or votes from which 
                they personally or their employer would directly and 
                materially benefit.
                    (B) Required disclosures.--The policy under 
                subparagraph (A) shall require each member to publicly 
                disclose all relevant financial and employment 
                relationships and include recusal procedures in the 
                event of a conflict.
                    (C) Records.--The Designated Federal Officer of the 
                Working Group shall maintain records of disclosures 
                under subparagraph (B) and make summaries of the 
                disclosures available to NTIA.
            (5) Threat information access.--ODNI, in coordination with 
        other appropriate Federal entities, shall ensure that the 
        Working Group has access to relevant cybersecurity threat 
        information, including through closed or classified briefings 
        for members eligible to receive such information, when 
        appropriate.
            (6) Closed sessions.--Notwithstanding section 1009 of title 
        5, United States Code, the Working Group may hold closed or 
        restricted-access sessions when the Assistant Secretary 
        determines that the matters to be discussed involve any of the 
        following:
                    (A) Classified information.
                    (B) Sensitive cybersecurity vulnerabilities.
                    (C) Threat information.
                    (D) Proprietary business information.
                    (E) Other information exempt from public disclosure 
                under section 552 of title 5, United States Code.
    (d) Transparency and Communication.--The Assistant Secretary 
shall--
            (1) publish Industry Best Practices, implementation 
        guidance, and criteria for third-party assessors;
            (2) publish on the website of NTIA and submit to the 
        relevant congressional committees the bylaws, membership, and 
        procedures of the Working Group; and
            (3) publish a memorandum of understanding (or equivalent 
        written coordination instrument) among NTIA, CISA (acting 
        through the CSRMA), NIST, and the Commission describing roles, 
        coordination, and non-duplication procedures under this Act.
    (e) Termination of Advisory Committee.--Section 1013(a) of title 5, 
United States Code, shall not apply with respect to the Working Group.

SEC. 4. DEVELOPMENT OF INDUSTRY BEST PRACTICES FOR CYBERSECURITY.

    (a) In General.--Not later than 18 months after the date of 
enactment of this Act, the Working Group shall, in consultation with 
the heads of NTIA, CISA, NIST, ODNI, ONCD, NSA, and the Commission, 
develop and maintain cybersecurity best practices (and corresponding 
implementation guidance), referred to in this Act as ``Industry Best 
Practices'', for telecommunications carriers and other eligible 
entities that--
            (1) are for carriers and communications sector suppliers 
        and the telecommunications sector to elect to implement and 
        maintain;
            (2) are issued and maintained by CISA, acting through the 
        CSRMA, with NTIA serving as the convener and administrative 
        home for the Working Group;
            (3) apply, as appropriate, to communications sector 
        suppliers and other supply chain participants, which may 
        participate as eligible entities for purposes of certification 
        under section 5;
            (4) focus solely on identifying, responding to, mitigating, 
        preventing, and remediating cybersecurity incidents and 
        vulnerabilities;
            (5) are risk-based and consistent with other Federal 
        cybersecurity risk management frameworks, including CISA sector 
        guidance, the NIST Cybersecurity Framework, the NIST Risk 
        Management Framework, and relevant cybersecurity guidance 
        developed pursuant to Executive Order 14028 (44 U.S.C. 3551 
        note; relating to improving the nation's cybersecurity), 
        including those for communications subsectors, and any relevant 
        successor guidance;
            (6) may account for, as appropriate, relevant cybersecurity 
        requirements and certifications of a current member of the 
        North Atlantic Treaty Organization, a major non-NATO ally (as 
        designated under section 517 of the Foreign Assistance Act of 
        1961 (22 U.S.C. 2321k)), or a member of the Five Eyes countries 
        (as defined in section 1606(c) of the James M. Inhofe National 
        Defense Authorization Act for Fiscal Year 2023 (10 U.S.C. 2271 
        note)), including as relevant to interoperability or avoiding 
        unnecessary duplication;
            (7) avoid duplication of existing cybersecurity risk 
        management processes; and
            (8) reflect available threat intelligence, Federal 
        cybersecurity advisories, and technological developments at the 
        time of development or update.
    (b) Industry Best Practices Contents.--The Industry Best Practices 
may include--
            (1) application of security updates to network devices, as 
        available;
            (2) the timely decommissioning, or implementation of secure 
        alternative mitigations, of network devices owned by and under 
        the control and management of the telecommunications carrier 
        that no longer receive updates by the original equipment 
        manufacturer to address identified security vulnerabilities in 
        the network device;
            (3) the creation and maintenance of configuration 
        management practices for the hardware, software, or firmware, 
        or a combination thereof, of network devices owned by or under 
        the control and management of the telecommunications carrier 
        including, at a minimum, a baseline configuration and 
        configuration management plan that align with internal security 
        policies and NIST CSF 2.0 industry best practices;
            (4) implementation of appropriate multi-factor 
        authentication, or identity control and access management 
        measures; and
            (5) other such practices as established by the Working 
        Group.
    (c) Review and Update.--The Working Group shall review and update 
Industry Best Practices (and corresponding implementation guidance) not 
less frequently than once every 2 years, and interim updates may be 
made in response to significant cybersecurity incidents or material 
changes in threat conditions if determined necessary by the Working 
Group, to reflect evolving cybersecurity risks and technologies.
    (d) Use of Existing Bodies.--In carrying out this section, the 
Working Group may consult with other public-private advisory councils 
and relevant information-sharing organizations, as well as any Federal 
entities, including the Commission, NTIA, and CISA, that the Working 
Group determines may be capable of providing meaningful insight with 
respect to the development of Industry Best Practices (and 
corresponding implementation guidance).
    (e) Publication and Guidance Access.--
            (1) In general.--The Assistant Secretary shall publish 
        Industry Best Practices (and corresponding implementation 
        guidance) on the website of NTIA, to promote transparency and 
        encourage voluntary alignment across the telecommunications 
        sector.
            (2) Guidance.--
                    (A) Withholding for cybersecurity.--The Assistant 
                Secretary, in consultation with the head of CISA, may 
                withhold detailed implementation guidance from public 
                release to mitigate cybersecurity risks, provided that 
                the implementation guidance is made available to 
                eligible entities and eligible cybersecurity assessors 
                for purposes of certification under section 5.
                    (B) Exemption from disclosure.--Detailed 
                implementation guidance withheld under subparagraph (A) 
                is exempt from disclosure under section 552(b)(3) of 
                title 5, United States Code.
                    (C) No use for regulatory enforcement.--No 
                information disclosed by an eligible entity for the 
                purposes of informing guidance published or disclosed 
                pursuant to this paragraph may be used in any 
                regulatory proceeding or enforcement action.
                    (D) Rule of construction (no new commission 
                authority).--Nothing in this Act shall be construed to 
                expand the authority of the Commission to promulgate or 
                enforce cybersecurity regulations, or to require 
                adoption of Industry Best Practices, which eligible 
                entities may elect to adopt.
                    (E) No adverse inference.--No regulatory agency may 
                draw any inferences from an eligible entity choosing 
                not to adopt Industry Best Practices or implementation 
                guidance.

SEC. 5. CYBERSECURITY CERTIFICATION REQUIREMENTS FOR ELIGIBLE ENTITIES.

    (a) Eligible Assessor Criteria and Publication.--
            (1) Development and approval of criteria.--
                    (A) Development of criteria.--The Working Group 
                shall determine, and the Assistant Secretary shall 
                approve, criteria for independent third-party 
                cybersecurity assessors.
                    (B) Documentation.--In developing the criteria 
                under subparagraph (A), the Working Group shall publish 
                the assessment criteria and general methodology to be 
                used by eligible cybersecurity assessors, except for 
                information the Assistant Secretary determines should 
                be withheld to mitigate cybersecurity risks.
            (2) Publication of eligible cybersecurity assessors.--The 
        Assistant Secretary shall--
                    (A) establish an evaluation process and assessment 
                standard for designating eligible cybersecurity 
                assessors;
                    (B) publish a list of eligible cybersecurity 
                assessors designated pursuant to subparagraph (A) that 
                a telecommunications carrier, or other eligible entity 
                for which Industry Best Practices were developed, may 
                elect to evaluate the telecommunication carrier's or 
                eligible entity's implementation of Industry Best 
                Practices and that may issue a proposed certification; 
                and
                    (C) establish conditions under which to revoke or 
                suspend the designation as an eligible cybersecurity 
                assessor.
            (3) Prohibition on certain assessors.--No entity owned or 
        controlled by a telecommunications carrier may be designated as 
        an eligible cybersecurity assessor under this subsection.
    (b) Certification and Approval Process.--
            (1) Approval of certification.--
                    (A) Submission.--
                            (i) In general.--A telecommunications 
                        carrier or other eligible entity that elects to 
                        have an eligible cybersecurity assessor 
                        evaluate the telecommunication carrier or 
                        eligible entity and receives a proposed 
                        certification may submit the proposed 
                        certification to the Assistant Secretary for 
                        approval.
                            (ii) Format of submissions.--The Assistant 
                        Secretary may require submissions of the 
                        proposed certification under clause (i) to be 
                        submitted in machine readable format in the 
                        Open Security Controls Assessment Language 
                        architecture developed by NIST, or a successor 
                        framework.
                    (B) Contents of submission.--A submission under 
                subparagraph (A) shall include--
                            (i) the full assessment report prepared by 
                        the eligible cybersecurity assessor;
                            (ii) documentation of the Industry Best 
                        Practices against which the telecommunications 
                        carrier or other eligible entity was evaluated; 
                        and
                            (iii) the disclosures required under 
                        subsection (c)(4).
                    (C) Timeframe for decision.--Upon receipt of a 
                proposed certification for approval, the Assistant 
                Secretary shall, within 30 days, determine whether the 
                submission is complete and, not later than 90 days 
                after the date of such determination, approve or 
                disapprove the complete proposed certification.
                    (D) Disapproval of certification.--In the event 
                that the Assistant Secretary disapproves a proposed 
                certification under this paragraph, the Assistant 
                Secretary shall inform the eligible entity of the basis 
                for the disapproval.
                    (E) Right to cure and appeal.--
                            (i) Right to cure.--An eligible entity the 
                        proposed certification of which was disapproved 
                        by the Assistant Secretary shall have 30 days 
                        to resubmit the proposed certification, during 
                        which period no adverse action shall be taken 
                        by the Assistant Secretary against the eligible 
                        entity on the basis of lacking a certification.
                            (ii) Right to appeal.--
                                    (I) In general.--An eligible entity 
                                described in clause (i) may appeal the 
                                disapproval to the Assistant Secretary.
                                    (II) Process.--The Assistant 
                                Secretary shall establish the manner 
                                and form in which appeals under this 
                                clause shall be heard and shall render 
                                a decision on any such appeal not later 
                                than 90 days after the date of the 
                                initiation of the appeal.
            (2) Effect of certification.--A certified 
        telecommunications carrier or other eligible entity shall, in 
        any Federal or State court, be entitled to an affirmative 
        defense that approval of a certification under paragraph (1) 
        constitutes due care or reasonableness for mitigating, 
        preventing, and remediating cybersecurity incidents and 
        vulnerabilities, unless the telecommunications carrier or other 
        eligible entity is found to have acted with gross negligence, 
        willful misconduct, or have not materially implemented and 
        maintained the Industry Best Practices consistent with the 
        approved certification.
            (3) Timing; later change.--The defense under paragraph (2) 
        shall apply if the eligible entity was certified and in 
        compliance with the Industry Best Practices in effect at the 
        time of the incident, notwithstanding--
                    (A) subsequent revisions to Industry Best 
                Practices; or
                    (B) subsequent expiration, subsequent suspension, 
                or non-renewal of the certification.
            (4) Conflict preemption.--No State or political subdivision 
        of a State may establish, maintain, prescribe, continue, or 
        enforce any law, rule, regulation, or requirement imposing a 
        duty, standard, requirement, or liability or enforcing 
        standards for cybersecurity that are inconsistent with this Act 
        with respect to a certified eligible entity.
    (c) Certification Requirements.--Each approved certification under 
subsection (b)(1) shall--
            (1) be valid for a period of not more than 2 years;
            (2) be renewable through comprehensive reassessment;
            (3) include documentation of implementation and maintenance 
        of the applicable Industry Best Practices at the time of 
        certification;
            (4) require disclosure of any direct financial interest or 
        material business relationship between the assessor and the 
        entity being assessed;
            (5) include a description of the assessment methodology and 
        criteria used; and
            (6) be subject to revocation by the Assistant Secretary if 
        the assessor is found to have issued invalid or false 
        certifications.
    (d) Whistleblower Protection.--
            (1) In general.--No eligible cybersecurity assessor or 
        telecommunications carrier with an approved or pending 
        certification, or any officer, employee, contractor, 
        subcontractor, or agent of such company, may discharge, demote, 
        suspend, threaten, harass, or in any other manner discriminate 
        against an employee in the terms and conditions of employment 
        because of any lawful act done by the employee to provide 
        information to, cause information to be provided to, or 
        otherwise assist in an investigation by an agency, entity, or 
        person described in paragraph (2), relating to any conduct that 
        the employee reasonably believes reflects non-compliance with 
        or gross misrepresentation relating to the certification 
        standard established by the Working Group.
            (2) Agency, entity, or person described.--An agency, 
        entity, or person described in this paragraph is--
                    (A) a Federal regulatory or law enforcement agency;
                    (B) any Member of Congress or any committee of 
                Congress; or
                    (C) a person with supervisory authority over the 
                employee (or such other person working for the employer 
                who has the authority to investigate, discover, or 
                terminate misconduct).
    (e) Routine Implementation and Maintenance Obligation.--A certified 
eligible entity shall routinely implement and maintain cybersecurity 
practices aligned with Industry Best Practices, as updated, during the 
period of certification.
    (f) Early Reassessment.--
            (1) Authority.--
                    (A) In general.--Upon any of the grounds described 
                in paragraph (2), the Assistant Secretary may direct an 
                eligible cybersecurity assessor to conduct, or may on 
                the Assistant Secretary's own initiative commission by 
                an alternative eligible cybersecurity assessor, an 
                early reassessment of a certified eligible entity and 
                may, upon a written finding of credible evidence of 
                material failure to implement or maintain the Industry 
                Best Practices, suspend the approved certification of 
                the eligible entity pending successful completion of 
                the reassessment.
                    (B) Responsibility for costs associated with 
                assessment.--If an assessment conducted pursuant to 
                subparagraph (A) determines that the eligible entity 
                has materially failed to implement or maintain the 
                Industry Best Practices, the eligible entity shall be 
                responsible for all costs associated with performing 
                the assessment.
            (2) Grounds for reassessment.--The grounds described in 
        this paragraph include--
                    (A) a substantial revision to Industry Best 
                Practices;
                    (B) a telecommunications carrier or other eligible 
                entity experiences a significant cyber-incident, as 
                defined by Presidential Policy Directive-41 (July 26, 
                2016; relating to United States cyber incident 
                coordination); and
                    (C) the Assistant Secretary receives credible 
                information that--
                            (i) any of the contents submitted to the 
                        Assistant Secretary under subsection (b)(1) to 
                        approve a certification were false or 
                        fraudulent; or
                            (ii) an eligible entity has failed to 
                        routinely implement and maintain cybersecurity 
                        practices in accordance with subsection (e).
            (3) Good faith protection.--A certified telecommunications 
        carrier or other eligible entity shall not have its 
        certification under subsection (b) revoked solely due to an 
        early reassessment under this subsection, unless and until the 
        early reassessment produces a final determination that the 
        eligible entity--
                    (A) materially failed to implement or maintain the 
                Industry Best Practices the entity elected to adopt 
                through the certification process; or
                    (B) has engaged in gross negligence or willful 
                misconduct.

SEC. 6. REPORTING REQUIREMENTS.

    (a) Annual Report.--Not later than 1 year after the publication of 
any Industry Best Practices developed under section 4, and annually 
thereafter, the Assistant Secretary, in consultation with the Working 
Group, shall submit to the relevant congressional committees and 
publish a public version on the website of NTIA a report that 
includes--
            (1) an overview of the development of Industry Best 
        Practices, and any updates or modifications of Industry Best 
        Practices;
            (2) data on participation of eligible entities in the 
        certification process;
            (3) a summary of early reassessment activity, if any;
            (4) an assessment of the adoption of Industry Best 
        Practices; and
            (5) the effectiveness of Industry Best Practices and 
        certification in enhancing cybersecurity across the 
        telecommunications sector.
    (b) Event-Triggered Report.--Not later than 90 days after a 
substantial revision to Industry Best Practices or a significant cyber-
incident, as defined in Presidential Policy Directive-41 (July 26, 
2016; relating to United States cyber incident coordination), affecting 
the telecommunications sector, the Assistant Secretary, in consultation 
with the Working Group, shall submit to Congress a report that 
includes, to the greatest extent practicable, the consensus views and 
recommendations of the Working Group to improve cybersecurity across 
the telecommunications sector.

SEC. 7. RULES OF CONSTRUCTION.

    Nothing in this Act shall be construed to--
            (1) grant any regulatory authority to any Federal agency;
            (2) expand or otherwise alter obligations or authorities 
        under the Communications Act of 1934 (47 U.S.C. 151 et seq.), 
        the Secure and Trusted Communications Networks Act of 2019 (47 
        U.S.C. 1601 et seq.), the Secure Equipment Act of 2021 (47 
        U.S.C. 1601 note), or any other Federal law;
            (3) prohibit the Working Group from consulting with or 
        referencing the work product of Federal advisory committees 
        subject to chapter 10 of title 5, United States Code, including 
        the President's National Security Telecommunications Advisory 
        Committee, CSRIC, and the Commission's Technological Advisory 
        Council;
            (4) require adoption of Industry Best Practices or 
        implementation guidance, or authorize any regulatory 
        requirement of adoption;
            (5) displace or replace the functions of any Federal 
        advisory council or information-sharing agreement;
            (6) grant regulatory authority to the Commission, or any 
        other Federal body; or
            (7) authorize, expand, or imply any Federal authority to 
        supervise, direct, mandate, regulate, audit, or otherwise 
        oversee the cybersecurity operations, risk-management programs, 
        technical controls, or network security practices of any 
        telecommunications carrier or other eligible entity, except as 
        expressly permitted for the development, publication, and 
        voluntary certification of Industry Best Practices under this 
        Act.

SEC. 8. SEVERABILITY.

    If any provision of this Act, or its application to any person or 
circumstance, is held to be unconstitutional, the remainder of this 
Act, and the application of the provision to any other person or 
circumstance, shall not be affected.
                                 <all>