SenateS. 5598119th Congress

Blocking Foreign Cellular Modules in Defense Systems Act of 2026

Full Text

Official text as published. Use Ctrl+F / Cmd+F to search within the document.

[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5598 Introduced in Senate (IS)]

<DOC>

119th CONGRESS
  2d Session
                                S. 5598

 To provide for an audit and mitigation of covered cellular modules in 
         the Department of Defense systems and infrastructure.

_______________________________________________________________________

                   IN THE SENATE OF THE UNITED STATES

                           September 29, 2026

   Mr. Banks introduced the following bill; which was read twice and 
              referred to the Committee on Armed Services

_______________________________________________________________________

                                 A BILL

 
 To provide for an audit and mitigation of covered cellular modules in 
         the Department of Defense systems and infrastructure.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Blocking Foreign Cellular Modules in 
Defense Systems Act of 2026''.

SEC. 2. AUDIT AND MITIGATION OF COVERED CELLULAR MODULES IN THE 
              DEPARTMENT OF DEFENSE SYSTEMS AND INFRASTRUCTURE.

    (a) Department of Defense Audit.--
            (1) In general.--Not later than 180 days after the date of 
        the enactment of this Act, the Secretary of Defense shall 
        initiate a Department-wide audit to identify the presence of 
        covered cellular modules within covered systems.
            (2) Scope.--The audit required under paragraph (1) shall--
                    (A) cover all military departments, combatant 
                commands, defense agencies, and Department of Defense 
                activities or programs;
                    (B) prioritize covered systems critical to military 
                mobility, logistics, and installation security;
                    (C) include both government-owned and contractor-
                operated covered systems connected to Department of 
                Defense networks or accessing Department of Defense 
                information;
                    (D) identify to the maximum extent practicable, the 
                manufacturer, model, firmware version, and host product 
                for each covered cellular module identified; and
                    (E) assess the cybersecurity risk posed by each 
                identified covered cellular module, including data 
                flows, network exposure, and potential for remote 
                access.
    (b) Mitigation and Reporting.--
            (1) Report required.--Not later than 1 year after the date 
        of the enactment of this Act, and biennially thereafter for a 
        period not to exceed 6 years, the Secretary shall submit to the 
        congressional defense committees a report on the audit and 
        mitigation activities carried out under this section.
            (2) Contents.--Each report submitted under paragraph (1) 
        shall include the following:
                    (A) The preliminary or updated findings of the 
                audit required under subsection (b).
                    (B) A description of ongoing and planned mitigation 
                measures, including--
                            (i) rip-and-replace programs;
                            (ii) accelerated divestiture or retirement 
                        of legacy assets;
                            (iii) network segmentation, isolation, or 
                        compensating cybersecurity or engineering 
                        controls;
                            (iv) firmware or software remediation; and
                            (v) supply-chain substitution with trusted 
                        alternatives.
                    (C) Cost estimates, timelines, and resource 
                requirements for each category of mitigation measure 
                described in subparagraph (B).
                    (D) An identification of any statutory, regulatory, 
                or acquisition barriers to completing mitigation.
                    (E) Recommendations for additional legislative 
                authorities, if any, needed to complete mitigation.
            (3) Form.--Each report submitted under paragraph (1) shall 
        be submitted in unclassified form, but may include a classified 
        annex.
    (c) Comptroller General Report.--Not later than 180 days after the 
submission of the report required in subsection (b), the Comptroller 
General of the United States shall submit to the congressional defense 
committees a report on the implementation and effectiveness of the 
activities described in subsection (b).
    (d) Definitions.--In this section:
            (1) Cellular module.--The term ``cellular module'' means a 
        modular transmitter, as described in section 15.212 of title 
        47, Code of Federal Regulations, that provides cellular 
        connectivity to a host product, including an Internet of things 
        device.
            (2) Congressional defense committees.--The term 
        ``congressional defense committees'' has the meaning given the 
        term in section 101(a)(16) of title 10, United States Code.
            (3) Covered cellular module.--The term ``covered cellular 
        module'' means any cellular module produced, manufactured, or 
        provided by--
                    (A) an entity identified under section 889 of the 
                John S. McCain National Defense Authorization Act for 
                Fiscal Year 2019 (Public Law 115-232; 41 U.S.C. 3901 
                note prec.);
                    (B) an entity that is owned by, controlled by, or 
                subject to the jurisdiction or direction of the 
                People's Republic of China; or
                    (C) any other entity determined by the Secretary of 
                Defense to present an unacceptable supply-chain risk.
            (4) Covered system.--The term ``covered system'' means any 
        item of infrastructure owned, leased, operated, or controlled 
        by the Department of Defense.
            (5) Internet of things device.--The term ``Internet of 
        things device'' has the meaning given to such term in NIST 
        Special Publication 1800-16.
                                 <all>