Telecommunications Cybersecurity and Resilience Act
Sponsor

Full profile: /officials/W000805
Source: Congress.gov · FEC
Cosponsors (1)
Members who have signed on to support this bill since introduction. Source: Congress.gov.
Latest Action
The most recent step in the bill's legislative path. Committee Activity below shows referrals and reports; the full action-by-action history including floor proceedings lives at Congress.gov →
Read twice and referred to the Committee on Commerce, Science, and Transportation.
2026-09-24
Source: Congress.gov
Committee Activity
Currently in
- Senate Committee on Commerce, Science, and TransportationReferred To · 2026-09-24
Plain-English Summary
Plain-English summary pending. Introduced on 2026-09-24. Check back soon — summaries are generated as bills progress through Congress.
Full Bill Text
Verbatim text published on Congress.gov via GovInfo. Use Cmd+F / Ctrl+F to search within this excerpt.
[Congressional Bills 119th Congress] [From the U.S. Government Publishing Office] [S. 5508 Introduced in Senate (IS)] <DOC> 119th CONGRESS 2d Session S. 5508 To establish a public-private working group to develop cybersecurity best practices for telecommunications carriers and related supply chain participants, and for other purposes. _______________________________________________________________________ IN THE SENATE OF THE UNITED STATES September 24, 2026 Mr. Warner (for himself and Mr. Cruz) introduced the following bill; which was read twice and referred to the Committee on Commerce, Science, and Transportation _______________________________________________________________________ A BILL To establish a public-private working group to develop cybersecurity best practices for telecommunications carriers and related supply chain participants, and for other purposes. Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, SECTION 1. SHORT TITLE. This Act may be cited as the ``Telecommunications Cybersecurity and Resilience Act''. SEC. 2. DEFINITIONS. In this Act: (1) Assistant secretary.--The term ``Assistant Secretary'' means the Assistant Secretary of Commerce for Communications and Information. (2) Eligible entity.--The term ``eligible entity'' means-- (A) a telecommunications carrier; or (B) any other telecommunications sector or related supply chain stakeholder for which Industry Best Practices are developed under section 4. (3) CISA.--The term ``CISA'' means the Cybersecurity and Infrastructure Security Agency. (4) Commission.--The term ``Commission'' means the Federal Communications Commission. (5) CSRMA.--The term ``CSRMA'' means Communications Sector Risk Management Agency. (6) CSRIC.--The term ``CSRIC'' means the Communications Security, Reliability, and Interoperability Council Federal advisory committee to the Commission. (7) Industry best practices.--The term ``Industry Best Practices'' means voluntary cybersecurity frameworks and best practices for eligible entities described in section 4(a). (8) NIST.--The term ``NIST'' means the National Institute of Standards and Technology. (9) NIST csf.--The term ``NIST CSF'' means the latest version of the NIST Cybersecurity Framework. (10) NSA.--The term ``NSA'' means the National Security Agency. (11) NTIA.--The term ``NTIA'' means the National Telecommunications and Information Administration. (12) ODNI.--The term ``ODNI'' means the Office of the Director of National Intelligence. (13) ONCD.--The term ``ONCD'' means the Office of the National Cyber Director. (14) Relevant congressional committees.--The term ``relevant congressional committees'' means the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Energy and Commerce of the House of Representatives. (15) Telecommunications carrier.--The term ``telecommunications carrier'' has the meaning given that term in section 3 of the Communications Act of 1934 (47 U.S.C. 153). (16) Working group.--The term ``Working Group'' means the Telecommunications Cybersecurity Working Group established under section 3(a). SEC. 3. TELECOMMUNICATIONS CYBERSECURITY WORKING GROUP. (a) Establishment.--There is established, within NTIA, a public- private advisory body to be known as the ``Telecommunications Cybersecurity Working Group'' that shall-- (1) develop Industry Best Practices, including associated adoption instructions and materials as outlined in section 4; (2) create a network of independent third-party assessors eligible to certify implementation and maintenance of best practices under section 5, including criteria for such assessors; and (3) provide and advise on technical feedback and implementation guidance relating to Industry Best Practices developed pursuant to paragraph (1). (b) Membership.-- (1) In general.--The Working Group shall include representatives from NTIA, CISA, NIST, ODNI, ONCD, NSA, the Commission, and industry members appointed in accordance with paragraph (2). (2) Initial appointment of industry members.--The Assistant Secretary shall appoint initial members of the Working Group that, to the extent practicable, represent the following stakeholder categories: (A) National telecommunications carriers. (B) Regional and rural telecommunications carriers, including small and medium-sized telecommunications providers. (C) Communications sector suppliers, including network infrastructure and equipment manufacturers. (D) Software and systems providers that offer cloud services, network management, or cybersecurity tools. (E) State and local government communications…
Show the remaining 3,470 wordsHide the remaining 3,470 words
or emergency network operators. (F) Independent cybersecurity experts and representatives of academia. (G) Other relevant supply chain stakeholders, as jointly determined by the co-chairs. (3) Terms and vacancies of industry members.-- (A) Terms.--Each industry member of the Working Group shall serve 1 term of not longer than 2 years and may be reappointed for 1 successive term. (B) Vacancy replacement.--The Working Group shall develop a vacancy replacement procedure that includes-- (i) for vacancies occurring due to the end of an industry member's term, a vote not later than 90 days before the last day of the industry member's term; and (ii) for vacancies occurring under paragraph (4) or for any other reason, joint nomination of a replacement by the co-chairs from the same stakeholder category under paragraph (2), to the extent practicable, as the industry member creating the vacancy, subject to approval by a majority vote of the members of the Working Group. (4) Removal.--Any member that fails to comply with the conflict of interest policy adopted pursuant to subsection (c)(4) shall be removed from the Working Group. (5) Co-chairs.--The Working Group shall have 2 co-chairs, of which-- (A) 1 shall be the Assistant Secretary; and (B) 1 shall be selected by a majority vote among a quorum of the industry members appointed in accordance with paragraph (2). (6) Member access to classified information.-- (A) Access.-- (i) In general.--Not later than 60 days after the date on which a member is first selected to the Working Group and before the member is granted access to any classified information necessary to participate in a closed session pursuant to subsection (c)(6), the Assistant Secretary shall determine, for the purposes of the Working Group, if the member should be restricted from reviewing, discussing, or possessing classified information. (ii) Management.--Access to classified materials shall be managed in accordance with Executive Order 13526 (50 U.S.C. 3161 note; relating to classified national security information), or any subsequent corresponding Executive order. (B) Protection of information.--A member of the Working Group granted access to classified information shall protect the classified information in accordance with the applicable requirements for the particular level of classification of the information. (C) Rule of construction.--Nothing in this paragraph shall be construed to affect the security clearance of a member of the Working Group or the authority of a Federal agency to provide a member of the Working Group access to classified information. (c) Procedures.-- (1) Designated federal officer.--The Assistant Secretary shall designate a Federal officer or employee to serve as the Designated Federal Officer of the Working Group, consistent with the requirements of chapter 10 of title 5, United States Code (commonly known as the ``Federal Advisory Committee Act''). (2) Initial meeting and bylaws.--Not later than 120 days after the date of enactment of this Act, the Working Group shall convene and establish bylaws that-- (A) govern quorum and voting rules; (B) set deliverable timelines and meeting schedules; and (C) create procedures for recommending third-party certification assessors, including conflict-of-interest protocols. (3) Operating procedures.--Unless otherwise specified, the Working Group shall adopt written procedures governing its meetings, consistent with chapter 10 of title 5, United States Code, that include-- (A) requirements for public notice of meetings and the maintenance of records and minutes; (B) decision making by majority vote of those present and voting, or in accordance with the voting rules established in the bylaws; (C) authorization for the establishment of subgroups as necessary, subject to the approval of the co-chairs; and (D) approval of the meeting agendas by the co-chair described in subsection (b)(5)(A), in consultation with the co-chair described in subsection (b)(5)(B) and the Designated Federal Officer of the Working Group to ensure compliance with applicable laws. (4) Conflict-of-interest policy.-- (A) In general.--The Working Group shall adopt and enforce a written conflict of interest policy to ensure that members have a fiduciary responsibility to the Working Group, a duty to report conflicts of interest, including the appearance of a conflict of interest, and do not participate in deliberations or votes from which they personally or their employer would directly and materially benefit. (B) Required disclosures.--The policy under subparagraph (A) shall require each member to publicly disclose all relevant financial and employment relationships and include recusal procedures in the event of a conflict. (C) Records.--The Designated Federal Officer of the Working Group shall maintain records of disclosures under subparagraph (B) and make summaries of the disclosures available to NTIA. (5) Threat information access.--ODNI, in coordination with other appropriate Federal entities, shall ensure that the Working Group has access to relevant cybersecurity threat information, including through closed or classified briefings for members eligible to receive such information, when appropriate. (6) Closed sessions.--Notwithstanding section 1009 of title 5, United States Code, the Working Group may hold closed or restricted-access sessions when the Assistant Secretary determines that the matters to be discussed involve any of the following: (A) Classified information. (B) Sensitive cybersecurity vulnerabilities. (C) Threat information. (D) Proprietary business information. (E) Other information exempt from public disclosure under section 552 of title 5, United States Code. (d) Transparency and Communication.--The Assistant Secretary shall-- (1) publish Industry Best Practices, implementation guidance, and criteria for third-party assessors; (2) publish on the website of NTIA and submit to the relevant congressional committees the bylaws, membership, and procedures of the Working Group; and (3) publish a memorandum of understanding (or equivalent written coordination instrument) among NTIA, CISA (acting through the CSRMA), NIST, and the Commission describing roles, coordination, and non-duplication procedures under this Act. (e) Termination of Advisory Committee.--Section 1013(a) of title 5, United States Code, shall not apply with respect to the Working Group. SEC. 4. DEVELOPMENT OF INDUSTRY BEST PRACTICES FOR CYBERSECURITY. (a) In General.--Not later than 18 months after the date of enactment of this Act, the Working Group shall, in consultation with the heads of NTIA, CISA, NIST, ODNI, ONCD, NSA, and the Commission, develop and maintain cybersecurity best practices (and corresponding implementation guidance), referred to in this Act as ``Industry Best Practices'', for telecommunications carriers and other eligible entities that-- (1) are for carriers and communications sector suppliers and the telecommunications sector to elect to implement and maintain; (2) are issued and maintained by CISA, acting through the CSRMA, with NTIA serving as the convener and administrative home for the Working Group; (3) apply, as appropriate, to communications sector suppliers and other supply chain participants, which may participate as eligible entities for purposes of certification under section 5; (4) focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities; (5) are risk-based and consistent with other Federal cybersecurity risk management frameworks, including CISA sector guidance, the NIST Cybersecurity Framework, the NIST Risk Management Framework, and relevant cybersecurity guidance developed pursuant to Executive Order 14028 (44 U.S.C. 3551 note; relating to improving the nation's cybersecurity), including those for communications subsectors, and any relevant successor guidance; (6) may account for, as appropriate, relevant cybersecurity requirements and certifications of a current member of the North Atlantic Treaty Organization, a major non-NATO ally (as designated under section 517 of the Foreign Assistance Act of 1961 (22 U.S.C. 2321k)), or a member of the Five Eyes countries (as defined in section 1606(c) of the James M. Inhofe National Defense Authorization Act for Fiscal Year 2023 (10 U.S.C. 2271 note)), including as relevant to interoperability or avoiding unnecessary duplication; (7) avoid duplication of existing cybersecurity risk management processes; and (8) reflect available threat intelligence, Federal cybersecurity advisories, and technological developments at the time of development or update. (b) Industry Best Practices Contents.--The Industry Best Practices may include-- (1) application of security updates to network devices, as available; (2) the timely decommissioning, or implementation of secure alternative mitigations, of network devices owned by and under the control and management of the telecommunications carrier that no longer receive updates by the original equipment manufacturer to address identified security vulnerabilities in the network device; (3) the creation and maintenance of configuration management practices for the hardware, software, or firmware, or a combination thereof, of network devices owned by or under the control and management of the telecommunications carrier including, at a minimum, a baseline configuration and configuration management plan that align with internal security policies and NIST CSF 2.0 industry best practices; (4) implementation of appropriate multi-factor authentication, or identity control and access management measures; and (5) other such practices as established by the Working Group. (c) Review and Update.--The Working Group shall review and update Industry Best Practices (and corresponding implementation guidance) not less frequently than once every 2 years, and interim updates may be made in response to significant cybersecurity incidents or material changes in threat conditions if determined necessary by the Working Group, to reflect evolving cybersecurity risks and technologies. (d) Use of Existing Bodies.--In carrying out this section, the Working Group may consult with other public-private advisory councils and relevant information-sharing organizations, as well as any Federal entities, including the Commission, NTIA, and CISA, that the Working Group determines may be capable of providing meaningful insight with respect to the development of Industry Best Practices (and corresponding implementation guidance). (e) Publication and Guidance Access.-- (1) In general.--The Assistant Secretary shall publish Industry Best Practices (and corresponding implementation guidance) on the website of NTIA, to promote transparency and encourage voluntary alignment across the telecommunications sector. (2) Guidance.-- (A) Withholding for cybersecurity.--The Assistant Secretary, in consultation with the head of CISA, may withhold detailed implementation guidance from public release to mitigate cybersecurity risks, provided that the implementation guidance is made available to eligible entities and eligible cybersecurity assessors for purposes of certification under section 5. (B) Exemption from disclosure.--Detailed implementation guidance withheld under subparagraph (A) is exempt from disclosure under section 552(b)(3) of title 5, United States Code. (C) No use for regulatory enforcement.--No information disclosed by an eligible entity for the purposes of informing guidance published or disclosed pursuant to this paragraph may be used in any regulatory proceeding or enforcement action. (D) Rule of construction (no new commission authority).--Nothing in this Act shall be construed to expand the authority of the Commission to promulgate or enforce cybersecurity regulations, or to require adoption of Industry Best Practices, which eligible entities may elect to adopt. (E) No adverse inference.--No regulatory agency may draw any inferences from an eligible entity choosing not to adopt Industry Best Practices or implementation guidance. SEC. 5. CYBERSECURITY CERTIFICATION REQUIREMENTS FOR ELIGIBLE ENTITIES. (a) Eligible Assessor Criteria and Publication.-- (1) Development and approval of criteria.-- (A) Development of criteria.--The Working Group shall determine, and the Assistant Secretary shall approve, criteria for independent third-party cybersecurity assessors. (B) Documentation.--In developing the criteria under subparagraph (A), the Working Group shall publish the assessment criteria and general methodology to be used by eligible cybersecurity assessors, except for information the Assistant Secretary determines should be withheld to mitigate cybersecurity risks. (2) Publication of eligible cybersecurity assessors.--The Assistant Secretary shall-- (A) establish an evaluation process and assessment standard for designating eligible cybersecurity assessors; (B) publish a list of eligible cybersecurity assessors designated pursuant to subparagraph (A) that a telecommunications carrier, or other eligible entity for which Industry Best Practices were developed, may elect to evaluate the telecommunication carrier's or eligible entity's implementation of Industry Best Practices and that may issue a proposed certification; and (C) establish conditions under which to revoke or suspend the designation as an eligible cybersecurity assessor. (3) Prohibition on certain assessors.--No entity owned or controlled by a telecommunications carrier may be designated as an eligible cybersecurity assessor under this subsection. (b) Certification and Approval Process.-- (1) Approval of certification.-- (A) Submission.-- (i) In general.--A telecommunications carrier or other eligible entity that elects to have an eligible cybersecurity assessor evaluate the telecommunication carrier or eligible entity and receives a proposed certification may submit the proposed certification to the Assistant Secretary for approval. (ii) Format of submissions.--The Assistant Secretary may require submissions of the proposed certification under clause (i) to be submitted in machine readable format in the Open Security Controls Assessment Language architecture developed by NIST, or a successor framework. (B) Contents of submission.--A submission under subparagraph (A) shall include-- (i) the full assessment report prepared by the eligible cybersecurity assessor; (ii) documentation of the Industry Best Practices against which the telecommunications carrier or other eligible entity was evaluated; and (iii) the disclosures required under subsection (c)(4). (C) Timeframe for decision.--Upon receipt of a proposed certification for approval, the Assistant Secretary shall, within 30 days, determine whether the submission is complete and, not later than 90 days after the date of such determination, approve or disapprove the complete proposed certification. (D) Disapproval of certification.--In the event that the Assistant Secretary disapproves a proposed certification under this paragraph, the Assistant Secretary shall inform the eligible entity of the basis for the disapproval. (E) Right to cure and appeal.-- (i) Right to cure.--An eligible entity the proposed certification of which was disapproved by the Assistant Secretary shall have 30 days to resubmit the proposed certification, during which period no adverse action shall be taken by the Assistant Secretary against the eligible entity on the basis of lacking a certification. (ii) Right to appeal.-- (I) In general.--An eligible entity described in clause (i) may appeal the disapproval to the Assistant Secretary. (II) Process.--The Assistant Secretary shall establish the manner and form in which appeals under this clause shall be heard and shall render a decision on any such appeal not later than 90 days after the date of the initiation of the appeal. (2) Effect of certification.--A certified telecommunications carrier or other eligible entity shall, in any Federal or State court, be entitled to an affirmative defense that approval of a certification under paragraph (1) constitutes due care or reasonableness for mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities, unless the telecommunications carrier or other eligible entity is found to have acted with gross negligence, willful misconduct, or have not materially implemented and maintained the Industry Best Practices consistent with the approved certification. (3) Timing; later change.--The defense under paragraph (2) shall apply if the eligible entity was certified and in compliance with the Industry Best Practices in effect at the time of the incident, notwithstanding-- (A) subsequent revisions to Industry Best Practices; or (B) subsequent expiration, subsequent suspension, or non-renewal of the certification. (4) Conflict preemption.--No State or political subdivision of a State may establish, maintain, prescribe, continue, or enforce any law, rule, regulation, or requirement imposing a duty, standard, requirement, or liability or enforcing standards for cybersecurity that are inconsistent with this Act with respect to a certified eligible entity. (c) Certification Requirements.--Each approved certification under subsection (b)(1) shall-- (1) be valid for a period of not more than 2 years; (2) be renewable through comprehensive reassessment; (3) include documentation of implementation and maintenance of the applicable Industry Best Practices at the time of certification; (4) require disclosure of any direct financial interest or material business relationship between the assessor and the entity being assessed; (5) include a description of the assessment methodology and criteria used; and (6) be subject to revocation by the Assistant Secretary if the assessor is found to have issued invalid or false certifications. (d) Whistleblower Protection.-- (1) In general.--No eligible cybersecurity assessor or telecommunications carrier with an approved or pending certification, or any officer, employee, contractor, subcontractor, or agent of such company, may discharge, demote, suspend, threaten, harass, or in any other manner discriminate against an employee in the terms and conditions of employment because of any lawful act done by the employee to provide information to, cause information to be provided to, or otherwise assist in an investigation by an agency, entity, or person described in paragraph (2), relating to any conduct that the employee reasonably believes reflects non-compliance with or gross misrepresentation relating to the certification standard established by the Working Group. (2) Agency, entity, or person described.--An agency, entity, or person described in this paragraph is-- (A) a Federal regulatory or law enforcement agency; (B) any Member of Congress or any committee of Congress; or (C) a person with supervisory authority over the employee (or such other person working for the employer who has the authority to investigate, discover, or terminate misconduct). (e) Routine Implementation and Maintenance Obligation.--A certified eligible entity shall routinely implement and maintain cybersecurity practices aligned with Industry Best Practices, as updated, during the period of certification. (f) Early Reassessment.-- (1) Authority.-- (A) In general.--Upon any of the grounds described in paragraph (2), the Assistant Secretary may direct an eligible cybersecurity assessor to conduct, or may on the Assistant Secretary's own initiative commission by an alternative eligible cybersecurity assessor, an early reassessment of a certified eligible entity and may, upon a written finding of credible evidence of material failure to implement or maintain the Industry Best Practices, suspend the approved certification of the eligible entity pending successful completion of the reassessment. (B) Responsibility for costs associated with assessment.--If an assessment conducted pursuant to subparagraph (A) determines that the eligible entity has materially failed to implement or maintain the Industry Best Practices, the eligible entity shall be responsible for all costs associated with performing the assessment. (2) Grounds for reassessment.--The grounds described in this paragraph include-- (A) a substantial revision to Industry Best Practices; (B) a telecommunications carrier or other eligible entity experiences a significant cyber-incident, as defined by Presidential Policy Directive-41 (July 26, 2016; relating to United States cyber incident coordination); and (C) the Assistant Secretary receives credible information that-- (i) any of the contents submitted to the Assistant Secretary under subsection (b)(1) to approve a certification were false or fraudulent; or (ii) an eligible entity has failed to routinely implement and maintain cybersecurity practices in accordance with subsection (e). (3) Good faith protection.--A certified telecommunications carrier or other eligible entity shall not have its certification under subsection (b) revoked solely due to an early reassessment under this subsection, unless and until the early reassessment produces a final determination that the eligible entity-- (A) materially failed to implement or maintain the Industry Best Practices the entity elected to adopt through the certification process; or (B) has engaged in gross negligence or willful misconduct. SEC. 6. REPORTING REQUIREMENTS. (a) Annual Report.--Not later than 1 year after the publication of any Industry Best Practices developed under section 4, and annually thereafter, the Assistant Secretary, in consultation with the Working Group, shall submit to the relevant congressional committees and publish a public version on the website of NTIA a report that includes-- (1) an overview of the development of Industry Best Practices, and any updates or modifications of Industry Best Practices; (2) data on participation of eligible entities in the certification process; (3) a summary of early reassessment activity, if any; (4) an assessment of the adoption of Industry Best Practices; and (5) the effectiveness of Industry Best Practices and certification in enhancing cybersecurity across the telecommunications sector. (b) Event-Triggered Report.--Not later than 90 days after a substantial revision to Industry Best Practices or a significant cyber- incident, as defined in Presidential Policy Directive-41 (July 26, 2016; relating to United States cyber incident coordination), affecting the telecommunications sector, the Assistant Secretary, in consultation with the Working Group, shall submit to Congress a report that includes, to the greatest extent practicable, the consensus views and recommendations of the Working Group to improve cybersecurity across the telecommunications sector. SEC. 7. RULES OF CONSTRUCTION. Nothing in this Act shall be construed to-- (1) grant any regulatory authority to any Federal agency; (2) expand or otherwise alter obligations or authorities under the Communications Act of 1934 (47 U.S.C. 151 et seq.), the Secure and Trusted Communications Networks Act of 2019 (47 U.S.C. 1601 et seq.), the Secure Equipment Act of 2021 (47 U.S.C. 1601 note), or any other Federal law; (3) prohibit the Working Group from consulting with or referencing the work product of Federal advisory committees subject to chapter 10 of title 5, United States Code, including the President's National Security Telecommunications Advisory Committee, CSRIC, and the Commission's Technological Advisory Council; (4) require adoption of Industry Best Practices or implementation guidance, or authorize any regulatory requirement of adoption; (5) displace or replace the functions of any Federal advisory council or information-sharing agreement; (6) grant regulatory authority to the Commission, or any other Federal body; or (7) authorize, expand, or imply any Federal authority to supervise, direct, mandate, regulate, audit, or otherwise oversee the cybersecurity operations, risk-management programs, technical controls, or network security practices of any telecommunications carrier or other eligible entity, except as expressly permitted for the development, publication, and voluntary certification of Industry Best Practices under this Act. SEC. 8. SEVERABILITY. If any provision of this Act, or its application to any person or circumstance, is held to be unconstitutional, the remainder of this Act, and the application of the provision to any other person or circumstance, shall not be affected. <all>
Related legislation
Bills by the same sponsor or covering overlapping subjects.
- S5586Ensuring Accurate Payments to Specialty Pharmacies ActReferred to Committee · 2026-09-29
- S5576Artificial Intelligence Risk Management and Security Act of 2026Referred to Committee · 2026-09-29
- S5499STOP TICKS ActReferred to Committee · 2026-09-24
- S5496Health CARE Act of 2026Referred to Committee · 2026-09-24