S. 5508: Telecommunications Cybersecurity and Resilience Act
This bill would create a federal public-private working group, housed within the National Telecommunications and Information Administration (NTIA), to develop voluntary cybersecurity best practices for telecommunications carriers and related companies in the telecom supply chain.
What the working group would do
The working group would include federal agencies such as NTIA, CISA, NIST, the Office of the National Cyber Director, NSA, the FCC, and industry representatives from carriers, equipment makers, software and cloud providers, state and local communications operators, cybersecurity experts, and other supply chain stakeholders.
Its main jobs would be to:
- develop cybersecurity best practices and implementation guidance;
- set criteria for independent third-party assessors who can review whether a company follows those best practices;
- provide technical feedback and guidance on how to apply the practices.
The group would have to meet within 120 days of enactment, adopt bylaws, and follow conflict-of-interest rules. It could hold closed sessions when discussing classified, sensitive, proprietary, or threat-related information.
Cybersecurity best practices
Within 18 months, the working group would develop and maintain a set of “Industry Best Practices” for telecom carriers and certain related entities. These would be voluntary, not mandatory. The practices would focus only on cybersecurity issues such as preventing, detecting, responding to, mitigating, and remediating incidents and vulnerabilities.
The bill says the best practices should be risk-based and aligned with existing federal frameworks, such as the NIST Cybersecurity Framework and other federal cybersecurity guidance, while avoiding duplication of existing requirements.
Examples of topics the practices could cover include:
- installing security updates on network devices when available;
- phasing out or mitigating devices that no longer receive manufacturer updates;
- maintaining baseline configurations and configuration management plans for hardware, software, and firmware;
- using multi-factor authentication and access controls;
- other practices the working group chooses to add.
The best practices would be updated at least every two years, and sooner if there is a major cyber incident or a significant change in threat conditions.
Voluntary certification program
The bill would create a voluntary certification process for telecom carriers and other eligible entities. Independent third-party assessors, approved under standards set by the working group and the Assistant Secretary of Commerce for Communications and Information, would evaluate whether a company is following the best practices.
A company could submit a proposed certification to the Assistant Secretary for approval. The certification would have to include the assessor’s report, the best practices used for the evaluation, and required conflict disclosures. The Assistant Secretary would decide within set deadlines whether to approve or reject it.
If approved, the certification would generally be valid for up to two years and could be renewed after a full reassessment.
Legal effects of certification
A certified company would be able to use the approved certification as an affirmative defense in federal or state court, unless it is shown to have acted with gross negligence, willful misconduct, or failed to materially follow the certified best practices.
For a company that was certified and following the applicable best practices at the time of an incident, the defense would still apply even if the best practices later changed or the certification later expired.
The bill would also prevent states and local governments from imposing cybersecurity rules that are inconsistent with the bill’s certification framework for a certified entity.
Oversight, reassessment, and whistleblower protections
The Assistant Secretary could order an early reassessment if there is a substantial update to the best practices, a significant cyber incident, or credible information that a certification was false or that the company is not maintaining the practices. If the reassessment shows material failure, the company could be responsible for the reassessment costs.
The bill also includes whistleblower protections for employees of assessors or certified companies who report suspected noncompliance or false statements related to the certification process.
Reporting to Congress
NTIA would have to report annually to Congress on the best practices, certification participation, reassessments, adoption levels, and how effective the program appears to be. It would also have to submit a report within 90 days after a substantial revision to the practices or a major telecommunications cyber incident.
Limits on federal authority
The bill repeatedly says it does not give new regulatory authority to federal agencies, does not require companies to adopt the best practices, and does not expand the FCC’s power to regulate cybersecurity. It frames the program as a voluntary coordination and certification system rather than a new regulatory mandate.
Relevant Companies
- T — AT&T may be affected as a major telecommunications carrier that could choose to adopt the best practices and seek certification.
- VZ — Verizon may be affected as a major telecommunications carrier that could choose to adopt the best practices and seek certification.
- TMUS — T-Mobile US may be affected as a major telecommunications carrier that could choose to adopt the best practices and seek certification.
- CSCO — Cisco may be affected as a supplier of networking equipment that could be subject to industry best practices used across the telecom supply chain.
- ANET — Arista Networks may be affected as a networking equipment provider serving communications and cloud-related infrastructure.
- FFIV — F5 may be affected through telecom-related network and security products that could be relevant to certification and best-practice adoption.
- ORCL — Oracle may be affected to the extent telecom operators use its cloud, software, or systems tools covered by the bill’s supply-chain stakeholder category.
- ACN — Accenture may be affected indirectly if telecom carriers hire outside firms for cybersecurity assessments, implementation, or compliance support.
This is an AI-generated summary of the bill text. There may be mistakes.
Sponsors
2 bill sponsors
Actions
2 actions
| Date | Action |
|---|---|
| Sep. 24, 2026 | Introduced in Senate |
| Sep. 24, 2026 | Read twice and referred to the Committee on Commerce, Science, and Transportation. |
Corporate Lobbying
0 companies lobbying
None found.
* Note that there can be significant delays in lobbying disclosures, and our data may be incomplete.