US Senate advances telecom cybersecurity bill
A bipartisan Senate bill would create a voluntary certification system for telecom vendors and a working group at NTIA.
The U.S. Senate advanced S.5529 to strengthen telecom cybersecurity through a voluntary certification system for providers and suppliers that meet security standards. Introduced by Senator Thomas Tillis and sent the same day to the Senate Judiciary Committee, the measure also calls for a NTIA working group to define risk-based best practices.
The U.S. Senate introduced S.5529 to strengthen telecom cybersecurity through a voluntary certification framework for providers and suppliers that meet security standards. Senator Thomas Tillis introduced the bill, and it was referred the same day to the Senate Judiciary Committee, according to the congressional record.
What does the bill propose for telecoms?
The Telecommunications Cybersecurity and Resilience Act would create a voluntary framework allowing providers and suppliers to seek certification if they meet security standards. According to CyberScoop, the certification would be optional and handled by independent outside evaluators.
Nextgov linked the proposal to the debate opened after the Salt Typhoon espionage campaign and to the FCC's rollback of certain safeguards adopted in response to that incident. In that context, the measure appears aimed at setting minimum security criteria for a sector that came under pressure after those events.
How would the best-practice framework work?
The text calls for a working group within the National Telecommunications and Information Administration, made up of providers, suppliers, cybersecurity experts, and public agencies. Its task would be to develop specific, risk-based best practices for telecoms, according to the Senate Commerce Committee's official statement.
That same statement says the best practices should be reviewed and updated at least every two years. They would also need to be revisited after major cyber incidents or significant changes in the threat landscape.
Nextgov adds that the NTIA working group should develop the first best practices within 18 months of enactment. That deadline does not appear in the available approved material, but it is part of the framework described in the reporting.
What would the certification cover?
The certification would be voluntary and limited to identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities, according to CyberScoop. The available material does not include a general requirement to adopt the certification, nor any sanctions tied to failing to obtain it.
Law360 described the bill as a bipartisan Senate measure aimed at strengthening telecom cybersecurity through a voluntary certification system for providers and suppliers. S.5529 was formally introduced and referred to the Judiciary Committee in the same action.
Sources
- Biotech: US House and Senate propose 2 bills for CISA to step up the protection of biotechnology infrastructuredig.watch· Digital Watch Observatory
- S.5529 - 119th Congress (2025-2026)congress.gov· U.S. CongressUnverified URL
- House and Senate members propose legislation for CISA to step up cyber defenses for biotechcyberscoop.com· CyberScoop
- Cybersecurity & Privacy Newslaw360.com· Law360
- Cruz, Warner Introduce Bipartisan Bill to Strengthen Telecommunications Cybersecuritycommerce.senate.gov· U.S. Senate Committee on Commerce, Science, and Transportation
- Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hackscyberscoop.com· CyberScoop
- Senators propose voluntary telecom security framework after Salt Typhoon hacksnextgov.com· Nextgov



