
Warner-Cruz bill creates NTIA voluntary telecom practices after mandatory rules scrapped
Bipartisan legislation shifts telecom cybersecurity to voluntary NTIA-led standards after mandatory requirements were eliminated. Evidence from Salt Typhoon shows persistent gaps in basic controls that binding rules aimed to close. Adoption and enforcement mechanisms remain untested.
The bill tasks the NTIA working group with telecom-specific practices updated every two years and an optional certification process. This follows the 2024 rescission of Biden-era mandates that required annual cybersecurity risk management plans and attestations. Biden administration assessments stated that secure configurations, timely patching, behavioral monitoring, and MFA on admin accounts would have raised adversary costs substantially.
Procurement and lobbying records show carriers opposed binding rules through trade associations while accepting post-incident funding for upgrades. Technical indicators from the intrusions—lateral movement via unpatched edge devices and weak admin credential hygiene—align with patterns in earlier PRC operations documented in CISA alerts and Mandiant reporting. No independent verification of full remediation at all nine affected carriers has been released.
The voluntary framework risks repeating the pattern where compliance stays low absent penalties. Congressional reporting requirements offer limited visibility unless tied to contract awards or spectrum licenses. Next steps hinge on whether NTIA incorporates existing NIST and CISA controls or creates duplicative guidance that industry can selectively adopt.
NTIA: Draft best practices released by December 2025 with fewer than 30% of Tier-1 carriers obtaining certification within 24 months of final publication.
Sources (3)
- [1]Primary Source(https://therecord.media/lawmakers-introduce-bill-for-voluntary-telecom-cyber-rules)
- [2]Supporting Source(https://www.cisa.gov/news/2024/10/25/cisa-and-fbi-release-advisory-salt-typhoon)
- [3]Supporting Source(https://www.fcc.gov/document/fcc-acts-after-salt-typhoon-breach)