U.S. Senate backs telecom cybersecurity bills
The Senate advanced bipartisan telecom bills on voluntary certification and an NTIA working group to set cybersecurity best practices.
The U.S. Senate introduced S.5529 to strengthen telecom cybersecurity through a voluntary certification program for providers and suppliers that meet security standards. The bill was introduced by Sen. Thomas Tillis and referred the same day to the Senate Judiciary Committee, according to the congressional record.
Update September 30, 2026: The Senate added another telecom bill, S.5508, introduced by Mark Warner and referred on September 24, 2026, to the Committee on Commerce, Science, and Transportation. It proposes a public-private working group to develop cybersecurity best practices for operators and their supply chain participants.
The U.S. Senate introduced S.5529 to strengthen telecom cybersecurity through a voluntary certification program for providers and suppliers that meet security standards. The bill was introduced by Sen. Thomas Tillis and referred the same day to the Senate Judiciary Committee, according to the congressional record.
What does the telecom bill propose?
The Telecommunications Cybersecurity and Resilience Act would create a voluntary framework for providers and suppliers to certify compliance with security standards. According to CyberScoop, the certification would be optional and handled by outside independent assessors.
Nextgov tied the proposal to the debate that followed the Salt Typhoon espionage campaign and the FCC’s rollback of certain safeguards adopted in response to that incident. In that context, the measure appears aimed at setting minimum security criteria for a sector that came under pressure after those events.
How would the best-practices scheme work?
The text calls for a working group inside the National Telecommunications and Information Administration, made up of providers, suppliers, cybersecurity experts and public agencies. Its task would be to develop telecom-specific, risk-based best practices, according to the Senate Commerce Committee’s official statement.
That same statement says the best practices should be reviewed and updated at least every two years. They would also need to be revisited after major cyber incidents or significant changes in the threat landscape.
Nextgov adds that the NTIA working group would need to develop the first set of best practices within 18 months of enactment. That deadline does not appear as approved in the material available, but it is part of the architecture described in the reporting.
What would the certification cover?
The certification would be voluntary and limited to identifying, responding to, mitigating, preventing and remediating cybersecurity incidents and vulnerabilities, according to CyberScoop. The material available does not include a general adoption mandate or a penalty regime tied to failing to certify.
Law360 summarized the measure as a bipartisan Senate bill aimed at strengthening telecom cybersecurity through a voluntary certification system for providers and suppliers. S.5529 was formally introduced and sent to the Judiciary Committee at the same time.
What changes with S.5508?
S.5508 broadens the Senate debate by proposing a public-private working group to develop cybersecurity best practices for telecom operators and participants in their supply chains. According to Congress.gov, it was introduced by Sen. Mark Warner and referred on September 24, 2026, to the Committee on Commerce, Science, and Transportation.
That new text does not replace S.5529, but it adds another legislative track for the same sector. While the first bill focuses on voluntary certification, S.5508 centers on best-practice development by a group with public and private participation.
Congress.gov identifies S.5508 as a bill to establish a public-private working group that would develop cybersecurity best practices for telecom carriers and related supply chain actors.
Sources
- US Telecom Cyber Security Bill’s Completely Voluntaryinsidetelecom.com· Inside Telecom
- Cybersecurity & Privacy news coveragelaw360.com· Law360
- S.5522 - A bill to amend the Homeland Security Act of 2002 to require CISA to protect genetic and other sensitive biometric datacongress.gov· Congress.govUnverified URL
- S.5541 - A bill to establish the Cybersecurity and AI Board of Investigationscongress.gov· Congress.govUnverified URL
- S.5508 - A bill to establish a public-private working group to develop cybersecurity best practices for telecommunications carriers and related supply chain participantscongress.gov· Congress.govUnverified URL
- Biotech: US House and Senate propose 2 bills for CISA to step up the protection of biotechnology infrastructuredig.watch· Digital Watch Observatory
- S.5529 - 119th Congress (2025-2026)congress.gov· U.S. CongressUnverified URL
- House and Senate members propose legislation for CISA to step up cyber defenses for biotechcyberscoop.com· CyberScoop
- Cybersecurity & Privacy Newslaw360.com· Law360
- Cruz, Warner Introduce Bipartisan Bill to Strengthen Telecommunications Cybersecuritycommerce.senate.gov· U.S. Senate Committee on Commerce, Science, and Transportation
- Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hackscyberscoop.com· CyberScoop
- Senators propose voluntary telecom security framework after Salt Typhoon hacksnextgov.com· Nextgov
- H.R.10568 - Protecting Biological Data as Critical Infrastructure Actcongress.gov· Congress.govUnverified URL



