Two years after Salt Typhoon burrowed into the core of American telecommunications, Washington still has not settled on how to secure the sector against a repeat. The Federal Communications Commission tried a mandate in January 2025, reversed it in November, and this week two senators introduced a bill that returns to the same voluntary model the FCC just abandoned. The pattern is not new to CyberTech readers. It is the same enforcement gap this desk documented in a Department of Homeland Security inspector general report on federal cloud security mandates, where 86 percent of agencies missed a binding deadline with no consequence. Telecom cybersecurity policy is now on its third attempt at the same unresolved question: what happens when a security requirement has no teeth.

What Salt Typhoon actually did

Salt Typhoon is the industry name for a People’s Republic of China state-sponsored campaign that the Cybersecurity and Infrastructure Security Agency, the FBI, the National Security Agency and international partners detailed in a joint advisory. The campaign targeted the backbone of telecommunications networks directly: provider-edge and customer-edge routers, the equipment that sits at the boundary between a carrier’s network and its customers. According to the advisory, the actors modified router firmware to establish network access that persisted across reboots and configuration changes, the kind of foothold that is difficult to evict without replacing hardware. The advisory urges network defenders to hunt for that activity and apply the mitigations it outlines, guidance aimed squarely at telecom security teams rather than end users.

The campaign’s reach became public in 2024, when reporting tied it to intrusions at major U.S. carriers and interception of communications tied to senior government officials. It remains, in Senator Mark Warner’s words, a watershed event for the sector, and it is the direct trigger for every policy move described below.

Media Partner

Web3 x AI Fusion — Media Partner

Washington tried a mandate, then reversed it

The first policy response was a mandate. On January 16, 2025, in the final days of the prior administration, the FCC issued a declaratory ruling holding that Section 105 of the Communications Assistance for Law Enforcement Act (CALEA) affirmatively required telecom carriers to secure their networks against unlawful access. A companion rulemaking proposal would have required carriers to create formal cybersecurity risk-management plans and certify annually to the FCC that they were following them, turning network security from a best practice into a standing legal obligation with a paper trail regulators could audit.

That ruling did not survive the year. On November 20, 2025, the FCC voted 2 to 1 to rescind it. Chairman Brendan Carr’s order called the prior ruling an unlawful and ineffective reading of CALEA, and the agency’s own announcement framed the reversal as correcting course toward “effective and agile cybersecurity responsiveness.” In its place, the FCC pointed to a narrower set of targeted actions taken since January: a new agency Council on National Security to coordinate with national security partners, a requirement that submarine cable licensees maintain cybersecurity risk-management plans, and a rule barring untrustworthy testing labs from its equipment authorization program. None of those measures apply broadly to the wireless and wireline carrier networks Salt Typhoon actually compromised. Commissioner Anna Gomez dissented from the rescission. The FCC’s own announcement said the reversal followed “months-long engagement with communications service providers where they have demonstrated a strengthened cybersecurity posture following Salt Typhoon,” crediting industry’s own efforts rather than the certification requirement for whatever improvement had occurred, and quoted providers as having agreed to “extensive, urgent, and coordinated efforts to mitigate operational risks, protect consumers, and preserve national security interests.”

That is the part of the record a security leader should sit with. The agency that regulates the sector concluded, on its own timeline, that a binding annual certification was not the right tool, and unwound it in under eleven months without replacing it with an equivalent obligation. The stated rationale, that a rigid rule cannot keep pace with an evolving threat, is a real tradeoff in security regulation generally. It is also the same rationale Congress is about to write into a new bill, one more time.

The new bill offers a third voluntary track

On September 24, Senate Commerce Committee Chairman Ted Cruz and Senator Warner introduced the Telecommunications Cybersecurity and Resilience Act. Its mechanics, according to the committee’s own announcement, are a working group of carriers, equipment suppliers, cybersecurity experts and government agencies, convened to write risk-based best practices specific to telecom. Adoption would run through a voluntary certification process, with independent third-party assessment providing what the announcement calls “real accountability,” and the practices would be revisited at least every two years or after a major incident.

Cruz framed the design choice explicitly as a rejection of the approach the FCC had just discarded: “Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats. This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated. As Commerce Committee chairman, I will continue working to strengthen the networks Americans rely on while preserving the innovation needed to protect them.”

Warner, who sits atop the Senate Intelligence Committee and has direct visibility into the classified damage assessment of Salt Typhoon, did not dispute the voluntary framing but was blunter about the stakes: “The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way. If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

Both senators are describing the same design: a working group writes standards, a third party certifies who follows them, and nothing in the bill’s own summary compels a carrier to participate. That is a materially different structure from the certification-to-the-regulator model the FCC just abandoned, and it lands in territory the National Telecommunications and Information Administration already knows well. NTIA has run voluntary, multistakeholder security processes before, most recently a vulnerability-disclosure initiative it wrapped up by thanking participants for reaching consensus principles that, as the agency’s own account of the process put it, reflected the fact that “there is no one-size-fits-all solution.” That is a reasonable way to build a disclosure norm among willing participants who showed up because they wanted to. It is a different exercise from compelling a market of carriers, several of them not eager to absorb new compliance costs during a period of heavy AI-infrastructure capital spending, to actually adopt a standard that costs money and can slow deployment.

There is a structural reason voluntary frameworks tend to underperform in telecom specifically, and it is the same one this desk’s reporting on CISA’s own patch-adoption gap surfaced for enterprise vulnerability management: the organizations with the weakest security posture and the least budget to fix it are also the ones with the least incentive to volunteer for a program that will document exactly how far behind they are. A carrier already meeting the bar has every reason to seek certification as a market differentiator. A carrier that is not has every reason to wait for the next working-group cycle.

What this means for the security leader

None of this changes what a telecom security team, or a security team dependent on telecom infrastructure, should already be doing under the CISA advisory: hunting for the specific router-firmware persistence techniques Salt Typhoon used, and treating provider-edge and customer-edge equipment as a priority asset class rather than a boundary someone else manages. What it should change is how much weight a CISO or a board places on the existence of a federal cybersecurity framework, voluntary or not, as a substitute for that direct work. CISA’s own binding order for federal cloud security, Binding Operational Directive 25-01, has enforcement teeth on paper and an 86 percent non-compliance rate in practice, because a directive without funded follow-up audits and consequences is a document, not a control. A voluntary certification framework carries less enforcement weight than that binding directive did, not more, and it is being proposed for a sector that just watched its one actual mandate get repealed within a year.

The practical read for any organization whose operations depend on carrier networks, which is to say nearly every organization, is that “the telecom sector is now covered by federal cybersecurity requirements” will not be an accurate sentence for at least the 18 months the bill sets aside for the working group to write its practices, and it may never become one if certification stays voluntary and adoption stays uneven. Security leaders who build vendor-risk assessments or business continuity plans around telecom providers should treat carrier cybersecurity posture as something to verify directly, through contract language, incident-notification clauses and direct questions about Salt Typhoon remediation status, rather than assume regulation is closing that gap on their behalf.

What defenders should do now

Three actions follow directly from the record. First, apply the CISA, FBI and NSA joint advisory’s hunting guidance for Salt Typhoon indicators against any provider-edge or customer-edge equipment your organization operates directly, rather than assuming it is exclusively a carrier problem. Second, if your organization negotiates contracts with telecom carriers, add explicit cybersecurity attestation and incident-notification requirements now, since federal certification will not backfill that language for years, if it arrives at all. Third, track the Telecommunications Cybersecurity and Resilience Act’s working group appointments and its 18-month deadline the way this desk already tracks CISA’s Known Exploited Vulnerabilities catalog deadlines: as a date to verify against actual outcomes, not a date to assume solves the problem on its own.

Source: U.S. Senate Committee on Commerce, Science, and Transportation