U.S. Senators Mark Warner and Ted Cruz have introduced the Telecommunications Cybersecurity and Resilience Act, a bipartisan bill that would establish a voluntary framework for strengthening telecommunications cybersecurity across the sector.
The legislation would bring telecom providers, equipment suppliers, cybersecurity specialists and government agencies together to develop risk-based cybersecurity practices tailored to telecommunications networks. It also proposes an independent certification process that would allow organisations to demonstrate their adoption of the recommended practices.
The bill follows the disclosure of the Salt Typhoon cyber intrusions, which compromised telecommunications networks in the United States and other markets. The proposed framework is intended to improve network resilience by encouraging operators and other industry participants to adopt practices designed specifically around telecom infrastructure and evolving cyber risks.
Bill Proposes Telecom-Specific Cybersecurity Framework
The Telecommunications Cybersecurity and Resilience Act would establish a telecommunications cybersecurity working group made up of providers, suppliers, cybersecurity experts and relevant state, local and federal agencies.
The group would be responsible for developing practical and risk-based cybersecurity best practices for the telecommunications sector. The approach would focus on measures that can be applied to the specific operating conditions and security requirements of communications networks.
The legislation does not propose mandatory federal cybersecurity requirements. Instead, it would create a voluntary structure through which industry participants could adopt sector-specific practices developed through cooperation between government and private-sector experts.
This structure is intended to give telecom companies a framework for improving telecommunications cybersecurity without imposing fixed requirements that could become outdated as technology and cyber threats evolve.
The bill also seeks to connect adoption of these practices with an independent verification mechanism. Under the proposal, organisations would be able to undergo assessment by independent third parties and receive certification for meeting the established cybersecurity practices.
Certification and Regular Updates Proposed
The voluntary certification process would provide a mechanism for demonstrating that an organisation has implemented the recommended telecommunications cybersecurity practices. The legislation would therefore link the proposed framework to an external assessment process rather than relying only on companies to self-report their compliance.
The bill would also require the cybersecurity practices to be reviewed and updated at least every two years. Additional reviews would be required following major cyber incidents or significant changes in the threat environment.
This update mechanism is designed to keep the framework aligned with emerging security risks and changes in telecommunications infrastructure. It also recognises that network technologies and attack methods can change over time, requiring cybersecurity practices to be revised accordingly.
For telecom operators, suppliers and other industry participants, the proposal would create a common voluntary framework for addressing telecommunications cybersecurity while allowing companies to demonstrate their adoption through independent certification.
The legislation remains a bill introduced in the U.S. Senate. Any framework, certification process or cybersecurity practices described in the proposal would depend on the legislative process and subsequent implementation.



















