Security3 publishers2 min readPublished Updated
Warner and Cruz's Salt Typhoon bill keeps telecom security voluntary for carriers
Sens. Mark Warner and Ted Cruz filed a bill giving NTIA 18 months to write voluntary telecom security practices, with an optional third-party certification. Adopting them stays each carrier's choice, nearly a year after the mandatory post-breach rules were scrapped.
The Watch · Security desk

What happened
- Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday in response to the Salt Typhoon intrusions.
- The bill sets up a working group inside NTIA, made up of carriers, suppliers, security experts and federal officials, to write voluntary best practices for the telecom sector.
- Nearly a year earlier, Republican officials scrapped post-Salt Typhoon rules that would have required carriers to secure their networks and certify a risk management plan every year.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Federal officials say Salt Typhoon is still a threat. During the drafting window and after it, each carrier's defenses against the group are whatever that carrier chooses to deploy.
- contradiction When the mandatory rules were scrapped, Warner warned that voluntary codes with no penalties would let the Chinese government keep hacking unabated. The bill he now co-sponsors is voluntary.
- decision Enforcement falls to enterprise and government buyers of carrier service. Any buyer that wants proof a carrier follows the practices will have to ask it for the certificate.
The controls that would have raised Salt Typhoon's costs are already written down, and carriers can deploy them today. Biden administration officials reported that the campaign would have been "far riskier, harder and costlier for the Chinese" if carriers had kept minimum practices: secure configurations, up-to-date patching, network architecture that monitors for anomalous behavior, and multi-factor authentication on administrator accounts [12].
The campaign ran for years. Chinese government-backed hackers held access to at least nine US carriers, including Verizon, AT&T and Lumen [9]. They took call detail records, which show whom a person spoke to, when, for how long and where they were. In some cases they intercepted audio and text [10]. According to The Record, the hackers reportedly focused on 150 high-profile targets, including President Donald Trump and Vice President JD Vance [11].
Salt Typhoon became public nearly two years ago [21]. The bill's clock starts only at enactment. The working group would have 18 months from passage to publish its practices [3], then review them every two years or after a major incident [4]. If the group uses its full window, the first scheduled revision lands 42 months after the bill becomes law [18]. According to the legislative text CyberScoop quoted, the practices would "focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities" and follow existing federal risk management frameworks [16]. The group would also report to Congress each year [17].
Both sponsors leave adoption to the carriers. "If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient," Warner said [14]. He also said: "This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day" [19]. Cruz chairs the Senate Commerce panel. Warner is the top Democrat on the Intelligence Committee [20]. "This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated," Cruz said [15].
The certification is the one output an outsider could check. An independent assessor would certify that a company had implemented and maintained the practices, but only for companies that choose to seek it [5]. Published descriptions of the bill include no penalty for a carrier that turns down the practices or the assessment [1].
What to watch
- Whether the Senate Commerce panel Cruz chairs moves the bill, and whether amendments tie the certification to federal procurement or add penalties.
- Whether any breached carrier, including Verizon, AT&T or Lumen, commits to seeking the third-party certification once the practices exist.
- New federal advisories on Salt Typhoon activity inside US carrier networks during the 18-month drafting window.