HR 1709 · 119th Congress

Understanding Cybersecurity of Mobile Networks Act

mobile network securitycybersecuritysurveillancetelecommunicationsconsumer privacy
Share

Last action 2025-07-15

Sponsored by Rep. Landsman, Greg [D-OH-1] (D) — OH

Click any stage to learn more about the legislative process.

Would require the head of the National Telecommunications and Information Administration to deliver a report to Congress within one year examining cybersecurity vulnerabilities in mobile service networks — covering encryption gaps, carrier security practices, and adversary use of cell-site simulators. Notably, the bill explicitly excludes 5G networks from the review's scope, focusing analysis on older mobile systems where known real-world vulnerabilities persist.

What this bill would do

What it would do

The bill would direct the Assistant Secretary of Commerce for Communications and Information to submit a report to Congress within one year of enactment examining the cybersecurity of mobile service networks. The report would assess how well mobile carriers have addressed known vulnerabilities, estimate the prevalence and effectiveness of encryption and authentication techniques used in mobile services and devices, analyze barriers to adopting stronger security practices, and assess how commonly adversaries use cell-site simulators (also known as IMSI catchers) and similar interception tools in the United States.

The bill explicitly limits the report's scope to non-5G mobile networks and restricts the vulnerability assessment to flaws that have been exploited or are feasibly exploitable in real-world conditions. The report must be produced in unclassified form, though a classified annex is permitted. A version redacted of potentially exploitable technical details would be made available publicly, while the full unredacted report would go only to the relevant House and Senate committees.

Key provisions

  1. 1Would direct the Assistant Secretary of Commerce for Communications and Information to submit a cybersecurity report on mobile service networks to Congress within one year of enactment.Sec. 2(a)
  2. 2Would require the report to assess how well mobile service providers have addressed known cybersecurity vulnerabilities identified by researchers and federal agencies.Sec. 2(b)(1)
  3. 3Would require the report to estimate the prevalence and effectiveness of encryption and authentication techniques used in mobile services, devices, operating systems, and applications.Sec. 2(b)(4)
  4. 4Would require the report to estimate the prevalence, costs, and adversary use of cell-site simulators (IMSI catchers) and other mobile surveillance and interception technologies in the United States.Sec. 2(b)(7)
  5. 5Would limit the report's scope to non-5G mobile networks and restrict the vulnerability assessment to flaws exploited or feasibly exploitable in real-world conditions.Sec. 2(d)
  6. 6Would require the report to be produced in unclassified form — with potentially exploitable details redacted in the public version — while providing the full unredacted report to the relevant congressional committees.Sec. 2(e)

Who would be affected

Mobile service providers — including small and rural carriers — device and equipment manufacturers, mobile operating system developers, and app makers would all be subjects of the report's assessment. Federal agencies including DHS, NIST, FCC, and the intelligence community would be consulted. Consumers, businesses, and government agencies that use mobile services are the ultimate population whose security the report would evaluate.

Why it matters

If enacted, Congress and the public would receive a first-of-its-kind baseline assessment of how well the mobile industry has secured its networks against surveillance and cyberattacks. Findings on carrier practices, encryption weaknesses, and adversary use of IMSI catchers could lay the groundwork for future legislation, FCC rulemaking, or changes to industry security standards — particularly for the older mobile protocols currently outside the 5G upgrade cycle.

What would change

Agencies directed to act

National Telecommunications and Information AdministrationDepartment of Homeland SecurityCybersecurity and Infrastructure Security AgencyScience and Technology Directorate of the Department of Homeland SecurityNational Institute of Standards and TechnologyFederal Communications CommissionDepartment of State

Effective dates

  • Deadline for submitting the mobile network cybersecurity report to CongressSec. 2(a)Within 1 year of enactment

Funding and costs

Congressional Budget Office estimate

CBO estimates that implementing H.R. 1709 would cost less than $500,000, subject to appropriations, with no effect on direct spending, revenues, or the deficit over the 2025–2035 period.

CBO estimates that H.R. 1709 would have no effect on direct (mandatory) spending, revenues, or the federal deficit over the 2025–2035 scoring window. The bill would require the Department of Commerce to assess cybersecurity practices of mobile communications providers and report to Congress on mobile network and device vulnerabilities; implementing those requirements would cost less than $500,000 in discretionary spending (funds that depend on future congressional appropriations). CBO found no intergovernmental or private-sector mandates in the bill.

View the full CBO cost estimate

How implementation would work

The Assistant Secretary must complete the report within one year, consulting a broad set of stakeholders: federal agencies (FCC, NIST, CISA, DHS Science and Technology Directorate, and the intelligence community), academic and independent researchers, international standards bodies such as the 3GPP and IETF, mobile carriers, device and equipment manufacturers, and software developers. The vulnerability assessment is limited to real-world or feasibly exploitable flaws. Two versions of the report must be produced — a redacted public unclassified version and a full unredacted version delivered only to the named congressional committees; a classified annex is permitted.

Legislative status & sources

Latest action

Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.

2025-07-15

Official CRS summary

Show the CRS summary

This bill requires the National Telecommunications and Information Administration to examine and report on the cybersecurity of mobile service networks and the vulnerability of these networks and mobile devices to cyberattacks and surveillance conducted by adversaries.

The report must include, among other items, (1) an assessment of the degree to which mobile service providers have addressed certain cybersecurity vulnerabilities; (2) a discussion of the degree to which these providers have implemented cybersecurity best practices and risk assessment frameworks; and (3) an estimate of the prevalence and efficacy of encryption and authentication algorithms and techniques.

From the Congressional Research Service.

Legislative subjects

Computer security and identity theft; Congressional oversight; Consumer affairs; Homeland security; Science, Technology, Communications; Telephone and wireless communication

Committee report

H. Rept. 119-177

Congressional Bill

Ask GovernmentReporter about this bill

Ask anything about this bill. The AI can look up referenced laws and statutes to provide context.

HR 1709: Understanding Cybersecurity of Mobile Networks Act | Legislation Reporter