Communications Security Act
Click any stage to learn more about the legislative process.
Would give statutory authority to a Federal Communications Commission advisory council on communications security, directing the FCC to formally establish — or designate an existing advisory body as — a permanent council to recommend ways to improve the security, reliability, and interoperability of U.S. communications networks.
The bill would exempt the council from the federal rule that automatically terminates advisory committees after two years, and would bar representatives of foreign-adversary-linked entities from membership, giving the body a more durable and vetted legal footing than it currently has.
What this bill would do
What it would do
The bill would direct the Federal Communications Commission to formally establish a council — or designate an already-operating FCC advisory committee for that role — to advise the agency on the security, reliability, and interoperability of communications networks. The FCC Chair would appoint all members and would be required to include, to the extent practicable, representatives from the communications industry, public interest organizations or academic institutions, and federal, state, local, and tribal governments (with at least one member from each tier of government). Entities owned, controlled, or influenced by a foreign adversary, or otherwise deemed a national security threat, would be barred from membership. The council would submit biennial reports to the FCC Chair, and the FCC would post those reports publicly on its website.
The bill would not itself create a new substantive regulatory program; it codifies and stabilizes an advisory function the FCC already performs through the Communications Security, Reliability, and Interoperability Council. Critically, it would exempt the council from the provision of federal law that automatically terminates advisory committees after two years, allowing it to operate indefinitely without repeated renewals.
Key provisions
- 1Would require the FCC to establish a communications security advisory council, or designate an existing advisory committee, within 90 days of enactment.
- 2Would require council membership to include representatives of the communications industry, public interest or academic institutions, and federal, state, local, and tribal governments, with at least one member from each government tier.
- 3Would bar from membership any entity the FCC Chair determines is owned, controlled, or influenced by a foreign adversary, or otherwise poses a threat to U.S. national security.
- 4Would require the council to submit biennial reports to the FCC Chair and direct the FCC to post those reports publicly on its website.
- 5Would exempt the council from the federal advisory committee termination requirement that otherwise dissolves such bodies after two years.
Who would be affected
The FCC and its Chair, who would bear new statutory obligations to establish the council and vet members. Communications industry companies, public interest organizations, academic institutions, and representatives of federal, state, local, and tribal governments who would be eligible for — or barred from — council membership. Entities tied to foreign adversaries would be explicitly excluded from participation.
Why it matters
Without this statutory footing, the FCC's advisory council could lapse under the two-year automatic-termination rule each time its charter expires. Codifying its existence — and permanently banning foreign-adversary-linked entities from membership — would give the council more stable authority and a cleaner process for keeping national-security risks off a body that advises on critical communications infrastructure.
What would change
Changes to existing law
Amends 5 U.S.C. § 1013(a)(2) (Federal Advisory Committee Act termination provision) (Sec. 2(d))
Exempts the FCC communications security council from the two-year automatic termination requirement that applies to most federal advisory committees.
Amends Secure and Trusted Communications Networks Act of 2019 (47 U.S.C. 1601(c)) (Sec. 2(e)(4))
Incorporates its national-security criteria by reference as the standard the FCC Chair must use when determining whether an entity is 'not trusted' for membership purposes.
Amends Communications Act of 1934 (47 U.S.C. 153) (Sec. 2(e)(5))
Incorporates its definition of 'State' for use in this bill's membership provisions.
Agencies directed to act
Effective dates
- FCC must establish or designate the council within 90 days of enactment
Funding and costs
Congressional Budget Office estimate
CBO estimates that enacting H.R. 1717 would have no significant effect on the federal budget.
H.R. 1717 would require the FCC to formally establish the Communications Security, Reliability, and Interoperability Council (CSRIC) in statute. The CSRIC already exists and performs these duties under a charter that is renewed every two years; the current charter expires in March 2026. Because the bill would essentially codify an already-functioning body, CBO finds it would have no significant budgetary effect. CBO did not identify any intergovernmental or private-sector mandates in the bill.
How implementation would work
Within 90 days of enactment, the FCC Chair would establish a new council or formally designate an existing advisory committee, adjusting membership as needed to meet the bill's composition requirements. The Chair would appoint members on two-year terms, screening out entities deemed "not trusted" using criteria from the Secure and Trusted Communications Networks Act. Every two years, the council would submit to the Chair all reports and working-group outputs from the preceding period; the FCC would then post those reports on its public website. The council would have no automatic expiration date.
Legislative status & sources
Latest action
Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill provides statutory authority for a council established by the Federal Communications Commission (FCC) to provide advice regarding the security, reliability, and interoperability of communications networks. (This advice is currently provided by the FCC’s Communications Security, Reliability, and Interoperability Council.)
The bill specifies that the FCC may designate an existing advisory committee to fulfill this role, provided the committee’s membership is modified, as necessary, to comply with membership requirements set forth in the bill.
Specifically, the bill requires the council to include, to the extent practicable, representatives of companies in the communications industry; public interest organizations or academic institutions; and federal, state, tribal, and local governments (with at least one member representing each level of government). Members are to be selected by the FCC's chair and generally may not include representatives of entities owned or controlled by, or subject to the influence of, a foreign adversary, or otherwise deemed to pose a threat to U.S. national security.
Under current law, federal advisory committees must generally terminate after two years unless they are renewed or a statute specifies a different termination date. However, the bill exempts the council from this requirement.
Legislative subjects
Broadcasting, cable, digital technologies; Computer security and identity theft; Congressional oversight; Executive agency funding and structure; Federal Communications Commission (FCC); Government studies and investigations; Internet, web applications, social media; Public-private cooperation; Science, Technology, Communications; State and local government operations; Telephone and wireless communication
Committee report
H. Rept. 119-194