A federal watchdog has concluded that the Federal Communications Commission’s rollback of mandatory cybersecurity expectations for telecommunications carriers is a rule that must be submitted to Congress. The finding does not immediately impose new duties on AT&T, T-Mobile, Verizon or smaller providers, but it challenges the procedural footing of the FCC’s decision to favor voluntary cooperation over an enforceable, industrywide standard.
In a July 29 legal decision, the U.S. Government Accountability Office said the FCC’s November 2025 cybersecurity order is subject to the Congressional Review Act. That law generally requires an agency to send a rule to both chambers of Congress and the comptroller general before it can take effect. Congress then has a defined process for considering a resolution to overturn it.
The dispute concerns how carriers secure the systems used to route calls and handle call-identifying information. It grew out of the Salt Typhoon intrusions, in which hackers linked to China penetrated U.S. telecommunications networks. The incident exposed the stakes behind what might otherwise look like a narrow argument over administrative procedure: weak access controls, delayed security patches or poorly protected network-management systems can put customers’ communications and account information at risk.
What the FCC removed
In January 2025, the FCC interpreted Section 105 of the Communications Assistance for Law Enforcement Act, or CALEA, as requiring telecommunications carriers to protect their networks against unauthorized interception and access. The agency said carriers would be unlikely to meet that obligation without basic measures such as role-based access controls, stronger passwords, multifactor authentication and timely patching of known vulnerabilities. It also proposed a broader rulemaking on carrier cybersecurity practices.
The commission reversed course in November 2025. In its order on reconsideration, the FCC said the earlier interpretation stretched CALEA beyond its text and attempted to create vague, enforceable obligations without first adopting formal rules. It rescinded both the declaratory ruling and the related proposal.
The FCC argued that direct coordination with providers had produced more useful results. According to the order, carriers agreed to accelerate patching, review access controls and remote-access configurations, disable unnecessary outbound connections, improve threat hunting and share more security information with the government and one another. Those descriptions largely reflect commitments and representations from the industry, however, rather than a common public standard customers can use to compare carriers.
Why GAO classified the rollback as a rule
The FCC maintained that its reversal was an adjudicatory order, not a rule covered by the Congressional Review Act. GAO disagreed. Its decision says the order did more than settle an individual dispute: it rescinded requirements that applied across the telecommunications industry, changed the FCC’s interpretation of CALEA and announced how the agency intended to handle carrier cybersecurity oversight going forward.
GAO also rejected the idea that the order concerned only the FCC’s internal organization or procedures. By extinguishing across-the-board obligations and changing the compliance position of regulated carriers, the rollback affected parties outside the agency. That made it the kind of policy action Congress intended to review, GAO concluded.
The finding is procedurally important, but its immediate effect is limited. GAO does not say that the January 2025 interpretation has automatically returned, nor does it decide that any carrier has violated a cybersecurity obligation. It also does not resolve whether a court would invalidate or suspend the rollback. The decision establishes GAO’s view that the FCC must follow the Congressional Review Act’s submission requirements.
If the order is submitted, Congress could leave it in place or pursue a resolution of disapproval under the act. Submission would also create a clearer public record of when the congressional review process began. Until the FCC, Congress or a court addresses the consequences, the status of the rollback carries a measure of legal uncertainty.
Practical impact for wireless customers
Customers should not expect an immediate plan change, bill credit or coverage improvement from the GAO decision. Its significance is accountability: whether carrier network-security practices remain primarily voluntary or become enforceable through a legally durable FCC rulemaking.
Consumers cannot audit a carrier’s internal patching or access controls, so ordinary plan comparisons offer little protection against a network-level intrusion. Account safeguards such as a strong password, multifactor authentication and a carrier port-out lock can still reduce account-takeover risk, but they cannot repair weaknesses inside the carrier’s network. The useful question now is whether the FCC formally submits its rollback and replaces the abandoned approach with specific, enforceable protections rather than commitments that customers have no practical way to verify.
Sources
- U.S. Government Accountability Office: Federal Communications Commission—Applicability of the Congressional Review Act to Order on Reconsideration in Protecting the Nation's Communications Systems from Cybersecurity Threats
- Federal Communications Commission: Protecting the Nation’s Communications Systems from Cybersecurity Threats, Order on Reconsideration (FCC 25-81)