Cybersecurity Policy Report, FCC Hears Mixed Views on Undersea Cable Cyber Rules, (Apr 16, 2025)
Organizations Mentioned:Incompas | National Institute of Standards & Technology | Telecommunications Industry Association | United States Telecommunications, Inc.
By Jeff Williams
The FCC garnered general praise for conducting its first comprehensive review of its undersea cable rules since 2001, but several groups and companies raised concerns that some of the Commission’s proposals, including those related to physical and data security, would add unnecessary uncertainty and complexity without corresponding benefits.
Adopted unanimously last fall in OI docket 24-523 and MD docket 24-524 (TR Daily, Nov. 21, 2024), the notice of proposed rulemaking sought input on, among other things, the use in undersea cable networks of equipment or services from the FCC’s “covered list” of untrustworthy foreign suppliers.
NCTA told the FCC that “many of the proposals in the Notice go beyond what is necessary to achieve the Commission’s objectives and impose unnecessary burdens that will hinder the deployment of network facilities without a corresponding security improvement.”
The trade group asked the FCC not to adopt new cybersecurity regulations for submarine cable licensees, but if the Commission does adopt new requirements, “it should limit the scope of any such requirements to cable license holders and maintain its policy to give applicants and licensees the flexibility to implement cybersecurity practices that best meet the needs of their customers and businesses.”
CTIA said any updates to the rules “should support a robust market of trusted providers” and suggested that “[h]armonization and streamlining” the regime would “support national security and trusted subsea investment.”
To that end, the Commission should, among other things, “clarify the relationship” between its licensing requirements and those of the Committee for the Assessment of Foreign Participation in the United States Telecommunications Sector (also known as Team Telecom), CTIA said.
The Commission should also “not independently adopt mandates related to the Covered List without explicit direction from Congress,” the group said.
Incompas said that “regulatory requirements that have unintended national security threats as a consequence must not be implemented,” including requiring applicants to disclose “precise” cable landing locations, which could “increase risks of sabotage and could lead other countries to create reciprocal requirements.”
The “most efficient” way to address national security concerns regarding submarine cables “would be for the Commission to provide a list of adversary countries with a rebuttable presumption that new submarine cables landing in the United States cannot directly connect with those countries nor can companies directly or indirectly owned by those adversary companies own or control new submarine cables that land in the United States,” Incompas said.
U.S. Telecom said the NPRM would “impose significant burdens” on submarine cable applicants and licensees that would provide “little corresponding benefit” and “could cause unintended consequences.”
The “best strategy” is an “outcome-oriented and adaptable approach grounded in the broadly utilized National Institute of Standards & Technology (‘NIST’) Cybersecurity Framework (‘CSF’), requiring practices in each of the core functions,” U.S. Telecom said. “Specifically, we urge the Commission to mirror its own approach to setting requirements for 5G funding recipients.”
Saying that the “[c]urrent targeting and restrictions on untrusted vendors in the licensing process is vague and ad-hoc,” the Telecommunications Industry Association (TIA) called for the FCC to institute “brightline rules to exclude untrusted vendors” from submarine cable networks.
“The FCC should rely on rules and exclusion lists to improve market certainty and ensure a comprehensive, harmonized approach that supports U.S. national security,” TIA said.
The International Connectivity Coalition (ICC) said regulations on deployment and operation of submarine cable “should be narrowly tailored to well-articulated and credible national security risks while ensuring minimum impact to U.S. data flows and industries that rely on global communications and digital infrastructure.”
The North American Submarine Cable Association (NASCA) faulted the NPRM for “inexplicably” proposing “vast new regulatory regime that would impair U.S. connectivity, diversity, and resilience by making the United States a far less attractive market in which to land and operate submarine cables.”
Among other things, NASCA said, the NPRM “wrongly assumes that there are significant unaddressed national security and law enforcement risks, in part because it fails to account for longstanding and continuous oversight of submarine cables by the Team Telecom agencies.”
The Commission should therefore revise the proposals to “tailor them to specific regulatory needs that are not already addressed—and to rationalize the Commission’s regime with Team Telecom’s parallel national security regulatory regime,” the group said. “These regimes should be complementary, not duplicative or conflicting.”
The FCC should adopt “simplified, bright-line rules that will speed licensing, standardize security mitigation conditions, and free industry and agency resources to focus on building and securing infrastructure rather than completing a mountain of paperwork requirements, on repeat,” NASCA.
The Foundation for Defense of Democracies said the FCC should “prohibit any entity on the Covered List, along with those subject to the jurisdiction, direction, or control of a foreign adversary, from owning submarine cables connected to the United States” and “restrict submarine cable manufacturers from incorporating equipment from firms on the Covered List, along with components produced by firms under the jurisdiction of foreign adversaries.”
SentinelOne said it supported the FCC’s proposal to designate a lead licensee within submarine cable consortium arrangements and “generally” supported proposed risk management and cybersecurity requirements, provided the Commission recognizes the need to “appropriately scope these obligations to reflect the operational realities of undersea cable systems.”
The Southern Cross Cable Network (SCCN) told the FCC it supported introducing cybersecurity certifications but urged the Commission to include International Organization for Standardization standards.
News: FederalLegislation DataSecurity