Cybersecurity Policy Report, Privacy Advocates, Industry Groups Take Sides on FCC’s CALEA Cybersecurity Ruling, (Jul 31, 2025)
Organizations Mentioned:Public Knowledge | USTelecom
By Jeff Williams
Privacy advocacy groups are urging the FCC to leave in place the declaratory ruling the agency adopted in January that found that section 105 of the Communications Assistance for Law Enforcement Act (CALEA) “affirmatively requires telecommunications carriers to secure their networks from unlawful access or interception of communications,” while CTIA and NCTA are calling for the FCC to grant their petition for reconsideration of the decision.
The FCC adopted the declaratory ruling in PS docket 22-239 in the final days of former FCC Chairwoman Jessica Rosenworcel’s tenure, over the dissents of then-Commissioner Brendan Carr, who is now FCC Chairman, and his fellow Republican Commissioner Nathan Simington, who has since left the agency (CPR, Jan. 17). CTIA, NCTA, and USTelecom filed their petition for reconsideration in February (CPR, Feb. 20).
According to an ex parte filing describing a July 23 meeting with representatives from Mr. Carr’s office and the FCC’s Office of General Counsel, CTIA and NCTA representatives argued that the FCC’s declaratory ruling “misinterprets the plain language of the statute, fails to provide notice and comment required by CALEA and the Administrative Procedure Act, and is arbitrary and capricious.”
The groups also argued that the declaratory ruling “will have adverse public policy consequences by undercutting the meaningful, collaborative, and government-wide approach to cybersecurity that already exists—and has prevailed for decades.”
In addition, CTIA and NCTA said, now-Chairman Carr’s dissent from the declaratory ruling, “with its emphasis on CALEA’s limited grant of authority to the FCC and misguided approach to cyber risk management, should serve as the foundation for an approach to cybersecurity grounded in public-private partnerships and interagency coordination.”
According to an ex parte filing describing a July 28 meeting with several representatives from the FCC’s Public Safety and Homeland Security Bureau, representatives from the Electronic Privacy Information Center (EPIC), Public Knowledge, and R Street expressed their support for the FCC’s declaratory ruling and discussed a filing written by EPIC that they submitted “clarifying the FCC’s authority to enforce cybersecurity measures in response to the harms exposed by the ongoing Salt Typhoon incident, and the FCC’s role more broadly."
The filing discussed at the meeting calls for the FCC to “leave its Declaratory Ruling as-is,” describing it as an “appropriate response to an unprecedented cyber attack that re-iterates already-existing obligations, supported by caselaw and decades of FCC rulings, including recent actions against malign foreign actors.”
CALEA “[c]learly” gave the FCC authority to establish communications security safeguards, the EPIC filing said, adding that other federal agencies are “ill-suited” to enforce such safeguards.
In addition, the filing said, “It seems unlikely that America’s communications networks can be adequately secured against the next Salt Typhoon-level attack absent greater leadership from the FCC, including challenging carriers to implement baseline cybersecurity practices.”
The FCC should “meaningfully and promptly compel carriers to take steps to guard against the next Salt Typhoon attack,” the filing said. “This is not a time for the Commission to step back, or to unwind its January Ruling.”
News: FederalLegislation DataSecurity