Full Report
Congressman August Pfluger (TX-11) has introduced bipartisan legislation to establish clear, standardized security requirements for submarine cables landing in the United States while streamlining the licensing process for trusted companies. The United States Submarine Cable Security Policy Act of 2026 would replace case-by-case security agreements with transparent, predictable rules. Over 95% of international data flows…
Analysis Summary
# Regulation/Compliance: United States Submarine Cable Security Policy Act of 2026
## Overview
This bipartisan legislation seeks to protect the critical infrastructure of undersea cables, which carry over 95% of international data. The bill replaces the current system of ad-hoc, case-by-case security agreements with a standardized regulatory framework. It aims to prevent foreign adversaries (specifically citing China) from compromising U.S. national and economic security through the landing stations and physical infrastructure located in the United States.
## Key Details
- **Issuing Authority:** U.S. Congress (Introduced by Rep. August Pfluger, TX-11)
- **Effective Date:** TBD (Legislation introduced Oct 2026)
- **Jurisdiction:** United States (Submarine cable landing points)
- **Status:** Proposed Bipartisan Legislation
## Requirements
### Mandatory Requirements
1. **Adherence to Standardized Security Rules:** Companies must transition from individualized "Security Agreements" to a uniform set of national security standards for cable landings.
2. **Supply Chain Integrity:** Entities must ensure that infrastructure components are not sourced from "untrusted" foreign adversaries or companies under their influence.
3. **Licensing Compliance:** Companies must undergo a streamlined but rigorous licensing process to prove they are "trusted" entities.
### Recommended Practices
1. **Risk Mitigation for International Data Flows:** Proactive monitoring of data integrity for cables connecting to high-risk geographic regions.
2. **Standardized Reporting:** Maintaining transparent communication channels with federal regulators regarding infrastructure maintenance and security incidents.
## Affected Organizations
- **Industries:** Telecommunications, Internet Service Providers (ISPs), Global Tech firms (Cloud providers/Hyperscalers), and Submarine Cable Operators.
- **Organization Size:** All sizes, provided they own, operate, or land submarine cables in the U.S.
- **Geographic Scope:** Any international cable landing on U.S. soil.
## Compliance Timeline
- **Oct 04, 2026:** Legislation introduced to Congress.
- **[Future Date]:** Passage by House and Senate.
- **[Future Date]:** Presidential Signature.
- **[Implementation Period]:** Transition period for existing case-by-case agreements to be replaced by the new standardized rules.
## Implementation Guidance
### Assessment Phase
- Audit existing case-by-case security agreements currently held with the U.S. government.
- Map out cable landing stations and identify components sourced from foreign adversary-linked vendors.
### Implementation Phase
- Adopt the new "transparent and predictable" security rules once finalized by the executive branch/regulatory agencies.
- Update licensing applications to align with the "trusted company" criteria established by the Act.
### Validation Phase
- Submit to government audits or inspections of landing stations to ensure compliance with the standardized rules.
## Technical Requirements
*Specific technical controls are to be codified following the bill’s passage, but focus will include:*
- Physical security of landing stations.
- Logical security and encryption of data at the point of landing.
- Supply chain verification for optical repeaters, branching units, and terminal equipment.
## Penalties & Enforcement
- **Fines:** To be determined by the specific regulatory body (likely FCC or Team Telecom) based on the severity of the security breach.
- **Other Consequences:** Potential revocation of landing licenses; exclusion from the "trusted company" list, which would halt operations in the U.S. market.
- **Enforcement:** Streamlined federal oversight replacing the current fragmented case-by-case review process.
## Related Standards
- **NIST CSF:** Likely alignment with Critical Infrastructure protection standards.
- **CISA "Securing the Next 250":** Aligns with current CISA campaigns to strengthen resilience in the communications sector.
## Resources
- **Official Documentation:** [pfluger.house.gov/news/documentsingle.aspx?DocumentID=3050](https://pfluger.house.gov/news/documentsingle.aspx?DocumentID=3050)
- **Guidance Documents:** CISA Critical Infrastructure Sector-Specific Plans (Communications).
## Practical Recommendations
- **Engage Government Relations:** Affected firms should monitor the bill's progress to influence the "standardized rules" during the public comment or drafting phases.
- **Supply Chain Review:** Immediately begin identifying and phasing out equipment from vendors associated with foreign adversaries to ensure "trusted company" status.