H.R. 1709House119th Congress (2025-2027)Passed House

Understanding Cybersecurity of Mobile Networks Act

Introduced February 27, 2025

AI-Generated Summary

Updated November 24, 2025 at 2:19 AM UTC

The Understanding Cybersecurity of Mobile Networks Act directs the Commerce Department’s Assistant Secretary for Communications and Information to produce a comprehensive report on the security of U.S. mobile service networks. The report, due within a year, will evaluate provider vulnerabilities, consumer security considerations, encryption practices, and the use of surveillance tools, while consulting a broad set of government, industry, and academic experts. It focuses on real‑world threats, excludes 5G protocols, and will be delivered in an unclassified format with possible classified annexes.

Key Provisions

  • The Assistant Secretary of Commerce for Communications and Information must, within one year of the law’s enactment, deliver a report to the House Energy and Commerce Committee and the Senate Commerce, Science, and Transportation Committee on the cybersecurity of mobile service networks.
  • The report must assess how mobile service providers have addressed vulnerabilities identified by researchers, standards bodies, industry experts, and federal agencies, and evaluate how customers consider security when choosing services or devices.
  • It must examine the use and effectiveness of encryption and authentication methods in mobile networks, equipment, phones, operating systems, and apps, as well as barriers providers face in adopting stronger security measures.
  • The report must estimate the prevalence and use of cell‑site simulators (IMSI catchers) and other surveillance tools by adversaries in the United States.
  • In preparing the report, the Assistant Secretary must consult with a wide range of stakeholders, including the FCC, NIST, the intelligence community, DHS agencies, academic researchers, standards groups, international partners, and mobile providers of all sizes.
  • The report is limited to mobile service networks (excluding 5G protocols) and only considers vulnerabilities that have been exploited in real‑world settings or are feasibly exploitable, while ignoring those already mitigated by manufacturers.
  • The report will be released in an unclassified form, may include a classified annex, and any potentially exploitable unclassified details will be redacted for public release but provided unredacted to the committees.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

14 earlier actions
SenateIntro Referral Latest Action

Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.

July 15, 2025

View full timeline
HouseIntro Referral

Introduced in House

February 27, 2025

HouseIntro Referral

Referred to the House Committee on Energy and Commerce.

February 27, 2025

HouseCommittee

Committee Consideration and Mark-up Session Held

March 4, 2025

HouseCommittee

Ordered to be Reported by Voice Vote.

March 4, 2025

HouseCommittee

Reported by the Committee on Energy and Commerce. H. Rept. 119-177.

June 30, 2025

HouseCalendars

Placed on the Union Calendar, Calendar No. 143.

June 30, 2025

HouseFloor

Mr. Latta moved to suspend the rules and pass the bill.

July 14, 2025 • 3:00 PM

HouseFloor

Considered under suspension of the rules. (consideration: CR H3209-3211)

July 14, 2025 • 3:00 PM

HouseFloor

DEBATE - The House proceeded with forty minutes of debate on H.R. 1709.

July 14, 2025 • 3:00 PM

HouseFloor

At the conclusion of debate, the Yeas and Nays were demanded and ordered. Pursuant to the provisions of clause 8, rule XX, the Chair announced that further proceedings on the motion would be postponed.

July 14, 2025 • 3:08 PM

HouseFloor

Considered as unfinished business. (consideration: CR H3230-3231)

July 14, 2025 • 6:30 PM

HouseFloor

Passed/agreed to in House: On motion to suspend the rules and pass the bill Agreed to by the Yeas and Nays: (2/3 required): 360 - 10 (Roll no. 191).

July 14, 2025 • 6:56 PM

HouseFloor

On motion to suspend the rules and pass the bill Agreed to by the Yeas and Nays: (2/3 required): 360 - 10 (Roll no. 191). (text: CR H3209-3210)

July 14, 2025 • 6:56 PM

HouseFloor

Motion to reconsider laid on the table Agreed to without objection.

July 14, 2025 • 6:56 PM

SenateIntro Referral

Received in the Senate and Read twice and referred to the Committee on Commerce, Science, and Transportation.

July 15, 2025

Floor Debate

13 members

What members said about H.R. 1709 on the floor

5 Republicans8 Democrats
Monica De La Cruz
Rep. Monica De La CruzR-TX-15 · May 6, 2025

Under clause 7 of rule XII, sponsors were added to public bills and resolutions, as follows: H.R. 116: Ms. Boebert. H.R. 151: Ms. Van Duyne. H.R. 255: Mr. Gill of Texas, Mr. Self, and Ms. Crockett.…

Robert E. Latta
Rep. Robert E. LattaR-OH-5 · Jul 14, 2025

Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 1709) to direct the Assistant Secretary of Commerce for Communications and Information to submit to Congress a report examining the…

Frank Pallone, Jr.
Rep. Frank Pallone, Jr.D-NJ-6 · Jul 14, 2025

Mr. Speaker, I yield myself such time as I may consume. Mr. Speaker, I rise in support of H.R. 1709, the Understanding Cybersecurity of Mobile Networks Act. The security of our mobile networks and…

Greg Landsman
Rep. Greg LandsmanD-OH-1 · Jul 14, 2025

Mr. Speaker, I thank my colleague from Ohio (Mr. Latta) and Mr. Pallone. This is, I think, a really important bipartisan piece of legislation. It is a very simple and straightforward bill. It is…

Brett Guthrie
Rep. Brett GuthrieR-KY-2 · Jul 14, 2025

Mr. Speaker, on Roll Call No. 191, No. 192, and No. 193, I was not recorded due to inclement weather delaying travel. Had I been present, I would have voted YEA on Roll Call No. 191, YEA on Roll Call…

Show 8 more
Debbie Wasserman Schultz
Rep. Debbie Wasserman SchultzD-FL-25 · Jul 14, 2025

Mr. Speaker, due to weather related travel delays outside of my control, I was not able to be physically present for votes today. Had I been present, I would have voted YEA on Roll Call No. 191, YEA…

Zachary Nunn
Rep. Zachary NunnR-IA-3 · Jul 14, 2025

Mr. Speaker, I was unable to be present for the following floor votes today. Had I been present, I would have voted: YEA on Roll Call No. 191, H.R. 1709; YEA on Roll Call No. 192, H.R. 1770; and YEA…

Maxine Dexter
Rep. Maxine DexterD-OR-3 · Jul 14, 2025

Mr. Speaker, my flight was delayed in getting to D.C. Had I been present, I would have voted YEA on Roll Call No. 191, H.R. 1709; YEA on Roll Call No. 192, H.R. 1770; and YEA on Roll Call No. 193, S.…

Suzanne Bonamici
Rep. Suzanne BonamiciD-OR-1 · Jul 14, 2025

Mr. Speaker, I was unable to attend today's vote series. Had I been present, I would have voted YEA on Roll Call No. 191, YEA on Roll Call No. 192, and YEA on Roll Call No. 193. personal explanation

Hillary J. Scholten
Rep. Hillary J. ScholtenD-MI-3 · Jul 14, 2025

Mr. Speaker, due to travel delays, I was unable to vote today. Had I been present, I would have voted: YEA on Roll Call No. 193, YEA on Roll Call No. 192, and YEA on Roll Call No. 191.

Susie Lee
Rep. Susie LeeD-NV-3 · Jul 14, 2025

Mr. Speaker, my votes were not recorded today. Had they been recorded, I would have voted: YEA on Roll Call No. 191, YEA on Roll Call No. 192, and YEA on Roll Call No. 193.

Marie Gluesenkamp Perez
Rep. Marie Gluesenkamp PerezD-WA-3 · Jul 14, 2025

Mr. Speaker, I unfortunately missed votes today. Had I been present, I would have voted: YEA on Roll Call No. 191, YEA on Roll Call No. 192, and YEA on Roll Call No. 193.

Juan Ciscomani
Rep. Juan CiscomaniR-AZ-6 · Jul 14, 2025

Mr. Speaker, had I been present, I would have voted YEA on Roll Call No. 191.

Bill Text

4 versions available

Reading Mode
Latest
Referred in SenateIssued July 15, 2025

IIB

119th CONGRESS

1st Session

H. R. 1709

IN THE SENATE OF THE UNITED STATES

July 15, 2025

Received; read twice and referred to the Committee on Commerce, Science, and Transportation

AN ACT

To direct the Assistant Secretary of Commerce for Communications and Information to submit to Congress a report examining the cybersecurity of mobile service networks, and for other purposes.

1.

Short title

This Act may be cited as the Understanding Cybersecurity of Mobile Networks Act.

2.

Report on cybersecurity of mobile service networks

(a)

In general

Not later than 1 year after the date of the enactment of this Act, the Assistant Secretary, in consultation with the Department of Homeland Security, shall submit to the Committee on Energy and Commerce of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a report examining the cybersecurity of mobile service networks and the vulnerability of such networks and mobile devices to cyberattacks and surveillance conducted by adversaries.

(b)

Matters To be included

The report required by subsection (a) shall include the following:

(1)

An assessment of the degree to which providers of mobile service have addressed, are addressing, or have not addressed cybersecurity vulnerabilities (including vulnerabilities the exploitation of which could lead to surveillance conducted by adversaries) identified by academic and independent researchers, multistakeholder standards and technical organizations, industry experts, and Federal agencies, including in relevant reports of—

(A)

the National Telecommunications and Information Administration;

(B)

the National Institute of Standards and Technology; and

(C)

the Department of Homeland Security, including—

(i)

the Cybersecurity and Infrastructure Security Agency; and

(ii)

the Science and Technology Directorate.

(2)

A discussion of—

(A)

the degree to which customers (including consumers, companies, and government agencies) consider cybersecurity as a factor when considering the purchase of mobile service and mobile devices; and

(B)

the commercial availability of tools, frameworks, best practices, and other resources for enabling such customers to evaluate cybersecurity risk and price tradeoffs.

(3)

A discussion of the degree to which providers of mobile service have implemented cybersecurity best practices and risk assessment frameworks.

(4)

An estimate and discussion of the prevalence and efficacy of encryption and authentication algorithms and techniques used in each of the following:

(A)

Mobile service.

(B)

Mobile communications equipment or services.

(C)

Commonly used mobile phones and other mobile devices.

(D)

Commonly used mobile operating systems and communications software and applications.

(5)

A discussion of the barriers for providers of mobile service to adopt more efficacious encryption and authentication algorithms and techniques and to prohibit the use of older encryption and authentication algorithms and techniques with established vulnerabilities in mobile service, mobile communications equipment or services, and mobile phones and other mobile devices.

(6)

An estimate and discussion of the prevalence, usage, and availability of technologies that authenticate legitimate mobile service and mobile communications equipment or services to which mobile phones and other mobile devices are connected.

(7)

An estimate and discussion of the prevalence, costs, commercial availability, and usage by adversaries in the United States of cell site simulators (often known as international mobile subscriber identity catchers) and other mobile service surveillance and interception technologies.

(c)

Consultation

In preparing the report required by subsection (a), the Assistant Secretary shall, to the degree practicable, consult with—

(1)

the Federal Communications Commission;

(2)

the National Institute of Standards and Technology;

(3)

the intelligence community;

(4)

the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security;

(5)

the Science and Technology Directorate of the Department of Homeland Security;

(6)

academic and independent researchers with expertise in privacy, encryption, cybersecurity, and network threats;

(7)

participants in multistakeholder standards and technical organizations (including the 3rd Generation Partnership Project and the Internet Engineering Task Force);

(8)

international stakeholders, in coordination with the Department of State as appropriate;

(9)

providers of mobile service, including small providers (or the representatives of such providers) and rural providers (or the representatives of such providers);

(10)

manufacturers, operators, and providers of mobile communications equipment or services and mobile phones and other mobile devices;

(11)

developers of mobile operating systems and communications software and applications; and

(12)

other experts that the Assistant Secretary considers appropriate.

(d)

Scope of report

The Assistant Secretary shall—

(1)

limit the report required by subsection (a) to mobile service networks;

(2)

exclude consideration of 5G protocols and networks in the report required by subsection (a);

(3)

limit the assessment required by subsection (b)(1) to vulnerabilities that have been shown to be—

(A)

exploited in non-laboratory settings; or

(B)

feasibly and practicably exploitable in real-world conditions; and

(4)

consider in the report required by subsection (a) vulnerabilities that have been effectively mitigated by manufacturers of mobile phones and other mobile devices.

(e)

Form of report

(1)

Classified information

The report required by subsection (a) shall be produced in unclassified form but may contain a classified annex.

(2)

Potentially exploitable unclassified information

The Assistant Secretary shall redact potentially exploitable unclassified information from the report required by subsection (a) but shall provide an unredacted form of the report to the committees described in such subsection.

(f)

Definitions

In this section:

(1)

Adversary

The term adversary includes—

(A)

any unauthorized hacker or other intruder into a mobile service network; and

(B)

any foreign government or foreign nongovernment person engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons.

(2)

Assistant secretary

The term Assistant Secretary means the Assistant Secretary of Commerce for Communications and Information.

(3)

Entity

The term entity means a partnership, association, trust, joint venture, corporation, group, subgroup, or other organization.

(4)

Intelligence community

The term intelligence community has the meaning given that term in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).

(5)

Mobile communications equipment or service

The term mobile communications equipment or service means any equipment or service that is essential to the provision of mobile service.

(6)

Mobile service

The term mobile service means, to the extent provided to United States customers, either or both of the following services:

(A)

Commercial mobile service (as defined in section 332(d) of the Communications Act of 1934 (47 U.S.C. 332(d))).

(B)

Commercial mobile data service (as defined in section 6001 of the Middle Class Tax Relief and Job Creation Act of 2012 (47 U.S.C. 1401)).

(7)

Person

The term person means an individual or entity.

(8)

United states person

The term United States person means—

(A)

an individual who is a United States citizen or an alien lawfully admitted for permanent residence to the United States;

(B)

an entity organized under the laws of the United States or any jurisdiction within the United States, including a foreign branch of such an entity; or

(C)

any person in the United States.

Passed the House of Representatives July 14, 2025.

Kevin F. McCumber,

Clerk.