<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ALL26614-2N9-4S-MKL"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S3404 RS: Satellite Cybersecurity Act of 2025</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2026-09-14</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 560</calendar><congress>119th CONGRESS</congress><session>2d Session</session><legis-num>S. 3404</legis-num><associated-doc role="report">[Report No. 119–141]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20251209">December 9, 2025</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S287">Mr. Cornyn</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20260914">September 14, 2026</action-date><action-desc>Reported by <sponsor name-id="S355">Mr. Cruz</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To require a report on Federal support to the cybersecurity of commercial satellite systems, and for other purposes.</official-title></form><legis-body><section id="id77fa29afee1949dda1b751b58c79fb87" section-type="section-one" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Satellite Cybersecurity Act of 2025</short-title></quote>.</text></section><section id="id6601843dbffe4e258b64454320054275" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="idE03B7F4B68C34B59B6689B8403297F05"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="id005353CEDF834374B4BF4A485FF60520"><enum>(A)</enum><text>the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate; and</text></subparagraph><subparagraph id="id457E505B3DD74E94A4EA22169D20658B"><enum>(B)</enum><text>the Committee on Energy and Commerce, the Committee on Space, Science, and Technology, and the Committee on Homeland Security of the House of Representatives.</text></subparagraph></paragraph><paragraph id="idCAE56CA8580C4633A9DDD216130F56D5"><enum>(2)</enum><header>Clearinghouse</header><text>The term <term>clearinghouse</term> means the commercial satellite system cybersecurity clearinghouse required to be developed and maintained under section 4(b)(1).</text></paragraph><paragraph id="id638de7797a834462b32d1d7a04fa9f1c"><enum>(3)</enum><header>Commercial satellite system</header><text>The term <term>commercial satellite system</term>—</text><subparagraph id="idACC1DCF49E2A4EC09845C15FE14A68C1"><enum>(A)</enum><text>means a system that—</text><clause id="id290F674A8AE1481D8534598EBA10215A"><enum>(i)</enum><text>is owned or operated by a non-Federal entity that holds a license issued by the United States for business operations; and</text></clause><clause id="id4DB5409E53974980B52E5E398BDF2898"><enum>(ii)</enum><text>is composed of not less than 1 earth satellite; and</text></clause></subparagraph><subparagraph id="id56F2333E3A79499A8167EDA85558ADE2"><enum>(B)</enum><text>includes—</text><clause id="id953D9D766D90439A819187120E41F57A"><enum>(i)</enum><text>any ground support infrastructure for each satellite in the system; and</text></clause><clause id="idA458B86C846E4531B373FD9ED092D7E8"><enum>(ii)</enum><text>any transmission link among and between any satellite in the system and any ground support infrastructure in the system.</text></clause></subparagraph></paragraph><paragraph id="id3e48b1395da6421487631c9326ad2115"><enum>(4)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning given the term in subsection (e) of the Critical Infrastructure Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph id="id310a4d3bb48a44c2a2f2101aa026e0b5"><enum>(5)</enum><header>Cybersecurity risk</header><text>The term <term>cybersecurity risk</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="id6da052b33cdd4cf889bf657033992464"><enum>(6)</enum><header>Cybersecurity threat</header><text>The term <term>cybersecurity threat</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4da074aad9f2463781c55313a183717d"><enum>(7)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></section><section id="id7338a66b31014c0fbfbb43916963e004" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>3.</enum><header>Report on commercial satellite cybersecurity</header><subsection id="id1b9ced2b85b449cfbaf6f6aa9acf540d"><enum>(a)</enum><header>Study</header><text>The Comptroller General of the United States shall conduct a study on the actions the Federal Government has taken to support the cybersecurity of commercial satellite systems, including as part of any action to address the cybersecurity of critical infrastructure sectors.</text></subsection><subsection id="id755ad097f61c4cc894646c68a31f91d4"><enum>(b)</enum><header>Report</header><text>Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall report to the appropriate congressional committees on the study conducted under subsection (a), which shall include information—</text><paragraph id="id88955c0f1df64e80a160bba401223e8a"><enum>(1)</enum><text>on efforts of the Federal Government, and the effectiveness of those efforts, to—</text><subparagraph id="id238C4FA596A743249EAEC8A62A9E2A7E"><enum>(A)</enum><text>address or improve the cybersecurity of commercial satellite systems; and</text></subparagraph><subparagraph id="id17B825EE3AD6444DABD34E7D611E1883"><enum>(B)</enum><text>support related efforts with international entities or the private sector;</text></subparagraph></paragraph><paragraph id="id4b6e635538b7401abb71689fcd6c3dca"><enum>(2)</enum><text>on the resources made available to the public by Federal agencies to address cybersecurity risks and threats to commercial satellite systems, including resources made available through the clearinghouse;</text></paragraph><paragraph id="idfea844ddb5cb4267b955b9187f8cb67c"><enum>(3)</enum><text>on the extent to which commercial satellite systems are reliant on, or relied on by, critical infrastructure;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide4f9a15e4f2449b9817ddb4452e6c6f6"><enum>(4)</enum><text display-inline="yes-display-inline">that includes an analysis of how commercial satellite systems and the threats to those systems are integrated into Federal and non-Federal critical infrastructure risk analyses and protection plans;</text></paragraph><paragraph id="id078aeae8522e424ea31d2aaa505e3e87"><enum>(5)</enum><text>on the extent to which Federal agencies are reliant on commercial satellite systems and how Federal agencies mitigate cybersecurity risks associated with those systems;</text></paragraph><paragraph id="id32b7fbec899745b1a592b67f60e05eaa"><enum>(6)</enum><text>on the extent to which Federal agencies are reliant on commercial satellite systems that are owned wholly or in part or controlled by foreign entities, or that have infrastructure in foreign countries, and how Federal agencies mitigate associated cybersecurity risks;</text></paragraph><paragraph id="ide16bb7bcae844cf68938e56cb518a076"><enum>(7)</enum><text>on the extent to which Federal agencies coordinate or duplicate authorities and take other actions focused on the cybersecurity of commercial satellite systems; and</text></paragraph><paragraph id="id728330b3fda44c05b8206eac1709a623"><enum>(8)</enum><text>as determined appropriate by the Comptroller General of the United States, that includes recommendations for further Federal action to support the cybersecurity of commercial satellite systems, including recommendations on information that should be shared through the clearinghouse.</text></paragraph></subsection><subsection id="idbbe64f4f906f417490972b69de0313ae"><enum>(c)</enum><header>Consultation</header><text>In carrying out subsections (a) and (b), the Comptroller General of the United States shall coordinate with appropriate Federal agencies and organizations, including—</text><paragraph id="idee8a5d9639a541ef82f75ea2390c102f"><enum>(1)</enum><text>the Department of Commerce;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idea453fc152434704b81132c1a816e79d"><enum>(2)</enum><text>the Office of the National Cyber Director;</text></paragraph><paragraph id="id1c1ee69d14a6459bbfd05548fb02f929"><enum>(3)</enum><text>the Department of Homeland Security;</text></paragraph><paragraph id="id201f2a8e387c40daa75d285fb95307ad"><enum>(4)</enum><text>the Department of Defense;</text></paragraph><paragraph id="idfb4a8d1f344b42edb674fcfce88cd543"><enum>(5)</enum><text>the Department of Transportation;</text></paragraph><paragraph id="id10d390bc9e37467d9e81fcda61ea76c6"><enum>(6)</enum><text>the Federal Communications Commission;</text></paragraph><paragraph id="id63ede35fc6b44849b1fd11af4884278a"><enum>(7)</enum><text>the National Aeronautics and Space Administration;</text></paragraph><paragraph id="idc61b7599d9d8466d8ad0a16ac933ec69"><enum>(8)</enum><text>the National Executive Committee for Space-Based Positioning, Navigation, and Timing;</text></paragraph><paragraph id="id0672533f7ebc4cbebce9c007efb424fd"><enum>(9)</enum><text>the National Space Council;</text></paragraph><paragraph id="id343B0EAF5FF746EE879C9A000553FCE5"><enum>(10)</enum><text>the Department of Justice; and</text></paragraph><paragraph id="idF7F2A3F6AB57431F952048C9851432F0"><enum>(11)</enum><text>the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector.</text></paragraph></subsection><subsection id="idde754f5f9ef64e4092c092156d064ec4"><enum>(d)</enum><header>Briefing</header><text>Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall provide a briefing to the appropriate congressional committees on the study conducted under subsection (a).</text></subsection><subsection id="id1b6650e95a2541b985453cacc2fd5406"><enum>(e)</enum><header>Classification</header><text>The report made under subsection (b) shall be unclassified but may include a classified annex.</text></subsection></section><section id="ide6b3833c67cb44acbf2a173d742f22ac" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>4.</enum><header>Responsibilities of the Department of Commerce</header><subsection id="id4172058b40234b7d800c6f16a6c02f12"><enum>(a)</enum><header>Small business concern defined</header><text>In this section, the term <term>small business concern</term> has the meaning given the term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></subsection><subsection id="id29cac49b1e7840e29e5d9f591c074195"><enum>(b)</enum><header>Establishment of commercial satellite system cybersecurity clearinghouse</header><paragraph id="id52b0c0b9af6449519998c1a4f4739eee"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Secretary, in coordination with the Chair of the Federal Communications Commission and the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and maintain a commercial satellite system cybersecurity clearinghouse.</text></paragraph><paragraph id="idb2c2738f57d94043ae6f08eb26c3965e"><enum>(2)</enum><header>Requirements</header><text>The clearinghouse—</text><subparagraph id="idb31ecc04556e4e75973270768b7939ca"><enum>(A)</enum><text>shall be publicly available online;</text></subparagraph><subparagraph id="idc8c5195a344d49cfa2baeae2d0d91d0b"><enum>(B)</enum><text>shall contain publicly available commercial satellite system cybersecurity resources, including the voluntary recommendations consolidated under subsection (c)(1);</text></subparagraph><subparagraph id="idB19579155F174545A14FC3E9471DF3E9"><enum>(C)</enum><text>shall contain appropriate materials for reference by entities that develop, operate, or maintain commercial satellite systems;</text></subparagraph><subparagraph id="idf4f86585abd6476da64f3a9e5aa1b016"><enum>(D)</enum><text>shall contain materials specifically aimed at assisting small business concerns with the secure development, operation, and maintenance of commercial satellite systems; and</text></subparagraph><subparagraph id="id6d4f7ee7f35342dbba679ce6d1cbc8bc"><enum>(E)</enum><text>may contain controlled unclassified information distributed to commercial entities through a process determined appropriate by the Secretary.</text></subparagraph></paragraph><paragraph id="id7425813bb6024fc69a9f616e1f1f1964"><enum>(3)</enum><header>Content maintenance</header><text>The Secretary shall maintain current and relevant cybersecurity information on the clearinghouse.</text></paragraph><paragraph id="id5e79430aa77c45468558740033f30553"><enum>(4)</enum><header>Existing platform or website</header><text>To the extent practicable, the Secretary shall establish and maintain the clearinghouse using an online platform, a website, or a capability in existence as of the date of enactment of this Act.</text></paragraph></subsection><subsection id="id08b954f1bea848a48a9788964ebfb610"><enum>(c)</enum><header>Consolidation of commercial satellite system cybersecurity recommendations</header><paragraph id="id29894fdfb6644a5e9f85974e34159f4e"><enum>(1)</enum><header>In general</header><text>The Secretary, in coordination with the Secretary of Homeland Security, shall consolidate voluntary cybersecurity recommendations designed to assist in the development, maintenance, and operation of commercial satellite systems.</text></paragraph><paragraph id="idd9aba54216784367b50ea3d709e69879"><enum>(2)</enum><header>Requirements</header><text>The recommendations consolidated under paragraph (1) shall include materials appropriate for a public resource addressing, to the greatest extent practicable, the following:</text><subparagraph id="id3988ec11f2c64c2ba756213ca3ca446b"><enum>(A)</enum><text>Risk-based, cybersecurity-informed engineering, including continuous monitoring and resiliency.</text></subparagraph><subparagraph id="id2fff4532eb814cf696f028fc4f313667"><enum>(B)</enum><text>Planning for retention or recovery of positive control of commercial satellite systems in the event of a cybersecurity incident.</text></subparagraph><subparagraph id="id9cff7211c5c64f1ea17139de9ec71796"><enum>(C)</enum><text>Protection against unauthorized access to vital commercial satellite system functions.</text></subparagraph><subparagraph id="id0470612889b84385b509394d54ae5331"><enum>(D)</enum><text>Physical protection measures designed to reduce the vulnerabilities of a commercial satellite system’s command, control, and telemetry receiver systems.</text></subparagraph><subparagraph id="ida0b17728275f4431be61bcd1213375b4"><enum>(E)</enum><text>Protection against jamming, eavesdropping, hijacking, computer network exploitation, spoofing, threats to optical satellite communications, and electromagnetic pulse.</text></subparagraph><subparagraph id="id74a5800d1aa5498cb22294f8757f22e8"><enum>(F)</enum><text>Security against threats throughout a commercial satellite system’s mission lifetime.</text></subparagraph><subparagraph id="ide718a1b8e20d49738296b6eab950b39e"><enum>(G)</enum><text>Management of supply chain risks that affect the cybersecurity of commercial satellite systems.</text></subparagraph><subparagraph id="idd2310181f94c4cd3bdb2e8ea80d29052"><enum>(H)</enum><text>Protection against vulnerabilities posed by ownership of commercial satellite systems or commercial satellite system companies by foreign entities.</text></subparagraph><subparagraph id="ide2c2e15b814d4139a047f7c6352cbbf9"><enum>(I)</enum><text>Protection against vulnerabilities posed by locating physical infrastructure, such as satellite ground control systems, in foreign countries.</text></subparagraph><subparagraph id="idee36a369da8240ecb53f626bc547ff94"><enum>(J)</enum><text>As appropriate, and as applicable pursuant to the maintenance requirement under subsection (b)(3), relevant findings and recommendations from the study conducted by the Comptroller General of the United States under section 3(a).</text></subparagraph><subparagraph id="id290c984c411f4fb5b5bf7135a4bf7bf9"><enum>(K)</enum><text>Any other recommendations to ensure the confidentiality, availability, and integrity of data residing on or in transit through commercial satellite systems.</text></subparagraph></paragraph></subsection><subsection id="id37c760c0dc6b4939baaab731a353f562"><enum>(d)</enum><header>Implementation</header><text>In implementing this section, the Secretary shall—</text><paragraph id="idcd0c13f2d885421da465a4244c75f204"><enum>(1)</enum><text>to the extent practicable, carry out the implementation in partnership with the private sector;</text></paragraph><paragraph id="ida9bcc5a8af6b435ca40705bceb4d1b9c"><enum>(2)</enum><text>coordinate with—</text><subparagraph id="id32D6733ECA314E9FBD66FFC9B989476C"><enum>(A)</enum><text>the Secretary of Homeland Security, the Office of the National Cyber Director, the National Space Council, the Chair of the Federal Communications Commission, and the head of any other agency determined appropriate by the Office of the National Cyber Director or the National Space Council; and</text></subparagraph><subparagraph id="id023352876730414689FCEC9025AD244E"><enum>(B)</enum><text>the heads of appropriate Federal agencies with expertise and experience in satellite operations, including the entities described in section 3(c) to enable the alignment of Federal efforts on commercial satellite system cybersecurity and, to the extent practicable, consistency in Federal recommendations relating to commercial satellite system cybersecurity; and</text></subparagraph></paragraph><paragraph id="id38ffd938628d4ca793db48823ebd8b3d"><enum>(3)</enum><text>consult with non-Federal entities developing commercial satellite systems or otherwise supporting the cybersecurity of commercial satellite systems, including private, consensus organizations that develop relevant standards.</text></paragraph></subsection><subsection id="id94fc5c2577f84703a8393122c727dfb0"><enum>(e)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of this Act, and every 2 years thereafter until the date that is 9 years after the date of enactment of this Act, the Secretary shall submit to the appropriate congressional committees a report summarizing—</text><paragraph id="idF38B35B63A6E4A5DA3E86471AB46FF10"><enum>(1)</enum><text>any partnership with the private sector described in subsection (d)(1);</text></paragraph><paragraph id="idCB15B04F2831479B8B08587DD06CA800"><enum>(2)</enum><text>any consultation with a non-Federal entity described in subsection (d)(3);</text></paragraph><paragraph id="id07E70A67E5B5433099E95961662F8526"><enum>(3)</enum><text>the coordination carried out pursuant to subsection (d)(2);</text></paragraph><paragraph id="id488B8269C6E24FFF920C1B43E65E623B"><enum>(4)</enum><text>the establishment and maintenance of the clearinghouse pursuant to subsection (b);</text></paragraph><paragraph id="id6405FA6C9CD4429BA491CA19E4FA0EF3"><enum>(5)</enum><text>the recommendations consolidated pursuant to subsection (c)(1); and</text></paragraph><paragraph id="id9B081A6A61A6406BBE48DB6289E94ABD"><enum>(6)</enum><text>any feedback received by the Secretary on the clearinghouse from non-Federal entities.</text></paragraph></subsection></section><section id="id7575B1F6E5E24760B05543782B5B2F53" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>5.</enum><header>Strategy</header><text display-inline="no-display-inline">Not later than 120 days after the date of the enactment of this Act, the Secretary, jointly with the National Space Council and the Office of the National Cyber Director, in coordination with the Secretary of Homeland Security, the Director of the Office of Space Commerce, the Chair of the Federal Communications Commission, and the heads of other relevant agencies, shall submit to the appropriate congressional committees a strategy for the activities of Federal agencies to address and improve the cybersecurity of commercial satellite systems, which shall include an identification of—</text><paragraph id="id29E3087AFACA4E6DA8F2560DAF354485"><enum>(1)</enum><text display-inline="yes-display-inline">proposed roles and responsibilities for relevant agencies; and</text></paragraph><paragraph id="id81B820D94A0E459BBCBFC0342DB9BDA3"><enum>(2)</enum><text display-inline="yes-display-inline">as applicable, the extent to which cybersecurity threats to such systems are addressed in Federal and non-Federal critical infrastructure risk analyses and protection plans.</text></paragraph></section><section id="id234F428B0177410AB8B3448D9B1908AA" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>6.</enum><header>Rules of construction</header><text display-inline="no-display-inline">Nothing in this Act shall be construed to—</text><paragraph id="idc4b3159356174d16aab0ab80e8d8ca19"><enum>(1)</enum><text>designate commercial satellite systems or other space assets as a critical infrastructure sector; or</text></paragraph><paragraph id="id6028dd1ab834498392ff3804105b5c7e"><enum>(2)</enum><text>infringe upon or alter the authorities of the agencies described in section 3(c).</text></paragraph></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section id="id17f9f8a847d04271b812e3bae3c18f15" section-type="section-one" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Satellite Cybersecurity Act of 2025</short-title></quote>.</text></section><section id="idb55eb5b4eb734128899fd41670ba6fbc" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id285cc7a99b9948c29137bc27b0e3aa3f"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="id0e7b2f53742040af9ac7421ad20318fc"><enum>(A)</enum><text>the Committee on Commerce, Science, and Transportation and the Committee on Homeland Security and Governmental Affairs of the Senate; and</text></subparagraph><subparagraph id="id314aeb1e6828427495164723966445f5"><enum>(B)</enum><text>the Committee on Energy and Commerce, the Committee on Space, Science, and Technology, and the Committee on Homeland Security of the House of Representatives.</text></subparagraph></paragraph><paragraph id="id068aabff787e430aba3fa06cadf9b4bc"><enum>(2)</enum><header>Clearinghouse</header><text>The term <term>clearinghouse</term> means the commercial satellite system cybersecurity clearinghouse required to be developed and maintained under section 4(b)(1).</text></paragraph><paragraph id="id1918f56c23f4447b8443232684301df9"><enum>(3)</enum><header>Commercial satellite system</header><text>The term <term>commercial satellite system</term>—</text><subparagraph id="id34efc9f9b9e14fe1a576895f402b8169"><enum>(A)</enum><text>means a system that—</text><clause id="idd1a55d92abf04765ad5338d308c6ca1c"><enum>(i)</enum><text>is owned or operated by a non-Federal entity that holds a license issued by the United States for business operations; and</text></clause><clause id="id7d93aafd739043f888fd585b5bf7f14b"><enum>(ii)</enum><text>is composed of not less than 1 earth satellite; and</text></clause></subparagraph><subparagraph id="id194c74aa757e436b8146446e8ccd1e6a"><enum>(B)</enum><text>includes—</text><clause id="id4422a029311543169ae89d66fef8acd5"><enum>(i)</enum><text>any ground support infrastructure for each satellite in the system; and</text></clause><clause id="idfdac4521e5c34275b17783717e8d3f28"><enum>(ii)</enum><text>any transmission link among and between any satellite in the system and any ground support infrastructure in the system.</text></clause></subparagraph></paragraph><paragraph id="id6eb175db4f3a41a38b8eade58f138ebf"><enum>(4)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning given the term in subsection (e) of the Critical Infrastructures Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph id="id917a14e77cd04078b62bf8edaac18a3b"><enum>(5)</enum><header>Cybersecurity risk</header><text>The term <term>cybersecurity risk</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="id2933ec13a0924bd4be735c11a06b6494"><enum>(6)</enum><header>Cybersecurity threat</header><text>The term <term>cybersecurity threat</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="id63af2ea18159443cb4b75286f9d3c8fe"><enum>(7)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Commerce.</text></paragraph></section><section id="id770dc1f103e248889b03bf00564600a5" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>3.</enum><header>Report on commercial satellite cybersecurity</header><subsection id="idd4052d233b1b4cbfa8200f45b35d4e68"><enum>(a)</enum><header>Study</header><text>The Comptroller General of the United States shall conduct a study on the actions the Federal Government has taken to support the cybersecurity of commercial satellite systems, including as part of any action to address the cybersecurity of critical infrastructure sectors.</text></subsection><subsection id="idbe953021928a4a9791317b5140464bfd"><enum>(b)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall report to the appropriate congressional committees on the study conducted under subsection (a), which—</text><paragraph commented="no" display-inline="no-display-inline" id="id5a5cfbefe11e48f2b73fcb8248a6d41e"><enum>(1)</enum><text display-inline="yes-display-inline">shall include—</text><subparagraph commented="no" display-inline="no-display-inline" id="idbeeb9ff5cd994d37a4268d8132879146"><enum>(A)</enum><text display-inline="yes-display-inline">information on efforts of the Federal Government, and the effectiveness of those efforts, to—</text><clause id="id048eb4ae2fe54317a3fabfeb03a90f02"><enum>(i)</enum><text>address or improve the cybersecurity of commercial satellite systems; and</text></clause><clause id="id29f5d5b2737d47f28ef1b1269b6efd5d"><enum>(ii)</enum><text>support related efforts with international entities or the private sector;</text></clause></subparagraph><subparagraph id="id718cb7992db24387a878b9fdebfe227d"><enum>(B)</enum><text>information on the resources made available to the public by Federal agencies to address cybersecurity risks and threats to commercial satellite systems, including resources made available through the clearinghouse;</text></subparagraph><subparagraph id="id74be1d5a168c45909cfdc5cfeb7cb36d"><enum>(C)</enum><text>information on the extent to which commercial satellite systems are reliant on, or relied on by, critical infrastructure;</text></subparagraph><subparagraph id="id01ba87dde9ed469a9a8709c3e8f18d29"><enum>(D)</enum><text> an analysis of how commercial satellite systems and the threats to those systems are integrated into critical infrastructure risk analyses and protection plans;</text></subparagraph><subparagraph id="idabeb7ffa6f4246a6a894f1ef1dde5e34"><enum>(E)</enum><text>information on the extent to which Federal agencies are reliant on commercial satellite systems and how Federal agencies mitigate cybersecurity risks associated with those systems;</text></subparagraph><subparagraph id="id98a25d9c8a6c4303b876fca2cd0ab685"><enum>(F)</enum><text>information on the extent to which Federal agencies are reliant on commercial satellite systems that are owned wholly or in part or controlled by foreign entities, or that have infrastructure in foreign countries, and how Federal agencies mitigate associated cybersecurity risks;</text></subparagraph><subparagraph id="id4e6d388014954fd5a9b318d627fc022c"><enum>(G)</enum><text>information on the extent to which Federal agencies coordinate or duplicate authorities and take other actions focused on the cybersecurity of commercial satellite systems; and</text></subparagraph><subparagraph id="idb6a2e9f6c30144baa68864d2f9198d60"><enum>(H)</enum><text>as determined appropriate by the Comptroller General of the United States, recommendations to support the cybersecurity of commercial satellite systems, including recommendations on information that should be shared through the clearinghouse; and</text></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide5f45b03d4fa45849cdf3d04b0fbb74d"><enum>(2)</enum><text display-inline="yes-display-inline">shall not include recommendations described in paragraph (1)(H) for new or changing authorities or regulations for Federal agencies.</text></paragraph></subsection><subsection id="id7bffe18f6f40497ab8dca18af61bf003"><enum>(c)</enum><header>Consultation</header><text>In carrying out subsections (a) and (b), the Comptroller General of the United States shall coordinate with appropriate Federal agencies and organizations, including—</text><paragraph id="id67b21ee77645491a9f891f9a4360d158"><enum>(1)</enum><text>the Department of Commerce;</text></paragraph><paragraph id="id97a2158f87174bf687bf79c7cd907537"><enum>(2)</enum><text>the Office of the National Cyber Director;</text></paragraph><paragraph id="idb6ac4970e8ca4d479234493ee37dd5ea"><enum>(3)</enum><text>the Department of Homeland Security;</text></paragraph><paragraph id="idf21c8e81a7ca45e9bdd34410953f232b"><enum>(4)</enum><text>the Department of Defense;</text></paragraph><paragraph id="ideaf114c25508417aba121662671df1fb"><enum>(5)</enum><text>the Department of Transportation;</text></paragraph><paragraph id="idff29010b41de43c69404617d06693c24"><enum>(6)</enum><text>the Federal Communications Commission;</text></paragraph><paragraph id="id363ffe7b24b44a719bb4f592d6468188"><enum>(7)</enum><text>the National Aeronautics and Space Administration;</text></paragraph><paragraph id="idc43b57a2c16d4eba8f53115e15dacc90"><enum>(8)</enum><text>the National Executive Committee for Space-Based Positioning, Navigation, and Timing;</text></paragraph><paragraph id="idb843f2d61ea24cb181f56725bd434ecc"><enum>(9)</enum><text>the National Space Council;</text></paragraph><paragraph id="id9c291a61da80417d9026e39015d23946"><enum>(10)</enum><text>the Office of Science and Technology Policy;</text></paragraph><paragraph id="id1d2ab188ce2847c8aafb9a3b21d93e81"><enum>(11)</enum><text>the Department of Justice ; and</text></paragraph><paragraph id="idd98d8f116afd4921a22bd23b564c3f00"><enum>(12)</enum><text>the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector.</text></paragraph></subsection><subsection id="id4594632a01874187accc7387be3dc608"><enum>(d)</enum><header>Briefing</header><text>Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall provide a briefing to the appropriate congressional committees on the study conducted under subsection (a).</text></subsection><subsection id="idf7fbfd9e55894deeab02072ceabd5aaf"><enum>(e)</enum><header>Classification</header><text>The report made under subsection (b) shall be unclassified but may include a classified annex.</text></subsection></section><section id="id203c8606dce3413290079a653d61e264" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>4.</enum><header>Responsibilities of the department of commerce</header><subsection id="id1e1a5962232542508c1801dc6ac65796"><enum>(a)</enum><header>Small business concern defined</header><text>In this section, the term <term>small business concern</term> has the meaning given the term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></subsection><subsection id="id088dd1cf8e7443a09b6c43935fe25546"><enum>(b)</enum><header>Establishment of commercial satellite system cybersecurity clearinghouse</header><paragraph id="idc61bec4b2c44451c812b0a6fe4f04d35"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Secretary, in coordination with the Secretary of Homeland Security, shall develop and maintain a commercial satellite system cybersecurity clearinghouse for the purpose of serving as a repository for publicly available resources, guidance, frameworks, voluntary recommendations, and tools.</text></paragraph><paragraph id="id6fb25d24444a4c739376c33867e50ab5"><enum>(2)</enum><header>Requirements</header><text>The clearinghouse—</text><subparagraph id="id741b1febe29f4a03a2ad46db11037901"><enum>(A)</enum><text>shall be publicly available online;</text></subparagraph><subparagraph id="ide5b9f1c960114ee596cfdb9daff52987"><enum>(B)</enum><text>shall contain publicly available commercial satellite system cybersecurity resources, including the voluntary recommendations consolidated under subsection (c)(1);</text></subparagraph><subparagraph id="id99328d0563c84c09ab08ebf9cc1f3e0d"><enum>(C)</enum><text>shall contain appropriate materials for reference by entities that develop, operate, or maintain commercial satellite systems;</text></subparagraph><subparagraph id="iddca6848829144254825fca968b7e27d4"><enum>(D)</enum><text>shall contain materials specifically aimed at assisting small business concerns with the secure development, operation, and maintenance of commercial satellite systems;</text></subparagraph><subparagraph id="iddfba404f4fbb4fd19915b134adff9574"><enum>(E)</enum><text>may contain controlled unclassified information distributed to commercial entities through a process determined appropriate by the Secretary; and</text></subparagraph><subparagraph id="id8fb543b98ac848108bf1ec5357d08960"><enum>(F)</enum><text>may not contain sensitive security or proprietary information in the absence of the establishment and use of a gateway to limit access to approved users, as determined by the Secretary.</text></subparagraph></paragraph><paragraph id="idbd35a74616994881b5fe65f21153f73f"><enum>(3)</enum><header>Content maintenance</header><text>The Secretary shall maintain current and relevant cybersecurity information on the clearinghouse.</text></paragraph><paragraph id="id5746b6670c1141ec8c460f37f383bca6"><enum>(4)</enum><header>Existing platform or website</header><text>To the extent practicable, the Secretary shall establish and maintain the clearinghouse using an online platform, a website, or a capability in existence as of the date of enactment of this Act.</text></paragraph></subsection><subsection id="id8aac1bf9e5ed4f21a82e7e7b95109883"><enum>(c)</enum><header>Consolidation of commercial satellite system cybersecurity recommendations</header><paragraph id="id3013e86dfaf1433b8663e71aaf6a565e"><enum>(1)</enum><header>In general</header><text>The Secretary, in coordination with the Secretary of Homeland Security, shall consolidate voluntary cybersecurity recommendations designed to assist in the development, maintenance, and operation of commercial satellite systems.</text></paragraph><paragraph id="idf8d643fa0b3d45efada5d9b5ae5aa39b"><enum>(2)</enum><header>Requirements</header><text>The recommendations consolidated under paragraph (1) shall include materials appropriate for a public resource addressing, to the greatest extent practicable, the following:</text><subparagraph id="idef7dc9d87bbc40b68b9b7fa35d55c552"><enum>(A)</enum><text>Risk-based, cybersecurity-informed engineering, including continuous monitoring and resiliency.</text></subparagraph><subparagraph id="id4952782d362d45c9b0fe5e065b993b0f"><enum>(B)</enum><text>Planning for retention or recovery of positive control of commercial satellite systems in the event of a cybersecurity incident.</text></subparagraph><subparagraph id="idc1064707bafa432fb7a0eb2a59d0de3c"><enum>(C)</enum><text>Protection against unauthorized access to vital commercial satellite system functions.</text></subparagraph><subparagraph id="idfaf7108092844b64b18b5af1d76c2df4"><enum>(D)</enum><text>Physical protection measures designed to reduce the vulnerabilities of a commercial satellite system’s command, control, and telemetry receiver systems.</text></subparagraph><subparagraph id="id0935c298661245179228f3ddf8638e17"><enum>(E)</enum><text>Protection against jamming, eavesdropping, hijacking, computer network exploitation, spoofing, threats to optical satellite communications, and electromagnetic pulse.</text></subparagraph><subparagraph id="id4208b260ea2b45258ecb1e8a72cc8774"><enum>(F)</enum><text>Security against threats throughout a commercial satellite system’s mission lifetime.</text></subparagraph><subparagraph id="idf3ad7f0149bc4f5c9e65ac8e412c1654"><enum>(G)</enum><text>Management of supply chain risks that affect the cybersecurity of commercial satellite systems.</text></subparagraph><subparagraph id="idf012c071f6374a93ad5e34fc0e0961f4"><enum>(H)</enum><text>Protection against vulnerabilities posed by ownership of commercial satellite systems or commercial satellite system companies by foreign entities.</text></subparagraph><subparagraph id="id1e5733e4de274398a16a13e08dddef5a"><enum>(I)</enum><text>Protection against vulnerabilities posed by locating physical infrastructure, such as satellite ground control systems, in foreign countries.</text></subparagraph><subparagraph id="id8bcb81e649cc4ea8a69c6523833b7b7f"><enum>(J)</enum><text>As appropriate, and as applicable pursuant to the maintenance requirement under subsection (b)(3), relevant findings and recommendations from the study conducted by the Comptroller General of the United States under section 3(a).</text></subparagraph><subparagraph id="id5e6a92acf79a4f3b906381cc445beb84"><enum>(K)</enum><text>Any other recommendations to ensure the confidentiality, availability, and integrity of data residing on or in transit through commercial satellite systems only for the purpose described in subsection (b)(1).</text></subparagraph></paragraph></subsection><subsection id="iddf21e9883a0e4dde8da179a4f4e0c944"><enum>(d)</enum><header>Implementation</header><text>In implementing this section, the Secretary shall—</text><paragraph id="idaf64344ea2c641cd910437a8f40ed80b"><enum>(1)</enum><text>to the extent practicable, carry out the implementation in partnership with the private sector;</text></paragraph><paragraph id="idf5e2effb846b4567907bdb49a09ae1a5"><enum>(2)</enum><text>coordinate with—</text><subparagraph id="ide23723eb221540d1b4366a9d3f20d65f"><enum>(A)</enum><text>the Secretary of Homeland Security, the Office of the National Cyber Director, the National Space Council, the Director of the National Institute of Standards and Technology, and the head of any other agency with expertise relating to cybersecurity or satellite communications determined appropriate by the Secretary; and</text></subparagraph><subparagraph id="idb57e43daebd1419f9786bcc63c4911c3"><enum>(B)</enum><text>the heads of appropriate Federal agencies with expertise and experience in satellite operations, including the entities described in section 3(c) to enable the alignment of Federal efforts on commercial satellite system cybersecurity and, to the extent practicable, consistency in Federal recommendations relating to commercial satellite system cybersecurity; and</text></subparagraph></paragraph><paragraph id="id8a0f1827a7ef44de9b1e5d79e4b9e913"><enum>(3)</enum><text>consult with non-Federal entities developing commercial satellite systems or otherwise supporting the cybersecurity of commercial satellite systems, including private, consensus organizations that develop relevant standards.</text></paragraph></subsection><subsection id="idb8c2d62c94624059ac66898349edcd9b"><enum>(e)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of this Act, and every 2 years thereafter until the date that is 9 years after the date of enactment of this Act, the Secretary shall submit to the appropriate congressional committees a report summarizing—</text><paragraph id="idfde1e7bd14c1484e9205730f4bd7405c"><enum>(1)</enum><text>the general status of any partnership with the private sector described in subsection (d)(1);</text></paragraph><paragraph id="ideb40dfe8bd9544e3b337d713376126fc"><enum>(2)</enum><text>the results of consultations with a non-Federal entity described in subsection (d)(3);</text></paragraph><paragraph id="id2ad24d154a46419d8ae4ea25c1dd60bd"><enum>(3)</enum><text>the coordination carried out pursuant to subsection (d)(2);</text></paragraph><paragraph id="id9e82dc9c499349bfacc2cca47d9d3a97"><enum>(4)</enum><text>the establishment and maintenance of the clearinghouse pursuant to subsection (b);</text></paragraph><paragraph id="id9afa34122bd94a09aa639fd5ca32258b"><enum>(5)</enum><text>the recommendations consolidated pursuant to subsection (c)(1); and</text></paragraph><paragraph id="id5abfa2d12eeb484799f48ee22ee5c458"><enum>(6)</enum><text>general feedback received by the Secretary on the clearinghouse from non-Federal entities, including overall trends and any proposed changes to the clearinghouse as a result of the feedback.</text></paragraph></subsection></section><section id="id1073cff1b08847e896bdd9b32277c40d" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>5.</enum><header>Strategy</header><text display-inline="no-display-inline">Not later than 120 days after the date of the enactment of this Act, the Secretary, jointly with the National Space Council and the Office of the National Cyber Director, in coordination with the Secretary of Homeland Security, the Director of the Office of Space Commerce, the Director of the Office of Science and Technology Policy, and the heads of other relevant agencies, shall submit to the appropriate congressional committees a strategy to support coordination, information sharing, and voluntary best practices among Federal agencies and private sector stakeholders relating to the cybersecurity of commercial satellite systems, which shall include an identification of—</text><paragraph id="idacf8d06a5c374815ab24ae155de6f90c"><enum>(1)</enum><text>proposed coordination roles among relevant agencies; and</text></paragraph><paragraph id="idd4976d5de25e4664bba03170112a7dc2"><enum>(2)</enum><text>as applicable, the extent to which cybersecurity threats to commercial satellite systems are addressed in—</text><subparagraph commented="no" display-inline="no-display-inline" id="id37f1b9070ba943ba9068033726225a61"><enum>(A)</enum><text display-inline="yes-display-inline">critical infrastructure risk analyses and protection plans; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id467743a67606439b96242879ec59fcbb"><enum>(B)</enum><text display-inline="yes-display-inline">activities relating to commercial satellite systems.</text></subparagraph></paragraph></section><section id="id6332e39f0e04430f88f29994a62661ae" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>6.</enum><header>Rules of construction</header><text display-inline="no-display-inline">Nothing in this Act shall be construed to—</text><paragraph id="id56ed6c11441e45f8986496ee943e0b66"><enum>(1)</enum><text>designate commercial satellite systems or other space assets as a critical infrastructure sector;</text></paragraph><paragraph id="id02f68efa9a1648649b42fc73593d4ef5"><enum>(2)</enum><text>infringe upon or alter the authorities of the agencies described in section 3(c);</text></paragraph><paragraph id="ida1d67fd8d04240d98614a4ab35932f56"><enum>(3)</enum><text>authorize the development or implementation of any rulemaking or regulatory requirement, including by way of enforcement action or condition on any license or permit for a commercial satellite system; or</text></paragraph><paragraph id="id9ef8fcf0e9ce4688b5d7db6c8b287c4f"><enum>(4)</enum><text>modify or expand existing authorities of the Committee on Foreign Investment in the United States or the Committee for the Assessment of Foreign Participation in the United States Telecommunications Service Sector.</text></paragraph></section></legis-body><endorsement><action-date>September 14, 2026</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

