Telecommunications
FCC, CPNI, and network security requirements
Reporting threshold in 47 CFR 4.9 for wireline, wireless, cable and interconnected VoIP providers.
Telecommunications providers maintain critical communications infrastructure under FCC regulation and national security requirements. Thalorin supports telecom compliance with CPNI protection, network security requirements, and the emerging supply chain security mandates affecting the sector.
The FCC withdrew its own post-Salt Typhoon security mandate on 20 November 2025, voting 2-1 to rescind the January 2025 declaratory ruling that had read section 105 of CALEA as an affirmative duty to secure carrier networks against unlawful access, and withdrawing the accompanying proposal for annual certification of cybersecurity and supply chain risk management plans. The reversal rested on commitments carriers made directly, not on a finding that the threat had receded. A programme built for a coming FCC security rule now has no rule beneath it.
What remains is procedural, and the clocks do not agree. Part 4 requires outage notification within 120 minutes of discovery, an initial report within 72 hours and a final report within 30 days. The CPNI rules in subpart U of Part 64 require notification of a breach to the Secret Service and the FBI no later than seven business days after a reasonable determination that one occurred. And 47 CFR 1.20003 requires a report to the affected law enforcement agencies within a reasonable time of discovering that a lawful interception was compromised — the one duty here that carries no number. One intrusion can start all three, and none of them measures the same event.
The consistently underestimated asset is the interception plane itself. CALEA obliges a carrier to maintain a capability that by design exposes call content and call-identifying information, and 47 CFR 1.20003 requires a named senior officer accountable for it, written policies defining appropriate authorisation, and an appendix carrying that officer's round-the-clock contact details. Salt Typhoon showed what a patient adversary does with that capability from the inside. Those systems are commonly run by a small team under a separate confidentiality regime, outside the enterprise vulnerability programme, and represented in the compliance record by a filing rather than by evidence.
Thalorin models that plane as its own asset class rather than as part of the corporate network, with the CALEA policies, the designated officer and the records required by 47 CFR 1.20004 bound to the systems they govern. The annual CPNI certification filed with the Enforcement Bureau by 1 March is produced from the same state, and one determination raises the Part 4, subpart U and CALEA obligations together, each against its own clock.
Critical infrastructure is under constant threat
Three reporting duties, three triggers
Part 4 starts on discovery of service loss, CPNI notification on a determination that customer information was taken, the CALEA report on discovery of a compromised interception. Two carry a numeral, one does not, and satisfying any does nothing for the others.
The interception capability is in scope
CALEA requires carriers to maintain access that reveals content and call-identifying information. Those systems are frequently administered outside the enterprise security programme, which is precisely where an intruder wants them.
A withdrawn mandate, an intact liability
Rescinding the CALEA declaratory ruling removed a prospective FCC security rule. It removed nothing from 47 U.S.C. 222, from Part 4 outage reporting, or from the CALEA rules in 47 CFR 1.20003.
Provenance below the vendor name
Equipment on the Covered List cannot obtain an equipment authorization under 47 CFR 2.903, and the prohibition reaches assemblies incorporating a covered module. Tracking the supplier is not tracking the equipment.
How Thalorin helps
CPNI compliance automation
Hold the subpart U obligations as one state — disclosure limits, approval records, safeguards, breach notification — and produce the annual officer certification filed under EB Docket No. 06-36 from it.
FCC security requirements
Track what survived the November 2025 rescission: Part 4 notification at 120 minutes, initial report at 72 hours, final report at 30 days, each tied to its triggering event.
Network infrastructure security
Map controls to NIST CSF 2.0 while keeping signalling, provisioning and interception as separate boundaries, so a control proved on the IT estate is not credited to a network element.
Supply chain risk for telecom
Carry equipment provenance against the Covered List under 47 CFR 1.50002, including modules inside authorised assemblies, so a part that can never be authorised surfaces during procurement rather than at type approval.
5G security compliance
Bind vendor assurance evidence — 3GPP TS 33.501 requirements, GSMA NESAS audit results — to the network functions actually deployed rather than to a product line.
CALEA compliance support
Keep the 47 CFR 1.20003 policies, designated officer and 24-hour contact appendix as live records, with interception records under 47 CFR 1.20004 held to the same retention discipline.
Telecommunications: common questions
Does the FCC still require a cybersecurity risk management plan?
No. On 20 November 2025 the FCC voted 2-1 to rescind the January 2025 declaratory ruling interpreting section 105 of CALEA and to withdraw the accompanying proposal, which would have required annual certification of such a plan. Neither is in force. The Commission pointed instead to commitments carriers had made directly, so a carrier that made them now answers for them outside the regulatory process.
How fast must a carrier report a network outage to the FCC?
Under 47 CFR 4.9, notification is due within 120 minutes of discovering a reportable outage, an initial report within 72 hours and a final report within 30 days, filed through the Network Outage Reporting System. Thresholds vary by service — 900,000 user-minutes of lost telephony or paging, for instance. An outage potentially affecting a 911 or 988 special facility is reportable on its own, and separately requires notice to that facility within 30 minutes of discovery.
Is a CPNI breach notification the same as an outage report?
No, and they rarely coincide. Outage reporting turns on service loss against numeric thresholds. CPNI notification under 47 CFR 64.2011 turns on a reasonable determination that customer information was accessed without authorisation, and goes to the Secret Service and the FBI no later than seven business days after that determination. Read the current rule, not the 2024 expansion of it: those amendments were delayed indefinitely when published and have never been given an effective date, and the Sixth Circuit panel decision upholding them was vacated on 31 July 2026 when the court granted rehearing en banc.
Does CALEA impose a general duty to secure the network?
Not as the FCC now reads it. Section 105 requires a carrier to ensure interceptions occur only with lawful authorisation and the affirmative intervention of one of its officers or employees. The January 2025 ruling extended that into a general security duty and was rescinded in November 2025. The implementing rules stand: 47 CFR 1.20003 still requires a designated senior officer, written authorisation policies, a law enforcement contact appendix reachable at any hour, and a report to the affected law enforcement agencies when an interception is compromised.
What does the Covered List actually prohibit?
Equipment authorization. Equipment and services on the Covered List, published by the Public Safety and Homeland Security Bureau under 47 CFR 1.50002, cannot obtain an authorization under 47 CFR 2.903, and the prohibition extends to equipment incorporating covered items. It is not by itself an order to remove installed gear, which is why removal obligations are a separate question and why provenance must be tracked at module level.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Telecommunications.
See how one evidence artifact satisfies Telecommunications requirements alongside every other framework you carry.