The Federal Communications Commission voted 2–1 on November 20, 2025, to rescind a Biden-era interpretation of federal surveillance law and withdraw a related cybersecurity rulemaking for telecommunications providers. The action followed the Salt Typhoon campaign, which U.S. officials and the FCC associated with China-sponsored intrusions into communications networks.
Republican commissioners Brendan Carr and Olivia Trusty said the earlier framework exceeded the FCC’s legal authority under the Communications Assistance for Law Enforcement Act (CALEA) and was too prescriptive to improve security. Democratic Commissioner Anna Gomez said repealing it removed the agency’s only meaningful post–Salt Typhoon accountability framework. The vote did not eliminate every cybersecurity or privacy obligation that applies to phone, broadband, or internet companies.
What the FCC voted to rescind
The FCC’s FCC 25-81 Order on Reconsideration, adopted November 20 and released November 21, 2025, took two principal actions in PS Docket No. 22-329:
- It rescinded the FCC’s January 2025 declaratory ruling.
- It withdrew the accompanying notice of proposed rulemaking (NPRM).
The January action had interpreted CALEA as supporting broader obligations for telecommunications providers to secure their networks against unlawful access or interception and to adopt additional cybersecurity practices. The November order called that interpretation unlawful and ineffective. In practical terms, the FCC removed that specific framework; it did not repeal every security, privacy, breach-reporting, or critical-infrastructure requirement that may apply to a carrier.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhy CALEA was central to the dispute
CALEA generally requires telecommunications carriers to maintain capabilities that allow legally authorized government surveillance. The January FCC ruling treated that statute as a basis for wider network-security requirements. Carr and Trusty concluded that Congress had not given the FCC authority to use CALEA as a general cybersecurity mandate.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
That statutory question is separate from whether stronger security would be desirable. The majority’s position was that an agency cannot impose technically broad obligations without a clear legal foundation, even after a serious cyber incident. The order is the FCC’s legal conclusion, not a final judicial ruling settling every issue surrounding CALEA.
What Salt Typhoon changed about the stakes
Salt Typhoon was described by U.S. officials and the FCC as a China-sponsored cyber-espionage campaign targeting communications networks. Reporting and FCC statements linked the activity to compromises of U.S. telecommunications companies and systems associated with lawful wiretapping. That raised concerns beyond ordinary customer-data theft, including surveillance of communications, access to sensitive government-related targets, and the security of infrastructure used for lawful intercepts.
The reported scale depends on the definition used. TechCrunch reported more than 200 telecommunications companies were involved, while Carr’s statement referred to at least eight U.S. communications companies and effects spanning dozens of countries. Those figures should not be treated as a single definitive count of affected U.S. carriers.
Why the FCC majority supported repeal
Carr and Trusty argued that the January framework was legally unsupported, insufficiently targeted, and not technically clear enough to produce better security. They also said rigid requirements could create compliance confusion and divert resources from more effective defenses.
Carr’s statement said the FCC and carriers had pursued voluntary measures, including:
- Accelerating patches for outdated or vulnerable equipment.
- Reviewing and tightening access controls.
- Disabling unnecessary outbound connections.
- Improving threat hunting.
- Expanding cybersecurity information sharing.
The FCC also cited a Council on National Security, submarine-cable security work, restrictions involving “bad labs” in its equipment-authorization program, and direct engagement with communications providers in a November 2025 release. These initiatives differ in legal status: an agency structure, voluntary commitment, public guidance, proposed rule, and binding regulation are not interchangeable.
What the dissent and critics said
Gomez’s dissent argued that Salt Typhoon showed existing incentives were inadequate. She said the rescinded action would have created clear duties and a basis for accountability after a breach. Voluntary cooperation can improve security, she acknowledged, but does not guarantee a common minimum standard or give regulators a clear test for whether a carrier took reasonable precautions.
Her objection was also practical: the FCC’s other initiatives did not necessarily address the vulnerabilities exploited by Salt Typhoon, and consumers generally cannot see or compare a carrier’s voluntary security commitments. The majority disputed that enforceable, prescriptive rules were the right or lawful solution.
NCTA, the telecommunications industry’s representative group, supported the rescission, according to TechCrunch. Its position was that overlapping mandates, unclear technical requirements, legal uncertainty, and compliance costs could make security less effective. That is an industry policy argument, not independent evidence that voluntary arrangements are sufficient.
Rank #3
- INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
- UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
- IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
- CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
- COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.
What cybersecurity obligations remain
The vote did not leave carriers free of regulation. Existing duties can arise under multiple authorities, depending on the provider, service, and incident:
- Customer Proprietary Network Information (CPNI): FCC rules require telecommunications carriers and interconnected VoIP providers to protect CPNI and file annual certifications. See the FCC CPNI portal and its enforcement advisory.
- Section 222 and other FCC rules: Existing privacy and security requirements from separate FCC proceedings remain unless separately changed.
- Federal and state obligations: Privacy, breach-notification, securities-disclosure, and critical-infrastructure rules may apply based on the company and event.
- Sector-specific requirements: A provider’s corporate structure and services can trigger additional obligations.
CPNI protections concern sensitive customer information; they are not a comprehensive, prescriptive standard for hardening every part of a carrier’s network. A company can also satisfy an incident-reporting duty without meeting a broad preventive-security baseline.
Free tools Windows power users keep installed
One-click scans. No signup required.
What the decision means for carriers and consumers
Immediate consumer effects
There is no documented basis for saying the vote immediately changed a customer’s phone, broadband, or internet service. The action primarily changed the federal accountability framework for network security, not the technology delivered to subscribers on the day of the vote.
Longer-term systemic risk
Carrier weaknesses can affect call metadata, location information, internet traffic, authentication systems, and lawful-intercept infrastructure. Under a voluntary model, consumers usually cannot determine whether a provider has implemented the measures described by the FCC, and smaller or regional providers may have different resources from national carriers.
Rank #4
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
The policy trade-off
| Approach | Potential benefits | Potential risks |
|---|---|---|
| Binding cybersecurity rules | Common baseline, auditable duties, and a clearer enforcement path after an incident. | Rules may become outdated, exceed statutory authority, impose costs, or divert effort from higher-priority threats. |
| Voluntary cooperation | Faster adaptation, closer government-carrier coordination, and less risk of obsolete technical mandates. | Uneven implementation, limited transparency, unclear enforcement, and weaker incentives for providers with fewer resources. |
The record does not establish that the January proposal would have prevented Salt Typhoon, nor that rescission itself caused a new breach. It establishes a disagreement over whether enforceable rules or flexible cooperation is the more lawful and effective security model.
Why “Trump’s FCC” needs a qualification
The vote was taken by Trump-appointed commissioners Carr and Trusty, with Gomez dissenting. Donald Trump did not cast a vote. “Trump’s FCC” is political shorthand for the commission’s composition and policy direction, not a description of the president personally voting on FCC 25-81.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat to watch next
- Whether the FCC creates a new telecom cybersecurity rulemaking with a different statutory basis.
- How the agency oversees or measures the voluntary commitments it cited.
- Congressional legislation addressing carrier security or lawful-intercept systems.
- Court challenges and any later rulings on the scope of CALEA.
- Further disclosures about Salt Typhoon and the carriers or systems affected.
Frequently Asked Questions
Did the FCC eliminate all cybersecurity rules for phone and internet companies?
No. It rescinded a January 2025 CALEA interpretation and withdrew a related NPRM. CPNI protections, Section 222-related duties, other FCC requirements, and applicable state and federal obligations remain.
Would the rescinded rules have stopped Salt Typhoon?
The available record does not show that the proposed requirements would have prevented the intrusion. The dispute concerns the legal authority and likely effectiveness of the framework, not a proven counterfactual.
Are voluntary carrier commitments legally equivalent to FCC rules?
No. Voluntary commitments may guide or coordinate security improvements, but they do not automatically create the uniform, enforceable duties imposed by a binding regulation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




