S-3404-119
Passed Senate with an amendment by Unanimous Consent.
Sponsored by Gary Peters (D-MI)
What it does
This bill would require the Comptroller General to study federal efforts supporting the cybersecurity of commercial satellite systems and report to Congress within two years. It would also direct the Secretary of Commerce, working with other agencies, to build a public online clearinghouse of voluntary cybersecurity recommendations for satellite operators and to submit a coordination strategy, while explicitly barring any new regulations, enforcement actions, or licensing conditions.
Who benefits
Commercial satellite operators, including small satellite businesses, who would gain access to consolidated voluntary cybersecurity guidance and a public resource hub; federal agencies (Commerce, DHS, NASA, FCC, DOD) that would gain a coordination mechanism; and Congress, which would receive a comprehensive report on federal satellite cybersecurity gaps to inform future policy.
Who is hurt
No group bears a significant direct burden, since the bill creates only voluntary guidance and reporting requirements with no mandates, fees, or enforcement authority; the Department of Commerce and GAO would bear modest administrative and staffing costs to produce the study, clearinghouse, and reports, and satellite companies face no new compliance obligations.
Supporters argue
Supporters argue that commercial satellites increasingly underpin critical infrastructure like GPS, communications, and weather forecasting, yet cybersecurity practices vary widely across an industry with limited federal guidance. They contend that a voluntary, publicly available clearinghouse and coordinated federal strategy would help especially small satellite companies adopt baseline protections against jamming, spoofing, and hijacking without imposing costly new regulations that could slow innovation.
Opponents argue
Opponents argue that the bill's explicit prohibition on new regulations or enforcement means it may amount to a paperwork exercise that produces studies and voluntary guidance without addressing documented vulnerabilities, such as foreign ownership risks or supply chain weaknesses, in any binding way. They contend that if satellite cybersecurity is truly a critical infrastructure concern, purely voluntary measures may prove insufficient given the industry's uneven adoption of existing best practices.
Constitutional context
This bill raises no significant constitutional question; it directs executive branch reporting and creates a voluntary information-sharing resource under Congress's Article I authority to regulate interstate and foreign commerce, including satellite communications licensed under federal authority.
Checks and balances
Congress directs the executive branch (Commerce Department, GAO, DHS, and other agencies) to study and report, but the bill explicitly withholds any new regulatory or enforcement authority, preserving the existing balance between agencies and industry.
Historical precedent
Similar voluntary information-sharing and clearinghouse models have been used in other federal cybersecurity efforts, such as CISA's public-private information sharing programs for critical infrastructure sectors, though no directly analogous satellite-specific statute has previously been enacted.