Back to news

Satellite Cybersecurity Act Clears Three Committees in Three Months

Share:
Satellite Cybersecurity Act Clears Three Committees in Three Months

The Satellite Cybersecurity Act of 2025 cleared the Senate Energy and Natural Resources Committee on July 29, its third committee markup in three months, moving the bill closer to a Senate floor vote than at any point in its four-year legislative history.

What the bill would actually do

Introduced by Senators Gary Peters (D-MI) and John Cornyn (R-TX), the legislation is deliberately narrow. It does not mandate new security requirements, impose fines, or designate satellites as critical infrastructure. Instead it directs the Department of Commerce to build and maintain a publicly accessible online clearinghouse consolidating voluntary cybersecurity recommendations for commercial satellite operators, pulling guidance from industry and from agencies including CISA and the Space Force. The bill also tasks the Government Accountability Office with a review of existing federal efforts to support satellite security, and requires Commerce and the National Cyber Director to develop a coordinated federal strategy within 120 days of enactment. The Congressional Budget Office estimated the cost at roughly $14 million over five years, equivalent to six additional Commerce Department staff.

Four years of stalling, three months of movement

This is the third iteration of a bill Peters has pushed since 2022. The previous two versions each won committee approval — once in the Homeland Security panel in 2022 and again in 2023 — before dying without a floor vote. The Record noted at reintroduction in December 2025 that both earlier attempts cleared committee but failed to advance. The current version has moved faster: the Senate Commerce Committee passed it on April 14 by voice vote without objection alongside the Secure Space Act, according to Broadband Breakfast; the House Oversight Committee reported it on May 20; and the Senate Energy and Natural Resources Committee added its approval on July 29. Three committees in 107 days is a different pace than the bill has maintained at any earlier point.

The gap it is meant to close

The commercial satellite sector currently has no single federal cybersecurity regulator and no unified point of access for guidance. Relevant material is scattered across NIST, CISA, the FCC, and Space Force publications that few small operators have the bandwidth to track. A July 2026 commentary in Federal News Network by Comtech's Daniel Gizinski put it directly: the information exists but the fragmentation makes it effectively inaccessible for operators outside the largest primes. The clearinghouse the bill mandates is a consolidation play, not a new regulatory regime. Peters has pointed repeatedly to a 2025 study finding that roughly half of surveyed commercial satellite signals were unencrypted despite carrying sensitive data, a figure the Satellite Industry Association and the Information Technology Industry Council cited in their letters of support for the legislation.

What still has to happen

Committee clearance is not passage. The bill now needs floor time in a Senate calendar that has shown little appetite for moving individual technology measures outside of must-pass vehicles. Peters is retiring in January 2027 when his second term ends, which gives the legislation a natural deadline: if it does not reach a floor vote before the end of the 119th Congress, it would need to be reintroduced from scratch for the fourth time. Whether the multi-committee momentum translates into a floor slot, or whether the bill attaches to a larger authorization package, is the question that will determine whether this round ends differently from the last two.

Legislative developments reported by The Record, Broadband Breakfast, and Senator Peters' office.