United States

North America

US telecom security regulation is distributed across the FCC (rulemaking authority), CISA (operational guidance), NIST (technical standards), and DOJ (CALEA enforcement). The regulatory posture on signaling security has hardened substantially since 2016.

Regulator: FCC + CISA + NIST + DOJ

Primary frameworks: CSRIC IV/VII/VIII reports, FCC signaling security rulemaking, CALEA, NIST SP 800-187

CSRIC signaling security

The FCC's Communications Security, Reliability, and Interoperability Council (CSRIC) has produced signaling-security best-practice reports since 2016. CSRIC VII and VIII cover SS7, Diameter, and 5G signaling with concrete category-based screening recommendations.

CALEA obligations

The Communications Assistance for Law Enforcement Act imposes lawful-intercept obligations. Modernization to 5G and IMS anchoring is ongoing; VoLTE and VoNR bring the LI anchor decision into scope for every operator.

FCC rulemaking

The FCC has active rulemaking on SIM swap and port-out fraud (2023 order), signaling-security reporting, and 5G security. Notice-and-comment cycles are the mechanism operators track.

NIST guidance

NIST SP 800-187 provides guidelines to mobile-network security. NIST also drives PQC migration standards affecting SUCI ECIES.

Key takeaways

  • CSRIC is best-practice, not binding — but the FCC increasingly cites it as the reference for "reasonable" security.
  • The 2023 SIM-swap order created hard rules on port-out identity verification.
  • CALEA modernization is the biggest 5G compliance cost item for many US operators.