Commerce Department gets new cybersecurity office—but who sets the rules?
S. 2049 — NTIA Policy and Cybersecurity Coordination Act · Filed by John Hickenlooper (D-CO) · 3 cosponsors · Introduced Jun 12, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill creates a new Office of Policy Development and Cybersecurity within the National Telecommunications and Information Administration (NTIA) and redesignates an existing Associate Administrator position to lead it. The office will develop market-based policies on internet access, communications, cybersecurity, and digital innovation; conduct studies on how Americans use digital services; coordinate multistakeholder cybersecurity guidance; and advise federal agencies and Congress on telecom and cybersecurity policy.
Why we flagged it
The bill's core function is to establish a new administrative office within NTIA to coordinate national policy on communications, cybersecurity, and digital innovation. It is primarily a structural/governance measure, not a substantive policy change, though it signals a shift toward market-based approaches in telecom and cybersecurity regulation.
What the text implies
- The office's mandate to 'develop, analyze, and advocate for market-based policies' may bias policy recommendations toward deregulation and industry self-regulation over consumer protection or mandatory security standards.
- The emphasis on 'multistakeholder processes' without explicit representation requirements for consumer advocates or public-interest groups could allow industry to dominate consensus-building on cybersecurity standards.
The full analysis lists 4 implications of this text.
Who stands to gain
telecommunications companies; software and hardware vendors; cybersecurity service providers