The Satellite Cybersecurity Act of 2025 would direct the Comptroller General to study how the federal government supports cybersecurity for commercial satellite systems and to report findings to Congress within two years. The study would examine federal efforts, available public resources, the role of commercial satellites in critical infrastructure, federal reliance on these systems, foreign ownership or foreign-based infrastructure risks, interagency coordination, and recommendations for further federal action. The bill also requires a briefing to Congress and allows the report to include a classified annex.
The bill further directs the Department of Commerce, working with the FCC and CISA, to create and maintain a public online clearinghouse for commercial satellite cybersecurity resources. That clearinghouse would consolidate voluntary cybersecurity recommendations and include materials for system developers and operators, with specific support for small businesses. The bill also requires Commerce to consolidate best-practice recommendations covering engineering, monitoring, resiliency, command-and-control protection, jamming and spoofing defenses, supply chain risk, foreign ownership and foreign-located infrastructure risks, and data confidentiality, integrity, and availability.
In addition, the bill requires Commerce, the National Space Council, and the Office of the National Cyber Director to submit a federal strategy within 120 days describing agency roles and how satellite cybersecurity threats are addressed in critical infrastructure risk analyses and protection plans. Commerce must also provide recurring reports on its coordination efforts, private-sector partnerships, and feedback on the clearinghouse. The bill expressly states that it does not designate commercial satellite systems as a critical infrastructure sector or alter existing agency authorities.
The bill’s impact on state law is minimal because it is a federal reporting, coordination, and guidance measure rather than a preemption or regulatory mandate on states. Its practical effect would be on federal agencies, commercial satellite operators, satellite manufacturers, ground-station operators, and related private-sector entities, especially small businesses and firms with foreign ownership or foreign-based infrastructure. It would likely increase visibility into satellite cyber risks and encourage more standardized federal guidance and information sharing.
Overall sentiment appears favorable and bipartisan, as reflected by introduction from Senators Peters and Cornyn and the committee action ordering the bill reported favorably with an amendment in the nature of a substitute. No vote record or transcript indicates organized opposition. The main potential points of contention are the bill’s attention to foreign ownership and foreign infrastructure, the possibility of handling controlled unclassified information through the clearinghouse, and whether the federal government should expand its role in coordinating cybersecurity guidance without formally classifying satellites as critical infrastructure.
This is a federal oversight and coordination bill that does not directly amend state statutes or impose state-level mandates. It would require new federal studies, strategies, reports, and a public cybersecurity clearinghouse for commercial satellite systems, while directing Commerce and other agencies to consolidate voluntary guidance and coordinate interagency efforts. The bill’s practical impact would fall on federal agencies and the commercial satellite industry, including operators, ground infrastructure providers, and small businesses, with particular attention to cybersecurity risks, foreign ownership, and supply-chain vulnerabilities.
The available context suggests generally positive sentiment. The bill was introduced by Senators Peters and Cornyn and was ordered reported favorably by the Senate Committee on Commerce, Science, and Transportation with an amendment in the nature of a substitute. There are no recorded votes or transcript excerpts showing opposition, so the public record provided indicates committee-level support and a consensus-oriented approach focused on information gathering and coordination rather than regulation.
No formal opposition is shown in the provided materials, but the bill’s most likely areas of contention are its emphasis on foreign ownership and foreign-located infrastructure, the handling of controlled unclassified information in a public-facing clearinghouse, and whether federal agencies should take on additional coordination responsibilities. Some stakeholders may also be sensitive to the bill’s discussion of critical infrastructure risk analyses, even though the bill expressly says it does not designate commercial satellite systems as a critical infrastructure sector or alter existing agency authorities.