Hogan Lovells logo
  • Our people
  • What we do
    Sectors Practices Legal Tech
    • Through deep business and sector knowledge and cross-sector collaboration, we turn insight into impact - enabling clients to master change, stay ahead and seize opportunities in a fast-moving, highly regulated world.
      Our sector offering
    • Aerospace and Defense
    • Automotive and Mobility
    • Consumer
    • Education
    • Energy
    • Financial Institutions
    • Insurance
    • Life Sciences and Health Care
    • Manufacturing and Industrials
    • Private Capital
    • Real Estate
    • Sports, Media and Entertainment
    • Technology
    • Transportation and Logistics
    • Through deep business and sector knowledge and cross-sector collaboration, we turn insight into impact - enabling clients to master change, stay ahead and seize opportunities in a fast-moving, highly regulated world.
      Our sector offering
    • Corporate & Finance
    • Disputes
    • Global Regulatory
    • Intellectual Property
  • Case studies
  • Our thinking
    • Discover insights, analysis, and thought leadership that are vital for change. Success today requires actionable insights, perspectives that cut through complexity, and tools to navigate the evolving needs of your sector, shaping a stronger tomorrow.
      All Our thinking
    • All Our thinking
    • Comparative guides
    • Digital Client Solutions
    • Events and webinars
    • Podcasts

    Insights and Analysis

    AI-washing – when AI hype becomes a litigation risk

    Insights and analysis
  • ESG
  • Careers
Search Search
close
Search Search Search
lang-sel-icon English
  • Deutsch
  • English
  • Español
  • Français
  • 日本語
  • 中文
False
people-new
Mobile area
  • About us
    • Our difference
    • Where we are
    • Our history
    • Our values
    • Global management team
  • Where we are
    • Americas
    • Asia-Pacific
    • Europe, Middle East, and Africa
    • By region
    • By country
    • By Office
    • Our locations
    • Law Firm Network
  • Media center
    • Media contacts
    • Press releases
    • Awards & rankings
    • All
  • Events and webinars
  • Responsible Business
    • Overview
    • Diversity, Equity & Inclusion
    • Operating Sustainably
    • Strategic Themes and Partnerships
    • Pro Bono
    • Community Investment
    • Fundraising Partnerships
    • HL Business and Social Enterprise practice
    • Environmental, Social and Governance (ESG)
  • HL Inclusion
  • Alumni
LinkedIn
Youtube
twitter
Wechat
News

Breaking down state legislative efforts in telecom security

30 March 2026
Silhouette of an Indian Mobile Network Tower at Sunset
Bynder Desktop Image for mobile
wechat x linkedin
hogan-lovells-logo
Share by email
Enter email
Enter Subject
Cancel
Send
News
Breaking down state legislative efforts in telecom security
Chapter
  • Chapter

  • Chapter 1

    State legislative efforts
  • Chapter 2

    State enforcement efforts
  • Chapter 3

    State vs. federal: Conflicting or complementary?
  • Chapter 4

    Planning for compliance in a rapidly shifting landscape
  • Chapter 5

    Conclusion

Foreign adversaries and other malicious actors are increasingly targeting communications networks, data flows and connected technologies that underpin U.S. economic and national security. Security experts warn that cyber threats to critical infrastructure are expected to further intensify due to the current conflict in the Middle East.1 Despite political gridlock in many policy areas, there is broad bipartisan consensus in Washington that the U.S. faces growing cybersecurity, espionage, supply chain and other risks affecting critical telecommunications infrastructure. While the Trump administration and federal agencies have taken robust actions to strengthen national security safeguards across the technology and telecommunications ecosystem, the states have also asserted a role in telecom national security.

In many cases, these state-driven initiatives stand to exceed the scope of existing federal programs, creating new restrictions and compliance obligations for broadband providers, equipment manufacturers and other industry participants. The result is a rapidly evolving regulatory landscape in which companies must navigate state-by-state requirements atop federal frameworks.

Chapter 1

State legislative efforts

expanded collapse

Several states are pursuing their own measures to secure communications networks from malicious actors. One angle to address this threat is the proposal and adoption of laws designed to curb the use of Chinese-made equipment and services in state infrastructure, as well as equipment and services made by other foreign adversaries — including communications infrastructure.

State legislation on this topic commonly includes language on: prohibiting contracts and agreements with entities based in foreign adversary countries; imposing greater oversight on sales, transfers and investments by or with non-U.S.-domiciled entities; and adopting state-specific prohibited equipment or services lists, as well as state-specific obligations to remove and replace problematic equipment in networks.

Examples of existing and proposed state regimes

Colorado (enacted)

In 2024, Colorado passed S.B. 24-151, which mandates that all critical telecommunications infrastructure in the state exclude equipment manufactured by federally banned entities or any telecommunications equipment prohibited by the federal government. The law also requires that any existing infrastructure using prohibited equipment be removed and replaced.2

Arizona (pending)

In January, legislators proposed H.B. 2134, which would prohibit the use of software produced by Chinese companies in any critical infrastructure within the state.3

Nebraska (pending)

Lawmakers also proposed L.B. 1096 in January, which would ban software and network-connected technologies linked to foreign adversaries in critical infrastructure, require their removal and replacement, and restrict agreements that allow foreign principals to access or control critical systems. The bill also directs the attorney general to maintain a list of prohibited technologies.4

Wisconsin (pending)

Lawmakers proposed S.B. 651 in 2024, which would direct that telecommunications providers maintaining critical infrastructure containing equipment from a foreign principal or any federally prohibited equipment must remove that equipment from the state's critical systems.5

Chapter 2

State enforcement efforts

expanded collapse

Enforcement is another tool that states are using to address cyber risk in communications networks and equipment.

For example, in 2024 and 2025, multiple states — Connecticut, Delaware, Illinois, Indiana, Maine, Massachusetts, New York, Oregon, Pennsylvania and Vermont — as well as the District of Columbia, entered into memoranda of understanding and enforcement partnerships with the Federal Communications Commission to enable joint oversight and compliance.6

So far this year, Texas stands out as the most aggressive state pursuing infrastructure risks related to foreign adversaries. Under Attorney General Ken Paxton, Texas filed multiple lawsuits in February against communications equipment manufacturers — including TP-Link Systems Inc., Anzu Robotics LLC and Lorex Technology Inc. — alleging misleading representations, adversarial foreign ownership ties and vulnerabilities in digital infrastructure that may expose consumers to foreign state influence.7

The state's S.B. 17 legislation further expands oversight, imposing strict requirements on entities with potential foreign adversary connections and mandating compliance measures for telecom infrastructure in Texas.

Collectively, these examples demonstrate that state-level scrutiny is no longer isolated or symbolic — it is active, legally consequential and often coordinated with federal enforcement, creating heightened compliance risk for any entity operating across multiple jurisdictions.

Chapter 3

State vs. federal: Conflicting or complementary?

expanded collapse

Many recent state proposals mirror or build on federal efforts to address national security risks from foreign adversaries in critical infrastructure and technology supply chains. But variations among federal and state regimes risk regulatory fragmentation and, for businesses operating across multiple states, complicate compliance strategies.

These types of variations within federal and state regimes can be seen in the following areas.

Prohibited equipment lists

While the FCC maintains the covered list of communications equipment and services that are deemed to pose an unacceptable risk to the national security of the U.S., states are contemplating creating their own lists of prohibited equipment and vendors. State lists may impose sanctions on entities and products that are not otherwise subject to federal restrictions.

Rip and replace obligations

The FCC administers the Secure and Trusted Communications Networks Reimbursement Program, commonly known as "rip and replace," which supports the removal and replacement of certain Chinese-manufactured telecommunications equipment from U.S. networks.8

Many state proposals differ substantially from the federal program in terms of participation being mandatory versus voluntary, the equipment targeted, reporting obligations and reimbursement mechanisms.

Scope of affected entities

Federal requirements primarily apply to broadband providers, but some state proposals extend obligations to any entity with access to telecom infrastructure, including utilities, contractors, suppliers and other personnel involved in maintaining networks.

Investment reviews

The federal government reviews transactions involving foreign entities and oversees of inbound investments through the Committee on Foreign Investment in the United States.

This authority has expanded in recent years through the Foreign Investment Risk Review Modernization Act, which broadened CFIUS jurisdiction to include noncontrolling investments and real estate transactions near sensitive facilities, and established mandatory filing requirements for certain transactions involving critical technologies, infrastructure or data.

State-specific regimes may have overlapping or unique triggers, requirements and timelines for review.

Employer obligations

Some states would require enhanced background checks for employees with access to state infrastructure. The FCC does not have rules on this topic.

Chapter 4

Planning for compliance in a rapidly shifting landscape

expanded collapse

Due to increasing federal activity and interest from the states, telecom providers and industry participants must now design compliance strategies around an evolving patchwork of requirements.

There is no one-size-fits-all solution for efficiently mitigating risk and liability. However, at a minimum, companies should consider the following advice.

Develop robust and pressure-tested internal controls.

The rapid expansion of restrictions and obligations by both federal and state authorities necessitates that companies create a methodical, centralized compliance program. Key elements of such a program may include:

  • Adopting a gating process to ensure all projects, vendors and employees undergo compliance reviews before approval;
  • Conducting an inventory of network infrastructure, equipment and services that identifies their geographic reach within or across states;
  • Vetting suppliers and contractors, including for foreign owners or interest holders, personnel screening procedures, and compliance policies;
  • Identifying employees and third parties with access to critical infrastructure;
  • Developing enterprise-wide cyber and physical security policies, which may include centralized training, role-based access procedures, internal vetting and third-party penetration testing and audits; and
  • Retaining documentation and records demonstrating compliance and best efforts.

Allocate responsibility for filing requirements and deadlines.

Differing federal and state regimes impose filing obligations with varying requirements and cadences. The legal team should identify and track its obligations to ensure that requirements are met and that enforcement penalties are avoided.

Monitor state-by-state developments.

Given the interconnected nature of the industry, companies operating nationwide may need to comply with the strictest requirements across all states. In addition, the likelihood of a foreign vendor or supplier being banned in one state increases significantly when that entity is flagged in other states.

Check for blind spots.

It is not a given that state-level requirements will only attach to entities regulated by the federal government. Not all states are choosing to regulate in the same way. Companies should analyze enacted laws in any state where they operate to verify whether they fall within the law's scope and face any new requirements.

Chapter 5

Conclusion

expanded collapse

As cyber threats grow more complex amid geopolitically uncertain times, the president, federal agencies and now states are taking stronger action to protect critical infrastructure, including communications networks.

In some cases, state policymakers are considering requirements that reach beyond existing federal safeguards or diverge from them. Companies that proactively track this activity — at the federal and state levels — and design nimble compliance strategies will be best positioned to succeed in this rapidly changing landscape.

 

This article was originally published on Law360 on March 23, 2026.

 

Authored by Katy Milner, Warren Kessler, and Jaclyn Rosen.

References

1 Joint Advisory – Middle East Conflict and Critical Infrastructure (Mar. 2026), available at https://business.cch.com/CybersecurityPrivacy/isaciranadvisory031226.pdf.

2 Colo. Rev. Stat. § 24-33.5-1624(2)(a)–(2)(b)(I).

3 H.B. 2134, 57th Leg., 2d Reg. Sess. (Ariz. 2026).

4 L.B.1096, 119th Leg., 2d Reg. Sess. (Neb. 2026).

5 S.B. 651, 2025–26 Reg. Sess. (Wis. 2026).

6 Press Release, FCC, FCC Privacy & Data Protection Task Force Launches First-Ever Enforcement Partnerships With State Attorneys General (Dec. 6, 2023), https://tinyurl.com/5x53jhck; Press Release, FCC, FCC Privacy & Data Protection Task Force Announces Ongoing Initiatives to Strengthen Enforcement Efforts Through Increased Technical Expertise & Cooperation (Mar. 26, 2024), https://tinyurl.com/4yd822kp; Press Release, FCC, FCC Now Partnering With Ten State Attorneys General on Privacy Protection (Oct. 21, 2024), https://tinyurl.com/5yfeub8d; Fed. Commc'ns Comm'n, Partnerships, https://tinyurl.com/45reewj2 (last visited Mar. 12, 2026).

7 See, e.g., State of Texas vs. Lorex Corporation and Lorex Technology, Inc., No. 494-01112-2026 (Tex. Dist. Ct. Collin Cnty. filed Feb.19, 2026); State of Texas v. Anzu Robotics, LLC, No. 429-01089-2026 (Tex. Dist. Ct. Collin Cnty. filed Feb. 18, 2026); State of Texas v. TP Link Systems Inc., No. 471-01066-2026 (Tex. Dist. Ct. Collin Cnty. filed Feb. 17, 2026).

8 See Fed. Commc'ns Comm'n, Supply Chain Reimbursement Program, https://tinyurl.com/mvpfub3v (last visited Mar. 11, 2026).

Contacts

bio-image

Katy J. Milner

Partner

location Washington, D.C.

email Email me

bio-image

Warren A. Kessler

Senior Associate

location Washington, D.C.

email Email me

bio-image

Jaclyn P. Rosen

Senior Associate

location Washington, D.C.

email Email me

View more

Related topics

  • Technology
  • Telecommunications and Internet
Load more

Related countries

  • United States
Load more

Related keywords

  • Telecom
  • Infrastructure
  • national security
  • state legislation
  • state enforcement
  • rip-and-replace
  • FCC enforcement
  • Federal Communications Commission
  • communications networks
  • supply chain
  • broadband providers
  • equipment manufacturers
Load more

Articles you may be interested in

image_1
Insights and Analysis

Building an ultra-wideband product? You may need an FCC waiver before you can sell it

07 April 2026

image_1
Insights and Analysis

Life Sciences & Health Care Horizons 2026

11 March 2026

image_1
News

Fifth Circuit rejects FCC’s TCPA written‑consent rule for marketing calls

03 March 2026

image_1
News

District Courts increasingly divided on whether the TCPA allows Do-Not Call claims for texts

02 March 2026

image_1
Insights and Analysis

Fiber to the community: How smart cities really get built - with Jeff Bankston (Underline) and David Fritz (Hogan Lovells)

17 February 2026

image_1
News

Shaping the future of AI security: NIST seeking input on agent identity & authorization

10 February 2026

image_1
News

Doing Business in the United States 2026

10 February 2026

image_1
News

Insights from CES 2026

06 February 2026

image_1
Insights and Analysis

Connected Life Brochure 2026

15 January 2026

left_arrow
right_arrow

View more insights and analysis

arrow
arrow
"" ""
Digital Client Solutions
Empowering you to lead change through our digital solutions.
Learn more

Register now to receive personalized content and more!

 

Register
close
See benefits
Register
Hogan Lovells logo
Contact us
Quick Links
  • About us
  • Where we are
  • Media center
  • Responsible Business
  • HL Inclusion
  • Alumni
  • Contact us
  • Our thinking
  • Cookies
  • Disclaimer
  • Fraudulent and Scam Emails
  • Legal notices
  • Modern Slavery Statement
  • Our thinking terms of use
  • Privacy
  • Remote Working
  • RSS
  • Sitemap
Connect with us
LinkedIn
Youtube
Twitter
Wechat

© 2026 Hogan Lovells. All rights reserved. "Hogan Lovells" or the “firm” refers to the international legal practice that comprises Hogan Lovells International LLP, Hogan Lovells US LLP and their affiliated businesses, each of which is a separate legal entity. Attorney advertising. Prior results do not guarantee a similar outcome.

Subscribe to Our thinking
Connect with us
LinkedIn
Youtube
Twitter
Wechat