Review of Submarine Cable Landing License Rules and Procedures To Assess Evolving National Security, Law Enforcement, Foreign Policy, and Trade Policy Risks
In this document, the Federal Communications Commission (Commission or FCC) adopted a Report and Order that updates the Commission's submarine cable licensing process and adopts rule changes to protect critical U.S. communications infrastructure against foreign adversary threats, specifically those posed by an entity that is owned by, controlled by, or subject to the jurisdiction or direction of a foreign adversary. The Report and Order adopts a requirement for certain licensees to file an annual report about the licensee, submarine cable system ownership, and submarine cable operations. The Report and Order adopts a one-time information collection for licensees to identify, among other things, how many entities currently own or operate submarine line terminal equipment (SLTEs) on existing licensed cable systems. The Report and Order also requires applicants and licensees to certify that they have created, updated, and implemented a cybersecurity and physical security risk management plan and requires applicants to certify that the submarine cable system will not use equipment or services identified on the Commission's Covered List. With respect to the circuit capacity data collection, the Report and Order adopts streamlined rules and eliminates the requirement for licensees to file a cable operator report about the capacity on a cable and clarify the types of capacity that need to be reported on an annual basis.
What this rule actually says
The FCC updated rules for companies that operate submarine cables (the physical fiber optic lines connecting continents underwater). The new rules require these companies to report annually on ownership and operations, implement cybersecurity plans, and avoid using equipment made by companies controlled by foreign adversaries. This is a national security measure—the FCC wants to prevent hostile foreign governments from gaining control over critical internet infrastructure.
Who it applies to
- If you operate or own a submarine cable system, this applies to you. Period.
- If you're building an AI app (medical scribe, hiring assistant, support chatbot) that runs on servers in the US, this does not apply to you directly.
- If you're a hosting provider or telecom company that owns or leases submarine cable capacity, this applies to you.
- Jurisdiction: This is a US FCC rule, so it affects any submarine cable landing in the US or its territories, regardless of where your company is incorporated.
- User data scope: The reporting requirements are about cable ownership, operations, and equipment—not about what data flows through the cables or how user data is handled.
In short: indie AI founders can skip this unless your business model is literally operating undersea fiber optic cables.
What founders need to do
Most indie AI founders: nothing. This doesn't apply to you.
If you somehow operate a submarine cable:
- Audit your ownership and control (3-5 days). Document who owns your cable system and whether any owner is controlled by a foreign adversary. The FCC's definition of "foreign adversary" is narrow but serious—mainly China, Russia, Iran, North Korea.
- Create or update a cybersecurity and physical security plan (1-2 weeks). This needs to cover how you protect the cable from hacking and tampering. No exotic requirements; standard telecom security practices count.
- Check your equipment against the FCC's "Covered List" (2-3 days). Some network gear is banned for national security reasons. Cross-reference your suppliers against the FCC list.
- File annual compliance reports (ongoing, 1-2 days per year). Document your cable's ownership, operations, and security posture.
- Identify and report on line terminal equipment operators (1-2 days, one-time). List which companies own the gear connecting to your cable.
Bottom line
Ignore this unless you operate submarine cables.