Metronet T-Mobile - Mitigation Agreement
The Letter of Agreement (LOA) establishes binding national-security and law-enforcement mitigation commitments for Metronet-related Section 214 transfers and assignments involving MetroNet Systems, KKR Metro Parent, and T-Mobile.
What it does The Companies agree to controls overseen by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector, the U.S. Department of Justice, and the U.S. Department of Homeland Security. The LOA requires a U.S. law-enforcement point of contact and U.S. security officer; personnel screening; protection and U.S.-based handling of U.S. Records, domestic communications, infrastructure, and Lawful U.S. Process; CALEA compliance; security and systems plans; review of foreign-person access, countries of access, Principal Equipment, Service Providers, and network operations centers; prompt reporting of security incidents; annual compliance reporting; site visits; and possible third-party audits. T-Mobile separately accepts obligations concerning records and lawful-process requests covered by its CFIUS national security agreement.
Who it affects The commitments bind Metronet Holdings and its subsidiaries, MetroNet Systems, KKR Metro Parent, and T-Mobile, with oversight by DOJ, DHS, and the Committee. They also govern relevant employees, foreign persons, equipment providers, Service Providers, and contractors with access to covered systems or records.
Why it matters The agreement links approval of the telecommunications transfers to continuing safeguards for sensitive customer and network information, lawful interception, supply-chain security, and foreign access. Breach or unresolved risk may lead to recommendations that the FCC modify, condition, revoke, cancel, or nullify relevant authorizations.
Key dates and numbers
- Executed May 9, 2025; FCC approval is the trigger for most deadlines.
- Initial LEPOC and security-officer nominations are generally due within 15 days after FCC approval.
- Foreign-access information, Principal Equipment, and Service Provider lists are generally due within 30 days.
- Cybersecurity and Systems Security Plans, training, and network diagrams are generally due within 60 days.
- Security Incidents must be reported to the CMAs within 72 hours of discovery; annual reports begin one year after FCC approval.
- The agreement concerns four FCC application file numbers and WC Docket No. 24-244 (TT 24-044 to -048).