NatSec Noir

Tech and geopolitics out of the shadows

Newsletter·RSS·About
Record · FCC

Cincinnati Bell - Team Telecom Mitigation Agreement

This Letter of Agreement establishes binding national-security and law-enforcement mitigation commitments for CBTS in connection with the proposed transfer of indirect control of CBTS Technology Solutions LLC to CBTS Borrower LLC and states that, after execution, the FCC will be notified that there is no objection to granting the applications.

Docket
WC Docket No. 24-42
Issuing body
FCC
Document date
2024-10-10
Entered
2026-09-26
Persons of interest
Cincinnati Bell
Lists
Team TelecomMitigation agreement

What it does The agreement, made by CBTS Technology Solutions LLC, CBTS LLC, and CBTS Borrower LLC for the U.S. Department of Justice, including the FBI, governs access to U.S. records, domestic communications, communications infrastructure, and lawful U.S. process. It requires a U.S. law-enforcement point of contact and security officer; personnel screening; U.S.-based handling of responsive records; controls on foreign access, equipment, service providers, network operations centers, and ownership changes; cybersecurity and system-security plans; incident reporting; annual reports; site visits; and possible third-party audits. It supersedes the 2021 LOA as to CBTS.

Who it affects The principal obligations fall on CBTS and its affiliates, contractors, service providers, equipment providers, and personnel with access to protected systems or records. The DOJ, FBI, DoD, FCC, and the interagency Committee receive notice, objection, approval, monitoring, or enforcement roles.

Why it matters The LOA links FCC Section 214 transfer approval to continuing controls over data, lawful interception, supply chain security, foreign access, and network operations. Breach or inadequate mitigation may support FCC action against relevant authorizations.

Key dates and numbers

  • Signed October 10, 2024; the commitments generally run from the “Date of FCC Approval.”
  • Many initial submissions are due within 15, 30, or 60 days after FCC approval.
  • Security incidents generally must be reported within 48 hours; CPNI breaches follow a seven-business-day deadline under the cited rule.
  • Annual compliance reports are due one year after FCC approval and every year thereafter.
  • Relevant identifiers: ITC-T/C-20240207-00028; WC Docket No. 24-42; TT 24-010 to -011.
Approved 2026-09-26 · published 2026-09-26