Takeaways

  • The FCC adopted a Third Report and Order expanding the scope of its restrictions on Covered List equipment to, among other things, prohibit the authorization of radio frequency (RF) devices containing logic-bearing components produced by covered entities, where, had the device itself been produced by the covered entity, it would have been prohibited from obtaining an equipment authorization.
  • An accompanying Third Further Notice of Proposed Rulemaking seeks comment on additional measures, including bifurcating the Covered List; requiring detailed Bills of Material disclosures; requiring registration of Supplier’s Declarations of Conformity (SDoC); expanding the equipment authorization ban to include all components produced by covered entities; and adopting streamlined procedures to revoke equipment authorizations.
  • The Report and Order is effective 30 days after publication in the Federal Register. Comments on the Third Further Notice of Proposed Rulemaking are due September 8, 2026, with reply comments due September 21, 2026.

At its July 22 Open Meeting, the Federal Communications Commission (FCC) adopted a Third Report and Order and Third Further Notice of Proposed Rulemaking (the Order and the Further Notice, respectively) that builds on the agency’s ongoing efforts to expand the scope of its equipment authorization and Covered List rules. The adopted Order adopts several clarifications and provides for rules that (1) close a “component part loophole” to the Covered List; (2) require online marketplaces to display the FCC ID at the point of sale; (3) require full certification for any modification or permissive change made by an entity identified on the Covered List; and (4) define “critical infrastructure,” as used in the Covered List context.

The Further Notice seeks comment on several measures intended to target additional “loopholes” the FCC has identified in the current framework, thereby enhancing the agency’s enforcement capabilities and further refining its Covered List rules in light of other recently adopted changes.

Closing the “Component Part Loophole”
As we have written about here, here, here, and here, the Covered List is an FCC-managed list of communications and surveillance equipment and services deemed to pose an unacceptable risk to national security. Since the adoption of the Covered List, the FCC has primarily enacted rules to prospectively restrict “covered” entities and equipment from receiving the equipment authorizations necessary to permit importation, marketing, and sale in the U.S. market, though has included proposals and decisions to further limit the existing equipment authorizations of certain covered equipment, including a pending request for comment on further restricting foreign-produced unmanned aircraft systems (UAS) that are deemed “military grade.”

In the October 2025 Second Report and Order, the FCC determined that “covered” equipment also includes modular transmitters and adopted rules to prohibit authorization of any device containing a modular transmitter that is itself covered equipment. The FCC concurrently released a Second Further Notice of Proposed Rulemaking, seeking comment on whether to prohibit authorization of equipment containing other components produced by covered entities.

The instant Order adopts this proposal, extending the prohibition to include logic-bearing hardware components produced by covered entities and devices containing such components where, had the device itself been produced by the covered entity, it would have been prohibited from obtaining an equipment authorization. Notably, this prohibition applies only with respect to logic-bearing components produced by covered entities, and not to logic-bearing components produced by non-covered entities who produce covered equipment (i.e., foreign producers of UAS, UAS critical components, or commercial routers).

Logic-Bearing Equipment Defined
The Order defines “logic-bearing hardware” components as:

“[A]ny device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses timing signals or pulses at a rate in excess of 9,000 pulses (cycles) per second and uses digital techniques; inclusive of telephone equipment that uses digital techniques or any device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses radio frequency energy for the purpose of performing data processing functions, such as electronic computations, operations, transformations, recording, filing, sorting, storage, retrieval, or transfer.”

Unlike the long-standing definition of “digital device” already contained in the FCC’s Part 15 rules, “logic-bearing hardware” includes intentional radiators. The Order further clarifies this definition by providing criteria for “non-logic-bearing” components, which are those that are (i) fixed, (ii) do not use digital techniques, and (iii) are non-programmable, including:

  1. Purely mechanical/structural parts, such as housings, chassis, brackets, fasteners, and enclosures;
  2. Passive electrical/electronic parts that do not generate or use digital timing signals, such as simple resistors, capacitors, inductors, wiring/cable, and connectors;
  3. Basic power-only components that do not themselves perform digital logic or RF data processing, such as a plain battery cell (but unlike a battery management system); and
  4. A bare motor with no embedded digital controller as a component.

The Order also tasks the FCC’s Office of Engineering and Technology with responding to any additional “questions as to what sort of components meet this definition” and providing further clarification where appropriate. In adopting this restriction, the FCC concluded that such components pose many of the same national security risks as equipment produced directly by covered entities given their capability to execute instructions that could enable surveillance, cause disruption or sabotage, accept firmware updates, and respond to remote signals that activate dormant code.

The prohibition will be applied prospectively and will take effect 30 days after publication of the Order in the Federal Register. Following significant industry advocacy, the FCC also exempted any applications filed prior to the effective date of the Order from the effects of this prospective prohibition, but notes that such exemption will not apply to later amendments or modifications to add, substitute, or change a logic-bearing hardware component.

New Obligations for Online Marketplaces
The FCC’s rules prohibit the “marketing” of RF devices that lack a valid equipment authorization. The term “marketing” broadly encompasses the sale, lease, advertising, importation, shipment, and distribution for the purpose of selling or leasing of such device. The Order concludes that “distribution for the purpose of selling” includes the listing of RF equipment on an online marketplace—even if the equipment is sold by a third party—if the online marketplace also engages in consignment, warehousing, inventory management, order processing, labelling, packaging, billing, or fulfilment services.

The Order requires e-commerce platforms that “market” RF devices to display the FCC ID at the online point of sale, enabling consumers to make informed purchasing decisions and verify that the devices are “authorized for sale within the United States and are safe products.” The display requirement does provide several exemptions, including listings for used RF devices and for “small sellers” that do not qualify as “high volume third-party seller,” as the terms are defined in the INFORM Consumers Act. The FCC also declined to adopt its proposal to require online marketplaces to display the compliance information statements for devices authorized pursuant to an SDoC.

Online marketplaces will now be subject to FCC enforcement action if they market unauthorized devices on their platforms without conducting “reasonable due diligence” to verify the validity of the device. For online marketplaces that market their own devices, or have physical access or take title to the devices being marketed, the online marketplace must display a valid and accurate FCC ID corresponding to the listed product. For online marketplaces that do not have physical access or take title to the devices, the online marketplace is not responsible for the validity of the FCC ID so long as they have (i) taken reasonable steps to verify the validity against the FCC equipment authorization database and (ii) obtained a certification from the third-party seller regarding the accuracy of the information.

The Order imposes staggered compliance deadlines for online marketplaces with physical access to products (March 1, 2027) and for third-party marketplace listings (June 1, 2027). The Order also adopts a prospective implementation, applying the display requirement only to product listings published for the first time on or after the effective date for the relevant marketplace.

Definition of Critical Infrastructure
In 2024, the D.C. Circuit vacated the FCC’s initial definition of “critical infrastructure” as overly broad for failing to support the inclusion of “systems or assets” that were merely “connected to” such critical infrastructure. Addressing the D.C. Circuit’s concerns, the Order adopts the narrower definition used in the USA PATRIOT Act of 2001, which defines “critical infrastructure” as:

“[S]ystems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”

This definition continues to encompass systems and assets used in the provision of services or functions in the sixteen critical infrastructure sectors identified in the National Security Memorandum on Critical Infrastructure Security and Resilience.

Additional Clarifications
In addition to clarifying the applicability of the “marketing” rules to e-commerce platforms, the Order clarifies (or re-affirms) that:

  • Previously authorized devices may not be modified (including changes in the design, circuitry, or construction of the device, which may otherwise have been made pursuant to a permissive change) if doing so would cause the device to become covered as a result of such modification or permissive change;
  • All covered entities that seek any modification or permissive changes to covered or non-covered equipment must submit full applications for recertification; and
  • No covered entity is permitted to rely on the SDoC process for modifications, even for non-covered equipment regardless of the nature or scope of the change.

Proposed Rules
The Further Notice seeks comment on a host of measures intended to close additional loopholes the FCC has identified in the current Covered List framework. At a high level, these include:

  • Whether to bifurcate the Covered List rules into producer/provider-based and production location-based categories with the intent to provide clarity with respect to which rules apply to both categories and which apply only to one category;
  • Whether to codify a definition of “produced in a foreign country,” “UAS critical components,” and “routers” for purposes of the Covered List and related rules;
  • Whether to adopt measures to address potential “white labeling” abuse with respect to devices claiming “electrically identical” status;
  • Whether to require applicants to submit a written and signed hardware and software bills of material at the time they apply for certification and require grantees to update the FCC of any changes to the device bills of material or, alternatively, limit such disclosure requirements to “higher-risk” equipment, such as that coming from foreign adversary countries, or certain identified components;
  • Whether to prohibit authorization of devices incorporating any components produced by a covered entity (including software and/or firmware);
  • Whether to require certification for devices in Covered List sectors (UAS, UAS critical components, and routers) even if it would otherwise be eligible for authorization pursuant to SDoC or exempt from authorization, or alternatively, limit such prohibition to certain categories of equipment or higher-risk places of origin;
  • Whether to adopt new restrictions and conditions for importation and marketing of covered equipment, or further revise the requirements adopted in the Order;
  • Whether to impose term limits on equipment authorizations;
  • Whether to require registration of SDoC-authorized devices;
  • Whether to require a U.S.-based liable party for FCC-certified equipment (similar to the SDoC requirement to have a U.S.-based responsible party) and whether failure to respond by the liable party should be grounds for revocation of equipment authorization; and
  • Whether to adopt a streamlined procedure for revoking equipment authorizations.

The FCC also proposes to codify in its rules a framework for permitting permissive changes for software and firmware updates that mitigate harm to U.S. consumers for previously authorized covered equipment. Such changes are currently permitted through a set of limited waivers that are currently set to expire on January 1, 2029.

Effective Dates and Comment Deadlines
The Order will be effective 30 days following publication in the Federal Register, with certain rules having delayed implementation, as described above.

Comments on the Further Notice are due on September 8, 2026, with reply comments due September 21, 2026. Interested stakeholders are encouraged to participate in the rulemaking regarding the identified questions, as well as any other outstanding issues arising out of the implementation and expansion of rules through the Supply Chain Security docket.

* * * * * * * * * *

For more information about the FCC’s proposed equipment authorization changes, the Covered List, or for assistance evaluating the impact of these proposals or engaging with the FCC during the rulemaking process, please contact the authors.

These and any accompanying materials are not legal advice, are not a complete summary of the subject matter, and are subject to the terms of use found at: https://www.pillsburylaw.com/en/terms-of-use.html. We recommend that you obtain separate legal advice.