Alert 05.13.26
Alert
Alert
By Jessica T. Nyman, Jodi A. Goldberg, Betsy Craig, Marcus Burden
07.13.26
At its July 22 Open Meeting, the Federal Communications Commission (FCC) adopted a Third Report and Order and Third Further Notice of Proposed Rulemaking (the Order and the Further Notice, respectively) that builds on the agency’s ongoing efforts to expand the scope of its equipment authorization and Covered List rules. The adopted Order adopts several clarifications and provides for rules that (1) close a “component part loophole” to the Covered List; (2) require online marketplaces to display the FCC ID at the point of sale; (3) require full certification for any modification or permissive change made by an entity identified on the Covered List; and (4) define “critical infrastructure,” as used in the Covered List context.
The Further Notice seeks comment on several measures intended to target additional “loopholes” the FCC has identified in the current framework, thereby enhancing the agency’s enforcement capabilities and further refining its Covered List rules in light of other recently adopted changes.
Closing the “Component Part Loophole”
As we have written about here, here, here, and here, the Covered List is an FCC-managed list of communications and surveillance equipment and services deemed to pose an unacceptable risk to national security. Since the adoption of the Covered List, the FCC has primarily enacted rules to prospectively restrict “covered” entities and equipment from receiving the equipment authorizations necessary to permit importation, marketing, and sale in the U.S. market, though has included proposals and decisions to further limit the existing equipment authorizations of certain covered equipment, including a pending request for comment on further restricting foreign-produced unmanned aircraft systems (UAS) that are deemed “military grade.”
In the October 2025 Second Report and Order, the FCC determined that “covered” equipment also includes modular transmitters and adopted rules to prohibit authorization of any device containing a modular transmitter that is itself covered equipment. The FCC concurrently released a Second Further Notice of Proposed Rulemaking, seeking comment on whether to prohibit authorization of equipment containing other components produced by covered entities.
The instant Order adopts this proposal, extending the prohibition to include logic-bearing hardware components produced by covered entities and devices containing such components where, had the device itself been produced by the covered entity, it would have been prohibited from obtaining an equipment authorization. Notably, this prohibition applies only with respect to logic-bearing components produced by covered entities, and not to logic-bearing components produced by non-covered entities who produce covered equipment (i.e., foreign producers of UAS, UAS critical components, or commercial routers).
Logic-Bearing Equipment Defined
The Order defines “logic-bearing hardware” components as:
“[A]ny device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses timing signals or pulses at a rate in excess of 9,000 pulses (cycles) per second and uses digital techniques; inclusive of telephone equipment that uses digital techniques or any device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses radio frequency energy for the purpose of performing data processing functions, such as electronic computations, operations, transformations, recording, filing, sorting, storage, retrieval, or transfer.”
Unlike the long-standing definition of “digital device” already contained in the FCC’s Part 15 rules, “logic-bearing hardware” includes intentional radiators. The Order further clarifies this definition by providing criteria for “non-logic-bearing” components, which are those that are (i) fixed, (ii) do not use digital techniques, and (iii) are non-programmable, including:
The Order also tasks the FCC’s Office of Engineering and Technology with responding to any additional “questions as to what sort of components meet this definition” and providing further clarification where appropriate. In adopting this restriction, the FCC concluded that such components pose many of the same national security risks as equipment produced directly by covered entities given their capability to execute instructions that could enable surveillance, cause disruption or sabotage, accept firmware updates, and respond to remote signals that activate dormant code.
The prohibition will be applied prospectively and will take effect 30 days after publication of the Order in the Federal Register. Following significant industry advocacy, the FCC also exempted any applications filed prior to the effective date of the Order from the effects of this prospective prohibition, but notes that such exemption will not apply to later amendments or modifications to add, substitute, or change a logic-bearing hardware component.
New Obligations for Online Marketplaces
The FCC’s rules prohibit the “marketing” of RF devices that lack a valid equipment authorization. The term “marketing” broadly encompasses the sale, lease, advertising, importation, shipment, and distribution for the purpose of selling or leasing of such device. The Order concludes that “distribution for the purpose of selling” includes the listing of RF equipment on an online marketplace—even if the equipment is sold by a third party—if the online marketplace also engages in consignment, warehousing, inventory management, order processing, labelling, packaging, billing, or fulfilment services.
The Order requires e-commerce platforms that “market” RF devices to display the FCC ID at the online point of sale, enabling consumers to make informed purchasing decisions and verify that the devices are “authorized for sale within the United States and are safe products.” The display requirement does provide several exemptions, including listings for used RF devices and for “small sellers” that do not qualify as “high volume third-party seller,” as the terms are defined in the INFORM Consumers Act. The FCC also declined to adopt its proposal to require online marketplaces to display the compliance information statements for devices authorized pursuant to an SDoC.
Online marketplaces will now be subject to FCC enforcement action if they market unauthorized devices on their platforms without conducting “reasonable due diligence” to verify the validity of the device. For online marketplaces that market their own devices, or have physical access or take title to the devices being marketed, the online marketplace must display a valid and accurate FCC ID corresponding to the listed product. For online marketplaces that do not have physical access or take title to the devices, the online marketplace is not responsible for the validity of the FCC ID so long as they have (i) taken reasonable steps to verify the validity against the FCC equipment authorization database and (ii) obtained a certification from the third-party seller regarding the accuracy of the information.
The Order imposes staggered compliance deadlines for online marketplaces with physical access to products (March 1, 2027) and for third-party marketplace listings (June 1, 2027). The Order also adopts a prospective implementation, applying the display requirement only to product listings published for the first time on or after the effective date for the relevant marketplace.
Definition of Critical Infrastructure
In 2024, the D.C. Circuit vacated the FCC’s initial definition of “critical infrastructure” as overly broad for failing to support the inclusion of “systems or assets” that were merely “connected to” such critical infrastructure. Addressing the D.C. Circuit’s concerns, the Order adopts the narrower definition used in the USA PATRIOT Act of 2001, which defines “critical infrastructure” as:
“[S]ystems and assets, whether physical or virtual, so vital to the United States that the incapacity or destruction of such systems would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”
This definition continues to encompass systems and assets used in the provision of services or functions in the sixteen critical infrastructure sectors identified in the National Security Memorandum on Critical Infrastructure Security and Resilience.
Additional Clarifications
In addition to clarifying the applicability of the “marketing” rules to e-commerce platforms, the Order clarifies (or re-affirms) that:
Proposed Rules
The Further Notice seeks comment on a host of measures intended to close additional loopholes the FCC has identified in the current Covered List framework. At a high level, these include:
The FCC also proposes to codify in its rules a framework for permitting permissive changes for software and firmware updates that mitigate harm to U.S. consumers for previously authorized covered equipment. Such changes are currently permitted through a set of limited waivers that are currently set to expire on January 1, 2029.
Effective Dates and Comment Deadlines
The Order will be effective 30 days following publication in the Federal Register, with certain rules having delayed implementation, as described above.
Comments on the Further Notice are due on September 8, 2026, with reply comments due September 21, 2026. Interested stakeholders are encouraged to participate in the rulemaking regarding the identified questions, as well as any other outstanding issues arising out of the implementation and expansion of rules through the Supply Chain Security docket.
* * * * * * * * * *
For more information about the FCC’s proposed equipment authorization changes, the Covered List, or for assistance evaluating the impact of these proposals or engaging with the FCC during the rulemaking process, please contact the authors.