Proposed Rule

Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program

Published 6 Aug 2026 · retrieved 7 Aug 2026, 02:30 EDT · version 1Official source

The full text was pulled automatically from the official source and is not Threadline News reporting; the annotations alongside it are.

Preamble

1

FEDERAL COMMUNICATIONS COMMISSION

2

47 CFR Parts 1, 2, and 15

3

Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program

Agency

1

Federal Communications Commission.

Action

1

Proposed rule.

Summary

1

The Federal Communications Commission (Commission or FCC) issues a Third Further Notice of Proposed Rulemaking seeking comment on a broad set of additional measures to strengthen the security and integrity of its equipment authorization program. The measures include bifurcating the Covered List into producer/provider-based and production location-based categories; addressing "white labeling" of covered equipment; hardware and software bill of materials (HBOM/SBOM) disclosure requirements; further prohibitions or presumptions against authorizing equipment containing Covered List components or software; certification requirements for devices in Covered List sectors; reforms to equipment importation, marketing, and pre-authorization operation rules; restrictions on use of the FCC logo; streamlined revocation procedures; codification of permissive-change waivers for software, firmware, and hardware updates to covered equipment; codified definitions for UAS, UAS critical components, and routers; term limits on equipment authorizations; registration of Supplier's Declaration of Conformity (SDoC) devices; modernization of the Commission's equipment authorization database; updates to submarine cable Covered List rules; and a proposal to require a U.S.-based liable party for FCC-certified equipment.

Dates

1

Comments are due on or before September 8, 2026 and reply comments are due on or before September 21, 2026.

Addresses

1

Pursuant to Sec. Sec. 1.415 and 1.419 of the Commission's rules, 47 CFR 1.415, 1.419, interested parties may file comments and reply comments on or before the dates indicated in the DATES section above. Comments may be filed using the Commission's Electronic Comment Filing System (ECFS). You may submit comments, identified by ET Docket No. 21-232, by any of the following methods: Electronic Filers: Comments may be filed electronically using the internet by accessing the ECFS: https://www.fcc.gov/ecfs. Paper Filers: Parties who choose to file by paper must file an original and one copy of each filing. Filings can be sent by hand or messenger delivery, by commercial courier, or by the U.S. Postal Service. All filings must be addressed to the Secretary, Federal Communications Commission. Hand-delivered or messenger-delivered paper filings for the Commission's Secretary are accepted between 8:00 a.m. and 4:00 p.m. by the FCC's mailing contractor at 9050 Junction Drive, Annapolis Junction, MD 20701. All hand deliveries must be held together with rubber bands or fasteners. Any envelopes and boxes must be disposed of before entering the building. Commercial courier deliveries (any deliveries not by the U.S. Postal Service) must be sent to 9050 Junction Drive, Annapolis Junction, MD 20701. Filings sent by U.S. Postal Service First-Class Mail, Priority Mail, and Priority Mail Express must be sent to 45 L Street NE, Washington, DC 20554. People with Disabilities: To request materials in accessible formats for people with disabilities (Braille, large print, electronic files, audio format), send an email to [email protected] or call the Consumer & Governmental Affairs Bureau at 202-418-0530.

For further information contact

1

[email protected] for the Office of Engineering and Technology.

Supplementary information

1

This is a summary of the Commission's Third Further Notice of Proposed Rulemaking, in ET Docket No. 21-232, FCC 26- 50, adopted on July 22, 2026, and released on July 23, 2026. The full text of this document, including the accompanying Third Report and Order, is available for public inspection and can be downloaded at https://docs.fcc.gov/public/attachments/FCC-26-50A1.pdf. Alternative formats are available for people with disabilities (Braille, large print, electronic files, audio format) by sending an email to [email protected] or calling the Commission's Consumer and Governmental Affairs Bureau at (202) 418-0530 (voice). Ex Parte Presentations. The proceeding this document initiates shall be treated as a "permit-but-disclose" proceeding in accordance with the Commission's ex parte rules. Persons making ex parte presentations must file a copy of any written presentation or a memorandum summarizing any oral presentation within two business days after the presentation (unless a different deadline applicable to the Sunshine period applies). Persons making oral ex parte presentations are reminded that memoranda summarizing the presentation must (1) list all persons attending or otherwise participating in the meeting at which the ex parte presentation was made, and (2) summarize all data presented and arguments made during the presentation. If the presentation consisted in whole or in part of the presentation of data or arguments already reflected in the presenter's written comments, memoranda or other filings in the proceeding, the presenter may provide citations to such data or arguments in his or her prior comments, memoranda, or other filings (specifying the relevant page and/or paragraph numbers where such data or arguments can be found) in lieu of summarizing them in the memorandum. Documents shown or given to Commission staff during ex parte meetings are deemed to be written ex parte presentations and must be filed consistent with rule 1.1206(b). In proceedings governed by rule 1.49(f) or for which the Commission has made available a method of electronic filing, written ex parte presentations and memoranda summarizing oral ex parte presentations, and all attachments thereto, must be filed through the electronic comment filing system available for that proceeding, and must be filed in their native format (e.g., .doc, .xml, .ppt, searchable .pdf). Participants in this proceeding should familiarize themselves with the Commission's ex parte rules. Regulatory Flexibility Act. The Regulatory Flexibility Act of 1980, as amended (RFA), requires that an agency prepare a regulatory flexibility analysis for notice and comment rulemakings, unless the agency certifies that "the rule will not, if promulgated, have a significant economic impact on a substantial number of small entities." Accordingly, the Commission has prepared an Initial Regulatory Flexibility Analysis (IRFA) concerning the potential impact of the rule and policy proposals in this document on small entities. The IRFA is set forth in Appendix D to the Third Further Notice of Proposed Rulemaking. The Commission invites the general public, particularly small businesses, to comment on the IRFA. Comments must be filed by the deadlines for comments on the Third Further Notice of Proposed Rulemaking indicated in the DATES section above and must have a separate

2

and distinct heading designating them as responses to the IRFA. Paperwork Reduction Act. This document contains proposed new or modified information collection requirements subject to the Paperwork Reduction Act of 1995 (PRA), Public Law 104-13. The Commission, as part of its continuing effort to reduce paperwork burdens, invites the general public and the Office of Management and Budget (OMB) to comment on any information collection requirements contained in this document. In addition, pursuant to the Small Business Paperwork Relief Act of 2002, Public Law 107-198, see 44 U.S.C. 3506(c)(4), the Commission seeks specific comment on how it might "further reduce the information collection burden for small business concerns with fewer than 25 employees." Providing Accountability Through Transparency Act. Consistent with the Providing Accountability Through Transparency Act, Public Law 1189- 9, a summary of this Third Further Notice of Proposed Rulemaking will be available at https://www.fcc.gov/proposed-rulemakings. OPEN Government Data Act. The OPEN Government Data Act requires agencies to make "public data assets" available under an open license and as "open Government data assets," i.e., in machine-readable, open format, unencumbered by use restrictions other than intellectual property rights, and based on an open standard that is maintained by a standards organization. This requirement is to be implemented "in accordance with guidance by the Director" of the OMB. The term "public data asset" means "a data asset, or part thereof, maintained by the Federal Government that has been, or may be, released to the public, including any data asset, or part thereof, subject to disclosure under [the Freedom of Information Act (FOIA)]." A "data asset" is "a collection of data elements or data sets that may be grouped together," and "data" is "recorded information, regardless of form or the media on which the data is recorded."

3

Synopsis

4

Introduction. In this Third Further Notice of Proposed Rulemaking, the Commission identifies additional gaps in its equipment authorization framework that may present national security vulnerabilities, and proposes and seeks comment on targeted rules and clarifications to close them. Several of the proposals respond to the Covered List's recent expansion to include production location-based determinations (UAS, UAS critical components, and routers "produced in a foreign country") which, unlike prior producer/provider-based determinations, turn on where and how equipment is made rather than on the identity of a named producer. Bifurcating Covered List Rules. In light of the Covered List's recent expansion to include production location-based entries, the Commission seeks comment on reorganizing its part 2 rules to distinguish rules that apply to producer/provider-based Covered List entries from rules that apply to production location-based entries and to "Covered List sectors" (i.e., device categories, such as UAS or routers, subject to a production location-based entry). The Commission proposes to direct the Public Safety and Homeland Security Bureau (PSHSB) to redesign the Covered List website into two columns reflecting this bifurcation. White Labeling. The Commission seeks comment on whether to codify a definition of "produced by" for Covered List purposes--for example, whether a device is "produced by" an entity that exercises substantial responsibility for, or control over, any major stage of the process by which the device comes into existence, and whether design- only contributions should be excluded under certain conditions, as one commenter proposes, or included more broadly, as another commenter proposes. The Commission also seeks comment on requiring applicants to disclose all entities that produced a device, and on measures to prevent abuse of the Commission's "electrically identical" and change-of-identification procedures to evade Covered List restrictions through undisclosed white-labeling or rebranding arrangements, including whether to require disclosure of all brand and model names associated with a given FCC ID. Hardware and Software Bills of Materials. The Commission seeks comment on requiring applicants for equipment certification to submit a written and signed hardware bill of materials (HBOM) and software bill of materials (SBOM) identifying, for each component, its producer, production location(s), and the percentage of component value attributable to each location, with updates required within 30 days of any change. The Commission seeks comment on the costs and benefits of this approach, including preliminary cost estimates of under $5,000 per software program and up to $10,000 per hardware device, and on narrower alternatives, such as limiting HBOM/SBOM requirements to devices in Covered List sectors, to higher-risk equipment, or to specified categories of components (e.g., logic-bearing hardware, modular transmitters, semiconductors). Software and Other Components Produced by Covered List Entities. Building on the logic-bearing hardware component prohibition adopted in the Third Report and Order, the Commission seeks comment on prohibiting authorization of devices incorporating any component--not only logic- bearing hardware--produced by a Covered List entity, or, alternatively, adopting a rebuttable presumption against authorization that an applicant could overcome by demonstrating the device does not pose unacceptable national security risk. The Commission also seeks comment on prohibiting authorization of, or the downloading of, software or firmware produced or provided by a Covered List entity, and tentatively estimates the annual cost of such a prohibition at under $50 million. Requiring Certification for Devices in Covered List Sectors. The Commission proposes to amend Sec. 2.907(c) to require that devices in a Covered List sector (e.g., UAS, UAS critical components, and routers)--regardless of producer--undergo the certification process even if they would otherwise be eligible for SDoC or exempt from authorization, mirroring the Commission's existing treatment of equipment produced by Covered List entities. The Commission seeks comment on this proposal, on whether to exempt categories such as UAS on the Defense Contract Management Agency's Blue UAS Cleared List, and on whether certification would close a potential loophole allowing Covered List sector devices to evade authorization requirements by incorporating previously authorized, non-covered modular transmitters. Importation Under 47 CFR 2.1204. The Commission proposes to exclude covered equipment from the general importation conditions of Sec. 2.1204(a) and to create a new subsection establishing a narrow set of conditions under which covered equipment may be imported: with a valid, unrestricted equipment authorization; in quantities of 40 or fewer units for testing, evaluation, or product development (down from the current 4,000-unit threshold generally applicable to unauthorized devices), absent written approval from the Chief of OET for a greater quantity; solely for export; for exclusive use by the U.S. Government; or solely to develop products for U.S. Government use. The Commission also proposes to eliminate the existing exception permitting marketing of unauthorized cellphone handsets that

5

are capable of functioning only outside the United States, and seeks comment on the personal-use importation exemption and other existing importation exceptions as applied to covered equipment. Marketing Under 47 CFR 2.803. The Commission seeks comment on further marketing measures, including whether to require online marketplaces to verify (not merely display) FCC ID and SDoC compliance information; on expressly prohibiting the marketing of covered equipment under the Commission's pre-authorization marketing rule; on requiring disclosure of all brand and model names under which authorized equipment is marketed; and on rules restricting the marketing of otherwise-lawful devices (such as software-defined radios) in a manner that promotes illegal use or unauthorized modification, including a proposed point-of-sale warning notice for equipment restricted to licensed users. Use of the FCC Logo, 47 CFR 2.1074. The Commission seeks comment on whether to extend the FCC logo's current voluntary-use framework to certified devices, prohibit its use on incidental radiators and on any device that has not been properly tested and authorized, and whether to require its use on all validly authorized devices. Streamlined Revocation, 47 CFR 2.939. The Commission seeks comment on replacing the Commission's decades-old, radio-station-license-based revocation procedure with a streamlined process--paralleling the process adopted for covered equipment in the First Report and Order-- for revocations involving willfulness, termination of a Conditional Approval, or willful failure to provide required information, and on extending a streamlined process to all revocations involving covered equipment consistent with the notice-and-opportunity-to-cure procedure required by the Administrative Procedure Act. Permitting Permissive Changes for Basic Software and Hardware Updates to Covered Equipment. The Commission proposes to codify, and make permanent, OET's waivers (currently effective through January 1, 2029) permitting Class I and Class II software and firmware permissive changes--such as security patches and compatibility updates--to already-authorized covered equipment where the change mitigates consumer harm and does not alter the device's capability or marketed identity. The Commission also seeks comment on extending similar treatment to limited hardware component swaps for equipment in a producer/provider-based Covered List entry, subject to conditions including that the modification does not enhance capability, does not substitute a foreign-produced component for a U.S.-produced one, and that the device continues to be marketed as identical to the pre- modification product. Operation of RF Devices Prior to Equipment Authorization. The Commission seeks comment on conforming Sec. 2.805, which governs pre- authorization operation of RF devices, to the Commission's proposed marketing and importation reforms for covered equipment, including whether existing exceptions for trade-show demonstrations and pre- production evaluation should apply to covered equipment. UAS and Router Covered List Definitions. The Commission proposes to codify definitions, previously articulated through Public Notices and FAQ guidance, for "produced in a foreign country" (tied to the "domestic end product" standard in 48 CFR 25.101(a)(1)), "UAS critical components" (an enumerated list including data transmission devices, communications systems, flight controllers, ground control stations, navigation systems, sensors and cameras, batteries and battery management systems, and motors, designed and intended primarily for UAS use), and "routers" (consumer-grade networking devices, primarily intended for residential use, that forward IP data packets between networked systems). The Commission seeks comment on these definitions and on whether "produced in a foreign country" should be interpreted more broadly (e.g., aligned with the FTC's "Made in USA" standard) or more narrowly (e.g., aligned with trade-law rules of origin). Term Limits on Equipment Authorizations. The Commission seeks comment on whether equipment authorizations, which currently remain valid indefinitely absent revocation, should instead expire after a fixed term--tentatively suggesting ten years--and on associated renewal procedures, streamlined renewal or expedited re-authorization processes, and how any expiration requirement should apply to SDoC- authorized equipment. Registration of SDoC Devices. Noting substantial changes in the equipment authorization landscape since the Commission's 1996 decision not to require registration of SDoC-authorized devices, the Commission proposes to require that all SDoC devices be registered with the Commission and assigned a unique, publicly listed identification number, and seeks comment on the scope of required registration information (including whether to include HBOM/SBOM data), whether the registration number should be displayed on the device label, and whether online marketplaces should be required to collect and verify SDoC compliance information or registration numbers at the point of sale, paralleling the FCC ID display requirement the Commission adopts in the concurrently released Third Report and Order. Data Analytics Capability and Need for a Modern Equipment Authorization System (EAS) Database. The Commission seeks comment on modernizing its Equipment Authorization System database to better support enforcement priorities while streamlining and reducing administrative burden on TCBs and other participants in the equipment authorization process, including what data-sharing and system improvements would be most beneficial. Submarine Cables. The Commission proposes to narrow its submarine cable Covered List certification and routine-condition requirements, adopted in the 2025 Submarine Cable First Report and Order, to apply to producer/provider-based Covered List determinations, rather than production location-based determinations, unless a location-based determination specifically references national security threats to submarine cable systems. The Commission seeks comment on this proposal and its effect on submarine cable infrastructure security. Rule Clarification. The Commission proposes to amend Sec. 2.903(c) to clarify that the prohibition on authorizing Covered List equipment applies to all equipment authorization pathways, not only the three categories currently enumerated in that paragraph, and seeks comment on whether this revision is necessary to prevent the rule from being construed to exclude equipment authorized through mechanisms other than certification, SDoC, or exemption. Universal Service Fund and Supply Chain Annual Report. The Commission seeks comment on how the component-level prohibitions adopted in the Third Report and Order and the Covered List bifurcation proposed in this Further Notice would affect the supply-chain certification requirements in part 54 of the Commission's rules and the annual Universal Service Fund supply chain report. Impact on Other Service Provider Certifications. The Commission seeks comment on how the determinations in the Third Report and Order and the proposals in this Further Notice--particularly the component- level prohibitions and the proposed Covered

6

List bifurcation--may affect other existing or proposed certifications, filings, or attestations that reference the Covered List. U.S.-Based Liable Party for FCC-Certified Equipment. The Commission proposes to amend Sec. 2.909 to require that every applicant or grantee of FCC certification have a U.S.-based liable party, paralleling the existing requirement for SDoC-authorized equipment. Under the proposal, the liable party would be the U.S.-based manufacturer or assembler; if none, the importer; a retailer or other party that assumes the liable-party role by agreement; or, following an unauthorized modification, the party performing the modification (if U.S.-based) or the importer. The Commission finds that its existing requirement to designate a U.S. agent for service of process has, in multiple instances, proven insufficient to ensure compliance, and seeks comment on the costs, benefits, and alternative approaches to this proposal. The Commission seeks comment on appropriate transition periods and implementation timelines for each of the proposals discussed above.

7

Ordering Clauses

8

It is ordered, pursuant to the authority found in sections 4(i), 301, 302, 303, 403, and 503 of the Communications Act of 1934, as amended, 47 U.S.C. 154(i), 301, 302a, 303, 403, 503; the Secure and Trusted Communications Networks Act of 2019, 47 U.S.C. 1601-1609; and the Secure Equipment Act of 2021, Public Law 117-55, 135 Stat. 423, 47 U.S.C. 1601 note, that this Third Further Notice of Proposed Rulemaking is hereby adopted. It is further ordered that the Commission's Office of the Secretary shall send a copy of this Third Further Notice of Proposed Rulemaking, including the Initial Regulatory Flexibility Analysis, to the Chief Counsel of the Small Business Administration Office of Advocacy.

9

List of Subjects in 47 CFR Parts 1, 2, and 15

10

Administrative practice and procedure, Communications equipment, Imports, Reporting and recordkeeping requirements, Telecommunications.

11

Federal Communications Commission. Marlene Dortch, Secretary.

12

Proposed Rules

13

For the reasons discussed in the preamble, the Federal Communications Commission proposes to amend 47 CFR parts 1, 2, and 15 as follows:

14

PART 1--PRACTICE AND PROCEDURE

15

0 1. The authority citation for part 1 continues to read as follows:

16

Authority: 47 U.S.C. chs. 2, 5, 9, 13; 28 U.S.C. 2461 note; 47 U.S.C. 1754, unless otherwise noted.

17

0 2. Delayed indefinitely, amend Sec. 1.70006 by revising paragraph (d) to read as follows:

18

Sec. 1.70006 Certifications.

19

* * * * * (d) That the submarine cable system will not use equipment or services that are produced or provided by an entity identified on the Covered List that the Commission maintains on its website pursuant to the Secure Networks Act, 47 U.S.C. 1601-1609, or other covered communications equipment or services wherein the specific determination concerning such equipment or services specifically references national security threats involving submarine cable systems. 0 3. Delayed indefinitely, amend Sec. 1.70007 by revising paragraph (u) to read as follows:

20

Sec. 1.70007 Routine conditions.