United States Federal Communications Commission Proposes Changes to Equipment Authorization Requirements
On September 8, 2026, the United States Federal Communications Commission (“FCC”) began accepting comments in a regulatory proceeding with the potential to significantly expand the FCC’s national-security controls over communications equipment, largely impacting devices manufacturers outside of the U.S. in countries such as China.
In its Third Further Notice of Proposed Rulemaking (“Third FNPRM”) in ET Docket No. 21-232, the FCC proposes to move beyond identifying specific foreign companies as security risks and increasingly scrutinize generally where equipment is produced. The proposals would have substantial implications for Chinese manufacturers seeking to obtain or maintain FCC equipment authorizations.
The proceeding largely focuses on the FCC’s “Covered List.” The Covered List is a list of equipment and services that have been specifically determined to pose an unacceptable risk to the national security of the United States or the security and safety of United States persons. Devices on the Covered List may not be imported or marketed in the U.S. Until December 2025, the FCC added devices to the Covered List by identifying the specific producer or provider of the equipment or services. In 2025, however, the FCC began adding devices to the Covered List based on the country in which the equipment was produced. For example, the FCC has added all UAS (i.e., drones), UAS critical components, and routers produced outside the U.S. to the Covered List. For a Chinese manufacturer, this distinction is critical. A company that is not itself named on the Covered List could nevertheless face authorization problems if it manufactures equipment falling within a location-based Covered List category.
Bills of Materials
Perhaps the most consequential of the FCC’s proposals for manufacturers is the potential requirement for hardware bills of materials and software bills of materials. The FCC proposes requiring applicants for equipment authorization to disclose all components, including hardware and software of a device. For critical components, the proposed disclosures could include the component's name and function, its producer, where it was designed, developed, manufactured, assembled, or otherwise produced, and the percentage of component value attributable to particular producers and production locations.
This would substantially increase the compliance burden for manufacturers with complex supply chains. A manufacturer would need reliable visibility not merely into its direct suppliers, but potentially into the origin of important subcomponents, software, firmware, semiconductors, optical transceivers, modules, and other technology. Further, the FCC proposes to require updated hardware and software lists be provided within 30 days of changes thereto.
The significance is that the FCC would gain a much clearer picture of whether a supposedly non-covered device incorporates components associated with a Covered List entity or location. Supply-chain documentation would therefore become an important part of FCC authorization strategy rather than merely an internal procurement function.
White Labelling
The FCC is also targeting arrangements in which equipment is manufactured by one entity but marketed under another company's name. The Third FNPRM seeks comment on whether an entity exercising substantial responsibility or control over a major stage of production, including the design, manufacturing, assembly, or development, should be treated as the producer.
The FCC proposes requiring applicants to identify all entities that “produced” and asks whether applicants for equipment authorization should disclose all brand and model names associated with an FCC ID.
For Chinese manufacturers, this could materially affect OEM business models. A Chinese factory producing an FCC-authorized product for a U.S. brand may no longer be able to remain effectively undisclosed in the authorization process.
Component-Level Restrictions
The Third FNPRM proposes potentially prohibiting, or establishing a presumption against, authorization of devices containing hardware components, software, or firmware produced by a Covered List entity, even when used as device components by another manufacturer. It also proposes certification requirements for devices falling within Covered List sectors, regardless of the identity of the manufacturer.
This could be particularly significant for Chinese manufacturers because a device could become difficult or impossible to authorize even where the Chinese company itself is not named on the Covered List. The issue could instead arise from a single covered component or software element. In addition, a manufacturer that currently relies on a Chinese supplier that later becomes subject to a Covered List determination could face problems not only with new products but potentially with product modifications and future authorizations.
Importation and Marketing Restrictions
The FCC proposes additional restrictions on importing covered equipment into the United States. Among other things, the proposal would generally permit covered equipment to be imported only where it has a valid, unrestricted authorization, is imported in quantities of 40 or fewer units for testing/evaluation or product development, is imported solely for export, or is intended for certain U.S. Government purposes.
For a Chinese manufacturer, this could make U.S. product development and commercial launch more difficult where authorization status is uncertain. The proposed framework would also reinforce restrictions on marketing unauthorized equipment and tighten rules concerning pre-authorization operation.
The accompanying Third Report and Order separately closes a “component part loophole” by prohibiting authorization of certain devices containing logic-bearing hardware components produced by Covered List entities. It also subjects modifications or permissive changes made by Covered List entities to full certification. Those provisions are distinct from the proposals in the FNPRM but demonstrate the direction in which the FCC is moving.
Equipment Authorization Expirations
The FCC also seeks comment on term limits for equipment certifications, potentially requiring periodic recertification. Currently, device certifications are good forever, unless withdrawn, revoked, or terminated or become subject to a subsequent rule change that affects their validity. The Commission asks whether a 10-year term is sufficient. For Chinese manufacturers, these measures could mean that FCC compliance becomes a continuing obligation rather than a one-time certification exercise. Manufacturers may need systems capable of tracking component changes, production sites, suppliers, software updates, corporate ownership, and FCC representations over the entire product lifecycle.
Impacts
Taken together, the Third FNPRM would make the FCC equipment-authorization regime substantially more supply-chain-oriented. The FCC is considering a framework under which regulators could examine the entire chain: the manufacturer, contract manufacturers, production locations, component suppliers, software and firmware, branding arrangements, importers, and U.S. entities responsible for compliance. Costs of compliance would certainly increase as a result.
For Chinese manufacturers that are not currently on the Covered List, the immediate message is therefore not that U.S. market access will necessarily disappear, but that traditional certification and OEM structures may become inadequate. Companies should follow the FCC’s rulemaking closely and be prepared to adjust to any new requirements.