top of page

US FCC Covered List Update: Components & E-Commerce

13 hours ago
7 min read

United States Extends FCC Covered List Enforcement to Device Components, Product Modifications and Online Marketplaces


Until now, the question at the heart of the FCC Covered List regime was fairly simple: who made the finished product? Starting October 13, 2026, that is no longer enough. The Federal Communications Commission has adopted rules that look past the brand on the enclosure and into the circuit board, the change log, and the online storefront.

The changes come from the FCC's Third Report and Order in ET Docket No. 21-232 (FCC 26-50), adopted on July 22, 2026, and published in the Federal Register on September 11, 2026 (91 FR 57798). For any company placing radio frequency (RF) or digital devices on the US market, the order turns national security screening into a design, sourcing, and distribution issue, not only a certification formality.


Quick Facts


Item

Detail

Authority

Federal Communications Commission (FCC), Office of Engineering and Technology

Instrument

Third Report and Order, FCC 26-50

Docket

ET Docket No. 21-232

Federal Register citation

91 FR 57798 (FR Doc. 2026-18535), published September 11, 2026

Rules amended

47 CFR Parts 1 and 2 (§§ 1.50001, 2.803, 2.902, 2.903, 2.932, 2.1043, 2.1204)

Effective date

October 13, 2026

Marketplace compliance dates

March 1, 2027 and June 1, 2027

Legal basis

Secure and Trusted Communications Networks Act of 2019; Secure Equipment Act of 2021


Why the FCC Acted: Three Gaps in the System


The FCC's Covered List framework has been built in stages. The First Report and Order (2022) barred new authorizations for covered equipment, and the Second Report and Order (2025) addressed covered modular transmitters. Recent Covered List additions for uncrewed aircraft systems (UAS), UAS critical components, and routers produced abroad raised the stakes further.

The third order targets three routes by which covered technology could still reach US networks:


  1. The component route: a non-covered brand building a device around chips or modules from a covered producer.

  2. The modification route: covered entities updating authorized products through lighter-touch permissive change or SDoC procedures.

  3. The retail route: unauthorized devices reaching consumers through online marketplaces that presented themselves as neutral intermediaries.


How the FCC Covered List Now Reaches Inside the Device


The FCC will no longer authorize a device that contains a logic-bearing hardware component made by a Covered List entity, where the device would itself be barred had that entity produced it as a whole. The Commission's position is that a compromised component carries essentially the same risk as a compromised finished product, whoever assembles it.


What counts as "logic-bearing"


The new definition in 47 CFR 2.902 borrows from the existing "digital device" concept in Part 15. It covers any device, module, sub-assembly, integrated circuit, or other physical part that:


  • uses timing signals above 9,000 pulses per second together with digital techniques, or

  • uses RF energy to process, store, retrieve, or transfer data.


For engineering teams, this realistically includes processors, systems-on-chip, microcontrollers, programmable logic, memory, wireless chipsets, and RF modules.


What remains outside the rule


  • Purely mechanical or passive parts, such as housings, fasteners, resistors, wiring, and plain battery cells.

  • Software and firmware, which the FCC declined to regulate under this order.

  • Components from entities listed only under production location-based entries (for example, the foreign-produced UAS and router entries), unless the producer is separately named on the Covered List.


The FCC also rejected, for now, a blanket ban on every component from Covered List entities and a wider ban on parts from any foreign adversary-controlled company. Both questions remain open in the record.


Transition for existing products and pending filings


The prohibition is forward-looking. Existing grants are untouched, and applications already pending on October 13, 2026 continue under the prior rules unless they are amended to add, replace, or alter a logic-bearing component.


An infographic summarizing new FCC rules that expand Covered List enforcement to internal logic-bearing components, product modifications, and e-commerce marketplaces.

No More Shortcuts for Covered Entities


The order closes the modification pathway for Covered List entities. Any change they make to equipment, even to equipment that is not itself covered, now requires a new grant of certification. Class I and Class II permissive changes are unavailable to them, and the Supplier's Declaration of Conformity (SDoC) cannot be used for any modification.


The FCC also confirmed that permissive changes are barred for any modification that would turn an authorized device into covered equipment, for example moving production to a Covered List entity, or a change that removes a device's "domestic end product" status.


Two boundaries matter here. First, a non-covered manufacturer modifying a product originally built by a Covered List entity is not caught, as long as the change does not make the device "produced by" that entity. Second, existing waivers permitting Class I and II permissive changes for covered UAS equipment and covered routers stay in force until January 1, 2029.


E-Commerce Platforms Become Part of the Compliance Chain


The FCC has amended its marketing rules in 47 CFR 2.803 to make clear that online marketplaces can be responsible for unauthorized devices sold through them. A platform that lists RF equipment and provides services such as warehousing, fulfillment, packaging, order processing, or billing is now treated as marketing that equipment, even if a third party is the seller. Enforcement does not depend on proof that the platform knew the device was non-compliant.

Platforms must also show the FCC ID at the online point of sale, with obligations scaled to their level of control:


Marketplace model

Obligation

Compliance date

Sells its own devices, or has physical access to or title over a third-party device

Display a valid and accurate FCC ID

March 1, 2027

Hosts third-party listings without physical access or title

Display a valid FCC ID, verify it against the FCC Equipment Authorization System, and require seller certification of accuracy

June 1, 2027


Not every listing is caught. Listings posted before the effective date and not later substantively edited, listings by sellers below the "high-volume third-party seller" threshold of the INFORM Consumers Act, and listings for used devices are exempt. FCC ID labeling on external packaging was considered but not adopted.


A Narrower Definition of "Critical Infrastructure"


Following a partial remand from the U.S. Court of Appeals for the D.C. Circuit, the FCC rewrote the definition of "critical infrastructure" used in Covered List determinations under section 889(f)(3) of the 2019 NDAA. The court had found the earlier "connected to" wording too broad. The revised definition covers systems and assets used in the 16 DHS critical infrastructure sectors when used to deliver one of the 55 National Critical Functions. The order also fixes cross-references in § 2.903 and clerical errors in the import conditions of § 2.1204.


What This Means for Manufacturers


The practical effect of this update is that FCC eligibility is now decided at the bill-of-materials level. How that plays out depends on a company's position in the supply chain:


  • Brand owners and OEMs: Certification readiness now depends on knowing who produced every processing and wireless component. A single covered chipset can block an otherwise compliant product.

  • Module and chipset suppliers: Customers will increasingly ask for origin declarations and producer traceability as a condition of design-in, particularly for modules reused across multiple host products.

  • ODMs and contract manufacturers: Alternate-part substitutions made for cost or availability can have regulatory consequences if they affect a product under a new or amended FCC filing.

  • Importers and online sellers: Accurate FCC IDs become a prerequisite for listing on major platforms, and missing or incorrect IDs may lead to delisting.

  • Covered List entities: Every product update carries the cost and lead time of a full certification cycle through a TCB.


Applicants already certify to their TCB that the equipment is not covered equipment. Because that determination now depends on internal components, manufacturers should ask their TCB how component sourcing will be documented and reviewed in the application file.


Certification Impact Summary


Scenario after October 13, 2026

Outcome

New device using a processor or RF module made by a producer named on the FCC Covered List

Cannot be authorized

New device using only passive or mechanical parts from a Covered List entity

Not affected by the component ban

New device whose only link to the Covered List is covered firmware or software

Not prohibited under this order

Component from an entity covered only under a production location-based entry

Component ban does not apply, unless the producer is separately listed

Product already holding an FCC grant

Grant remains valid

Application pending on October 13, 2026 and not amended

Continues under previous rules

Pending application amended to change a logic-bearing component

New prohibition applies

Covered List entity modifies any equipment

Full recertification required; no permissive change, no SDoC

Non-covered OEM modifies a device originally made by a Covered List entity

Normal modification rules, unless the change makes the device "produced by" that entity

Covered UAS or router holding an existing OET waiver

Permissive changes allowed until January 1, 2029


Timeline and Required Actions


Regulatory Timeline


Date

Event

July 22–23, 2026

Third Report and Order adopted and released

September 11, 2026

Publication in the Federal Register

October 13, 2026

Component prohibition, recertification rule, marketing clarifications, and new critical infrastructure definition take effect

March 1, 2027

FCC ID display mandatory for marketplaces selling directly or holding physical access/title

June 1, 2027

FCC ID verification and seller certification mandatory for third-party-only marketplaces

January 1, 2029

End of existing permissive change waivers for covered UAS and routers


Action Plan


Immediately (before October 13, 2026)

  • Map every logic-bearing component in products planned for US certification, including second-source and alternate parts.

  • Screen each component producer, and its parent companies and affiliates, against the current FCC Covered List.

  • Prioritize filing products that are ready for certification, and freeze their logic-bearing component lists while applications are pending.


Short term (October 2026 – Q1 2027)

  • Replace covered components and schedule the redesign and retesting required.

  • Add supplier origin declarations to procurement contracts and component qualification procedures.

  • Agree with your TCB on how component sourcing evidence will be presented in applications.

  • Introduce a regulatory check into engineering change control, so part substitutions are screened before any FCC filing.


Before the marketplace deadlines (March 1 and June 1, 2027)

  • Validate every FCC ID in your portfolio against the FCC Equipment Authorization System.

  • Share FCC IDs with distributors, resellers, and platform partners in a structured format.

  • Update listings you create or revise, since substantive edits remove the pre-effective-date exemption.


Ongoing

  • Monitor Covered List updates, which can bring new producers into scope overnight.

  • Follow the open FCC record on broader component bans, software and firmware, and packaging labels.


Frequently Asked Questions


Does this rule cancel existing FCC grants? No. The component prohibition applies to new applications only. Existing authorizations remain valid.


Is firmware from a Covered List company prohibited? Not under this order. The FCC limited the ban to hardware and left software and firmware for possible future action.


Do small online sellers need to display FCC IDs? The display obligation does not apply to listings by sellers who fall below the INFORM Consumers Act "high-volume third-party seller" threshold, nor to used devices.


Can a Covered List entity still file a Class II permissive change? No. Every modification by a Covered List entity requires a new certification, except under the existing UAS and router waivers, which run until January 1, 2029.

bottom of page