US FCC Covered List Update: Components & E-Commerce
United States Extends FCC Covered List Enforcement to Device Components, Product Modifications and Online Marketplaces
Until now, the question at the heart of the FCC Covered List regime was fairly simple: who made the finished product? Starting October 13, 2026, that is no longer enough. The Federal Communications Commission has adopted rules that look past the brand on the enclosure and into the circuit board, the change log, and the online storefront.
The changes come from the FCC's Third Report and Order in ET Docket No. 21-232 (FCC 26-50), adopted on July 22, 2026, and published in the Federal Register on September 11, 2026 (91 FR 57798). For any company placing radio frequency (RF) or digital devices on the US market, the order turns national security screening into a design, sourcing, and distribution issue, not only a certification formality.
Quick Facts
Item | Detail |
Authority | Federal Communications Commission (FCC), Office of Engineering and Technology |
Instrument | Third Report and Order, FCC 26-50 |
Docket | ET Docket No. 21-232 |
Federal Register citation | 91 FR 57798 (FR Doc. 2026-18535), published September 11, 2026 |
Rules amended | 47 CFR Parts 1 and 2 (§§ 1.50001, 2.803, 2.902, 2.903, 2.932, 2.1043, 2.1204) |
Effective date | October 13, 2026 |
Marketplace compliance dates | March 1, 2027 and June 1, 2027 |
Legal basis | Secure and Trusted Communications Networks Act of 2019; Secure Equipment Act of 2021 |
Why the FCC Acted: Three Gaps in the System
The FCC's Covered List framework has been built in stages. The First Report and Order (2022) barred new authorizations for covered equipment, and the Second Report and Order (2025) addressed covered modular transmitters. Recent Covered List additions for uncrewed aircraft systems (UAS), UAS critical components, and routers produced abroad raised the stakes further.
The third order targets three routes by which covered technology could still reach US networks:
The component route: a non-covered brand building a device around chips or modules from a covered producer.
The modification route: covered entities updating authorized products through lighter-touch permissive change or SDoC procedures.
The retail route: unauthorized devices reaching consumers through online marketplaces that presented themselves as neutral intermediaries.
How the FCC Covered List Now Reaches Inside the Device
The FCC will no longer authorize a device that contains a logic-bearing hardware component made by a Covered List entity, where the device would itself be barred had that entity produced it as a whole. The Commission's position is that a compromised component carries essentially the same risk as a compromised finished product, whoever assembles it.
What counts as "logic-bearing"
The new definition in 47 CFR 2.902 borrows from the existing "digital device" concept in Part 15. It covers any device, module, sub-assembly, integrated circuit, or other physical part that:
uses timing signals above 9,000 pulses per second together with digital techniques, or
uses RF energy to process, store, retrieve, or transfer data.
For engineering teams, this realistically includes processors, systems-on-chip, microcontrollers, programmable logic, memory, wireless chipsets, and RF modules.
What remains outside the rule
Purely mechanical or passive parts, such as housings, fasteners, resistors, wiring, and plain battery cells.
Software and firmware, which the FCC declined to regulate under this order.
Components from entities listed only under production location-based entries (for example, the foreign-produced UAS and router entries), unless the producer is separately named on the Covered List.
The FCC also rejected, for now, a blanket ban on every component from Covered List entities and a wider ban on parts from any foreign adversary-controlled company. Both questions remain open in the record.
Transition for existing products and pending filings
The prohibition is forward-looking. Existing grants are untouched, and applications already pending on October 13, 2026 continue under the prior rules unless they are amended to add, replace, or alter a logic-bearing component.

No More Shortcuts for Covered Entities
The order closes the modification pathway for Covered List entities. Any change they make to equipment, even to equipment that is not itself covered, now requires a new grant of certification. Class I and Class II permissive changes are unavailable to them, and the Supplier's Declaration of Conformity (SDoC) cannot be used for any modification.
The FCC also confirmed that permissive changes are barred for any modification that would turn an authorized device into covered equipment, for example moving production to a Covered List entity, or a change that removes a device's "domestic end product" status.
Two boundaries matter here. First, a non-covered manufacturer modifying a product originally built by a Covered List entity is not caught, as long as the change does not make the device "produced by" that entity. Second, existing waivers permitting Class I and II permissive changes for covered UAS equipment and covered routers stay in force until January 1, 2029.
E-Commerce Platforms Become Part of the Compliance Chain
The FCC has amended its marketing rules in 47 CFR 2.803 to make clear that online marketplaces can be responsible for unauthorized devices sold through them. A platform that lists RF equipment and provides services such as warehousing, fulfillment, packaging, order processing, or billing is now treated as marketing that equipment, even if a third party is the seller. Enforcement does not depend on proof that the platform knew the device was non-compliant.
Platforms must also show the FCC ID at the online point of sale, with obligations scaled to their level of control:
Marketplace model | Obligation | Compliance date |
Sells its own devices, or has physical access to or title over a third-party device | Display a valid and accurate FCC ID | March 1, 2027 |
Hosts third-party listings without physical access or title | Display a valid FCC ID, verify it against the FCC Equipment Authorization System, and require seller certification of accuracy | June 1, 2027 |
Not every listing is caught. Listings posted before the effective date and not later substantively edited, listings by sellers below the "high-volume third-party seller" threshold of the INFORM Consumers Act, and listings for used devices are exempt. FCC ID labeling on external packaging was considered but not adopted.
A Narrower Definition of "Critical Infrastructure"
Following a partial remand from the U.S. Court of Appeals for the D.C. Circuit, the FCC rewrote the definition of "critical infrastructure" used in Covered List determinations under section 889(f)(3) of the 2019 NDAA. The court had found the earlier "connected to" wording too broad. The revised definition covers systems and assets used in the 16 DHS critical infrastructure sectors when used to deliver one of the 55 National Critical Functions. The order also fixes cross-references in § 2.903 and clerical errors in the import conditions of § 2.1204.
What This Means for Manufacturers
The practical effect of this update is that FCC eligibility is now decided at the bill-of-materials level. How that plays out depends on a company's position in the supply chain:
Brand owners and OEMs: Certification readiness now depends on knowing who produced every processing and wireless component. A single covered chipset can block an otherwise compliant product.
Module and chipset suppliers: Customers will increasingly ask for origin declarations and producer traceability as a condition of design-in, particularly for modules reused across multiple host products.
ODMs and contract manufacturers: Alternate-part substitutions made for cost or availability can have regulatory consequences if they affect a product under a new or amended FCC filing.
Importers and online sellers: Accurate FCC IDs become a prerequisite for listing on major platforms, and missing or incorrect IDs may lead to delisting.
Covered List entities: Every product update carries the cost and lead time of a full certification cycle through a TCB.
Applicants already certify to their TCB that the equipment is not covered equipment. Because that determination now depends on internal components, manufacturers should ask their TCB how component sourcing will be documented and reviewed in the application file.
Certification Impact Summary
Scenario after October 13, 2026 | Outcome |
New device using a processor or RF module made by a producer named on the FCC Covered List | Cannot be authorized |
New device using only passive or mechanical parts from a Covered List entity | Not affected by the component ban |
New device whose only link to the Covered List is covered firmware or software | Not prohibited under this order |
Component from an entity covered only under a production location-based entry | Component ban does not apply, unless the producer is separately listed |
Product already holding an FCC grant | Grant remains valid |
Application pending on October 13, 2026 and not amended | Continues under previous rules |
Pending application amended to change a logic-bearing component | New prohibition applies |
Covered List entity modifies any equipment | Full recertification required; no permissive change, no SDoC |
Non-covered OEM modifies a device originally made by a Covered List entity | Normal modification rules, unless the change makes the device "produced by" that entity |
Covered UAS or router holding an existing OET waiver | Permissive changes allowed until January 1, 2029 |
Timeline and Required Actions
Regulatory Timeline
Date | Event |
July 22–23, 2026 | Third Report and Order adopted and released |
September 11, 2026 | Publication in the Federal Register |
October 13, 2026 | Component prohibition, recertification rule, marketing clarifications, and new critical infrastructure definition take effect |
March 1, 2027 | FCC ID display mandatory for marketplaces selling directly or holding physical access/title |
June 1, 2027 | FCC ID verification and seller certification mandatory for third-party-only marketplaces |
January 1, 2029 | End of existing permissive change waivers for covered UAS and routers |
Action Plan
Immediately (before October 13, 2026)
Map every logic-bearing component in products planned for US certification, including second-source and alternate parts.
Screen each component producer, and its parent companies and affiliates, against the current FCC Covered List.
Prioritize filing products that are ready for certification, and freeze their logic-bearing component lists while applications are pending.
Short term (October 2026 – Q1 2027)
Replace covered components and schedule the redesign and retesting required.
Add supplier origin declarations to procurement contracts and component qualification procedures.
Agree with your TCB on how component sourcing evidence will be presented in applications.
Introduce a regulatory check into engineering change control, so part substitutions are screened before any FCC filing.
Before the marketplace deadlines (March 1 and June 1, 2027)
Validate every FCC ID in your portfolio against the FCC Equipment Authorization System.
Share FCC IDs with distributors, resellers, and platform partners in a structured format.
Update listings you create or revise, since substantive edits remove the pre-effective-date exemption.
Ongoing
Monitor Covered List updates, which can bring new producers into scope overnight.
Follow the open FCC record on broader component bans, software and firmware, and packaging labels.
Frequently Asked Questions
Does this rule cancel existing FCC grants? No. The component prohibition applies to new applications only. Existing authorizations remain valid.
Is firmware from a Covered List company prohibited? Not under this order. The FCC limited the ban to hardware and left software and firmware for possible future action.
Do small online sellers need to display FCC IDs? The display obligation does not apply to listings by sellers who fall below the INFORM Consumers Act "high-volume third-party seller" threshold, nor to used devices.
Can a Covered List entity still file a Class II permissive change? No. Every modification by a Covered List entity requires a new certification, except under the existing UAS and router waivers, which run until January 1, 2029.
