FCC Covered List Expands as National Security Controls Reach Deeper into Technology Supply Chains
18. September 2026The US administration is rapidly expanding the use of the Federal Communications Commission’s (FCC’s) Covered List as a national security tool, extending restrictions beyond named companies and equipment to broad categories of foreign-produced connected equipment. Recent additions covering uncrewed aircraft systems, consumer-grade routers, advanced robotic devices, and power inverters mean that companies well outside the traditional telecommunications sector may now need to consider FCC equipment authorization requirements as part of their supply chain and trade compliance programs.
The shift has potentially significant consequences. Equipment placed on the Covered List generally cannot receive a new FCC equipment authorization. For devices that require authorization, that can effectively prevent future importation, marketing, and sale in the United States. Recent actions also demonstrate that the government is increasingly looking beyond the identity of a manufacturer to where equipment is produced and, in some circumstances, what components are inside it.
FROM TELECOMMUNICATIONS REGULATION TO NATIONAL SECURITY TOOL
Although it has worked closely with other agencies (e.g., the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector, commonly referred to as “Team Telecom”) to address national security risk related to telecommunications authorizations and submarine cable licenses it grants and regulates, the FCC has not traditionally been viewed as a national security agency. However, its authority over devices that emit radio frequency signals gives it an important role in regulating the connected equipment on which businesses and consumers increasingly rely.
The Secure and Trusted Communications Networks Act of 2019 (Secure Networks Act) established the Covered List for communications equipment and services determined to pose an unacceptable risk to US national security or the security and safety of US persons. The Secure Equipment Act of 2021 subsequently required the FCC to prohibit authorization of covered equipment.
Importantly, the FCC does not independently decide what belongs on the Covered List. Under the Secure Networks Act, additions generally depend on determinations from specified national security agencies or interagency bodies (e.g., Team Telecom). Once the statutory requirements are satisfied, however, the FCC implements the resulting restrictions through its equipment authorization regime and uses its investigative and enforcement authorities to achieve compliance.
The Covered List initially focused largely on equipment and services associated with specifically identified companies. More recent actions represent a significant expansion of that model.
In December 2025, the FCC relied on a national security determination made by a White House-convened Executive Branch interagency body to add uncrewed aircraft systems (UAS)/drones and UAS critical components produced in foreign countries, subject to specified exceptions. In March 2026, the FCC similarly relied on a White House-convened Executive Branch interagency body’s national security determination to add consumer-grade routers produced in foreign countries, except those receiving conditional approval. In July, foreign-produced advanced robotic devices and power inverters were added by relying again on the White House-led national security assessment process that was employed to include foreign-produced UAS/drones and consumer-grade routers to the Covered List.
The national security rationale focuses in significant part on the risks created by connectivity. Connected devices can potentially provide avenues for remote access, surveillance, sensitive-data exfiltration, intellectual property theft, or disruption and sabotage. The government's consumer router determination, for example, cited the use of router vulnerabilities in major cyber campaigns and warned that compromised devices could provide foreign actors a built-in backdoor to homes, businesses, critical infrastructure, and emergency services.
Connected vehicles, which are being addressed separately under the Commerce Department’s Executive Order 13873 information and communications technology and services (ICTS) supply chain authorities, illustrate the broader concerns. Modern vehicles contain communication, sensor, software, and data collection technology. Similar concerns can extend to other connected technologies that might provide surveillance capabilities near sensitive locations or enable remote interference with physical systems.
THE NEW MODEL LOOKS BEYOND FOREIGN ADVERSARIES
Perhaps the most consequential feature of recent Covered List actions is that they do not necessarily depend on whether equipment originates in a designated foreign adversary country.
The consumer router restriction, for example, applies to routers produced in a foreign country regardless of the producer's nationality. That means a US-headquartered company's equipment could potentially fall within the restriction if the relevant production occurs abroad.
For companies accustomed to trade compliance frameworks centered on sanctioned jurisdictions, restricted parties, or countries of concern, this requires a different lens. A supply chain in Canada, Mexico, Europe, or elsewhere may require analysis even where there is no traditional foreign-adversary connection.
The FCC is also moving deeper into products themselves. In July, the Commission adopted rules prohibiting authorization of certain devices incorporating logic-bearing hardware components produced by entities identified on the Covered List. The rule addresses components such as integrated circuits, modules, and other hardware capable of processing or transmitting data, reflecting the concern that a compromised component can undermine an otherwise noncovered finished device. The FCC has also sought comment on whether broader component-based restrictions are warranted.
The result is a regulatory model that increasingly demands visibility beyond tier-one suppliers.
CONDITIONAL APPROVALS PROVIDE A PATH FOR SOME FOREIGN PRODUCTION
The breadth of the new categorical restrictions has also produced a mechanism for distinguishing equipment that may not present the risks underlying the broader determination.
For certain categories, manufacturers can seek a conditional approval from designated national security agencies. For routers, for example, the FCC acts as the conduit for information reviewed by the US Departments of War and Homeland Security. A favorable determination allows specified equipment to remain outside the Covered List restrictions for the approval period.
The process resembles a rebuttable presumption: covered foreign production is presumed to present an unacceptable risk, but a company can provide information supporting a different determination for particular equipment.
The government's guidance as to the information required to request conditional approval illustrates the depth of the inquiry. Applicants must disclose corporate structure and ownership, including beneficial owners of 5% or more, board and executive leadership, and foreign government ownership or influence. They must also provide detailed manufacturing and supply chain information, including a bill of materials, component countries of origin, software and intellectual property ownership and responsibilities, and potential supply chain choke points. The government also seeks information concerning plans to establish trusted manufacturing capacity in the United States.
Conditional approvals have already been granted for certain UAS/drones and consumer router products, demonstrating that the process is not merely theoretical. The conditional approvals that have been granted have varied in length with no end dates assigned to UAS/drones and various dates assigned to consumer routers.
WHAT COMPANIES SHOULD BE DOING NOW
For businesses that manufacture, import, integrate, distribute, or rely on connected equipment, Covered List compliance is becoming a supply chain exercise as much as an FCC exercise. Companies should consider the following:
- Mapping products and components against current Covered List categories: Determine which products and components may fall within existing categories and which products require FCC authorization.
- Reviewing the supply chain beyond tier-one suppliers: Identify where equipment and potentially relevant components are produced, who supplies them, and whether supplier representations remain reliable when sourcing, manufacturing locations, or component suppliers change.
- Maintaining detailed documentation: Keep records of supplier inquiries, equipment authorizations, countries of production, bills of materials where appropriate, and the level of diligence applied to particular suppliers.
- Tracking authorization dates and product changes: Existing equipment authorizations may receive different treatment from future authorizations. Companies should therefore document authorization dates and monitor subsequent software, firmware, hardware, and component changes.
- Monitoring adjacent sectors: The rapid progression from drones to routers, robotics, and power equipment suggests that the Covered List is becoming an increasingly important tool for addressing ICTS supply chain risk. Companies should monitor developments affecting sectors adjacent to those already covered.
- Assessing embedded components: Recent FCC action on logic-bearing hardware components reinforces the need to understand what is inside connected products. As connected functionality becomes embedded in more products, the distinction between a telecommunications company and a company subject to telecommunications regulation is becoming less useful.
- Preparing to conduct risk-based due diligence: When any addition to the Covered List potentially impacts a company’s path to market, the company should be prepared to conduct risk-based due diligence on proposed alternative suppliers or other alternative counterparties. This will help the company to mitigate the risk of later investigations or enforcement actions by the FCC or other US government agencies regarding whether new counterparties are indeed bona fide or, instead, are suspected of participating in a scheme to evade the Covered List’s restrictions.
The practical challenge is therefore not simply determining whether a company appears on a government list. Increasingly, companies may need to know what is inside their products, where those products and components were made, who controls the relevant technology, and how those facts can be documented if regulators come asking.
Developments that have been building for years can move quickly once they reach a tipping point. For companies with globally distributed manufacturing and connected products, understanding the supply chain before the next Covered List expansion may be considerably easier than reconstructing it afterward.
Loyaan Egal previously served as a special advisor to the FCC chair, chief of the FCC Enforcement Bureau, and led the FCC’s Privacy and Data Protection Task Force. Prior to his leadership positions at the FCC, he oversaw the US Department of Justice’s national security efforts related to the telecommunications services and ICTS supply chain sectors as the first staff chair of the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector and a deputy chief in the Foreign Investment Review Section of the Department of Justice’s National Security Division.
Contacts
If you have any questions or would like more information on the issues discussed in this Insight, please contact any of the following: