The Federal Communications Commission adopted a Third Report and Order on Secure Equipment Authorizations on July 22, 2026, closing the component-part loophole in the US supply-chain security regime. New devices that contain components from any Covered List entity can no longer receive FCC equipment authorization, and Covered List entities must file a full recertification for any modification to already-authorized gear. The move forces every manufacturer, importer, and certification body routing radio and telecom equipment into the US market to re-examine its bill of materials now.
The Order, released as FCC document DOC-423291A1, tightens a regime that has barred Huawei, ZTE, Hytera, Hikvision, Dahua and their affiliates from obtaining new FCC authorizations since February 6, 2023. Until now, a device could still pass authorization if the Covered List entity supplied only a sub-component rather than the whole product, and Covered List entities could make minor changes to authorized gear without a full recertification. Both doors are now shut.
What does the new Order change for equipment authorization?
Two obligations are now binding. First, the FCC will not grant a new equipment authorization to any device that contains a component, module, or sub-assembly sourced from a Covered List entity, whether or not that entity is the applicant. The bar reaches across the whole supply chain, not only to Covered List companies filing for themselves. Second, a Covered List entity that wants to modify an already-authorized device must file a full recertification application, not a minor-change amendment. Chairwoman Jessica Rosenworcel framed the action as closing the component-part loophole that bad actors have used to bring dangerous gear into US networks.
Practically, a manufacturer that previously certified a router or IoT module by sourcing only its Wi-Fi radio from a Covered List supplier can no longer rely on that structure. The Covered List component taints the whole application. The same logic reaches host devices that integrate modular transmitters from listed entities, an extension the FCC already flagged in its Second Report and Order and now makes operative by closing the residual gap.
Who has to act, and what is at stake?
The obligation lands on four groups: device manufacturers marketing radio or telecom equipment in the United States, importers of record for that equipment, IoT and connected-device vendors whose products fall under 47 CFR Part 15 or Part 2, and the Telecommunication Certification Bodies (TCBs) that issue certifications on the FCC's behalf. TCBs must now screen applications for Covered List components before granting a certification, not only screen for Covered List applicants.
The commercial stake is binary. A device denied FCC authorization cannot legally be marketed, sold, or imported in the United States. There is no grace period once the operative rules apply: pending applications that contain a Covered List component will be rejected, and already-marketed gear that a Covered List entity modifies without full recertification loses its authorization. For product lines with long design cycles, a sourcing decision made today determines US market access months from now.
How does this fit the existing Covered List regime?
The Covered List is the FCC's national-security overlay on its equipment-authorization program. The current list names Huawei, ZTE, Hytera, Hikvision, Dahua and their affiliates, and the underlying Secure Equipment Act of 2021 prohibited new authorizations for their equipment from February 6, 2023. The Second Report and Order extended the bar to modular transmitters and host devices. This Third Report and Order closes the last gap: it removes the component-level workaround and the minor-modification escape route. Each step has narrowed, not widened, the path to authorization.
What should compliance teams do now?
Treat the Order as an active trigger, not a watch item. Four actions are time-sensitive:
- Run a component-level supply-chain audit across every product line submitted for FCC certification, flagging any part, module, or sub-assembly sourced from a Covered List entity or its affiliates.
- Inventory pending and recently granted certifications. Applications that contain a Covered List component should be restructured before the operative date, or withdrawn.
- For Covered List entities holding existing authorizations, map every planned product change against the full-recertification requirement. No modification is minor anymore.
- Brief the TCB handling your filings: confirm it will apply the component screen to your application, and ask how it documents the supply-chain check.
The exact operative and compliance dates are set in the Federal Register publication of the Order. Confirm them against the FCC document before locking a redesign or filing timeline, and track the Federal Register notice rather than the July 22, 2026 adoption date alone.
| Obligation | Before the Third Report and Order | After the Third Report and Order |
|---|---|---|
| New device containing a Covered List component | Could be authorized if the applicant was not a Covered List entity | Cannot receive FCC authorization |
| Covered List entity modifying authorized gear | Minor-change amendment permitted | Full recertification required |
| Host device with a listed modular transmitter | Bar already applied (Second Report and Order) | Bar confirmed, component gap closed |
Take advantage of this real-time watch
For compliance leads: verify whether any active product line integrates a Covered List component, confirm the operative date in the Federal Register notice, and brief your TCB and sourcing team this week. Continuous, per-jurisdiction monitoring of FCC rulemaking surfaces this kind of change the moment it publishes, before a pending application is rejected or a product line is blocked at the border. Obsidian tracks this docket so you do not have to.


