On August 7, 2026, the Federal Communications Commission (FCC) published its Third Further Notice of Proposed Rulemaking (FCC 26-50, ET Docket No. 21-232) in the Federal Register (91 FR 51139), opening a 32-day comment window on the most sweeping overhaul yet of the US equipment authorization program. Comments are due September 8, 2026 and reply comments September 21, 2026. The proceeding, adopted July 22, 2026 and released July 23, 2026, would impose hardware and software bill of materials (HBOM/SBOM) disclosure on certified equipment, split the Covered List into two categories, require a US-based liable party for every FCC-certified device, and add term limits to authorizations.
For US telecom equipment manufacturers, importers, router and unmanned aircraft system (UAS) OEMs, Telecommunication Certification Bodies (TCBs) and Supplier's Declaration of Conformity (SDoC) registrants, this is not a future-state planning item. The proposals interact with the existing Covered List ban, in force since February 6, 2023 and covering Huawei, ZTE, Hytera, Hikvision and Dahua, and with the list's recent expansion to production location-based entries for UAS, UAS critical components and routers "produced in a foreign country". Comments filed now shape rules that will govern certification filings, supply-chain disclosures and import practices.
Who must act, and by what date?
Any party that obtains or holds FCC equipment authorization, or imports or markets radio-frequency equipment in the United States, has standing to comment by September 8, 2026, with replies due September 21, 2026. The Notice explicitly seeks input from small entities, with a separate Initial Regulatory Flexibility Analysis (Appendix D) inviting small-business comment under a distinct heading. Comments are filed through the FCC's Electronic Comment Filing System (ECFS) under ET Docket No. 21-232, and the full text, including the companion Third Report and Order, is available at FCC-26-50A1.pdf.
What would the HBOM and SBOM disclosure rules require?
The FCC proposes to require every certification applicant to submit a signed hardware bill of materials and software bill of materials identifying, for each component, its producer, its production location or locations, and the percentage of component value attributable to each location, with updates required within 30 days of any change. The Commission offers preliminary cost estimates of under $5,000 per software program and up to $10,000 per hardware device, and explicitly asks whether the obligation should be narrowed to Covered List sectors, to higher-risk equipment, or to specified component categories such as logic-bearing hardware, modular transmitters and semiconductors. Compliance leads should map their component-level supply-chain data now, because the 30-day update cadence is tighter than most current supplier disclosure cycles.
How would the Covered List and white-labeling rules change?
The Notice proposes to bifurcate the Covered List into producer/provider-based entries and production location-based entries, with the Public Safety and Homeland Security Bureau redesigning the list website into two columns. Alongside this structural split, the FCC seeks comment on codifying a definition of "produced by" for Covered List purposes, requiring applicants to disclose every entity that produced a device, and closing a rebranding loophole by requiring disclosure of all brand and model names tied to a single FCC ID. Building on the logic-bearing hardware component prohibition adopted in the companion Third Report and Order, the Notice also asks whether to prohibit, or apply a rebuttable presumption against, authorizing any device containing a component produced by a Covered List entity, and whether to impose certification requirements on devices in Covered List sectors.
What other authorization reforms are on the table?
The Notice bundles a wide set of further measures: a mandatory US-based liable party for all FCC-certified equipment; term limits on equipment authorizations; streamlined revocation procedures; codified permissive-change waivers for software, firmware and hardware updates to covered equipment; restrictions on use of the FCC logo; reforms to importation, marketing and pre-authorization operation rules; registration of SDoC devices; modernization of the FCC equipment authorization database; updates to submarine cable Covered List rules; and codified definitions for UAS, UAS critical components and routers.
| Proposal | What it would add | Who is exposed |
|---|---|---|
| HBOM/SBOM disclosure | Per-component producer, location and value share, 30-day updates | All certification applicants, potentially narrowed |
| Covered List bifurcation | Producer/provider column plus production-location column | Listed entities and their rebranding partners |
| US-based liable party | One US entity accountable per certified device | Non-US OEMs selling into the US |
| Authorization term limits | Time-bounded certifications subject to renewal | All holders of FCC authorization |
Continuous, per-jurisdiction real-time monitoring surfaces this kind of change the moment it publishes in the Federal Register, rather than when a certification filing is first rejected.
Take advantage of this real-time watch
Next steps for compliance teams: confirm whether your products fall in a Covered List sector (UAS, UAS critical components, routers) or use logic-bearing components from listed entities; inventory the producer, production location and value-share data you would need to assemble an HBOM/SBOM within the proposed 30-day update window; identify a US-based liable party if you are a non-US manufacturer; and file comments by September 8, 2026 on the cost, scope and narrowing alternatives the FCC has explicitly requested.


