Summary
- The FCC voted to deny new authorization to a device containing logic-bearing hardware from a producer/provider-based Covered List entity when the finished device would be barred if that entity had made it.
- Chips, cellular or IoT modules, baseband hardware, optical transceivers and printed circuit boards can fall within the rule; inert parts such as screws do not.
- Online marketplaces must display the FCC ID for certified devices at the point of sale.
- A Covered List entity must use full certification for modifications and cannot rely on the Supplier's Declaration of Conformity route.
- The order does not generally revoke previously authorized products, and broader location-based component restrictions remain proposals.
The economic effect of the FCC's vote begins before a device reaches a shop. An assembler seeking US authorization must now know whether the logic-bearing parts inside its product came from a producer or provider on the Covered List. If the device would be ineligible when made by that listed entity, using its controlling hardware no longer cures the problem.
That closes a genuine allocation gap. Since 2022, finished equipment made by named companies such as Huawei and ZTE has faced restrictions on new authorizations. A different company could nonetheless assemble a product around a listed supplier's component and present itself as the applicant. The new rule treats the source of the relevant logic as part of the finished device's security identity.
Compliance moves into procurement
Logic-bearing is the limiting term. The order reaches components capable of processing, storing or directing information: semiconductors, cellular and IoT modules, baseband units, optical transceivers and printed circuit boards are among the relevant examples. It is not a ban on every material or mechanical input. Screws, nails and other inert parts do not become security-controlled merely because a listed company supplied them.
For manufacturers, the cost is not confined to a filing fee. Bills of materials, supplier attestations, redesign options and component substitutions become market-access controls. A cheaper module can become expensive if it prevents authorization of the entire device. The burden will be greatest where suppliers, firmware ownership and white-label manufacturing are difficult to trace.
The rule is also deliberately narrower than a blanket country-of-origin ban. Its adopted component prohibition attaches to producer/provider-based Covered List determinations. The FCC is asking for comment on broader location-based categories, hardware and software bills of materials and additional software or firmware restrictions. Those ideas could expand the compliance surface later, but they are not today's rule.
Marketplaces become part of enforcement
The FCC also clarified that online marketplaces participate in marketing equipment even when a third party is the seller. Certified products must show their FCC ID at the online point of sale. That identifier gives buyers and regulators a way to compare a listing with the authorization database.
The marginal task of displaying an identifier may be small. The operating obligation is larger: platforms must preserve the link between a constantly changing seller catalogue and an external certification record. A missing or reused number can expose a marketplace to scrutiny rather than leaving the issue solely with the merchant.
Covered List entities face a tighter modification path as well. Changes and permissive modifications require full certification, and those entities cannot use the lighter Supplier's Declaration of Conformity process. That makes post-approval redesign more costly and reduces the value of obtaining approval through one configuration before altering the product later.
Existing stock is not automatically withdrawn
The order acts on new and pending authorizations. It does not say that every previously authorized device containing a newly relevant component must disappear from use or sale. Previously approved equipment also cannot be modified so that it becomes covered, but a forward authorization restriction is not the same as a universal recall.
The Commission separately narrowed its definition of critical infrastructure after a court found an earlier version too broad. That matters for surveillance and communications equipment whose covered status depends on the use case. A more defensible definition may reduce litigation risk even as the component rule expands supplier scrutiny.
Who pays is therefore divided. Manufacturers pay to trace and, where necessary, replace components. Certification applicants pay for a more demanding evidentiary record. Marketplaces pay to connect listings with FCC IDs. Listed suppliers and their customers bear the lost option value when a component can no longer carry a device into the US market.
The next useful evidence will be the released final order, its effective dates and the first authorization or enforcement decisions applying the logic-bearing test. Those records will show whether the FCC has created a workable procurement rule or a compliance standard whose uncertain edges make manufacturers redesign more products than the text strictly requires.

