POLKASPOTS

In validation · Supply-chain evidence · US FCC

The FCC now bans components you can't see.

From 6 September 2026, no device gets FCC equipment authorization if any logic-bearing hardware component — SoC, module, transceiver — was produced by a Covered List entity. Proposed next: a signed HBOM and SBOM with every application.

PolkaSpots is building the attestation layer that makes this provable once per component, instead of once per applicant.

BOOK A 30-MINUTE PILOT CALL
01
22 July 2026

FCC adopts the Third Report & Order: no authorization for devices containing logic-bearing hardware components produced by Covered List entities.

6 September 2026

The component ban takes effect, thirty days after Federal Register publication on 7 August.

8 / 21 September 2026

Comments and replies close on the proposal to require a signed HBOM and SBOM with every certification application, term-limited authorizations, and SDoC registration.

31 March 2027

The first ISP supply-chain annual report in which foreign-produced routers count.

October 2027 – February 2028

The first Conditional Approval renewal wave.

02

Around 43,000 certifications are granted each year through 18 Telecommunication Certification Bodies. The facts that now decide eligibility — who produced each processing component, and who owns that producer — are facts about the component, not about the applicant.

Yet every applicant is expected to research them independently, for every filing, under penalty of revocation. The same chipset gets re-documented hundreds of times. Nobody gets better information. Everybody pays.

03

One signed attestation per component, made by its producer: producing legal entity, ownership screened against the Covered List and its subsidiaries and affiliates, production sites. Versioned, append-only, cryptographically signed.

Applicants resolve their BOM against these attestations and roll up an HBOM/SBOM a TCB can actually verify — and every applicant using that component reuses the same record.

We filed this architecture as comments with the FCC in ET Docket 21-232.

NODE
Component producer
SIGNED ONCE
Attestation
Device maker ATCB CHECK
Device maker BTCB CHECK
Device maker CTCB CHECK
Attest once. Reuse everywhere.
04

For TCBs & test labs

The ban's due-diligence burden lands on you on 6 September, with no tooling behind it. We're piloting a verification API that screens BOM lines against producer attestations and a machine-readable Covered List.

For device makers & ODMs

If you file more than a handful of grants a year, you are about to document the same components again and again — and sign for it every time. Attest against the record instead.

05
FREE

The Covered List, screenable.

Entities, subsidiaries, and affiliates in one structured brief, updated as the list changes. Free.

One brief, no sequence. We email you when the list changes.

06

Three pilot slots. Same rule as ForgeCRA: design partners shape the schema. Everyone else waits.

Already collecting supplier evidence for the EU Cyber Resilience Act? It is the same attestation problem with a different regulator, and the same record answers both.

Writing on the Covered List, logic-bearing components and HBOM →

07

What is a logic-bearing hardware component?

The FCC's definition covers essentially any hardware capable of digital processing — devices, modules, and integrated circuits, including modular transmitters, IoT modules, semiconductors, and optical transceivers.

Are devices that are already authorized affected?

Existing authorizations stand, and applications pending on the effective date are exempt unless amended to change a logic-bearing component. Separately, the FCC has proposed limiting importation and marketing of some previously authorized covered equipment — that proceeding is open.

What is in force versus proposed?

In force: the component ban and the marketplace FCC-ID display rule. Proposed: signed HBOM/SBOM with every application, term-limited authorizations, SDoC registration, and a US-based liable party.

Who is on the Covered List?

Named entities including Huawei, ZTE, Hytera, Hikvision, and Dahua — including their subsidiaries and affiliates — plus categorical entries for foreign-produced routers, drones, power inverters, and advanced robotic devices.

Is this legal advice?

No. We build screening data and attestation infrastructure. For legal determinations about your products, use FCC counsel.