Two things happened in this proceeding, and they are being discussed as though they were one thing.
In force. On 22 July 2026 the Commission adopted the Third Report and Order in ET Docket 21-232. From 6 September 2026, thirty days after Federal Register publication on 7 August, no device receives equipment authorization if any logic-bearing hardware component inside it was produced by an entity on the Covered List. Not the radio. Any part that does digital processing.
Not in force. In the same proceeding the Commission proposed — and so far only proposed — a signed HBOM and SBOM with every certification application, term-limited authorizations, SDoC registration, and a US-based party carrying liability.
Almost everything being marketed this month is priced against the second list while borrowing the urgency of the first. It is worth being precise about which is which, because the two require completely different responses.
"Logic-bearing" is doing a lot of work
The instinct is to read a Covered List rule as a rule about radios. It is not.
The definition reaches essentially any hardware capable of digital processing: modular transmitters, IoT modules, semiconductors, optical transceivers, integrated circuits. If it computes, it is in scope. For most product teams the practical consequence is that the eligibility question has moved from a component you chose deliberately and can name, to a long tail of parts that arrived inside a module somebody else specified.
That is the shift. The ban did not get stricter about a component you already track. It reached into a layer most applicants have never had to enumerate.
What is not changing
Worth stating plainly, because the panic marketing tends to skip it.
Existing authorizations stand. Applications already pending on the effective date are exempt, unless they are amended in a way that changes a logic-bearing component. There is no retroactive revocation event scheduled for 6 September.
Separately, the Commission has proposed limiting the importation and marketing of some previously authorized covered equipment. That is a live proceeding, and it is the one to watch if you have a long-lived catalogue. It is not a rule today.
The structural problem
Here is the part that does not get solved by buying software this quarter.
Around 43,000 certifications are granted each year, through 18 Telecommunication Certification Bodies. From September, eligibility turns on two facts:
- Which legal entity produced this component?
- Who owns that entity?
Both are facts about the component. Neither is a fact about the applicant. The producer of a given transceiver does not change because a different company put it on a different board.
Yet the rule places the research burden on the applicant, per filing, under penalty of revocation. So the same chipset gets investigated hundreds of times a year by hundreds of companies who cannot see each other's work, each reaching their own conclusion, each signing for it.
Nobody's answer improves through that repetition. The hundredth company to research a part is not better informed than the first — it is just the hundredth to pay for the same lookup, and the hundredth to carry the risk of getting it wrong. Meanwhile the fact that would actually settle the question sits with the producer, who is not part of the transaction at all.
This is the same shape as the supplier evidence problem under the EU Cyber Resilience Act: a fact that lives with one party, an obligation that lands on another, and no plumbing between them. Different regulator, same missing layer.
Why the HBOM proposal sharpens this rather than softening it
If the HBOM and SBOM filing requirement is adopted, every application will carry a signed declaration of what is inside the product.
A bill of materials is only as good as the identity resolution beneath it. A line item saying WM-8021-B, 2 units is not an answer to "who produced this and who owns them" — it is a restatement of the question in a fixed-width font. Signing it does not make it true; it makes you liable for it being true.
Build that per-applicant and you have not fixed the duplication, you have formalised it: 43,000 signed documents a year, each asserting facts their signer had no privileged way to establish. The signature makes the weakest part of the process the legally binding part.
The shape that fits the fact
If the fact belongs to the component, the attestation should be made once, by the producer, and reused by everyone downstream.
One signed record per component: the producing legal entity, ownership screened against the Covered List including subsidiaries and affiliates, production sites. Versioned, append-only, signed. Applicants resolve their BOM against those records and roll up an HBOM a TCB can verify by checking a signature rather than by repeating the research.
That is the layer we are building, and we filed the architecture as comments with the Commission in ET Docket 21-232. It is not a certification service and it does not file anything on your behalf. It is the boring, shared piece of infrastructure that has to exist before a signed HBOM means anything.
What we do not know
We do not know whether the HBOM proposal will be adopted, in what form, or on what timetable. We do not know how aggressively the subsidiaries-and-affiliates clause will be read in practice, and that clause is where most of the real difficulty lives — the Covered List names parents, and supply chains are full of entities two ownership hops away with unremarkable names.
We also do not know that a shared attestation layer will get the density it needs. Nobody is mandating it. It has to be worth using before it is widely used, which is the honest risk in this whole approach and the reason we are running small pilots instead of announcing a platform.
What we are reasonably confident about: the component ban is in force on 6 September, the diligence burden lands hardest on the TCBs who have to check the answers, and per-applicant research does not scale to 43,000 filings a year. That much is arithmetic.
Dates and rule status verified against the docket on 28 August 2026. This is a live proceeding — check ET Docket 21-232 before relying on any date here. Not legal advice.
If you certify equipment, or file more than a handful of grants a year, the FCC Covered List page has the timeline and the two pilot tracks. The screening brief — Covered List entities, subsidiaries and affiliates in one structured document — is free.
What is a logic-bearing hardware component?
The FCC's definition covers essentially any hardware capable of digital processing — devices, modules, and integrated circuits, including modular transmitters, IoT modules, semiconductors, and optical transceivers. It is much broader than the radio section of the device.
Does this affect products that are already authorized?
Existing authorizations stand, and applications pending on the effective date are exempt unless they are amended to change a logic-bearing component. Separately, the Commission has proposed limiting importation and marketing of some previously authorized covered equipment, and that proceeding is open.
Is the HBOM requirement in force?
No. A signed HBOM and SBOM with every certification application is a proposal in the same proceeding, not a rule. Comments close 8 September 2026 and replies close 21 September 2026. Anyone selling you HBOM compliance as a current obligation is describing a document that has not been adopted.
Who is on the Covered List?
Named entities including Huawei, ZTE, Hytera, Hikvision and Dahua, together with their subsidiaries and affiliates, plus categorical entries covering foreign-produced routers, drones, power inverters and advanced robotic devices. The subsidiaries and affiliates clause is where most of the practical difficulty lives.
Is this legal advice?
No. We build screening data and attestation infrastructure. For legal determinations about your products and your filings, use FCC counsel.