Published in the Federal Register on September 11, 2026 as document 2026-18535 (91 FR 57798), the Federal Communications Commission's Third Report and Order in ET Docket No. 21-232, FCC 26-50, adopted July 22, 2026 and released July 23, is a final rule effective October 13, 2026.[1][2] FederalRegister.gov is an unofficial XML copy, so anyone who needs legal notice should use the official edition on govinfo.[1][2]
The summary says the Commission closes a component-part loophole by prohibiting authorization of devices that incorporate logic-bearing hardware components produced by an entity identified on the Commission's Covered List, where the device would itself be prohibited from authorization had the Covered List entity produced the entire device.[1][2] The Commission finds that a compromised logic-bearing component can enable interception, disruption, sabotage, or unauthorized access regardless of who assembles or brands the finished device, and that such components pose essentially the same unacceptable risks as covered equipment itself.[1][2]
A logic-bearing hardware component is any device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses timing signals or pulses at a rate in excess of 9,000 pulses (cycles) per second and uses digital techniques, or that generates and uses radio frequency energy to perform data processing functions such as computation, storage, or transfer of data, drawing on 47 CFR 15.3(k).[1][2] Housings, fasteners, resistors, wiring, and plain battery cells are excluded as purely mechanical or passive components.[1][2]
Meanwhile the Commission declined, at this time, to prohibit all components produced by Covered List entities, to extend the prohibition to components produced by any entity owned or controlled by a foreign adversary regardless of Covered List status, and to extend the prohibition to software or firmware, and it keeps the record open on those questions.[1][2] Those refusals keep the October 13 clock narrower than a full inventory of every part. The prohibition applies only to logic-bearing hardware produced by entities subject to producer/provider-based Covered List determinations. It does not apply to production location-based entries such as uncrewed aircraft systems, UAS critical components, or routers produced in a foreign country unless the producing entity is independently identified on the Covered List.[1][2][3]
This rule applies prospectively to new equipment authorization applications and does not affect previously authorized equipment. Applications pending as of the effective date are exempt unless later amended to add, substitute, or change a logic-bearing hardware component.[1][2] Any modification or permissive change to equipment by a Covered List entity must go through full certification.[1][2] The Commission says it is not imposing new component-lineage investigation obligations beyond those already required for compliance, and that the "produced by" standard continues under a totality-of-the-circumstances test looking to substantial responsibility for or control over design, development, manufacture, or assembly.[1][2]
That listing surface is a later receipt for a grant, not a substitute for that application test. Online marketplaces that sell their own devices, or that have physical access to or take title to a third-party seller's device, must display a valid and accurate FCC ID at the online point of sale by March 1, 2027.[1][2] Marketplaces that market third-party listings without physical access or title need only verify that the FCC ID supplied is validly issued and require the seller to certify its accuracy, with a June 1, 2027 date.[1][2] Listings published before the rule's effective date that are not later amended or updated, listings by sellers that are not high-volume third-party sellers as defined in the INFORM Consumers Act, and listings for used devices are excluded.[1][2] The Commission declines, at this time, to require FCC IDs on external product packaging.[1][2]
That further notice invites comment on hardware and software bills of materials, among other proposals.[4] That invitation is not a current disclosure duty. An FCC ID on a product page can show that a grant exists. It does not, by itself, name the logic-bearing parts inside the housing.
July coverage of the July 22 adoption is in The Policy Surface Inside the AI Rack.[5] The new public facts are the September 11 publication, the October 13 effective date, the 2027 FCC ID clocks, and the software and firmware gap left open. This names no compromised finished product and is not legal, procurement, or investment advice.
Verification bottleneck
This scarce check is whether a new authorization application after October 13 can show that no logic-bearing hardware component inside the device was produced by a producer/provider-based Covered List entity, before anyone treats an FCC ID on a later marketplace listing as that showing.
- Authorization of finished devices can now inherit a Covered List prohibition from a named class of chips and modules. Software and firmware were left out of that test.
- Applicants, certification bodies, online marketplaces, and later buyers would have to verify which Covered List entry is producer-based, whether the application is new or grandfathered, and whether an FCC ID on a listing is current.
- Watch October 13 for the first new applications under the component rule, the March 1 and June 1, 2027 listing dates, and whether later rules reach software, firmware, or a bill of materials.
Opportunities
So a one-SKU component worksheet is where value may appear: brand and model, FCC ID if any, whether the application would be new after October 13, which parts meet the logic-bearing definition, which Covered List entries are producer-based, and whether software or firmware is being treated as if this rule already covered them. Filing decisions stay with counsel. Idea fodder only.
Sources
[1] Federal Communications Commission, "Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program," 91 FR 57798, September 11, 2026, FR Doc. 2026-18535. https://www.federalregister.gov/documents/2026/09/11/2026-18535/protecting-against-national-security-threats-to-the-communications-supply-chain-through-the
[2] Official PDF, 91 FR 57798. https://www.govinfo.gov/content/pkg/FR-2026-09-11/pdf/2026-18535.pdf
[3] Federal Communications Commission, "List of Equipment and Services Covered By Section 2 of The Secure Networks Act," Covered List updated August 14, 2026. https://www.fcc.gov/supplychain/coveredlist
[4] Federal Communications Commission, Third Report and Order and Third Further Notice of Proposed Rulemaking, ET Docket No. 21-232, FCC 26-50, adopted July 22, 2026, released July 23, 2026. https://docs.fcc.gov/public/attachments/FCC-26-50A1.pdf
[5] Jordan Finneseth, "The Policy Surface Inside the AI Rack," Hypernovelty Institute, August 6, 2026. https://hypernovelty.institute/articles/the-policy-surface-inside-the-ai-rack/
