2026-16197Proposed RuleWallet

FCC Demands Spy-Proof 'Ingredient Lists' for Phone Guts

Published Date: 8/7/2026

Proposed Rule

Summary

The Federal Communications Commission (Commission or FCC) issues a Third Further Notice of Proposed Rulemaking seeking comment on a broad set of additional measures to strengthen the security and integrity of its equipment authorization program. The measures include bifurcating the Covered List into producer/provider-based and production location-based categories; addressing "white labeling" of covered equipment; hardware and software bill of materials (HBOM/SBOM) disclosure requirements; further prohibitions or presumptions against authorizing equipment containing Covered List components or software; certification requirements for devices in Covered List sectors; reforms to equipment importation, marketing, and pre-authorization operation rules; restrictions on use of the FCC logo; streamlined revocation procedures; codification of permissive-change waivers for software, firmware, and hardware updates to covered equipment; codified definitions for UAS, UAS critical components, and routers; term limits on equipment authorizations; registration of Supplier's Declaration of Conformity (SDoC) devices; modernization of the Commission's equipment authorization database; updates to submarine cable Covered List rules; and a proposal to require a U.S.-based liable party for FCC-certified equipment.

Analyzed Economic Effects

9 provisions identified: 2 benefits, 7 costs, 0 mixed.

Hardware & Software BOM Disclosure

If you apply for FCC equipment certification, you would have to submit a written, signed hardware bill of materials (HBOM) and software bill of materials (SBOM) listing each component, its producer, production location(s), and the percentage of component value per location, and update that information within 30 days of any material change. The FCC preliminarily estimates costs of under $5,000 per software program and up to $10,000 per hardware device for these disclosures.

Ban or Presumption Against Covered-Entity Components

The FCC seeks comment on prohibiting authorization of devices that include components or software produced by entities on the Covered List, or on adopting a rebuttable presumption against such authorizations. The FCC tentatively estimates the annual cost of a prohibition on downloading or authorizing software/firmware from Covered List entities at under $50,000,000 per year.

Certification Requirement for Covered Sectors

Devices in Covered List sectors (for example, UAS, UAS critical components, and routers), regardless of producer and even if they would otherwise qualify for Supplier's Declaration of Conformity (SDoC) or exemption, would be required to undergo FCC certification. The FCC is asking whether certain narrow exemptions should apply (for example, Defense Contract Management Agency Blue UAS Cleared List items).

Stricter Import Limits for Covered Equipment

Covered equipment may be imported into the United States only under narrow conditions: with a valid, unrestricted equipment authorization; solely for export; exclusively for U.S. Government use; to develop products for U.S. Government use; or in quantities of 40 or fewer units for testing, evaluation, or product development unless the Chief of OET grants written approval for a larger quantity (replacing the current general 4,000-unit threshold).

Online Marketplace Verification & Warnings

Online marketplaces would have to collect and take reasonable steps to verify Supplier's Declaration of Conformity or equivalent compliance documentation, display equipment authorization/compliance information at point of sale, and prominently show a required notice for devices restricted to licensed users stating that purchase information may be provided to the FCC. Marketings that promote illegal modification or evasion of rules would be prohibited.

Register SDoC Devices With Unique ID

All devices authorized under the Supplier's Declaration of Conformity process must be registered with the FCC before marketing and assigned a unique identification number. That identifier must be displayed on the device or packaging, in the compliance statement, and in online listings; registration records would be publicly available unless protected.

U.S.-Based Liable Party Requirement

For FCC equipment certification grants where the grantee is located outside the United States, the FCC proposes requiring a liable party located in the U.S.: the U.S.-based manufacturer or assembler, or if none, the importer, or another U.S. party that assumes the role by agreement. The FCC cites instances where a U.S. agent alone was insufficient for ensuring compliance.

Term Limits on Equipment Authorizations

The FCC seeks comment on making equipment authorizations expire after a fixed term—tentatively suggesting ten years—instead of remaining valid indefinitely absent revocation, and on associated renewal and expedited re-authorization procedures.

Permissive-Change Waivers Made Permanent

The FCC proposes to codify and make permanent OET waivers (currently effective through January 1, 2029) that permit Class I and Class II software and firmware permissive changes—such as security patches and compatibility updates—to already-authorized covered equipment without a new equipment authorization, provided changes mitigate consumer harm and do not alter device capability or marketed identity. The proposal also seeks comment on limited hardware swaps under conditions.

Personalized for You

How does this regulation affect your finances?

Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Key Dates

Published Date
Comments Due
8/7/2026
9/8/2026

Department and Agencies

Department
Independent Agency
Agency
Federal Communications Commission
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register