US Edition
Your source for latest news
TechnologyTelecom Regulation

FCC rule closing loophole for blacklisted chips takes effect October 13

A Federal Communications Commission order bars authorization of any device that contains even a single chip from a blacklisted supplier such as Huawei, closing a gap that let banned components reach the U.S. market inside otherwise compliant hardware, including drones and routers.

PT
By PressTemps Technology DeskPublished Today, 18:48 ET · 6 min read
FCC rule closing loophole for blacklisted chips takes effect October 13
FCC Chairman Brendan Carr, official portrait, 2025. Carr issued a statement alongside the commission's new equipment-authorization order, which takes effect October 13. (Official U.S. government portrait, via Wikimedia Commons.)
What to know
A new FCC rule effective October 13 bars authorization of any device containing a chip from a blacklisted supplier such as Huawei or ZTE, closing a prior loophole that applied only to whole devices.
The commission estimates industry compliance costs of up to $300 million one-time and under $40 million annually, against projected security benefits exceeding $1 billion a year.
The rule builds on the FCC's December 2025 and March 2026 additions of foreign-made drones and routers to its Covered List, which Chairman Brendan Carr says have already drawn more than $4 billion into U.S.-based production.
A companion proposal now open for public comment would extend restrictions to software and firmware components and require manufacturers to disclose detailed bills of materials.

A new Federal Communications Commission rule that bars U.S. approval of electronic devices containing even one chip from a blacklisted manufacturer takes effect October 13, nine days from now, closing what the agency calls a "component-part loophole" in its national-security equipment rules.

The rule, formally adopted by the commission on July 22 and published in the Federal Register on September 11, prohibits authorization of any device that incorporates a "logic-bearing hardware component" produced by an entity on the FCC's Covered List — the roster of suppliers, led by Huawei Technologies and ZTE and including Hikvision, Dahua, Hytera and Kaspersky, that the government has determined pose an unacceptable risk to national security. Until now, a device could still win FCC approval even if it contained a blacklisted chip, so long as the finished product itself was not branded or produced by the listed company.

What the order does

The commission defines a logic-bearing hardware component as any chip, module or sub-assembly that generates timing signals above 9,000 pulses per second and performs digital data-processing functions — in practice, the processors, radio modules and controllers that make a device "smart" rather than purely mechanical. If a device would have been barred from authorization had a Covered List company produced it outright, it is now barred if that company merely supplied one qualifying component. The order, known as the Third Report and Order in ET Docket No. 21-232, also requires any modification to Covered List-linked equipment to undergo full re-certification rather than a lighter permissive-change review, and it compels online marketplaces to display a certified device's FCC ID at the point of sale.

The numbers behind the rule

The FCC's own regulatory analysis estimates one-time industry compliance costs of no more than $300 million, concentrated among online marketplaces updating listing systems, plus recurring annual costs under $40 million, while projecting that the security benefits of closing the loophole exceed $1 billion a year. Separately, Chairman Brendan Carr said in a statement accompanying the order that more than $4 billion has flowed into U.S.-based drone and router manufacturing since the agency began blacklisting foreign-made versions of that equipment, adding "hundreds of thousands of square feet" of domestic production space. The commission's own small-business impact data show the rule's reach is broad: more than 86 percent of firms in categories such as electronic computer manufacturing and semiconductor manufacturing, and over 96 percent of computer-terminal makers, qualify as small entities under federal size standards.

How a telecom blacklist became a chip-level crackdown

The Covered List dates to the 2019 Secure and Trusted Communications Networks Act, with Congress ordering the FCC in 2021 to stop approving listed equipment outright. The commission's 2022 First Report and Order implemented that ban for whole devices from Huawei, ZTE and, in narrower circumstances, Hikvision, Dahua and Hytera. A 2025 Second Report and Order closed a related loophole for devices built around "modular transmitters." Then, starting in December 2025, the FCC's Public Safety and Homeland Security Bureau took a new approach, blacklisting entire categories of equipment by where they are made rather than by brand — first adding uncrewed aircraft systems and their critical components produced in a foreign country, then, in March 2026, foreign-made routers. Those location-based additions already made it harder for Chinese-made drones, including models from market leaders DJI and Autel, to win new FCC authorization, a shift drone-industry trade press has tracked closely. DJI, which was added to the Covered List's drone category in December 2025, has called the designation procedurally flawed and is separately challenging it in federal appeals court, arguing the FCC acted without a completed security review. This new order does not add DJI or Autel to the list by name; instead, it builds on that momentum by extending the same loophole-closing logic the agency already applied to whole drones and routers down to the level of individual chips supplied by companies such as Huawei and ZTE.

Who absorbs the cost

The prohibition falls hardest on manufacturers who source components globally rather than building devices in-house — a description that fits much of the consumer-electronics and networking industry. The FCC's filing identifies potentially affected sectors ranging from radio and television broadcasting equipment makers to semiconductor manufacturers, aircraft-radio-equipment producers and medical-laboratory device makers, with small businesses making up the overwhelming majority of firms in nearly every category listed. Online marketplaces such as Amazon and eBay face new disclosure duties too: any marketplace that sells or hosts a radiofrequency device on behalf of a third party must now display a valid FCC ID at the point of sale, though the commission phased in compliance dates of March 1, 2027, and June 1, 2027, for different categories of third-party sellers and exempted listings for used devices and lower-volume sellers to soften the transition. The agency estimates that burden at under $40 million a year industry-wide, arguing marketplaces already display extensive product information and that adding one more identifier is a marginal cost.

"Manufacturers that bring products such as drones, networking equipment, and security devices to the U.S. market rely on complex global supply chains to source hundreds of components that go into a single device. ... In some cases, a single compromised component can introduce vulnerabilities that undermine the security of an otherwise compliant device."

That assessment came from Commissioner Olivia Trusty, who joined Carr in issuing a statement alongside the order, which the commission adopted without dissent. Trusty said the rule "closes that security gap by ensuring that hardware produced by entities on the Covered List cannot be incorporated into devices authorized for sale in the U.S. through our equipment authorization process."

What happens next

The same order opened a companion Third Further Notice of Proposed Rulemaking asking whether the FCC should go further still — including splitting the Covered List into separate brand-based and location-based tracks, extending the chip prohibition to software and firmware, requiring manufacturers to file hardware and software bills of materials, and imposing term limits on equipment authorizations rather than permanent approvals. The notice also asks whether the FCC should require a U.S.-based party to be held legally liable for certified equipment, consider term limits on authorizations rather than permanent approvals, and expand streamlined revocation procedures so that equipment later found to rely on Covered List components can be pulled from the market faster. Comments on those proposals are due 30 days after the September 11 Federal Register publication, with replies due 45 days after that.

Carr's statement also noted that the commission had, the day before the order's adoption, separately proposed banning the import and sale of already-authorized foreign-made military-grade drones, including so-called swarming drones — equipment that won approval years ago and would otherwise remain legal to sell indefinitely. Taken together with October's effective date, the two actions signal that the agency's supply-chain scrutiny is shifting from blocking new product approvals toward clawing back equipment that is already on the market and already in use.

More on this story

All Technology