FCC 26-50: the covered list reaches components, and a court narrows it
7 min read
A list of banned suppliers looks like a list of brands. It is not: it is a definition, and definitions move. On 22 July 2026 the Federal Communications Commission adopted FCC-26-50 — Third Report and Order and Third Further Notice of Proposed Rulemaking, ET Docket No. 21-232 — released on 23 July. We have already covered the half of that measure that made the news: the closing of the “component part loophole”, under which a device incorporating even a single component from a Covered List entity cannot be certified, whatever brand is on the shell. But the same document, on the same day, does the opposite as well: it narrows the perimeter, and it does so because a court ordered it to. That is the half almost nobody read, and it is the one that reaches contracts already signed.
What is already decided, not proposed
At the heart of the measure, the Commission “closes the component part loophole by prohibiting authorization of devices incorporating logic-bearing hardware components if—had the entity produced the device itself—it would be prohibited from authorization”. Three more things take effect on adoption, not on consultation: modifications made by entities on the Covered List must now go through full certification; marketing rules reach “any entity—including ecommerce platforms—that market unauthorized equipment”, with a mandatory FCC ID at the online point of sale (limited exceptions); and the definition of “critical infrastructure” on the Covered List changes — in the opposite direction, as shown below.
The component that carries logic
The Commission defines logic-bearing components as follows: “any device, system, module, sub-assembly, integrated circuit, or other physical component that generates and uses timing signals or pulses at a rate in excess of 9,000 pulses (cycles) per second and uses digital techniques” — extended to digital telephony equipment and to components that use radio frequency for data-processing functions. It builds on the “digital device” definition already at section 15.3(k), with “the only substantial distinction” being that the new one does not exclude intentional radiators. Purely mechanical or structural parts fall outside it: the Commission opts for a general definition — not a component-by-component approach — to “guide companies within the communications industry”.
A technical note of our own, not the Commission’s: 9,000 cycles per second is an extremely low threshold, one that almost any circuit fitted with a microcontroller clears.
Why silicon, not just software
The technical rationale (¶¶25-26): the concern is “malicious logic or hardware-level backdoors embedded directly into silicon”. Unlike many software vulnerabilities, often fixable with a patch, “malicious modifications at the hardware level in logic-bearing hardware components may persist throughout a device’s lifecycle and can be exceptionally difficult to detect, analyze, or remediate” — “they are not passive”, as a commentator cited in the proceeding puts it.
The passage that makes the piece (¶34): “Device makers that incorporate untrusted logic-bearing hardware components because they fail to maintain a supply chain risk management program with visibility into such components, including by using bills of materials, simply pass those costs onto the end users of the devices. Those costs are not merely financial. End users ultimately absorb the costs and risks created by device makers…”
The restriction: the perimeter narrows by order of a court
The definition of “critical infrastructure” determines when equipment made by Hikvision, Dahua and Hytera — already covered on this desk — counts as used “for the purpose of … physical security surveillance of critical infrastructure” (NDAA 2019 §889(f)(3), folded into the Covered List via the Secure Networks Act); it had been challenged. The Court of Appeals, in Hikvision USA, Inc. v. FCC (D.C. Cir. 2024), found the Commission’s sources reasonable, but noted that it “had failed to explain or justify why the definition should include any “systems or assets” that are merely “connected to” critical infrastructure sectors or functions”, making the scope “arbitrarily broad”. It vacated those parts and remanded to the Commission.
The Commission complies: “we retain our reliance on the government sources that the D.C. Circuit upheld, but narrow the definition to no longer interpret “critical infrastructure” to broadly encompass all components “connected to” critical infrastructure”. In its place, section 1016(e) of the USA PATRIOT Act 2001: systems and assets, whether physical or virtual, so vital that their loss would have a debilitating impact on security, the national economy, public health or safety.
Decided and proposed are not the same thing
Everything else is consultation, not rule. The Third Further Notice opens for comment — it does not decide — splitting the Covered List into two categories (producer/supplier and place of production), a requirement to disclose hardware and software bills of materials (HBOM and SBOM), restrictions on certain import channels, and stronger post-market enforcement: simplified revocation, term-limited authorisations, a US-based responsible party. Deadlines run from Federal Register publication: 30 days for comments, 45 for replies.
Not an Italian rule. But the clause is
This is US regulation: it does not apply in Europe, and it bans nothing for an Italian company. It matters anyway, for three reasons. NDAA/Covered List compliance is already a recurring contractual clause in supplies to US customers and in defence supply chains: it binds by contract even those not subject to the rule. It effectively defines what the market treats as an unreliable component, a judgement that travels beyond the border that produced it. And the method it calls for — bills of materials, visibility into components, an identifiable responsible party — is the question a European buyer has to ask regardless: the same logic as a tender that ends up naming a single supplier, applied here to a definition.
The other side, in fairness
The Commission acknowledges that the new rules “may impose compliance costs on device makers”, and some commentators in the proceeding had asked for bright-line rules — “bright line rules clearly identifying components that are covered” — rather than a general definition. The Commission chose the general definition regardless, placing on manufacturers the burden of knowing what is inside their own products. Whether that is proportionate is not a judgement this piece makes.
What to take away
- If your specification bans “brand X equipment”, rewrite it: the risk sits at component level, and the brand on the box may be entirely unrelated to the list.
- Ask your supplier for the bill of materials, hardware and software, with a contractual duty to report changes: it is the line the regulator draws between those who control their supply chain and those who pass the cost onto the customer.
- Check any signed clauses that refer to “critical infrastructure”: the American reference notion changed on 22 July 2026, and a dynamic cross-reference may have shifted the object of the obligation without anyone noticing.
- Ask who the identifiable responsible party for the equipment is, and what happens if the authorisation is revoked: the FCC proposes making both mandatory — already sensible contractual questions today.
- Remember the difference between hardware and software: a software vulnerability gets patched; a manipulation at the silicon level, the measure says, can persist for the device’s entire lifecycle.
The method, applied here
The check — what is inside this piece of equipment, who answers for it, which definition the signed contract points to — is not a stand-alone opinion: it is a control that runs across the client’s specifications, contracts and equipment inventory, feeding a critical dependencies register — for each supply, which device, which bill of materials, which list touches it, with what deadline and what alternative — with the trail ready to show at an inspection or to a customer asking for evidence of compliance. The same system ties together inventory, contracts, specifications, archives, management systems and documents into a single operating model, on which AI agents execute decisions with a human operator in command, for large enterprises, defence, the public sector and healthcare: when a list changes, “which of our devices are affected, where, who replaces them” has an answer in hours, not months. Always in two modes — on-premise, on autonomous machines that do not require deep integration into the client’s network, or a dedicated cloud with a data centre in Italy — always with shared management.
Want to know whether one of your tenders or contracts points to a definition that has just moved? The first session is free of charge.