Overview
Industry Seeks Narrower Proposed FCC Equipment Authorization and Covered List Rules
The FCC received a wide array of comments and reply comments in response to its Third Further Notice of Proposed Rulemaking relating to the Covered List and equipment authorization (ET Docket No. 21-232) (Third NPRM).
A broad cross-section of manufacturers, communications providers, technology companies, online marketplaces, and industry trade associations support narrowing the proposals in the Third NPRM. While commenters generally support protecting the supply chain, they seek a greater nexus between additional regulatory requirements and the ostensible risk of the product.
Among other things, commenters objected to proposals that would require hardware and software bills of materials (BoM) for all devices, that would require certification of every product in a Covered List sector, that would require registration of devices authorized through a Supplier’s Declaration of Conformity (SDoC), and that would make equipment authorizations expire automatically. Commenters also request specific, actionable routes to marketing and selling products that do comply with the rules.
Below is a summary of the comments received in response to the Third NPRM:
Energy and Industrial Equipment
American Clean Power Association (ACP). ACP urges distinct treatment of location-based power-inverter restrictions and favors the FAR domestic-end-product test as the foreign production standard. ACP argues that foreign design alone should not make an otherwise domestic product foreign-produced. ACP seeks reporting and component restrictions limited to relevant components, preservation of SDoC and equipment updates, and workable repair and research importation pathways. ACP opposes fixed authorization terms for long term energy assets and seeks realistic transitions and reliable FCC compliance records.
Solar Energy Industries Association (SEIA). SEIA argues that the rules must follow the scope of the revised power inverter determination. It supports permanent software and firmware update relief, appropriate hardware substitutions, and continued repair and support of installed equipment. It opposes extending broader component and software restrictions to location-based entries and seeks limited, confidential BoM requirements that avoid duplicating conditional approval submissions. Any authorization term should, at most, restrict future marketing without preventing continued operation or maintenance.
National Electrical Manufacturers Association (NEMA). NEMA opposes universal BoM disclosures, SDoC registration, fixed authorization terms, and duplicative approvals for electrically identical products. It supports routine component substitutions, security updates, reasonable supplier reliance, and a single US responsible party. It also supports protections for long term electrical equipment, rejects procurement or consumer labeling standards for foreign production, and seeks industrial and commercial exclusions from the router definition. It requests at least one year for BoM implementation if adopted and at least three years for transitions accommodating expanded Covered List scope.
National Association of Manufacturers (NAM). NAM supports reporting focused on programmable, logic-bearing, RF-active, or network connected components, with supplier reliance and updates only for material security or Covered List changes. NAM opposes blanket sector-wide certification and fixed authorization terms, while supporting SDoC, development and testing exceptions, and grandfathering.
Association of Home Appliance Manufacturers (AHAM). AHAM would limit BOM requirements to Covered List sectors and specified high risk components, with confidentiality, materiality thresholds, and implementation aligned with product design cycles. It opposes fixed terms for non-covered equipment and questions universal SDoC registration. Any US responsible party rule should accommodate entity-level compliance, supplier attestations, and good faith safe harbors rather than impose strict liability on importers.
Outdoor Power Equipment Institute (OPEI). OPEI warns that robotic lawnmowers and similar equipment may be swept into advanced robotics restrictions despite relatively low risks and use of pre-certified communications modules. It seeks SDoC eligibility, narrow BOM disclosures, and continued testing, trade show, repair, and servicing pathways. OPEI is receptive to authorization terms, but only through a streamlined, risk-based approach. It opposes automatically making the US agent liable for a foreign grantee’s compliance.
Robotics and Drones
Boston Dynamics. Boston Dynamics supports strengthening the domestic robotics industry but urges distinctions between advanced mobile robots, such as humanoids and quadrupeds, and simpler warehouse robots. It questions the Buy American component cost test as the sole origin standard and suggests transitional recognition of allied components or greater focus on sensitive components. It also seeks appropriate SDoC access for domestic and allied producers, narrower SBOM requirements, and broad update flexibility for long-term industrial robots.
SKL Robotics / Humanoid. Humanoid seeks workable US testing and commercialization pathways for conditional-approval applicants. It requests trade show and customer evaluation exceptions, market trials, conditional sales agreements, and a testing allowance of 200 units per model and predictable approval for larger quantities. It also seeks grandfathering of lawfully imported units and confidential BOM requirements coordinated with defense department reporting. Humanoid supports a US-based liable party.
National Rural Electric Cooperative Association (NRECA). NRECA focuses on drones used for inspections, storm response, vegetation management, and other operations. It says electric cooperatives depend on foreign manufactured UAS because adequate domestic alternatives are not yet available. NRECA requests a transition lasting several years and grandfathering of existing fleets and parts through their useful lives, warning that abrupt restrictions could impair grid reliability.
SPRINT Robotics. SPRINT emphasizes that restrictions on industrial inspection robots may send workers back into hazardous spaces. It seeks continued operation despite authorization expiration, explicit permission to export covered equipment for repair and reimport, and temporary imports for specialized inspections. It also requests software update relief for location-based listings and recognition of industrial inspection and maintenance equipment as a distinct category.
RoboStrategy Advisors. RoboStrategy argues that the proposals do not adequately account for advanced robotics. It seeks reconciliation of the domestic end-product standard with component tracing, a definition of logic-bearing hardware focused on external accessibility or security relevance, and continued separation of entity-based and location-based restrictions. It favors permissive changes, testing and customer evaluation, and internal BOM retention with production upon request. It opposes automatic expiration of existing authorizations.
Commercial Drone Alliance (CDA). CDA supports a stronger domestic drone industry but opposes imposing blanket certification and universal BOM filings on trusted manufacturers. It favors continued use of pre-certified modules, clear definitions of foreign production and UAS critical components, and safe harbors or exemptions for demonstrably trusted products. CDA also seeks reasonable implementation periods to avoid disrupting domestic development and deployment.
Experimental Aircraft Association (EAA). EAA warns that broad UAS component definitions could capture equipment used in recreational and experimental aviation. Communications systems, sensors, cameras, batteries, and motors may serve several markets. EAA therefore seeks functional definitions based on actual capabilities, intended use, and demonstrated risk, rather than a component’s mere suitability for installation in a drone.
DJI. DJI opposes universal BOM filings, automatic authorization expiration, and revocation without meaningful procedural protections. It seeks prospective importation and marketing restrictions and continued updates for previously authorized equipment. Software or firmware should disqualify a device only when a specific national security determination reaches the relevant risk. DJI favors assessing ongoing control over sensitive functions rather than historical code provenance or incidental open-source contributions.
Telecommunications
CTIA. CTIA emphasizes the combined capacity of trusted US and allied suppliers and opposes treating all foreign production as equally risky. It seeks transparent conditional approval criteria and timelines, including presumed approval for US, allied, and mutual-recognition partner companies. CTIA supports the FCC’s "produced by" definition with limits protecting routine commercial relationships, while opposing broad BOM filings, sector-wide certification, universal SDoC registration, and authorization expiration. It supports supplier reliance and permanent update flexibility and urges assessment of cumulative burdens on laboratories and certification capacity.
Information Technology Industry Council (ITI). ITI questions treating production anywhere outside the United States as inherently suspect. It urges the FCC to avoid future location-based listings or, at minimum, consult industry and provide transitions. ITI favors a "produced by" standard grounded in genuine substantial control, excluding ordinary licensing and commercial arrangements. It opposes extending component and software prohibitions beyond logic-bearing hardware without a specific national security determination.
Computer & Communications Industry Association (CCIA). CCIA combines objections to broad geographic restrictions with economic analysis. It estimates costs of approximately $4.4 billion under the current production location approach, compared with $0.1 billion if confined to foreign-adversary jurisdictions. It estimates roughly $151 million annually for proactive BOM filings and favors internal retention with production upon request. CCIA also opposes expansive producer definitions, passive component restrictions, fixed authorization terms, and the 40-unit testing-import cap, while seeking marketplace safe harbors and due process in revocations.
INCOMPAS. INCOMPAS argues that the FCC cannot convert implementation of specific national security determinations into general supply-chain jurisdiction. It opposes universal BOM filings, sector-wide certification, SDoC registration, authorization terms, and the 40-unit testing-import limit. It would tie producer status to ongoing control over security-critical functions or final manufacturing specifications and favors entry-specific origin rules, with substantial transformation tied to foreign-adversary risk as a starting point. INCOMPAS rejects using allegations about particular optical transceivers to justify universal restrictions and requests at least 30 days to address disputed revocation allegations absent an immediate safety threat.
Telecommunications Industry Association (TIA). TIA seeks obligations tied to each underlying national security determination, continued SDoC and development flexibility, and distinct treatment of producer-based and location-based entries. It emphasizes that attestations and enforcement can address compliance without universal BOM filings. If reporting is adopted, TIA seeks targeted disclosures, origin information only for covered components, automatic confidentiality, materiality thresholds, and good-faith safe harbors. It warns that centralized disclosures could expose trade secrets and vulnerabilities and discourage supplier diversification.
USTelecom. USTelecom seeks clear distinctions among Covered List categories, trusted allied sourcing, and practical router maintenance. It opposes universal BOM filings and passive component restrictions. It proposes an applicant supplied producer list, subject to exceptions for material falsehoods or omissions, and an FCC advisory process for difficult cases. It also seeks hardware update rules allowing component relocation and benign capability improvements when they introduce no material new security, interference, or functional concern.
Wi-Fi Alliance. Wi-Fi Alliance seeks SDoC and electrically identical device pathways, a foreign-production definition based on actual manufacturing or assembly, and a narrow residential router definition. It opposes comprehensive BOM filings, the 40-unit testing cap, independent marketplace verification, and authorization expiration. It supports permanent updates, procedural protections in revocations, and liability tied to meaningful control. FCC logo rules should preserve voluntary use for SDoC devices and leave independent industry certification marks unaffected.
Mobile & Wireless Forum (MWF). MWF supports separate treatment of producer-based and location-based listings but argues that production location rarely establishes risk by itself. It supports the FCC’s totality-of-the-circumstances producer framework while opposing exhaustive producer lists and mandatory BOM filings. For components and software, it favors a rebuttable presumption over categorical bans. MWF also supports permanent update relief and database modernization and opposes authorization terms and universal SDoC registration.
Software & Information Industry Association (SIIA). SIIA argues that threats generally arise from particular actors and warns against turning equipment authorization into supply-chain licensing. It seeks clarification of logic-bearing-components and producer and origin definitions. SIIA opposes universal BOM filings and SDoC registration and supports marketplace safe harbors, testing import allowances, confidentiality, and database modernization.
Consumer Technology Association (CTA). CTA emphasizes testing, pre-authorization imports, and demonstrations at events such as CES as essential to startups and innovation. It supports distinct Covered List categories and permanent permissive changes but opposes broad reporting, certification, registration, and renewal requirements. CTA supports reliance on attestations and retained records; any additional disclosures should be narrowly limited and automatically confidential. CTA also sought at least three years to implement major changes to the general authorization regime.
Semiconductor Industry Association (SIA). SIA explains that tracing semiconductor origin and value through multiple supplier tiers would be impractical and expose sensitive intellectual property. It proposes a Supply Chain Security Attestation based on reasonable diligence concerning logic-bearing hardware, with retained records available to the FCC. SIA presents this as an alternative to routinely filing detailed BOMs, reserving any more extensive requirements for genuinely high-risk cases.
Japan Electronics and Information Technology Industries Association (JEITA). JEITA supports distinguishing producer-based from location-based listings but opposes universal BOM filing, broad passive-component and software restrictions, and mandatory SDoC registration. Any BOM rules should focus on security-relevant components, protect confidentiality, and use reasonably available information with longer reporting periods. JEITA also opposes reducing testing imports from 4,000 to 40 units, citing effects on large-scale testing, quality assurance, and security validation.
The Toy Association. The Toy Association seeks differentiated treatment for closed-system and other low-risk electronic toys. It favors limited BOM and component rules, continued voluntary FCC-logo use, and tradeshow and development pathways. It opposes blanket sector-wide certification and urges careful assessment of SDoC registration and authorization terms. It also requests 12 months to implement the already-adopted online FCC ID display requirement.
Broadband Providers
NCTA – The Internet & Television Association. NCTA supports tailored HBOM/SBOM disclosures during equipment authorization by entities that possess and control the information. It sees transparency as useful for downstream procurement and supply chain security. Its comments also supported supplier reliance, permanent update flexibility, and a producer definition tied to meaningful control, while opposing automatic sector-wide certification and seeking narrow router and software restrictions.
NTCA – The Rural Broadband Association. NTCA supports BOM disclosures to help rural providers understand supply-chain risks. It nevertheless opposes a blanket prohibition on every component from a listed entity, favoring a rebuttable presumption focused on components able to process data, execute code, affect RF emissions, or alter device operation. NTCA seeks predictable conditional approvals and permanent update relief and opposes expiration rules that would undermine legacy equipment availability, repair, and support.
Fiber Broadband Association (FBA). FBA opposes universal BOM filings and country-specific component-value reporting without a workable methodology. It seeks compliance responsibility upstream, reasonable provider reliance on authoritative records, and updates and substitutions that do not materially increase risk. FBA also requests that every Covered List change come with authoritative guidance addressing scope, pending applications, existing authorizations, inventory, deployed equipment, and relief. Clear boundaries for the residential-router category are a particular concern.
WISPA. WISPA opposes broad BOM mandates because of disproportionate burdens on smaller producers and rural providers. Unlike many commenters, it supports registering all SDoC devices with unique identifiers in an FCC database, arguing that this would improve confidence in compliance while preserving the streamlined authorization process. WISPA also supports basic software and hardware permissive changes and considers authorization term limits premature given unresolved costs and maintenance consequences.
Online Marketplaces
eBay. eBay seeks to preserve small seller and used goods exemptions and opposes independent marketplace verification of product-specific FCC IDs or SDoC information. It challenges the expanded marketing definition, universal SDoC registration, authorization terms that could obstruct lawful resale, and broad US liable-party obligations. It also opposes liability for sellers’ FCC-logo misuse absent specific FCC notice. eBay supports modernized databases.
Coalition to Protect America’s Small Sellers (PASS Coalition). PASS challenges treating third-party marketplaces as equipment marketers and seeks to preserve exemptions for small sellers and used goods and limited duties for non-fulfillment platforms. It seeks equivalent treatment for livestream sales and at least a 12-month transition for FCC ID marketing requirements. PASS opposes extending marketplace duties to SDoC devices and authorization terms that would disrupt secondary markets, emphasizing that platforms cannot verify unavailable technical information.
Etsy. Etsy emphasizes that it never takes possession of sellers’ products. It asks the FCC to exclude non-fulfillment platforms from the relevant marketplace definition or preserve and extend small-seller and used goods exemptions to new FCC ID and SDoC duties. It argues that verification requirements imposed on platforms unable to inspect products would burden micro-entrepreneurs without materially improving security.
Other Business Concerns
Exhibitions and Conferences Alliance (ECA). ECA seeks coordinated protection for otherwise lawful importation, display, and operation of covered devices at bona fide trade shows. It requests retention of the 400-unit import allowance, approval for larger quantities, and demonstrations subject to notice, custody, interference, and disposition safeguards. ECA favors clear general conditions over individual waivers and asks the FCC to confirm the existing rules while the proceeding remains pending. It argues that controlled demonstrations support innovation and security research.
US Chamber of Commerce. The Chamber favors obligations calibrated to actual risk and access to information, permanent update relief, and practical hardware substitutions. It seeks conditional approvals and transitions where alternatives are unavailable at scale, preservation of trade shows and testing, and an import-testing threshold substantially above 40 units. It opposes blanket sector certification and fixed authorization terms and urges narrow, confidential BOM rules and modernized FCC systems before new data-dependent obligations take effect.
Chinese Industry Perspectives
China Chamber of Commerce for Import and Export of Machinery and Electronic Products (CCCME). CCCME raises statutory and due process objections to broad supply chain regulation and seeks narrow producer definitions, preservation of testing and electrically identical-device pathways, and withdrawal or narrowing of BOM mandates. It also urges differentiated treatment of low-risk consumer robots. It opposes importing the foreign-entity-of-concern framework advocated by the SAFE Alliance into the foreign-production definition, favoring actual substantial manufacturing or assembly over ownership, financing, foreign design, or the domestic-end-product test. CCCME supports update flexibility across Covered List categories and opposes fixed authorization terms and broad importer liability.