The Federal Communications Commission (FCC) is moving to tighten the approval process for radiofrequency devices sold in the U.S., aiming to close gaps that could allow restricted technology to reach customers through embedded components, software, imports or online marketplaces.
The FCC is scheduled to consider draft equipment-authorization rules at its July 22 open meeting. If approved, the item would create near-term duties for online marketplaces and open a wider discussion over whether device makers should file supply-chain records such as SBOMs, HBOMs and component-origin data.
The FCC draft defines SBOMs, or software bills of materials, as formal records of software and firmware components used in a device and their supply-chain relationships. It defines HBOMs, or hardware bills of materials, as formal records identifying hardware components in a device and information about their origin and production.
The July open-meeting agenda lists a combined Third Report and Order and Third Further Notice of Proposed Rulemaking. The first part would adopt rules if commissioners approve the item. The second part would ask whether the FCC should later require deeper component, software and import documentation.
Closing the component loophole
The order would close what the FCC calls the “component part loophole” by prohibiting authorization of devices that contain logic-bearing hardware components produced by entities identified on the FCC’s Covered List, where a device made by the same Covered List entity would be barred.
It would also clarify that online marketplaces can be treated as marketers of third-party radio-frequency devices and require them to display the correct FCC ID for certified products at the online point of sale.
The FCC says the component rule responds to risks inside the device, not only the finished product. The draft cites Hudson Institute scholars David Feith and Michael Sobolik, who supported restrictions covering “risks posed by equipment containing logic-bearing components produced by Covered List entities.”
The draft quotes Feith and Sobolik as arguing that such components could leave Americans and critical infrastructure “vulnerable to remote access, data collection, and exploitation.”
Industry warns of supply chain tracking hurdles
Industry groups have warned the FCC that component-level checks can be difficult to administer. CTIA, which represents wireless carriers, device manufacturers, suppliers, apps and content companies, told the commission that sweeping component parts into equipment authorization would create “a bevy of new practical hurdles.” CTIA also urged the FCC to avoid rules requiring the “creation and maintenance of parts lists” in the authorization process.
The Commercial Drone Alliance raised a similar traceability concern from the drone industry. In reply comments, the group said drones and other equipment contain “hundreds of individual components,” each of which would need to be traced to its original source. It added that manufacturers cannot reasonably certify component tracing compliance when supplier disclosures are “beyond their control.”
In a separate FCC equipment-authorization proceeding, the Consumer Technology Association raised a similar cost-and-delay concern. CTA told the FCC that requiring third-party certification or FCC-accredited laboratories for equipment currently handled through Supplier’s Declaration of Conformity “would drastically increase costs and delays without commensurate security benefit.”
The Commercial Drone Alliance also warned that replacing restricted components may raise supply-chain costs, saying functionally equivalent substitutes may exist “only at higher costs, increasing prices throughout the supply chain.”
Expanding bills of materials into hardware
The FCC’s further notice would reopen cost, feasibility and burden questions around component-origin reporting and bills of materials. The draft asks whether certification applicants should submit hardware and software bills of materials, identify component origins and update filings after material changes. It says “supply-chain monitoring is now central” to the equipment-authorization program’s national-security function.
The FCC also seeks comment on its own cost assumptions. It asks whether SBOM requirements for existing software would cost under $5,000 per software program, whether HBOM requirements may cost up to $10,000 per hardware equipment and whether approximately 50% of equipment seeking Commission authorization already meets the proposed SBOM and HBOM requirements.
CISA’s 2025 SBOM minimum-elements notice says SBOM tooling and implementation maturity have grown since 2021, while noting that government-wide policy does not generally require agencies to obtain SBOMs from software vendors.
The FCC proposal would extend similar disclosure logic to equipment authorization. The hardware version would identify components inside a device and information about their origin and production. The software version would cover software and firmware components used in a device.
Proposed duties for online marketplaces
Online marketplaces face a separate rulemaking track. The FCC draft proposes requiring marketplaces to collect compliance documentation, take reasonable steps to verify authorization or exemption, maintain records for a commission-specified period and display authorization or compliance information at the online point of sale. The draft asks commenters to address the viability, benefit and added expenses of those requirements.
The commission argues that the immediate FCC ID display rule should add little marginal cost because online marketplaces already publish product specifications, model numbers, UPC codes and regulatory marks.
Its small-entity analysis says the adopted rules should present “minimal compliance costs” to small entities and says adding an FCC ID online “does not increase marginal effort or expense.” It also acknowledges that the FCC cannot determine whether small entities would need professional help to comply.
The proposed rules leave the larger cost question open. The FCC asks small entities to submit information on possible reporting, recordkeeping and compliance burdens, including SBOM and HBOM filings, SDoC registration, expanded producer disclosures, possible authorization renewals and enhanced import documentation.
If commissioners approve the item, most final rules would take effect 30 days after Federal Register publication. Comments on the proposed rules would be due 30 days after publication, with replies due 45 days after publication.