Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • DHS Board Blames Microsoft’s ‘Cascade’ of Errors for 2023 E-mail Breach
    • Bill to Revise Browser Requirements Under CCPA Advances
    • Children’s Data Privacy Act Advances in California
    • D.C. Circuit Gives Hikvision, Dahua Some Hope in ‘Covered List’ Case
    • Greek Immigration Authority Fined Over GDPR Violations
    • HEALTH CARE COMPLIANCE NEWS—New Jersey SNF hit with $100K CMP for HIPAA violation over timely access to medical records
    • Hong Kong DPA Issues Enforcement Notice After Cyberport Data Breach
    • Italy Suspends Worldcoin’s Orb Collection of Iris Scans
    • NIST Publishes Draft Handbook on IoT Cybersecurity
    • Summit Seeks Clarity Amid ‘Rip-and-Replace' Funding Shortfall
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, D.C. Circuit Gives Hikvision, Dahua Some Hope in ‘Covered List’ Case, (Apr 3, 2024)

    By Lynn Stanton

    The U.S. Court of Appeals for the District of Columbia Circuit yesterday rejected challenges by Hikvision USA, Inc., and Dahua Technology USA, Inc., of the FCC’s placement of the companies’ equipment on the agency’s “cover ...

    By Lynn Stanton

    The U.S. Court of Appeals for the District of Columbia Circuit yesterday rejected challenges by Hikvision USA, Inc., and Dahua Technology USA, Inc., of the FCC’s placement of the companies’ equipment on the agency’s “covered list” of equipment deemed a national security risk, but the court agreed with the companies that the FCC’s definition of “critical infrastructure” was “overbroad, unexplained, and arbitrary.”

    In a November 2022 order, the FCC prohibited the authorization, importation, or marketing of equipment on its covered list, as mandated by the Secure Equipment Act (SEA) of 2021 (CPR, Nov. 29, 2022). For Hikvision and Dahua, the prohibition covers telecommunications and video surveillance equipment that is used for the purpose of public safety, security of government facilities, physical surveillance of critical infrastructure, and other national security purposes.

    In an opinion released in consolidated cases Hikvision USA, Inc., v. FCC et al. (case 23-1032) and Dahua Technology USA, Inc., v. FCC et al. (case 23-1073), the court vacated the portions of the order defining “critical infrastructure” and remanded it to the FCC “to comport its definition and justification for it with the statutory text” of the National Defense Authorization Act for fiscal year 2019.

    Writing for the court, Circuit Judge Florence Pan said, “The SEA ratified the composition of the Covered List at the time of the SEA’s enactment and thus precludes Petitioners from claiming that their products were improperly put on the list at an earlier point in time.”

    The SEA also required the FCC to promulgate the proposed rule on equipment authorizations that was included in the November 2022 order.

    “It appears, then, that when Congress passed the SEA, it intended to require the FCC to prohibit the marketing and sale of Petitioners’ products for listed purposes within the United States,” Judge Pan wrote.

    As for the FCC’s definition of “critical infrastructure” for use in determining whether the relevant equipment is being used for physical surveillance of critical infrastructure, Judge Pan noted that the Commission “relied on the Patriot Act, Presidential Policy Directive 21 [PPD-21], and the Cybersecurity and Infrastructure Security Agency’s set of National Critical Functions in crafting its definition of critical infrastructure. The Order states that ‘any systems or assets, physical or virtual, connected to the sixteen critical infrastructure sectors identified in PPD-21 or the 55 [National Critical Functions] identified in [the] CISA/NRMC [risk management guide] could reasonably be considered “critical infrastructure.”’ J.A. 211. Although Petitioners concede that the FCC’s application of the Patriot Act definition of critical infrastructure may be appropriate, they assert that the Commission went too far in incorporating PPD-21 and the CISA National Critical Functions, as well as sweeping in anything that is merely ‘connected to’ those economic sectors and functions.”

    Judge Pan said, “The Commission’s choice of reference materials — government sources that define ‘critical infrastructure’ and related concepts in national-security contexts — was reasonable, and the Commission adequately explained why the cited sources were relevant. … But the definition of ‘critical infrastructure’ ultimately adopted by the FCC includes any ‘systems or assets’ that are merely ‘connected to’ the sixteen sectors identified by PPD-21 or the fifty-five functions listed by the CISA risk-management guide. J.A. 211. The FCC failed to explain or justify its use of the expansive words ‘connected to,’ and the scope of the definition is therefore arbitrarily broad.”

    Judge Pan was joined in the opinion by Circuit Judge Patricia Millett and Senior Circuit Judge A. Raymond Randolph.

    Oral argument was held in the case in December (CPR, Dec. 15, 2023).

    News: FederalLegislation DataSecurity LitigationEnforcement

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use