Cybersecurity Policy Report, FCC Aims to Close Security ‘Loopholes’ in Equipment Authorization Process, (Oct 8, 2025)
By Lynn Stanton and Paul Kirby
“Loopholes” in the FCC’s equipment authorization process may be letting some equipment into the U.S. that presents a national security threat to communications networks, according to Chairman Brendan Carr.
At its Oct. 28 meeting, as previously reported, the FCC is expected to vote on a draft second report and order and second further notice of proposed rulemaking in ET docket 21-232 that will seek to close the loopholes (CPR, Oct. 7).
According to new details released yesterday, the item is aimed at previously authorized equipment whose newer models have been added to the “covered list” of equipment that cannot be imported, marketed, or sold in the U.S., as well as equipment that contains proscribed components.
In a statement, FCC Chairman Brendan Carr said, “For years, we have known that devices produced by Huawei, Hikvision, and other Covered List entities threaten America’s national security. But up to now, FCC regulations have not prevented Covered List providers from continuing to sell previously authorized device models. Nor have they applied to a device’s component parts. This month, the FCC will vote on closing these loopholes and providing the agency with new tools to safeguard our networks from insecure spy gear. These actions build on the FCC’s long-standing and bipartisan commitment to promoting America’s national security.”
Specifically, the draft second report and order would “[c]larify that covered equipment includes modular transmitters”; “[p]rohibit authorization of devices that include modular transmitters that are covered equipment”; “[p]rovide a procedure to limit previously granted authorizations of covered equipment to prohibit the continued importation and marketing of such equipment, without limiting continued operation or use”; “[c]larify the term ‘produced by’ as used in [the FCC’s] rules”; and “[c]larify the prohibition on modification, including permissive changes, to previously authorized covered equipment or equipment that would become covered as a result of such modification or permissive change,” according to an FCC fact sheet.
The draft FNPRM would “[s]eek additional comment on modular transmitters and component parts in relation to covered equipment”; “[p]ropose a definition of ‘critical infrastructure’ as used on the Covered List and seek comment on the implementation of that definition”; “[s]eek comment on whether any device modification made by an entity identified on the Covered List should require full certification”; “[s]eek comment on clarifying the scope of activities that constitute marketing of equipment”; and “[s]eek comment on measures to strengthen enforcement of marketing prohibitions,” the fact sheet adds.
News: FederalLegislation DataSecurity