Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Apple Gets Reprieve From U.K.’s Data-Access Demand, Gabbard Says
    • Administration’s Cyber Cuts Endanger U.S., Homeland Security Democrats Say
    • Court Finds ‘Pay-or-OK’ Model Violates EU Privacy Law
    • Lawmakers Seek Investigation into Spain-Huawei Arrangement
    • Privacy Law Updates Contemplated in Colombia
    • Stakeholders Raise Concerns About FCC’s ‘Bad Lab’ Proposals
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Stakeholders Raise Concerns About FCC’s ‘Bad Lab’ Proposals, (Aug 19, 2025)

    Organizations Mentioned:Bureau Veritas Consumer Products Services | Information Technology Industry Council (ITI) | National Electrical Manufacturers Association | SGS North America, Inc. | Telecommunications Industry Association

    By Lynn Stanton

    While supporting the goals and past efforts of the FCC in improving its equipment authorization processes, stakeholders commenting on further proposed actions in that area expressed concern that blanket prohibitions on participation by entities with ...

    By Lynn Stanton

    While supporting the goals and past efforts of the FCC in improving its equipment authorization processes, stakeholders commenting on further proposed actions in that area expressed concern that blanket prohibitions on participation by entities with ties to foreign adversaries could affect those with only tangential connections, that proposals regarding post-market surveillance could be burdensome and complicated to implement, and that new rules that conflict with those of other regulatory bodies could leave U.S. entities at a disadvantage.

    Parties were responding to a further notice of proposed rulemaking (FNPRM) adopted in May in ET docket 24-136 alongside a report and order that prohibited telecommunications certification bodies (TCBs), test labs, or laboratory accreditation bodies that are owned, controlled, or directed by an entity on the FCC’s “covered list” or other specified government lists of national security threats from participating in the FCC’s equipment authorization program.

    The FNPRM proposed and sought comment on “further measures to safeguard the integrity of our equipment authorization program,” such as extending the prohibitions in the order to “entities subject to the jurisdiction of a foreign adversary” or applying “a presumption-of-prohibition to a larger class of entities beyond prohibited entities. It also sought comment on a proposal “to expand the group of prohibited entities to include several additional lists from federal agencies or statutes” and on “ways the Commission can facilitate and encourage more equipment authorization testing to occur at test labs located within the United States or United States allied countries.” It also sought “further comment on post-market surveillance procedures to ensure compliance relating to prohibitions on authorization of covered equipment,” FCC, Report and Order and Further Notice of Proposed Rulemaking, Dkt. 24-136 (May 22, 2025) (CPR, May 22).

    The Consumer Technology Association said it was “concerned that certain proposals put forward in the FNPRM could increase costs for consumers, reduce innovation and disrupt the supply chain throughout the tech industry, without providing commensurate security benefits.”

    CTA added, “Any changes should meaningfully increase security while minimizing burdens and adverse economic effects on consumers and innovators. This means avoiding (i) unnecessarily expelling or forbidding participants from the equipment authorization program, (ii) misaligned post-market surveillance requirements, (iii) barriers to the Telecommunications Certification Body (TCB) and test lab relationship and (iv) third-party testing requirements that would undermine the Supplier’s Declaration of Conformity (SDoC) program. In addition, any rule changes must provide manufacturers with sufficient time and guidance to comply with changes and avoid more disruption to supply chains than is necessary.”

    The Information Technology Industry Council (ITI) urged the FCC “to ensure any new requirements are narrowly tailored to address concrete risks, align with existing national security and supply chain oversight frameworks, and avoid duplicative or conflicting mandates. A balanced, risk-based, and evidence-driven approach is essential to preserve U.S. innovation leadership and global competitiveness. Requiring U.S. based companies to navigate overly prescriptive or duplicative obligations as proposed by the FNPRM would risk slowing their ability to integrate the latest, most advanced technologies into products and services for the American public. Such constraints could hinder time-to-market, limit consumer access to the latest innovations and erode the competitive edge of U.S. companies in the global marketplace.”

    ITI said the proposed approach to restricting participation by entities owned by, controlled by, or subject to the jurisdiction of foreign adversaries “could inadvertently sweep in U.S. companies (based in the U.S. and/or with operations internationally) with only incidental or tangential connections to foreign adversaries — for example companies employing remote workers or sourcing from suppliers located in designated countries.”

    In response to a question in the FNPRM about hindrances and advantages facing entities that seek to rely primarily on TCBs, test labs, and laboratory accreditation bodies based in the U.S., ITI said that “relying solely, or even mostly, on equipment authorization facilities located within in the U.S. is very likely to cause major disruptions in the availability of technologies to the marketplace and to businesses. Certification testing is a massive undertaking that often involves tens of thousands of radiofrequency chamber testing hours for each device. Shifting all of that testing capacity to the U.S. would be a very time-consuming and expensive prospect that will upend testing timelines and investor expectations.”

    It also expressed concerns about the administrative burdens the proposed changes in market surveillance would impose on the FCC and industry.

    The Fixed Wireless Communications Coalition urged the FCC to “refrain from making further changes to the Supplier’s Declaration of Conformity (SDoC) procedures at this time. The FNPRM’s proposed changes would undermine the SDoC process without any countervailing benefits. Specifically, requiring that ‘all equipment authorized under the SDoC procedure be tested at an accredited and FCC-recognized laboratory’ will significantly increase testing costs, which will ultimately increase costs for consumer and other users of electronics across virtually every industry in the country. The proposed changes will also increase time-to-market for new products, making the U.S. market less competitive globally when it comes to the development and deployment of new technologies. Finally, the SDoC rules, as recently updated, provide the Commission with the tools necessary to ensure SDoC authorized devices comply with the Commission’s rules. Therefore, further changes are unnecessary.”

    The Telecommunications Industry Association said that ICT (information and communications technology) was “a global industry, and while the existing testing and certification infrastructure is expensive, it is efficient. Any further action taken too quickly will likely result in delays or increased costs for testing and certifying could have widespread effects on U.S. consumers. It is with that in mind that we urge the Commission to continue its measured approach in this docket, balancing the need to efficiently test and certify innovative products with the imperative to mitigate demonstrable national security risks.

    “Specifically, any new rules to restrict labs and TCBs for certification authorization should be phased in to first exclude the most high-risk entities from the EAP and over a sufficient time period that allows industry to find alternatives while continuing to introduce new devices to the U.S. market at the pace U.S. consumers expect. Additionally, the Commission should not adopt any of its proposals to restrict the successful Supplier’s Declaration of Conformity (‘SDoC’) program, which allows for the self-approval of very low-risk, but important devices,” TIA added.

    The National Electrical Manufacturers Association urged the FCC to tailor prohibitions to specific categories, subcategories, or even specific products of RF (radiofrequency) devices. It said the SDoC should remain “largely unchanged.” Any changes in either certification or SDoC processes should allow for “adequate transition time,” it added.

    The FCC’s goal of increasing testing and certification within the U.S. will require “additional resources” at the National Institute of Standards and Technology, NEMA said.

    The Mobile & Wireless Forum said “the FNPRM has the potential for results counter to the objectives of the ‘Delete, Delete, Delete’ proceeding without providing protection additive to the Report & Order. That is, instead of promoting the objectives of streamlining and efficiency, which are the hallmarks of the ‘Delete’ docket, there is a potential for adding unnecessary and burdensome requirements to the device authorization processes. For this reason, MWF’s primary recommendation is for the FCC to give the just-approved Report & Order time to operate before seeking to augment it.”

    TIC Council Americas expressed concern that the FNPRM proposals would, among other things, complicate supply chains. “Additionally, TIC Council members note that labor constraints in the USA and allied countries will also hinder the timely relocation of equipment authorization testing and certification. Policies that encourage the nearshoring of the ICT supply chain — and supplemented by policies that promote skilled ICT labor — would likely be the most effective in building testing capacity outside of China,” it said.

    HCT America opposed the proposal to prohibit TCBs “from reviewing an application that includes test data … that was prepared by a measurement facility that is owned by, controlled by, or subject to the direction of any entity that also owns, controls, or directs the TCB” and the proposal to require TCBs to accept test data from any FCC-recognized accredited test laboratory, except as provided by the earlier prohibition, “subject to the requirements in ISO/IEC 17065, and must not unnecessarily repeat tests.”

    “The impartiality requirements of ISO/IEC 17065 address all affiliations by requiring a rigorous accredited impartiality policy,” HCT America said. It added that “TCBs do not issue reports, only reviewing test reports issued by any recognized laboratory even in its own affiliated testing lab. There is no issue to review test reports issued by its own affiliated test labs or other recognized testing firms.”

    As for the post-market surveillance proposal, HCT America said it would “increase complexity of post market surveillance tests due to NDAs [nondisclosure agreements] between TCBs and manufacturers, varying expertise, and communication among TCBs regarding new technical features in the state-of-art telecommunication devices.”

    SGS North America, Inc., said the FCC’s current instruction for TCBs to “exercise due diligence” in tasks outside their designated authority, such as assessing whether a product contains or can contain prohibited software, “does not equip TCBs with the necessary tools or clarity to fulfill these responsibilities effectively.”

    “The proposals outlined in the FNPRM do not enhance the integrity or security of the equipment authorization program. Rather, they risk undermining it. TCBs are experts in conformity assessment—not regulators, intelligence agencies, or corporate registrars. The responsibility for determining an entity’s eligibility to receive an equipment authorization should rest solely with the FCC,” it said.

    Bureau Veritas Consumer Products Services, Inc., expressed three concerns about the proposed rules: language barring labs physically or legally located in foreign adversary countries “could undermine U.S. commercial interests and innovation” by putting them at a competitive disadvantage to “foreign competitors testing for other regulatory bodies”; language barring TCBs from reviewing an application that contains data prepared by a measurement facility owned by, controlled by, or subject to the jurisdiction of the same entity as the TCB could conflict with procedures accepted by other regulatory bodies, lead to the breach of confidentiality commitments, or force businesses to outsource testing or certification; language requiring post-market surveillance of product types certified by a different certification body could create insurmountable time constraints, create substantial risks related to testing viability, complicate contractual arrangements, and create “substantial bottlenecks in the surveillance process.”

    Compliance Testing LLC Chief Executive Officer Michael Schafer called for banning all Chinese labs from the equipment authorization process. “If we don't recognize China as a collective foreign adversary working in every capacity to undermine and overthrow U.S. interests[,] we are blind to the truth,” he said.

    Jennifer Sanchez, a wireless compliance engineer, opposed the proposed “restrictions on TCBs accepting data from associated laboratories and expanded post-market surveillance requirements. While I support the FCC’s goals of maintaining impartiality and protecting national security, the proposed approach would impose severe harm on U.S.-based TCBs, reduce domestic capacity, and risk shifting certification work to foreign entities.”

    News: FederalLegislation DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use