United States of America Enforces Network Equipment Security Standards

United States of America has implemented a mandatory Equipment Authorization Program to safeguard its communications supply chain by requiring strict security certification for all network equipment and communication devices through regulation, with supporting updates in regulation, regulation, and regulation.

USA – NETWORK EQUIPMENT

USA Requires Security Checks for All Network Gear

All network equipment must pass security tests before it can be sold in the US.

What changed

Equipment Authorization Program mandatory for all network equipment entering the US market.

Security assessments required to verify resilience against cyber threats and unauthorized access.

Product scope covers cable modems, network hardware, and all telecom devices.

Manufacturers must meet strict national security standards before authorization is granted.

Who it affects

Network equipment manufacturers must obtain authorization before products enter the US market.

Importers of communication devices must ensure all equipment meets security standards.

Telecom hardware suppliers must verify products have passed security assessments.

United States — network equipment security authorization

Compliance Analysis: U.S. Equipment Authorization Program for Communications Supply Chain Security

The U.S. Federal Communications Commission (FCC) has strengthened its Equipment Authorization Program to mitigate national security threats posed by covered communications equipment and devices. The program imposes strict certification, marketing, and enforcement requirements under Title 47 of the Code of Federal Regulations (CFR) Part 2, effective 26 December 20251. Key provisions include prohibitions on authorizing "covered equipment," expanded definitions of critical infrastructure, and enhanced enforcement measures for modular transmitters and modified devices.

Regulation Analysis

1. Core Requirements of the Equipment Authorization Program

The FCC’s final rule (ET Docket No. 21-232; FCC 25-71) establishes the following obligations:

RegulationKey RequirementDeadline/ThresholdAuthority
Prohibition on Covered EquipmentNo equipment identified on the Covered List (maintained by the FCC) may be authorized for importation, marketing, or use in the U.S. communications supply chain. This includes devices "produced by" entities on the list1.Effective 26 Dec 2025FCC1
Modular TransmittersDevices containing modular transmitters that are classified as covered equipment are prohibited from authorization, even if the final product is not explicitly listed1.Effective 26 Dec 2025FCC1
Modification of Authorized DevicesAny modification to a previously authorized device by an entity on the Covered List requires a new certification application2. The FCC seeks comment on whether this applies to all modifications or only material changes.Comment period closes 5 Jan 2026 (reply comments due 2 Feb 2026)FCC2
Marketing ProhibitionsThe scope of "marketing" is clarified to include advertising, selling, leasing, or offering for sale covered equipment, with enhanced enforcement measures proposed2.Enforcement begins 26 Dec 2025FCC2
Critical Infrastructure DefinitionThe FCC proposes defining "critical infrastructure" for inclusion on the Covered List, seeking public comment on implementation2.Comment period closes 5 Jan 2026FCC2
Revocation of Prior AuthorizationsPreviously granted authorizations for covered equipment may be limited or revoked to prohibit continued importation and marketing1.Effective 26 Dec 2025FCC1

2. Key Definitions and Scope

A. Covered Equipment

  • Equipment identified on the Covered List, which includes devices posing national security risks (e.g., those produced by entities deemed threats by U.S. agencies)1.
  • The term "produced by" is clarified to encompass devices manufactured, assembled, or designed by entities on the Covered List, regardless of the final product’s branding1.

B. Modular Transmitters

  • Components that transmit radiofrequency signals (e.g., Wi-Fi modules, cellular chips) are subject to the same prohibitions as finished devices if they are covered equipment1.

C. Critical Infrastructure

  • The FCC proposes defining this term to include systems essential to national security, economic stability, or public safety, with comment sought on specific criteria2.

3. Enforcement and Compliance

A. Marketing Restrictions

  • Prohibited activities include:
    • Advertising, selling, or offering for sale covered equipment2.
    • Leasing or distributing such equipment in the U.S. market2.
  • The FCC seeks comment on additional enforcement measures, such as penalties for non-compliance2.

B. Certification Process

  • New applications are required for:
    • Devices modified by entities on the Covered List2.
    • Equipment containing modular transmitters that are covered1.
  • Previously authorized devices may face revocation if they pose security risks1.

C. Public Comment Period

  • Initial comments due: 5 January 20262.
  • Reply comments due: 2 February 20262.
  • Submissions must be made to the USA WTO TBT Enquiry Point (`usatbtep@nist.gov`) or via the FCC’s Electronic Comment Filing System (ECFS)2.

4. Legal Basis and Implementation

  • Final Rule: Published in the Federal Register (90 FR 53227, 25 Nov 2025) and codified in 47 CFR Part 21.
  • Proposed Rule: Published in the Federal Register (90 FR 55826, 4 Dec 2025) for public comment2.
  • Docket: ET Docket No. 21-232; FCC 25-71. Documents available via:
    • 2(https://www.fcc.gov/edocs/search-results?t=quick&dockets=21-232)1.
    • 2(https://www.fcc.gov/ecfs/search/search-filings/results?q=(proceedings.name:(%2221-232%22)))2.

Summary Answer

The FCC’s Equipment Authorization Program mandates strict security certification for communications equipment to protect the U.S. supply chain from national security threats. Key requirements include:

  1. Prohibition on covered equipment (effective 26 Dec 2025), including devices produced by entities on the Covered List and those containing modular transmitters1.
  2. New certification applications for modified devices or those altered by listed entities, with public comment sought on implementation2.
  3. Enhanced marketing restrictions and enforcement measures, including potential revocation of prior authorizations1.
  4. Public comment periods open until 5 Jan 2026 (initial comments) and 2 Feb 2026 (reply comments) on critical infrastructure definitions and enforcement clarifications2.

All stakeholders must comply with 47 CFR Part 2 and monitor updates via the FCC’s docket (ET Docket No. 21-232)2, 1.

Sources

  1. Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program — SS / directdoc https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=Q:/G/TBTN21/USA1771R1A1.pdf&Open=True
  2. Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program — SS / directdoc https://docs.wto.org/dol2fe/Pages/SS/directdoc.aspx?filename=Q:/G/TBTN21/USA1771R2.pdf&Open=True

Create your account