US Requires Import Permits and Certification for Network Gear from 1 March 2027

by admin
United States of America Enforces Network Equipment Security Standards

United States of America has implemented a mandatory Equipment Authorization Program to safeguard its communications supply chain by requiring strict security certification for all network equipment and communication devices through regulation, with supporting updates in regulation, regulation, and regulation.

The US Federal Communications Commission has banned the import and sale of all network equipment and communication devices that pose a national security risk, under a new mandatory Equipment Authorization Program that takes effect on 1 March 2027.

The rules cover everything from routers and mobile phones to submarine cable systems and emergency-call infrastructure, cutting off any device made by companies already flagged on the FCC’s Covered List. Every importer, manufacturer and retailer must now prove that a product contains no prohibited components before it can be sold in the United States.

It is the first time the agency has used its equipment-authorisation powers to block entire categories of hardware rather than just individual models.

The Covered List and what it blocks

The Covered List is a rolling register of equipment and services that the US government has already determined “pose an unacceptable risk to the national security of the United States or the security and safety of United States persons.” It is drawn from four official sources: the Department of Commerce, the Department of Homeland Security, the Director of National Intelligence, and the Department of Defense1.

What the Covered List blocks at the border

Any device with a listed component Barred even when assembled in a third country
White-labelled products Different brand, listed supplier behind it
Modular transmitters Wi-Fi chips and 5G radio units later built into larger systems

As of the latest update, the list names five Chinese manufacturers—Huawei, ZTE, Hytera, Hikvision and Dahua—plus their subsidiaries and any entity they control. Any device that contains a component from one of those companies is automatically barred, even if the final assembly happens in a third country2.

The ban extends to “white-labelled” products—devices sold under a different brand but built by a listed supplier—and to modular transmitters such as Wi-Fi chips or 5G radio units that are later integrated into larger systems3.

Who must comply and by when

The prohibition applies to every company that imports, manufactures, markets or sells communications equipment in the United States. Importers must obtain a pre-issued import permit for every shipment; retailers must stop selling any product that contains a Covered-List component; and certification bodies must refuse to test or approve such equipment2.

The rules take effect on 1 March 2027, giving the industry a twelve-month transition period. After that date, any device that has not been certified under the new regime is prohibited from entry and cannot be advertised, sold or operated in the United States2.

How the certification process changes

The FCC runs two pathways for equipment approval: certification (for high-risk devices) and Supplier’s Declaration of Conformity (SDoC, for lower-risk items). Under the new rules, every product that contains any Covered-List component must now go through the stricter certification process, regardless of its previous classification2.

Approval pathways, before and after

RequirementUntil nowUnder the new rules
Pathway for products with a Covered-List componentCertification or SDoC, by prior classificationStricter certification, always
Who may test and approveAny accredited TCB or labOnly bodies free of Covered-List or foreign-adversary control
Responsible partyNone named in the USUS-based liable party required

Certification bodies—known as Telecommunication Certification Bodies (TCBs)—and the laboratories that test the equipment must themselves be free of ownership, direction or control by any entity on the Covered List or by any foreign adversary. The FCC has set up a vetting process to remove untrustworthy actors from the programme4.

Importers must also name a US-based liable party—a company or individual physically located in the United States who can be held responsible if the equipment later proves non-compliant2.

What happens to equipment already in the country

The new rules are prospective: they do not force consumers or businesses to remove or destroy devices they already own. However, the FCC has created a “partial revocation” procedure that allows it to block the continued import and marketing of any product that was previously authorised but is now on the Covered List1.

Once the revocation takes effect, retailers may no longer advertise or sell the product, and importers may not bring in new stock. The FCC has not set a deadline for clearing existing inventory, but it has warned that any company caught importing or selling prohibited equipment after 1 March 2027 will face enforcement action1.

Submarine cables and emergency networks

The rules also tighten oversight of submarine cable landing stations and next-generation 911 (NG911) infrastructure. Submarine cable operators must now obtain a separate FCC licence for their Submarine Line Terminating Equipment (SLTE)—the hardware that converts optical signals from undersea cables into electrical signals for land-based networks5.

The licence comes with mandatory security conditions: operators must certify that no principal equipment is produced by a foreign adversary, that no third-party service provider is on the Covered List, and that no capacity is leased to any entity flagged by the FCC5.

For NG911 systems, the FCC has adopted new reliability standards that require service providers to monitor network traffic, maintain circuit diversity, and implement active fail-over mechanisms. The rules apply to every company that carries emergency calls, from traditional telecoms to cloud-based voice providers6.

Costs and exemptions

The FCC estimates one-time compliance costs of $28.5 million and annual costs of $10.7 million across the industry. Those figures include the expense of re-testing equipment, updating supply chains, and setting up US-based liable parties5.

Estimated industry compliance costs, USD

One-time compliance costs $28.5m
Annual costs $10.7m

There are no blanket exemptions for small businesses or for equipment that is already in the supply chain. The only carve-out is for devices that are physically incapable of connecting to a network—such as a standalone sensor with no radio transmitter—but even those must still be certified if they contain a Covered-List component2.

What the rules do not change

The new programme does not alter the existing process for adding companies to the Covered List; that remains the responsibility of the four national-security agencies. It also does not affect the separate bulk-power executive order that bans certain foreign-made electric-grid equipment7.

Nor does it change the FCC’s authority over state and local 911 authorities: the agency sets minimum reliability standards, but states can still impose stricter rules through their own statutes and service-level agreements6.

The next deadline

The FCC has committed to a March 2028 review of the entire programme, including the effectiveness of the certification process, the accuracy of the Covered List, and the impact on small and rural providers3. In the meantime, the agency has opened a dedicated portal for importers to register their US-based liable parties and to apply for the new import permits2.

Sources

  1. Protecting Against National Security Threats to the Communications Supply Chain https://www.federalregister.gov/documents/2025/11/25/2025-21001/protecting-against-national-security-threats-to-the-communications-supply-chain-through-the
  2. FCC Rule on Equipment Authorization Program to Protect Communications Supply Chain from National Security Threats https://www.federalregister.gov/documents/2023/02/06/2022-28263/protecting-against-national-security-threats-to-the-communications-supply-chain-through-the
  3. Protecting Against National Security Threats to the Communications Supply Chain through the Equipment Authorization Program https://docs.wto.org/imrd/directdoc.asp?DDFDocuments/T/G/TBTN21/USA1771R3.docx
  4. Promoting the Integrity and Security of Telecommunications Certification Bodies and the Equipment Authorization Program https://www.federalregister.gov/documents/2025/08/07/2025-14970/promoting-the-integrity-and-security-of-telecommunications-certification-bodies-measurement
  5. Review of Submarine Cable Landing License Rules and Procedures https://www.federalregister.gov/documents/2026/07/27/2026-15123/review-of-submarine-cable-landing-license-rules-and-procedures-to-assess-evolving-national-security
  6. Facilitating Implementation of Next-Generation 911 Services (NG911) https://www.federalregister.gov/documents/2026/07/10/2026-13998/facilitating-implementation-of-next-generation-911-services-ng911-improving-911-reliability
  7. Executive Order 14421: National Emergency to Secure the U.S. Bulk-Power System https://www.federalregister.gov/documents/2026/09/09/2026-18370/securing-the-united-states-bulk-power-system

You may also like