
Today, I submitted a reply comment on the Federal Communication Commission's Third Further Notice of Proposed Rulemaking regarding its equipment authorization program. The FCC's extensive list of questions regarding how to better execute its equipment authorization program touches on the complexity of managing the increasing scope of its Covered list. I offer several modifications to the rules as they stand today, including codifying some of the best current practices and interpretations as well as adjusting some of its least workable ones.
I thank the FCC for the opportunity to respond to comments on the Third Further Notice of Proposed Rulemaking (Third FNPRM) published by the Commission concerning additional measures to strengthen its equipment authorization program. My organization, the Foundation for American Innovation, has long sounded the alarm regarding critical infrastructure manufactured by adversaries, particularly UAS. As a former Intelligence Community analyst, I have closely watched the Covered List since its inception and have supported its continued progress in addressing national security risks. Nonetheless, I echo the proposal modifications outlined in many of the initial comments. FCC authorization rules function best when they target only the components that threaten national security, when adversaries cannot easily circumvent them, and when domestic and allied industry can reasonably comply with them.
To that end, I recommend the following:
- Codify the Commission's rejection to expand prohibition to passive components that are not logic-bearing. Codify the Commission's interpretation that no device requires equipment authorization that did not already, even covered entities' logic-bearing components that do not "use digital techniques or generate and use RF" for data processing.
- Codify the Class I and Class II changes permitted by the recent waivers for Covered List sectors.
- Do not implement fixed-term authorizations. Authorization term limits do nothing to prevent adversarial actors from operating.
- Create a database of Suppliers' Declaration of Conformity (SDoC) holders to facilitate online marketplace compliance and instill confidence in end-product manufacturers' component provenance. Continue not to require Hardware Bills of Material (HBOM) and Software Bills of Material (SBOM). Requiring further attestation in the form of HBOMs and SBOMs does not prevent a malicious actor intent on fraud, but does hamper domestic manufacturers.
- Adopt random hardware verification screenings carried out by trusted provenance verifiers, subjecting risky or suspicious components and end products to more frequent screenings.
- Leverage the technical expertise of government bodies in addition to the Departments of War and Homeland Security, such as the National Institute for Standards and Technology (NIST), to better gauge whether adversaries can evade rules. Convene round tables with domestic industry to anticipate questions and align rules with other, relevant regulations.
- Exempt FAA Part 135 certificate holders from the Covered List. Subjecting FAA certified operators to provenance requirements does not prevent foreign actors from endangering national security, as they would never qualify for the certificate's more stringent U.S. control and ownership requirements. It only adds hoops to jump through for U.S. companies.
- Replace "produced in a foreign country" with "foreign produced" and define the term by a tiered, risk-based framework.
- Codify UAS critical components as “components designed and intended primarily for use in UAS.” Seek comment on the definition of advanced robotics.
Focus on Logic-Bearing Hardware Components
The Commission is right to decline a rule prohibiting all components produced by Covered List entities. For the sake of clarity and investment planning, it should close the record on the question. While the Commission has the authority to place equipment or services on the Covered List if they "otherwise pose an unacceptable risk to United States national security," Congress has enumerated the primary threat vectors it expects the Commission to address. Namely, the Commission must place on the Covered List equipment or services that can route or redirect user data traffic, permit visibility into user data or packets, or cause a provider’s advanced communications network to be disrupted remotely. In an earnest effort to tackle national security issues while avoiding mission creep, the Commission asked whether it has the legal authority to prohibit passive, non-RF components. I concur with the many industry stakeholders who hold the Commission has no such authority.
The Commission has correctly identified that the national security risk hinges on the logic-bearing capacity of a component. To that end, I applaud the Commission for closing the component loophole by banning all logic-bearing hardware components produced by Covered List entities. I ask the Commission to codify its interpretation that this prohibition applies only to logic-bearing components that "use digital techniques or generate and use RF" for data processing, since this places the rules squarely within the Commission's purview. Not codifying this opens the door to legal action against the FCC for overstepping its authority.
If the Commission expands prohibition to all firmware and software produced by Covered List entities, or all logic-bearing hardware produced by adversary-controlled entities, it should not do so without specific National Security Designations and separate opportunities for comment. With respect to the latter, whether an adversary owns or operates an entity is probably best determined by the Commission, not manufacturers, especially when the sub-component in question is several layers down the supply chain. With respect to firmware and software bans, it is not clear what the bar for compliance would be. As the Wi-Fi Alliance points out in its comment, while adversarial control of software presents a concern, categorical prohibitions based on provenance complicate both enforcement and compliance, since the country of origin for a software repository or package is often impossible to determine.
Codify Permissive Changes, Refrain from Authorization Term Limits
The Commission should codify and expand the permissive Class I and Class II changes that it has allowed by waiver for UAS equipment and routers, and should expand this to minor hardware modifications. The Commission is right to employ a different compliance regime for Covered List entities as it does for Covered List sectors. The full recertification necessary for covered entities' modifications is appropriate. However, the workability of the new rules hinges on making permanent the waivers that facilitate covered sector manufacturers' modifications. As Boston Dynamics, a domestic robotics company whose success sharpens the U.S. technological edge, pointed out, the "treatment of software and hardware changes to existing product models already authorized and on the market" may be "the most challenging, burdensome, and costly aspect of the Third FNPRM." The flood of industry comments expressing strong support for codifying the waivers suggests trade groups and companies agree. This is not just because of the decade-plus lifespan of many products in covered sectors. It is also because the drastic supply chain recalibration required to get newly authorized products to market will mean extending the longevity of current product models.
Nefarious actors may use permissive modifications to insert back doors undetected, but subjecting to review every small bug fix, security update, or cog repositioning would create an administrative backlog so burdensome as to all but guarantee the very service disruptions the Covered List seeks to prevent. The Commission itself acknowledged that routers would face “unavoidable supply chain shortages” if certain hardware changes to current models were prohibited. Given that reality, cementing Class I and Class II permissive changes allows both the Commission and industry to focus on securing tomorrow's technology. The Commission should also expand the permissive changes outlined by the waivers for covered sectors. In addition to allowing minor hardware updates regardless of provenance, the Commission should permit any modification when the replacement component is U.S. produced, as recommended by Boston Dynamics.
For the same reasons the Class I and II permissive change waivers should extend beyond 2029, the Commission should refrain from fixed-term authorization limits. As the FCC acknowledges, "different classes of equipment have different lifecycles." Even if most authorized equipment phases out sooner than 10 years—a conjecture with ready counterexamples such as inverters, robots, and enterprise equipment—the Commission's desire to avoid de-authorizing still functional equipment highlights the ineffectiveness of the proposal. Either the proposal forces a subset of long-lasting equipment off the market despite Commission authorization and a lack of evidence of a security breach or it has no effect whatsoever because all equipment ages out before the limit. In neither scenario does it improve the FCC's ability to detect network disruption or data back doors. An authorization expiration would help catch nefarious actors whose exploitation of vulnerabilities has gone unnoticed, but in the process it would also capture multitudes of compliant products. Nefarious actors whose products were only phased out as the result of expirations have proven themselves adept at circumventing security checks; nothing stops them from receiving new authorizations for new products with the same vulnerabilities.
Fixed-term authorizations also inhibit future innovations that extend the utility horizon of a product. Supply chain constraints, now exacerbated by FCC provenance requirements, are already encouraging industry to architect cloud infrastructure, operating systems, and software to stretch the lifespan of legacy hardware in a variety of industries. As several comments noted, if the Commission detects currently authorized equipment poses an unacceptable threat, it can rely on revocation.
Maintain SDoC Verification and Build an SDoC Database, Continue Not Requiring Component Lineage Investigations
The Commission's concern that SDoC attestation leaves room for abuse is well grounded. The revocation of Odyssey Robot's authorization last month proves as much. However, proposals to improve accountability must actively deter malicious actors while ensuring domestic and allied companies can reasonably comply. For this reason, the Commission was right not to expand the removal of the SDoC pathway to covered sectors. Several commenters noted that the mandate would overwhelm Telecommunications Certification Bodies (TCB). More importantly, denying SDoC approval for a component when it goes into a covered sector product, while allowing it when it goes into other widespread consumer products whose disruption or data leakage would affect national security, is a double standard with no clear security benefit. Unless the Commission intends to fully remove SDoC component verification, reversing the first Trump Administration's creation of the procedure, then removing the pathway for only some devices is an arbitrarily piecemeal approach to whatever threat unintentional radiators pose. Instead, creating a database of SDoC holders is an intermediary step that the FCC can pursue to better understand the order of magnitude of products SDoC regulations would affect. The database would have the added benefit of helping good-faith manufacturers ensure they are not reliant on faulty attestations when procuring components. It would also facilitate compliance with the Commission's online marketplace rules.
Moreover, the Commission was right not to impose HBOM and SBOM requirements on covered sectors. Such requirements would be more burdensome than the expectations for military contractors under the recent Executive Order 14415, since the Commission's proposal would affect a much wider array of producers, require constant updates, and demand estimates for the value-add of every production location. As a way of determining the trustworthiness of components, HBOM and SBOM are no more valid than SDoC. While costly to implement, these ingredient lists ultimately rely on attestation of end-product manufacturers, who in turn must trust the attestation of their component manufacturers, and so on several layers down the supply chain. The ineffectiveness of the proposal is best summed up by electric vehicle company Faraday Future. "Disclosing every entity involved in every component at every stage of the supply chain is incredibly costly, if not downright impossible, requiring applicants to use their judgment to determine the 'major stage[s] of the process by which a device comes into existence.'" This is all the more true for SBOMs, where defining the provenance of open source software is impossible and where continuous integration, deployment, feature testing, and security patching make updating SBOMs highly labor-intensive, as many comments noted.
And yet, the Commission is justified in its fear that attestation is easily circumvented. At least for hardware, it is probably within the FCC's authority to mandate greater proof from manufacturers. To ensure that components do not originate from covered entities, the Commission could adopt random hardware verification screenings carried out by trusted provenance verifiers. Unlike HBOM, post-authorization random verification improves the enforceability of the Commission's rules without delaying product release. The sampling could be risk-based, subjecting certain components and end products to more frequent screenings. Partnering with supply chain validation labs would complement the FCC's effort to prune TCB "bad labs."
Implement Technical Round Tables
Including whole sectors on the Covered List significantly raises the ambition and widens the scope of the List. Even the most knowledgeable and well-intentioned Commission staff cannot anticipate all the potential complications arising from new rules. Neither does the Commission need to build a secure supply chain framework from the ground up. Building on initial comment recommendations, the Commission should regularly convene with economic analysts at the International Trade Administration's Office of Manufacturing Industries and technical experts at NIST to evaluate whether FCC rules are well targeted. The Commission should separately convene industry stakeholders to help inform and stress-test new Rule and Orders, as multiple comments recommend. The FCC adopting industry round tables would not make it beholden to an industry desire to continue operations unimpeded. Rather, it would help the Commission anticipate questions, so that, once promulgated, rules have little need for clarification or exemption.
Exempt Part 135 Certificate Holders
While no vetting process, including a Part 135 certificate, can completely eliminate the risk of disruptions, unauthorized surveillance, or data exfiltration, Part 135 certification is arguably the most rigorous security vetting for any of the technology included in covered sectors. Along with domestic manufacturer-operators who do not sell UAS to third parties, Part 135 operators have greater control over the operations and inputs of their equipment, control which should be favorably reflected. It is hard to see how manufacturing in the U.S., in and of itself, enhances national security more than the ownership, component transparency, software control, and data custody that Part 135 requires. For example, the Covered List is not clear whether Chinese drone hegemon DJI is an entity, subject to the logic-bearing hardware ban, or merely included in the UAS and UAS critical component sector ban. For that reason, a UAS whose total domestic component costs exceed 65 percent may be allowed to source logic-bearing hardware from DJI without scrutiny; a Part 135 operator categorically could not.
If Part 135 does not satisfy the Commission's national security concerns, the Commission should work with the FAA to fortify the certification. As they stand now, clearing both regulatory hurdles is extremely difficult. As one affected operator acknowledges in its comment, migrating to U.S. suppliers resets the more rigorous FAA certification process, leaving models in a months or yearslong holding pattern despite being otherwise ready for use. The cost of this delay, along with all supply chain redirection across the covered sectors, is excluded in the Commission's cost benefit analysis of the rule.
Defining Foreign Produced
Defining foreign produced parts is the Commission's single most consequential decision, as many of the recent rules apply only to foreign produced products. In this effort, the Commission should consider several key factors. First, the definition should target the threat of adversarial control of RF-emitting components, not the value of a good. As many comments argued, the Buy American standard should not be retrofitted for the FCC's distinct purpose, as some high value components like drone frames have few security implications. If adversarial actors can evade the Covered List by manufacturing high-value, security-irrelevant components in the U.S., the definition is not fit to task. Second, for some producers, merely moving production out of adversarial countries is a herculean effort, especially for smaller manufacturers with less buying power to source components in the U.S.
Third, producing in the U.S. is not, in and of itself, sufficiently secure. As the Coalition for a Prosperous America pointed out, Zhongji Innolight and Eoptolink, two Chinese manufacturers that make the bulk of high-speed transceivers in U.S. data centers, have shifted assembly outside of China to avoid scrutiny, but maintain control over production. If they manufactured in the U.S. but were not subject to greater scrutiny or testing, they would remain a threat. Adversarial control is a better proxy for security threat than location of assembly line. Lastly, foreignly produced products must remain a separate concept than products "produced by" covered entities. Foreign production in general is less threatening than foreign production by entities specifically highlighted as unacceptably risky to national security.
With this in mind, the Commission should replace "produced in a foreign country" with "foreign produced," which allows for consideration of additional factors. The FCC should then establish "foreign produced" as a tiered, risk-based framework. A product is foreign produced when an entity incorporated in or predominantly operated out of an adversarial country meaningfully controls security-relevant components and is subject to operational interference by its government. A product is probably foreign produced when an entity incorporated in or predominantly operated out of an adversarial country meaningfully controls security-relevant components but is not subject to operational interference by its government. A product is potentially foreign produced when non-adversary, non-U.S. entities meaningfully control security-relevant components, and it is domestically produced when U.S. entities solely control such components. Each tier can be tied to a different level of scrutiny, from outright prohibition under the Covered List to further hardware testing to streamlined authorization.
Notably, within this framework, a product can be produced foreignly regardless of production location. This also allows for foreign engineers to contribute to design and development without raising alarm; future rules can mandate attestation that U.S. engineers retain oversight or, should the Commission see necessary, are the primary contributors. This definition of foreign produced leaves space to consider production location as a factor in meaningful control without foreign designation hinging on it. This definition is also more in line with the Protecting Americans from Foreign Adversary Controlled Applications Act, and the FCC can borrow the definitions of key terms from the Act. Although enacted in a different context, the Act's aim to address Chinese control of a U.S. consumer product (Tiktok) is more in line with the Commission's goal than the Buy American standard. The change of phrase from "produced in a foreign country" to "foreign produced" is not a slight of hand. It is a more fitting approach that recognizes production as the "process by which a device comes into existence," a process that involves both location and control.
Defining UAS Critical Components and Advanced Robotics Devices
The Commission should codify its working definition of UAS components as “components designed and intended primarily for use in UAS.” Otherwise, as the Commission notes, a foreign-manufactured camera is banned when attached to a drone, and permitted when attached to license plate readers for local police departments, despite similar national security risks. UAS are not uniquely insecure because they are flying cameras instead of perched ones. The Commission should clarify that codifying this definition means components that have received modular transmitter certification are not subject to the Covered List, since those modules are largely multi-use and not specific to UAS. The compounded listing of UAS and UAS components is another reason the Buy American standard is a poorly fit test. As it stands, a complete UAS that is 65 percent manufactured in the U.S. but whose critical components are mostly foreign is excluded from the Covered List. Meanwhile, a UAS whose RF components are mostly U.S. manufactured but whose frame is foreign may still be banned.
Additionally, as one comment noted, the Commission did not seek comment on defining advanced robotic devices. That definition will be crucial to the enforceability of recent production-location based designations. Whatever future critical component manufacturing takes place in the U.S., it will likely be in factories integrated with advanced robotic devices. If those devices themselves suffer supply bottlenecks, increased production capacity will never be realized. The Commission should seek comment separately on how best to define this term.
Conclusion
The FCC should adopt the conservative principle of taking as light of a regulatory approach as possible to achieve its goal of hardening the national security of RF-emitting products. As one of the initial comments explains, the proposed framework subjugates every layer of the stack–the design of connected devices, the data center infrastructure that undergirds American AI, and the advanced robotics that onshoring will require–to the ad hoc approval of the FCC. The Commission may be wary to readily accept the concerns of companies whose bottom line is affected by improving national security. The Commission is hopefully more sympathetic to the concern that the supply chain shortages resulting from its new rules undermine other FCC goals, such as Unleashing American Drone Dominance or improving connectivity through infrastructure buildout.
Just nine months ago, the Covered List included only specific entities' specific components. Now, it includes four whole industries, and regulates their countless components. Even ardent national security proponents recognize the pace of regulation increases the risk of the very disruptions the Commission aims to prevent. As the FCC grapples with the myriad ways global supply chains that are intricately bound to adversaries threaten national security, it must craft rules that cannot be easily circumvented by bad actors and can be complied with by good-faith ones. The proposals outlined in this reply comment aim to help the Commission better strike that balance.



