From banned devices to bills of materials: every FCC Covered List action, March to September 2026
Six months ago a Covered List entry stopped new devices at the border. It now reaches the components inside them — and backward, to equipment already sold.
Status verified September 23, 2026. This page tracks a moving target and is updated as actions land.
Six months ago the FCC's Covered List worked one way: a category of finished device was named, and new authorizations for it stopped. Since March 2026 the Commission has changed the shape of the tool twice over. It has started reaching underneath the finished device, to the components inside it and the places they were made. And it has started reaching backward, to equipment that was already authorized and already sold.
Both shifts matter more than any single device category, because both change what a Covered List listing can actually touch. Here is the record, action by action.
Covered List additions
March 23 — foreign-produced consumer routers (DA 26-278). Bars new equipment authorizations, import and marketing of new models. Devices already purchased are untouched. An 18-month conditional-approval path runs through the Department of War or DHS, tied to onshoring commitments. A companion waiver, DA 26-286, permits firmware and security updates to already-authorized routers through March 1, 2027.
July 28 — foreign-produced power inverters and advanced robotic devices (DA 26-786). Inverters are covered where they contain components enabling remote communication, control, sensing or monitoring. Smart machines are defined by weight, environmental sensors, network connectivity, and autonomous or remote command.
August 20 — the inverter entry modified (DA 26-870). Broadened to wired and Ethernet connectivity, after the Department of War found that Ethernet-connected inverters pose the same risk as wireless ones. Simultaneously narrowed to utility-interactive inverters, with an exclusion for producers eligible for the §45X advanced manufacturing credit.
That August modification is worth pausing on. The argument that a threat only arrives over the air did not survive contact with the analysis. Connectivity is connectivity.
The component-level shift — the significant one
July 22–23 — FCC 26-50 (ET Docket 21-232), a Third Report and Order together with a Third Further Notice of Proposed Rulemaking.
The Order extends Covered List prohibitions to devices containing logic-bearing hardware components from Covered List entities, and imposes compliance obligations on online marketplaces. A clean device with a listed component inside it is now in scope, and the marketplace that sells it carries duties too.
The Further Notice goes further still. It proposes:
- Hardware and software bills of materials identifying each critical component's producer, its production locations, and its share of component value
- A production-location-based Covered List category alongside the existing producer-based one
- Anti-white-labeling measures
- Mandatory certification for devices in Covered List sectors
Comments closed September 8; reply comments were due September 21.
Read that list again as an operator rather than a manufacturer. A hardware bill of materials is a provenance document. If it arrives, the question stops being "who put their brand on this box" and becomes "where did the logic inside it actually come from, and how much of its value came from there." That is a far harder question to answer about equipment you already own than about equipment you are about to buy.
Reaching the installed channel
June 26 — DA 26-635 prohibits continued import and marketing of previously authorized covered equipment that was added to the Covered List in 2024 or earlier.
Equipment already purchased remains usable. Post-2024 additions are excluded. Restrictions are temporarily suspended for equipment used in physical-security surveillance of critical infrastructure, pending a new federal definition.
This is the first action to reach backward rather than only forward, and it revises something we said when the router listing landed: that the FCC, acting alone, could not reach the installed base. For listings from 2024 and earlier, it now does — at the import and marketing stage. What it still does not do is make a device already sitting in a clinic, a substation or a plant room any safer. Nothing is recalled. Nothing is removed. The hundreds of millions of devices already deployed and already trusted the moment they were switched on remain exactly where they are.
Enforcement
August 11 — the first equipment-authorization revocation of its kind. Odyssey Robot LLC had two authorizations revoked (DA 26-839) after false statements that its products were not covered equipment.
August 10 — an import and marketing prohibition proposed for Anzu Robotics (DA 26-832, PS Docket 26-184), with comments due September 23. A separate July notice (DA 26-742) covers nine other entities, including XAG.
A list without enforcement is a suggestion. This is the point at which the Covered List stopped being one.
Context worth holding alongside this
Uncrewed aircraft systems and their critical components were added December 22, 2025 (DA 25-1086). Blue UAS Cleared List and Buy American exemptions now run through January 1, 2028, and Department of War conditional approvals were made indefinite (DA 26-761, July 21).
The Cyber Trust Mark. The ioXt Alliance was named lead administrator on April 13, 2026 (DA 26-354). As of this writing there is no public evidence of approved label administrators or certified products. The consumer-facing half of this policy — the part that would let a buyer tell a trustworthy device from an untrustworthy one at the point of sale — is not yet operating.
What this adds up to
The direction of travel is consistent, and it is the right direction. Device categories, then the components inside them, then the provenance of those components, then the channel that already sold them — each step closes a gap the previous one left open.
But every one of these actions operates on transactions: authorization, import, marketing, sale. None of them operates on the device already installed and already trusted. That gap does not close by regulation, because regulation reaches the market and the installed base is no longer in the market.
That is the gap Faction was built for. A Faction Pod sits in front of equipment you already own and cannot replace — legacy controllers, IP cameras, building systems, clinical devices — and takes over authentication and encryption on that equipment's behalf. Nothing is installed on the device. Nothing about it changes. It joins a network that is invisible and unreachable from the internet, where access is granted by key possession rather than by a policy someone else administers. The untrustworthy router it sits behind stops being the thing that decides who can reach it.
Sources: FCC Covered List · Router FAQ · Robots and inverters FAQ · UAS FAQ
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.