
The Equipment Authorization Third Report and Order Is Now a Final Rule, Effective October 13, 2026
September 11, 2026
The Third Report and Order in ET Docket No. 21-232 published in the Federal Register on September 11, 2026, moving it from adopted-but-not-effective to binding law with a hard effective date of October 13, 2026. Component-level prohibitions, the closure of the permissive-change route, and online point-of-sale FCC ID display all arrive with it. In the same window: a consolidated Prohibited Entities List, series-level conditional approvals for ASUS and Comtrend, and an FCC citation against a Telecommunication Certification Body.
In focus: FR Doc. 2026-18535 / FCC 26-50 Third Report and Order (ET Docket No. 21-232) / DA 26-962 (ET Docket No. 24-136) / DA 26-957 / DA 26-970 (File No. EB-SED-26-00041408) / DARS class deviation 2026-O0025 Revision 3
1. The Third Report and Order reached the Federal Register — proposal becomes binding rule
On September 11, 2026 the FCC's Third Report and Order published in the Federal Register as FR Doc. 2026-18535, under ET Docket No. 21-232 and document number FCC 26-50. It is effective October 13, 2026.
This is the status change that matters most in this window. The order was adopted by the Commission on July 23, 2026, but for the five weeks that followed it never appeared in the Federal Register, so every prior issue of this briefing recorded it accurately as adopted but not yet in effect, with no effective date computable. That premise expired on September 11. The legal status has moved from adopted-and-pending to a final rule — published, dated, and binding on arrival. If your internal assessment still treats 21-232 as an open proceeding you are waiting on, that assessment is out of date.
Four substantive changes take effect:
- New 47 CFR § 2.903(b)(2). A device may not be authorized if it incorporates a logic-bearing hardware component produced by a Covered List entity, where the finished device would itself be barred had that entity produced it. The prohibition now reaches down into the bill of materials.
- Amended § 2.902. Defines logic-bearing hardware component, supplying the test the new prohibition runs on.
- New § 2.932(f). Permissive change procedures may not be used to modify equipment produced by a Covered List entity. Full certification is required instead — the route of carrying an existing authorization forward through incremental changes is closed for that equipment.
- Amended § 2.803(c). A valid, accurate FCC ID must be displayed at the online point of sale. Compliance dates are staged: March 1, 2027 for marketplaces that take title to or physical possession of the goods, and June 1, 2027 for third-party listings.
- Amended § 1.50001(f). Critical infrastructure is redefined by reference to the DHS 16 critical infrastructure sectors and the 55 National Critical Functions.
Read the limits as carefully as the prohibitions. The new bar is not retroactive — equipment already authorized is not invalidated by this rule. What closes on October 13 is the door to new authorizations and to modifications of covered equipment.
What it could mean for a Taiwanese ODM or OEM. The unit of exposure has dropped from the brand to the BOM line item. Screening the finished-product brand and your tier-one suppliers no longer discharges the obligation; Covered List screening has to extend to chips, modules, PCBs, controllers, and any other programmable part.
Three things should be finished before October 13, 2026. First, take every new authorization filing you expect to submit after the effective date and confirm, line by line, whether any logic-bearing component in it comes from a Covered List entity. Second, re-examine every model change you had planned to run through permissive change — if the underlying equipment is produced by a Covered List entity, that route no longer exists under § 2.932(f), and the work has to be rebudgeted and rescheduled as full certification. Third, if you sell into US online channels, put accurate FCC ID display at the point of sale into your channel agreements and listing checklists now; the 2027 dates are not urgent, but getting listing data correct across a marketplace estate is not a short project.
Primary sources:
- FR Doc. 2026-18535, Third Report and Order (September 11, 2026)
- FCC 26-50 original document
- FCC Covered List
2. A consolidated Prohibited Entities List — seven source lists in one place
On September 9, 2026 the FCC issued DA 26-962 (ET Docket No. 24-136), announcing that the Office of Engineering and Technology had published a consolidated Prohibited Entities List on September 2, 2026 at fcc.gov. Legal status: administrative guidance. The list creates no new obligation of its own; the obligations come from the rules and statutes it draws on.
It combines the seven source lists referenced in 47 CFR § 2.902 into a single searchable, filterable, CSV-downloadable interface:
- The FCC Covered List
- The BIS Entity List and Military End User List
- The DHS UFLPA Entity List
- NDAA FY2023 section 5949
- NDAA FY2021 section 1260H
- The Treasury NS-CMIC list
- Commerce foreign-adversary designations
The list exists because the Second Equipment Authorization Integrity Report and Order (ET Docket No. 24-136, May 15, 2026) directed it. That order, through 47 CFR § 2.949, requires laboratory accreditation bodies to certify that they are not owned or controlled by a prohibited entity and to document any equity or voting interest of 5% or more. The consolidated list gives that check one place to look.
Note what the FCC says about its own list. Users remain responsible for verifying accuracy, and the list omits affiliates and subsidiaries not yet captured by the source agencies.
What you can swap out is the tool, not the judgment. Maintaining seven separate lists on seven different update cadences was real overhead, and folding one CSV into your supplier master data is a genuine cost reduction worth scheduling into the next supplier review cycle.
Treating a clean result as a clean bill of health is the failure mode, and the last two issues of this briefing have already shown two ways it fails. Covered List exposure travels through technology licensing and co-development relationships — a named entity's "affiliates, subsidiaries, and other partners" can be reached without ever being listed themselves. And the FCC has proposed forfeitures against Covered List entities for incomplete affiliate disclosure, which confirms the agency cross-checks corporate group structure against public records rather than accepting self-declaration. The workable rule: a hit on the list is a red light; the absence of a hit is not a green light, and you still owe yourself a traced answer on ultimate control and on any 5%-or-greater interest.
Primary sources:
3. Conditional approvals granted at series level, with two Taiwan-linked brands on the list
On September 9, 2026 the FCC's Public Safety and Homeland Security Bureau released DA 26-957 (WC Docket No. 18-89 / ET Docket No. 21-232 / EA Docket No. 21-233), announcing DoW Conditional Approvals exempting equipment from the Covered List. Legal status: formal agency order — in effect on grant. The grants:
- ASUS Computer International — the RT Router Series, ROG GT, ROG Strix GS, TUF Gaming, ExpertWiFi, ZenWiFi Mesh and 5G MiFi series, plus repeaters and wireless access points, terminating March 6, 2028.
- Comtrend Corporation — the GRG-4366u, VG-8043u, PBL-6201 and NL-3131 wireless routers, terminating March 6, 2028.
- Husqvarna AB — the 305v, 310v, 420v and 440v IQ robotic platforms, with no termination date stated in the notice.
The same notice confirms two dates worth recording: advanced robotic devices were added to the Covered List on July 28, 2026 by DA 26-786, and routers on March 23, 2026 by DA 26-278.
The granularity is the story, not the names. Conditional approvals tracked in this series have mostly been model by model, with occasional class-level grants. The ASUS entry goes further still — it covers whole product series, and category language such as "repeaters and wireless access points." Comtrend, in the same notice, is enumerated model by model. Having both drafting styles side by side in one document is useful precedent for anyone preparing a filing.
If you have an application in preparation or under review, this is a reason to revisit the scope you requested. A series- or category-level request, if granted, removes the per-SKU filing burden and the timing gaps that come with it. It is not a guarantee — the agency still decides case by case — but the precedent exists, and requesting too narrow a scope is now a self-inflicted limit.
Two hard limits are unchanged by any of this. A conditional approval covers only what the notice text actually says — derivative or rebadged SKUs outside that language are not automatically inside it, and Comtrend's model-by-model list should be read literally. And a conditional approval does not substitute for ordinary FCC equipment authorization; it removes a Covered List prohibition, not a technical compliance requirement. Record the March 6, 2028 expiries in product lifecycle management and start renewal work months ahead of them.
Primary sources:
4. The FCC cited a certification body — the certification chain is itself an audit target
On September 11, 2026 the FCC's Enforcement Bureau issued DA 26-970 (File No. EB-SED-26-00041408), a Citation against Derycom Certification Services, Inc., a Telecommunication Certification Body, for false statements under 47 CFR § 1.17 and for acting beyond its authorized scope. Legal status: enforcement action, binding on the named party.
The findings are blunt. Derycom claimed an operating base in Glencoe, Minnesota, on the strength of a lease with International Certification Services. ICS's CEO declared under penalty of perjury that Derycom had never performed work at that location and had assigned no personnel to it. In fact five of six employees and all four contract technical reviewers are located in China, and the 99% owner is a Chinese citizen. The United States has no mutual recognition agreement with China, so a China-located TCB cannot be NIST-designated or FCC-recognized.
The scope violation is equally concrete. Derycom admitted certifying at least ten devices that required testing to 100, 200 and 220 GHz against an accredited scope that topped out at 40 GHz. The FCC IDs include 2AD56HLK-LD6002, 2AZGI-AF130, 2AMUU-MS605, 2AQ7Q-DB7U1R455, 2ATM77806, 2BS4BAW101ANRISLEEP, 2AF9HT70, 2ACN7TL615, 2BUM4-CQRSENWB01 and 2BTVF-BCN2.
The timeline: A2LA suspended accreditation in May 2026; NIST and the FCC suspended Derycom on May 19, 2026; and FCC recognition expired on June 30, 2026.
One detail here runs against intuition. Under 47 CFR § 2.960(i), certifications issued by a TCB remain valid unless specifically set aside or revoked by the Commission. Those ten FCC IDs did not lapse automatically as a result of this action.
Who this reaches. For Taiwanese device makers whose US market access runs through a TCB certification chain, this changes how that chain should be assessed. The certification body is itself now an audit target, and its actual place of operation, staff location, ownership structure and accredited frequency scope are all live questions — checked against third-party sworn statements.
Three concrete steps. First, pull every FCC certification your company has obtained in recent years and confirm the issuing body and its recognition status at the time; if Derycom appears, the certification may be legally valid but customer and channel due diligence will not stop at "legally valid," so assess recertification on its own merits. Second, compare the actual test frequency ceiling your products require against the accredited scope ceiling of the body that certified them — that gap is exactly the violation here, and it matters most for millimeter-wave, automotive radar and high-frequency communications products. Third, move TCB selection into your formal supplier vetting process rather than treating it as a procurement detail; the Second Equipment Authorization Integrity Report and Order already pushes accreditation bodies in the same direction.
Primary sources:
5. The CMMC Phase 2 suspension is now contracting-officer direction — the standard itself did not move
DARS class deviation 2026-O0025 Revision 3, signed and effective September 3, 2026, revises and supersedes Revision 2 of July 16, 2026, and applies under DFARS Part 240 / FAR Part 40. Legal status: administrative guidance — a class deviation is not a Federal Register rulemaking, and it creates no new CMMC policy.
What it does is translate the DoW CIO memorandum of July 13, 2026, "Suspension of the Advancement to CMMC Phase 2 Requirements," into direction a contracting officer can act on:
- Requiring activities may include CMMC Level 1 (Self) or Level 2 (Self) assessments.
- Baseline compliance with NIST SP 800-171 Rev 2 under DFARS 252.204-7012 is still required.
- The November 2026 CMMC Phase 2 transition is suspended.
- Contracting officers must amend active solicitations, and must remove these requirements from existing contracts by modification before the next option exercise or at the next scheduled administrative modification.
The same deviation separately implements four unrelated authorities: NDAA FY2025 section 853 (Huawei-linked semiconductor products), NDAA FY2024 section 803 and FY2025 section 836 (transfer of DoD employee PII), NDAA FY2023 section 817 and FY2020 section 848 (certain UAS and counter-UAS), and a July 5, 2026 order from the Northern District of California temporarily waiving 10 U.S.C. § 4663 treatment for Alibaba entities.
On the defense side, what changes is paperwork, not controls. For a Taiwanese manufacturer touching CUI through a prime's purchase orders, the practical value of Revision 3 is that it tells you what your counterparty is about to do: primes' contracting officers will issue modifications stripping third-party certification requirements out of live contracts, and those changes will travel down to you through flow-down provisions.
The right response is to check, not to celebrate. When a modification or a revised flow-down clause arrives, confirm three things line by line: that the NIST SP 800-171 Rev 2 baseline obligation is still there (under this deviation it should be), that self-assessment and attestation requirements are still there, and that what has been removed is limited to Phase 2 third-party certification. If a prime uses the modification to dilute the substance of 800-171, that is its own judgment call and not something this deviation authorizes — keep your controls and your evidence where they are.
And keep the risk shift this briefing has flagged before firmly in view: with third-party certification paused, self-assessment and self-attestation are the interim standard, and the False Claims Act exposure of getting an attestation wrong goes up accordingly. The thing to strengthen during this period is how quickly you can produce your evidence, not how lightly you implement.
Primary sources:
- DARS class deviation 2026-O0025 Revision 3, signed September 3, 2026 (superseding Revision 2 of July 16, 2026)
- DoW CIO memorandum, "Suspension of the Advancement to CMMC Phase 2 Requirements," July 13, 2026
6. Strategic action agenda
1. Finish BOM-level Covered List screening before October 13
- Do now: For every new authorization filing you expect to submit after the effective date, check each chip, module, PCB, controller and other programmable part in the bill of materials against the Covered List.
- Target: Screening moves from brand level to line-item level, with a component-provenance table producible on demand for every pending filing.
2. Re-assess every planned permissive change
- Do now: Inventory the model changes you intended to run through permissive change. Where the underlying equipment is produced by a Covered List entity, § 2.932(f) has closed that route — move the work to full certification and rebudget it.
- Target: No product launch date depends on a procedure that will not exist after October 13, 2026.
3. Fold the Prohibited Entities List into supplier master data — but do not stop there
- Do now: Import the CSV into your supplier screening process in place of seven separately maintained lists, and keep tracing ultimate control, technology licensing relationships and 5%-or-greater interests yourself.
- Target: A hit is a red light; the absence of a hit still leaves a documented trace of your own verification, never a green light on its own.
4. Audit the certification-body link in your chain
- Do now: Pull the issuing body and its recognition status for every FCC certification obtained in recent years, and compare your products' actual test frequency ceiling against that body's accredited scope.
- Target: TCB selection sits inside formal supplier vetting, and high-frequency and millimeter-wave products have a written confirmation behind their certification chain.
5. Redesign conditional-approval requests at series or category scope
- Do now: Use the DA 26-957 series-level drafting as a model when scoping requests, and record existing expiry dates such as March 6, 2028 in product lifecycle management.
- Target: No request is narrowed by your own drafting, and every purchase order maps to an approval that is both in term and textually covering.
The bottom line
The dividing line this window is clean: ET Docket No. 21-232 is no longer a proceeding you can wait on. After October 13, 2026, component-level prohibition and the closure of permissive change are current law, not proposals. The other four items each fill in a piece around it — the Prohibited Entities List lowers screening cost while stating plainly that it is incomplete, the series-level conditional approvals show how wide a request can reasonably be drafted, the TCB citation proves the certification chain itself gets audited, and the CMMC class deviation tells the defense supply chain exactly how the contract modifications will arrive. The common requirement has not changed: every representation you make should have evidence behind it that you can produce on the day you are asked.
About this briefing
Vantikon tracks US regulatory developments that reach Taiwanese manufacturers and their supply chains. If something here touches your product line and you want to talk it through, get in touch — we are glad to have the conversation.
This briefing is informational and does not constitute legal advice; consult qualified counsel for your specific situation.
