# Promoting the Integrity and Security of Telecommunications Certification Bodies, Measurement Facilities, and the Equipment Authorization Program

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/fr%3A2025-14970

## Record

- **Collection:** Federal Register
- **Document type:** Rule
- **Published:** August 7, 2025
- **Citation:** 90 FR 38045

## Text

FEDERAL COMMUNICATIONS COMMISSION
47 CFR Parts 2 and 15
[ET Docket No. 24-136; FCC 25-27; FR ID 305703]
Promoting the Integrity and Security of Telecommunications Certification Bodies, Measurement Facilities, and the Equipment Authorization Program

AGENCY:

Federal Communications Commission.

ACTION:

Final rule.

SUMMARY:

In this document, the Federal Communications Commission (Commission or FCC) requires all recognized telecommunication certification bodies (TCBs), test labs, and laboratory accreditation bodies to certify to the Commission that they are not owned by, controlled by, or subject to the direction of a prohibited entity and to report all equity or voting interests of 5% or greater by any entity. The FCC also amends it rules to state that it will not recognize—and will revoke any existing recognition of—any TCB, test lab, or laboratory accreditation body that fails to provide, or that provides a false or inaccurate, certification; or that fails to provide, or provides false or inaccurate, information regarding equity or voting interests of 5% or greater. The FCC prohibits recognition of any TCB, test lab, or laboratory accreditation body owned by, controlled by, or subject to the direction of a prohibited entity, and prohibits such TCBs, test labs, and laboratory accreditation bodies from participating in the Commission's equipment authorization program, not only with regard to the equipment certification process but also the Supplier's Declaration of Conformity (SDoC) process.

DATES:

Effective September 8, 2025, except for amendatory instructions 4, 8, 9, 10, 12, 15, 16, 18, 20, 22, 23, and 24 which are delayed indefinitely. The Federal Communications Commission will publish a document in the
Federal Register
announcing the effective date. The incorporation by reference of certain material listed in the rule is approved by the Director of the Federal Register as of September 8, 2025. The incorporation by reference of certain other material listed in the rule was approved by the Director of the Federal Register as of October 30, 2023.

FOR FURTHER INFORMATION CONTACT:

Jamie Coleman of the Office of Engineering and Technology, at
Jamie.Coleman@fcc.gov
or 202-418-2705.

SUPPLEMENTARY INFORMATION:

This is a summary of the Commission's Report and Order (
Report and Order
), in ET Docket No. 24-136, FCC 25-27, adopted on May 22, 2025, and released on May 27, 2025. The full text of this document is available for public inspection and can be downloaded at
https://docs.fcc.gov/public/attachments/FCC-25-27A1.pdf.
Alternative formats are available for people with disabilities (Braille, large print, electronic files, audio format) by sending an email to
fcc504@fcc.gov
or calling the Commission's Consumer and Governmental Affairs Bureau at (202) 418-0530 (voice), (202) 418-0432 (TTY).

Regulatory Flexibility Act.
The Regulatory Flexibility Act of 1980, as amended (RFA), requires that an agency prepare a regulatory flexibility analysis for notice-and-comment rulemaking, unless the agency certifies that “the rule will not, if promulgated, have a significant economic impact on a substantial number of small entities.” Accordingly, the Commission has prepared a Final Regulatory Flexibility Analysis (FRFA) concerning the possible impact of the rule and policy changes contained in the
Report and Order
on small entities. The FRFA is set

forth in Appendix C of the
Report and Order.

Paperwork Reduction Act.
This document contains proposed new or modified information collection requirements subject to the Paperwork Reduction Act of 1995 (PRA), Public Law 104-13. The Commission, as part of its continuing effort to reduce paperwork burdens, invites the general public and the Office of Management and Budget (OMB) to comment on any information collection requirements contained in this document. In addition, pursuant to the Small Business Paperwork Relief Act of 2002, Public Law 107-198, see 44 U.S.C. 3506(c)(4), we seek specific comment on how we might “further reduce the information collection burden for small business concerns with fewer than 25 employees.”

Congressional Review Act.
The Commission has determined, and the Administrator of the Office of Information and Regulatory Affairs, Office of Management and Budget, concurs, that this rule is “non-major” under the Congressional Review Act, 5 U.S.C. 804(2). The Commission will send a copy of this Report and Order and Further Notice of Proposed Rulemaking to Congress and the Government Accountability Office pursuant to 5 U.S.C. 801(a)(1)(A).

Synopsis

Introduction

The Commission adopts new rules to help ensure that the telecommunication certification bodies (TCBs), measurement facilities (test labs), and laboratory accreditation bodies that participate in the FCC's equipment authorization program are not subject to ownership, direction, or control by untrustworthy actors that pose a risk to national security. The Commission previously established new equipment authorization program rules that prohibit authorization of specified equipment determined to pose an unacceptable risk to the national security of the United States or the security and safety of United States persons. It is incumbent on TCBs and test labs, to which certain functions of the certification process—including the receipt and maintenance of sensitive and proprietary information regarding communications equipment—have been entrusted, to be vigilant and to promote the integrity of the FCC's authorization procedures to help protect our nation's supply chain against such unacceptable risk. In light of these responsibilities and ongoing security risks, the Commission strengthens its oversight of TCBs, test labs, and laboratory accreditation bodies by adopting new rules that will help ensure the integrity of these entities for purposes of the FCC's equipment authorization program, promote national security, and advance the Commission's comprehensive strategy to build a more secure and resilient communications supply chain. The Commission finds that it is critical for national security and the integrity of the supply chain that it prohibit from recognition or participation in the equipment authorization program TCBs, test labs, and laboratory accreditation bodies that are owned by, controlled by, or subject to the direction of a prohibited entity.

In defining the scope of the term “prohibited entity,” the Commission relies on federal government agency determinations identifying entities that pose national security threats. For purposes of the
Order,
the term “prohibited entity” means any of the following:

• Entities identified on the FCC's Covered List;

• Entities identified by any of the following sources:

• Department of Commerce Bureau of Industry and Security (BIS) Entity List;

• BIS Military End-User List;

• Department of Homeland Security (DHS) Uyghur Forced Labor Prevention Act (UFLPA) Entity List;

• Section 5949 of the James M. Inhofe National Defense Authorization Act (NDAA) for Fiscal Year 2023 (Section 5949 List of Semiconductor Companies);

• Department of Defense (DOD) 1260H list of Chinese Military Companies (1260H List);

• Department of Treasury NS-CMIC List of Chinese military companies (NS-CMIC List); and

• Entities identified as “foreign adversaries” by the Department of Commerce.

The Commission will deem a TCB, test lab, or laboratory accreditation body as “owned by” a prohibited entity when any such prohibited entity, has, possesses, or otherwise controls an equity or voting interest of 10% or more in the relevant TCB, test lab, or laboratory accreditation body. The Commission also provides further clarity on what it means for a TCB, test lab, or laboratory accreditation body to be controlled by or subject to the direction of a prohibited entity.

To help ensure that the Commission has the necessary information to enforce this prohibition, the FCC expands its current reporting and certification requirements. The Commission adopts a requirement for all recognized TCBs, test labs, and laboratory accreditation bodies to certify to the FCC, within 30 days after the effective date of the rules, and thereafter with the request for recognition, that they are not owned by, controlled by, or subject to the direction of a prohibited entity. The Commission also adopts a requirement for all recognized TCBs, test labs, and laboratory accreditation bodies to report, within 90 days after the effective date of the rules, and thereafter with the request for recognition, all equity or voting interests of 5% or greater by any entity. The Commission also amends its rules to state that it will not recognize—and will revoke any existing recognition of—any TCB, test lab, or laboratory accreditation body that fails to provide, or that provides a false or inaccurate, certification; or that fails to provide, or provides false or inaccurate, information regarding equity or voting interests of 5% or greater.

In keeping with the new reporting requirements, the Commission also clarifies the requirement that every entity specifically named on the Covered List must provide to the Commission, pursuant to § 2.903(b), information regarding all of its subsidiaries and affiliates, not merely those that produce “covered” equipment. Each relevant entity must provide this information no later than 30 days after the effective date of this rule and thereafter in accordance with the provisions of § 2.903(b). The Commission makes a minor rule change clarifying its process for withdrawing recognition from test labs and laboratory accreditation bodies. The Commission also adopts several additional rules to strengthen the integrity of TCBs and test labs associated with its equipment authorization program.

Background

In the
EA Integrity NPRM,
the Commission sought to strengthen its requirements for and oversight of FCC-recognized TCBs and test labs by proposing new rules that would help ensure the integrity of these entities for purposes of the equipment authorization program, better protect national security, and advance the Commission's comprehensive strategy to build a more secure and resilient supply chain. As the Commission stated, it is vital to ensure that these TCBs and test labs are not subject to control by foreign adversaries or other untrustworthy actors that pose a risk to national security.

The Equipment Authorization Program

The Commission's equipment authorization program, codified in its part 2 rules, plays a critical role in enabling the Commission to carry out its responsibilities under the Communications Act of 1934, as amended (the Act). Under section 302 of the Act, the Commission is authorized to make reasonable regulations governing the interference potential of equipment that emits radiofrequency (RF) energy and that can cause harmful interference to radio communications; such regulations are implemented through the equipment authorization program. In addition, the equipment authorization program helps ensure that communications equipment complies with certain other policy objectives—which include protecting the communications networks and supply chain from equipment that poses an unacceptable risk to national security.

Under section 302a(e) of the Act, certain important responsibilities have been delegated to TCBs and test labs with regard to implementing its equipment authorization program. Specifically, TCBs and test labs each play a role in ensuring that RF equipment complies with Commission rules, which is required for such equipment to be marketed in or imported to the United States. Test labs gather radiofrequency measurement data and develop technical reports to demonstrate subject equipment compliance with the Commission's applicable technical rules to minimize the risk of harmful interference, promote efficient use of spectrum, and advance other technical policy goals, such as ensuring hearing aid compatibility and controlling the environmental effects of RF radiation.

TCBs perform evaluation and review of application data, including test reports, and make decisional determinations for certifications. For all granted certification applications, the TCBs must send to the Commission any test lab data and other information relied upon by the TCB. This information is made publicly available on the FCC's website upon grant of the equipment authorization. Commission rules also impose certain obligations on each TCB to perform post-market surveillance, based on “type testing a certain number of samples of the total number of product types” that the TCB has certified. Accreditation bodies conduct assessments to ensure that TCBs and test labs are competent and capable of providing accurate and reliable certification and testing services.

To be recognized for participation in the FCC's equipment certification process, TCBs, test labs, and laboratory accreditation bodies must meet certain criteria specified in its rules. TCBs must be designated to issue grants of certification and must be located in the United States or in countries that have entered into applicable mutual recognition agreements (MRAs) with the United States. Currently, there are 39 FCC-recognized TCBs, 23 of which are located in the United States while the remaining 16 are located in seven MRA-partnered countries. The Commission will withdraw recognition of a TCB if the TCB's designation or accreditation is withdrawn, if the Commission determines that there is “just cause,” or if the TCB requests that it no longer hold its designation or recognition. The Commission's rules also set forth specific procedures, including notification requirements, that the Commission will follow if the Commission intends to withdraw its recognition of a TCB.

Test lab recognition occurs based on current Commission rules stating that if a test lab has been accredited for the appropriate scope for the types of equipment that it will test, then it “shall be deemed competent to test and submit test data for equipment subject to certification.” Based on such accreditation, the Commission—namely, the Chief Engineer, to whom recognition authority has been delegated—makes determinations regarding the continued acceptability of individual test labs. Test labs must be reassessed for accreditation and recognition at least every two years. Approximately 75% of certified devices are tested in recognized labs located in China.

The Commission recognizes four laboratory accreditation bodies in the U.S. that can accredit test labs in the United States. For test labs in countries with which the U.S. has entered into an MRA, the Commission will consider for recognition an accredited laboratory that has been designated by a foreign designating authority. Currently there are 24 such FCC-recognized laboratory accreditation bodies outside the United States, located in 23 different MRA-partnered countries. All other test labs must be accredited by an organization recognized by the Commission to perform test lab accreditations in non-MRA countries. Currently, the Commission recognizes three such accrediting bodies. Current rules do not preclude a laboratory accreditation body that is not in an MRA-partnered country from submitting a request to be recognized, but, to date, the FCC has not recognized any laboratory accreditation body outside of an MRA-partnered country.

Recent Related Commission Action

The EA Security R&O and FNPRM.
On November 11, 2022, the Commission adopted the
EA Security Report and Order, Order, and Further Notice of Proposed Rulemaking
(88 FR 7592; February 6, 2023). Specifically, the Commission established several new rules to prohibit authorization of equipment identified on the Commission's Covered List (covered equipment) maintained pursuant to the Secure and Trusted Communications Networks Act of 2019 (Secure Networks Act). The Covered List identifies certain types of communications equipment produced by particular entities as well as information security products and certain services provided by various entities. This list is derived from specific determinations made by sources enumerated in the Secure Networks Act, including certain federal agencies and Congress, that certain equipment or services pose an unacceptable risk to national security. The
EA Security R&O
adopted several revisions to part 2 of the Commission's rules concerning equipment authorization requirements and processes. These revisions include requirements that, to help implement the prohibition on authorization of any covered equipment, applicants seeking equipment certification must make certain attestations about the relevant equipment. These include attesting that the equipment is not prohibited from receiving authorization and whether the applicant is an entity identified on the Covered List as an entity producing covered communications equipment. TCBs, pursuant to their responsibilities as part of the Commission's equipment authorization program, review the applications and must ensure that only applications that meet all of the Commission's applicable technical and non-technical requirements are ultimately granted, and that none of these grants are for covered equipment.

In the
EA Security R&O,
the Commission, in affirming its authority to prohibit authorization of communications equipment that had been placed on the Covered List, noted that it has broad statutory authority, under sections 302 and 303(e) of the Communications Act and other statutory provisions, to take into account national security concerns when promoting the public interest, including in its equipment authorization program.

Evolving Risks Order and NPRM
(88 FR 50486; August 1, 2023). Since adopting the
EA Security R&O,
the

Commission has taken several additional steps to address evolving national security concerns to protect the security of America's critical communications networks and supply chains. In April 2023, in the
Evolving Risks Order and NPRM,
the Commission required all international section 214 authorization holders to respond to a one-time information collection to update the Commission's records regarding their foreign ownership, noting that “the information will assist the Commission in developing a timely and effective process for prioritizing the review of international section 214 authorizations that are most likely to raise national security, law enforcement, foreign policy, and/or trade policy concerns.” The Commission also sought comment on further actions it could take to protect the nation's telecommunications infrastructure from threats in an evolving national security and law enforcement landscape by proposing comprehensive changes to the Commission's rules that allow carriers to provide international telecommunications service. The Commission proposed, among other things, to adopt a renewal framework or, in the alternative, a formalized periodic review process for all international section 214 authorization holders. The Commission stated that, due to the evolving national security and law enforcement concerns identified in its recent proceedings to revoke the section 214 authorizations of certain providers controlled by the Chinese government, a formalized system of periodically reassessing international section 214 authorizations would better ensure that international section 214 authorizations, once granted, continue to serve the public interest.

In addition, in the
Evolving Risks NPRM,
the Commission proposed, among other things, to prioritize the renewal applications or any periodic review filings and deadlines based on, for example, “reportable foreign ownership, including any reportable foreign interest holder that is a citizen of a foreign adversary country,” as defined in the Department of Commerce's rule, 15 CFR 791.4. The Commission also sought comment on whether to revise its ownership reporting threshold, currently set at 10% or greater direct and indirect equity and/or voting interests, to 5%, noting that the current 10% threshold may not capture all of the foreign interests that may present national security, law enforcement, foreign policy, and/or trade policy concerns in today's national security and law enforcement environment. The Commission also proposed, among other things, to require applicants to certify in their application whether they use equipment or services identified on the Commission's Covered List.

Cybersecurity IoT Labeling R&O
(89 FR 61242; July 30, 2024). On March 14, 2024, the Commission adopted the
Cybersecurity IoT Labeling R&O
to strengthen the nation's cybersecurity protections by adopting a voluntary cybersecurity labeling program for wireless Internet of Things (IoT) products. In that R&O, the Commission determined that entities that are owned by, controlled by, or affiliated with “foreign adversaries,” as defined by the Department of Commerce, should be ineligible for purposes of the Commission's voluntary IoT Labeling Program. The Commission also generally prohibited entities that produce equipment on the Covered List, as well as entities named on the DOD's list of Chinese military companies or the Department of Commerce's Entity List, and entities suspended or debarred from receiving federal procurements or financial awards, including all entities and individuals published as ineligible for award on the General Service Administration's System for Award Management, from any participation in the IoT Labeling Program. Also, the Commission specifically prohibited any of these entities from serving as a Cybersecurity Label Administrator or serving as a CyberLAB for testing products for compliance with forthcoming cybersecurity technical standards. The Commission concluded that these lists represent the determination of relevant federal agencies that entities on these lists may pose a national security threat within their respective areas, and that it is not in the public interest to permit these entities to provide assurance to the public that their IoT products meet the new cybersecurity standards for obtaining the U.S. Cyber Trust Mark.

In the
Submarine Cable Landing License NPRM
(90 FR 12036; March 13, 2025), the Commission opened a proceeding to improve and streamline the submarine landing license rules, seeking comment on how to facilitate efficient deployment of submarine cables while ensuring the security, resilience, and protection of this critical infrastructure. It noted that, of the 84 licensed cables that currently are operating or planned to enter service, three land in a “foreign adversary” country as defined by the U.S. Department of Commerce rules and, according to the Commission's records, nine licensees of submarine cables have direct or indirect interest holders that include the Chinese government or an entity with a place of organization in China.

The Commission, among other things, sought comment on whether to preclude the grant of a cable landing license application filed by any applicant that: (1) is directly and/or indirectly owned or controlled by, or subject to the influence of a government organization of a foreign adversary country, as defined under 15 CFR 791.4; (2) is directly and/or indirectly owned or controlled by, or subject to the influence of an individual or entity that has a citizenship(s) or place(s) of organization in a foreign adversary country; (3) is directly and/or indirectly owned or controlled by, or subject to the influence of an individual or entity on the Commission's Covered List; and/or (4) is using or will use equipment or services identified on the Commission's Covered List in the proposed submarine cable infrastructure.

The Commission also proposed, among other things, to prioritize the filing and review of periodic ownership reports and related submarine cable system information for submarine cable systems that: (1) have a licensee that is directly or indirectly wholly or partially owned by a government of, or other entities with a place of organization in, a “foreign adversary” country, as defined in the Department of Commerce's rule, 15 CFR 791.4; (2) have a licensee with a place of organization in a “foreign adversary” country; or (3) land in a “foreign adversary” country.

The Commission also sought comment on whether it should prohibit cable landing licensees from entering into arrangements for Indefeasible Rights of Use or leases for capacity on submarine cables landing in the United States, with any entity that has a citizenship(s) or place(s) of organization in a “foreign adversary” country, as defined under 15 CFR 791.4. It sought comment on whether it should prohibit cable landing licensees from entering into such arrangements with any entity that is directly and/or indirectly owned or controlled by, or subject to the influence of, (1) a government organization of a foreign adversary country, and/or (2) any individual or entity that has a citizenship(s) or place(s) of organization in a “foreign adversary” country, as defined under 15 CFR 791.4. Additionally, it sought comment on whether to adopt rules that prohibit cable landing licensees from landing a cable licensed by the Commission in certain locations, such as landing points in a “foreign

adversary” country, as defined under 15 CFR 791.4.

The EA Integrity NPRM

On May 23, 2024, the Commission adopted the
EA Integrity NPRM
(89 FR 55530; July 5, 2024), in which it proposed measures to strengthen the requirements for and oversight of TCBs and test labs to help ensure the integrity of these entities for purposes of the equipment authorization program, better protect national security, and help build a more secure and resilient communications supply chain. The Commission explained that, in light of the new national security-related responsibilities on TCBs and test labs, and their ongoing responsibilities to receive and maintain sensitive and proprietary information regarding communications equipment, among other reasons, it is vital to ensure that TCBs and test labs are not subject to influence or control by untrustworthy actors that pose a risk to national security.

First, the Commission proposed to prohibit any TCB or test lab in which an entity identified on the Covered List has, possesses, or otherwise controls an equity or voting interest of 10% or more from being recognized by the FCC or participating in the FCC's equipment authorization program. Second, the Commission proposed prohibiting the use of, or reliance on, any TCB or test lab for equipment authorization if any entity listed on the Covered List holds, possesses, or otherwise controls an equity or voting interest of 10% or more. Third, the Commission sought comment on prohibiting recognition of any TCB or test lab owned or controlled by a foreign adversary or any other entity that has been found to pose a risk to national security. To that end, the Commission sought comment on whether and how the FCC should consider national security determinations made in other federal agency lists in establishing eligibility qualifications for Commission recognition of a TCB or a test lab in the equipment authorization program. Fourth, to help ensure that the Commission has the information required to enforce any requirements adopted in the proceeding, the FCC proposed new certification, recordkeeping, and reporting obligations for TCBs and test labs, including requiring TCBs and test labs to certify that no entity identified on the Covered List has, possesses, or otherwise controls an equity or voting interest of 10% or more in the TCB or test lab, and to produce documentation identifying any entity that has, possesses, or otherwise controls an equity or voting interest of 5% or more in the TCB or test lab. The Commission also sought comment on other revisions or clarifications to its rules to implement this requirement. Finally, the Commission sought comment on various related matters regarding implementation of the proposed prohibition and the equipment authorization program generally. Namely, the Commission sought comment regarding whether to revise its rules, policies, or guidance regarding post-market surveillance, accreditation and reassessment of TCBs, recognition and withdrawal of recognition of TCBs, transparency for test labs, accreditation of test labs, recognition and withdrawal of recognition of test labs, and whether to require the use of accredited, FCC-recognized test labs in the SDoC process. In particular, in light of the goals of the proceeding, the Commission sought comment on potential revisions to the rules governing TCB and laboratory accrediting bodies.

In response to the NPRM, the Commission received 10 comments and two reply comments. Some commenters generally supported the goal of the Commission to ensure the integrity of entities that participate in its equipment authorization program and found the Commission's proposals to be reasonable and important to promoting national security, while others generally supported the Commission's goals but expressed concerns with certain aspects of its proposals or contended that no changes to the equipment authorization program are needed. Some advised that any action the Commission takes should be designed so as not to cause disruption or delay in the equipment authorization process and to the FCC's supply chains, and suggest alternative actions the Commission could take that those commenters believe would be less disruptive.

Report and Order

In the
Report and Order,
the Commission adopts revisions to its rules designed to promote the integrity of the FCC's equipment authorization program and ensure that it serves the Commission's goal of protecting its communications equipment supply chain from entities posing unacceptable risks to national security. The Commission recognizes that the benefits of protecting U.S. national security, law enforcement, foreign policy, and trade policy interests are difficult to quantify in monetary terms. The difficulty in quantifying these benefits does not, however, diminish their importance. The Commission previously has found that “a foreign adversary's access to American communications networks could result in hostile actions to disrupt and surveil its communications networks, impacting the nation's economy generally and online commerce specifically, and result in the breach of confidential data.” Given that the national gross domestic product was over $29 trillion in 2024, the digital economy accounted for approximately 16% of its economy, and the volume of international trade for the United States (exports and imports) was $7.3 trillion in 2024, even a temporary disruption in communications could cause millions of dollars in economic losses. The harms by foreign adversaries or other untrustworthy actors thus could be significant, causing disruption to the U.S. economy, residential and government communications, and critical infrastructure.

Through the Commission's equipment authorization process, third party entities are tasked with various responsibilities to ensure that RF devices comply with FCC rules. Specifically, equipment for which an authorization is sought is provided to a test lab to gather radiofrequency measurement data and develop technical reports to demonstrate device compliance with the Commission's applicable rules. For devices for which equipment certification is sought (as opposed to SDoC), TCBs perform evaluation and review of those test reports along with other application data, and make decisional determinations for certifications. The Commission has a process, known as “recognition,” for ensuring that accredited TCBs and test labs, and the laboratory accreditation bodies, meet the necessary qualifications for participation in the FCC's equipment authorization program.

The Commission finds that excluding from participation in its equipment authorization program entities that threaten to undermine national security is necessary to effectively promote the integrity of the FCC's equipment authorization program and to protect national security interests. To implement this finding, the Commission takes several actions to ensure the integrity of those entities the FCC recognizes for participation in its equipment authorization program or upon which entities seeking authorization may rely. First, the Commission identifies, pursuant to federal agency or congressional determinations, a class of “prohibited entities” that pose national security threats and therefore could adversely affect the trustworthiness of, or

otherwise undermine the public's confidence in, a TCB, test lab, or laboratory accreditation body that is owned by, controlled by, or subject to the direction of a prohibited entity. Second, the Commission prohibits from participation in its equipment authorization process, any TCB, test lab, or laboratory accreditation body that is owned by, controlled by, or subject to the direction of a prohibited entity. This includes a prohibition on the reliance on or use of, for purposes of equipment authorization, any such TCB or test lab, for both certification and supplier's declaration of conformity (SDoC). Third, the Commission explains that it will consider a TCB, test lab, or laboratory accreditation body as “owned by” a prohibited entity when a prohibited entity has, possesses, or otherwise controls an equity or voting interest of 10% or more in the TCB, test lab, or laboratory accreditation body. The Commission also provides clarification on what it means for a TCB, test lab, or laboratory accreditation body to be controlled by, or subject to the direction of, a prohibited entity. Fourth, the Commission adopts expanded reporting requirements to require that all TCBs, test labs, and laboratory accreditation bodies seeking Commission recognition certifies to the Commission that they are not owned by, controlled by, or subject to the direction of a prohibited entity and report all equity or voting interests of 5% or greater by any entity. The Commission will not recognize, and will revoke recognition of, any TCB, test lab, or laboratory accreditation body that fails to provide or provides false or inaccurate information or certification. Finally, the Commission adopts a minor rule change clarifying its process for withdrawing recognition from test labs and laboratory accreditation bodies, and the Commission adopts other revisions to its rules including related recordkeeping and reporting obligations associated with the FCC's equipment authorization program and non-substantive changes to remove repetition of requirements.

Identifying “Prohibited Entities”

In the
EA Integrity NPRM,
the Commission proposed to not recognize or permit reliance on TCBs, test labs, or their accrediting bodies, or permit them to have any role in the FCC's equipment authorization program, if they have sufficiently close ties with Covered List entities. The Commission also sought comment on whether, and to what extent, the Commission should apply its measures to other entities identified by federal agencies or Congress that reflect expert determinations about entities that pose national security concerns. Specifically, the Commission sought comment on extending the proposed prohibition to the entities identified pursuant to the following:

• Department of Commerce list of “foreign adversary” countries that identifies any foreign government or foreign non-government person that the Secretary of Commerce has determined to have engaged in a “long-term pattern or serious instances of conduct significantly adverse to the national security interest of the United States or security and safety of United States persons;”

• DOD 1260H list of Chinese Military Companies;

• Department of Commerce Entity List;

• Department of Commerce Military End-User List;

• Non-Specially Designated Nationals Chinese Military-Industrial Complex Companies List;

• FY2023 NDAA section 5949 list of semiconductor companies;

• Foreign entities of concern as defined by the CHIPS Act; and

• Uyghur Forced Labor Prevention Act Entity List.

The Commission concludes that the integrity of its equipment authorization program is more effectively ensured not only through the exclusion of participation by entities identified on the Covered List, but also the other entities as described herein that federal government agencies or Congress have determined pose national security risks. Collectively, the Commission will refer to these as “prohibited entities” with regard to participation in the Commission's equipment authorization program.

Entities Identified on the Covered List

The Covered List is derived from specific determinations made by certain sources (particular federal agencies with national security expertise and Congress) designated by the Secure Networks Act that certain equipment or services produced or provided by a specified entity poses an unacceptable risk to national security. In light of these determinations from expert federal agencies and Congress about the serious national security risks posed by equipment or services produced or provided by entities identified on the Covered List, the Commission concludes that it should not permit TCBs, test labs, or laboratory accreditation bodies to have any role in its equipment authorization program, if they have sufficiently close ties with entities identified on the Covered List. This exclusion will help to promote the integrity of the equipment authorization program and protect the equipment supply chain from pre-authorization exposure to entities that present national security concerns.

Other Entities That Raise National Security Concerns

The Covered List is only one source that identifies entities presenting national security concerns that have potential to compromise the integrity of the equipment authorization program. Several federal agencies with particular national security responsibilities—including two agencies that also serve as sources of determinations for the Covered List—develop or maintain lists that identify entities, companies, persons, and other parties that they have determined raise national security concerns. Congress has done similarly in legislation. The Commission finds that to help ensure the integrity of entities that play a role in its equipment authorization program, to promote national security, and to advance the Commission's comprehensive strategy to build a more secure and resilient communications supply chain, the Commission should not limit its definition of “prohibited entities” to entities identified on the Covered List, but also address entities that federal agencies have determined raise similar national security concerns.

The Commission's conclusion to include entities identified by federal agencies as posing unacceptable risks to national security in addition to those on the Covered List is supported by the Heritage Foundation and the Foundation for Defense of Democracies (FDD) (two Washington, DC think tanks with national security expertise). Heritage stated that “it would be prudent for the Commission to consult other agencies that maintain lists of known entities that present national security risks to the U.S.” In fact, Heritage encouraged the Commission to go even further and consider extending the prohibition to any foreign adversary-linked entity. FDD similarly encouraged the Commission to extend its prohibition to “entities not only listed on the FCC's Covered List, but also those subject to the jurisdiction, direction, or control of a foreign adversary, consistent with federal definitions under the Committee on Foreign Investment in the United States.” According to FDD, “[g]iven the PRC's current regulatory environment, including national security laws that coerce corporate cooperation with state intelligence objectives, firms operating under PRC jurisdiction cannot credibly demonstrate operational independence

from the Chinese government. This presents a material compliance and reputational risk to U.S. markets. Therefore, all PRC-based or PRC-controlled entities must be assumed to be under state influence.” Additionally, DOJ strongly supports “the FCC considering eligibility restrictions based on determinations made by Executive Branch agencies regarding entities that pose national security risks. This whole-of-government approach leverages specialized expertise across the federal enterprise to identify and mitigate evolving threats. For example, it is essential that the FCC utilizes other lists developed by Executive Branch agencies that reflect expert determinations about entities that pose national security concerns, rather than relying solely on the FCC's Covered List.” The Commission seeks comment on a similar proposal in the
Further Notice of Proposed Rulemaking
(FNPRM) portion of the proceeding, relying instead on the Department of Commerce's definition of foreign adversary.

Conversely, the China-based Telecommunication Terminal Industry Forum Association (TAF) argued that the Commission's current regulations in this area are “sufficiently strict,” and that the Commission should not rely on lists from other U.S. government agencies, and instead, use these lists “as background references for the FCC when considering the covered list.” The Commission disagrees and finds unpersuasive TAF's argument that these other federal agency lists “are established for different regulatory purposes.” The Commission also rejects TAF's argument that referencing other lists and determinations would “contravene the spirit of the [World Trade Organization Agreement on Technical Barriers to Trade]” and “increase the costs for telecommunications equipment manufacturers, ultimately driving up the final prices of electronic consumer products in the U.S.” The Commission finds that prohibiting entities that have been determined to pose risks to U.S. national security is not an unnecessary or arbitrary barrier to trade, but instead serves to promote public confidence in the integrity of the FCC's equipment authorization process and helps protect U.S. communications networks by addressing these national security concerns. The Commission also finds that any potential increased costs are outweighed by the substantial benefit to enhancing national security.

Each of the entities on the lists that the Commission discusses in the
Order
has been determined by either Congress or a federal agency to raise national security concerns and has been blocked from accessing certain aspects of the U.S. supply chain, thereby addressing concerns similar to those that the FCC seeks to address today to protect the integrity of its equipment authorization program. Moreover, many of the same agencies that Congress directed to serve as sources of determinations for inclusion on the Covered List are the sources of determination for entities on these other lists. The Commission finds that permitting such entities to participate in its equipment authorization program as TCBs, test labs, or laboratory accreditation bodies would adversely affect the trustworthiness of, or otherwise undermine the public's confidence in, the equipment authorization program, and would be inconsistent with U.S. national security interests.

For these and the other reasons discussed in the
Order,
the Commission finds that, in addition to the entities identified on the Covered List, it is incumbent upon us to also address, with regard to the equipment authorization program, other entities deemed by federal agencies to pose risks to national security as follows:

• Entities identified by any of the following sources:

• Department of Commerce Bureau of Industry and Security (BIS) Entity List (BIS Entity List);

• BIS Military End-User List;

• Department of Homeland Security (DHS) Uyghur Forced Labor Prevention Act (UFLPA) Entity List;

• Section 5949 of the James M. Inhofe National Defense Authorization Act (NDAA) for Fiscal Year 2023 (Section 5949 List of Semiconductor Companies);

• Department of Defense (DOD) 1260H list of Chinese Military Companies;

• Department of Treasury NS-CMIC List of Chinese military companies; and

• Entities identified as “foreign adversaries” by the Department of Commerce, including governments.

Department of Commerce BIS Entity List.
“The [BIS] Entity List . . . identifies persons or addresses of persons reasonably believed to be involved, or to pose a significant risk of being or becoming involved, in activities contrary to the national security or foreign policy interests of the United States” as determined by an End-User Review Committee consisting of various federal national security agencies. The BIS Entity List in part seeks to ensure that sensitive technologies do not fall into the hands of known threats. The Commission concludes that these entities, which federal agencies found to, at the very least, “pose a significant risk” of activities threatening American national security or foreign policy interests, present the same concerns with regard to the integrity of the equipment authorization program. Seeing as U.S. persons are generally prohibited from providing unlicensed exports, re-exports, or transfers (in-country) of certain commodities, software, and technology subject to BIS jurisdiction to entities on the BIS Entity List, the Commission finds it particularly risky for such entities to be closely associated with the review and approval of communications devices (with all the components therein) for the U.S. market—if these entities should not be allowed access to sensitive technologies after they are on the market, they similarly should not be allowed access before they are on the market through the equipment authorization program. This conclusion is consistent with the Commission's action in the
Cybersecurity IoT Labeling R&O
(89 FR 61242; July, 30, 2024), which prohibited entities named on the BIS Entity List from having their products receive a U.S. Cyber Trust Mark label or from serving as Cybersecurity Label Administrator or other lab participating in the labelling program.

Commerce Department BIS Military End-User List.
The Military End-User List consists of entities subject to heightened export controls because the End-User Review Committee determined that “exports, reexports, or transfers . . . to that entity represent an unacceptable risk of use in or diversion to a `military end use' in Belarus, Burma, Cambodia, China, Nicaragua, the Russian Federation, or Venezuela, or for a Belarusian, Burmese, Cambodian, Chinese, Nicaraguan, Russian, or Venezuelan `military end user,' wherever located.” The Commission finds that the national security risks presented by these foreign military-associated entities in terms of export activities are applicable to the FCC's obligation to ensure the integrity of its equipment authorization program, which is an integral step in the importation and marketing of devices in the U.S.

DHS Uyghur Forced Labor Prevention Act Entity List.
Section 2 of the UFLPA requires reporting a list of entities found to be involved in forced labor in the Xinjiang region of China, which the Department of Homeland Security posts on its website. The Commission received no comments on this specific list, but Heritage did urge the

Commission to consider forced labor practices in China and noted that broadening the sources used to make determinations about recognition of test labs might remove from recognition consideration labs using forced labor or committing other human rights abuses. Federal agencies have found the entities listed on the UFLPA Entity List to be involved in forced labor, and goods that are manufactured wholly or in part by such entities are prohibited from U.S. importation. Because goods manufactured by these entities are prohibited from U.S. importation, the Commission finds that it would not be in the public interest or consistent with the integrity and security of the equipment authorization testing program for these entities to play a role in the equipment authorization program, particularly in such a way that contributes to ensuring compliance to the FCC's rules of equipment that must be authorized to be imported.

Section 5949 List of Semiconductor Companies.
Section 5949 of the James M. Inhofe National Defense Authorization Act (NDAA) for Fiscal Year 2023 prohibits Executive Branch agencies from procuring, obtaining, or contracting with entities to obtain any electronic parts, products, or services that include a semiconductor, a semiconductor product, or a product that incorporates semiconductor products designed or produced by Semiconductor Manufacturing International Corporation, ChangXin Memory Technologies, Yangtze Memory Technologies Corp, or any subsidiary, affiliate, or successor of such entities; or any such product produced by an entity determined by designated sources. The FCC finds that Congress's determination that these entities were not to be trusted to provide semiconductor products and services to “Federal systems” and were a threat in the “supply chains of Federal contractors and subcontractors” is strong evidence that the Commission should address the threat such entities present to ensuring the integrity and security of the equipment authorization program.

DOD 1260H List of Chinese Military Companies.
Under section 1260H of the FY 2021 NDAA, the Secretary of Defense is required to publicly list entities that the Secretary has determined to be a “Chinese military company” that is “operating directly or indirectly in the United States” and is “engaged in providing commercial services, manufacturing, producing, or exporting.” Effective June 30, 2026, DOD is prohibited from entering into, renewing, or extending contracts for goods, services, or technology with entities on the 1260H List or their affiliates. Contracts with companies controlled by these listed entities are also prohibited. Further, in 2027, DOD is prohibited from entering into, renewing, or extending a contract for the procurement of goods or services that include goods or services produced or developed by an entity, or controlled by an entity, on the Section 1260H List. The prohibitions do not extend to existing contracts or to contracts for goods, services, or technology that provide a service that connects to the facilities of a third party, including backhaul, roaming, or interconnection arrangements. The Secretary of Defense may waive the prohibition under certain circumstances.

The FCC concludes that, for the same reasons that these entities are identified on the 1260 List, such companies present an unacceptable risk to ensuring the integrity and security of the equipment authorization testing program. This is consistent with the Commission's action in the
Cybersecurity IoT Labeling R&O,
which prohibited entities named on the DOD 1260H List from having their products receive a U.S. Cyber Trust Mark label or from serving as Cybersecurity Label Administrator or other lab participating in the labelling program.

Department of Treasury NS-CMIC List of Chinese Military Companies.
The NS-CMIC List, maintained by the Department of Treasury, consists of persons found to “operate or have operated in the defense and related materiel sector or the surveillance technology sector of the economy of the PRC” and was created as part of an Executive Order to address “the threat posed by the military-industrial complex of the People's Republic of China (PRC) and its involvement in military, intelligence, and security research and development programs, and weapons and related equipment production under the PRC's Military-Civil Fusion strategy.” This list is almost identical to the 1260H List. The FCC concludes that the threat presented by such entities as determined by federal agencies would apply in terms of its efforts to ensuring the integrity and security of the equipment authorization program.

Foreign Adversary Governments and Persons.
The Department of Commerce has developed a list of “foreign adversary” governments and persons, which includes “any foreign government or foreign non-government person determined by the Secretary [of Commerce] to have engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons.” Currently, the list of foreign adversaries consists of the People's Republic of China (including the Hong Kong Special Administrative Region and the Macau Special Administrative Region), Republic of Cuba, Islamic Republic of Iran, Democratic People's Republic of North Korea, Russian Federation, and the Venezuelan politician Nicolas Maduro.

The rules establishing the process for these determinations were made pursuant to Executive Order 13873 of May 15, 2019, “Securing the Information and Communications Technology and Services Supply Chain.” President Trump issued Executive Order 13873 in response to the national emergency caused by the threat of foreign adversaries exploiting vulnerabilities in information and communications technology and services (ICTS). The same concerns that the Department of Commerce's ICTS rules seek to address are also a key component of the Commission's equipment authorization program; namely, the equipment authorization program seeks to ensure the Commission protects the U.S. communications networks and the supply chain from equipment that poses an unacceptable risk to national security.

Moreover, the Secure Networks Act's definition of “foreign adversary” is identical to the definition of “foreign adversary” as used by the Department of Commerce in producing its list of foreign adversaries. National Telecommunications and Information Administration (NTIA), in a notice and request for public comment implementing these provisions of the Secure Networks Act, treated the Department of Commerce's list of foreign adversaries as “foreign adversaries” for purposes of determining who is a “trusted . . . provider of advanced communications service or a supplier of communications equipment or service” under the Secure Networks Act. If Congress and NTIA determined that entities subject to foreign adversaries' ownership or control are not to be trusted to provide or supply communications equipment or services, the Commission does not believe they should be trusted to participate in the equipment authorization program, which tests and reviews communications equipment.

The FCC's proposal to address participation by foreign adversaries in the equipment authorization program is generally supported by Heritage and FDD. And the Commission does not

agree that application of the foreign adversary list is “discriminatory,” as TAF contends, given that the list reflects determinations by an expert agency that the entities listed have engaged in a “long-term pattern or serious instances of conduct significantly adverse to the national security interest of the United States or security and safety of United States persons.”

The Commission finds that its efforts to ensure the integrity and security of the equipment authorization program could be hindered by the participation of entities determined to have engaged in a long-term pattern or serious instances of conduct significantly adverse to the national security of the United States or security and safety of United States persons. These findings are consistent with the Commission's actions in other proceedings. For example, in the
Cybersecurity IoT Labeling R&O,
the Commission relied on the foreign adversary list as a disqualifier from receiving a U.S. Cyber Trust Mark label or from serving as Cybersecurity Label Administrator or other lab participating in the labelling program. Additionally, in the
Evolving Risks Order and NPRM,
the Commission proposed to rely on the Department of Commerce's definition of foreign adversary in its proposal to prioritize the renewal applications or any periodic review filings and deadlines based on, for example, “reportable foreign ownership, including any reportable foreign interest holder that is a citizen of a foreign adversary country.”

CHIPS Act.
At this time, the FCC declines to extend the definition of prohibited entity to any “foreign entity of concern” as defined by the CHIPS Act, because this definition extends to entities subject to the “jurisdiction” of specified countries. The FCC interprets this definition as potentially applicable to a broader range of entities than those owned by, controlled by, or subject to the direction of certain entities, and thereby more broadly applicable than anticipated in the
EA Integrity NPRM.
So, the FCC seeks further comment on adopting this definition, as discussed in the FNPRM portion of the proceeding. The FCC also declines at this time to extend the prohibition in this R&O to several other federal agency-developed and statutory “lists” of entities of concern both because the record on these lists is not developed and because the alignment between the policy goals underlying those lists and the integrity and security of the equipment authorization testing program is not as obvious, and seeks further comment in the
FNPRM.

Preventing Prohibited Entities From Participating in the Equipment Authorization Program

Recognizing the importance of ensuring that the TCBs and test labs that review equipment for importation and marketing in the U.S., and the entities that accredit test labs, are themselves trustworthy actors, and to complement the FCC's efforts to ensure the security of the supply chain, the Commission takes steps to remove from participation in its equipment authorization program entities that have been determined to pose unacceptable risks to the national security of the United States based on a number of sources (
i.e.,
prohibited entities). The Commission adopts its proposals in the EA Integrity NPRM to: (1) prohibit from recognition by the Commission and participation in the FCC's equipment authorization program any TCB, test lab, or laboratory accreditation body owned by, controlled by, or subject to the direction of a prohibited entity; and (2) prohibit reliance on or use of, for purposes of equipment authorization, any TCB or test lab owned by, controlled by, or subject to the direction of a prohibited entity. By adopting these prohibitions, the FCC takes a significant step in addressing the risks posed by these actors to U.S. national security in the communications equipment supply chain.

The restriction on entities that present national security concerns is rooted in longstanding legislative and regulatory efforts aimed at safeguarding U.S. national security, economic interests, and technological leadership, which have consistently recognized the risks posed by foreign adversaries. These efforts have consistently targeted the same foreign adversaries (or a subset thereof) designated as such by the Department of Commerce and treated as “prohibited entities” in the rules the FCC adopts today. These efforts include actions to safeguard military operations, protect U.S. supply chains against foreign adversaries exploiting vulnerabilities in key industries, and federal restrictions on adversarial access to sensitive data and emerging technologies that have been implemented to address cybersecurity, research security, and otherwise protect national security. In February of this year, President Trump issued a memorandum announcing the America First Investment Policy which, among other things, states that “[e]conomic security is national security,” discusses the need to limit certain investments in strategic sectors by the same six foreign adversaries as identified in the Department of Commerce's rules, and singles out China in particular for its nefarious exploitation of U.S. open capital markets to gain access to U.S. strategic technology and critical infrastructure. Taken together, these measures reflect an ongoing, bipartisan effort to mitigate foreign adversary involvement in U.S. economic and technological supply chains across multiple fronts over multiple Congresses and multiple Presidential Administrations.

Contrary to TAF's assertion that accreditation according to relevant ISO standards alone is sufficient to allow test lab participation in the Commission's equipment authorization program, the FCC believes that compliance with ISO standards should be a floor, not a ceiling, for all equipment authorization participants. And, while such compliance with generally universally-applied standards may be necessary to ensure technical competency, it may not be sufficient. Furthermore, the Commission believes that implementation of Congress's instruction that the Commission “may . . . establish such qualifications and standards as it deems appropriate for such private organizations, testing, and certification” requires us to address other concerns, such as protecting the supply chain from entities that present national security concerns. In light of ongoing security risks, the Commission must take measures to ensure that entities entrusted with access to equipment, and related data, prior to authorization for importing and marketing, as well as entities that assess the competence of such, are not acting on behalf of foreign adversaries but instead are operating consistent with their responsibilities to help ensure that equipment that poses an unacceptable risk to national security is kept out of our nation's supply chain, in addition to being technically competent. In fact, the Secure Networks Act demonstrates Congress's view that participants in the communications equipment supply chain that are “owned by, controlled by, or subject to the influence of a foreign adversary” are not to be “trusted.”

Additionally, one of the agencies upon which the FCC regularly relies for national security expertise—the Department of Justice, National Security Division (FIRS)—has noted several other national security concerns arising from reliance on TCBs and test labs “that could be exploited by adversarial entities.” Specifically, FIRS points out that TCBs and test labs perform certain activities that create technical vulnerabilities. The privileged access by TCBs and test labs to highly sensitive

intellectual property and emerging technologies could lead to systematic collection of information that represents a significant counterintelligence concern and the aggregation of such data has the potential to aid foreign adversaries in developing counterstrategies or identifying asymmetric advantages. Also, compromised entities could deliberately overlook or inadequately test devices, or manipulate test results, which could result in compromised devices in the U.S. market that have the potential to facilitate access by foreign intelligence services or that do not meet compliance requirements and pose interference risks.

The FCC finds that allowing entities that have been repeatedly identified as foreign adversaries of the U.S. government, specifically those identified in the
Order
as prohibited entities, to participate in the equipment authorization program as TCBs, test labs, and laboratory accreditation bodies could adversely affect a TCB's, test lab's, or laboratory accreditation body's “trustworthiness, or otherwise undermine the public's confidence,” especially their “access to proprietary, sometimes sensitive information about suppliers and their devices.” By enforcing stricter regulations on ownership and control of TCBs, test labs, and laboratory accreditation bodies, the FCC upholds core national security priorities, reinforcing the broader strategy to protect U.S. interests from adversarial exploitation.

Prohibiting Recognition of TCBs, Test Labs, and Laboratory Accreditation Bodies That Are Owned by, Controlled by, or Subject to the Direction of Prohibited Entities

In the
EA Integrity NPRM,
the Commission proposed to prohibit from recognition by the Commission and participation in the FCC's equipment authorization program any TCB, test lab, or laboratory accreditation body in which an entity identified on the Covered List has, possesses, or otherwise controls an equity or voting interest of 10% or more, either directly or indirectly, and sought comment on this proposal. The Commission also proposed and sought comment on whether it should decline to recognize laboratory accreditation bodies associated with any foreign adversary, including as to how such association should be determined.

The Commission adopts a modified version of these proposals to include a prohibition on recognition of, or participation by, TCBs, test labs, and laboratory accreditation bodies that are owned by, controlled by, or subject to the direction of prohibited entities, as defined in the
Order.
Several commenters were broadly supportive of the proposal, stating, for example, that it is necessary to ensure equipment is properly vetted against the Commission's rules intended to address national security threats. The Covered List represents expert determinations made by Congress and relevant federal agencies that the specified equipment and services produced by certain named entities represent an unacceptable threat to national security, and the risk of their importation into the United States necessitates that the FCC take measures to prevent such equipment from improperly obtaining FCC equipment authorization. Congress believed so strongly that the importation or marketing of certain equipment and services produced or provided by specific entities posed a threat to the national security and public safety that it passed the Secure Equipment Act to ensure that such equipment and services would be unable to obtain equipment authorizations from the Commission. The Commission takes seriously the Congressional mandate to ensure that its equipment authorization system excludes entities that have been determined to pose an unacceptable risk to the national security of the United States or the security and safety of United States persons. As such, the FCC finds it necessary to expand its proposal beyond the Covered List to include all prohibited entities as defined in the
Order.
The Commission finds it imperative that it not allow prohibited entities to circumvent supply chain protections or otherwise undermine the integrity of its supply chain. Prohibiting recognition of TCBs, test labs, or laboratory accreditation bodies that are owned by, controlled by, or subject to the direction of prohibited entities will help to ensure that participants in the FCC's equipment certification procedure, the most rigorous equipment authorization process, are not subject to undue influence and support the integrity and security of the program.

The Commission rejects TAF's arguments that there is no need to make changes to the existing authorization system because it has operated effectively to date without national security incidents, and that restricting lab authorization based on national security lacks a technical basis because labs do not modify products and so cannot introduce national security issues, nor do they possess any information that could threaten national security. A2LA also observed that as part of ISO/IEC 17011, accreditation bodies must maintain impartiality and, by that criteria, no accreditation body should have an “affiliation” with a foreign government, adversarial or not. The Commission emphasizes that the measures it adopts today are both an important corollary to the rules the FCC adopted in the
EA Security R&O
and proactive measures against evolving risks reflected in the record before us. As FDD noted, this action is just the latest Commission effort in recognition of “a growing vector of systemic risk: adversarial control over the authorization process that safeguards the U.S. communications technology ecosystem.” Further, the Commission agrees with FDD that “TCBs and test labs handle highly sensitive, proprietary manufacturing and development data, conduct testing protocols, and produce compliance certifications upon which the FCC relies,” meaning “their actions directly affect what devices are legally imported into and offered for sale within the United States.” The Commission further agrees with FDD that if U.S. adversaries are participants in this layer of the supply chain, they can introduce vulnerabilities at scale, long before devices reach consumers or critical systems.”

Absent rules intended to ensure the impartiality of TCBs, test labs, and laboratory accreditation bodies, prohibited entities could pressure TCBs, test labs, or laboratory accreditation bodies to take actions that are contrary to the FCC's efforts to protect the communications equipment supply chain. For example, entities that own, control, or direct TCBs, test labs, or laboratory accreditation bodies could pressure the TCB, test lab, or laboratory accreditation body to overlook requirements that could ultimately result in the authorization of equipment identified on the Covered List. Furthermore, TCBs and test labs have access to sensitive, proprietary information related to equipment submitted for testing and certification and laboratory accreditation bodies are tasked with assessing the competence of test labs. Access to such information by entities who have been determined to pose unacceptable risks to national security would provide further opportunity for actions that would compromise the integrity of the FCC's equipment authorization program.

Given the importance of ensuring the security of the FCC's supply chain and limiting vulnerabilities from entities that present national security concerns, the Commission declines to implement certain alternatives proposed by commenters. For example, the

Commission finds inadequate TIC's suggestion that it would be sufficient to simply adopt disclosure requirements, because such disclosure requirements would not necessarily prevent entities presenting national security concerns from, participating in the FCC's equipment authorization program. Moreover, such a disclosure regime would potentially require the Commission to engage in extensive, individualized reviews of test lab and TCB ownership to determine whether national security interests are implicated. Such a regime also would result in uncertainty within the regulated community as to what the Commission might do to address such instances. By adopting the rules in the
Order,
the Commission is creating a transparent method of addressing the threat of entities that present national security risks within its equipment authorization program. The Commission is also not persuaded that its proposed rules would meaningfully adversely impact global supply chains, slow equipment approvals, or increase costs for manufacturers. The transparency of these new requirements will not only provide the Commission with the necessary information to ensure the integrity of its equipment authorization program, it will also increase awareness within industry as to the entities with whom they choose to do business and lessen concern that prohibited entities could interfere with their equipment authorizations or the process of obtaining such, potentially speeding up equipment approvals and reducing costs. Additionally, the Commission doesn't find it necessary to provide an extended transition period for implementation of the rules in order to allow sufficient time to identify and engage adequate replacement facilities, as suggested. Considering the time needed for the rules adopted here to take effect, in addition to the procedural timeframes included in the rules for withdrawal of recognition, the Commission believes that any concerns are speculative and outweighed by its goal of ensuring the integrity of the equipment authorization program.

The role of laboratory accreditation bodies in the FCC's equipment authorization program—namely, to provide impartial assessment of the competence of the test labs that they accredit—requires that they be free of and safeguarded from influence by actors that may pose a risk to national security. The Commission also recognizes that the activities and practices of laboratory accreditation bodies extend internationally and include relationships with various foreign actors, and so clarity is needed regarding how to determine which laboratory accreditation bodies will be recognized by the Commission. In addition, if the Commission were to adopt a prohibition on TCBs and test labs owned by, controlled by, or subject to the direction of prohibited entities without adopting a corresponding prohibition on laboratory accreditation bodies, the Commission would leave open the possibility that prohibited entities would simply move upstream to exercise ownership, control, or direction within the equipment authorization program. Acknowledging commenters' desire for clarity, the Commission adopts a rule that it will not recognize a laboratory accreditation body, and will revoke the recognition of any previously-recognized laboratory accreditation body, that is owned by, controlled by, or subject to the direction of a prohibited entity.

The Commission finds that this rule, along with the explanation provided in the proceeding of what the FCC means by “owned by, controlled by, or subject to the direction of” will provide clear requirements for participation in the equipment authorization program. With regard to A2LA's observation that laboratory accreditation bodies are required to maintain impartiality pursuant ISO/IEC 17011, the Commission finds it incumbent upon us to take proactive measures to ensure the integrity and guarantee against equipment authorization program participation by entities owned by, controlled by, or subject to the direction of prohibited entities.

Prohibiting Reliance on, or Use of, for Purpose of Equipment Authorization, and TCB or Test Lab Owned by, Controlled by, or Subject to the Direction of a Prohibited Entity

In the
EA Integrity NPRM,
the Commission also proposed to prohibit from recognition by the Commission and participation in its equipment authorization program, any TCB or test lab in which an entity identified on the Covered List has direct or indirect ownership or control. The Commission tentatively concluded that, in light of the determinations made from expert federal agencies and Congress about the national security risks posed by entities with equipment identified on the Covered List, the Commission should not permit such TCBs and test labs to have any role in its equipment authorization program.

The Commission adopts the proposed rule to prohibit reliance on or use of any TCB or test lab owned by, controlled by, or subject to the direction of an entity (or its subsidiaries or affiliates) identified on the Covered List, for purposes of equipment authorization. The Commission expands this prohibition, however, to include all “prohibited entities.” This means that parties seeking equipment authorization pursuant to the SDoC process may not rely on testing performed at a test lab that is owned by, controlled by, or subject to the direction of a prohibited entity.

By prohibiting, for purposes of SDoC authorization, the use of test labs that are owned by, controlled by, or subject to the direction of a prohibited entity, the Commission seeks to ensure that entities posing national security risks cannot use the SDoC process as a loophole to circumvent the FCC's restrictions. The Commission rejects the arguments of commenters that extending the prohibition to the SDoC process will not enhance national security, and that any security concerns are mitigated by the existing prohibition on entities identified on the Covered List from using SDoC. The Commission also disagrees with TIA that we must provide specific evidence of abuse of the SDoC process to warrant changes. In enacting the Secure Networks Act and Secure Equipment Act, Congress recognized that it was imperative that those entities determined to pose unacceptable risks to U.S. national security be foreclosed from accessing U.S. communications networks and supply chains, and nothing in the record would support excluding test labs used as part of the SDoC process from this prohibition.

Information on equipment authorized via the SDoC process is less readily transparent to the Commission than information on equipment authorized via certification, meaning that equipment authorization through the SDoC process may be at greater risk of potential exploitation by prohibited entities, raising national security concerns regarding the possible introduction of equipment that poses an unacceptable risk to national security into the U.S. market. In prohibiting entities identified on the Covered List from using SDoC to obtain equipment authorization, the Commission sought to ensure consistent application of the prohibition on further authorization of covered equipment, while also providing for more active oversight. The same rationale applies here—namely that, absent the clarification the Commission adopts today, prohibited entities might use their influence over labs, and take advantage of the more limited oversight the Commission has

over the SDoC process, to allow for the introduction of equipment that poses an unacceptable risk to U.S. national security and otherwise undermine the integrity of its equipment authorization process. The value of the SDoC process to many parties seeking equipment authorization, and the importance of prohibiting equipment that poses an unacceptable risk to national security, necessitates that the Commission takes measures to prevent abuse of the SDoC process.

Defining “Ownership” and “Direction or Control”

The FCC prohibitions in section III.B. of this document rely on specific definitions of “ownership” and “direction or control.” As the Commission discusses below, it has repeatedly used ownership limits or attribution rules to identify entities presumed to be able to exert effective direction or control even in the absence of a majority voting interest. Here the Commission defines and adopts such a limit. The Commission also recognizes that an entity may exert direction or control when it has minority interests below the limits the Commission sets or no ownership interests, so the Commission adopts and clarifies qualitative indicia that entities, and the Commission, may use in determining and attesting to the existence of direction or control.

Implementation of the 10% Ownership Threshold

The Commission adopts its proposals in the
EA Integrity NPRM
to prohibit from recognition by the Commission and participation in its equipment authorization program, any TCB, test lab, or laboratory accreditation body in which a prohibited entity directly or indirectly owns or controls 10% or more of the equity or voting rights. Consistent with Commission precedent and the rules and precedent of other federal regulatory agencies, the Commission finds that the 10% ownership threshold provides a reasonable proxy or indication that a TCB, test lab, or laboratory accreditation body is controlled by or subject to the direction of a prohibited entity.

Some commenters oppose the proposed prohibition and recommended alternative approaches. For instance, TIA proposed that the Commission first “target” only TCBs and test labs that are wholly owned by entities on the Covered List. TIA presented no evidence, however, to support its implicit contention that a threat is only present when a TCB or a test lab is wholly owned by a prohibited entity, nor does it explain why a prohibited entity cannot exert direction or control even though it may hold only a minority ownership interest or no ownership interest in the TCB, test lab, or laboratory accreditation body. Indeed, under TIA's proposal, a TCB 99.99% owned by an entity identified on the Covered List would not be prohibited, but it would be prohibited if such ownership rose to 100%. Based on the FCC's record, such a limited prohibition would not adequately protect the integrity of the equipment authorization program against participation by prohibited entities. Therefore, the Commission rejects TIA's proposal and concludes that prohibiting only those TCBs and test labs that are wholly owned by prohibited entities would not sufficiently advance the national security interests in the proceeding.

Some commenters question whether laboratory accreditation bodies have the capability to ascertain ownership interests. In their view, because laboratory accreditation is primarily a technical assessment conducted by technical experts—and not a review of ownership interests by financial analysts, accountants, or auditors—reliance on laboratory accreditation bodies to prevent accreditation of test labs based on ownership interests is not feasible. A preferable approach, according to A2LA, would be for the Commission to assess all test labs, offer accreditation if warranted, and then restrict the ability of labs to conduct testing or participate in the equipment authorization if accredited entities are found to be a national security risk. Another proposed alternative was to create a “self-reporting component” for ownership interests of TCBs and test labs that the Department of Commerce might oversee. A2LA further stated that it was unclear how ownership impacts national security risk.

In response to concerns of commenters that laboratory accreditation bodies are not equipped to determine ownership interests, the Commission clarifies that the rules it adopts today do not require laboratory accreditation bodies to independently investigate and establish ownership. Rather, the rules will require TCBs and test labs themselves to certify that no prohibited entity has an equity or voting interest of 10% or more in the TCB or test lab. And while the FCC's rules do require that the laboratory accreditation body submit a test lab's certification directly to the Commission in order for the test lab to be included on the list of accredited test labs that the FCC has recognized, this does not require the laboratory accreditation body to undertake its own investigation of a test lab's ownership. Nor do the Commission see that this requirement imposes an undue burden on laboratory accreditation bodies, which must already submit to the Commission various information regarding the test lab. That said, the Commission do, however, expect a laboratory accreditation body to take reasonable steps to not knowingly or negligently facilitate the obfuscation of the ownership of a test lab. In other words, a laboratory accreditation body could be held responsible for what it knew or should reasonably have known concerning the ownership interests in the TCB or test lab. Indeed, this is the same standard that TCBs should already be applying in the equipment authorization context in assessing whether an applicant's attestations regarding the equipment for which authorization is sought—namely that the equipment is not “covered,” and providing a valid U.S. agent for service of process—is accurate and true.

A2LA asked how “affiliation” would be defined, as used in the
NPRM,
and asked whether participation by accreditation bodies in countries with which the U.S. has MRA and accreditation of test labs in foreign countries might be considered “affiliation.” A2LA said U.S. accreditation bodies have accredited test labs in foreign countries that “may be” on the adversary list and questioned whether those accreditation bodies would be precluded for that reason. ANAB similarly said that the FCC should clarify that “affiliation” does not include participation in widely recognized international accreditation cooperations through which ANAB accepts and promotes the results of conformity assessment bodies accredited by other signatories, some of which are government organizations in countries identified on the foreign adversaries list. In the proposals the Commission provided in the
NPRM,
we used the term “affiliation” very broadly throughout the discussion and once in the proposed rules to convey a connection between entities. The Commission did not specifically propose to tie that term to its definition of “affiliate” nor did the Commission propose a new definition. In finalizing the rules that the Commission adopts today, we are adopting a defined relationship of ownership, direction, or control in lieu of affiliation, for the reasons discussed herein. As such, the Commission finds no reason to further expand upon the discussion of “affiliation” as raised by A2LA and

ANAB. The Commission also clarifies here that its rules apply equally to all TCBs, test labs, and laboratory accreditation bodies regardless of the existence of MRAs or physical location of the relevant facility.

The Commission concludes that it is appropriate to prohibit any TCB, test lab, laboratory accreditation body from participating in the equipment authorization process if a prohibited entity directly or indirectly owns 10% or more of the equity or voting stock. Consistent with Commission precedent and that of other federal agencies, the Commission finds that a third party could exert direction or control over another entity even without holding a majority of the equity or voting rights. Establishing the direct and indirect ownership rule at 10% aligns with Commission precedent and reflects a reasonable standard for identifying potential direction or control. For example, applicants for an international section 214 authorization are required to identify any individual or entity that directly or indirectly owns 10% or more of the equity interests and/or voting interests, or a controlling interest, of the applicant. Also, applicants or licensees subject to the ownership reporting requirements of § 1.2112 of the FCC's rules must identify any party holding 10% or more of stock, partnership interest, or indirect ownership interest in the reporting entity.

This 10% threshold is also consistent with definitions of ownership applied by other federal agencies with expertise in examining corporate ownership and structure. For example, the Internal Revenue Code defines the term “United States shareholder” with respect to any foreign corporation, as “a United States person . . . who owns . . . 10 percent or more of the total combined voting power of all classes of stock entitled to vote of such foreign corporation, or 10 percent or more of the total value of such shares of all classes of stock of such foreign corporation.” Under the Change in Bank Control Act, anyone, including those “acting in concert,” must provide a written notice before acquiring control of a bank or bank holding company, if they acquire 10% or more of its voting shares. Similarly, a foreign entity acquiring at least 10% of the voting interest (directly or indirectly through a U.S. entity) in a U.S. business enterprise, either through acquisition or establishment of a new entity, is required to file a BE-13 Report with the Bureau of Economic Analysis (BEA). The Commission concludes that adopting the 10% ownership threshold appropriately identifies entities with sufficient direction or control as to pose a risk.

Heritage asked the Commission to explain “why entities with less than 10% [ownership or control] pose a risk, but entities below 5% do not.” The Commission recognizes that a third party may exercise direction or control over another entity even where it holds less than a 10% ownership stake in that entity or holds no ownership stake. Consistent with precedents discussed above of this document, the Commission expands its current reporting requirement and adopts a requirement that all TCBs, test labs, and laboratory accreditation bodies report all equity or voting interests of 5% or greater by any entity. This 5% reporting threshold balances the need to protect national security while minimizing undue reporting burden by providing the Commission with the necessary information to confirm compliance with the ownership prohibitions and to more easily identify closely associated entities. The Commission notes that the reporting requirement is parallel to and not a substitute for its requirement that all TCBs, test labs, and laboratory accreditation bodies, regardless of ownership interests, certifies that they are not under the ownership, or otherwise direction or control of prohibited entities based on the indices of direction or control that the Commission discusses next.

Definition of “Direction or Control”

In addition to prohibiting any TCB, test lab, or laboratory accreditation body in which a prohibited entity has direct or indirect ownership or control of 10% or more equity or voting interest from recognition or participation in the FCC's equipment authorization process, the Commission also adopts that prohibition for any TCB, test lab, or laboratory accreditation body that is subject to the direction or control of a prohibited entity. The concept of direction and control includes the control that is inherent when an entity is a part of the governmental structure or hierarchy of a foreign adversary, including subnational governments thereof. Recognizing that a prohibited entity may exert direction or control over another entity even where it does not own 10% or more of the equity or voting stock of that entity, the Commission therefore requires TCBs, test labs, and laboratory accreditation bodies to assess whether a prohibited entity directly or indirectly possesses or has the power (whether or not exercised) to determine, direct, or decide important matters affecting an entity. Factors indicating direction or control could include the power to decide matters pertaining to the entity's reorganization, merger, or dissolution; the opening or closing of facilities or major expenditures or to exercise authority over its operating budget; selection of new lines of business; entering into, terminating, or otherwise affecting the fulfillment of significant contracts; adopting policies relating to treatment of non-public or proprietary information; appointing officers or senior leadership; appointing or dismissing employees with access to critical or sensitive technology; or amending the entity's organizational documents. Such indicators would be relevant regardless of whether the power was exercised, and could take the form of, for example, ownership of securities or partnership or other ownership interests, board representation, holding a special share, contractual arrangements, or other formal or informal arrangements to act in concert or to decide important matters affecting an entity. Additionally, the Commission considers any applicant, wherever located, to be under the direction or control of a prohibited entity if that applicant acts as an agent or representative of a prohibited entity or acts in any other capacity at the order or request of a prohibited entity or whose activities are directly or indirectly supervised, directed, controlled, financed, or subsidized in whole or in majority part.

Reporting, Certification, and Recordkeeping Requirements

To help ensure that the Commission have the necessary information to implement the measures it adopts to prohibit from participation in the equipment authorization program entities that have been determined to pose unacceptable risks to national security, the Commission expands its current reporting and certification requirement for TCBs, test labs, and laboratory accreditation bodies that seeks Commission recognition. The Commission finds that requiring certification and reporting of ownership is necessary to minimize vulnerabilities in the telecommunications infrastructure and strengthen national security through the equipment authorization process by ensuring that TCBs, test labs, and laboratory accreditation bodies will not be owned by or under the direction or control by prohibited entities. The Commission finds that these adopted rules will yield significant benefits, including improved consistency in the Commission's consideration of evolving national security risks, completeness of the

Commission's information regarding equipment authorization, and timely Commission attention to issues that warrant heightened scrutiny. The Commission also finds that the adoption of the rules will better protect U.S. telecommunications infrastructure from national security risks posed by prohibited entities. These benefits cannot be achieved with
ad hoc
reviews alone. Thus, adopting a systemized review of the ownership certification and report by TCBs, test labs, and laboratory accreditation bodies is necessary to help ensure that the Commission and the Executive Branch agencies have the necessary information to address evolving national security, law enforcement, foreign policy, and/or trade policy risks on a continuing basis. While it is difficult to quantify these economic benefits, the Commission believes the benefits are far greater than the costs of the requirements.

The Commission adopts a requirement for all recognized TCBs, test labs, and laboratory accreditation bodies to certify to the Commission, within 30 days after the effective date of the relevant rules, and thereafter with each request for recognition, that they are not owned by, controlled by, or subject to the direction of a prohibited entity. The Commission also adopts a requirement that all recognized TCBs, test labs, and laboratory accreditation bodies report, within 90 days after the effective date of the relevant rules and thereafter with each request for recognition, all equity or voting interests of 5% or greater by any entity. The Commission will not recognize—and will revoke any existing recognition of—any TCB, test lab, or laboratory accreditation body that fails to provide, or that provides a false or inaccurate certification; or that fails to provide, or provides false or inaccurate, information regarding equity or voting interests of 5% or greater. If there is any change to any of the lists that make up the prohibited entities resulting in the addition of an entity after the effective date of these rules, the Commission will require compliance with the relevant reporting, certification, and recordkeeping requirements no later than 90 days after the effective date of such change. In keeping with these reporting requirements, the FCC also clarifies the requirement that every entity specifically named on the Covered List must provide to the Commission, pursuant to § 2.903(b), information regarding all of its subsidiaries and affiliates, not merely those that produce “covered” equipment. The Commission orders each relevant entity to provide this information no later than 30 days after the effective date of this rule and thereafter in accordance with the provisions in § 2.903(b).

In order to more effectively protect the FCC's equipment authorization program from the direction or control of untrustworthy entities and ensure the integrity of the program, the Commission proposed and sought comment in the
EA Integrity NPRM
on new recordkeeping, reporting, and certification obligations for TCBs and test labs to enable the Commission to determine ownership or control, as well as comment on any changes to its rules governing laboratory accreditation bodies.

First, the Commission proposed that any entity seeking to become an FCC-recognized TCB or test lab report to the Commission equity or voting interests in the TCB or test lab of 5% or more. Second, the Commission proposed to require that recognized TCBs and test labs: (1) no later than 30 days after the effective date of any final rules adopted in this proceeding, certify that no entity identified on the Covered List (or otherwise specified in our final rules) has, possesses, or otherwise controls an equity or voting interest of 10% or more in the TCB or test lab, and (2) no later than 90 days after the effective date of any final rules adopted in this proceeding identify any entity (including the ultimate parent of such entities) that holds such ownership or control interest as our final rules require, proposed as 5% or more ownership, as discussed above. Third, the Commission proposed that any test lab that takes measurements of equipment subject to an equipment authorization, whether pursuant to certification or SDoC, maintain in its records a certification that no entity identified on the Covered List has, possesses, or otherwise controls an equity or voting interest of 10% or more in the test lab and documentation identifying any entity that has, possesses, or otherwise controls an equity or voting interest of 5% or more in the test lab. Finally, the Commission sought comment on precluding laboratory accreditation bodies associated with foreign adversaries, including how such association should be determined.

The Commission received comments directed at these reporting requirements. The American Council of Independent Laboratories commented that the Commission's reporting requirements are reasonable and appropriate. Other commenters expressed concerns or suggested changes to these proposals. For instance, TIC commented that the proposed reporting requirements are not currently covered in MRAs between the United States and participating countries, and asked that any rules adopted be tailored to address supply chain security without disrupting testing capacity or U.S. trade commitments. Heritage asked the Commission to consider whether any level of ownership by an entity on the Covered List needs to be disclosed. Other commenters made more general observations that are relevant here. For example, TIA said that any new rules should not overly burden trustworthy TCBs or test labs.

The Commission adopts the certification, reporting, and recordkeeping requirements that the Commission proposed in the
EA Integrity NPRM
with the modifications that these requirements will be extended to laboratory accreditation bodies and broadened to include ownership, control, or direction by any prohibited entity, as well as the additional note that reported ownership information will be made publicly available on the Commission's website. The Commission and all parties seeking equipment authorization must have ready access to the information necessary to determine which TCBs, test labs, and laboratory accreditation bodies can be relied upon for purposes of the FCC's equipment authorization program. In particular, stakeholders must be able to evaluate any ownership interest concerns that may be raised regarding an entity's impartiality or trustworthiness, particularly with regard to potential influence by entities that raise national security concerns. The Commission also finds that such ownership information could be relevant going forward to establishing appropriate “qualifications and standards” under section 302(e) of the Act regarding private entities to which the Commission has delegated and entrusted certain responsibilities as part of its equipment authorization program. Such data could also be instructive in other efforts to bolster the integrity of the equipment authorization program, such as ensuring that TCBs are complying with applicable impartiality requirements and rules targeted at ensuring they are not owned or controlled by a manufacturer whose equipment they must examine.

Certification Requirement.
To implement our prohibition on recognition of TCBs, test labs, and laboratory accreditation bodies that are subject to ownership or direction or control of a prohibited entity, the Commission adopts the proposal that,

no later than 30 days after the effective date of the rules adopted in the proceeding, recognized TCBs, test labs, and laboratory accreditation bodies must certify that no prohibited entity has, possesses, or otherwise controls an equity or voting interest of 10% or more. The Commission also requires that recognized TCBs, test labs, and laboratory accreditation bodies certify compliance with these rules and submit the requested ownership information along with the request for recognition and within 30 days after any relevant change. Because ownership interests evolve over time, and the lists of prohibited entities are subject to modification, the Commission believes that change-dependent certification and reporting requirements, along with regular confirmation, are critical to verifying the integrity of TCBs, test labs, and laboratory accreditation bodies. The Commission recognizes that relevant entities would need time to consider their options when there is a change to any of the lists that make up the prohibited entities resulting in the addition of an entity. To allow TCBs, test labs, and laboratory accreditation bodies to fully assess their ownership considerations, the Commission will require compliance with the relevant certification requirements no later than 90 days after the effective date of such changes to the prohibited entities.

Reporting Requirement.
The Commission also adopts a requirement that all recognized TCBs, test labs, and laboratory accreditation bodies report, within 90 days after the effective date of the rules, all equity or voting interests of 5% or greater by any entity. The Commission further requires that recognized TCBs, test labs, and laboratory accreditation bodies submit an updated report with the request for recognition and within 30 days after any change to entities that own 5% or more of its equity or voting interests. The Commission recognizes that the current 10% ownership threshold may not capture all of the information necessary to adequately assess whether a TCB, test lab, or laboratory accreditation body is owned by, controlled by, or subject to the direction of a prohibited entity. In certain instances, an entity holding less than 10% of direct or indirect ownership may nonetheless be able to exert direction or control over a TCB, a test lab, or a laboratory accreditation body. For example, where enhanced voting rights are present, such an entity may possess disproportionate decision-making power relative to its ownership stake. To balance the need to protect national security while minimizing undue reporting burden, the Commission expands its current reporting requirement and adopts a requirement that all recognized TCBs, test labs, and laboratory accreditation bodies, or those seeking recognition, report all equity or voting interests of 5% or greater by any entity. A reporting threshold of 5% would be consistent with the ownership threshold used by the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector (Committee) in its review of certain applications. For instance, in the
2021 Standard Questions Order,
the Commission noted the views of Committee staff that, “5% threshold is appropriate because in some instances a less-than-ten percent foreign ownership interest—or a collection of such interests—may pose a national security or law enforcement risk.” The Commission, based on the views of Committee staff, agreed that a 5% ownership reporting threshold is appropriate with respect to the Standard Questions. Given the Committee's expertise in assessing national security and law enforcement risks associated with foreign ownership interests, the Commission finds its reliance on a 5% threshold lends further support to its decision to adopt the same. The Commission concludes that a 5% reporting threshold would position the Commission to more easily identify foreign interests and their possible control.

A reporting threshold of 5% would also be consistent with requirements imposed by other agencies, such as the Securities and Exchange Commission (SEC). The SEC Exchange Act Rule 13d-1 requires a person or “group” that becomes, directly or indirectly, the “beneficial owner” of more than 5% of a class of equity securities registered under section 12 of the Exchange Act to report the acquisition to the SEC. The Commission further notes that various SEC forms filed by issuers, including their annual reports (or proxy statements) and quarterly reports, require the issuer to include a beneficial ownership table that contains,
inter alia,
the name and address of any individual or entity, or “group,” who is known to the issuer to be the beneficial owner of more than 5% of any class of the issuer's voting securities. Finally, a reporting threshold of 5% is also consistent with the standards adopted by the Committee on Foreign Investment in the United States (CFIUS), which reviews certain transactions involving foreign acquisitions of U.S. businesses.

The Commission is mindful of the caution from commenters against placing overly burdensome restrictions on TCBs or test labs. However, the Commission considers this type of information collection to be routine in many contexts and find that these obligations are an appropriate and not unduly burdensome means of enabling the Commission to confirm compliance with the ownership prohibitions and to more easily identify closely associated entities of TCBs, test labs, and laboratory accreditation bodies seeking to participate in the equipment authorization program. As aforementioned, the Commission and other government agencies commonly adopt rules to identify direct or indirect ownership or control of entities by third parties to address various concerns including national security. The Commission concludes that ascertaining the holders of 5% or more of the direct or indirect ownership should not present a substantial burden because it is reasonable to conclude that a privately held company would be aware of its investors and would maintain record of such information in the ordinary course of business, while for publicly held companies, the information on persons holding 5% or more of any class of equity security should be generally available to the public. The Commission recognizes that relevant entities would need time to consider their options when there is a change to any of the lists that make up the prohibited entities resulting in the addition of an entity. To allow TCBs, test labs, and laboratory accreditation bodies to fully assess their ownership considerations, the Commission will require compliance with the relevant reporting requirements no later than 90 days after the effective date of such an addition of prohibited entities.

Recordkeeping requirements.
In order to implement the prohibition, for purposes of SDoC authorization, on the use of test labs that are owned by, controlled by, or subject to the direction of a prohibited entity, the Commission adopts a requirement that parties seeking equipment authorization pursuant to the SDoC process maintain a record that the entity performing the testing conducted pursuant to the SDoC process is not owned by, controlled by, or subject to the direction of a prohibited entity. Specifically, parties availing themselves of the SDoC process must maintain a record that no prohibited entity has, possesses, or otherwise controls an equity or voting interest of 5% or more in the test lab performing the testing conducted

pursuant to the SDoC process. This requirement will help to ensure that responsible parties perform the due diligence necessary to compile the required record and determine that the test lab is eligible to participate in the FCC's equipment authorization program pursuant to the rules the Commission adopts today. The Commission also finds, and agrees with CTA, that this requirement will not meaningfully raise the cost and complexity of the SDoC process. As with test labs seeking FCC recognition, the Commission believes this type of ownership information would be retained by the test lab in the ordinary course of business. For these reasons, the Commission modifies § 2.938(b)(2) of its rules to adopt this requirement. The Commission recognizes that relevant entities would need time to consider their options when there is a change to any of the lists that make up the prohibited entities resulting in the addition of an entity. To allow TCBs, test labs, and laboratory accreditation bodies to fully assess their ownership considerations, the Commission will require compliance with the relevant recordkeeping requirements no later than 90 days after the effective date of such changes to the prohibited entities. To make determinations regarding the continued acceptability of TCBs, test labs, and laboratory accreditation bodies, the Commission may also request additional information regarding the test site, the test equipment, or the qualifications of the company or individual performing the tests for the SDoC process, including documentation identifying any entity that holds a 5% or greater direct or indirect equity or voting interest in the test lab, company, or individual performing the testing.

Reporting subsidiaries and affiliates of Covered List entities.
The Commission proposed in the
EA Integrity NPRM
to require that every entity specifically named on the Covered List must provide to the Commission information regarding all of its subsidiaries and affiliates, not just those subsidiaries and affiliates that produce “covered” equipment, pursuant to § 2.903(b). The Commission stated that this proposal would be in keeping with the certification and reporting requirements for test labs and TCBs discussed above. The Commission did not receive comment directed at this proposal.

The Commission adopts this proposal and requires that every entity specifically named on the Covered List must provide to the Commission information regarding all of its subsidiaries and affiliates. The Commission has previously explained that in adopting rules and procedures to prohibit authorization of “covered” equipment, it is critical for the Commission, applicants for equipment authorizations, TCBs, and other interested parties to have the requisite, transparent, and readily available information of the particular entities that in fact are associated with the named entities on the Covered List. In light of the rules the Commission adopts today, it is now critical that the Commission and all stakeholders have complete information regarding all of the subsidiaries and affiliates of Covered List entities in order for the Commission, applicants for equipment authorization, TCBs, and others to make determinations about which entities may be relied upon for purposes of the Commission's equipment authorization program. Requiring this information is reasonable and justified in keeping with its goal of effectively ensuring that “covered” equipment determined as posing an unacceptable risk to national security under the Secure Networks Act, and prohibited from authorization under the Secure Equipment Act, is not authorized, and helps to ensure that the Commission meet the mandate in the Secure Equipment Act that the Commission not approve the grant of any “covered” equipment.

Accordingly, the Commission requires each entity specifically named on the Covered List to submit a complete and accurate list to the Commission, within 30 days after the effective date of the rules, identifying all subsidiaries and affiliates. For each associated entity (
e.g.,
subsidiary or affiliate), the entity named on the Covered List must provide the following information: the full name, mailing address or physical address (if different from mailing address), email address, and telephone number of each of that named entity's associated entities (
e.g.,
subsidiaries or affiliates). As before, named entities must provide up-to-date information on any changes to the list, and if there are changes, the named entity must submit such updated information to the Commission within 30 days after the change(s), and indicate the date on which the particular change(s) occurred. Furthermore, when the Covered List is updated, any newly named entity must submit the required information for associated entities within 30 days after its inclusion on the Covered List. These submissions must be reported by an affidavit or declaration under penalty of perjury, signed and dated by an authorized officer of the named entity on the Covered List with personal knowledge verifying the truth and accuracy of the information provided about the entity's associated entities. The affidavit or declaration must comply with § 1.16 of the Commission's rules. The Commission directs the OET to make the lists of affiliates and subsidiaries available to the public for review and inspection.

Defining “own” for purposes of identifying affiliates.
The Commission also proposed in the
EA Integrity NPRM
to revise the term “own,” in the context of determining what is an “affiliate” of an entity named on the Covered List, from ownership of more than 10 percent to ownership of 10 percent
or more.
The Commission received only one comment relevant to this revision. A2LA observed that the current definition of “affiliate” uses an ownership threshold of “more than 10 percent,” while the rule as proposed uses a threshold of 10% or more, and asked for clarity as to the threshold.

The Commission adopts the revision as proposed. Specifically, the Commission revises its rules such that the term “own” in the context of determining what is an “affiliate” of an entity named on the Covered List means to “have, possess, or otherwise control an equity or voting interest (or the equivalent thereof) of 10 percent
or more.”
The Commission observes first that it's not bound, here, by a particular statutory definition of the term “affiliate.” Rather, while the Communications Act generally defines the terms “affiliate” and “own,” and there “own” means “to own an equity interest (or the equivalent thereof) of more than 10 percent,” such definitions are applied “unless the context otherwise requires.” The National Defense Authorization Act for Fiscal Year 2019, which designated as “covered telecommunications equipment or services” any telecommunications equipment produced by Huawei or ZTE “or any subsidiary or affiliate of such entities,” and, for certain purposes, video surveillance and telecommunications equipment produced by Hytera, Hikvision, or Dahua “or any subsidiary or affiliate of such entities,” did not define the term “affiliate,” but the Commission believes that the threshold of 10% or more, rather than more than 10%, is most consistent with Congress's intent because of its use in several other statutory schemes as well as other Commission information collections. The Commission finds that the compelling interest in preventing authorization of equipment that may pose an unacceptable risk to national security also justifies using the

moderately more expansive definition the Commission adopts today.

Other Rule Revisions

TCB, test lab, and laboratory accreditation body recognition withdrawal.
The Commission proposed in the
EA Integrity NPRM
that, if a relevant TCB or test lab does not make the certification required in the proceeding, or provides a false or inaccurate certification, the Commission would suspend the recognition of any such TCB or test lab and commence action to withdraw FCC recognition under applicable withdrawal procedures. The Commission also sought comment on whether laboratory accreditation bodies should be subject to additional requirements. With regard to withdrawal of recognition of test labs, the Commission received one comment directly relevant to this proposal. A2LA suggested that the Commission employ different levels of sanctions for different violations, such as harsher penalties for intentional violations of FCC requirements. Further, A2LA asked the Commission to consider offering test labs the opportunity to remediate an otherwise prohibited ownership threshold before withdrawing recognition.

Inherent in the authority to recognize a TCB, test lab, or laboratory accreditation body is the authority to withdraw or cease such recognition when a TCB, test lab, or laboratory accreditation body does not comply with the FCC's requirements. Accordingly, the Commission adopts rules specifying that its will to withdraw the FCC's recognition of a TCB, test lab, or laboratory accreditation body, if the TCB, test lab, or laboratory accreditation body is owned by, controlled by, or subject to the direction of a prohibited entity; fails to provide, or provides a false or inaccurate, certification that it is not owned by, controlled by, or subject to the direction of a prohibited entity or, similarly, fails to provide, or provides a false or inaccurate, report regarding entities with more than 5% ownership. Although the Commission believes that such ownership, control, or direction, a failure to report, or providing a false or inaccurate report, would constitute “just cause” that would permit revocation under existing rules, the Commission takes the opportunity here to codify it as an explicit basis for revocation and to provide a more streamlined process for resolution. The Commission finds this is necessary to adequately ensure the integrity of the equipment authorization program. It is also consistent with existing obligations on TCBs, test labs, and laboratory accreditation bodies and the Commission's rules regarding withdrawal of recognition of a TCB for just cause or if the TCB is not certifying equipment in accordance with the Commission's rules and policies.

The FCC's rules already specifies the procedures the Commission will follow when withdrawing recognition of a TCB. The Commission adopts similar rules here, specific to withdrawal of recognition of a TCB, test lab, or laboratory accreditation body, if the TCB, test lab, or laboratory accreditation body is owned by, controlled by, or subject to the direction of a prohibited entity pursuant to § 2.902; fails to provide, or provides a false or inaccurate, certification that it is not owned by, controlled by, or subject to the direction of a prohibited entity or, similarly, fails to provide, or provides a false or inaccurate, report regarding entities with more than 5% ownership. The procedure for such withdrawal is consistent with that explained in the
EA Integrity NPRM
and already employed by OET in taking action to suspend or deny the recognition of a test lab apparently owned by an entity on the Covered List. In any instance in which the Commission or OET, acting on delegated authority, has a reasonable basis for determining that a TCB, test lab, or laboratory accreditation body is owned by, controlled by, or subject to the direction of a prohibited entity, or fails to provide or provides a false or inaccurate, certification of such, the Commission directs OET to issue a letter to the TCB, test lab, or laboratory accreditation body notifying it of the FCC's intent to withdraw or deny recognition. The letter will request explanation or correction of any apparent deficiencies, and for the TCB, test lab, or laboratory accreditation body to show cause it should be allowed recognition, within 30 days after the date of correspondence. The Commission directs OET to withdraw or deny recognition of any TCB, test lab, or laboratory accreditation body that fails, in OET's determination, to timely reply, to adequately explain or correct any deficiencies, or to show cause OET will issue a public notice of withdrawal of recognition of any TCB, test lab, laboratory accreditation body.

Other NPRM Proposals

TCB Post-market surveillance.
In the
EA Integrity NPRM,
the Commission invited comment on whether to revise the post-market surveillance rules, policies, or guidance to require surveillance of authorized equipment for compliance relating to the prohibition on authorization of “covered” equipment. In particular, the Commission sought comment on reasona

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/fr%3A2025-14970. Public record. Not legal advice.
