Since December 2025, the FCC has added a whole new category of device to its Covered List roughly every three to four months. Uncrewed aircraft systems and UAS critical components were added on December 22, 2025. Consumer-grade routers followed on March 23, 2026. In July 2026, the FCC added advanced robotic devices and connected power inverters. The FCC’s July 28 Public Notice is the latest step in that progression.
Each addition does the same thing: a new model in that category cannot receive FCC equipment authorization, and without that authorization it cannot be imported, marketed, or sold in the United States.
Three additions in seven months is not a news cycle. It's a template running.
The important part of that template is not simply which products are being added. It is how the FCC is defining them.
The shift: from named companies to products
The Covered List comes out of the Secure and Trusted Communications Networks Act of 2019 (47 U.S.C. §§ 1601–1609, implemented at 47 C.F.R. § 1.50002). Equipment on it cannot receive FCC equipment authorization, and most electronic devices need that authorization before import, marketing, or sale in the US. It is a market-access gate administered by the agency that certifies radios.
Through 2024, every entry on the list named a company. The 2025–2026 wave listed something different: categories of product, defined by where the product was made.
That is the structural change, and it is the part that travels to any sector.
A list of companies is something you can check yourself against. A category defined by place of production is something you have to prove yourself out of.
The FCC does not make the underlying national-security determination itself. It implements determinations from qualifying national security authorities. For the July additions, those determinations came from a White House-convened executive-branch interagency body. The stated risks were supply-chain vulnerabilities that could disrupt US economic and national security, along with cybersecurity risks to critical infrastructure and the safety of US persons. (The FCC's July 28 notice)
There is also an important distinction: because these entries identify equipment by place of production rather than naming a company, producing covered equipment does not make you a covered entity. The listing is about the article, not about you.
“Foreign-produced” is the part that matters
For both July categories, “foreign-produced” means an article that would not qualify as a “domestic end product” under 48 C.F.R. § 25.101(a), the Buy American definition in the Federal Acquisition Regulation.
The test has two parts.
- First, the article must be manufactured in the United States.
- Second, the cost of its domestic components must exceed the applicable threshold. That threshold is 65% for items delivered in calendar years 2024 through 2028, rising to 75% from calendar year 2029.
That is why US final assembly is not enough.
Imagine a product assembled in the United States using a bill of materials dominated by foreign components. The fact that the final assembly happened here does not make the article a domestic end product. The relevant question is whether enough of the cost of the components incorporated into that product is domestic to clear the threshold.
This is a component-cost test, not a test of every cost involved in making the product. The FAR defines a component as an article, material, or supply incorporated directly into the end product. That is why the cost of assembly labor is not what gets you over the threshold. The question is the proportion of the component cost that is domestic.
The distinction matters because the threshold is going up. A product that satisfies the 65% test today faces a 75% threshold beginning in 2029.
There is one important qualification. The FCC borrows FAR's definition without FAR's procurement machinery around it, so some edge cases remain open questions for counsel rather than settled outcomes.
And the producer's nationality is not the test.
The July action is country-neutral. A US company manufacturing offshore is covered. A foreign-owned company whose article meets the domestic-content test is not.
That matters operationally. If you scope your response as “audit our suppliers in one country,” you can pass your audit and still fail the test. The question is what fraction of your component cost is domestic across the bill of materials.
What products are actually covered?
The two July additions are broad, but their definitions are specific.
Advanced robotic devices
An “advanced robotic device” is a mechanical mobile device — the FCC names autonomous mobile robots, humanoid robots, and quadrupeds — that is capable of locomotion, obstacle avoidance, navigation, or movement on the ground; operates at a distance from a human operator or supervisor on commands and/or sensor data; weighs more than 4.4 lbs including any ground or docking station; and contains all three of a sensor that perceives its environment, a component providing at least 200 kbps of network connectivity in either direction, and software controlling autonomous navigation or movement, perception, data collection, or remote command-and-control. The definition explicitly includes firmware and AI/ML model weights.
There are specific exclusions, including connected vehicles as defined at 15 C.F.R. § 791.301, rail-only vehicles, uncrewed aircraft under 47 C.F.R. § 88.5, unmanned underwater vehicles, medical devices under FD&C Act § 513, and fixed, stationary industrial and medical robots.
The regime is aimed at mobile, sensing, connected, autonomous machines. A bolted-down articulating arm is out. A twelve-pound inspection quadruped is in.
Connected power inverters
A “power inverter” is a bi-directional device or system converting DC to AC and back — including microinverters, string, central, hybrid, and battery-based inverters — that contains components enabling remote communication, control, sensing, data collection, or monitoring over Wi-Fi, cellular, Bluetooth, or similar.
Connectivity is the hook. Solar, storage, and EV and grid-edge inverters land here; the conversion function alone is not what pulled the category in.
What the Covered List actually restricts
The restriction lands on new models.
As of July 28, 2026, new models in a covered category cannot get FCC equipment authorization, which means they cannot be imported, marketed, or sold in the US. Existing authorized models may still be imported, marketed, and sold, and devices already purchased may still be used. (The FCC's July 28 Public Notice)
Software and firmware updates that maintain usability are also permitted for previously authorized covered equipment under FCC waivers through at least January 1, 2029. The FCC first established those protections for UAS and routers and then extended and expanded the waiver in May 2026. (The FCC's May 8, 2026 waiver)
There is no effect on sale to, or use by, the federal government or federal agencies.
The practical bite, based on the UAS and router precedent, is subtler than a simple ban: an already-authorized model also cannot take a change that would require a new or amended authorization. For a hardware company that regularly ships revisions, that can effectively freeze the product line.
There is one exit. A producer can escape the listing if the Department of War, for robots, or the Department of War and/or DHS, for inverters, transmits a determination to the FCC that a device or class of devices does not pose unacceptable risks. Applications are due by January 1, 2028.
The certification problem
This is the part of the new framework that matters even if none of the current categories is yours.
An applicant for FCC equipment authorization must certify that its device is not covered equipment and must have sufficient evidence to support that certification. The FCC does not prescribe a specific set of documents or an evidence standard. (FCC FAQs on the robots and inverters additions)
That creates a simple problem.
The obligation is clear: make the certification and have evidence behind it.
What is not clear is what “sufficient” evidence looks like.
There is no standard checklist that says a particular supplier letter, database record, bill of materials, or other artifact is enough. The company making the certification has to decide what evidence is sufficient to support it.
If that shape sounds familiar, it should. It is the same one as the Declaration of Conformity under the Commerce Department's connected-vehicle rule: an executive signature attesting to supply-chain facts, with supporting documentation required to exist and no standard prescribed for what it has to be. We walked through what Rule 791D bans, who it reaches, and the model-year timeline when that rule came into force.
And that company is often the party furthest from the underlying facts.
A robotics company may know the machine it builds, the firmware it flashes, and the suppliers it buys from. That does not necessarily mean it knows where the components inside those suppliers' products were made or what their component costs are.
That is why this is not fundamentally a paperwork problem.
It is an inventory problem.
Why the inventory is so difficult
The fact being certified spans the bill of materials. Domestic content is not something you can reliably determine by looking at the finished product or asking where the final assembly took place. You need to know what is actually in the product and where those components came from.
And the usual supplier questionnaire has an obvious weakness: it is only as good as the supplier's knowledge of what is inside their product. An attestation tells you what someone believes. It does not tell you what is true — a distinction we have written about at length, because the supplier who turns out to be wrong is almost never the one lying.
The supplier tells you where its product was made. But where were the components inside it made? Which version of the component is actually in your product? Has anything changed since the last time you asked?
The deeper issue is the same one that sits underneath modern supply-chain security generally: integrity.
For machines that move and make decisions next to people, you have to be able to trust what hardware and software are actually inside.
As Block Harbor CEO Brandon Barry put it in June 2026, “it should not be this hard to answer questions like do you know if an adversarial nation has software and hardware in your vehicle?”
That was a diagnosis, not a complaint.
The provenance regimes are not asking for better paperwork. They are asking for the inventory the paperwork was always supposed to be describing.
What actually closes the gap
The answer is fairly simple, even if doing it well is not.
Build a structured inventory of the real components in the product. Attach every provenance signal you have to the component it belongs to. Then put a second, independent check underneath the supplier's word rather than relying on it alone.
That is what VSEC Core is for.
Core is the asset and risk layer of our platform. It models a product the way these rules read it — as a tree of assets running from the whole machine down to the component and the feature — and it attaches every finding to the specific asset it belongs to rather than to a document. That structure is what makes provenance answerable across a product line instead of one device at a time.
We built that spine for connected vehicles, where OEMs face the same question under a different rule. Firmware scans feed the asset tree and supplier attestations sit alongside them, with the output being the evidence set behind a Declaration of Conformity. It is delivered and running in a customer environment today. We have also written up how a firmware scan recovers country-of-origin signal from a binary.
Why this transfers
A car is an autonomous robot. It just has wheels instead of legs.
From a cybersecurity standpoint, the hardware presents the same class of problem, and a mobile robot is far closer to a connected vehicle than either is to traditional IT. We can put a device on the bench (or build an asset tree from publicly available information), pull it apart, and produce component- and firmware-level provenance and vulnerability findings because that is the same engineering we already do on vehicles.
The claim is about the problem, which we know, and the work, which we do.
What comes next?
Which category is next is a live question, not a settled list.
The FCC has already sought comment on adding Chinese connected vehicles to the Covered List. That would put the FCC regime and the Commerce rule in the same lane rather than in deliberately separate ones.
The other thing to watch is the domestic-content threshold itself. It is 65% through calendar year 2028 and rises to 75% beginning in calendar year 2029. A product that clears the test today can fail it later without a single supplier changing anything. (48 C.F.R. § 25.101)
The larger pattern is what matters.
These determinations can arrive with days of notice rather than the multi-year runway a type-approval milestone gives you. The work they demand — a component-level inventory with provenance attached to it — takes longer than the notice period.
That is the argument for starting the inventory before a determination has your category's name in it.
The inventory is useful the day you build it, and one inventory can answer all of these rules at once.
If you want to see what a component-level provenance inventory looks like against your own firmware rather than in the abstract, reach out and we will stand up a workspace and run one.
Stay Connected with Block Harbor
Keep up with the latest in vehicle cybersecurity through our specialized newsletters. Choose the option that best fits your interests and role.
Thank you for your submission!
Read More
Explore more automotive cybersecurity insights from our experts. Discover best practices, case studies, and emerging trends to strengthen your organization's security posture.

The CRA doesn't touch type-approved cars. It does reach the machinery around them, and its reporting clock starts September 11, 2026 on units already in the field.

Most product-security tools start as a slide, then get retrofitted onto real engineering work. We built VSEC Core the other way — out of years spent doing risk and asset tracking by hand inside customer teams. Here's the honest picture of what's built, what's still beta, and why the order matters.

Most OEMs collect supplier attestation letters and call it compliance. The problem isn't dishonest suppliers — it's suppliers who genuinely don't know what's in their own firmware. Here's why an empty attestation satisfies the paperwork and proves nothing, and what secondary verification actually changes.
.png)
While continuous monitoring certainly can mean 24/7 monitoring and response, it doesn't necessarily have to mean 24/7 monitoring and response. It should be aligned to your organization's risk appetite and should match the overall product security incident response maturity.
Try Block Harbor Today
Start protecting your vehicles with the same platform the world’s best hackers and defenders use.
