Buy the robot from China. Flash your own firmware onto it. Put your name on the chassis and sell it as a US product. That model is common among self-described US robotics companies, and it worked for some time. It does not work anymore. The FCC added advanced robotic devices to its Covered List on July 28, 2026, and a robot in that category cannot get a new model through FCC equipment authorization. The reason is more specific than "the government is cracking down on China."
The FCC announced both additions, advanced robotic devices and connected power inverters, together. Equipment on the Covered List cannot receive FCC equipment authorization, and most electronic devices need that authorization before they can be imported, marketed, or sold in the United States. This is not the FCC's first categorical addition: uncrewed aircraft systems went on the list in December 2025, and routers followed in March 2026 (we walked through that pattern separately). The one way off the list is a Conditional Approval, transmitted to the FCC by the Department of War for robots and by DoW and/or DHS for inverters, with applications due January 1, 2028.
That filing is not a security questionnaire. It is an origin audit. It asks for a component-level bill of materials, country of origin for every part and for the design, country of origin for all onboard software and firmware, a quantitative country-concentration analysis, and a time-bound plan to move production to the US. Counsel can write the document. Nobody can write an inventory the company has never built. That gap is the whole problem, and the deadline that closes it does not move.
First: the FCC's Robot Rule Is Country-Neutral
The Covered List used to be a list of companies. Through 2024 it held 12 named entities, all China- or Russia-linked. The 2025–2026 additions changed the unit of listing from the entity to the product category, defined by place of production. The FCC's own FAQ is explicit that the action is country-neutral: the producer's nationality is irrelevant. A US company manufacturing offshore is covered. A Chinese-owned company whose product meets the domestic-content test is not.
The business model in the opening paragraph matters because it is common, not because it is Chinese. If your bill of materials is Vietnamese, Mexican, or German, you are in exactly the same position.
"Foreign-Produced" Is a Domestic-Content Test, Not an Assembly Test
For both new categories, foreign-produced means any article that would not qualify as a domestic end product under 48 C.F.R. § 25.101(a), the FAR / Buy American definition. Two parts: the article must be manufactured in the United States, and its domestic content, the cost of its domestic components, must exceed a threshold. That domestic-content threshold is 65% for items delivered CY2024 through CY2028, rising to 75% from CY2029.
Read the second half again, because that is where the shortcut dies. The test measures domestic component cost. Firmware is not a component cost. Final assembly is not a component cost. You can design the product in California, write every line of its software in Michigan, and screw it together in Texas, and if the parts came from somewhere else, you still have a foreign-produced device.
This is stricter than the workaround the robotics market has been leaning on. Becoming the "OEM of record" through US final assembly does move something real: it moves who holds the attestation and the liability, the same way importer-of-record liability works for connected vehicles. What it does not do is confer domestic status. The company that assembled the robot now owns a certification it cannot substantiate.
One caveat. The FCC borrowed FAR's definition without FAR's procurement context, so how the surrounding FAR machinery travels is untested, including the domestic-content waiver for commercial off-the-shelf items at § 25.101(a)(2)(i). Treat the two-part test as the operative rule and treat the edge cases as open.
What the FCC Covered List Actually Restricts
- New models cannot get FCC authorization, and therefore cannot be imported, marketed, or sold in the US.
- Existing authorized models may still be imported, marketed, and sold. Devices already purchased may still be used.
- Under the UAS and router precedent, the practical bite on an authorized model is that it cannot take a change requiring a new or amended authorization. The product line freezes.
- Software and firmware updates that keep devices usable are permitted under an FCC waiver.
- No effect on sale to, or use by, the federal government.
- Because these entries identify equipment by place of production rather than by entity, producing covered equipment does not make you a covered entity. You do not inherit the entity-directed obligations, such as § 2.903(d) affiliate reporting.
So this is a roadmap problem. Whatever is authorized today keeps selling. What you cannot do is ship the next model, or meaningfully change the current one.
What the FCC's Conditional Approval Actually Asks For
The Annex A guidance, structurally identical for robots and for inverters, requests three blocks of information.
1. Corporate structure. Legal name and jurisdictions. The full ownership graph including parents, subsidiaries, affiliates, and joint ventures. Every beneficial owner at 5% or more. Board members and executives with nationality and country of residence. Any foreign government ownership, control, influence, financing, or material support, including arrangements that let a foreign person or government influence operations, decisions, or access to technology.
2. Manufacturing and supply chain. A detailed bill of materials. Country of origin for every component and for the design. The entities that own the IP and the entities that push software updates. A justification for why the device is not made in the US and whether alternatives exist. Locations of manufacturing, final assembly, and testing. Country of origin for all onboard software and firmware. A quantitative supply-chain concentration assessment by country, expressed as both percentage of value and percentage of production volume. And single points of failure, including sole-source suppliers, their country, and your contingency plans.
3. US manufacturing and onshoring. A time-bound plan to establish or expand US manufacturing. A named point of contact reporting status quarterly. Your existing US assembly percentage, headcount, and facilities. Committed and planned capital over one to five years, with hiring, square-footage, and investment milestones. Progress against any onshoring plan submitted under a prior Conditional Approval.
Mechanics worth knowing: filings go to conditional-approvals@fcc.gov as machine-readable PDF, may cover a class of devices rather than a single model, may be filed by any entity involved in producing the device, and must be certified by an authorized corporate officer who then has to promptly disclose material changes. A knowing violation or material misrepresentation terminates the approval and permanently bars re-application. Decisions are discretionary and final.
Notice What Is Not in There
No TARA. No penetration test. No CSMS. No secure-development evidence of any kind.
The national security determinations behind both listings cite cyber risk: manipulation of a robot's data and its physical operation, surveillance of Americans, remote commandeering. For inverters: remote shut-off, data exfiltration, and foreign remote access compounding as inverter-based resources proliferate on the grid. Then the government asks for supply-chain transparency instead of security engineering.
We sell security engineering, so we could complain about that. We won't, because the request is coherent. For a device that moves and senses in the physical world, you cannot reason about any of those risks until you know what is inside it and who controls it. Across the CIA triad, integrity is the property that matters most here. As our CEO Brandon Barry puts it, it should not be this hard to answer whether an adversarial nation has software and hardware in your vehicle.
The Data Problem Inside the Filing
Block 1 is a corporate-records exercise; your general counsel already holds most of it. Block 3 is a business commitment; your CFO and COO own it. Block 2 is the one that stops companies, and it stops them for a reason that has nothing to do with law. It asks for a component- and firmware-level inventory that most product companies have never built.
Four lines in particular cannot be answered from a supplier survey:
- Country of origin for every component. Not your Tier 1's country. The component's.
- Country of origin for all onboard software and firmware. Including the parts a supplier shipped you as a binary.
- Concentration by country as both percentage of value and percentage of production volume. Two denominators, two datasets, both tied back to the same BOM.
- Sole-source single points of failure with contingency plans. Which requires knowing you have them.
And the survey answers you would use do not hold up. In a business-development call in July 2026 with a company deploying patrol-and-inspection quadrupeds at pilot scale, the pattern was plain: everyone claims they have no Chinese content, while the supply base admits it supplies everyone. Usually that is not fraud so much as a question asked at a level of the chain that cannot see the answer. For that buyer, the live compliance pain was component sourcing under NDAA rules and sector-specific rules like FERPA for school deployments; cybersecurity was a concern eventually, not a blocker now. Which is exactly how automotive started.
Two specific failure modes, both of which we have watched play out in connected vehicles:
Attestation with no evidence standard behind it. Equipment authorization applicants must certify their device is not covered equipment and must "have sufficient evidence" to support that certification, and the FCC prescribes no specific documentation or evidence. We have made this argument before: a signed attestation states what someone believes; a scan states what is actually there. The Commerce Department's connected-vehicle rule has the identical structural hole in its Declaration of Conformity, which we wrote up separately; the FCC narrows the same gap to a corporate officer's certification instead of a CEO's.
"Turned off" is not "absent." Suppliers who tell you there is no Chinese code in a module often mean the Chinese code is deactivated for the non-China market. The same binary ships worldwide; a region flag brings the code alive in one market and leaves it dormant everywhere else. Dormant code is still onboard software the filing has to attribute, and a filing that says otherwise is a misrepresentation an officer signed.
Where to Start, If You Build Robots
Pick one model. Not the portfolio.
- Build the asset tree down to the component. Product, component, feature, with the relationships between them. Every later answer hangs off this, including the concentration math.
- Get the binaries, not the questionnaires. Put origin requirements in the RFP, and revise your supplier agreements for the IP transparency that gets you the binary. Inspect the firmware; do not ask the supplier what is in it.
- Reconcile declared against detected. Put the supplier's statement and the scan result side by side on the same asset and treat every disagreement as an item to close, not an argument to win. Most disagreements are honest ignorance, and they still have to be resolved before an officer signs.
- Do the concentration math off that same BOM. Percentage of value and percentage of production volume, from the inventory you just built, not from a parallel spreadsheet that will diverge from it within a quarter.
- Write down the nulls. Some firmware won't yield an SBOM. Heavily custom or proprietary code comes back as a documented null result. A recorded gap is defensible under an officer's certification. A blank you quietly filled in is not.
None of that is throwaway work. The same inventory answers the Conditional Approval, the Commerce rule if you also build vehicles, and the next customer whose lawyer told them to ask. The deadline is the forcing function. The inventory is the asset.
January 1, 2028 is the runway's end. It runs out faster if you spend the front half discovering you need the inventory.
If you want that evidence produced by someone whose report your customer will accept, rather than your own team's word for it, send us one firmware image. That is the whole ask: one image off one product, and we will tell you what is in it and where it came from.
Stay Connected with Block Harbor
Keep up with the latest in vehicle cybersecurity through our specialized newsletters. Choose the option that best fits your interests and role.
Thank you for your submission!
Read More
Explore more automotive cybersecurity insights from our experts. Discover best practices, case studies, and emerging trends to strengthen your organization's security posture.

A top-5 OEM's diagnostic tool shipped its authentication logic to every machine that ran it. What it took to move the privileged commands off the endpoint.

Three new categories in seven months. The FCC's Covered List now gates US market access on where a device's components come from, not where it was assembled.

The CRA doesn't touch type-approved cars. It does reach the machinery around them, and its reporting clock starts September 11, 2026 on units already in the field.

Most product-security tools start as a slide, then get retrofitted onto real engineering work. We built VSEC Core the other way — out of years spent doing risk and asset tracking by hand inside customer teams. Here's the honest picture of what's built, what's still beta, and why the order matters.
Try Block Harbor Today
Start protecting your vehicles with the same platform the world’s best hackers and defenders use.
