Thoughts on the FCC’s Third Report & Order
Or, why we recommend you stop worrying and learn to love SBOM
On July 23, 2026, the FCC released its Third Report and Order and Third Further Notice of Proposed Rulemaking (TR&O) in the equipment authorization security docket (FCC-26-50), adopted the day before. At 108 pretty technical pages, it’s tempting to ignore, but it has some interesting new rules and indicates a major change ahead in the next year.
The TR&O is split into two parts - an Order, addressing new regulations which will go into effect in a few weeks, and new policy proposals which the FCC is seeking comment on.
Two new regulations.
The Commission will no longer authorize a device that contains a logic-bearing hardware component made by a Covered List entity (see TR&O ¶14). In plain terms: a covered chipset inside someone else's airframe now taints the airframe. "Logic-bearing" is defined by borrowing the existing digital-device threshold — semiconductors, wireless chipsets, cryptographic elements, battery management systems, and motor controller boards are in; housings, brackets, passive components, and bare motors are out.
Online marketplaces are now on the hook for the drones they sell being properly licensed with the FCC (see TR&O ¶37). Platforms must display a device's FCC ID at the point of sale, with a two-tier structure: if a website is selling a drone it makes or has taken possession of, the website must validate that the FCC ID is valid and matches to the drone being sold. Third-party listings need only verify the FCC ID exists in the database but the party selling through the website has to certify accuracy. Note that small-sellers and used devices are exempt. This is a big deal when read in the context of the recent enforcement actions against Lyno Dynamics and Talos / Skyhigh. The FCC is creating pathways to hold sellers equally responsible for putting non-compliant drones into the U.S. market.
How to read the SBOM proposal. The Third FNPRM opens twenty topics, but the one with teeth is Hardware Bill of Materials (HBOM)/ Software Bill of Materials (SBOM) disclosure: every certification applicant would submit a signed hardware and software bill of materials identifying each component's producer, production location, and percentage of value by country, updated within 30 days of any change (see TR&O ¶139). The Commission ties this directly to its recent show-cause order against Odyssey Robot for allegedly faking U.S. manufacture of drones.
This is a clear sign-post that the FCC is coming around to the fact that software is the bigger risk, but harder to regulate. Adversary-built hardware running trusted software produces malfunction; trusted hardware running adversary-authored software can put lives at risk and open unknowable threat vectors. A bill of materials that captures firmware provenance and update pathways addresses the actual threat vector — manufacturing-stage and software compromise — rather than treating imported components as merely deficient.
The FCC is also considering splitting the Covered List into two parts, one for telecom and network infrastructure and one for UAS regulation (see TR&O ¶129). This is a great step forward if adopted. The Covered List was created specifically to combat enterprise-level network devices from foreign adversary nations. While it has been effectively leveraged for UAS, it is getting unwieldy to treat everything monolithically as more aggressive UAS regulations force nuance, and a lot of time has to be wasted drafting regulations that only touch one of the two areas but has to address the other half each time.
To help combat the aggressive efforts to make FCC filings that obfuscate ownership and responsibility for FCC violations, the FCC is proposing that applicants be required to list an American-based person who would be held liable for the purposes of the FCC certification (Third R&O at ¶227). This would be a significant step in the right direction on the heels of a lot of certification fraud. However, given the prevalence of filers listing the names of unaffiliated factories and personnel in their FCC filings, it would be critical that notarization or similar validation processes were put in place to affirm that the person is both real and has assented to be held liable.
The FNPRM also considers extending the component ban to all components and to software, - requiring full certification for entire Covered List sectors (see TR&O ¶147). A full component-level prohibition may be sound in a vacuum, but it should be the final regulatory step, sequenced after domestic capacity for critical components exists. The U.S. industrial base is mid-buildout; the sensible reading of this notice is that pacing matters as much as principle.
Finally, the FCC is seeking comment on whether ‘permissive changes’ should be allowed to be pushed as updates for equipment on the Covered List (see TR&O ¶187). While an interesting question, our sense is that this carve out would prove unwieldy. Fully vetting updates is not tenable for the FCC to do and it would be too easy to obfuscate unapproved or malicious modifications.
Software enforcement by next summer is the rational prediction. This is not the first time the Commission has laid definitional track before running enforcement over it. The 2025 Second Report and Order (FCC 25-71) built the toolkit — the procedure to limit existing authorizations, the wind-down mechanism, sharpened "produced by" language — and delegated authority to the Bureaus to apply it. That toolkit is exactly what surfaced as enforcement in 2026: the December 2025 addition of all foreign-produced UAS to the Covered List, the July 16, 2026 prohibition on importing and marketing covered gear from entities including Lyno Dynamics, Skyhigh Tech, and XAG, and the Odyssey Robot proceeding, which resulted in a full revocation of Odyssey’s authorizations on August 11, 2026, after its named U.S. assembler denied any relationship with the company.
These actions should be seen as the next, not the last, step in the FCC and the rest of the US Government getting increasingly aggressive in this sector.