Home Wiki

FCC foreign-made router restrictions

Last updated View on consumerrights.wiki ↗

Contents9
  1. At a glance
  2. Background
  3. What the rule does
  4. Software update cutoff
  5. TP-Link and the Commerce Department proposal
  6. Security background
  7. Reception
  8. See also
  9. References

On March 23, 2026, the Federal Communications Commission added all consumer-grade routers produced in foreign countries to its Covered List, which bars new foreign-made router models from FCC equipment authorization & therefore from being imported, marketed, or sold in the United States.[1][2] The rule does not restrict routers Americans already own; previously authorized models can still be used, bought, & sold.[2] Those existing foreign-made routers keep receiving security & firmware updates only under a temporary FCC waiver, whose cutoff the agency's Office of Engineering and Technology extended from March 1, 2027 to at least January 1, 2029 on May 8, 2026.[3][4]

At a glance

  • Foreign-made routers already in American homes keep working, but lose FCC-permitted security and firmware updates once a temporary waiver expires, a cutoff the FCC extended from March 1, 2027 to at least January 1, 2029.[3][4]
  • New foreign-made router models can no longer receive FCC equipment authorization, so they cannot be imported, marketed, or sold in the United States.[2]
  • The rule is origin-based: it covers routers produced in a foreign country regardless of the producer's nationality, & the main target, TP-Link, is U.S.-headquartered and accounts for about 65 percent of U.S. home & small-business routers.[2][5]
  • A foreign-made router can stay on the market by winning a Conditional Approval from the Department of War or the Department of Homeland Security.[2][6]
  • The listing carries out a national security determination by a White House-convened Executive Branch body; the FCC cannot add equipment to the Covered List on its own.[1]

Background

The Covered List is the FCC's roster of communications equipment & services deemed to pose an unacceptable risk to the national security of the United States or the safety and security of U.S. persons.[1] Under the Secure and Trusted Communications Networks Act of 2019, the Commission can update the list only at the direction of national security authorities & cannot add equipment on its own.[1][6]

The router listing followed a national security determination transmitted to the FCC on March 20, 2026 by a White House-convened Executive Branch interagency body.[6][7] That determination found two risks in foreign-produced routers. The first is a supply-chain risk:

a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense.

[1] The second is a cybersecurity risk to critical infrastructure:

a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.

[1] FCC Chairman Carr framed the listing as the FCC carrying out an Executive Branch decision rather than acting on its own:

I welcome this Executive Branch national security determination, and I am pleased that the FCC has now added foreign-produced routers, which were found to pose an unacceptable national security risk, to the FCC's Covered List.

[1]

When the FCC first published the Covered List in March 2021, it named specific companies whose equipment was found to pose a risk.[6] The router entry, like the December 2025 addition of foreign-made drones, instead covers an entire category of devices regardless of the manufacturer.[6] Damon Small, a board director at the security firm Xcape, described the change to ClearanceJobs as a move away from entity-based listing:

a massive expansion of U.S. tech protectionism, moving beyond specific Chinese entities like Huawei or ZTE to a blanket ban on all foreign-produced consumer routing hardware.

[8]

What the rule does

Covered equipment is banned from receiving new FCC equipment authorizations, & most consumer devices need that authorization before they can be imported, marketed, or sold.[2] New foreign-made router models therefore cannot enter the U.S. market, while models the FCC previously authorized may still be imported, sold, & used.[2] The FCC's FAQ answers the question of whether consumers face any restriction on using covered routers with a single word: No.[2]

How the rule treats new versus already-owned foreign-made routers
New foreign-made models Foreign-made routers already owned
FCC equipment authorization Barred from new authorization[2] Previously authorized; unaffected[2]
Import, marketing, & sale Cannot be imported, marketed, or sold[2] Previously authorized models may still be sold[2]
Consumer use Not on the market No restriction on use[2]
Security & firmware updates Not on the market Allowed under a waiver until at least January 1, 2029[3]

The restriction turns on where a router is produced, not on who makes it. The Covered List entry reaches:

routers produced in a foreign country, regardless of the nationality of the producer, except for routers that have been granted a Conditional Approval by DoW or DHS.

[2] A router designed in the United States but manufactured abroad is covered, while a router produced in the United States is not covered merely because it contains foreign-made components.[2] The FCC adopted the definition of routers from the National Institute of Standards and Technology's Internal Report 8425A, which covers consumer-grade networking devices primarily intended for residential use that can be installed by the customer.[2]

A foreign-made router can escape the Covered List through a Conditional Approval from the Department of War (DoW) or the Department of Homeland Security (DHS).[2][6] According to the law firm DLA Piper, Conditional Approvals last up to 18 months & require detailed disclosures about corporate structure, manufacturing & supply-chain information, & a time-bound plan to establish or expand U.S.-based manufacturing.[6]

Software update cutoff

Without a waiver, adding routers to the Covered List would have blocked even routine software changes to devices already in people's homes, because the rules that bar new authorizations also bar Class I permissive changes, the routine software or firmware updates an already-approved device receives.[7] To prevent that, OET issued a blanket waiver so previously authorized routers could keep receiving software and firmware updates that mitigate harm to U.S. consumers, including updates that patch vulnerabilities and facilitate compatibility with different operating systems.[3] The waiver first ran at least until March 1, 2027.[7]

On May 8, 2026, OET extended the waivers on the prohibitions in 47 CFR §§ 2.932(b) and 2.1043(b) to at least January 1, 2029.[3] The FCC said that cutting off updates could leave millions of existing devices exposed to unpatched flaws.[4] Matt Wyckhouse, founder & CEO of the security firm Finite State, told ClearanceJobs that unsupported routers become the problem:

When they stop receiving updates, known vulnerabilities remain exposed, attackers gain durable footholds, and consumers are left with equipment they cannot realistically secure on their own.

[4]

Page one of FCC Public Notice DA 26-454, released May 8, 2026, extends the waiver of the prohibitions in 47 CFR sections 2.932(b) and 2.1043(b) at least until January 1, 2029.[3]

The categorical rule was preceded by a narrower fight over a single company. On October 30, 2025, The Washington Post reported that the Commerce Department had proposed barring future sales of TP-Link routers & that more than a half-dozen federal departments & agencies backed the proposal over the vendor's ties to mainland China.[10] Engadget reported that a months-long interagency process involving the Departments of Homeland Security, Justice, & Defense considered the move.[11]

TP-Link routers dominate the U.S. market. Reason reported that the company accounts for 65 percent of the home & small-business wireless router market.[5] TP-Link's own figure is 36 percent, while former U.S. cybersecurity official Rob Joyce testified to Congress that its share was roughly 60 percent.[11] The company is U.S.-headquartered: founded in Shenzhen, China, it split in 2022 into TP-Link Systems, based in Irvine, California, & TP-Link Technologies, based in China.[5] A TP-Link spokesperson rejected the proposed ban in a statement to Engadget:

any adverse action against TP-Link would have no impact on China, but would harm an American company.

[11]

The headline of Reason's November 4, 2025 report on TP-Link reads This Company Makes 65 Percent of the Wi-Fi Routers in U.S. Homes. The Government Wants To Ban Them.[5]

Security background

The FCC's fact sheet said foreign-made routers were also involved in the Volt, Flax, and Salt Typhoon cyberattacks.[1] On September 18, 2024, the Justice Department announced that a court-authorized operation had disrupted a botnet of more than 200,000 consumer devices in the United States and worldwide, including small-office/home-office routers, IP cameras, digital video recorders, & network-attached storage devices.[12] The Justice Department attributed the botnet to Integrity Technology Group, a Beijing company tracked in the private sector as Flax Typhoon.[12]

The Justice Department's September 18, 2024 announcement describes a court-authorized operation that disrupted a botnet of more than 200,000 consumer devices tied to Integrity Technology Group, tracked in the private sector as Flax Typhoon.[12]

Reception

Two security professionals interviewed by ClearanceJobs questioned whether the rule can be met today and what it would cost consumers. Matt Wyckhouse of Finite State told ClearanceJobs that no current product satisfies the standard:

Effectively, the FCC would ban all new routers, because there are no domestic routers that meet that standard today. No one can clear the bar right now.

[8]

Wyckhouse also told ClearanceJobs that the shift would raise prices, saying This will definitely increase prices as companies invest in U.S. manufacturing or retool existing operations.[8] Paul Bischoff, a consumer privacy advocate at Comparitech, told ClearanceJobs the measure is effectively just a more complicated tariff whose goal is to economically hurt foreign router makers and protect domestic ones like Cisco.[8]

See also

References

  1. 1.0 1.1 1.2 1.3 1.4 1.5 1.6 1.7 1.8 "FACT SHEET: FCC Updates Covered List to Include Foreign-Made Consumer Routers, Prohibiting Approval of New Models" (PDF). Federal Communications Commission. 2026-03-23. Retrieved 2026-07-18.
  2. 2.00 2.01 2.02 2.03 2.04 2.05 2.06 2.07 2.08 2.09 2.10 2.11 2.12 2.13 2.14 2.15 2.16 "FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries". Federal Communications Commission. 2026-05-12. Retrieved 2026-07-18.
  3. 3.0 3.1 3.2 3.3 3.4 3.5 "Office of Engineering and Technology Announces Extension and Expansion of Waiver of Prohibitions on Certain Software and Firmware Permissive Changes to Certain Covered UAS, UAS Critical Components, and Routers (DA 26-454)" (PDF). Federal Communications Commission, Office of Engineering and Technology. 2026-05-08. Retrieved 2026-07-18.
  4. 4.0 4.1 4.2 4.3 Suciu, Peter (2026-05-13). "FCC Extends Router Ban Deadline, But Warns of a Bigger Cybersecurity Threat". ClearanceJobs. Retrieved 2026-07-18.
  5. 5.0 5.1 5.2 5.3 Lancaster, Joe (2025-11-04). "This Company Makes 65 Percent of the Wi-Fi Routers in U.S. Homes. The Government Wants To Ban Them". Reason. Retrieved 2026-07-18.
  6. 6.0 6.1 6.2 6.3 6.4 6.5 6.6 "FCC prohibits sale and authorization of foreign-made routers in further Covered List expansion: Key implications". DLA Piper. 2026-04-08. Retrieved 2026-07-18.
  7. 7.0 7.1 7.2 "FCC Adds Foreign-Produced Consumer-Grade Routers to Covered List". Wiley Rein LLP. 2026-03-24. Retrieved 2026-07-18.
  8. 8.0 8.1 8.2 8.3 Suciu, Peter (2026-04-01). "Foreign-Made Routers Under Fire: New FCC Rule Could Shake Up Your Home Internet". ClearanceJobs. Retrieved 2026-07-18.
  9. "FAQs on Recent Updates to FCC Covered List Regarding Routers Produced in Foreign Countries". Federal Communications Commission. 2026-05-12. Archived from the original on 2026-07-10. Retrieved 2026-07-18.
  10. Menn, Joseph (2025-10-30). "U.S. agencies back banning popular home WiFi device, citing national security risk". The Washington Post. Retrieved 2026-07-18.
  11. 11.0 11.1 11.2 Revilla, Andre (2025-10-30). "US government is getting closer to banning TP-Link routers". Engadget. Retrieved 2026-07-18.
  12. 12.0 12.1 12.2 "Court-Authorized Operation Disrupts Worldwide Botnet Used by People's Republic of China State-Sponsored Hackers". U.S. Department of Justice, Office of Public Affairs. 2024-09-18. Retrieved 2026-07-18.