Cameras and infrastructure
The FCC component rule: what changes for safety cameras on October 13
From October 13, 2026 the FCC will not authorize new devices with logic-bearing parts from Covered List firms. What changes for safety cameras and what to ask.
By LIPAI WANG · Updated · 9 min read · 11 sources
On October 13, 2026, a new Federal Communications Commission (FCC) rule takes effect that reaches inside the devices safety teams buy. The FCC will no longer authorize a new device that contains a logic-bearing hardware component made by a company on its Covered List, where the whole device would have been barred had that company made it [1]. The FCC itself calls this closing a "component-part loophole" [1].
For EHS (environment, health and safety) buyers, the practical effect sits in cameras, network video recorders (NVRs), edge AI boxes and any connected sensor. This article explains what the rule changes, what it leaves alone, and what to ask vendors. For the country-by-country position on Hikvision and Dahua, see Hikvision and Dahua restrictions by country.
What the rule says
The rule was published in the Federal Register on September 11, 2026 as the FCC's Third Report and Order in ET Docket 21-232 (91 FR 57798) and is effective October 13, 2026 [1]. It builds on a 2023 rule that stopped new equipment authorizations for equipment on the Covered List, which named equipment from Huawei, ZTE, Hytera, Hikvision and Dahua [2]. Hikvision and Dahua video surveillance and telecommunications equipment is listed only to the extent it is used for certain purposes: public safety, security of government facilities, physical security surveillance of critical infrastructure and other national security purposes [3].
The new rule has five parts that matter to buyers [1]:
- Components. A device cannot be authorized if it incorporates a logic-bearing hardware component produced by a Covered List entity, where the device would itself be barred had that entity produced it.
- Definition. A "logic-bearing hardware component" is any device, system, module, sub-assembly, integrated circuit or other physical component that generates and uses timing signals above 9,000 pulses per second and uses digital techniques, or that uses radio frequency energy to process, store or transfer data. Purely mechanical or passive parts are excluded, such as housings, fasteners, resistors, wiring and plain battery cells.
- Changes by listed companies. A Covered List entity that wants to change any of its equipment must apply for full recertification instead of using the lighter permissive-change process.
- Online marketplaces. Marketplaces must display a device's FCC ID at the online point of sale.
- Critical infrastructure. The FCC narrowed its definition of "critical infrastructure" as used on the Covered List.
What it does not do
Much of the confusion around this rule comes from reading it as a ban on using Chinese cameras. It is not.
- It is prospective. The rule applies to new equipment authorization applications and does not affect previously authorized equipment [1]. Applications pending on October 13 are exempt unless they are later amended to add, substitute or change a logic-bearing component [1].
- It does not order removals. Nothing in the rule requires a site to take down installed cameras [1]. The FCC's 2025 Second Report and Order created a separate process to limit earlier authorizations, which can cut off import and marketing of a model, but it does not restrict continued use [4]. The FCC has already used it: since July 16, 2026, previously authorized equipment added to the Covered List in 2024 or earlier, including Hikvision and Dahua video surveillance equipment for the covered purposes, can no longer be imported or marketed [11]. That order paused the ban for physical security surveillance of critical infrastructure until the FCC defined the term, and said the ban would apply once a definition took effect [11]. The definition in this rule takes effect on October 13, so from then the pause ends [1][11]. Equipment that buyers already own can still be used [11].
- It does not cover software or firmware. The FCC declined, for now, to extend the ban to software or firmware [1].
- It does not cover every component. The FCC also declined, for now, to ban all components from Covered List entities, or components from any company controlled by a foreign adversary that is not on the list. It kept the record open on both questions [1].
- It only reaches company-based listings. The component ban applies to parts made by entities named on the Covered List. It does not apply to entries based on where a product is made unless the producer is itself listed [1].
The narrower definition of critical infrastructure
Hikvision and Dahua equipment is covered only when used for listed purposes, and one of those purposes is critical infrastructure [3]. After a partial remand by the US Court of Appeals for the D.C. Circuit, the FCC dropped its earlier "connected to" wording, which the court found "unjustifiably broad" [1]. Critical infrastructure now means systems and assets used in the 16 critical infrastructure sectors identified by the Department of Homeland Security when they are used to provide any of the 55 National Critical Functions [1].
For a safety manager, this changes the screening question. It is no longer enough to ask whether a site is connected to a critical sector. The question is whether the system is used to provide one of the 55 functions. Utilities, ports, chemical plants and food production sites should document that assessment with their legal or security team. This is our reading of the definition, not legal advice.
Where logic-bearing parts sit in a safety system
In our analysis, almost every active part of an AI video safety system meets the definition, because the definition covers anything that processes digital signals or uses radio for data. Typical places to look:
| System part | Logic-bearing parts to ask about | Why it matters |
|---|---|---|
| IP camera | Image signal processor, AI system-on-chip, network chip, main board | On-camera analytics depend on the camera's chip |
| NVR or video recorder | Main board, storage controller, network chip | Recorders are often white-label products |
| Edge AI box or on-site server | AI accelerator or GPU module, main board | Most safety analytics runs here rather than in the camera |
| Wireless sensors, tags and wearables | Radio modules, microcontrollers | The definition includes parts that use radio energy to transfer data [1] |
| Housings, mounts, cables, batteries | None | Passive and mechanical parts are excluded [1] |
The rule applies through the FCC authorization of the finished device [1]. That is why a vendor's FCC ID and its supply chain answers matter more after October 13 than a brand name on the box. For how these parts fit together, see the guide chapter on how AI video safety works and our comparison of existing cameras versus new AI cameras.
White-label risk
Many safety technology vendors sell cameras, recorders or edge boxes that another company designed or built. A device sold under a US or European brand can still contain a board or module from a Covered List entity. Under the new rule, a new device of that kind cannot be authorized [1].
The FCC is already looking further. A further notice of proposed rulemaking published on August 7, 2026 asks about white labeling, hardware and software bills of materials, broader bans on devices with Covered List components or software, term limits on authorizations, and splitting the Covered List into producer-based and production location-based categories [5]. Comments closed on September 8 and replies on September 21, 2026 [5]. None of these proposals is law yet, but each would raise the value of documentation you collect now.
Online marketplaces and FCC IDs
The rule also clarifies that the FCC's marketing rules apply to online marketplaces that market unauthorized equipment [1]. Marketplaces must display a device's FCC ID at the point of sale. Those that sell their own devices, or have physical access to or title over a seller's device, must comply from March 1, 2027. Those that rely on third-party sellers' certifications must comply from June 1, 2027 [1]. Listings for used devices, listings by sellers that are not high-volume sellers, and listings published before October 13 that are not later updated are excluded [1].
For buyers who source spare cameras or recorders online, the FCC ID becomes a practical check. Record it for every device and compare it with what the vendor supplied.
Federal contracts and grants: the separate rules
The FCC rule controls what can be authorized. Two older rules control who may buy or use covered equipment, and they matter more for many industrial sites.
- Section 889 (FAR 52.204-25). Federal agencies may not procure covered telecommunications or video surveillance equipment, and since August 13, 2020 they may not contract with companies that use it [6]. For Hikvision, Dahua and Hytera, the coverage is limited to the listed public safety, government facility, critical infrastructure and national security purposes [6].
- 2 CFR 200.216. Recipients of federal grants and loans may not use those funds to buy covered equipment [7].
If your company holds federal contracts, or a safety camera project is grant-funded, these rules can require you to avoid covered equipment even where the FCC rule does not.
What other countries restrict
No other jurisdiction in our research has a component rule like this one. The closest measures target public-sector use:
- United Kingdom. In November 2022, government departments were told to stop deploying cameras from companies subject to China's National Intelligence Law on sensitive sites, and not to connect such equipment to core networks [8].
- Canada. On June 27, 2025, the government ordered Hikvision Canada Inc. to wind up its operations under the Investment Canada Act [9].
- European Union. The Cyber Resilience Act regulates the security of products with digital elements regardless of brand. Reporting of actively exploited vulnerabilities and severe incidents started on September 11, 2026, and the main obligations apply from December 11, 2027 [10].
How these rules shape which vendors can sell where is covered in our vendor-by-country matrix.
A parts statement to ask for
A parts statement is a short written answer from the vendor, attached to the purchase order or contract. Ask for it for every camera, recorder, edge box and connected sensor:
- The FCC ID of each device model supplied, and the date it was authorized.
- The makers of the main logic-bearing components: main board, AI chip or module, network and radio modules.
- A statement that none of those components was produced by an entity on the FCC Covered List.
- Whether any device is white-label, and if so, who designed and built it.
- A commitment to tell you if a component source changes, and what the vendor will do if a model loses its authorization.
- For federal contractors and grant-funded projects, confirmation that the supply meets FAR 52.204-25 and 2 CFR 200.216 [6][7].
Use it alongside our questions to ask AI safety vendors and the procurement steps in the buying and piloting chapter.
What to do next
- Inventory installed cameras, recorders and edge boxes with brand, model and FCC ID. Nothing has to come down because of this rule, but you need the list for future replacements.
- Add the parts statement above to every request for proposal (RFP) and purchase order issued after October 13, 2026.
- Ask white-label suppliers who designed and built each device, and get the answer in writing.
- If a site may provide one of the 55 National Critical Functions, document whether its cameras serve that function, using the narrower definition.
- Check federal contract and grant clauses separately from the FCC rule.
- Track the FCC's further rulemaking on bills of materials, software and white labeling, which could widen the rule.
Frequently asked questions
+Do I have to remove Hikvision or Dahua cameras that are already installed?
Not because of this rule. It applies to new equipment authorization applications and does not affect equipment the FCC has already authorized. Separate federal procurement and grant rules can still require federal contractors and grant-funded projects to avoid covered equipment.
+Does the rule cover firmware or AI software from a Covered List company?
No. The FCC declined, for now, to extend the ban to software or firmware, and it kept the record open on broader options. A further rulemaking is also asking about software bills of materials.
+What counts as a logic-bearing hardware component?
Any device, module, sub-assembly, integrated circuit or other physical part that uses timing signals above 9,000 pulses per second with digital techniques, or that uses radio frequency energy to process data. Purely mechanical or passive parts such as housings, fasteners, resistors, wiring and plain battery cells are excluded.
+Does the rule apply to a private warehouse or factory?
The rule governs which new devices the FCC will authorize for the US market, so it affects what every buyer can purchase in future. It does not regulate what a private site may keep using.
Related reading
Sources
- [1]Federal Register, Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program, 91 FR 57798, FR Doc. 2026-18535 (2026)
- [2]Federal Register, Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program, 88 FR 7592, FR Doc. 2022-28263 (2023)
- [3]FCC, List of Equipment and Services Covered by Section 2 of the Secure Networks Act (2026)
- [4]FCC, Fact Sheet: Second Report and Order, ET Docket 21-232 (2025)
- [5]Federal Register, Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program, further notice of proposed rulemaking, FR Doc. 2026-16197 (2026)
- [6]Acquisition.gov, FAR 52.204-25 (2021)
- [7]eCFR, 2 CFR 200.216 (2026)
- [8]The Register, UK bans Chinese CCTV cameras on 'sensitive' government sites (2022)
- [9]Innovation, Science and Economic Development Canada, Investment Canada Act national security decisions (2025)
- [10]European Commission, Safer and more secure digital products (2026)
- [11]Federal Register, Prohibiting Importation and Marketing of Previously Authorized Covered Communications Equipment Added to the Covered List in 2024 or Earlier, 91 FR 41023, FR Doc. 2026-13518 (2026)
Get the free Safety Tech Buyer's Toolkit
A 15-page PDF: the public evidence checklist, a weighted vendor scorecard, 40 RFP questions and pilot acceptance criteria. Subscribe and download it straight away; then one email a month when we publish or update guidance. No vendor promotions. Unsubscribe any time.