Trade News 2 min read

FCC National Security Determination on Routers – Expanding U.S. Controls on ICT Supply Chain Risks

The Federal Communications Commission has issued a National Security Determination (NSD-Routers0326) on 24 March 2026, signaling heightened regulatory scrutiny over consumer-grade routers and their role in U.S. telecommunications infrastructure.

This determination reflects growing concern that routers widely embedded across residential and enterprise networks, pose systemic risks if sourced from vendors linked to foreign adversary jurisdictions. Particular focus is placed on vulnerabilities associated with firmware integrity, remote access capabilities, and software update mechanisms, which could be exploited for unauthorized surveillance or network disruption.

Importantly, this development suggests a potential regulatory shift from entity-specific restrictions to broader technology class-based controls. Rather than targeting individual companies alone, future measures may extend to entire categories of ICT equipment deemed high-risk, significantly widening the compliance perimeter.

For multinational corporations, the implications are immediate. Organizations should reassess ICT procurement strategies, strengthen third-party risk management, and conduct comprehensive reviews of existing network infrastructure to identify exposure to potentially restricted equipment. This is especially relevant for firms with U.S.-linked operations or data flows.

From a compliance standpoint, the determination underscores the increasing convergence of cybersecurity, trade compliance, and national security policy. Companies are advised to enhance governance frameworks, ensuring alignment between IT, legal, and supply chain functions.

Overall, the FCC’s action reinforces a clear regulatory trajectory: network infrastructure is now a frontline issue in geopolitical risk and compliance management.

Official source from FCC:

https://www.fcc.gov/sites/default/files/NSD-Routers0326.pdf