Skip to main content
Last updated: September 8, 2026Christopher Braccia
USTelecom — The Broadband Association

Securing the Communications Supply Chain

For Cybersecurity and Supply Chain Working Group Members Only

Tracking 17+ federal agency and office leads and 55 active source-linked rows, 17 archived rows, and 4 adjacent clocks, mapped into 8 documented interagency duplication clusters, across communications supply-chain, cybersecurity, procurement, foreign-adversary, and trade policy. Rolled forward to the September 8, 2026 verified state, each row linked to its primary federal source.

Sep 8
FCC 26-50 Effective
0d
Sep 21
FCC Replies / FIPS 140-2
13d
Sep 23
Anzu §2.939(e) Comments
15d
Sep 24
Xi State Visit
16d
Sep 25
Subsea 2nd R&O Effective
17d
~Oct 11
NSPM Procedures
33d
55Active Rows
17Archived Rows
4Adjacent Clocks
Explore the Federal Agency AtlasJump to deadline timeline
Since Last UpdateAugust 28 → September 8, 2026 · full-row sweepView Brief Archive

This cycle re-checked every row still carrying a July or August status. Five were wrong or incomplete; corrections are listed first because they change what members should be doing, not just what the tracker says.

Correction / GapCongress
CORRECTION: CISA 2015 extended to December 11 by the September 2 CR; no lapse; the NDAA was not the vehicle

The Cybersecurity Information Sharing Act of 2015 did not sunset on September 30. The Senate passed a continuing resolution 90-6 and the House 370-48 on September 1; the President signed it September 2, 2026 as the Continuing Appropriations and Extensions Act, 2027 (H.R. 6500). It funds the government through December 11, 2026 and moves the CISA 2015 sunset to the same date, alongside extensions of the Technology Modernization Fund and the Federal Cybersecurity Enhancement Act authorization for the National Cybersecurity Protection System. This is the fourth short-term patch since the original September 30, 2025 sunset. No substantive changes to definitions, liability, FOIA or antitrust protections. The NDAA was never the vehicle: Senate cloture on S. 4784 failed July 14 (50-46) and no further step is recorded. The next cliff now lands on the funding deadline; a December omnibus or a fifth CR is the probable carrier. The August 24 state wrongly treated a lapse as the base case and named the NDAA as the vehicle.

Correction / GapFCC
CORRECTION: test-lab track has two completed withdrawals (CVC February 25; CQC-IVTS March 27), not one

On March 27, 2026 OET withdrew recognition of CQC Internet of Vehicles Technical Service Co., Ltd (CN1329) in ET Docket 25-271 (DA 26-293), a wholly owned subsidiary of the China Quality Certification Center. It never responded to the September 8, 2025 notice or the February 12, 2026 order (DA 26-149) and OET drew an adverse inference. Completed withdrawals: CVC Shenzhen (February 25, DA 26-187) and CQC-IVTS (March 27, DA 26-293). Pending: SGS-CSTC Shenzhen (DA 26-744, OET Docket 26-111) and Shenzhen STS (DA 26-745, ET Docket 26-140; roughly 4,100 applications). Verified as of September 8: no order in either pending proceeding.

Correction / GapDoW
CORRECTION: WuXi AppTec 1260H designation enjoined August 7; implementing rule (RIN 0750-AM09) still unpublished

On August 7, 2026 a U.S. District Court granted a preliminary injunction barring DoW from enforcing the June 8 designation of WuXi AppTec as a Chinese military company on the 1260H list. It is the first successful challenge to a 2026 listing and a template other designees will use; Alibaba's separate challenge remains pending. Practitioner sources place the Section 805 implementing rule at RIN 0750-AM09 (Phase 1); if it is not published before Q4 2026, expect a surge in waiver applications ahead of the June 30, 2027 indirect prohibition. China's June 22 retaliation (10 U.S. firms added to its export control list; 46 barred from government procurement) shows the compliance burden now runs both ways.

Correction / GapUSTR
CORRECTION: 25-state CIT suit filed August 3 against the forced-labor Section 301 duties; excess-capacity determination still pending

Twenty-five states filed suit in the Court of International Trade on August 3, 2026 (State of Oregon v. Trump, Court No. 26-03467) to vacate the forced-labor Section 301 duties on 60 economies as beyond presidential authority and contrary to the APA. It is the second challenge to the July 23 action and the third multistate tariff suit in under a year, following small-business suits (Burlap and Barrel; Collective Horology) filed July 24. Duties remain payable while the cases run. The structural excess-capacity investigation across 16 economies is past its July 24 target with no determination published; mature-node semiconductors is decided but deferred to June 2027. Section 301 exclusions extended through November 2026 under the Busan truce, riding on the September 24 summit.

Correction / GapFCC
CORRECTION: Anzu §2.939(e) proposal (DA 26-832) and its September 23 comment date were not carried; August 31 and September 2 windows closed

PS 26-184 comments closed August 31 and the military-grade / swarming proceeding (PS 26-189, DA 26-758; 91 FR 48870) closed September 2; both are pending bureau action. The August 10 release in PS 26-184 was not only an erratum: it was DA 26-832, a separate Anzu-specific proposal with its own comment cycle. That proposal is the first §2.939(e) prohibition aimed at a U.S.-domiciled licensee (Anzu Robotics, Texas-incorporated), reaching the company through a licensing relationship rather than place of incorporation. Published August 24, 2026 (91 FR 54713); comments due September 23, 2026.

NewWhite House
Xi state visit September 24 becomes the decision point for the November 10 Affiliates Rule and rare-earth clocks

State visit confirmed for September 24, 2026 (Trump announcement July 23; Beijing confirmation May 16). Three clocks ride on the outcome: BIS Affiliates Rule reimposition November 10; the November 10 expiration of China's suspension of its October 2025 export-control package, with a second deadline November 27 for gallium, germanium, antimony, superhard materials and graphite; and Section 301 exclusions extended through November 2026 under the Busan truce. Critical minerals are on the U.S. agenda after some Chinese suppliers declined U.S. shipments despite valid licenses. The summit is the only scheduled venue before November 10 where both governments can extend, modify or let the reprieve lapse.

NewCommerce
Section 232 chip tariff Phase Two confirmed on the record September 2; no rates, scope or dates

On September 2, 2026, at the G20 Innovation Ministerial in Chapel Hill, Commerce Secretary Lutnick told CNBC and Bloomberg that a new round of chip duties is coming under one formula: build in the United States and pay nothing; build elsewhere and pay to enter the market. He confirmed the August 27 Politico report and named the pharmaceutical MFN model as the template. No rates, product lists or phase-in timeline were specified. Scope under consideration reaches servers, laptops and gaming hardware that Phase One's six exemption categories sheltered. Still no Federal Register action; the watch is now an announced policy direction, not deliberation.

NewNIST
SP 800-213A revision opened, comments October 15; SP 1347 final; SP 800-209r1 closes September 8

NIST opened a revision of SP 800-213A, IoT Device Cybersecurity Guidance for the Federal Government, with a pre-draft call for comments (posted August 28, updated August 31) due October 15, 2026, aiming to align with CSF 2.0 and SP 800-53 Rev. 5.2.0 and expand scope from devices to products. This is the catalog the FAR federal IoT mandate (January 4, 2027) and the Cyber Trust Mark stack point to. Also inside the window: SP 1347 final; CSF 2.0 Informative References Quick-Start Guide (August 25); IR 8611 (August 27); IR 8615 (September 1); draft SP 800-38Er1 (September 3). SP 800-209r1 comments close September 8. Open windows: SP 800-239 (September 25), SP 1353 and SP 800-213A (October 15).

VerifiedFCC
Submarine cable Second R&O effective September 25 confirmed by GAO; PRA-dependent sections delayed indefinitely

GAO's major-rule report (B-338617) confirms the Second Report and Order (FCC 26-42; 91 FR 46844) effective date is September 25, 2026, except for amendatory instructions covering numerous §1.70000-series sections, which are delayed indefinitely pending OMB approval. Practical reading: the SLTE licensing perimeter and routine conditions switch on September 25; the reporting and certification collections wait for OMB approval and a separate FCC notice, the same pattern the First R&O followed (DA 26-684). Second FNPRM comments were filed August 26; reply comments are due September 25. Day-of-use flag removed.

VerifiedFCC
FCC 26-50 effective September 8; Third FNPRM comments September 8, replies September 21

The FCC 26-50 Third R&O rules take effect September 8, 2026, including the logic-bearing component prohibition, the online-marketplace marketing clarification, full certification for Covered List entity modifications and the U.S.-based liable-party requirement. Third FNPRM comments are due September 8; replies September 21. The marketplace display-date flag stays: Category 1 FCC ID verification takes effect 180 days after Federal Register publication and Category 2 at 270 days, which from the August 7 publication computes to February 3 and May 4, 2027.

VerifiedDoW, CISA, FCC, FAR Council, BIS, USTR
Checked and unchanged across six agencies

CMMC: no Task Force output; recommendations due to the DoW CIO on or about September 13, 2026. CIRCIA: no final rule and no OIRA submission found; the Unified Agenda target remains September 2026. WC 26-82: no order; the September 30 tentative agenda is expected around September 9. Equipment-authorization Second FNPRM: record closed July 14, no action. Rip and replace: no new action; next 90-day status filing due in September. Cyber Trust Mark: CLA application window opened August 11 and remains open. FAR §5949: last confirmed status is the July 24 Open FAR Cases report. NSPM: no implementing procedures, roughly 33 days to the mid-October clock. Latest BIS item is the August 24 Container Manufacturing settlement, replacing the August 14 Plexon settlement; the structural excess-capacity determination is still pending.

01
Regulatory Oversight

Federal Agencies & Initiatives

70 active and near-term federal initiatives spanning 17+ federal agency and office leads — FCC, Commerce/BIS, NTIA, USTR, DHS, CBP, CISA, NIST, OMB, White House/ONCD/OSTP, FAR Council, GSA, DoW, DOJ, Treasury/CFIUS, FASC/ODNI, and Congress, plus FBI and NSA as joint cyber participants. Every row links to its primary federal source. This Section 01 count includes the 55 active supply-chain rows plus atlas-tracked adjacent items (such as the C-Band auction) surfaced in this table; it uses a broader denominator than the hero\u2019s 55 active source-linked rows and is not directly comparable.

All Agencies & Initiatives
70 Active Items — Click to Expand
Adjacent Cyber-Policy Clocks
3 adjacent items — not in the supply-chain total

Cyber and surveillance authorities we monitor because their authorization clocks affect members, but which are not communications supply-chain rules. Tracked separately so they never inflate the headline supply-chain count.

Congress / DHS / CISA

Cybersecurity Information Sharing Act of 2015 (CISA 2015) — voluntary cyber threat info-sharing with liability, FOIA, and antitrust protections. A cyber info-sharing statute, not a supply-chain rule; expired Sep 30, 2025; sequential extensions to Sep 30, 2026. The House-passed FY2027 NDAA carries an extension provision; the Senate draft NDAA does not, and Senate floor action is stalled while the Senate Intelligence Committee’s intelligence authorization bill carries a clean 10-year reauthorization — any fix must survive conference (verify S. 4784 status before publication)

Current sunset Sep 30, 2026Source ↗

Congress / DOJ / ODNI

FISA Section 702 reauthorization cliff — a foreign-intelligence surveillance authority, not a supply-chain rule. Short-term extensions have produced recurring reauthorization cliffs; tracked alongside the CISA 2015 clock

Recurring short-term reauthorizationsSource ↗

White House / DOJ / DHS

NSPM on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (published August 12, 2026) — directs the National Cyber Director to stand up a DOJ/DHS-supervised program for vetted private-sector companies to conduct offensive cyber operations against cyber-enabled transnational criminal organizations. A cyber-policy authority, not a supply-chain rule; implementing procedures due within 60 days of issuance (~mid-October 2026)

Implementing procedures due ~Oct 11, 2026Source ↗
02
Strategic Intelligence

Watch List & Agency Mapping

17 items to monitor for potential policy changes. Strategy flows from the White House through agencies to implementation.

FCC Covered List — power inverters and advanced robotic devices added (DA 26-786)

On July 28, 2026 the Public Safety and Homeland Security Bureau added two new category entries to the Covered List, effective immediately on release of Public Notice DA 26-786: foreign-produced power inverters (reaching commercial solar, battery storage, and wind projects, home solar and battery systems, and EV chargers) and foreign-produced advanced robotic devices (including humanoid and quadruped platforms). New models in these categories are ineligible for FCC equipment authorization, a de facto market-entry ban. The category-based track defined by place of manufacture now covers four classes: UAS and UAS critical components, routers, power inverters, and advanced robotic devices. The named-entity count is unaffected (still to be confirmed against the live FCC page).

Source ↗

FCC UAS import-and-marketing prohibitions: two proceedings closed; Anzu §2.939(e) proposal open (comments Sep 23)

PSHSB and OET opened two parallel import-and-marketing prohibitions, both now closed and pending bureau action. Section 1709 and covered UAS (PS Docket No. 26-184, PN DA 26-742; 91 FR 48108) closed comments August 31, 2026. The foreign-produced military-grade and swarming-capable UAS proceeding (PS Docket No. 26-189, DA 26-758; 91 FR 48870) closed comments September 2, 2026; the definition of military-grade remains an open question, with commenters (including FDD) proposing capability-based tests (payload, sensor packages, docking stations, autonomy, swarming). Separately, the August 10, 2026 release in PS 26-184 was not only an erratum: it was DA 26-832, a distinct Anzu-specific proposal to prohibit the Raptor and Raptor T UAS and controller, published August 24, 2026 (91 FR 54713) with comments due September 23, 2026. It is the first §2.939(e) prohibition aimed at a U.S.-domiciled licensee, reaching Anzu through a licensing relationship rather than place of incorporation.

Source ↗

FCC WC Docket 26-82 final rule

Could create domestic Section 214 exclusions, revocations, interconnection limits, attestations. Comments closed June 8; reply + PRA comments closed July 7, record closed, final rule pending. No order as of September 8, 2026; the September 30 tentative agenda posts roughly three weeks ahead, so expect it around September 9.

Source ↗

FCC Foreign Adversary Control filing portal (FACS) launch

Rule effective June 9, but the initial filing deadline runs 60 days after the LATER of the rule’s effective date or the public notice announcing the FACS launch (120 days for small entities). Since the June 9 effective date has passed, the launch public notice is now the operative trigger, and no launch notice has issued as of September 8, 2026, so the filing clock is not running. The core filing requirement in 47 C.F.R. § 1.80003 is also delayed indefinitely until OMB completes Paperwork Reduction Act review and OEA and PSHSB announce a compliance date, so there are two triggers, not one; watch OIRA’s PRA inventory for the 3060-series approval as the leading indicator. FCC DA 26-563 Small Entity Compliance Guide remains the authoritative reference for Schedule A/B/C obligations. Triggers ownership-mapping and disclosure work for all members holding covered authorizations.

Source ↗

FCC equipment-authorization integrity / Second FNPRM

Component parts, critical infrastructure definitions, modified devices, marketing enforcement, post-market surveillance, and Trusted Test Labs implementation. Reply comments on the Second FNPRM closed July 14; the record is complete and the proceeding is pending further Commission action as of September 8, 2026.

Source ↗

FCC "Dangerous Gear" Third R&O + Third FNPRM — ADOPTED July 22 (FCC 26-50)

Adopted at the July 22 Open Meeting and released as FCC 26-50 (ET Docket 21-232). The R&O prohibits authorization of logic-bearing hardware components produced by Covered List entities and devices containing them; extends marketing rules to online marketplaces with FCC ID display at the point of sale; requires full certification for Covered List entity modifications; adds a US-based liable-party requirement; and narrows the "critical infrastructure" definition per the D.C. Circuit partial remand. The FNPRM seeks comment on bifurcating the Covered List (producer/provider-based vs production-location-based), HBOM/SBOM disclosures, importation restrictions, term-limited authorizations, streamlined revocation, and SDoC registration. A direct supply-chain item, now moving to implementation and comment on the FNPRM questions. Published in the Federal Register August 7, 2026 (FR Vol. 91, No. 151; doc 2026-16197). R&O rules effective September 8, 2026 (applications pending as of that date are exempt from the component prohibition unless later amended to add, substitute, or change a logic-bearing component). Third FNPRM comments due September 8; reply comments September 21. The marketplace FCC ID display requirement phases in later: Category 1 at 180 days after Federal Register publication and Category 2 at 270 days, which from the August 7 publication computes to February 3, 2027 and May 4, 2027 respectively. Confirm the exact display dates against the Federal Register text before any member-facing claim.

Source ↗

FCC equipment-authorization enforcement — Odyssey Robot revocation executed (Aug 11)

On August 11, 2026 the FCC released an Order of Revocation against Odyssey Robot LLC, revoking authorizations for its UAS and remote controller over false U.S.-production attestations — the first completed revocation under the Commission’s national-security equipment-authorization framework, following the July 21 Order to Show Cause (DA 26-746). The Order of Revocation is DA 26-839, released August 11, 2026, revoking FCC ID 2BSYT-FMAWZOD (UAS) and 2BSYT-YMAWZOD (remote controller), effective immediately under the streamlined procedure in §2.939(d). The companion test-lab track (withdrawal of recognition from Shenzhen STS Test Services over falsified test reports) remains pending. Signals a live enforcement posture behind Covered List attestations and Trusted Test Labs implementation.

Source ↗

DoW NDAA §866 cyber harmonization output (CMMC reform track)

June 1, 2026 deadline elapsed without public output; annual report to Congress due Dec 31, 2026. On July 13, DoD suspended CMMC Phase 2 and stood up a Reform Task Force — assessed as the operative §866 harmonization vehicle in practice, though no official §866 linkage has been published. RFI closed Aug 14. Task Force report to the DoW CIO expected ~Sep 13; earliest formal determinations ~mid-October per practitioner reporting (unverified). Reform would arrive via a class deviation, a DFARS change, or a 32 CFR Part 170 amendment. Outputs will reshape DFARS cyber requirements for DIB-facing members.

Source ↗

CIRCIA final rule

Final pending; the communications-sector town hall (June 16) and written-input date (June 23) have passed. Reporting clock and final-rule effective date remain TBD; the final rule is now targeted for September 2026 (part of the September cyber convergence) with 72-hour incident and 24-hour ransom clocks intact.

Source ↗

BIS AI-chip framework — no AI Diffusion Rule replacement (new rulemaking instead)

On July 14, Under Secretary Jeffrey Kessler told Congress the administration will NOT replace the rescinded AI Diffusion Rule and will pursue new rulemaking instead — resetting expectations of a near-term full replacement framework. The Jan 13, 2026 case-by-case rule remains partial. GAIN AI Act (proposed) would give U.S. customers priority access to AI chips before exports. BIS enforcement is surging — Applied Materials ($252M, the second-largest BIS penalty ever), Cadence ($95M), and several smaller settlements — and a ~23% FY26 BIS budget increase signals heightened diligence expectations on intermediaries.

Source ↗

BIS 50% Affiliates Rule reimposition

Suspension expires Nov. 9, 2026; reimposition begins Nov. 10, 2026 unless extended; scope could reach foreign affiliates of Entity List / MEU List / SDN List parties. The September 24 Xi state visit is the decision point: the same day carries the expiration of China’s suspension of its October 2025 export-control package, with a further November 27 deadline for gallium, germanium, antimony, superhard materials, and graphite. A renewed rare-earth dispute could pull the Nov 10 reimposition forward or harden it.

Source ↗

FAR §5949 / CUI final rules

Proposed rule published Feb 17, 2026 (FAR Case 2023-008; FR Doc 2026-03065); comments closed Apr 20, 2026; final rule pending. Statutory prohibition effective Dec 23, 2027 (Parts A and B: covered semiconductors from SMIC, CXMT, YMTC + affiliates; applies to COTS and below the micro-purchase threshold; commercial-services carve-out except IT/telecom services; 72-hour discovery-notification + safe harbor; no-alternative-source exception expires Dec 23, 2028).

Source ↗

FCC submarine cable implementation

Second R&O adopted June 25, 2026 (3-0; FCC 26-42, released June 30); now an implementation workstream — SLTE licensing conditions, affiliate definitions, cable security plans, foreign-adversary screening, Team Telecom streamlining, and transition for existing systems. The Second R&O published in the Federal Register July 27 (FR Doc 2026-15123); GAO’s major-rule report (B-338617) confirms it is effective September 25, 2026 except for the §1.70000-series reporting and certification instructions, which are delayed indefinitely pending OMB approval. Second FNPRM comments were filed August 26 and reply comments are due September 25, 2026. Separately, the 2025 First R&O is now fully effective: the PRA-delayed rules, including the one-time SLTE information collection and annual reporting, took effect July 8, 2026 (DA 26-684; 91 FR 42137) after OMB approval June 26. Members holding cable landing licenses have live First R&O obligations now, alongside the running Second R&O comment clocks. On August 10, 2026, OIA issued filing instructions for Route Position List submissions, the next implementation step in the First R&O one-time information collection that took effect July 8.

Source ↗

CFIUS greenfield / emerging-tech expansion

Data centers, cloud, fiber, towers, cable landing, satellite, AI infrastructure.

Source ↗

Section 232 semiconductors: Phase Two confirmed on the record (Sep 2)

On September 2, 2026, at the G20 Innovation Ministerial in Chapel Hill, Commerce Secretary Lutnick told CNBC and Bloomberg that a new round of chip duties is coming under one formula: build in the United States and pay nothing; build elsewhere and pay to enter the market. He confirmed the August 27 Politico report and named the pharmaceutical MFN model as the template (tariff-free import allowances scaled to U.S. manufacturing investment). No rates, product lists, or phase-in timeline were specified. The Commerce data-center chip report due July 1 under Proclamation 11002 was completed but has not been made public. Scope under consideration reaches servers, laptops, and gaming hardware that Phase One’s six exemption categories sheltered, with possible country-specific rates and quotas. Still no Federal Register action, so the watch is now an announced policy direction, not deliberation. Data-center and network-equipment procurement loses the Phase One data-center carve-out if Phase Two lands as described. Related: the Section 48D advanced-manufacturing credit construction-start deadline is December 31, 2026 (SEMI pressed Congress July 22; Crapo and Wyden issued a supportive joint statement August 5; no legislation has passed).

Source ↗

AI Action Plan implementation tranches

Pillar II data-center buildout drives optical, transmission, power, and grid-telecom interdependency demand on members.

Source ↗

USTR Section 301 — forced-labor action EFFECTIVE July 24; structural excess-capacity determination pending

The forced-labor Section 301 final action took effect 12:01 a.m. ET July 24 — the exact minute the Section 122 surcharge expired (no-gap handoff). The limited in-transit exemption (goods loaded before July 24 and entered for consumption before 12:01 a.m. ET July 28) has now fully lapsed, so all in-scope goods from the 60 investigated economies are subject to the applicable rates. Additional duties of 10 percent (17 partners with prohibitions, reciprocal commitments, or partial regimes) or 12.5 percent (all others, including China and Vietnam); net-of-MFN treatment for Japan, Korea, and Switzerland; product exemptions per Annexes I and II, including Section 232-covered products. USTR-2026-0265, USTR-2026-0266; the FR notice runs 431 pages. Litigation is now underway: twenty-five states filed suit in the Court of International Trade on August 3, 2026 (State of Oregon v. Trump, Court No. 26-03467) to vacate the duties on 60 economies as beyond presidential authority and contrary to the APA, the second challenge to the July 23 action and the third multistate tariff suit in under a year, following small-business suits (Burlap and Barrel; Collective Horology) filed July 24. Duties remain payable while the cases run. The structural excess-capacity determination (16 largest trading partners) is past its July 24 target with no determination published; mature-node semiconductors is decided but deferred to June 2027. Section 301 exclusions extended through November 2026 under the Busan truce, riding on the September 24 summit. Adjacent 301 tracks: Brazil 301 (25% proposed); Vietnam IP 301 (initiated May 29); US-China Board of Trade docket (rebuttals due July 27).

Source ↗
03
Compliance Timeline

Critical Deadlines & Milestones

Track federal regulatory deadlines and compliance milestones impacting telecom supply chain operations through 2027. Days-away and status update automatically each day.

January 1, 2030

FY2026 NDAA §§834-835 targets for eliminating adversary reliance in optical glass / optical systems and computer displays

At least Jan 1, 2029

FCC software/firmware update waiver for previously authorized foreign-produced routers and UAS was extended and expanded (DA 26-454)

Dec 23, 2027

FAR §5949 statutory prohibition on procurement of covered semiconductor products / services takes effect

Jun 30, 2027

DoW Section 1260H indirect-procurement (goods/services) prohibition takes effect

Model Year 2027

BIS Connected Vehicles ICTS — software prohibitions begin (hardware MY 2030 / Jan 1, 2029 for non-MY units)

Jan 4, 2027

FAR federal IoT purchasing mandate (Cyber Trust Mark stack) takes effect

Dec 31, 2026

NDAA §866 DIB cyber harmonization annual report to Congress due

Dec 11, 2026

CISA 2015 sunset extended to December 11 by the September 2 CR (H.R. 6500); long-term reauthorization pending

Dec 4, 2026

Section 232 polysilicon minimum-import-price regime and downstream tariffs effective

Nov 10, 2026

BIS 50% Affiliates Rule suspension runs through Nov. 9, 2026; reimposition begins Nov. 10, 2026 unless extended

Mid-Sep 2026

CMMC Reform Task Force report to the DoW CIO expected

~Oct 11, 2026

DOJ/DHS/NCC implementing procedures due for the Aug 12 NSPM private-sector cyber-operations program (60-day clock)

Sep 30, 2026

Next FCC Open Meeting

September 2026

CIRCIA final rule expected (communications-sector town hall and written-input dates passed in June 2026) — 72-hour incident / 24-hour ransom reporting for covered communications-sector entities

Sep 21, 2026

FIPS 140-2 certificates move to the CMVP Historical List

Sep 21, 2026

FCC 26-50 Third FNPRM reply comments due

Sep 8, 2026 (today)

FCC 26-50 Third R&O rules effective — logic-bearing component prohibition and online-marketplace marketing rules

Sep 8, 2026 (today)

FCC 26-50 Third FNPRM comments due

Sep 2, 2026 (passed)

Military-grade / swarming-capable UAS import-and-marketing prohibition comments due (FR Doc. 2026-15659)

Aug 31, 2026 (passed)

Section 1709 / covered UAS import-and-marketing prohibition comments due (PS Docket No. 26-184)

Aug 26, 2026 (passed)

Submarine cable Second FNPRM comments due (OI Docket No. 24-523, MD Docket No. 24-524)

Aug 24, 2026 (passed)

NIST SP 800-213r1 draft comments due

Aug 14, 2026 (passed)

CMMC Reform Task Force RFI responses due (12:00 p.m. ET, email submission)

Aug 12, 2026 (published)

NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" published — NCC directed to stand up a vetted private-sector cyber-operations program

Aug 11, 2026 (executed)

FCC releases Order of Revocation against Odyssey Robot LLC — first completed national-security equipment authorization revocation (follows DA 26-746 Order to Show Cause)

Aug 11, 2026 (announced)

PSHSB announces Cybersecurity Label Administrators and opens a new CLA filing window under the U.S. Cyber Trust Mark program (PS Docket 23-239)

Aug 10, 2026 (issued)

OIA issues Route Position List filing instructions for the submarine cable First R&O one-time information collection (OI 24-523 / MD 24-524); erratum released in the Section 1709 / covered UAS §2.939(e) proceeding (PS Docket 26-184) — comment dates unchanged

Aug 6, 2026 (no supply-chain items)

FCC August Open Meeting — no supply-chain items in scope for the tracker

July 28, 2026 (passed)

Section 301 in-transit window fully closes; NTIA extends Tribal broadband deadlines 60 days

July 28, 2026 (effective)

FCC adds power inverters and advanced robotic devices to the Covered List (DA 26-786)

July 27, 2026 (published)

Submarine cable Second R&O published in the Federal Register (FR Doc 2026-15123); router Conditional Approval (DA 26-775)

~July 27, 2026 (passed)

US-China "Board of Trade" docket — rebuttal / response window closes

July 24, 2026 (passed)

Section 122 global surcharge expires — the 10% surcharge imposed effective Feb 24, 2026 to replace the IEEPA tariffs after the Supreme Court’s Feb 20, 2026 Learning Resources ruling

July 23-24, 2026 (effective July 24)

USTR forced-labor Section 301 final action announced (July 23), effective 12:01 a.m. ET July 24 as the Section 122 surcharge expires

July 22, 2026 (adopted — FCC 26-50)

FCC ADOPTED the Dangerous Gear Third R&O + Third FNPRM (ET Docket 21-232), released as FCC 26-50 — closes the component-part loophole, reaches online marketplaces, and narrows the critical-infrastructure definition on remand; the July Open Meeting also adopted Upper C-Band auction rules (adjacent)

July 16, 2026 (effective)

FCC prohibition on importing and marketing certain previously authorized covered equipment takes effect (47 CFR § 2.939(e))

July 15, 2026 (no public output)

1260H DFARS internal staff draft reportedly due to regulators (soft date, trade-bar reporting)

~July 14, 2026 (passed)

USTR Section 301 forced-labor — post-hearing rebuttal comments due (5 days after last hearing day)

July 14, 2026 (passed)

FCC equipment-authorization integrity Second FNPRM reply comments due (test lab / TCB reciprocity, IP protections, database modernization); record closed

July 13, 2026 (suspended)

DoD suspends CMMC Phase 2; CMMC Reform Task Force stood up (CIO memo dated July 10)

July 10, 2026 (passed)

US-China "Board of Trade" USTR docket — written comments closed (rebuttals/responses due July 27)

July 9, 2026 (passed)

USTR Section 301 forced-labor hearings concluded

July 8, 2026 (effective)

Submarine cable First R&O remaining rules effective (DA 26-684; 91 FR 42137) following OMB approval of the information collections on June 26, 2026

July 7, 2026 (passed)

Digitalsystem services added to the Covered List (DA 26-673) following the Section 214 denial (FCC 26-44)

July 7, 2026 (passed)

FCC WC Docket 26-82 reply + PRA comments due; USTR Section 301 hearings began (ran through July 9)

July 6, 2026 (passed)

USTR Section 301 forced-labor tariff written comments closed (10% on 14 economies / 12.5% on the remaining 46; docket USTR-2026-0265; hearing-appearance requests were due June 22 via USTR-2026-0266; hearings ran July 7–9)

July 1, 2026 (passed)

Commerce Section 232 data-center semiconductor market report deadline passed — no public action; watch for Federal Register Phase 2 modification

June 30, 2026 (in effect)

DoW Section 1260H direct-contracting prohibition IN EFFECT under FY2024 NDAA §805 (new, renewed, or extended contracts with 1260H List entities and entities under their control; list at 188 entities); FY2025 NDAA §851 lobbyist prohibition (10 U.S.C. 4663) also in effect; TINA certified cost-or-pricing-data threshold under 10 U.S.C. 3702 rose for contracts entered after this date; Class Deviation 2026-O0025 (June 29) created DFARS Subpart 240.70 and clause 252.240-7995, with the notice-and-comment Section 805 rule (RIN 0750-AM09) still unpublished; DoD compliance/waiver guidance posted at businessdefense.gov

June 26, 2026 (passed)

FCC Public Notice prohibiting further importation and marketing of certain previously authorized covered equipment under 47 CFR § 2.939(e)

June 25, 2026 (adopted)

FCC ADOPTED the Second Submarine Cable Report & Order (OI 24-523 / MD 24-524) by a unanimous 3-0 vote — bans all foreign-adversary equipment, introduces first-time SLTE operator licensing, presumptive disqualification for foreign-adversary applicants (10% is the reportable-interest threshold, not a safe harbor), and a fast-track for trusted operators

June 23, 2026 (passed)

CIRCIA communications-sector written input due (7 days after the June 16 Grouping A session)

June 22, 2026 (passed)

USTR Section 301 forced-labor — hearing-appearance requests due

June 18, 2026 (passed)

Submarine cable ex parte / Sunshine cutoff (OI 24-523 / MD 24-524)

June 16, 2026 (passed)

CIRCIA communications-sector town hall (critical-infrastructure grouping A)

June 16, 2026 (passed)

DoW deadline under FY2026 NDAA §1521 for expedited cloud Authorization to Operate (ATO) guidance

June 16, 2026 (passed)

DoW deadline under FY2026 NDAA §1512 for a department-wide AI/ML cybersecurity & governance policy

June 15, 2026 (passed)

FCC Trusted Test Labs / equipment-authorization integrity rule effective (FCC 26-28)

June 9, 2026 (passed)

FCC Foreign Adversary Control attestation rule effective (GN Docket 25-166; FCC 26-2)

June 8, 2026 (passed)

FCC WC Docket 26-82 — comments due on domestic Section 214 / Covered List / foreign-adversary proposal (FCC 26-29)

June 1, 2026 (passed)

DoW deadline under FY2026 NDAA §866 to harmonize cybersecurity requirements across the defense industrial base and eliminate duplicative DFARS provisions

Phased from Nov 10, 2025 (in effect)

DoW CMMC DFARS contractual requirement in effect; assessments and flow-downs ramping

Quarterly

SAM.gov FASCSA exclusion / removal order checks under FAR 52.204-30

08. INTERAGENCY OVERLAP ANALYSIS

Where the Right Hand Does Not Know the Left: Federal agencies duplicating work on the same problems through parallel authorities, different statutes, inconsistent timelines, and uncoordinated outcomes. Each cluster opens a detail panel documenting the double-work mechanics, the compliance burden by provider tier, the federal government own admissions of the duplication, and one primary source per claim.

Themes × Agencies heat map

Each row is an overlap cluster, each column a participating agency. Filled cells mark participation; the number is the count of that cluster related initiatives attributable to the agency, computed from the dataset. Select a cell to open the cluster detail filtered to that intersection, or a row label to open the full cluster.

ClusterUSTRBISFAR CouncilCISADoDFCCDHSFASCCommerce (BIS/OICTS)CFIUSDoJOMBNTIAState DeptCongress
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
2
High severity
Medium severity
Low severity
Not in cluster

Shared jurisdiction clusters

04
Exposure Map

Where the Pressure Converges

A visual read of the June–July 2026 compliance sprint and three views of where federal initiatives overlap: a theme × agency heat map, the initiatives where agencies co-lead the same workstream, and rules that span multiple themes. Click any event or cell to explore the detail.

Event Horizon

Verified as of September 8, 2026. The September convergence has largely resolved: FCC 26-50's logic-bearing component prohibition took effect September 8 with Third FNPRM replies due September 21, the CMMC Reform Task Force report lands on or about September 13, and FIPS 140-2 certificates move to the CMVP Historical List September 21. The CISA 2015 information-sharing authority did not lapse September 30: the September 2 continuing resolution (H.R. 6500) moved the sunset to December 11, 2026, alongside the funding deadline. Ahead: the Anzu §2.939(e) comment deadline September 23, the Xi state visit September 24 (the decision point for the November 10 BIS Affiliates Rule reimposition and the rare-earth truce), the submarine cable Second R&O effective September 25, the Section 232 polysilicon minimum-import-price regime effective December 4, and the CISA 2015 sunset December 11. Enforcement remains a live front alongside rulemaking, with the August 11 Odyssey Robot revocation (DA 26-839) standing as the first completed national-security equipment-authorization revocation, and a new adjacent cyber-policy clock runs to roughly mid-October for the August 12 NSPM's private-sector cyber-operations implementing procedures. Days-away and status update automatically each day.

Today · September 8, 2026

Overlap Map — Themes × Agencies

Each cell counts the initiatives where a cross-cutting theme meets a lead agency. Darker cells are convergence hotspots — places where members face stacked, overlapping obligations. Click a cell to see the initiatives behind it.

1 initiative
2–3 initiatives
4–5 initiatives
6+ (hotspot)
FCCCommerce / BISDHS / CISA / NISTDoW / FARUSTR / TreasuryWhite House
Foreign-Adversary & Ownership
Equipment Authorization & Labs
Export Controls & Tariffs
Cyber Incident & Software Assurance
Procurement & Contracts
Network Infrastructure (Cable / 214)

Select a cell above to see which initiatives drive that overlap. Hotspots sit at FCC equipment authorization (8), FCC foreign-adversary authority (7), CISA software assurance (7), and DoW / FAR procurement (6) — FCC now carries two 7-plus fronts, stacked compliance rather than one.

Shared Jurisdiction — Where Agencies Co-Lead

The heat map counts initiatives per agency. This is the actual overlap: single workstreams that two or more agencies lead jointly, so a member responding to one is answering to several at once. 13 of the initiatives mapped in this view carry shared jurisdiction.

DOJ+DHS+DoW+FCC
Team Telecom foreign-participation reviews

Four-agency committee review feeds FCC Section 214 / cable licensing decisions. July 7 Digitalsystem action: Committee recommendation → 214 denial → same-day Covered List placement.

FCC+CISA+FBI+NSA
Salt Typhoon response & comms cybersecurity expectations

Joint advisory AA25-239A; intersects CIRCIA reporting and FCC cyber rules.

Congress+DoW+FAR Council
FY2026 NDAA (P.L. 119-60) supply-chain & cyber provisions

§866 cyber harmonization, §§834-835 adversary-reliance, §1521 cloud ATO, §§843-850/1692 procurement bans.

Treasury+CFIUS+White House
America First Investment Policy & CFIUS Known Investor pilot

Investment-screening posture flows into Team Telecom and ICTS reviews.

USTR+Commerce+White House
Section 232 semiconductor tariff & Section 301 China investigation

Tariff + trade-remedy track; overlaps BIS export controls and forced-labor 301.

White House+NIST+CISA
Federal cybersecurity EO framework (EO 14144 / EO 14306)

Secure software/SSDF, post-quantum migration, IoT, AI — drives multiple downstream rules.

CISA+NIST+OMB
Secure software development self-attestation (SSDF / Common Form)

Collection mandate now agency-discretionary after OMB M-26-05.

White House+OSTP+Commerce
"Winning the Race" AI Action Plan + 3 companion EOs

Data-center permitting, AI-stack export, federal AI procurement.

White House+DOJ+Treasury
EO 14390 — Combating Cybercrime, Fraud & Predatory Schemes

Paired with the 2026 National Cybersecurity Strategy. Extended by the August 12, 2026 NSPM on transnational cyber-enabled crime, which directs the NCC to stand up a vetted private-sector offensive cyber-operations program; DOJ/DHS implementing procedures are due ~mid-October (likely around October 11).

DOJ+CISA
DOJ Data Security Program (EO 14117)

Bulk-sensitive-data transfer restrictions; CISA security requirements annex.

DoW+FAR Council
Section 1260H Chinese Military Companies contracting prohibition

In effect June 30, 2026; Class Deviation 2026-O0025 (June 29) created DFARS Subpart 240.70 and clause 252.240-7995, with the notice-and-comment Section 805 rule (RIN 0750-AM09) still unpublished. WuXi AppTec designation enjoined August 7, 2026. DoD compliance/waiver guidance posted at businessdefense.gov.

FCC+NIST
U.S. Cyber Trust Mark — IoT labeling & federal mandate

FCC program built on NIST IR 8425 criteria; FAR mandate by Jan 4, 2027.

NIST+NSA
Post-quantum cryptography standards & federal migration

FIPS 203/204/205 + NSA CNSA 2.0 migration timeline.

Initiatives That Span Multiple Themes

The other overlap dimension: a single rule that lands in more than one compliance bucket, so it shows up in multiple rows of the matrix above.

Domestic Section 214 overhaul (WC 26-82)Foreign-Adversary & OwnershipNetwork Infrastructure
International Section 214 revocationsForeign-Adversary & OwnershipNetwork Infrastructure
Submarine cable Second R&OForeign-Adversary & OwnershipNetwork Infrastructure
Section 1260H prohibitionForeign-Adversary & OwnershipProcurement & Contracts
Section 889 procurement banForeign-Adversary & OwnershipProcurement & Contracts
FAR §5949 semiconductorsExport Controls & TariffsProcurement & Contracts
CMMC / DFARSCyber Incident & Software AssuranceProcurement & Contracts
Outbound Investment SecurityForeign-Adversary & OwnershipExport Controls & Tariffs
Trusted Test Labs / MRA reciprocityEquipment Authorization & LabsExport Controls & Tariffs
Legal Disclaimer

This Supply Chain Policy Brief is provided by USTelecom – The Broadband Association for general informational and member-education purposes only. It summarizes selected federal and state supply-chain, cybersecurity, procurement, foreign-adversary, and related national security developments that may be relevant to members. It does not constitute legal, regulatory, or compliance advice or a legal opinion, and should not be relied upon as a substitute for advice from qualified counsel.

The application of the laws, regulations, orders, deadlines, and initiatives discussed here depends on each member's particular facts and circumstances. Members should consult their own legal, regulatory, and compliance advisors before taking or refraining from any action based on this Brief.

Requirements may change and agency interpretations may evolve after publication. USTelecom has sought to summarize developments accurately as of the date indicated but undertakes no obligation to update the Brief and makes no representation or warranty as to its completeness, accuracy, timeliness, or applicability to any member or situation.

Where this Brief references or summarizes statutes, regulations, agency guidance, or other third-party materials, those references are provided for convenience only. Members should review the underlying sources directly.

This Brief is confidential and intended solely for USTelecom members and other recipients USTelecom expressly authorizes. It may not be distributed, quoted, or published without USTelecom's prior authorization.

Questions or Comments? Please contact Christopher Braccia at CBraccia@ustelecom.org