Federal Agencies & Initiatives
70 active and near-term federal initiatives spanning 17+ federal agency and office leads — FCC, Commerce/BIS, NTIA, USTR, DHS, CBP, CISA, NIST, OMB, White House/ONCD/OSTP, FAR Council, GSA, DoW, DOJ, Treasury/CFIUS, FASC/ODNI, and Congress, plus FBI and NSA as joint cyber participants. Every row links to its primary federal source. This Section 01 count includes the 55 active supply-chain rows plus atlas-tracked adjacent items (such as the C-Band auction) surfaced in this table; it uses a broader denominator than the hero\u2019s 55 active source-linked rows and is not directly comparable.
Cyber and surveillance authorities we monitor because their authorization clocks affect members, but which are not communications supply-chain rules. Tracked separately so they never inflate the headline supply-chain count.
Congress / DHS / CISA
Cybersecurity Information Sharing Act of 2015 (CISA 2015) — voluntary cyber threat info-sharing with liability, FOIA, and antitrust protections. A cyber info-sharing statute, not a supply-chain rule; expired Sep 30, 2025; sequential extensions to Sep 30, 2026. The House-passed FY2027 NDAA carries an extension provision; the Senate draft NDAA does not, and Senate floor action is stalled while the Senate Intelligence Committee’s intelligence authorization bill carries a clean 10-year reauthorization — any fix must survive conference (verify S. 4784 status before publication)
Congress / DOJ / ODNI
FISA Section 702 reauthorization cliff — a foreign-intelligence surveillance authority, not a supply-chain rule. Short-term extensions have produced recurring reauthorization cliffs; tracked alongside the CISA 2015 clock
White House / DOJ / DHS
NSPM on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (published August 12, 2026) — directs the National Cyber Director to stand up a DOJ/DHS-supervised program for vetted private-sector companies to conduct offensive cyber operations against cyber-enabled transnational criminal organizations. A cyber-policy authority, not a supply-chain rule; implementing procedures due within 60 days of issuance (~mid-October 2026)
Watch List & Agency Mapping
17 items to monitor for potential policy changes. Strategy flows from the White House through agencies to implementation.
FCC Covered List — power inverters and advanced robotic devices added (DA 26-786)
On July 28, 2026 the Public Safety and Homeland Security Bureau added two new category entries to the Covered List, effective immediately on release of Public Notice DA 26-786: foreign-produced power inverters (reaching commercial solar, battery storage, and wind projects, home solar and battery systems, and EV chargers) and foreign-produced advanced robotic devices (including humanoid and quadruped platforms). New models in these categories are ineligible for FCC equipment authorization, a de facto market-entry ban. The category-based track defined by place of manufacture now covers four classes: UAS and UAS critical components, routers, power inverters, and advanced robotic devices. The named-entity count is unaffected (still to be confirmed against the live FCC page).
Source ↗FCC UAS import-and-marketing prohibitions: two proceedings closed; Anzu §2.939(e) proposal open (comments Sep 23)
PSHSB and OET opened two parallel import-and-marketing prohibitions, both now closed and pending bureau action. Section 1709 and covered UAS (PS Docket No. 26-184, PN DA 26-742; 91 FR 48108) closed comments August 31, 2026. The foreign-produced military-grade and swarming-capable UAS proceeding (PS Docket No. 26-189, DA 26-758; 91 FR 48870) closed comments September 2, 2026; the definition of military-grade remains an open question, with commenters (including FDD) proposing capability-based tests (payload, sensor packages, docking stations, autonomy, swarming). Separately, the August 10, 2026 release in PS 26-184 was not only an erratum: it was DA 26-832, a distinct Anzu-specific proposal to prohibit the Raptor and Raptor T UAS and controller, published August 24, 2026 (91 FR 54713) with comments due September 23, 2026. It is the first §2.939(e) prohibition aimed at a U.S.-domiciled licensee, reaching Anzu through a licensing relationship rather than place of incorporation.
Source ↗FCC WC Docket 26-82 final rule
Could create domestic Section 214 exclusions, revocations, interconnection limits, attestations. Comments closed June 8; reply + PRA comments closed July 7, record closed, final rule pending. No order as of September 8, 2026; the September 30 tentative agenda posts roughly three weeks ahead, so expect it around September 9.
Source ↗FCC Foreign Adversary Control filing portal (FACS) launch
Rule effective June 9, but the initial filing deadline runs 60 days after the LATER of the rule’s effective date or the public notice announcing the FACS launch (120 days for small entities). Since the June 9 effective date has passed, the launch public notice is now the operative trigger, and no launch notice has issued as of September 8, 2026, so the filing clock is not running. The core filing requirement in 47 C.F.R. § 1.80003 is also delayed indefinitely until OMB completes Paperwork Reduction Act review and OEA and PSHSB announce a compliance date, so there are two triggers, not one; watch OIRA’s PRA inventory for the 3060-series approval as the leading indicator. FCC DA 26-563 Small Entity Compliance Guide remains the authoritative reference for Schedule A/B/C obligations. Triggers ownership-mapping and disclosure work for all members holding covered authorizations.
Source ↗FCC equipment-authorization integrity / Second FNPRM
Component parts, critical infrastructure definitions, modified devices, marketing enforcement, post-market surveillance, and Trusted Test Labs implementation. Reply comments on the Second FNPRM closed July 14; the record is complete and the proceeding is pending further Commission action as of September 8, 2026.
Source ↗FCC "Dangerous Gear" Third R&O + Third FNPRM — ADOPTED July 22 (FCC 26-50)
Adopted at the July 22 Open Meeting and released as FCC 26-50 (ET Docket 21-232). The R&O prohibits authorization of logic-bearing hardware components produced by Covered List entities and devices containing them; extends marketing rules to online marketplaces with FCC ID display at the point of sale; requires full certification for Covered List entity modifications; adds a US-based liable-party requirement; and narrows the "critical infrastructure" definition per the D.C. Circuit partial remand. The FNPRM seeks comment on bifurcating the Covered List (producer/provider-based vs production-location-based), HBOM/SBOM disclosures, importation restrictions, term-limited authorizations, streamlined revocation, and SDoC registration. A direct supply-chain item, now moving to implementation and comment on the FNPRM questions. Published in the Federal Register August 7, 2026 (FR Vol. 91, No. 151; doc 2026-16197). R&O rules effective September 8, 2026 (applications pending as of that date are exempt from the component prohibition unless later amended to add, substitute, or change a logic-bearing component). Third FNPRM comments due September 8; reply comments September 21. The marketplace FCC ID display requirement phases in later: Category 1 at 180 days after Federal Register publication and Category 2 at 270 days, which from the August 7 publication computes to February 3, 2027 and May 4, 2027 respectively. Confirm the exact display dates against the Federal Register text before any member-facing claim.
Source ↗FCC equipment-authorization enforcement — Odyssey Robot revocation executed (Aug 11)
On August 11, 2026 the FCC released an Order of Revocation against Odyssey Robot LLC, revoking authorizations for its UAS and remote controller over false U.S.-production attestations — the first completed revocation under the Commission’s national-security equipment-authorization framework, following the July 21 Order to Show Cause (DA 26-746). The Order of Revocation is DA 26-839, released August 11, 2026, revoking FCC ID 2BSYT-FMAWZOD (UAS) and 2BSYT-YMAWZOD (remote controller), effective immediately under the streamlined procedure in §2.939(d). The companion test-lab track (withdrawal of recognition from Shenzhen STS Test Services over falsified test reports) remains pending. Signals a live enforcement posture behind Covered List attestations and Trusted Test Labs implementation.
Source ↗DoW NDAA §866 cyber harmonization output (CMMC reform track)
June 1, 2026 deadline elapsed without public output; annual report to Congress due Dec 31, 2026. On July 13, DoD suspended CMMC Phase 2 and stood up a Reform Task Force — assessed as the operative §866 harmonization vehicle in practice, though no official §866 linkage has been published. RFI closed Aug 14. Task Force report to the DoW CIO expected ~Sep 13; earliest formal determinations ~mid-October per practitioner reporting (unverified). Reform would arrive via a class deviation, a DFARS change, or a 32 CFR Part 170 amendment. Outputs will reshape DFARS cyber requirements for DIB-facing members.
Source ↗CIRCIA final rule
Final pending; the communications-sector town hall (June 16) and written-input date (June 23) have passed. Reporting clock and final-rule effective date remain TBD; the final rule is now targeted for September 2026 (part of the September cyber convergence) with 72-hour incident and 24-hour ransom clocks intact.
Source ↗BIS AI-chip framework — no AI Diffusion Rule replacement (new rulemaking instead)
On July 14, Under Secretary Jeffrey Kessler told Congress the administration will NOT replace the rescinded AI Diffusion Rule and will pursue new rulemaking instead — resetting expectations of a near-term full replacement framework. The Jan 13, 2026 case-by-case rule remains partial. GAIN AI Act (proposed) would give U.S. customers priority access to AI chips before exports. BIS enforcement is surging — Applied Materials ($252M, the second-largest BIS penalty ever), Cadence ($95M), and several smaller settlements — and a ~23% FY26 BIS budget increase signals heightened diligence expectations on intermediaries.
Source ↗BIS 50% Affiliates Rule reimposition
Suspension expires Nov. 9, 2026; reimposition begins Nov. 10, 2026 unless extended; scope could reach foreign affiliates of Entity List / MEU List / SDN List parties. The September 24 Xi state visit is the decision point: the same day carries the expiration of China’s suspension of its October 2025 export-control package, with a further November 27 deadline for gallium, germanium, antimony, superhard materials, and graphite. A renewed rare-earth dispute could pull the Nov 10 reimposition forward or harden it.
Source ↗FAR §5949 / CUI final rules
Proposed rule published Feb 17, 2026 (FAR Case 2023-008; FR Doc 2026-03065); comments closed Apr 20, 2026; final rule pending. Statutory prohibition effective Dec 23, 2027 (Parts A and B: covered semiconductors from SMIC, CXMT, YMTC + affiliates; applies to COTS and below the micro-purchase threshold; commercial-services carve-out except IT/telecom services; 72-hour discovery-notification + safe harbor; no-alternative-source exception expires Dec 23, 2028).
Source ↗FCC submarine cable implementation
Second R&O adopted June 25, 2026 (3-0; FCC 26-42, released June 30); now an implementation workstream — SLTE licensing conditions, affiliate definitions, cable security plans, foreign-adversary screening, Team Telecom streamlining, and transition for existing systems. The Second R&O published in the Federal Register July 27 (FR Doc 2026-15123); GAO’s major-rule report (B-338617) confirms it is effective September 25, 2026 except for the §1.70000-series reporting and certification instructions, which are delayed indefinitely pending OMB approval. Second FNPRM comments were filed August 26 and reply comments are due September 25, 2026. Separately, the 2025 First R&O is now fully effective: the PRA-delayed rules, including the one-time SLTE information collection and annual reporting, took effect July 8, 2026 (DA 26-684; 91 FR 42137) after OMB approval June 26. Members holding cable landing licenses have live First R&O obligations now, alongside the running Second R&O comment clocks. On August 10, 2026, OIA issued filing instructions for Route Position List submissions, the next implementation step in the First R&O one-time information collection that took effect July 8.
Source ↗CFIUS greenfield / emerging-tech expansion
Data centers, cloud, fiber, towers, cable landing, satellite, AI infrastructure.
Source ↗Section 232 semiconductors: Phase Two confirmed on the record (Sep 2)
On September 2, 2026, at the G20 Innovation Ministerial in Chapel Hill, Commerce Secretary Lutnick told CNBC and Bloomberg that a new round of chip duties is coming under one formula: build in the United States and pay nothing; build elsewhere and pay to enter the market. He confirmed the August 27 Politico report and named the pharmaceutical MFN model as the template (tariff-free import allowances scaled to U.S. manufacturing investment). No rates, product lists, or phase-in timeline were specified. The Commerce data-center chip report due July 1 under Proclamation 11002 was completed but has not been made public. Scope under consideration reaches servers, laptops, and gaming hardware that Phase One’s six exemption categories sheltered, with possible country-specific rates and quotas. Still no Federal Register action, so the watch is now an announced policy direction, not deliberation. Data-center and network-equipment procurement loses the Phase One data-center carve-out if Phase Two lands as described. Related: the Section 48D advanced-manufacturing credit construction-start deadline is December 31, 2026 (SEMI pressed Congress July 22; Crapo and Wyden issued a supportive joint statement August 5; no legislation has passed).
Source ↗AI Action Plan implementation tranches
Pillar II data-center buildout drives optical, transmission, power, and grid-telecom interdependency demand on members.
Source ↗USTR Section 301 — forced-labor action EFFECTIVE July 24; structural excess-capacity determination pending
The forced-labor Section 301 final action took effect 12:01 a.m. ET July 24 — the exact minute the Section 122 surcharge expired (no-gap handoff). The limited in-transit exemption (goods loaded before July 24 and entered for consumption before 12:01 a.m. ET July 28) has now fully lapsed, so all in-scope goods from the 60 investigated economies are subject to the applicable rates. Additional duties of 10 percent (17 partners with prohibitions, reciprocal commitments, or partial regimes) or 12.5 percent (all others, including China and Vietnam); net-of-MFN treatment for Japan, Korea, and Switzerland; product exemptions per Annexes I and II, including Section 232-covered products. USTR-2026-0265, USTR-2026-0266; the FR notice runs 431 pages. Litigation is now underway: twenty-five states filed suit in the Court of International Trade on August 3, 2026 (State of Oregon v. Trump, Court No. 26-03467) to vacate the duties on 60 economies as beyond presidential authority and contrary to the APA, the second challenge to the July 23 action and the third multistate tariff suit in under a year, following small-business suits (Burlap and Barrel; Collective Horology) filed July 24. Duties remain payable while the cases run. The structural excess-capacity determination (16 largest trading partners) is past its July 24 target with no determination published; mature-node semiconductors is decided but deferred to June 2027. Section 301 exclusions extended through November 2026 under the Busan truce, riding on the September 24 summit. Adjacent 301 tracks: Brazil 301 (25% proposed); Vietnam IP 301 (initiated May 29); US-China Board of Trade docket (rebuttals due July 27).
Source ↗Critical Deadlines & Milestones
Track federal regulatory deadlines and compliance milestones impacting telecom supply chain operations through 2027. Days-away and status update automatically each day.
FY2026 NDAA §§834-835 targets for eliminating adversary reliance in optical glass / optical systems and computer displays
FCC software/firmware update waiver for previously authorized foreign-produced routers and UAS was extended and expanded (DA 26-454)
FAR §5949 statutory prohibition on procurement of covered semiconductor products / services takes effect
DoW Section 1260H indirect-procurement (goods/services) prohibition takes effect
BIS Connected Vehicles ICTS — software prohibitions begin (hardware MY 2030 / Jan 1, 2029 for non-MY units)
FAR federal IoT purchasing mandate (Cyber Trust Mark stack) takes effect
NDAA §866 DIB cyber harmonization annual report to Congress due
CISA 2015 sunset extended to December 11 by the September 2 CR (H.R. 6500); long-term reauthorization pending
Section 232 polysilicon minimum-import-price regime and downstream tariffs effective
BIS 50% Affiliates Rule suspension runs through Nov. 9, 2026; reimposition begins Nov. 10, 2026 unless extended
CMMC Reform Task Force report to the DoW CIO expected
DOJ/DHS/NCC implementing procedures due for the Aug 12 NSPM private-sector cyber-operations program (60-day clock)
Next FCC Open Meeting
CIRCIA final rule expected (communications-sector town hall and written-input dates passed in June 2026) — 72-hour incident / 24-hour ransom reporting for covered communications-sector entities
FIPS 140-2 certificates move to the CMVP Historical List
FCC 26-50 Third FNPRM reply comments due
FCC 26-50 Third R&O rules effective — logic-bearing component prohibition and online-marketplace marketing rules
FCC 26-50 Third FNPRM comments due
Military-grade / swarming-capable UAS import-and-marketing prohibition comments due (FR Doc. 2026-15659)
Section 1709 / covered UAS import-and-marketing prohibition comments due (PS Docket No. 26-184)
Submarine cable Second FNPRM comments due (OI Docket No. 24-523, MD Docket No. 24-524)
NIST SP 800-213r1 draft comments due
CMMC Reform Task Force RFI responses due (12:00 p.m. ET, email submission)
NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" published — NCC directed to stand up a vetted private-sector cyber-operations program
FCC releases Order of Revocation against Odyssey Robot LLC — first completed national-security equipment authorization revocation (follows DA 26-746 Order to Show Cause)
PSHSB announces Cybersecurity Label Administrators and opens a new CLA filing window under the U.S. Cyber Trust Mark program (PS Docket 23-239)
OIA issues Route Position List filing instructions for the submarine cable First R&O one-time information collection (OI 24-523 / MD 24-524); erratum released in the Section 1709 / covered UAS §2.939(e) proceeding (PS Docket 26-184) — comment dates unchanged
FCC August Open Meeting — no supply-chain items in scope for the tracker
Section 301 in-transit window fully closes; NTIA extends Tribal broadband deadlines 60 days
FCC adds power inverters and advanced robotic devices to the Covered List (DA 26-786)
Submarine cable Second R&O published in the Federal Register (FR Doc 2026-15123); router Conditional Approval (DA 26-775)
US-China "Board of Trade" docket — rebuttal / response window closes
Section 122 global surcharge expires — the 10% surcharge imposed effective Feb 24, 2026 to replace the IEEPA tariffs after the Supreme Court’s Feb 20, 2026 Learning Resources ruling
USTR forced-labor Section 301 final action announced (July 23), effective 12:01 a.m. ET July 24 as the Section 122 surcharge expires
FCC ADOPTED the Dangerous Gear Third R&O + Third FNPRM (ET Docket 21-232), released as FCC 26-50 — closes the component-part loophole, reaches online marketplaces, and narrows the critical-infrastructure definition on remand; the July Open Meeting also adopted Upper C-Band auction rules (adjacent)
FCC prohibition on importing and marketing certain previously authorized covered equipment takes effect (47 CFR § 2.939(e))
1260H DFARS internal staff draft reportedly due to regulators (soft date, trade-bar reporting)
USTR Section 301 forced-labor — post-hearing rebuttal comments due (5 days after last hearing day)
FCC equipment-authorization integrity Second FNPRM reply comments due (test lab / TCB reciprocity, IP protections, database modernization); record closed
DoD suspends CMMC Phase 2; CMMC Reform Task Force stood up (CIO memo dated July 10)
US-China "Board of Trade" USTR docket — written comments closed (rebuttals/responses due July 27)
USTR Section 301 forced-labor hearings concluded
Submarine cable First R&O remaining rules effective (DA 26-684; 91 FR 42137) following OMB approval of the information collections on June 26, 2026
Digitalsystem services added to the Covered List (DA 26-673) following the Section 214 denial (FCC 26-44)
FCC WC Docket 26-82 reply + PRA comments due; USTR Section 301 hearings began (ran through July 9)
USTR Section 301 forced-labor tariff written comments closed (10% on 14 economies / 12.5% on the remaining 46; docket USTR-2026-0265; hearing-appearance requests were due June 22 via USTR-2026-0266; hearings ran July 7–9)
Commerce Section 232 data-center semiconductor market report deadline passed — no public action; watch for Federal Register Phase 2 modification
DoW Section 1260H direct-contracting prohibition IN EFFECT under FY2024 NDAA §805 (new, renewed, or extended contracts with 1260H List entities and entities under their control; list at 188 entities); FY2025 NDAA §851 lobbyist prohibition (10 U.S.C. 4663) also in effect; TINA certified cost-or-pricing-data threshold under 10 U.S.C. 3702 rose for contracts entered after this date; Class Deviation 2026-O0025 (June 29) created DFARS Subpart 240.70 and clause 252.240-7995, with the notice-and-comment Section 805 rule (RIN 0750-AM09) still unpublished; DoD compliance/waiver guidance posted at businessdefense.gov
FCC Public Notice prohibiting further importation and marketing of certain previously authorized covered equipment under 47 CFR § 2.939(e)
FCC ADOPTED the Second Submarine Cable Report & Order (OI 24-523 / MD 24-524) by a unanimous 3-0 vote — bans all foreign-adversary equipment, introduces first-time SLTE operator licensing, presumptive disqualification for foreign-adversary applicants (10% is the reportable-interest threshold, not a safe harbor), and a fast-track for trusted operators
CIRCIA communications-sector written input due (7 days after the June 16 Grouping A session)
USTR Section 301 forced-labor — hearing-appearance requests due
Submarine cable ex parte / Sunshine cutoff (OI 24-523 / MD 24-524)
CIRCIA communications-sector town hall (critical-infrastructure grouping A)
DoW deadline under FY2026 NDAA §1521 for expedited cloud Authorization to Operate (ATO) guidance
DoW deadline under FY2026 NDAA §1512 for a department-wide AI/ML cybersecurity & governance policy
FCC Trusted Test Labs / equipment-authorization integrity rule effective (FCC 26-28)
FCC Foreign Adversary Control attestation rule effective (GN Docket 25-166; FCC 26-2)
FCC WC Docket 26-82 — comments due on domestic Section 214 / Covered List / foreign-adversary proposal (FCC 26-29)
DoW deadline under FY2026 NDAA §866 to harmonize cybersecurity requirements across the defense industrial base and eliminate duplicative DFARS provisions
DoW CMMC DFARS contractual requirement in effect; assessments and flow-downs ramping
SAM.gov FASCSA exclusion / removal order checks under FAR 52.204-30
08. INTERAGENCY OVERLAP ANALYSIS
Where the Right Hand Does Not Know the Left: Federal agencies duplicating work on the same problems through parallel authorities, different statutes, inconsistent timelines, and uncoordinated outcomes. Each cluster opens a detail panel documenting the double-work mechanics, the compliance burden by provider tier, the federal government own admissions of the duplication, and one primary source per claim.
Themes × Agencies heat map
Each row is an overlap cluster, each column a participating agency. Filled cells mark participation; the number is the count of that cluster related initiatives attributable to the agency, computed from the dataset. Select a cell to open the cluster detail filtered to that intersection, or a row label to open the full cluster.
| Cluster | USTR | BIS | FAR Council | CISA | DoD | FCC | DHS | FASC | Commerce (BIS/OICTS) | CFIUS | DoJ | OMB | NTIA | State Dept | Congress |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | 1 | 1 | |||||||||||||
• | 1 | 1 | 1 | ||||||||||||
1 | • | 1 | 1 | • | • | ||||||||||
1 | 1 | ||||||||||||||
• | 1 | • | • | ||||||||||||
1 | 1 | • | |||||||||||||
1 | 1 | • | |||||||||||||
1 | • | 2 |
Shared jurisdiction clusters
Where the Pressure Converges
A visual read of the June–July 2026 compliance sprint and three views of where federal initiatives overlap: a theme × agency heat map, the initiatives where agencies co-lead the same workstream, and rules that span multiple themes. Click any event or cell to explore the detail.
Event Horizon
Verified as of September 8, 2026. The September convergence has largely resolved: FCC 26-50's logic-bearing component prohibition took effect September 8 with Third FNPRM replies due September 21, the CMMC Reform Task Force report lands on or about September 13, and FIPS 140-2 certificates move to the CMVP Historical List September 21. The CISA 2015 information-sharing authority did not lapse September 30: the September 2 continuing resolution (H.R. 6500) moved the sunset to December 11, 2026, alongside the funding deadline. Ahead: the Anzu §2.939(e) comment deadline September 23, the Xi state visit September 24 (the decision point for the November 10 BIS Affiliates Rule reimposition and the rare-earth truce), the submarine cable Second R&O effective September 25, the Section 232 polysilicon minimum-import-price regime effective December 4, and the CISA 2015 sunset December 11. Enforcement remains a live front alongside rulemaking, with the August 11 Odyssey Robot revocation (DA 26-839) standing as the first completed national-security equipment-authorization revocation, and a new adjacent cyber-policy clock runs to roughly mid-October for the August 12 NSPM's private-sector cyber-operations implementing procedures. Days-away and status update automatically each day.
Overlap Map — Themes × Agencies
Each cell counts the initiatives where a cross-cutting theme meets a lead agency. Darker cells are convergence hotspots — places where members face stacked, overlapping obligations. Click a cell to see the initiatives behind it.
| FCC | Commerce / BIS | DHS / CISA / NIST | DoW / FAR | USTR / Treasury | White House | |
|---|---|---|---|---|---|---|
| Foreign-Adversary & Ownership | ||||||
| Equipment Authorization & Labs | ||||||
| Export Controls & Tariffs | ||||||
| Cyber Incident & Software Assurance | ||||||
| Procurement & Contracts | ||||||
| Network Infrastructure (Cable / 214) |
Select a cell above to see which initiatives drive that overlap. Hotspots sit at FCC equipment authorization (8), FCC foreign-adversary authority (7), CISA software assurance (7), and DoW / FAR procurement (6) — FCC now carries two 7-plus fronts, stacked compliance rather than one.
Shared Jurisdiction — Where Agencies Co-Lead
The heat map counts initiatives per agency. This is the actual overlap: single workstreams that two or more agencies lead jointly, so a member responding to one is answering to several at once. 13 of the initiatives mapped in this view carry shared jurisdiction.
Four-agency committee review feeds FCC Section 214 / cable licensing decisions. July 7 Digitalsystem action: Committee recommendation → 214 denial → same-day Covered List placement.
Joint advisory AA25-239A; intersects CIRCIA reporting and FCC cyber rules.
§866 cyber harmonization, §§834-835 adversary-reliance, §1521 cloud ATO, §§843-850/1692 procurement bans.
Investment-screening posture flows into Team Telecom and ICTS reviews.
Tariff + trade-remedy track; overlaps BIS export controls and forced-labor 301.
Secure software/SSDF, post-quantum migration, IoT, AI — drives multiple downstream rules.
Collection mandate now agency-discretionary after OMB M-26-05.
Data-center permitting, AI-stack export, federal AI procurement.
Paired with the 2026 National Cybersecurity Strategy. Extended by the August 12, 2026 NSPM on transnational cyber-enabled crime, which directs the NCC to stand up a vetted private-sector offensive cyber-operations program; DOJ/DHS implementing procedures are due ~mid-October (likely around October 11).
Bulk-sensitive-data transfer restrictions; CISA security requirements annex.
In effect June 30, 2026; Class Deviation 2026-O0025 (June 29) created DFARS Subpart 240.70 and clause 252.240-7995, with the notice-and-comment Section 805 rule (RIN 0750-AM09) still unpublished. WuXi AppTec designation enjoined August 7, 2026. DoD compliance/waiver guidance posted at businessdefense.gov.
FCC program built on NIST IR 8425 criteria; FAR mandate by Jan 4, 2027.
FIPS 203/204/205 + NSA CNSA 2.0 migration timeline.
Initiatives That Span Multiple Themes
The other overlap dimension: a single rule that lands in more than one compliance bucket, so it shows up in multiple rows of the matrix above.
This Supply Chain Policy Brief is provided by USTelecom – The Broadband Association for general informational and member-education purposes only. It summarizes selected federal and state supply-chain, cybersecurity, procurement, foreign-adversary, and related national security developments that may be relevant to members. It does not constitute legal, regulatory, or compliance advice or a legal opinion, and should not be relied upon as a substitute for advice from qualified counsel.
The application of the laws, regulations, orders, deadlines, and initiatives discussed here depends on each member's particular facts and circumstances. Members should consult their own legal, regulatory, and compliance advisors before taking or refraining from any action based on this Brief.
Requirements may change and agency interpretations may evolve after publication. USTelecom has sought to summarize developments accurately as of the date indicated but undertakes no obligation to update the Brief and makes no representation or warranty as to its completeness, accuracy, timeliness, or applicability to any member or situation.
Where this Brief references or summarizes statutes, regulations, agency guidance, or other third-party materials, those references are provided for convenience only. Members should review the underlying sources directly.
This Brief is confidential and intended solely for USTelecom members and other recipients USTelecom expressly authorizes. It may not be distributed, quoted, or published without USTelecom's prior authorization.
