FCC Drone Vendor Lied About DJI-Created Product: New Rules Explained

Techwalla may earn compensation through affiliate links in this story. Learn more about our affiliate and product review process here.

FCC Drone Vendor Lied About DJI-Created Product: New Rules Explained

The FCC votes tomorrow on rules that would fundamentally change what an equipment authorization label means for a drone sold in the United States. The core change: certification would be blocked for any device whose internal logic-bearing components were produced by an entity on the agency's national-security Covered List, regardless of who assembled the finished product, according to the Commission's Third Report and Order circulated for tomorrow's open meeting. A reported case involving a US drone vendor and questions about a product's true component origins has helped surface exactly the gap these rules are designed to close though the available record does not identify the vendor, name any specific product, or confirm which manufacturers were involved.

The Covered List has been updated to address uncrewed aircraft systems, UAS critical components, and routers produced in foreign countries, placing commercial drone hardware under the same supply-chain framework previously applied to restricted telecom equipment, the Commission's document states. The accompanying rulemaking notice acknowledges this order won't finish the job: the FCC identifies "several additional loopholes" in the current framework that may carry national security implications and would remain open even after the order passes.

Advertisement

Why drones are unusually exposed to component-level risk

Video of the Day

Exploded diagram of a commercial drone highlighting radios, flight controller, signal processors, GPS, camera module, and firmware subsystems with arrows to different upstream suppliers to illustrate layered sourcing risk

The component-part problem hits drones harder than most consumer electronics because of how they're built. A typical commercial drone isn't a single product from a single supply chain. It's an assembly of radios, flight controllers, signal processors, GPS modules, camera systems, and firmware-intensive subsystems each potentially sourced from a different manufacturer across multiple tiers. A drone vendor might contract-manufacture the finished airframe while sourcing the flight controller from one supplier, the image transmission module from another, and speed controllers from a third. Each of those components may itself contain integrated circuits from yet another producer.

That structure creates layered sourcing risk at every tier below the assembler. Under the old authorization framework, none of those upstream relationships were the FCC's concern only the company whose name went on the box. The Covered List's recent expansion to include UAS and UAS critical components, per the FCC, reflects a recognition that drone hardware isn't cleanly analogous to a router or a handset. The component web is wider, the sourcing more fragmented, and the gap between what a brand label suggests and what's actually inside can be considerable.

Video of the Day

How the FCC equipment authorization drone component loophole worked

Flowchart of the prior FCC equipment authorization process showing certification tied to the entity that assembled the finished drone while upstream component origins were not examined, setting up the change described in FCC drone vendor lied about DJI-created product

FCC equipment authorization has historically focused on the finished device and the entity that assembled it. Nothing in the existing rules explicitly reached upstream suppliers of internal components. A drone maker could source flight controllers, signal processors, or communication modules from a Covered List manufacturer and still obtain a valid FCC certification, because authorization examined who built the box, not what was inside it, the FCC document confirms.

The proposed definition of "logic-bearing hardware components" is broad by design. The FCC defines the term to cover any device, module, sub-assembly, integrated circuit, or other physical component that generates and uses timing signals or pulses at a rate exceeding 9,000 cycles per second using digital techniques, per the Commission's order. That threshold reaches virtually every meaningful piece of electronics in any modern commercial drone.

The prohibition is framed without qualification. Certification would be blocked for any device incorporating a component produced by a Covered List entity regardless of who manufactured everything else, the order states. The logic is straightforward: if a Covered List entity had produced the whole device, it couldn't be authorized. Producing just one component inside it shouldn't change that outcome. A vendor disclosing only its final assembler, and not its component suppliers, operated in a space the existing rules left open. The proposed order closes that space by making component origin, not brand identity, the disqualifying fact.

Advertisement

Advertisement

What changes for vendors, and how the accountability chain now extends to online sellers

Screenshot-style mockup of an online drone listing where the FCC ID is prominently displayed at the point of purchase for third-party marketplace sellers

The practical weight of the new rules falls before certification, not at it. Vendors would need to establish that no logic-bearing component in their device traces back to a Covered List entity which means working backward through the supply chain to verify what each upstream supplier actually produced and sourced. A contract manufacturer's clean record is not sufficient if that manufacturer sourced a restricted component from a Covered List producer. The compliance question reaches further up the chain than most drone vendors have historically needed to look.

Post-market exposure is new territory too. The order would require full recertification for any modification or permissive change made by a Covered List entity after a product is authorized, the FCC document states. For buyers, a certified device would carry a different meaning if the order passes: one representing a supply chain screened at the component level, not just at final assembly. That stronger assurance would apply to products authorized after the rules take effect; existing certifications are not retroactively voided.

The order also updates a disclosure requirement that has been on the books since 1979. Section 2.925(d) has required since adoption that the FCC ID be permanently affixed to a device and be "readily visible to the purchaser at the time of purchase," per the FCC document. That language was written for physical storefronts. Online purchases now account for over 70 percent of consumer electronics sales, and the rule had never been updated to reach that environment, the FCC notes.

The order addresses that gap directly. The Commission clarifies that "marketing" includes the activities of online marketplaces that list, distribute, or offer equipment for sale through third-party sellers, the document states. Drone retailers and major platforms would be required to display a valid FCC ID at the online point of sale, and the FCC says marketplaces may be held liable for failures to do so. Platforms that have treated third-party product compliance as the seller's problem alone will need to adjust that position.

Advertisement

Advertisement

What the FCC says it still can't fix

Supply-chain bill of materials (BOM) illustration showing required documentation of component origins across multiple tiers, alongside notes about remaining national-security gaps

Even as it moves against the component-part loophole, the FCC acknowledges in the accompanying Third Further Notice that the current framework still has gaps that may carry national security implications, the document states. The measures now out for comment are specific: mandatory hardware and software bills of materials requiring vendors to document component origins across the full supply chain, restrictions on certain importation pathways for covered equipment, and stronger post-market enforcement after a product clears authorization.

The agency is also considering splitting the Covered List into two distinct categories one based on the identity of the producer or provider, the other based solely on where a product was manufactured. That bifurcation could expand the universe of restricted equipment beyond the companies currently named on the list, per the FCC, potentially sweeping in products from unnamed manufacturers based solely on their country of production.

On cost: the FCC estimates the order would impose roughly $50 million in annual compliance costs on industry, the document states. The agency argues that figure is justified preventing even one percent of malicious cyber activity or network disruption tied to compromised equipment would, by the Commission's own estimate, produce direct economic benefits in the hundreds of millions.

This order is the third in a series the FCC has used to progressively tighten supply-chain controls on communications equipment. Bills of materials requirements, import restrictions, and post-market enforcement measures still in the proposal stage make clear that what vendors need to verify before entering the authorization process keeps expanding. Whatever the reported vendor case ultimately reveals, the agency's direction isn't ambiguous: component-level transparency is becoming a compliance floor, not a preference, and tomorrow's vote sets the next baseline.

Advertisement

Advertisement