supply-chaintrade-pressNewsThe Broadside2 min read

FCC's SBOM proposal splits telecom industry groups

NCTA and NTCA back mandatory SBOM/HBOM disclosure at equipment authorization; USTelecom and CTIA say vendor attestations would do the job with less burden.


TL;DR

Telecom industry groups filed sharply divergent comments on the FCC's proposal to require software and hardware bills of materials as part of equipment authorization. NCTA and NTCA-The Rural Broadband Association support mandatory SBOM/HBOM disclosure, with NTCA arguing small providers lack the market power to demand them from vendors otherwise. USTelecom and CTIA oppose the requirement, contending vendor attestations and confidential supplier lists can achieve the Commission's Covered List compliance goals without the compliance burden of full BOM disclosure. The comments respond to the FCC's August 2026 Third Further Notice of Proposed Rulemaking in ET Docket No. 21-232.

The FCC's August 2026 Third Further Notice of Proposed Rulemaking asked whether equipment authorization applicants should be required to disclose hardware and software bills of materials at certification. The responses, filed ahead of a September 8 comment deadline, reveal a clean split: groups representing cable operators and rural broadband providers want the requirement; groups representing larger wireless carriers and legacy telecom don't.

NCTA argues disclosure obligations should land on "entities that possess, control, and have decision-making authority over the product's components and other manufacturing, design, or assembly information." The carve-out matters, it means that when a device manufacturer holds the BOM, the manufacturer bears the obligation, not the service provider filing the authorization paperwork. The goal, NCTA says, is ensuring "the Commission receives (and downstream providers have access to) useful and actionable information."

NTCA takes the case further. The rural broadband group contends small providers "do not have the market power to require an SBOM or HBOM as a condition to purchasing software and hardware." Making disclosure a condition of FCC authorization, in NTCA's view, is the only way those providers will get it. The group also warns that if the FCC bans "any component" produced by a Covered List entity, the compliance burden on providers to verify equipment provenance becomes significant, and providers must be able to rely on the filed BOM rather than being held responsible for components discovered later.

The other side: attestations are enough

USTelecom flatly opposes mandatory BOM disclosure. "The Commission does not need a complete SBOM or HBOM to achieve its core compliance objective, confirming that equipment submitted for authorization does not contain components from entities on the Covered List," the group writes. Its alternative: strengthen the existing attestation framework with more granular certifications about particular component categories, and if more is needed, require a confidential list of relevant hardware component suppliers rather than a full bill of materials.

CTIA, representing wireless carriers, filed in opposition as well, citing challenges in meeting the FCC's requirements, though the Inside Cybersecurity summary cuts off before detailing CTIA's full argument.

The proceeding sits within the FCC's broader multi-year effort to address national security risks through equipment authorization, which has already produced rules adding hardware components to the Covered List and bifurcating that list into producer-based and production-location-based categories. The SBOM/HBOM question is one of several items the Third Further Notice teed up; the others (including "white labeling" of covered equipment) will get their own comment splits.


Published ·Deep Fathom

FCC's SBOM proposal splits telecom industry groups — The Broadside