The Information Technology Industry Council just fired a warning shot across the FCC's bow. Its message: optical modules are not Huawei. The industry body formally opposed the Commission's proposal to sweep all foreign-made optical modules into the Covered List, a move that would effectively ban their use in federal procurement. This is not a routine regulatory objection. It's a collision between a legislative mandate designed for specific bad actors and an administrative appetite for wholesale categorization.
Washington is moving from listing companies to banning entire product categories. The optics are terrible — and the technical implications are worse.
The Covered List, born from the Secure Equipment Act of 2021, was always a scalpel aimed at specific threats — Huawei, ZTE, the named entities. The statutory language focuses on communications equipment that poses a national security risk, determined through a rigorous process. Now the FCC appears to be reaching for a sledgehammer, proposing to sweep an entire product category into the list. ITI, representing a who's who of American tech — think Apple, Google, Microsoft, Amazon — is telling the agency to step back and recalibrate.
Their logic is straightforward: focus on entities with clear ties to foreign adversaries, not the entire output of trusted companies. This pushback is an indication that the category approach is not just legally questionable; it is operationally unworkable.
Let me be clear about what a category ban on optical modules actually entails. Optical modules are not monolithic. They range from cheap SFP+ transceivers for data centers to high-end coherent modules for long-haul submarine cables. They are built by a global supply chain: Chinese giants like Zhongji Innolight and Eoptolink dominate the volume, but American firms like Coherent and Lumentum are still major players. A category ban is a blunt instrument that treats a component with a thousand variations as a single point of failure. It ignores the technical reality that a module's risk profile is defined by its firmware, its management interface, and its supply chain — not by the passport of its manufacturer.
The legislative intent of the Secure Equipment Act is clear. Congress was worried about state-sponsored backdoors in core infrastructure. The law was drafted to empower the FCC to act decisively against specific threats. It was not designed to be a trade embargo tool for the federal procurement market.
This distinction matters. It is the difference between a targeted strike and a carpet bomb. The FCC is proposing a carpet bomb.
The arguments against this approach have merit, grounded in a rational analysis of what a category-wide ban would actually do.
First, the legal overreach. The FCC's authority under the Secure Equipment Act is not a blank check. The statute requires a finding that specific equipment poses a national security risk. A category ban presumes that all foreign-made modules are risky. That is not how the law is written. ITI is right to point out that the Commission would be expanding its authority beyond the statutory text. This creates an opening for a legal challenge under the Administrative Procedure Act. The FCC's action could be deemed arbitrary, capricious, and an abuse of discretion. And a court might even apply the Major Questions Doctrine, requiring explicit congressional authorization for a decision of this economic and political significance. The precedent here is West Virginia v. EPA — if the FCC tries to regulate an entire product category, it will need more than a nudge from Congress.
Second, the supply chain reality. We are not just talking about a federal procurement issue. The market is interconnected. A federal ban is a chilling effect that extends far beyond the government. Major cloud providers and telecom operators, even those not bound by federal procurement rules, will likely preemptively drop any supplier on the list to avoid compliance headaches. This means a category ban could trigger a massive supply chain disruption, with no ready substitute. The U.S. market relies heavily on these foreign-made modules. Domestic capacity is nowhere near enough to fill the gap. We would see immediate price hikes, project delays, and a scramble for the few non-listed suppliers.
Third, the compliance burden. For the companies that buy these modules, the obligation becomes a nightmare. They must trace the origin of every single optical component in their networks. Given that these modules are embedded in larger switches, routers, and servers, this requires a bill-of-materials level of traceability that most companies simply do not have. It is not a simple fix. It is a multi-year, multi-million-dollar project. And the risk of unintentional violations would be very high. The consequences — contract termination, debarment, civil penalties — are severe.
Fourth, the international consequences. The optical module supply chain is deeply globalized. A blanket ban is a violation of WTO non-discrimination principles. This will be a serious flashpoint. China will not simply accept this. They have their own tools of response, from trade countermeasures to challenges at the WTO. The FCC might be creating a trade war over a component that is not even designed by a specific adversarial government.
The FCC's push also ignores a critical fact: optical modules are not like routers or switches. They are far less capable of hosting malicious code or performing complex tasks. The threat model is fundamentally different. The risk of a backdoor in an SFP transceiver is low. The firmware is minimal. The attack surface is constrained. The FCC's one-size-fits-all approach doesn't match the technical reality. It is a solution in search of a problem, which will create more problems than it solves.
This is a classic case of an agency's desire to control the entire ecosystem leading to a decision that is both legally weak and practically damaging. The FCC would be better served by a more targeted, risk-based approach.
Instead of banning an entire category, the FCC should be building a system to audit and certify. The focus should be on the supply chain's integrity and the absence of backdoors, not on the geographic origin of the product. A certification program — where trusted third parties audit the manufacturing process and the firmware for a security — would be far more effective. It would allow trustworthy foreign manufacturers to stay in the market while excluding those with real, demonstrable connections to foreign adversaries. The ITI is proposing a "risk-based approach" and they are right. That is how you actually secure the supply chain, not by banning a category.
We have seen the damage from this overreach. The Huawei and ZTE bans were effective because they targeted specific entities. The market could adjust. A category ban is a different beast. It's a systemic shock that will ripple through the entire network infrastructure. And once that precedent is set, what is next? Switches? Servers? Entire classes of technology? This is the slippery slope. The Covered List is supposed to be a precision instrument. Turning it into a broad-spectrum weapon is a strategic mistake.
There is also a major risk of an unintended consequence: a two-tiered market. Large companies can afford the compliance costs to source from certified suppliers. Small and medium-sized ISPs will be priced out of the market. We will see a consolidation of the market, where only a few mega-vendors survive, reducing competition and increasing costs. This is the opposite of what the FCC should be trying to achieve.
The ITI's objections are not just about corporate self-interest. It is a defense of a workable, security-conscious approach to supply chain risk management. The FCC needs to listen. If it doesn't, it will face a prolonged legal battle, a market crash, and a trade war — none of which will make the country safer.
The "Covered List" should be a tool for precision, not a blunt instrument. The FCC is trying to use it as a hammer to hit a problem that is more like a screw. It is the wrong tool for the job. The agency needs to go back to the drawing board, not with a broader mandate, but with a more intelligent and calibrated approach to real security threats.
The outcome is uncertain. The FCC could double down and face legal challenges. Or it could pull back and adopt a more targeted approach. Either way, the final decision will set a major precedent. If the FCC wins this, we can expect to see more categories, more bans, and more bureaucratic. If it loses, it will be a strong signal that the agency must operate within the limits of its statutory authority.
This is not just a fight over optical modules. It is a fight over the future of tech regulation and the boundaries of national security power. The battle is being fought in Washington, but the outcome will shape the global supply chain for years. The industry is watching closely, and the FCC is on notice.


