Overview of the Section 214 Security Modernization Draft
The Federal Communications Commission (FCC) has circulated a draft Report and Order and Further Notice of Proposed Rulemaking in IB Docket No. 23-119 and MD Docket No. 23-134 (FCC-CIRC 2610-05). The circulated document outlines comprehensive regulatory reforms designed to modernize the Commission's international Section 214 framework to protect U.S. telecommunications services and infrastructure from evolving national security, law enforcement, foreign policy, and trade policy risks, particularly those posed by foreign adversaries.
The draft reflects the results of the initial Evolving Risks One-Time Information Collection conducted in late 2023 and early 2024. Of approximately 7,000 international Section 214 authorization holders listed in the International Communications Filing System (ICFS), approximately 1,235 entities responded, confirming that a substantial majority of recorded authorizations were inactive or defunct. Based on these findings and record feedback, the draft declines to adopt a 10-year renewal mandate or a formalized periodic review cycle. Instead, it adopts targeted application obligations, routine conditions, a new baseline information collection, and ongoing reporting of material changes.
- Proceeding Dockets: IB Docket No. 23-119 and MD Docket No. 23-134
- Document Type: Draft Report and Order and Further Notice of Proposed Rulemaking (FCC-CIRC 2610-05)
- Circulation Date: October 8, 2026
- Primary Focus: International Section 214 authorizations under 47 U.S.C. Section 214 and 47 CFR Part 63
Key Measures Adopted in the Draft Report and Order
The draft Report and Order establishes several new application disclosures, routine authorization conditions, and administrative revisions under Parts 1 and 63 of the Commission's rules.
To ensure network visibility and integrity, the draft institutes specific operational and corporate disclosure standards for all entities holding or applying for international Section 214 authority.
- Cross-Border Facilities Information: Facilities-based applicants and authorization holders must report details on terrestrial facilities crossing the U.S.-Mexico and U.S.-Canada borders, including physical street addresses, geographic coordinates, Federal Information Processing Standard (FIPS) codes, Common Language Location Identification (CLLI) codes, IP prefixes/AS domain numbers, principal equipment, and whether foreign adversary-affiliated individuals have physical or remote access. Resale-only applicants must disclose wholesale providers, underlying Mobile Network Operators (for MVNOs), and call detail record maintenance.
- 5% Ownership Reporting Threshold: Lowers the ownership disclosure threshold from 10% to 5% direct or indirect equity and/or voting interests, incorporating an 'actual knowledge' due diligence standard for U.S. publicly traded companies. The submarine cable rules in Part 1 retain a 10% threshold.
- Services and Geographic Markets: Applicants must identify current and expected future services, customer types, facilities arrangements, and operating markets.
- Third-Party Service Providers: Requires disclosure of third-party service providers that are foreign adversary-controlled, listed on the Covered List, or access networks/records from a foreign adversary country.
- Cybersecurity Program: Mandates certification of baseline cybersecurity practices structured under recognized frameworks like the NIST Cybersecurity Framework (CSF), CISA Cross-Sector Cybersecurity Performance Goals (CPGs), or CIS Critical Security Controls.
- Covered List Prohibition: Prohibits new authorization holders from using or adding producer/provider-based Covered List equipment or services, and prohibits existing authorization holders from adding such equipment or services.
- Service Commencement and Discontinuance: Requires authorization holders to commence service within one year of grant and report in-service dates; defines permanent discontinuance as three consecutive months of non-use, requiring authorization surrender and customer notice.
- Material Change Reporting: Establishes a routine condition requiring notification within 30 days of any material change to cross-border facilities, ownership, services, third-party providers, or certifications.
- Revocation of Non-Responsive Entities: Sets a formal notice-and-revocation process via Federal Register publications for authorization holders that failed to respond to the prior one-time collection.
Proposals in the Further Notice of Proposed Rulemaking
The accompanying Further Notice of Proposed Rulemaking (FNPRM) proposes additional measures to prevent national security threats from current and potential foreign adversaries.
The Commission seeks public comment on these proposals 30 days after publication in the Federal Register, with reply comments due 60 days after publication.
- Presumptive Disqualifications: Proposing rebuttable presumptions precluding authorization grants for entities controlled by foreign adversaries, listed on the Covered List, subject to prior national security revocations, holding certain foreign adversary financing or strategic agreements, or having senior leadership operating from foreign adversary countries.
- Capacity and Infrastructure Prohibitions: Proposing to prohibit authorization holders and their downstream customers from entering into Indefeasible Rights of Use (IRU), capacity lease, dark fiber, or spectrum arrangements with foreign adversary entities or Covered List entities.
- Comprehensive Service Provider Prohibitions: Proposing to bar the use of foreign adversary third-party service providers across broader operational and network functions.
- Cyber and Physical Security Plans: Seeking comment on requiring formal, signed cybersecurity and physical security risk management plans and 72-hour incident reporting for cyberattacks or breaches.
- Foreign Adversary Route Approvals: Seeking comment on requiring prior FCC notification and approval before commencing service on routes between the United States and foreign adversary countries.