News

FCC Updates Covered List to Include Kaspersky Cybersecurity and Anti-Virus Software

The FCC Public Safety and Homeland Security Bureau has updated the Covered List pursuant to the Secure Networks Act, adding cybersecurity and anti-virus software produced or provided by Kaspersky Lab, Inc. following a Department of Commerce determination.

Expansion of Covered Equipment and Services List

On July 23, 2024, the Federal Communications Commission's Public Safety and Homeland Security Bureau issued Public Notice DA 24-712 announcing an update to the list of communications equipment and services deemed to pose an unacceptable risk to national security (Covered List). The action was taken pursuant to Section 2 of the Secure and Trusted Communications Networks Act of 2019 and Commission rules 47 CFR Sections 1.50002 and 1.50003.

Under the update, the Bureau added cybersecurity and anti-virus software produced or provided by Kaspersky Lab, Inc., including its successors, assignees, affiliates, subsidiaries, and parent companies, to the Covered List.

Statutory Authority and Commerce Department Determination

Under the Secure Networks Act and the Commission's Supply Chain Second Report and Order (WC Docket No. 18-89), the FCC does not exercise independent discretion to add entities to the Covered List outside of determinations made by specified enumerated sources. One such source is a specific determination made by the Department of Commerce pursuant to Executive Order 13873 regarding information and communications technology and services (ICTS) supply chain security.

On June 20, 2024, the Department of Commerce issued a Final Determination (Case No. ICTS-2021-002, published at 89 Fed. Reg. 52434 on June 24, 2024) prohibiting Kaspersky from engaging in ICTS transactions with U.S. persons involving its cybersecurity products, services, and anti-virus software. Commerce concluded that Kaspersky's provision of these products, including through third-party entities integrating Kaspersky software into commercial hardware or software, poses undue and unacceptable risks to U.S. national security and the security of U.S. persons.

  • Commerce determination promulgated under 15 CFR Part 7 review authority regarding foreign adversaries.
  • Final Determination explicitly prohibits transactions involving software designed, developed, manufactured, or supplied by Kaspersky in whole or in part.
  • Prohibition includes the integration of Kaspersky cybersecurity and anti-virus software into third-party commercial software or hardware.

Comparison with Prior Covered List Additions

The FCC previously added information security products, solutions, and services supplied by AO Kaspersky Lab to the Covered List on March 25, 2022. That initial listing was based on Department of Homeland Security Binding Operational Directive (BOD) 17-01, which required federal agencies to remove Kaspersky-branded products from federal information systems.

The July 23, 2024 update broadens the scope of covered Kaspersky offerings beyond the 2017 DHS directive, which did not address Kaspersky code embedded in third-party products. The current listing reflects Commerce's broader determination covering both standalone Kaspersky software and integrated third-party applications.

Administrative and Docket Details

The action was issued under WC Docket No. 18-89, ET Docket No. 21-232, and EA Docket No. 21-233. The complete, updated Covered List is maintained on the FCC website.

Inquiries regarding the Public Notice may be directed to Zenji Nakazawa, Associate Bureau Chief, Public Safety and Homeland Security Bureau.

  • Document Number: DA 24-712
  • Release Date: July 23, 2024
  • Lead Dockets: WC Docket No. 18-89, ET Docket No. 21-232, EA Docket No. 21-233
  • Bureau: Public Safety and Homeland Security Bureau

Source documents

This article is based on an official Federal Communications Commission publication released July 23, 2024.

FCC release date: 2024-07-23. Article last updated: 2026-08-19.