Skip to content

Product1 publisher3 min readPublished

Asus clears the approval queue that now gates new foreign-made routers in the US

Asus is the biggest name so far through the Conditional Approval process that the Defense and Homeland Security departments run. Applicants hand over a component-level supply chain report and a time-bound plan to build the router in the US.

The Product Desk · Product desk

Photograph accompanying Asus clears the approval queue that now gates new foreign-made routers in the US
Photo: wired.com

What happened

  • In March the FCC banned new consumer internet routers manufactured outside the US, adding foreign-made consumer routers to the Covered List of equipment deemed an unacceptable risk to national security.
  • Routers that already hold FCC approval can keep being sold, used and updated with new firmware at least until January 1, 2029, and routers already in American homes are not covered.
  • Any new router made outside the US now needs FCC approval before it can be imported, marketed or sold, and that includes devices from US companies manufactured overseas.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The onshoring plan is filed for a named router, so a vendor's clearance does not carry over to its successor, and a 2027 refresh depends on filings a buyer has no way to schedule around.
  • cost Admission to the US consumer market now costs a component-by-component bill of materials, an ownership disclosure and quarterly progress reports on American factory plans, paid by any vendor that wants to ship a new model.
  • decision A team standardizing on a mesh system chooses between an authorized SKU it can stockpile and a newer one whose clearance it would be betting on.
  • exposure Internet providers that hand out routers by the million are in the same queue as retail brands, which puts their customer-premises refresh cycle inside a Defense and Homeland Security review.

A home router gets replaced when the old one stops holding a signal, and the replacement is whatever the store has in stock that day. That shopper sees a stocked shelf [3]. The rule covers new consumer Wi-Fi routers and mobile hotspot devices, and not phones with hotspot features [5]. The people who feel it are the ones writing next year's hardware standard.

Conditional Approval comes from the Department of Defense and the Department of Homeland Security, and it has three parts [6]. The corporate structure disclosure covers ownership, board membership and "any foreign government ownership, control, influence, financing, or material support" [7]. The supply chain report breaks down where every major stage of production happens and lists every component in every router or hotspot the applicant makes, with its origin [8]. The third part asks for "A detailed, time-bound plan to establish or expand manufacturing in the United States for the router for which the applicant is seeking Conditional Approval", plus quarterly status updates on progress [9].

That wording ties the clearance to a single product. A vendor through the gate can keep selling and updating existing devices and release new routers and mesh systems [11], and next year's model is still its own filing.

Wired calls the definition of foreign-made murky, covering any consumer-grade router designed or manufactured outside the US, or made by a company that is not completely US-owned and operated [17]. Its list of the covered majors runs Netgear, TP-Link, Asus, Amazon's Eero, Google's Nest, Synology, Linksys and Ubiquiti, along with most or all of the routers US internet service providers hand out [12]. Wired's September 2026 update says several more companies now hold Conditional Approval, the biggest being Asus, and it does not name the others [10]. Of those eight majors, Asus is the only one the piece identifies as approved [19].

The FCC put its reasoning in writing: "Malicious actors have exploited security gaps in foreign-made routers to attack American households, disrupt networks, enable espionage, and facilitate intellectual property theft" [13]. The commission also wrote that "Foreign-made routers were also involved in the Volt, Flax, and Salt Typhoon cyberattacks targeting vital US infrastructure" [14]. Bogdan Botezatu, director of Threat Research at Bitdefender, said consumer routers "sit at the edge of every home network, which makes them an attractive target and a strategic risk if compromised at scale" [15]. Asked whether the risk is real, he said yes, and added that there is no easy way to prove intent [16].

For anyone buying consumer-grade networking gear in volume, two facts sort the decision: whether the model on your standard already holds FCC authorization, and whether its vendor holds Conditional Approval for the model meant to replace it. Both yes, and you buy as normal. Authorized model with an unapproved successor, and you buy the spares now and plan around a frozen SKU, with roughly 28 months of sanctioned sell-through left before the 2029 cutoff [18]. Unauthorized model from an approved vendor, and the question for the account team is which filing names that specific SKU, and when. Neither, and the product is unavailable until the vendor produces an approval, whatever the roadmap slide shows.

What to watch

  • Whether the full list of conditionally approved companies is published, and which of Netgear, TP-Link, Eero, Nest, Synology, Linksys and Ubiquiti appear on it.
  • Whether the January 1, 2029 sell-through date moves, since the FCC's FAQ words it as 'at least until'.
  • The first quarterly onshoring status update from an approved vendor, and whether a missed milestone costs the approval.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories