Five months after the FCC's blanket ban on foreign-manufactured consumer routers, the rule has quietly turned into something closer to a security certification program: brands that can prove a clean, transparent supply chain get conditional exemptions to keep selling. Two have gotten one. The brand whose hardware was actually behind the security incident that triggered the ban hasn't.
Netgear: First Major Exemption, April 2026
Netgear became the first major router brand to receive an FCC exemption from the ban, on April 15, 2026 — about three weeks after the rule took effect. The exemption lets Netgear continue importing and selling its foreign-manufactured router lineup while it works within the FCC's emerging supply-chain security framework.
Starlink: A Conditional Exemption With an Expiration Date
Starlink (SpaceX) secured its own conditional exemption on July 27, 2026 — specifically covering new devices manufactured in Vietnam, valid through February 1, 2028. That's a narrower, time-boxed exemption compared to Netgear's, and it's the exemption that later let Starlink file its first Wi-Fi 7 router, the UTR-261, for FCC certification in August 2026 — a story we cover in detail separately, including exactly why that filing became notable.
TP-Link: The Brand Left Out
TP-Link has not received a comparable exemption. That's not incidental — TP-Link devices made up the majority of the Flax Typhoon botnet that motivated the original ban, compromised in large numbers and used for DDoS attacks, credential spraying, and anonymizing proxy infrastructure for state-linked operations. TP-Link has publicly framed the stricter scrutiny as a "bar" being set for the whole industry rather than a targeted penalty — but in practice, it's the company facing the steepest path back to unrestricted US sales.
| Company | Exemption status | Date | Scope |
|---|---|---|---|
| Netgear | Granted | April 15, 2026 | General exemption |
| Starlink (SpaceX) | Granted, conditional | July 27, 2026 | Vietnam-made devices, through Feb 1, 2028 |
| TP-Link | Not granted | — | Named source of the botnet that triggered the ban |
What "Conditional" Actually Means
None of these exemptions restore the pre-ban status quo. What's emerging instead is a case-by-case certification model: a manufacturer has to demonstrate a transparent, auditable supply chain and meet enhanced security controls to get cleared, and even then the clearance can be scoped narrowly — by manufacturing country, by product line, or by time window, as with Starlink's 2028 cutoff. It's less "ban lifted" and more "probation granted."
Why This Matters If You're Shopping for a Router
Brand name alone no longer tells you whether a specific router is legally sellable in the US right now. A Netgear model may be cleared while a TP-Link model in the same category isn't — and a Starlink device may be cleared only because of a manufacturing-country-specific carve-out that could change before 2028. Checking the exemption status of the specific model, not just the brand, is the only way to know for sure before you buy.
Our Take
The FCC's approach here is more coherent than a flat ban would have been — it targets the actual risk factor (unaudited, insecure supply chains) instead of punishing every foreign-made device equally. But it also means TP-Link's path back to full market access depends on convincingly closing the exact gap that let Flax Typhoon happen in the first place, and that's a harder bar to clear than a paperwork exemption.
How the Exemption Process Actually Works
Getting cleared isn't a matter of simply asking. The FCC's emerging framework requires manufacturers to document their supply chain in enough detail to demonstrate it's auditable — where components are sourced, how firmware is signed and verified, and what controls exist against the kind of unpatched, mass-exploitable firmware that let Flax Typhoon take over so many devices in the first place. That documentation burden is a big part of why exemptions have rolled out one company at a time rather than industry-wide, and why some exemptions — like Starlink's — are scoped narrowly to a specific manufacturing country rather than granted globally.
Who Might Be Next
ASUS, Eero, Google Nest, Linksys, Ubiquiti, and Synology all remain in the same position TP-Link is in: named under the original ban, without a confirmed exemption as of this writing. Given that Netgear and Starlink both cleared the bar within a few months of the ban taking effect, it's reasonable to expect at least some of these brands to follow a similar path — assuming they can produce the same kind of supply-chain documentation. We'll update this piece as new exemptions are confirmed.
What Hasn't Changed
It's worth repeating: none of this affects routers already installed in homes. The exemption process only determines which foreign-manufactured routers can legally be imported and sold as new going forward. If you own a TP-Link router today, it keeps working exactly as it did before the ban — the open question is only about what you'd be able to buy new, from that brand, if you needed a replacement right now.