Equipment that is not foreign-produced under the FCC's Covered List entries may be authorized and sold in the United States — but its non-covered status must be certified with sufficient evidence, and no regulation prescribes what that evidence is. Every manufacturer, importer, distributor, and buyer in a covered category now carries a documentation question with no published answer. This Protocol is that answer: an open, versioned standard for what a complete origin-evidence file contains, how it is verified, and how conformity may be claimed.
Download the complete Protocol — standard + Annexes A–G (PDF)
Certification registry & certificate lookup →
Status: Version 1.0, Public Comment Draft, August 2026. The Protocol is free to use, cite, and require of counterparties, with attribution. Comments and adoption inquiries: [email protected]. The Protocol is maintained by Gatewell Group; verification against it may be performed by any qualified party. Conformity with this Protocol is a documentation standard — it is not an FCC, DoW, or DHS determination of any device's regulatory status, and does not guarantee any authorization outcome.
The Protocol's three conformity marks. Each level is defined in Section 2.
The Protocol defines the contents, provenance, and maintenance of an Origin Evidence File ("OEF") for connected equipment in categories subject to the FCC Covered List — as of this version: unmanned aircraft systems and components, routers, power inverters, and advanced robotic devices. It is designed so that a regulator, certification body, insurer, or commercial counterparty examining the file can trace every origin claim to a source document, and so that the file survives the scrutiny it will only ever receive after something has gone wrong.
The Protocol prescribes evidence and procedure only — it sets no ownership, content-percentage, or origin threshold of its own. Every outcome standard is incorporated by reference from the governing Covered List entry, National Security Determination, or Conditional Approval guidance as in force on the file's revision date. Two context points from the July 27, 2026 documents for inverters and robotics: Conditional Approval applications must be submitted by January 1, 2028, and both National Security Determinations define "foreign-produced" as any article that does not qualify as a "domestic end product" under 48 CFR § 25.101(a) — the Buy American definition.
Open questions for the comment period. Comment is specifically invited (through October 31, 2026, [email protected]) on: how the commercially-available-off-the-shelf (COTS) provision of 48 CFR § 25.101(a) should be treated under the July 2026 listings; how the inverter definition's bidirectionality element applies to classes of EV supply equipment; whether the Protocol's evidence-age limits, confirmation counts, and retention periods are workable for mid-size manufacturers; and whether the deep-trace component matrices are complete. The Protocol asserts no conclusion on the first two — it requires the position taken to be recorded with its basis.
Level 1 — DOCUMENTED. The manufacturer has assembled a complete OEF per Section 3, current within twelve months, with every element officer-attested. Self-declared.
Level 2 — VERIFIED. A qualified independent verifier has examined the OEF per the Section 4 methodology — authenticating documents, cross-checking public authorization records, and confirming a sample of supplier declarations at source — and has issued a dated verification statement identifying the Protocol version and file revision examined.
Level 3 — MONITORED. Level 2, plus standing change-control: the manufacturer maintains the Section 5 triggers, material changes are re-attested within thirty days, and the file is re-verified annually. Monitored status lapses automatically if re-verification is missed. For Conditional Approval holders, Level 3 adds a quarterly onshoring evidence module tracking the guidance's own reporting metrics — capex milestones against plan, U.S. headcount, facility square footage, and percentage of components assembled in the United States — closed within fifteen days of each quarter end (the guidance requires a dedicated point of contact or office to update the issuing agency on onshoring status once a quarter).
3.1 Device identity. A complete schedule of covered-category models: marketing names, model numbers, FCC IDs or SDoC status, equipment classes, and authorization dates.
3.2 Coverage determination. For each model, a documented determination of whether it falls within each potentially applicable Covered List entry — made against the operative definitions the listings incorporate (quoted in the complete Protocol document: the inverter definition's two conjunctive elements; the advanced-robotics criteria and exclusion list), not against paraphrases. The current texts are re-retrieved at each revision, and a non-covered conclusion must identify the specific definitional element not met, with the evidence for it.
3.3 Production provenance. Every site performing final assembly, principal subassembly, firmware loading, or testing for the scheduled models: legal operator, address, ownership or contractual relationship, and the production step performed. A production-flow narrative from major components to shipped unit. A signed attestation from an officer of each operating entity.
3.4 Component origin. A bill of materials for each model identifying country of origin for each line item, with deep-trace documentation — supplier declarations traced one tier up — for the components that determine the device's character in its category. Plus, tracking the July 27, 2026 guidance: the country of origin of the device's design; a supply-chain concentration summary by country expressed as both a percentage of total value and of production volume; and a sole-source supplier register with each supplier's country and a documented contingency plan per sole source.
3.5 Corporate provenance. The manufacturer's entity chain to its ultimate parents; beneficial ownership at five percent or greater with jurisdiction — the threshold the Conditional Approval guidance itself requires; board members and executive leadership with nationality and country of residence; express disclosure of any foreign-government ownership, control, influence, financing, or material-support arrangement; and a dated screening of all chain entities against the current Covered List entities and their published subsidiaries and affiliates.
3.6 Software, firmware, and IP provenance. A software bill of materials in SPDX or CycloneDX format for device firmware and companion applications; the entities responsible for IP ownership and for software updates; the country of origin of onboard software and firmware, including AI model weights where the category definition reaches them; the location and operator of build and code-signing infrastructure; update-server jurisdictions; and a data-flow summary identifying every endpoint the device communicates with in normal operation.
3.7 Evidence quality. Testable rules for the file itself: unique document IDs with a master index mapping every claim to its evidence; certified English translations for registry filings, attestations, declarations, and anything a coverage determination relies on; maximum evidence age by document class (registry extracts, ownership statements, site attestations, and supplier declarations within twelve months; SBOMs matching the shipping build); and ten-year retention of each superseded revision with everything it references.
3.8 Attestation. A certification signed by an officer of the manufacturer that the file is complete and accurate as of its revision date, in the form set out in Annex A of the complete Protocol document — drafted to the certification standard of the Conditional Approval guidance, which requires completeness, accuracy, and prompt disclosure of material changes.
A verifier examining an OEF at Level 2 or 3: (a) authenticates each document's source and date; (b) reconciles the device schedule against public FCC authorization records; (c) confirms that the coverage-determination texts in the file match the texts in force at the verification date; (d) confirms not fewer than three supplier declarations or ten percent of those on file, whichever is greater, selected by the verifier, directly with the declaring supplier; (e) reconciles the corporate chain, including five-percent beneficial ownership, against registry filings retrieved within ninety days; (f) recomputes the concentration summary and reconciles the sole-source register against the BOM; (g) re-runs the covered-entity screen as of the verification date; and (h) states in writing what was examined, what was confirmed, the Protocol version applied, and the file revision covered — retaining working papers for ten years. A verifier who provided consulting assistance in assembling a file must disclose that assistance in the verification statement.
The following require re-attestation of the affected sections within thirty days, and re-verification at Level 3: a new or changed production, assembly, testing, or firmware-loading site; a change of contract manufacturer; a sourcing change affecting any deep-trace component; any change in the corporate chain or five-percent beneficial ownership; a change in board or executive leadership; any new, changed, or terminated foreign-government ownership, control, influence, financing, or material-support arrangement; a change of the entity responsible for IP ownership or software updates; a sole-source supplier becoming unavailable; and any addition to the Covered List touching an entity or component in the file.
Conforming parties may state: "[Company]'s Origin Evidence File for [models] conforms to the Gatewell Protocol for Origin Evidence, Version 1.0, at Level [1/2/3], as of [date]." Claims must name the level and date, may not be applied to models outside the verified schedule, and may not state or imply endorsement by any government agency. Buyers and importers are encouraged to require a stated level and current date from counterparties as a condition of qualification.
The marks for the three levels appear at the head of this page. They may be displayed only with a current certificate ID from the registry, per Section 6. Verified parties receive the mark kit with their certificate.
The Protocol is versioned. Substantive changes are published with a comment period and a dated changelog; files verified under a prior version remain valid to that version's terms until their next re-verification. Regulatory developments — including any future prescribed documentation standard — will be incorporated by revision, and the Protocol will yield to any mandatory standard on its effective date.
Working with the Protocol. The standard is free and always will be. Gatewell Group provides OEF assembly, Level 2 verification, and Level 3 monitoring as engagements — and buyers who wish to require the Protocol of their vendor bench can adopt it by reference at no cost. Start with a conversation: request a diagnostic or write [email protected].
Get revision notices, the v1.0 final publication, and comment-period updates. No marketing beyond that; unsubscribe anytime.
© 2026 Gatewell Group. The Protocol text may be reproduced and distributed with attribution, unmodified. "Gatewell Protocol" designation reserved. Regulatory context verified against FCC sources as of August 8, 2026; the regime changes frequently — confirm current requirements before relying on any element of this document. This document is not legal advice.