New United States regulations now require automotive manufacturers to assess not only where vehicle components are made but also who designs the hardware, writes the software, and controls the companies that supply it.
The rule, finalized by the Department of Commerce, targets vehicle connectivity system hardware and software linked to China or Russia. Software restrictions take effect for model year 2027, while hardware limits begin with model year 2030 or January 1, 2029 for components without a defined model year.
Restrictions do not ban all electronics produced in China. They focus on defined categories of connected vehicle technology supplied by entities owned or controlled by those countries. Determining compliance therefore requires insight into corporate ownership, engineering control, and the origin of individual functions.

The covered technologies include cellular, satellite, Wi‑Fi, and Bluetooth systems, as well as software used in automated driving. These components can transmit vehicle data, receive remote commands, and potentially access other in‑vehicle systems.
Although the deadlines apply to the U.S. market, the impact is global. Automakers rarely design separate electronic architectures for each country, so a restriction in one market can alter purchasing decisions, platform designs, and supplier relationships across an entire vehicle program.
Automakers and suppliers are already exploring alternatives to Chinese‑designed connectivity hardware. The transition creates demand for new suppliers but also exposes the difficulty of replacing components already embedded in long development cycles.
Compliance involves more than swapping a physical module. A modern connectivity system combines cellular hardware, embedded firmware, operating system components, security functions, eSIM technology, cloud services, and operator integrations.
Changing one element can affect antenna performance, power consumption, modem firmware, emergency calling, eSIM provisioning, cybersecurity testing, data formats, cloud integration, and type approval. A technically similar module is not always a drop‑in replacement without engineering adjustments and renewed validation.
Long automotive development timelines mean that model year 2027 vehicles may have been designed years before the software prohibition applies. Suppliers must qualify, test, and secure production capacity well before a vehicle reaches the production line.
Software provenance is also critical. A component assembled outside China can still contain covered software developed by a Chinese entity. Determining origin may require more than a country‑of‑origin certificate, including details about intellectual property ownership and update infrastructure.
Existing cybersecurity frameworks already require manufacturers to set clear expectations for suppliers and verify implementation. The new origin requirements add another layer to those security and lifecycle obligations.
Regulators are increasingly treating networked products as parts of national digital infrastructure. Similar questions could arise in energy, industrial, healthcare, and public safety sectors, even if the current rule does not apply to them.
For IoT manufacturers, supply‑chain resilience now demands diversity at multiple levels of the technology stack, not just multiple suppliers. A second supplier may still rely on the same restricted modem design or firmware provider.
Replacing Chinese vendors can raise costs or reduce short‑term availability. Rapid transition to a new supplier introduces reliability and capacity risks that must be managed.
Companies selling connected products internationally may need modular hardware, portable connectivity software, and well‑documented interfaces to accommodate regional regulations. However, greater modularity can increase development complexity and testing requirements.
The most important lesson is that regulatory exposure can remain hidden until late in a product lifecycle. Visibility must extend into software repositories, corporate ownership structures, remote update systems, and cloud architectures.
In this new environment, knowing what a connected product does is no longer sufficient. Manufacturers must be able to demonstrate who ultimately controls the technologies that make it connected.






