Silverado Insights

Silverado regularly hosts video conversations, expert panels, and webinars featuring its research staff and subject-matter specialists. These programs explore emerging policy issues, unpack the findings behind Silverado’s publications, and provide context on key national and economic security trends. Each session offers clear, research-grounded insights for policymakers, practitioners, and the public.

Hero image

Follow us on :

Back to Media

The “China Threat” Lists Hadn’t Been Talking

Is there hope to finally get a translator? With U.S.-China relations sitting in a historic “pause and rethink” moment, it is time to consider how to use Lists to best support U.S. interests.

Author: Eric Lowe, Senior Fellow at Silverado Policy Accelerator 1

Executive Summary

Over the last decade, the U.S. Government has been busy creating and updating Restricted Party Lists (“RPLs” or just “Lists”) for various types of international transactions, including exports, imports, investment, and even immigration. These actions were driven in large part to address a set of emerging threats largely from China. Each iteration of this process was well-intentioned, but not-well coordinated, and there was a Russian invasion in the middle that may have distracted policymakers. The decentralized nature of List formation has created confusion for industry, difficulty for targeted enforcement, and in some cases, exploitable gaps for adversaries.

With U.S.-China relations sitting in a historic “pause and rethink” moment, it is time to consider how to use Lists to best support U.S. interests. At minimum, the United States should invest in a coherent List-based approach that advances a single national security technology strategy together with industry, and in a potentially scalable manner through joint actions with allies and partners . The solution should anchor around the following characteristics:

  • Mutual recognition for both threat identification and mitigation across the interagency.
  • Longer-term predictability for industries caught between Beijing and Washington, accepting that global industries that are resilient enough to resist China’s sphere of influence are still beneficial to U.S. national security even if they fail to meet every single U.S. preference.
  • Clear directives from the White House and/or Congress as to the goals, and cogently communicated thresholds, on a sector-by-sector basis, when the List-based approach is no longer sufficient, and a switch to sectoral controls is necessary.

Background – Why a “List” Approach?

It wasn’t that long ago that the United States and the Republic of China joined together to defeat the Axis powers for control of the free world. But much has happened since. Fast forward through half a century of Chinese hardship and the re-branding to the Peoples’ Republic of China , contrasted against U.S. ascension to the status of sole superpower, and you arrive at some point in the late 1990s, where the U.S. and China again found optimism in collaboration through cautious economic integration. Discussions ultimately led to China’s accession to the World Trade Organization in 2001, and the global economy sailed off into the sunset of Ricardian comparative advantage and efficient markets... except it didn’t.

Over the ensuing decade, the two economies accelerated supply chain integration while at the same time the U.S. subtly attempted—and failed—to persuade Beijing to become a responsible stakeholder of the global economic order. As the latter effort began to show signs of failure, the relationship took on a wholly unfamiliar nature for the U.S.; one of shrinking supremacy. The pivot to Asia that the Obama Presidency attempted, as noted by the World Economic Forum in 2016, left China with the mixed status as both a growth market for U.S. businesses, and a threat to U.S. economic prosperity. 2

Roughly from that moment, the relationship accelerated in its devolution into a multi-front rivalry defined by cyber warfare, aggressive de-risking and in some cases decoupling, and increasing militarization. If China had been a smaller share of global GDP in 2016, the solution would have be simple: country-wide sectoral sanctions that applied to all types of transactions; import, export, investment, etc. Yet, because global economic and technological interdependence with China was, and remains high, any strict form of broad economic blockade would cause severe harm and risk alienating the United States from certain aspects of global growth and development.

Enter the regulatory scalpel. If a geopolitical threat can be identified with great precision—the theory goes—then broader tools like sector-based, or even country-wide sanctions are not necessary. Instead, the regulating government can provide industry with ex ante notice about the specific entity that must be avoided in each type of international transaction, and industry does the heavy lifting. Precision in this manner avoids large scale economic harm. It also empowers more impactful government enforcement actions; is the legally distinct entity is identified, and an industry party interacts anyway, the government has a stronger case for penalties.

Over the last decade many U.S. agencies have attempted to use the scalpel approach to review, mitigate, restrict, or even prohibit transactions with certain entities while maintaining overall normal trade relations with China. 3 Congress has largely punted on a broad fix, other than a few targeted efforts aimed at forced labor and semiconductors. The result has been a massive expansion of Lists and other end user controls across several authorities. In theory, it is beginning to look less like surgery and more like “death from a thousand cuts.” In practice, it has a strange similarity to a circus knife throwing act.

Table 1 summarizes what is emerging to be the “Core Set” of these Lists and Appendix A provides additional details on a slightly more comprehensive set. Within the context of the Core Set, this brief examines recent USG efforts for a more unified approach. It also identifies a few tools that could make current Lists more interoperable for government enforcement and industry risk management.

Table 1: The Core Set of Restricted Party Lists 4

Lists table

Prior to now, efforts to make the application of certain Lists interoperable across the range of potential transactions have been limited. This is due, in part, to the nature of the Lists in the Core Set, with each having a specific target audience and inherent limits on who or what it regulates. This may be a missed opportunity, however, as the issues addressed by the Lists largely center around a few topical areas, summarized as:

  • Adversary Military Support : Lists largely designed to address the growing threat of modernization of the People’s Liberation Army (PLA) through Chinese industrial development, and headlined by DoW’s Section 1260H List, the BIS MEU List, and Treasury’s NS-CMIC List. In the case of the MEU List, there is an additional aspect in that the item must be of the nature to support or contribute to the operation, installation, maintenance, repair, overhaul, refurbishing, development, or production, of dual use and military use items.
  • Foreign Policy Goals : Lists designed to address issues ranging from forced labor and drug trafficking to trade evasion and intellectual property theft. The Entity List is the more senior statesman here, but new entrants include the UFLPA List and the DoW’s Section 1286 List, which bans U.S. universities and research institutions that receive DoW funding from collaborating with any institution on the 1286 List.
  • Cyber/Infrastructure Risk : Lists that seek to identify technology products or services providers where there is an unacceptable level of malign cyber risk. Although a lot of attention has been directed to this area in creating the authorities, few Lists have been widely implemented. Section 5494 List is the latest in this realm and is quickly making its way into the Core set, even though it remains in Notice of Proposed Rulemaking (NPRM) status with just three names. 5 Additional examples include: the FASC List; the Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA) List; 6 and the DOJ Bulk Data Rule List. Greater details on these can be found in Appendix A .
  • The Special Case of the FCC Covered List : At the outset, it is important to note that the Covered List is of a slightly different type. It is managed by the FCC, a quasi-independent agency, and under the Secure and Trusted Communications Networks Act (STCNA), the FCC is authorized to add individual entities to the Covered List where there has been a relevant national security risk assessment conducted by another federal agency. 7 The Covered List does not purport to address military risk, or implement foreign policy per se, but the recent shift in how the FCC is applying it (more on this below) might make it a tool for those goals.

Problem – The Lists Do Not Always Speak the Same Language

Internally, U.S Government action to address technology risks through national security and foreign policy is coordinated in the National Security Council (NSC). Unfortunately, there is no external facing NSC-issued guidance to industry outside of major changes implemented through Executive Orders and Presidential Proclamations. Congress can also play a role in the creation of Lists—arguably should play a greater role—but likewise cannot interact on a granular implementation basis, other than to occasionally add an entity to a List directly as part of a larger legislative action. 8 Despite best intentions, the ongoing coordination of a single, coherent national security technology strategy across various government agencies is not self-effectuating.

In practice, differing agency authorities and enforcement priorities, and variable capacity of industry to conduct due diligence and predict the strategic actions of adversarial foreign governments create gaps and discontinuity over time. The default has generally been that inclusion on one List did not impact the determination under a separate List. Essentially, the Lists don’t “talk to each other.”

One example of this can be found in the communication gap between the BIS MEU List and the DoW 1260H List. While both are expressly intended to identify Chinese military entities whose interaction with U.S. sensitive technology should be limited, they vary on which entities are named and what actions are required. The two Lists share many of the typical state-owned enterprises. 9 They diverge, however, in how they address new and emerging technology companies, with the 1260H List identifying consumer tech focused entities like Tencent, Alibaba, Unitree, and BYD. It is worth noting that the MEU List is illustrative, not exhaustive. 10 Which, of course begs the question of whether the newly minted entries on the 1260H List should just be assumed to also be subject to the MEU restrictions in EAR Part 744.21 and elsewhere.

The mismatch goes the other way too, where U.S. technology companies seek to include foreign suppliers into global supply chains, even though the U.S. company could not export to such an entity without a license. That is, the presence of a supplier on the BIS Entity List does not necessarily constrain an import-focused transaction. For example, as Apple attempts to navigate the current shortage of memory chips, it is actively looking to integrate NAND flash memory from Yangtze Memory Technologies Corp (YMTC).

YMTC has been on the Entity List since 2022 but has avoided inclusion on the 1260H List and other Lists in the Core Set. When looking at globally integrated supply chains for the digital realm, like Apple’s, the distinction between exports and imports seems lacking; it is hard to imagine that information, technology, data, and other intellectual property or know how will not be shared with (exported) YMTC as it is integrated into a supply chain as complex as Apple’s. If the message the U.S. Government is trying to send is that YMTC is bad for national security, it should send that message across all relevant Lists.

Models for Integration

As the United States continues to navigate the transition from China as a former growth market business partner, to China as malign near-peer technological power, the use of Lists should serve a consistent strategy with coordinated compliance, licensing, and mitigation operations. In short, greater integration is needed. That part is easy to say. The task gets harder on the notion of “but how?” The following are a few models of integration that can be currently observed:

  • Integration by Placement: Congress can, through legislation, place an entity on an existing List. This type of integration—call it placement—does not really move the needle on overall List coherence but at least prevents further confusion by additional List proliferation.
  • Integration by Proxy: Congress can also identify an existing List or set of Lists for use in the creation of a new authority—call it integration by proxy—potentially giving new scope to the agency already managing the original List. As one example of this, the American Security Drone Act of 2023 required the FASC to develop and publish a list of “covered foreign entities” using, as a baseline, the Consolidated Screening List (which is itself a consolidation of certain foreign looking Lists, managed by DOC’s International Trade Administration). 11 Likewise, in the CHIPS and Science Act Congress used the subset of the 1260H List and an earlier authority (Section 1237 from the FY1999 NDAA) to define the term ”Entity of Concern.”
  • Integration by Curation: Whether on their own initiative or in response to a presidential directive, agencies have also made attempts to bring select Lists together to operate in a more harmonious manner. This type of integration—call it curation, or even unilateral recognition appears to be catching on with recent efforts like the BIS Affiliates Rule, as further discussed below.
  • Integration by Pre-emption: Finally, although less common, there are a few government authorities that operate with true integration—call it pre-emption—where one national security program, informed by all other relevant authorities, creates a resolution with a controlling status. The best example of this (admittedly not a “List” approach) is how a National Security Agreement (NSA) under the CFIUS authority will centralize the government’s oversight of that company under those terms. 12

Green Shoots – Emerging List Interactions in 2026

There are subtle signs that some List interaction might be happening even if the interactions are not centrally coordinated and appear to be taking different forms.

Curation of “Prohibited Entity Lists”

Starting last fall, the FCC began to use a set of curated Lists as a benchmark for exercising its own authority: before any device that emits radio frequency energy (like a Wi-Fi router, or cellular module) can be sold in the U.S., it must be tested and certified by an FCC-approved Telecommunication Certification Body (TCB). As per a final rule published in September, the FCC no longer accepted certification from a TCB that is owned or controlled by a “prohibited entity”. 13 The FCC defined that term through reference to the following curated set of Lists: The BIS Entity and MEU Lists, the 1260H List, the UFLPA List, the Section 5949 List, the FCC Covered List, Entities identified as “foreign adversaries” by the Department of Commerce, and the NS-CMIC List.

In March 2026, DoW also began to dabble in curation, requiring recipients of its research funding—including funding for basic, open research, a previously lightly regulated area—to certify that the recipient will not use the funds to support research “in collaboration with, or using equipment from” any entity on one or more “Prohibited Entity Lists”. 14 DoW defined this term as a curated set of Lists that included the 1260H List, 1286 List, NS-CMIC List, BIS Entity List, BIS MEU List, FCC Covered List, Section 889 List, Section 5949 List, COINS Act List, and the UFLPA List.

On May 29, 2026, the Office of Management and Budget took this concept further by issuing a wide-reaching NPRM on how federal grants and assistance awards can be used. 15 This rule contains a prohibition on using federal funding to support an activity with an “entity of particular concern” which is identified as an entity “on a list maintained by a Federal agency pursuant to statute” which it defined to include the National Defense Authorization Act or the International Emergency Economic Powers Act. 16 Shortly thereafter the National Science Foundation began to issue “Dear Colleague” letters to research institutions indicating that it will prohibit the use of its funding to support collaboration with “entities on U.S. restricted parties lists” which were identified as essentially the Core Set. 17

The upside of a curation approach is it creates ex-ante clarity for regulated industries, at least on the question of where to look for the names. And there are software tools to provide a one-stop shop for screening entities against all the implicated Lists. For certain types of risks, this may be an effective way to address the more general question of how to avoid doing business directly with a malign entity: the U.S. party is put on notice, and if their counterparty is on one or more Lists, they choose not to participate in the transaction.

The downside is that the agency applying it might not always agree with additions or subtractions from the Lists it does not control. Moreover, given the focus of certain Lists, inclusion on them might not present the same type of risk the agency using a curation approach is seeking to address. Curation in this manner is also less effective for risks further up the supply chain and makes licensing and ad hoc mitigation more difficult. From a systemic coherence perspective, there is also the problem of ensuring the same set of Lists is curated by each relevant agency.

A Single List Proxy for “Malign Chinese Entities”

In the first couple years of existence, the 1260H List was largely viewed as a lens to inform geopolitical strategy, and less of an operational compliance mandate. Just a few years later—with the passage of the FY2024 NDAA and the recent addition of more mainstream PRC companies to the List—it looks positioned to become a central feature of the National Security technology framework. As of June 2026, the DoW ceased to provide funding to be used in direct connection with goods or services from an entity on the 1260H List. Starting in June 2027, DoW will not purchase goods or services that include components or services from 1260H entities. Even without further cross-List interaction, this indirect supply chain restriction should create ripples as the United States defense industrial base has a broad footprint across the economy and U.S. companies with even a single DoW contract may want to present a clean slate on the question of 1260H.

The BIOSECURE Act (which was part of the FY2026 NDAA) demonstrates how the 1260H List can be used as a proxy in other areas. The BIOSECURE Act restricts all U.S. federal agencies and federal fund recipients from using biotechnology equipment or services from designated "biotechnology companies of concern" (BCCs) and makes the 1260H List the default list for BCCs.

This theme is catching on. There are other bills at various stages in Congress that reference the 1260H List in exercise of authorities that are far outside of DoW’s direct purview: from denying VISA entry for former employees of a 1260H list entity, 18 to preventing 1260H entities from holding U.S. patents. 19 There is a bill to create an automatic process to force any 1260H entity to be added to the NS-CMIC List, leading to divestment of the relevant investment. 20 In addition, there is at least one attempt that would mandate that DoW review any Chinese entity restricted by other Lists (like the BIS Entity List) to determine if they should be added to the 1260H List. 21

It is a good development to see the 1260H List get traction. The recent interest in using it as a proxy outside the defense industrial base, however, brings deeper questions: Should incorporating as a proxy the 1260H List be the main way for an agency to limit interaction with all PRC-related threat actors? There are nuances involved for agencies with a mission to address IP theft, forced labor, or other issues that don’t necessarily follow military civil fusion. What about Russian or Iranian threats, or entities not clearly under PRC ownership, but suffering from PRC influence or indirect control?

This approach also raises serious questions for compliance and mitigation: How do non-DoW agencies engage in licensing or advisory opinions? For that matter, as more agencies use 1260H as a proxy, DoW may need to think of the non-defense sector and other agencies regulatory concerns when it mitigates with a single U.S. party regarding a listed entity, or adds/removes entities each year.

Amplification by Affiliates?

In September 2025, BIS promulgated the “Affiliates Rule” in an attempt to extend the reach of the Entities List to foreign end-users that are at least 50 percent owned, directly or indirectly, by one or more entities already expressly identified on the BIS Entity or MEU List, or the OFAC SDN List. 22

The Affiliates Rule can be seen as an attempt to cureate a set of Lists and put greater onus on U.S. persons to “know the end user.” It also deploys an amplification concept, where under the Affiliates Rule, the foreign entity is subject to the most restrictive license review policy applicable to one or more of its owners or affiliated entities. If for example, OFAC has a complete ban on a 10 percent owner of the parent company, then that is how BIS will address attempts to export to the subsidiary.

The strength of this approach is that it is somewhat self-adapting to evasion through business formation: it does not leave a gap between the information last published by BIS and any current information known or reasonably available to U.S. persons involved in the transaction. It also requires the U.S. person to gather additional non-public information—including asking for information on the beneficial owner—through the business relationship with a foreign entity.

The downside of the Affiliates approach, in current form, is that it lessens the clarity and precision of using one or more published Lists to identify the entity to avoid. It might also cause mismatch in the risks inherent in each type of transaction, and prevent the U.S. government from taking a stricter approach with the foreign parent organization, or a particularly malign affiliate, in the first place.

The Covered List as the Master Curator?

Covered List 1.0. Under the approach precisely stated in the text of STCNA, the FCC is empowered to curate the interaction of the technology-focused Lists by looking at technology risk assessments and adding entities to the Covered List after a separate national security agency has reached a final decision. STCNA identifies the following sources of authority to add an entity to the Covered List:

i. The Federal Acquisition Security Council (i.e. pursuant to 41 USC Sec. 1222);
ii. The Department of Commerce, OICTS (i.e. pursuant to E.O. 13873);
iii. Section 889 of the 2019 National Defense Authorization Act; or
iv. A specific determination made by an appropriate national security agency .

The first three sources are rather clear, and track authorities put in place around the same time STCNA was passed. These were all parts of a similar effort to address the growing threat of China origin—specifically Huawei—equipment on U.S. telecom networks. The last source is a very different type, and would appear to give the FCC a sweeping ability to curate a master list from any existing List, and even from non-List determinations, public or nonpublic. That alone would be a dramatic increase in cross-List integration, noting that it is still limited to “specific” determinations.

Under this approach, the Covered List adds a layer of compliance and enforcement on top of the original appropriate national security agency. Any actions to establish mitigation measures must be made under the original authority and somehow conveyed back to FCC. For the first three sources, it is likely a good match on the regulatory objectives of the original authority and the FCC. The “specific determination” prong, however, may not be aligned with the intent of the Covered List—which is identified as ensuring the security of technology that is placed into major U.S. communications networks. 23 For these reasons and others, using the Covered List as a master curator (instead of an enforcement tool for the three named programs) may not be structurally aligned nor capable of incentivizing industry to change global supply chains to meet a single mitigation standard.

Covered List 2.0. The FCC has further evolved the Covered List to categorically identify foreign equipment with no reference to a specific entity. Once a type of equipment is identified, the FCC will prohibit any new equipment authorizations unless the entity associated has been given a conditional approval under a specific agency process currently limited to DHS and DoW. Since all radio frequency devices must be authorized by the FCC for spectrum use and radiation levels to enter the U.S. market, this effectively blocks all new items with a radio frequency function from being imported, marketed, or sold in the United States.

The FCC has bolstered this endeavor through recent efforts to address component parts. This effort is intended to close the loophole that may have allowed a non-Covered List entity to import an item that otherwise incorporated a component from a Covered List entity. 24 The new approach would prohibit the authorization of any logic-bearing hardware components identified on the Covered List, and of any device that incorporates such a component.

This is a further significant change in scope: rather than a precise list of legally distinct entities, the Covered List 2.0 is essentially a country non-specific, broad multi-sectoral import ban. The ban covers all foreign production, but provides the opportunity to seek a specific authorization (from DHS or DoW) by voluntarily demonstrating low-risk corporate structure, foreign ownership, supply chains, and by establishing a timeline for on-shoring the manufacturing. The first two applications of this new approach—UAS and Foreign-made routers—had some underlying reason as they were essentially implementations of Congressional inquiries (of DJI/Autel and then TP Link). 25 In each of those first applications, the FCC provided a caveat that it was limiting the impact to only that equipment or services capable of the functions outlined in sections 2(b)(2)(A), (B), or (C) of STCNA. 26 It is worth noting that the public-facing versions of the relevant national security determinations lacked significant details to guide industry as to the technical nature of the risks. 27 Subsequent applications now include Advanced Robotic Devices and Connected Power Inverters, and generally follow the same formula which prohibits new models (not current models, already having FCC approval) from receiving FCC equipment certification needed for import or sale.

While the Covered List 2.0 approach has been praised by some national security experts for making broad strokes to address growing insecurities in certain supply chains, it has also been met with criticism from industry trade groups. The critics argue that the sweeping categorical bans are likely to create administrative bottlenecks, risk slowing down commercial innovation, and put immense pressure on tech manufacturers to fundamentally restructure all aspects of their supply chains in an environment that lacks abundance of supply chain options. 28 Some have also noted the potential due process concerns as there is no clear identification of the technical aspects of the vulnerability in question, and no clear path to mitigate the risk in advance. There might be a lot going on behind the scenes, but on the surface this approach seems to miss a big opportunity not only to secure supply chains for U.S. consumers, but to identify technical standards that could shape global supply chains in ways favorable to U.S. industry and U.S. national security.

There is also the criticism that the Covered List 2.0 approach, as applied to information services and non-communications equipment, exceeds the scope of STCNA, a 2019 law that was designed to support greater enforcement of entity-specific determinations under programs that were designed to have frequent industry engagement, as well as robust mitigation, monitoring, and enforcement mechanisms already in place prior to the FCC adding the entity to the Covered List.

The Position of Translator is Still Open

These recent attempts to unify the Lists are new and still evolving. The effort is commendable as the problem has been a decade in the making. At least for the moment, however, there is a real risk of ending up with more confusion in the coherence than there was in applying them independently. The Affiliates Rule and the Covered List 2.0 are sincere attempts to create a more centralized approach to technology security, but both suffer the same flaw: they erode the clarity of having a List-based approach in the first place and put the onus on industry to fully understand complex foreign supply chains and ownership interests. Supply chain oversight is significantly challenged when applied to opaque national security technology risks. Importantly, neither approach expressly adopts or accepts mitigation actions taken under the original authority, nor provides clarity on pre-emption and priority.

In short, the position of “List Translator” is still unfilled.

A New Hope?

The Comprehensive Outbound Investment National Security (COINS) Act, enacted on December 18, 2025 as part of the FY2026 NDAA, presents a glimmer of hope. Under COINS, Treasury has 365 days to establish a process for certain federal agencies (Treasury, Commerce, DoW, State) to share data, and to coordinate in evaluating entities already on Entity List, MEU List, or the DoW 1260H List to determine if they should face investment prohibitions or inclusion on the CMIC List. The text of the law does not go so far as to instruct the creation of a single combined List, but it could be interpreted in that way, at least for those four China-focused Lists. It might even support the creation of a pre-emption program, with formal process for adding, mitigating, or removing entities from all lists at once.

This aspect of the COINS Act could prove to be extremely timely and impactful. Export controls address not only the transfer of tangible things (equipment, hardware), but also intangible items like data and information. The COINS Act regulates the transfer of capital and the related "intangible benefits" (management, expertise, and information) for those technologies addressed. 29 As there is bound to be overlap in information and intangibles, it will be important to ensure that the Entity List and the COINS Act are used in concert to achieve the same goals.

Historically, the Entity List applied to the “legally distinct” entity identified, which is the exact entity at the exact address listed. The Affiliates Rule changes this and instead looks not only to the entity precisely identified, but also at a much broader set of affiliated entities under its ownership or control. The impact is that an entity can be implicitly on the Entity List based on its ownership, yet ownership can change, including through outbound investment.

At a minimum, a collaborative review could begin to address some of the inevitable issues of integration, including whether a COINS Act license to invest in a foreign technology company will address the need for a separate BIS license if the company is also on the Entity list. It could also set up the framework for investment regulated by the COINS Act to be one way to allow a foreign ownership to be brought down below the 50% threshold under the Affiliates Rule, essentially allowing export transactions without further license requirements.

Recommendation – Mutual Recognition

There are concepts embedded in the current efforts that are worth highlighting and potentially building on. The first is a need to have mutual recognition across certain agency Lists, at least initially, when the risk is of the similar type (e.g., cyber risk, tech transfer, support of foreign military, etc.). This concept would allow for implementation of cross-List enforcement that preserves the authority of the original List owner to update and amend its own List, as well as to retain flexibility for other agencies to provide license arrangements with a specific party for a specific use, while maintaining broader cross-agency prohibitions under the set of mutually recognized Lists.

This concept could be scaled, at least as it regards actions with a government approval nexus like imports/exports, or government contracts, by having the agency involved in the immediate transaction, require the U.S. party to certifying compliance with all of the Core Set of mutually recognized Lists. As part of this process, the U.S. party would identify any licenses or other authorizations held in regard to another agency’s List. In addition, each agency in the group could provide a “General License” approach when the U.S. party obtains a license or approval from the original List authority.

As we are still in the 365-day implementation period embedded in the COINS Act, there is an opportunity to build a mutual recognition regime—at least as it involves the 1260H, Entity, MEU, and CMIC Lists—that leverages each implicated agency’s distinct authorities and industry partnerships while providing greater certainty and license uniformity. Remember the goal should be to unite global supply chains in how they address malign Chinese actions, not necessarily limited to preventing U.S. persons from interacting with China.

Recommendation – Due Diligence Beyond Static Lists

The second concept worth consideration is a broader due diligence requirement, as generally expressed in the Affiliates Rule. 30 This concept would require more than just a reference to a static List for the specific transaction in question. Even if the four China-focused Lists identified in the COINS Act remain distinct, this concept could be implicated through a requirement for cross List diligence and reporting: If a U.S. person has knowledge that a foreign party to an intended transaction is on one of the China-focused Lists, or has significant ownership interests that are implicated by one or more Lists, then there would be an affirmative duty to inquire and report to the agency overseeing the immediate transaction the implications of the foreign party’s presence on one or more other Lists. Specifically, the U.S. person will identify how it will mitigate any risk created by the immediate transaction to any of the other areas of regulation. For example, if Apple wants to use YMTC’s NAND memory in products in ways that would need to clear 1260H List review (if YMTC was on the 1260H List) Apple would be required to identify exactly how it will mitigate the potential for technology transfers that would undermine YMTC’s presence on the Entity List.

This type of approach could create connective tissue between different risks addressed by different USG authorities, while also preserving individual agency autonomy. Essentially, if an entity is on one of the Core Set, then all agencies will will work to ensure that the business involved certifies its actions in a way that prevents new risks from emerging through the transaction.

Closing Thoughts

A mandate of good governance is to provide clear, consistent, and predictable rules, publicly to the regulated parties, with sufficient notice for them to make changes. In addition to the obvious reason — how can a person do what you want if they don’t know what you want — there is the Constitutional right of Due Process, which at a minimum requires some level of notice prior to any adverse enforcement action. Yet, clarity can be a challenge in the realm of national security controls, where a cogent public description of the threat is often clouded by the government’s need to maintain some level of secrecy around certain facts.

Restricted Party Lists have been somewhat useful in meeting this mandate, as they add clarity and precision for discrete actions at the margins to complement broader tools of national and economic security statecraft. The scale and complexity of China’s interventions with global supply chains, however, may have elevated the scope of the risk from the margins to the main stage. This seems to be reflected in the emerging focus of Lists to prohibit transactions involving items of Chinese origin, rather than force technological changes to address the vulnerabilities.

The purpose of a List-based approach should be to entice global supply chains to reduce their interaction with a small number of truly malign entities, while simultaneously creating the incentives, through certainty, to do business with and invest in companies that compete on market principles. If a country’s government is so oppressive as to render any entity subject to its jurisdiction as a malign proxy, with no technical mitigation that can s uffice, then it may be time to put Lists back on the shelf and look at broader tools like country-based sectoral sanctions. It is hard to tell if the state of the U.S.-China relationship is to this point. Before we conclude it is, it is worth one last effort to get the Lists to sit down, converse, and ultimately speak with one voice. Maybe industry and our allies will listen.

Appendix A – Core and Emerging Lists Fact Sheet

DoW Section 1260H List

  • Governing Agency: Department of War (DoW)
  • Established: 2020 as part of the FY2021 National Defense Authorization Act (NDAA)
  • Application: Identifies “Chinese military companies operating in the United States.” Required by statute to be updated annually through 2030.
  • Impact: Serves as a reputational risk flag signaling military-civil fusion risks. As of June 2026, the DoW is prohibited from entering into or renewing contracts with listed entities. As of June 2027, the DoW cannot purchase goods/services containing components or services from listed entities.
  • Recent Actions: On June 8, 2026, DoW added PRC consumer-focused companies (e.g., Alibaba, BYD, Baidu) and biotech firms (e.g., WuXi AppTec, WuXi Biologics, GenScript Group).
  • Limitations: Requires that the entity operates or does business within the United States.

BIS Military End User (MEU) List

  • Governing Agency: Department of Commerce, Bureau of Industry and Security (BIS)
  • Established: 2020 as a BIS Final Rule (85 FR 83793)
  • Application: Identifies specific foreign entities (primarily in China, Russia, and Venezuela) determined to be “military end users.”
  • Impact: Requires a license to export specific dual-use items (Supplement No. 2 to Part 744 of the EAR) to listed parties. License applications face a “presumption of denial,” restricting access to U.S. technology in sectors like aerospace, sensors, and marine propulsion.
  • Limitations: Limited to foreign parties in export transactions. It is non-exhaustive, requiring U.S. parties to conduct due diligence on unlisted entities.

DoW Section 1286 List

  • Governing Agency: Department of War (DoW)
  • Established: 2018 as part of the FY2019 National Defense Authorization Act (NDAA)
  • Application: Identifies foreign universities and research institutes (primarily in China, Russia, and Iran) involved in malign activities like IP theft or military-civil fusion (e.g., the “Seven Sons of National Defense” polytechnics and Academy of Military Medical Sciences branches).
  • Impact: U.S. universities and institutions receiving DoW funding are barred from collaborating with listed institutions. Non-DoW-funded industry and academia use it to guide risk management.
  • Limitations: Primarily a defense expenditure funding/research restriction. Does not carry asset-blocking financial sanctions or independently ban non-DoD-funded general commercial transactions or joint ventures.

FCC Covered List

  • Governing Agency: Federal Communications Commission (FCC)
  • Established: 2020 as part of the Secure and Trusted Communications Networks Act
  • Application: Curates additions identified via interagency review to flag foreign communications/video surveillance hardware (and foreign commercial drones) posing cyber or espionage risks.
  • Impact: Legally bars the FCC from granting new equipment authorizations to listed items. Because radiofrequency devices require FCC authorization to enter the market, new items cannot be imported, marketed, or sold in the U.S.
  • Limitations: Tightly bound to telecommunications and video surveillance hardware approvals. Does not function as a broad export control tool, freeze corporate assets, or block non-RF commercial financial transactions.

OFAC Non-SDN Chinese Military-Industrial Complex Companies List (NS-CMIC List)

  • Governing Agency: Department of the Treasury, Office of Foreign Assets Control (OFAC)
  • Established: 2020 & 2021 | Executive Orders 13959 and 14032
  • Application: Targets the PRC military-industrial complex without applying full Specially Designated Nationals (SDN) sanctions.
  • Impact: Prohibits U.S. persons from purchasing or selling publicly traded securities (or derivatives) of listed companies, restricting their access to U.S. investment capital.
  • Limitations: Strictly an investment/financing ban. As a Non-SDN list, it does not freeze U.S. assets, close operational banking channels, or prevent U.S. citizens from purchasing physical consumer products or conducting routine commercial trade.

BIS Entity List

  • Governing Agency: Department of Commerce, Bureau of Industry and Security (BIS)
  • Established: 1997 (Expanded in 2016, 2020, and 2025)
  • Application: Identifies foreign entities engaging in activities contrary to U.S. national security or foreign policy interests (originally focused on WMD proliferation).
  • Impact: Requires export licenses for items subject to the Export Administration Regulations (EAR), reviewed under a “presumption of denial.” Under the 2025 Affiliates Rule, restrictions extend to entities 50% or more owned by a listed party, requiring mandatory ownership checks by U.S. firms.
  • Limitations: Strictly applies to items “subject to the EAR” (U.S.-origin goods/tech). It is not an import embargo and does not prohibit purchasing standard commercial items from listed entities or conducting purely financial transactions.

DHS UFLPA Entity List

  • Governing Agency: Department of Homeland Security (DHS) / U.S. Customs and Border Protection (CBP)
  • Established: 2021 as part of the Uyghur Forced Labor Prevention Act (Enforcement began June 2022)
  • Application: Identifies entities connected to forced labor in Xinjiang, including miners/manufacturers using forced labor, entities working with the Xinjiang government to traffic labor, and suppliers sourcing materials from Xinjiang or the Xinjiang Production and Construction Corps.
  • Impact: Establishes a legal, rebuttable presumption that all goods produced in Xinjiang or by listed entities involve forced labor and are barred from entry into the U.S. Importers must supply “clear and convincing evidence” to CBP to clear supply chains.
  • Limitations: Strictly an import-control enforcement mechanism at the U.S. border. Does not regulate U.S. dual-use exports, freeze financial assets, or impose corporate ownership liabilities.

BIS Unverified List (UVL)

  • Governing Agency: Department of Commerce, Bureau of Industry and Security (BIS)
  • Established: 2002 (Expanded multiple times, including policy updates in 2022)
  • Application: Identifies foreign entities whose end-user legitimacy cannot be verified due to failed pre-license or post-shipment checks (often caused by host-government non-cooperation).
  • Impact: Flags entities as high-risk compliance “red flags.” Exporters cannot use license exceptions and must secure a signed “UVL Statement” from the party before non-licensed exports proceed. If verification is delayed by a host government for 60 days, the entity is transferred to the Entity List.
  • Limitations: Acts as an intermediate risk indicator rather than a complete export ban. Exports can proceed if exporters suspend license exceptions, execute deep due diligence, and secure proper UVL documentation.

Federal Acquisition Supply Chain Security Act (FASC) List

  • Governing Agency: Federal Acquisition Security Council (DoW, DHS, ODNI, GSA)
  • Established: 2018 as part of the Federal Acquisition Supply Chain Security Act
  • Application: Evaluates technology products/services for cyber or national security risks to establish removal or exclusion orders across federal procurement networks. Incorporates the International Trade Administration’s Consolidated Screening List.
  • Impact: Generates binding removal/exclusion orders barring federal executive agencies, contractors, and grant recipients from procuring or deploying covered products. Federal contractors must report banned products found anywhere in their supply chain within 3 business days. First public order issued September 18, 2025.
  • Limitations: Confined exclusively to federal procurement, contractors, and federal grant funding channels. Does not have statutory authority to restrict broader commercial private-sector or non-federally funded state/local systems.

DOJ PAFACA List

  • Governing Agency: Department of Justice (DOJ), National Security Division
  • Established: 2024 as part of the Protecting Americans from Foreign Adversary Controlled Applications Act (15 U.S.C. § 9901)
  • Application: Identifies public-facing digital applications, platforms, or websites controlled by designated foreign adversaries (China, Russia, North Korea, Iran). Explicitly designated ByteDance Ltd. and TikTok as initial entities.
  • Impact: Prohibits U.S. entities (e.g., app stores, web-hosting services) from distributing, maintaining, or hosting listed applications. Forces listed entities to execute a complete divestiture of U.S. operations to an approved buyer to avoid operational shutdown.
  • Limitations: Limited to high-active-user, public-facing digital applications posing data harvesting or algorithmic manipulation risks. Does not regulate enterprise B2B software, general international commercial websites, or applications outside foreign adversary control.

DOJ Bulk Data Rule (BDR) List

  • Governing Agency: Department of Justice (DOJ), National Security Division (28 CFR Part 202)
  • Established: 2025 under Executive Order 14117; DOJ Final Rule effective April 8, 2025
  • Application: Maintains a list/registry of entities and covered persons subject to the control of “countries of concern” (China, Russia, Iran, North Korea, Cuba, Venezuela) to block adversarial access to mass personal and sensitive government data.
  • Impact: Establishes data-export controls based on volume thresholds (e.g., geolocation, health, financial, biometric, genomic data). Bans commercial data brokerage and raw ‘omic data transfers outright. Requires strict CISA cybersecurity safeguards, data masking, and audits for restricted transactions (e.g., employment, cloud vendor agreements).
  • Limitations: Applies specifically to bulk sensitive personal data or target government dataset transactions. Does not apply to generalized financial services, cross-border internal corporate HR processing, standard academic research communications, or basic telecommunications routing.

DoW Section 5949 List

  • Governing Agency: Department of War (DoW) & Department of Commerce (DoC)
  • Established: 2022 as part of the FY2023 National Defense Authorization Act (Full implementation December 23, 2027)
  • Application: Identifies entities owned, controlled by, or connected to the governments of “semiconductor foreign countries of concern.”
  • Impact: Prohibits executive agencies from procuring or obtaining products and services that incorporate covered semiconductor products or services from listed entities once fully effective.
  • Limitations: Governs executive agency procurement and federal system integrations involving covered semiconductor products and services.

COINS Act Covered Person List

  • Governing Agency: Department of the Treasury
  • Established: (in process) authority created as part of the FY2026 National Defense Authorization Act (Codifying E.O. 14105 Outbound Investment rules; regulations due by March 2027)
  • Application: Publishes a non-exhaustive list of foreign persons engaged in sensitive technology sectors targeted for outbound U.S. investment bans or restrictions.
  • Impact: Restricts or prohibits U.S. outbound capital/investment in key sectors: Semiconductors & Microelectronics, Quantum Information Tech, AI Systems, High-Performance/Supercomputing, and Hypersonic Systems. Treasury may add categories via rulemaking.
  • Limitations: Applies specifically to outbound financial investments and capital flows in designated key technology sectors.

Footnotes

  1. Eric Lowe is a Senior Fellow at Silverado Policy Accelerator. The views expressed here are the author's own and do not necessarily reflect those of Silverado.
  2. See https://www.weforum.org/stories/2016/12/america-china-relationship/
  3. As just one example, the Department of Commerce Bureau of Industry and Security (BIS) Entity List grew from around 700 entities in 2017 to now comprising over 3200.
  4. These are the Lists that appear to be surfacing as the core set being used in the nascent efforts to build cross-List review.
  5. See https://www.govinfo.gov/content/pkg/FR-2026-02-17/pdf/2026-03065.pdf
  6. On his first day in office, President Trump negated the law as applied to TikTok, as he sought to negotiate a deal to bring TikTok under American ownership, but the authority for DOJ remains.
  7. See 47 U.S.C. Sec 1.50002
  8. For example, Section 1709 of the FY 2025 NDAA required Shenzhen DJI Technology Co., Ltd. (DJI) and Autel Robotics Co., Ltd. (Autel) to be added to the FCC Covered List, unless an appropriate national security agency made a determination otherwise.
  9. See e.g., China Aerospace Science and Technology Corporation (CASC), China Aerospace Science and Industry Corporation (CASIC), China State Shipbuilding Corporation (CSSC), and China National Nuclear Corporation (CNNC).
  10. See EAR 744.21(g), defining a MEU as “any entity whose actions or functions are intended to support military end users.” See also, 15 C.F.R. 744.21(b)(1).
  11. See https://www.congress.gov/bill/118th-congress/senate-bill/473/text
  12. While law enforcement agencies like the FBI still have their own independent authorities, any technology-focused regulatory risks are typically coordinated through the CFIUS framework to avoid conflicting mandates on the company.
  13. See https://www.federalregister.gov/documents/2025/08/07/2025-14970/promoting-the-integrity-and-security-of-telecommunications-certification-bodies-measurement
  14. See https://www.federalregister.gov/documents/2025/08/07/2025-14970/promoting-the-integrity-and-security-of-telecommunications-certification-bodies-measurement
  15. See https://www.federalregister.gov/documents/2026/05/29/2026-10817/regulation-for-federal-financial-assistance
  16. See proposed 2 c.f.r. 200.220.
  17. See https://www.nsf.gov/funding/information/dcl-prohibition-collaborations-entities-us-prohibited-party
  18. See No PLA Employees Act at https://moolenaar.house.gov/sites/evo-subsites/moolenaar-evo.house.gov/files/evo-media-document/noplaemployeesact.pdf
  19. See Prohibiting Adversarial Patents Act at https://files.constantcontact.com/f0eecb46901/50a37b09-b224-471c-b00c-20fa83465642.pdf
  20. See S. 3640, Divesting from Communist China’s Military Act at https://www.congress.gov/bill/119th-congress/senate-bill/3640
  21. See CLEAR Act at https://www.congress.gov/bill/119th-congress/senate-bill/3153
  22. See Final Rule, 90 FR 50857 at https://www.federalregister.gov/documents/2025/11/12/2025-19846/one-year-suspension-of-expansion-of-end-user-controls-for-affiliates-of-certain-listed-entities
  23. 47 C.F.R § 1.50001 (limiting the Covered List, at least in text, to equipment providing “high-speed, switched, broadband telecommunications capability”).
  24. See Third Report and Order and Third Further Notice of Proposed Rulemaking (July 23, 2026) at https://docs.fcc.gov/public/attachments/FCC-26-50A1.pdf
  25. See https://docs.fcc.gov/public/attachments/DA-25-1086A1.pdf; see also https://docs.fcc.gov/public/attachments/DA-26-278A1.pdf
  26. https://www.govinfo.gov/content/pkg/COMPS-15677/pdf/COMPS-15677.pdf
  27. See https://www.fcc.gov/sites/default/files/NSD-Routers0326.pdf
  28. See, e.g., AUVSI President & CEO Michael Robbins on FCC Public Notice Regarding UAS and UAS Critical Components, available at: /https://www.auvsi.org/news/auvsi-statement-on-fcc-public-notice-regarding-uas-and-uas-critical-components/
  29. A license is required to export items when destined to an Entity List user. The license applications are generally reviewed with a "presumption of denial," and especially so for areas of emerging technologies in scope for COINS Act.
  30. See Red Flag 29, which the Affiliates Rule added to BIS’s Know Your Customer Guidance under EAR Part 732.

Share on:

Related Publications

Explore more insights and analysis from our research team.