Chinese cellular IoT module makers have drawn scrutiny from U.S. officials because their components connect devices to mobile networks and may be embedded in sensitive equipment. The concern is a supply-chain risk question—not proof that Quectel, Fibocom, or another named supplier has used a module to spy on or sabotage a U.S. device. Public materials cited here document official questions, market concentration, a company response, and proposed supplier checks; they do not establish a confirmed module-specific compromise or how many U.S. devices contain these products.
What a cellular IoT module does—and why its supplier matters
A cellular IoT radio module is a connectivity component installed inside a larger product. It lets that product communicate over a cellular network; the module is not necessarily a complete device or a consumer product in its own right. Modules may be used in equipment such as medical devices, vehicles, farm machinery, wearables, routers, payment terminals, and infrastructure.
The security question is not simply where a module was made or which country its supplier is based in. It concerns what the module can do within the finished product, what permissions it has, how its firmware is maintained, and which people and systems can affect its operation. Device architecture, connected cloud services, deployment choices, and the module’s update and support pathways all matter. A module’s presence alone does not establish that its supplier can access the finished device’s data.
What U.S. officials have raised concerns about
FCC scrutiny in 2023
In a 2023 statement, then-FCC Chair Jessica Rosenworcel raised concerns about Quectel and Fibocom and called for the FCC to address cellular IoT modules in consultation with appropriate national-security agencies. She wrote, “Tackling PRC cellular IoT modules is a natural next step for the FCC, in consultation with appropriate national security agencies.” That is a policy position, not a finding that a particular module had been compromised or a completed rule banning all such products. Her observation that alternative suppliers existed reflected her assessment at the time, not a current audit of supplier availability.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- 📡 Multi-Network Cellular Connectivity: Supports 5G NR RedCap, LTE Cat 4, Cat 1 bis, and Cat M1 technologies with 2G/3G fallback for reliable data transmission in challenging environments.
- 🔌 Simplified Integration Design: Features standard mini berg connector with 20 mm pitch and simplified RF design for seamless integration into commercial and industrial IoT devices.
- ⚡ Flexible Power Requirements: Wide supply voltage support range from 1.8 V to 5.5 V with battery-friendly 1.8 V GPIO, ideal for ultra-low power consumption in battery-operated applications.
- 🌡️ Industrial-Grade Durability: Operates in extreme temperature range from -40°C to +85°C, making it suitable for demanding industrial and outdoor IoT deployments.
- 🌐 Advanced IoT Platform Features: Integrated TCP/IP and UDP/IP stacks, FOTA firmware updates, GNSS support, and edge logic programming for remote monitoring and control applications.
Questions from the House Select Committee
In an August 2023 letter, the House Select Committee on the Chinese Communist Party asked whether the FCC and collaborating agencies could track the presence of Quectel, Fibocom, and other PRC-based modules in U.S. devices. The letter raised possible consequences such as data exfiltration or device shutdown. Those were questions about potential exposure and capability, not evidence that either action had occurred. The materials cited here do not answer how many U.S. devices contain modules from the named suppliers or where those devices are deployed.
A later inquiry about health wearables
A June 18, 2026 letter from Senator Rick Scott and Representative Andy Ogles asks the FCC for a briefing about foreign-adversary modular transmitters in consumer health wearables. It cites an FCC Second Report and Order dated October 28, 2025. The letter establishes that lawmakers are asking about the order and wearable devices; it is not a substitute for the order itself. Without the operative text, its precise scope and current legal effect on cellular IoT modules cannot be characterized here as a blanket restriction or ban.
Rank #2
- Operates on LTE CAT-M1 and/or NB-IoT technology + GPS
- Directly compatible with Arduino Uno, Mega, and Leonardo + easy connection for other logic voltages
- Ultra low-power mode drawing < 8uA, ideal for battery-powered IoT devices + LiPo battery charging
- Kit includes dual flexible LTE/GPS antenna and stacking female header kit
- Detailed documentation, wiki, Arduino library, and code examples on Github + community forum to ask questions
How large is the Chinese suppliers’ market presence?
The U.S.-China Economic and Security Review Commission’s 2024 annual report described China as a leading producer of IoT equipment and reported these global cellular IoT module market shares for Q1 2024:
| Company | Reported global share |
|---|---|
| Quectel | 37.1% |
| Fibocom | 6.9% |
| China Mobile | 6.8% |
The three figures together amount to about half of the global market in that Q1 2024 snapshot, according to the commission. They are not current market shares, and they do not measure U.S. device installations, security incidents, or the probability of an attack.
Recommended Free Tools
Rank #3
- 1 Pcs RF module SIM7070G SIM7070G LCC-68(24x24)
What the record establishes—and what it does not
The evidence described here supports a serious supply-chain risk debate: officials have sought scrutiny, a congressional committee has asked about tracking and potential capabilities, and expert testimony has proposed ways to assess suppliers. It does not establish a confirmed U.S. espionage or sabotage incident caused by a Quectel, Fibocom, or other named cellular IoT module. Nor does it establish a module-specific compromise rate, a measured risk probability, or the number of affected devices in the United States.
GAO-26-107668, published May 19, 2026, addresses certain covered telecommunications and surveillance equipment identified in federal agency inventories and related mitigation. It should not be read as a finding that cellular IoT modules generally have been exploited. Likewise, a potential attack path—such as an insecure firmware update process—is a reason to assess controls, not proof that a supplier has used that path maliciously.
Rank #4
- CONNECTIVITY: Advanced RF transceiver with integrated MCU supporting LTE-M and NB-IoT cellular networks for IoT applications
- FREQUENCY RANGE: Wide operating frequency band from 600MHz to 2.2GHz, enabling versatile wireless communication capabilities
- GPS CAPABILITY: Integrated cellular GPS functionality for precise location tracking and positioning applications
- INTEGRATION: Single-board computer design combining RF transceiver and MCU for efficient space utilization and simplified development
- APPLICATIONS: Ideal for IoT devices, smart sensors, asset tracking, and cellular-connected embedded systems requiring low-power operation
What Quectel says about its security practices
In an August 14, 2023 response to media reports, Quectel said it holds ISO 9001, IATF 16949, ISO/SAE 21434, and ISO 27001 certifications. The company also stated that it cannot control, access, store, or manage customer device data. These are company representations; the response alone does not independently validate every product, certification scope, update pathway, or deployment. Buyers should check which products and operations a certification covers rather than treating a certification name as proof that a particular module is secure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to evaluate a cellular IoT module supplier
Charles Parton’s December 11, 2025 testimony at a U.S. House hearing recommends examining source-code control, technical dependencies, firmware updates, manufacturing risk, and server locations. These are expert recommendations presented in testimony, not a universal certification or an adjudicated finding about each supplier. For an actual procurement review, ask for product-specific evidence across the whole support lifecycle:
Best Value
- Ownership and governance: Identify the supplier’s ownership, corporate structure, governance, and relevant jurisdictions. A non-Chinese corporate identity does not, by itself, settle who controls technology, support, or operations.
- Technology provenance: Establish where the chipset, source code, and firmware originate, who controls them, and whether ongoing technical inputs depend on other parties or jurisdictions.
- Firmware updates: Determine who can create, approve, sign, and distribute updates. Ask how signing keys are protected, what authorization is required, and whether update operations depend on offshore staff or infrastructure.
- Servers and access: Request the locations of primary and mirrored update or support servers, who can reach them, and what access controls and monitoring apply.
- Manufacturing and audits: Identify manufacturing locations and safeguards, and examine the scope, independence, and product coverage of any security audit.
- Product fit and lifecycle: Verify carrier compatibility, support duration, product availability, and how vulnerabilities and end-of-life changes will be handled.
- Evidence quality: Separate independently verified, product-specific evidence from supplier statements and policy testimony. Record what has been verified, by whom, and for which model or firmware version.
These checks apply regardless of a supplier’s country of incorporation. Country can inform a jurisdiction and governance review, but a procurement decision should also account for technical dependencies, update control, support arrangements, and the device’s exposure if the module or its maintenance pathway fails.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

