Supply-chain risk is where small contractors get burned by rules they didn't know applied to them — and almost none of it is graded by CMMC. Section 889 bans five named telecom and surveillance manufacturers from your systems. FASCSA orders can bar a product government-wide overnight. DFARS 252.204-7012 forces CUI onto US-sovereign, FedRAMP-authorized hosting. And TAA keeps hardware from non-designated countries off a GSA Schedule. Before you buy any tool, you vet the vendor against these — because "we didn't know" is not a defense in a False Claims Act case.
This is the part of getting compliant that's easy to miss — none of it shows up on the SPRS scorecard — and it's exactly how the government itself decides which companies it will work with. The government is deliberately careful and selective about its suppliers; this guide translates that same process for a shop without a compliance department: the prohibition lists to know, the ownership and hosting questions to ask, and a checklist you can run before you buy anything. It's also the part consultants quietly skip.
Section 889 of the FY2019 NDAA is the one every small contractor eventually trips over. It prohibits the government from procuring — and, under Part B, from contracting with any company that uses — "covered telecommunications equipment or services" from five named companies and their affiliates:
The timing matters. Part A (effective Aug 2019) bars the government from buying products that use this gear. Part B (effective Aug 2020) is the one that reaches you: the government can't contract with an entity that uses covered equipment anywhere in its operation — even on systems that never touch the federal contract. That camera watching your parking lot counts.
The Federal Acquisition Supply Chain Security Act (part of the SECURE Technology Act of 2018) created the Federal Acquisition Security Council (FASC). The FASC assesses supply-chain risk and recommends exclusion or removal orders, which are then issued by DHS (civilian), DoD (defense), or the DNI (intelligence). Once issued, an order can bar a product or source across the government.
For you, the FAR rule (Subpart 4.23, clause 52.204-30) creates an ongoing duty: check SAM.gov for FASCSA orders and exclusions at least every three months during performance, not just at award. This isn't theoretical — the first FASCSA exclusion-and-removal order was issued in September 2025 (by the DNI, against Acronis AG, scoped to intelligence systems). More will follow, and the point of a quarterly re-check is that a vendor you cleared last quarter can be barred this one.
Beyond the specific bans, there's a broader principle worth understanding: the government is deliberately selective about the companies it does business with. Rather than leaving it to case-by-case opinion, it maintains published lists of entities it restricts, excludes, or prohibits, and it expects that same diligence to flow down to its contractors. The takeaway for you isn't to make foreign-policy calls of your own — it's to be mindful of who ultimately owns and controls a vendor, and to check the government's own lists before you put a tool in a sensitive role.
Two things to screen against:
This is the one with the sharpest teeth for tool selection. Under DFARS 252.204-7012, any cloud service that stores, processes, or transmits CUI must be FedRAMP Moderate authorized — or meet a documented FedRAMP Moderate equivalency. And "equivalency" got real: DoD's December 2023 guidance requires 100% of the FedRAMP Moderate controls met, no open POA&Ms, assessed by a FedRAMP-recognized third-party assessor. Self-attestation is off the table.
The practical effect is a sovereignty gate. FedRAMP authorization presumes US-based data storage and US-person administrative access — which is precisely why a foreign-owned SaaS that can't show a FedRAMP authorization is a compliance trap for CUI, no matter how good the product is. For export-controlled CUI (ITAR and similar), that pushes you to a US-sovereign enclave — GCC High or Azure Government. Verify any cloud claim on the FedRAMP Marketplace, not the vendor's marketing page.
If you resell hardware to the government, or put products on a GSA Schedule, the Trade Agreements Act (FAR 52.225-5) is a gate. Products must be made — or "substantially transformed" — in the US or a designated (allied) country. A number of major electronics-manufacturing countries are not on the designated list, so hardware made there generally can't ride a GSA Schedule. And because TAA applies at the contract level, every product on a Schedule must comply, even for a small order. Country of manufacture is a yes/no gate, not a footnote — which is exactly why "US-owned company, overseas-made hardware" (a common pattern) still deserves a hard look.
Here's the honest, precise answer, because it's the thing people get wrong. Today, no. CMMC Level 2 is built on NIST SP 800-171 Revision 2, which has 110 controls across 14 families and no dedicated supply-chain (SR) family. There is no scored supply-chain control an assessor checks. Your supply-chain obligations come from elsewhere — Section 889, FASCSA, DFARS 7012 — not from a CMMC score.
That's changing. NIST SP 800-171 Revision 3 (finalized 2024) restructures the framework and adds a Supply Chain Risk Management (SR) family. When DoD transitions CMMC from Rev 2 to Rev 3 — timing not finalized as of mid-2026 — supply-chain risk becomes assessable. So the accurate framing is: SCRM is a contractual and prohibition-list obligation now, and a graded CMMC control later. Anyone telling you your CMMC assessment scores your supply chain today is ahead of the rulebook.
This is the process, boiled down to what you actually run before you buy a tool or a piece of hardware. It takes about fifteen minutes and it's the difference between a clean rep and a False Claims Act problem.
The whole 15-minute vetting check on one page — the seven steps plus the six official lists to verify against. Keep it by your desk and run it before every purchase.
We keep a running, SCRM-vetted CMMC Tool Stack — US-based or FedRAMP-authorized where CUI is involved, and screened against the federal prohibition lists — so you're not vetting every vendor from scratch. And when it's time to document it all, the CMMC Level 2 DIY Compliance Kit gives you the SSP, 20 policies, POA&M, and SPRS scorer a small shop needs.
Not directly, and not yet. CMMC Level 2 is built on NIST SP 800-171 Rev 2, which has no dedicated supply-chain (SR) family — so there's no scored supply-chain control today. Your obligations come from Section 889, FASCSA orders, and DFARS 7012 flow-downs. NIST 800-171 Rev 3 adds an SR family, so when CMMC transitions to Rev 3, supply chain becomes assessable.
It prohibits the government from buying, or contracting with any company that uses, covered telecom/surveillance gear from Huawei, ZTE, Hytera, Hikvision, or Dahua (and affiliates). Part B (Aug 2020) reaches your own internal systems regardless of the contract — so yes, it applies. The most common finding is white-labeled Hikvision/Dahua cameras, so ask about the OEM, not the brand. You represent compliance annually in SAM.gov via FAR 52.204-26.
There's no single list — check the vendor and its ultimate parent against SAM.gov Exclusions, SAM.gov FASCSA orders, the DoD 1260H list, OFAC, and the BIS Entity List, plus the FCC Covered List. For any cloud handling CUI, verify FedRAMP authorization on the FedRAMP Marketplace. Re-check FASCSA orders and exclusions at least every three months.
Effectively no. DFARS 252.204-7012 requires any cloud handling CUI to be FedRAMP Moderate authorized or a documented FedRAMP Moderate equivalent (3PAO-assessed; self-attestation not permitted per DoD's Dec 2023 guidance). FedRAMP presumes US data storage and US-person admin access, which keeps CUI out of foreign hosting. For export-controlled data, use GCC High or Azure Government.
The Trade Agreements Act requires products be made, or substantially transformed, in the US or a designated (allied) country. Many major manufacturing countries aren't on the designated list, so hardware made there generally can't be sold on a GSA Schedule — and TAA applies at the contract level, so every product must comply even for a small order.