Home / Guides / Vendor Supply-Chain Risk

Vet Your Vendors for Supply-Chain Risk & Foreign Ownership

Focus: supply chain risk management Veteran-run · practitioner guide Updated Jul 19, 2026 ~13 min read
Update · Jul 2026 CMMC Phase 2 is suspended (DoD, Jul 13, 2026) — but the supply-chain rules below are separate and still in force. Section 889, FASCSA orders, and DFARS 252.204-7012 don't pause when CMMC does. CMMC status →
The short answer

Supply-chain risk is where small contractors get burned by rules they didn't know applied to them — and almost none of it is graded by CMMC. Section 889 bans five named telecom and surveillance manufacturers from your systems. FASCSA orders can bar a product government-wide overnight. DFARS 252.204-7012 forces CUI onto US-sovereign, FedRAMP-authorized hosting. And TAA keeps hardware from non-designated countries off a GSA Schedule. Before you buy any tool, you vet the vendor against these — because "we didn't know" is not a defense in a False Claims Act case.

This is the part of getting compliant that's easy to miss — none of it shows up on the SPRS scorecard — and it's exactly how the government itself decides which companies it will work with. The government is deliberately careful and selective about its suppliers; this guide translates that same process for a shop without a compliance department: the prohibition lists to know, the ownership and hosting questions to ask, and a checklist you can run before you buy anything. It's also the part consultants quietly skip.

The trap that catches everyone — including consultants There is no single "banned vendor" list. There are at least six, they overlap, and they are legally distinct: Section 889's covered-telecom list, the FCC Covered List, the DoD 1260H list, OFAC's sanctions lists, the BIS Entity List, and SAM.gov FASCSA orders. The single most common error in this space is treating them as one — for example, saying "DJI is banned under Section 889." It isn't; DJI is on the FCC Covered List and the 1260H list, which are different regimes with different teeth. Keep them separate and you're already ahead of most.

Section 889: the five names to know

Section 889 of the FY2019 NDAA is the one every small contractor eventually trips over. It prohibits the government from procuring — and, under Part B, from contracting with any company that uses — "covered telecommunications equipment or services" from five named companies and their affiliates:

The timing matters. Part A (effective Aug 2019) bars the government from buying products that use this gear. Part B (effective Aug 2020) is the one that reaches you: the government can't contract with an entity that uses covered equipment anywhere in its operation — even on systems that never touch the federal contract. That camera watching your parking lot counts.

The #1 real-world finding White-labeled cameras. Hikvision and Dahua manufacture surveillance gear that gets rebranded and sold under dozens of other names. A contractor buys "Brand X" cameras, represents clean on their annual SAM.gov rep, and is wrong — because Brand X is a rebadged Dahua. When you vet, ask about the original equipment manufacturer (OEM), not the label on the box, and get it in writing. You represent 889 compliance annually via FAR 52.204-26, and the underlying prohibition and flow-down live in FAR 52.204-25.

FASCSA: the order that can drop overnight

The Federal Acquisition Supply Chain Security Act (part of the SECURE Technology Act of 2018) created the Federal Acquisition Security Council (FASC). The FASC assesses supply-chain risk and recommends exclusion or removal orders, which are then issued by DHS (civilian), DoD (defense), or the DNI (intelligence). Once issued, an order can bar a product or source across the government.

For you, the FAR rule (Subpart 4.23, clause 52.204-30) creates an ongoing duty: check SAM.gov for FASCSA orders and exclusions at least every three months during performance, not just at award. This isn't theoretical — the first FASCSA exclusion-and-removal order was issued in September 2025 (by the DNI, against Acronis AG, scoped to intelligence systems). More will follow, and the point of a quarterly re-check is that a vendor you cleared last quarter can be barred this one.

Don't confuse the mechanisms The 2024 Kaspersky ban is often miscited as a FASCSA order — it wasn't. That was a Commerce Department ICTS Final Determination (effective Sept 2024) under a different authority, and it reaches the private sector, not just federal systems. Different law, different scope. If you're going to cite the rule to a prime, cite the right one.

How the government screens its suppliers

Beyond the specific bans, there's a broader principle worth understanding: the government is deliberately selective about the companies it does business with. Rather than leaving it to case-by-case opinion, it maintains published lists of entities it restricts, excludes, or prohibits, and it expects that same diligence to flow down to its contractors. The takeaway for you isn't to make foreign-policy calls of your own — it's to be mindful of who ultimately owns and controls a vendor, and to check the government's own lists before you put a tool in a sensitive role.

Two things to screen against:

FOCI — when the formal rule actually applies You'll hear "FOCI" (Foreign Ownership, Control, or Influence) thrown around. Be precise: FOCI is a DCSA / National Industrial Security Program concept that formally applies to cleared contractors — companies holding or seeking a facility clearance for classified work (32 CFR Part 117). If you only handle CUI and hold no clearance, the formal FOCI mitigation regime doesn't bind you — but the ownership question still absolutely does, through 889, 1260H, and your customers' own risk appetite. Know which rule you're actually under.

CUI hosting: US-sovereign, FedRAMP, no exceptions

This is the one with the sharpest teeth for tool selection. Under DFARS 252.204-7012, any cloud service that stores, processes, or transmits CUI must be FedRAMP Moderate authorized — or meet a documented FedRAMP Moderate equivalency. And "equivalency" got real: DoD's December 2023 guidance requires 100% of the FedRAMP Moderate controls met, no open POA&Ms, assessed by a FedRAMP-recognized third-party assessor. Self-attestation is off the table.

The practical effect is a sovereignty gate. FedRAMP authorization presumes US-based data storage and US-person administrative access — which is precisely why a foreign-owned SaaS that can't show a FedRAMP authorization is a compliance trap for CUI, no matter how good the product is. For export-controlled CUI (ITAR and similar), that pushes you to a US-sovereign enclave — GCC High or Azure Government. Verify any cloud claim on the FedRAMP Marketplace, not the vendor's marketing page.

TAA: where the hardware was made

If you resell hardware to the government, or put products on a GSA Schedule, the Trade Agreements Act (FAR 52.225-5) is a gate. Products must be made — or "substantially transformed" — in the US or a designated (allied) country. A number of major electronics-manufacturing countries are not on the designated list, so hardware made there generally can't ride a GSA Schedule. And because TAA applies at the contract level, every product on a Schedule must comply, even for a small order. Country of manufacture is a yes/no gate, not a footnote — which is exactly why "US-owned company, overseas-made hardware" (a common pattern) still deserves a hard look.

Does CMMC actually grade this?

Here's the honest, precise answer, because it's the thing people get wrong. Today, no. CMMC Level 2 is built on NIST SP 800-171 Revision 2, which has 110 controls across 14 families and no dedicated supply-chain (SR) family. There is no scored supply-chain control an assessor checks. Your supply-chain obligations come from elsewhere — Section 889, FASCSA, DFARS 7012 — not from a CMMC score.

That's changing. NIST SP 800-171 Revision 3 (finalized 2024) restructures the framework and adds a Supply Chain Risk Management (SR) family. When DoD transitions CMMC from Rev 2 to Rev 3 — timing not finalized as of mid-2026 — supply-chain risk becomes assessable. So the accurate framing is: SCRM is a contractual and prohibition-list obligation now, and a graded CMMC control later. Anyone telling you your CMMC assessment scores your supply chain today is ahead of the rulebook.

The pre-purchase vetting checklist

This is the process, boiled down to what you actually run before you buy a tool or a piece of hardware. It takes about fifteen minutes and it's the difference between a clean rep and a False Claims Act problem.

  1. Identify the real owner.HQ country and the country of the ultimate parent — not the US sales entity. A US-registered LLC can be wholly owned abroad.
  2. Screen against the lists (all of them).Check the entity and its parent against SAM.gov Exclusions, SAM.gov FASCSA orders, the DoD 1260H list, OFAC, and the BIS Entity List. A hit on any of them is stop-and-escalate — let the government's own lists do the judging, not you.
  3. Clear Section 889.Confirm no Huawei/ZTE/Hytera/Hikvision/Dahua components — and ask about the OEM, not the brand, to catch white-labeled cameras. Get it in writing for your 52.204-24/26 reps.
  4. Check country of manufacture (TAA).For anything going on a Schedule or a TAA-covered buy: US or a designated country. Hardware made in a non-designated country generally can't ride a GSA Schedule.
  5. Verify CUI hosting (if CUI is involved).FedRAMP Moderate authorized (or documented equivalent, 3PAO-assessed) on the FedRAMP Marketplace; US data residency; US-person admin access. No FedRAMP, no CUI.
  6. Secure the flow-downs.Get the vendor to accept DFARS 252.204-7012, and flow down 52.204-25 (889) and 52.204-30 (FASCSA) to any sub or supplier.
  7. Set a recurring re-check.Re-screen FASCSA orders and exclusions at least every three months during performance, and re-check the lists on every material re-buy. Clearance is a snapshot, not a permanent status.
Where to verify — bookmark these FedRAMP Marketplace (cloud authorization) · SAM.gov Exclusions and SAM.gov Supply Chain (FASCSA) Orders · the DoD 1260H list (defense.gov) · OFAC sanctions search and the BIS Entity List · the FCC Covered List · TAA-designated countries (GSA / FAR 25.003). Six windows, fifteen minutes, and you've done what most primes wish their subs would do.
Free · one-page PDF

Get this as a printable checklist

The whole 15-minute vetting check on one page — the seven steps plus the six official lists to verify against. Keep it by your desk and run it before every purchase.

No spam. Unsubscribe anytime. No login.
Vetted the way the government vets

Your tools are half the battle. The paperwork proves it.

We keep a running, SCRM-vetted CMMC Tool Stack — US-based or FedRAMP-authorized where CUI is involved, and screened against the federal prohibition lists — so you're not vetting every vendor from scratch. And when it's time to document it all, the CMMC Level 2 DIY Compliance Kit gives you the SSP, 20 policies, POA&M, and SPRS scorer a small shop needs.

$2,995
one-time · lifetime updates · a fraction of a consultant's retainer
Practitioner guidance, not legal advice. Verify current list status and clause requirements against your contract and official sources before you rely on them.
Primary sources

Frequently asked questions

Does CMMC grade my supply-chain risk management?

Not directly, and not yet. CMMC Level 2 is built on NIST SP 800-171 Rev 2, which has no dedicated supply-chain (SR) family — so there's no scored supply-chain control today. Your obligations come from Section 889, FASCSA orders, and DFARS 7012 flow-downs. NIST 800-171 Rev 3 adds an SR family, so when CMMC transitions to Rev 3, supply chain becomes assessable.

What is Section 889 and does it apply to my small business?

It prohibits the government from buying, or contracting with any company that uses, covered telecom/surveillance gear from Huawei, ZTE, Hytera, Hikvision, or Dahua (and affiliates). Part B (Aug 2020) reaches your own internal systems regardless of the contract — so yes, it applies. The most common finding is white-labeled Hikvision/Dahua cameras, so ask about the OEM, not the brand. You represent compliance annually in SAM.gov via FAR 52.204-26.

How do I check if a vendor is prohibited?

There's no single list — check the vendor and its ultimate parent against SAM.gov Exclusions, SAM.gov FASCSA orders, the DoD 1260H list, OFAC, and the BIS Entity List, plus the FCC Covered List. For any cloud handling CUI, verify FedRAMP authorization on the FedRAMP Marketplace. Re-check FASCSA orders and exclusions at least every three months.

Can I store CUI with a foreign-owned cloud provider?

Effectively no. DFARS 252.204-7012 requires any cloud handling CUI to be FedRAMP Moderate authorized or a documented FedRAMP Moderate equivalent (3PAO-assessed; self-attestation not permitted per DoD's Dec 2023 guidance). FedRAMP presumes US data storage and US-person admin access, which keeps CUI out of foreign hosting. For export-controlled data, use GCC High or Azure Government.

What does TAA-compliant mean and why does it matter?

The Trade Agreements Act requires products be made, or substantially transformed, in the US or a designated (allied) country. Many major manufacturing countries aren't on the designated list, so hardware made there generally can't be sold on a GSA Schedule — and TAA applies at the contract level, so every product must comply even for a small order.