Free tool · nothing leaves your browser

FOCI Screener — foreign ownership, control & influence

Commercial vendor-risk tools score a supplier's website hygiene — TLS grades, open ports, breach mentions. None of that tells you who owns your vendor, where their hardware is made, or whether they sit on a federal exclusion list. Those are the questions that bind a DoD contractor. This screens for them.

What this is, precisely. A structured screening aid built on the Foreign Ownership, Control, or Influence research area in NIST SP 1326, paired with the federal exclusion lists a contractor is actually bound by. It is not a legal FOCI determination. Formal FOCI is a National Industrial Security Program concept under 32 CFR 117.11, and only DCSA makes that determination — about your company, for facility clearance purposes. What you are doing here is borrowing the federal lens to screen your own suppliers. That is a due-diligence practice, not a compliance filing. SP 1326 is guidance written for federal C-SCRM practitioners. There is no SP 1326 certification and no contract clause requiring it. The method, explained →

First: your organization's risk posture

SP 1326 deliberately leaves country risk organization-defined — NIST publishes no country list. Set yours before you screen, not after you have found something.

How much foreign exposure can you tolerate in a supplier touching CUI or covered systems?

This sets the scoring threshold for everything below. Deciding it afterward, on a vendor you already want to buy from, is how people talk themselves into a bad purchase.

Level of concern
Not yet screened

Answer the questions above. Partial answers still produce a result — you do not have to finish to get something useful.

    Nothing you type here leaves your browser. This page has no backend and no form submission. Every answer, every score, and every export is computed locally in JavaScript and held in memory only — there is no analytics on what you enter, and closing the tab discards it. It works offline once loaded. Open your network tab and screen a vendor — you will see no requests. That is rather the point: a page that collected your suppliers' weaknesses would be a target, and we would rather not hold them.
    Provenance

    Where each question comes from

    Every screening question below traces to a primary federal source. Where a question is a practitioner judgment rather than a published requirement, it says so.

    • FOCI research areas (ownership, key leadership, foreign legal compulsion) — NIST SP 1326, derived from the baseline risk factors in SP 800-161 Rev 1, Appendix E.
    • Formal FOCI definition and DCSA authority32 CFR 117.11.
    • Pre-check exclusion sourcesITA Consolidated Screening List · SAM.gov Exclusions · SPRS. SP 1326 names all three as the checks to run before spending effort on research.
    • Section 889 covered telecomFAR 52.204-25.
    • Supply chain (FASCSA) ordersFAR Subpart 4.23.
    • Country-risk thresholds — deliberately not supplied. SP 1326 makes these organization-defined; NIST publishes no country list, and neither do we. The posture selector above is your tolerance, applied consistently.
    • Weighting — a practitioner judgment, not a published federal schema. The scoring below reflects how these factors are weighed in practice; it is not a NIST-sanctioned score. Treat the flags as the output, not the number.
    Screening is one half. This tool answers "is there a foreign-control problem, and are they barred?" It does not answer "what do I actually know about this company?" — that is the wider due-diligence research across provenance, resilience, foundational cyber practices, and supply chain tiers. The full federal method → · The prohibition rules in detail →

    Practitioner guidance, not legal advice. Exclusion lists and clause requirements change — verify current status against the official sources above and against your contract before you rely on any result here. This tool does not query any list on your behalf; you check them and record what you find.