Commercial vendor-risk tools score a supplier's website hygiene — TLS grades, open ports, breach mentions. None of that tells you who owns your vendor, where their hardware is made, or whether they sit on a federal exclusion list. Those are the questions that bind a DoD contractor. This screens for them.
SP 1326 deliberately leaves country risk organization-defined — NIST publishes no country list. Set yours before you screen, not after you have found something.
This sets the scoring threshold for everything below. Deciding it afterward, on a vendor you already want to buy from, is how people talk themselves into a bad purchase.
Answer the questions above. Partial answers still produce a result — you do not have to finish to get something useful.
Every screening question below traces to a primary federal source. Where a question is a practitioner judgment rather than a published requirement, it says so.
Practitioner guidance, not legal advice. Exclusion lists and clause requirements change — verify current status against the official sources above and against your contract before you rely on any result here. This tool does not query any list on your behalf; you check them and record what you find.