President Donald Trump has signed an executive order requiring the War Department to develop new rules for mapping and securing critical defense supply chains, including the software, services and technology used in national security systems.
Although the primary focus is on domestic procurement of critical materials, the executive order contains several provisions relevant to cybersecurity teams, particularly those responsible for software supply chain security, third-party risk, and defense contractor compliance.
The order states that the United States must protect its defense supply chains from “physical, cyber and economic subversion” and calls for greater transparency from suppliers and subcontractors at all levels.
Within 180 days, the Secretary of War must develop guidelines requiring defense contractors to map critical supply chains in support of national security procurement. Implementation provisions are due within 90 days of the closing of the policies.
The requirements would apply not only to prime contractors, but potentially also to subcontractors at all levels of the defense supply chain.
Table of Contents
Software included in supply chain mapping
Under the proposed regulations, contractors would be required to provide a complete “contractual bill of materials” that tracks components, equipment, software and materials through the supply chain and back to the origin of the underlying raw materials.
The planned documentation is much more comprehensive than a conventional software bill of materials (SBOM). It could link software and firmware dependencies to physical components, manufacturers, suppliers, maintenance information, countries of origin and raw material sources.
The order defines a critical supply chain as all tiers of suppliers and subcontractors that provide goods, materials, systems, software or services essential to contract performance, order security, security or resilience.
This definition could result in software developers, cloud providers, managed service providers and other technology companies falling within the scope of the upcoming regulations, even if they are several levels removed from the prime defense contractor.
Contractors must vet suppliers
Contractors would also be required to establish written procedures for proactively vetting suppliers and subcontractors.
At a minimum, reviews must consider financial stability, foreign ownership or influence, and manufacturing and supply risks. Contractors are expected to identify concerns such as single source dependencies, insufficient production capacity, supplier concentration and excessive single source dependency.
Foreign ownership, control, or influence is defined, in part, by whether a foreign interest could obtain unauthorized access to information or interfere with the performance of a national security treaty.
For cybersecurity teams, this could expand traditional third-party security assessments to include beneficial ownership, foreign investment, development locations, administrative access, data hosting arrangements and changes in corporate controls.
The order also directs the government to prohibit contractors from using covered materials from an unreliable foreign supplier, subject to certain exceptions.
Risks in the supply chain must be reported
Once the required review is completed, contractors would be required to mitigate identified risks and track corrective actions to completion.
Significant risks in the supply chain would be required to be reported to the War Department within 15 days of completion of verification activities. Contractors would then have 45 days to submit a confidential corrective action plan detailing their remedial actions and a timeline for completion of the work.
A final report would also be required after corrective actions have been implemented.
The regulation does not define what constitutes a “significant” supply chain risk or whether the provision covers specific software vulnerabilities, compromises or other cybersecurity findings. These details are likely to be addressed in upcoming regulations.
The 15-day provision should not be construed as a general deadline for reporting cybersecurity incidents. It applies to risks identified as part of the supplier verification process provided for in the order.
Regulation tightens exemptions and domestic procurement requirements
In addition to the mapping and verification requirements, the regulation tightens the procurement rules that regulate which materials contractors can actually use. Effective January 1, 2027, the Secretary of War and the Secretaries of Service generally would not issue waivers pursuant to 10 USC § 4872 permitting the acquisition of covered material from prohibited sources. An exemption could still be granted, but only if the prime contractor or subcontractor submits a formal mitigation plan that identifies the non-compliant source, documents efforts made to find a compliant alternative, and sets a timeline for removing the material from the supply chain. Contractors found to have committed fraud or knowingly failed to implement an approved mitigation plan will face liquidated damages and a referral to the Attorney General.
A separate provision would require contractors whose supply chains depend on an unreliable foreign supplier to qualify and move to an alternative source as quickly as possible. Failure to do so could result in the government suspending or terminating work orders, refusing to exercise contract options, or terminating the contract entirely.
Although these provisions are less directly linked to cybersecurity than the supply chain mapping requirements, they increase compliance requirements for the same third-party risk and supplier management teams that would be responsible for verification and reporting requirements elsewhere in the regulation.
Sensitive supply chain data could become a target
The comprehensive supply chain maps required by the regulation could themselves pose significant cybersecurity risks.
A detailed database linking defense systems to software dependencies, suppliers, raw materials, production locations and operational bottlenecks would provide a potentially valuable target for foreign intelligence agencies and other threat actors.
Compromised supply chain data could help an attacker identify single points of failure, difficult-to-replace suppliers, vulnerable software dependencies, and opportunities for espionage, sabotage, or economic coercion.
To protect this information, defense contractors may need to apply strict access controls, encryption, audit logging, data loss prevention, and compartmentalization. The order permits disclosure of some BOM information to government support contractors as necessary, provided protected information is protected from unauthorized access or use.
Government uses AI for supply chain analysis
The order directs the War Department to use available tools and technologies, including artificial intelligence, to analyze contractor procurement information and identify national security gaps, bottlenecks and single points of failure.
AI deployment could enable the government to analyze extremely large and complex networks of suppliers, components and dependencies. However, it can also raise questions about the accuracy of supplier risk determination, the protection of proprietary information, and the security of centralized government supply chain databases.
Although the regulation does not impose traditional cybersecurity requirements such as encryption standards, secure development practices, or vulnerability disclosure rules, it could significantly expand the responsibilities of cybersecurity and third-party risk teams in the defense industry.
The practical impact will depend on which acquisitions are classified as security-related and how comprehensively the government applies the upcoming rules. Defense contractors, meanwhile, may need to begin integrating SBOM management, hardware assurance, supplier provenance, foreign ownership verification and cybersecurity risk management into a single supply chain security program.
Related: Pentagon suspends CMMC Phase 2 as it reconsiders cybersecurity rules for contractors
Related: North Korean hackers target open source developers in supply chain attacks
Related: Do SBOMs fail? Supply chain attacks are on the rise as security teams struggle with SBOM data
https://www.securityweek.com/trump-orders-defense-contractors-to-map-software-suppliers-across-critical-supply-chains/
