Back to Feed
PolicyJul 21, 2026

Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains

US defense contractors must map software and suppliers across critical supply chains.

Summary

President Trump has signed an executive order requiring defense contractors to map their entire supply chains, including software dependencies, foreign ownership, and cyber risks. This initiative aims to enhance visibility and security within national security systems by demanding detailed 'indentured Bills of Materials' and proactive supplier vetting.

Full text

President Donald Trump has signed an executive order requiring the Department of War to develop new rules for mapping and securing critical defense supply chains, including the software, services and technology used in national security systems. While primarily focused on domestic sourcing of critical materials, the executive order contains several provisions relevant to cybersecurity teams, particularly those responsible for software supply chain security, third-party risk and defense contractor compliance. The order states that the United States must protect its defense supply chains against “physical, cyber, and economic subversion,” and calls for greater visibility into suppliers and subcontractors at every tier. Within 180 days, the Secretary of War must develop policies requiring defense contractors to map critical supply chains supporting national security acquisitions. Implementing regulations are due within 90 days after the policies are completed. The requirements would apply not only to prime contractors, but potentially to subcontractors at every level of the defense supply chain. Software Included in Supply Chain Mapping Under the proposed regulations, contractors would be required to submit a complete “indentured Bill of Materials” tracing components, equipment, software and materials through the supply chain and back to the origin of the underlying raw materials.Advertisement. Scroll to continue reading. The contemplated documentation is significantly broader than a traditional software bill of materials, or SBOM. It could connect software and firmware dependencies with physical components, manufacturers, suppliers, maintenance information, countries of origin and raw-material sources. The order defines a critical supply chain as all tiers of suppliers and subcontractors providing goods, materials, systems, software or services essential to contract delivery, mission assurance, security or resilience. That definition could bring software developers, cloud providers, managed service providers and other technology companies within the scope of the forthcoming regulations, even when they are several layers removed from the prime defense contractor. Contractors Required to Vet Suppliers Contractors would also be required to establish written procedures for proactively vetting suppliers and subcontractors. At a minimum, the reviews must consider financial stability, foreign ownership or influence, and manufacturing and supply risks. Contractors would be expected to identify concerns such as sole-source dependencies, inadequate production capacity, supplier concentration and overreliance on a single source. Foreign ownership, control or influence is defined partly in terms of whether a foreign interest could obtain unauthorized access to information or adversely affect the performance of a national security contract. For cybersecurity teams, that could expand traditional third-party security assessments to include beneficial ownership, foreign investment, development locations, administrative access, data-hosting arrangements and changes in corporate control. The order also directs the government to prohibit contractors from using covered materials supplied by an unreliable foreign supplier, subject to certain exceptions. Supply Chain Risks Must Be Reported After completing the required vetting, contractors would have to mitigate identified risks and track corrective actions until closure. Significant supply chain risks would need to be reported to the Department of War within 15 days after the vetting activities are completed. Contractors would then have 45 days to submit a confidential corrective action plan detailing their mitigations and a timeline for completing the work. A closeout report would also be required after corrective actions have been implemented. The order does not define what constitutes a “significant” supply chain risk or whether the provision will cover specific software vulnerabilities, compromises or other cybersecurity findings. Those details will likely be addressed through the forthcoming regulations. The 15-day provision should not be interpreted as a general cybersecurity incident reporting deadline. It applies to risks identified through the supplier-vetting process contemplated by the order. Order Tightens Waivers and Domestic Sourcing Requirements Beyond the mapping and vetting provisions, the order tightens the sourcing rules that govern which materials contractors may use in the first place. Starting January 1, 2027, the Secretary of War and the service secretaries would generally stop issuing waivers under 10 U.S.C. § 4872 that allow the acquisition of covered materials from prohibited sources. A waiver could still be granted, but only where the prime contractor or subcontractor submits a formal mitigation plan that identifies the non-compliant source, documents the efforts made to find a compliant alternative, and sets a timeline for removing the material from the supply chain. Contractors found to have committed fraud or knowingly failed to carry out an approved mitigation plan could face contractual penalties and referral to the Attorney General. A separate provision would require contractors whose supply chains depend on an unreliable foreign supplier to qualify and move to an alternative source as soon as practicable. Failure to do so could become grounds for the government to suspend or terminate task orders, decline to exercise contract options, or terminate the contract outright. While these provisions are less directly tied to cybersecurity than the supply chain mapping requirements, they raise the compliance stakes for the same third-party risk and supplier-management teams that would be responsible for the vetting and reporting obligations elsewhere in the order. Sensitive Supply Chain Data Could Become a Target The comprehensive supply chain maps required by the order could themselves create significant cybersecurity risks. A detailed database connecting defense systems to software dependencies, suppliers, raw materials, manufacturing locations and operational bottlenecks would provide a potentially valuable target for foreign intelligence services and other threat actors. Compromised supply chain data could help an adversary identify single points of failure, difficult-to-replace suppliers, vulnerable software dependencies and opportunities for espionage, sabotage or economic coercion. Defense contractors may need to apply strict access controls, encryption, audit logging, data loss prevention and compartmentalization to protect this information. The order allows some bill-of-materials information to be disclosed to government support contractors when necessary, provided proprietary information is protected against unauthorized access or use. Government to Use AI for Supply Chain Analysis The order directs the Department of War to use available tools and technologies, including artificial intelligence, to analyze contractor acquisition information and identify national security vulnerabilities, bottlenecks and single points of failure. The AI provision could allow the government to analyze extremely large and complex networks of suppliers, components and dependencies. However, it may also raise questions about the accuracy of supplier-risk determinations, the protection of proprietary information and the security of centralized government supply chain databases. Although the order does not impose conventional cybersecurity requirements such as encryption standards, secure development practices or vulnerability disclosure rules, it could significantly expand the responsibilities of cybersecurity and third-party risk teams in the defense industrial base. The practical effect will depend on which acquisitions are designated as national security-related and how broadly the government applies the forthcoming rules. Defense contractors, meanwhile, may need to begin integrating SBOM management, hard

Entities

Bill of Materials (product)software supply chain security (technology)third-party risk (technology)