The Notice Is Shorter Than the Work
An executive order directs that defence contractors will have to map their supply chains to the raw material and vet every supplier in them. The rules are not written yet. That reads like time, and it is not.
Avihu Marom · · 7 MIN READ
Somewhere in your supply chain there is a company you have never looked at. It makes a component that goes into an assembly that goes into a system you deliver. It is three or four steps down from you, it has never appeared in a contract you signed, and if someone asked you today who controls it, you would not be able to answer.
On 20 July an executive order made that your problem.
What the order actually directs
Read it for what it obliges rather than what it announces, because the two are different documents. The order directs the Secretary of War to develop policy and implementation guidance requiring all prime contractors and subcontractors, at any tier, to map and illuminate their critical supply chains for acquisitions that support national security. Not the first tier. Any tier, from the origin of the raw materials to the finished product you hand over.
The mapping is not a diagram. Contractors would be required to file a complete indentured Bill of Materials, tracing every component, part, item of equipment, piece of software and material back to where the raw material came from.
Then the part that matters most. Contractors would be required to establish written procedures to proactively vet all suppliers and subcontractors in that chain, screening at minimum for three categories the order names itself: financial condition, foreign ownership control or influence, and manufacturing and supply capacity.
Vetting on a clock, too. Significant risks identified by that screening go to the Department within fifteen days. A written corrective action plan follows within forty-five. Mitigation gets tracked to closure, with a closeout report at the end.
Two definitions worth reading twice
The order defines its own terms, and the definitions are where the work actually sits.
Financial risk it defines as a supplier that cannot generate revenue or income sufficient to meet its financial obligations, with distress leading to inability to perform, hostile takeover or bankruptcy. That is not a credit score. A credit score tells you what a rating agency thinks about a company that files. Reading whether a supplier is quietly failing means reading its accounts, over several years, for what they mean rather than what they say.
Foreign ownership, control or influence it defines as a foreign interest holding the power to direct or decide matters affecting the management or operations of a company, and then adds the clause that changes everything: "whether through direct or indirect control, whether or not exercised."
Not ownership. Power. And power that has never once been used still counts.
A screen built to find registered owners will not find that, because it does not appear as a shareholding. It appears as a supply agreement that cannot be terminated, a loan whose covenants decide who sits on the board, a licensing arrangement that makes one customer impossible to refuse, a founder whose other company is somewhere else entirely. None of that is on a register. All of it is control.
The second front
The order is not moving alone. On 7 May the Department published a proposed rule, DFARS Case 2021-D011, extending foreign ownership and beneficial ownership disclosure to unclassified defence contracts and subcontracts at any tier valued above five million dollars. Disclosures go to the Defense Counterintelligence and Security Agency, and identified risk has to be mitigated within ninety days.
The Department's own regulatory analysis estimates 37,740 potentially affected awardees, of which 21,511 are small businesses. Comments closed on 6 July. The final rule is pending.
So there are two instruments arriving from different directions at the same population, and a large share of that population is small companies with no compliance function at all.
Be precise about the clock, because the clock is the argument
None of this binds a contractor today. The order directs guidance within 180 days, and implementing regulations within 90 days of that guidance being completed. The DFARS rule is at final-rule stage with no published date. What is fixed is the waiver route: from 1 January 2027 the Secretary stops issuing waivers for non-compliant covered materials except against a formal accepted mitigation plan, and the order provides that fraud or deliberate misrepresentation in such a plan triggers contractual remedies and possible referral to the Attorney General.
Read that timeline and it looks like a year of room.
It is not, and this is the whole point. Mapping a supply chain to its fourth tier is not a form to complete. It is a programme of work: identifying who your suppliers actually buy from, getting them to tell you, verifying what they tell you, and then screening what you find for a category of control that by definition nobody registered. The organisations that begin when the regulation lands will be starting from zero on a multi-year map, under a deadline, with an attestation attached.
The notice period is shorter than the work. That gap is the entire exposure.
What this piece is not
It is not news that the order exists. Wiley, Squire Patton Boggs, Latham & Watkins, Torres Trade Law and others have published on the ownership and FOCI obligations, and their reading is sound. If you want the regulatory summary, they have written it.
What is missing from the commentary is the operational question. Everyone agrees you will have to screen suppliers for control that is not on a register. Almost nobody is saying how, or asking the harder question underneath it: when the concealment is deliberate and the screening is new, does the screening actually win?
So I am going to test it in public
In August I am running that question as a probabilistic war game. Fifty iterations. Fourteen actors, including the acquirer, the concealment layer, the sub-tier supplier, the prime, its compliance function, the screening agencies, and the private diligence providers. One question: over a three-month window, does the screening apparatus detect concealed foreign control inside a defence supply chain, or does the concealment survive contact with it?
The file gets locked before the window opens and never touched again. At the end I publish the grade, including what it got wrong. The last one of these I ran on the US-Iran confrontation, and when its three months were up I published the misses alongside the calls, because an assessment that cannot show you its failures is not an assessment.
The diligence layer is modelled as an actor in that game, not as the hero. If the runs show screening failing at a particular tier, that publishes as found.
What to do before the regulations arrive
Two things, and neither requires waiting.
Find out how far down your map actually goes. Most organisations know tier one, believe they know tier two, and are guessing below that. The gap between what you can evidence and what you would have to attest is the real size of the job, and you can measure it this quarter.
Then take one supplier that matters and ask the control question properly, rather than the ownership question. Not who is on the register. Who could direct a decision here if they chose to, and how would we know. That is a different investigation, and it is the one the order describes.
An enhanced due diligence file reads structure and control rather than registered ownership. A forensic financial report reads a subject's filed accounts to a verdict on whether the business is what it claims to be. Those are the two screens the order names, and they exist now, ahead of the regulation that will require them.