Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
President Trump has signed an executive order requiring defense contractors to map and vet their entire supply chains, including software and materials, to protect national security systems from foreign influence and subversion. This expansion of third-party risk management will require contractors to identify and mitigate vulnerabilities across multiple tiers of suppliers, with a focus on foreign ownership and control. The order also tightens sourcing rules, prohibiting the use of materials from unreliable foreign suppliers and utilizing AI to analyze supply chain data, presenting significant cybersecurity challenges and requiring defense contractors to integrate SBOM management and supplier provenance into their security programs.
President Donald Trump has signed an executive order requiring the Department of War to develop new rules for mapping and securing critical defense supply chains, including the software, services and technology used in national security systems. While primarily focused on domestic sourcing of critical materials, the executive order contains several provisions relevant to cybersecurity teams, particularly those responsible for software supply chain security, third-party risk and defense contractor compliance.
Within 180 days, the Secretary of War must develop policies requiring defense contractors to map critical supply chains supporting national security acquisitions. Implementing regulations are due within 90 days after the policies are completed. The requirements would apply not only to prime contractors, but potentially to subcontractors at every level of the defense supply chain.
Under the proposed regulations, contractors would be required to submit a complete “indentured Bill of Materials” tracing components, equipment, software and materials through the supply chain and back to the origin of the underlying raw materials. The contemplated documentation is significantly broader than a traditional software bill of materials, or SBOM. It could connect software and firmware dependencies with physical components, manufacturers, suppliers, maintenance information, countries of origin and raw-material sources.
Contractors would also be required to establish written procedures for proactively vetting suppliers and subcontractors. At a minimum, the reviews must consider financial stability, foreign ownership or influence, and manufacturing and supply risks. Contractors would be expected to identify concerns such as sole-source dependencies, inadequate production capacity, supplier concentration and overreliance on a single source. Foreign ownership, control or influence is defined partly in terms of whether a foreign interest could obtain unauthorized access to information or adversely affect the performance of a national security contract.
For cybersecurity teams, that could expand traditional third-party security assessments to include beneficial ownership, foreign investment, development locations, administrative access, data-hosting arrangements and changes in corporate control. The order also directs the government to prohibit contractors from using covered materials supplied by an unreliable foreign supplier, subject to certain exceptions.
Contractors would have to mitigate identified risks and track corrective actions until closure. Significant supply chain risks would need to be reported to the Department of War within 15 days after the vetting activities are completed. Contractors would then have 45 days to submit a confidential corrective action plan detailing their mitigations and a timeline for completing the work. A closeout report would also be required after corrective actions have been implemented.
The order does not define what constitutes a “significant” supply chain risk or whether the provision will cover specific software vulnerabilities, compromises or other cybersecurity findings. Those details will likely be addressed through the forthcoming regulations. The 15-day provision should not be interpreted as a general cybersecurity incident reporting deadline. It applies to risks identified through the supplier-vetting process contemplated by the order.
Beyond the mapping and vetting provisions, the order tightens the sourcing rules that govern which materials contractors may use in the first place. Starting January 1, 2027, the Secretary of War and the service secretaries would generally stop issuing waivers under 10 U.S.C. § 4872 that allow the acquisition of covered materials from prohibited sources. A waiver could still be granted, but only where the prime contractor or subcontractor submits a formal mitigation plan that identifies the non-compliant source, documents the efforts made to find a compliant alternative, and sets a timeline for removing the material from the supply chain. Contractors found to have committed fraud or knowingly failed to carry out an approved mitigation plan could face contractual penalties and referral to the Attorney General.
A separate provision would require contractors whose supply chains depend on an unreliable foreign supplier to qualify and move to an alternative source as soon as practicable. Failure to do so could become grounds for the government to suspend or terminate task orders, decline to exercise contract options, or terminate the contract outright.
Sensitive Supply Chain Data Could Become a Target: The comprehensive supply chain maps required by the order could themselves create significant cybersecurity risks. A detailed database connecting defense systems to software dependencies, suppliers, raw materials, manufacturing locations and operational bottlenecks would provide a potentially valuable target for foreign intelligence services and other threat actors. Compromised supply chain data could help an adversary identify single points of failure, difficult-to-replace suppliers, vulnerable software dependencies and opportunities for espionage, sabotage or economic coercion.
Defense contractors may need to apply strict access controls, encryption, audit logging, data loss prevention and compartmentalization to protect this information. The order allows some bill-of-materials information to be disclosed to government support contractors when necessary, provided proprietary information is protected against unauthorized access or use.
Government to Use AI for Supply Chain Analysis: The order directs the Department of War to use available tools and technologies, including artificial intelligence, to analyze contractor acquisition information and identify national security vulnerabilities, bottlenecks and single points of failure. The AI provision could allow the government to analyze extremely large and complex networks of suppliers, components and dependencies. However, it may also raise questions about the accuracy of supplier-risk determinations, the protection of proprietary information and the security of centralized government supply chain databases.
Although the order does not impose conventional cybersecurity requirements such as encryption standards, secure development practices or vulnerability disclosure rules, it could significantly expand the responsibilities of cybersecurity and third-party risk teams in the defense industrial base. The practical effect will depend on which acquisitions are designated as national security-related and how broadly the government applies the forthcoming rules. Defense contractors, meanwhile, may need to begin integrating SBOM management, hardware assurance, supplier provenance, foreign ownership screening and cybersecurity risk management into a single supply chain security program.