Executive Order Directs Defense Contractors to Map Software and Supplier Dependencies

President Donald Trump has signed an executive order directing the Department of War to establish new requirements for identifying and securing critical defense supply chains. The order emphasizes pro...

President Donald Trump has signed an executive order directing the Department of War to establish new requirements for identifying and securing critical defense supply chains. The order emphasizes protection against physical, cyber and economic disruption and calls for visibility into suppliers and subcontractors across every tier.

The Secretary of War has 180 days to develop policies requiring contractors to map supply chains that support national security acquisitions. Implementing regulations would follow within 90 days of those policies. Although the order is aimed largely at strengthening domestic sourcing of critical materials, its provisions could significantly affect software supply-chain security, third-party risk management and contractor compliance programs.

Broader than a conventional SBOM

Under the contemplated rules, contractors could be required to provide an “indentured Bill of Materials” covering equipment, materials, software and services, while tracing dependencies to suppliers and the origins of raw materials. That framework would extend beyond a conventional software bill of materials by potentially linking software and firmware to physical components, manufacturers, maintenance information, countries of origin and other supply-chain data.

The definition of a critical supply chain includes all supplier and subcontractor tiers involved in delivering goods, systems, software or services essential to a contract’s performance, mission assurance, security or resilience. As a result, software vendors, cloud providers and managed service companies could fall within scope even when they are several steps removed from a prime contractor.

Vetting, reporting and mitigation

Contractors would also need written processes for evaluating suppliers’ financial health, foreign ownership or influence, manufacturing capability and other risks. Reviews could identify single-source dependencies, supplier concentration and inadequate production capacity, while cybersecurity teams may need to assess development locations, administrative access, hosting arrangements and changes in ownership.

  • Significant risks identified through the vetting process would have to be reported within 15 days.
  • A confidential corrective-action plan would be due within 45 days, followed by a closeout report.
  • Contractors could be required to replace unreliable foreign suppliers or face suspension, loss of contract options or termination.

The order does not yet define a significant supply-chain risk or establish a general deadline for reporting cyber incidents. Those issues, along with protections for sensitive supply-chain maps, are expected to be addressed in the forthcoming regulations.