A new US executive order could significantly expand the supply-chain responsibilities of technology companies working directly or indirectly on national security contracts. The order calls for end-to-end mapping of critical defense supply chains, including software, services, physical components, suppliers and sources of underlying materials.
Although the final regulations have not yet been written, the direction is clear: defense contractors may need to understand much more than the security posture of their immediate vendors.
A broader view than a traditional SBOM
Software bills of materials generally identify packages, libraries and other components inside an application. The documentation contemplated by the order would be broader, connecting software and firmware dependencies with manufacturers, subcontractors, maintenance relationships, ownership structures, countries of origin and physical materials.
This could bring cloud providers, managed service providers, software developers and specialist technology firms into scope even when they are several contractual layers below a prime contractor. Organizations may also be expected to examine supplier concentration, foreign influence, operational capacity and single-source dependencies.
The order gives defense authorities 180 days to develop the policies, followed by a further period for implementing regulations. Contractors would be expected to vet suppliers, mitigate identified risks and report significant concerns. Important definitions, including what constitutes a significant supply-chain risk, remain to be established.
The resulting database becomes a target
Comprehensive visibility can improve resilience, but it creates its own security problem. A centralized map of defense dependencies could reveal vulnerable software, difficult-to-replace suppliers, production bottlenecks and attractive targets for espionage or sabotage.
What technology suppliers should do now
- Identify customers and contracts connected to the defense industrial base.
- Improve SBOM generation, validation and update procedures.
- Map critical fourth-party and lower-tier dependencies.
- Document foreign ownership, hosting locations and privileged support access.
- Protect supply-chain records with encryption, compartmentalization and detailed audit logging.
- Assign ownership across cybersecurity, procurement, legal and compliance teams.
I believe the difficult part will not be collecting dependency data once. It will be keeping that information accurate as software releases, suppliers and corporate ownership change. Organizations that treat the requirement as a static compliance document may produce an impressive inventory that becomes obsolete almost immediately. Continuous provenance management will be far more valuable than a yearly spreadsheet exercise. ([securityweek.com](https://www.securityweek.com/trump-orders-defense-contractors-to-map-software-suppliers-across-critical-supply-chains/))
