DoD and GSA Take Aim at Supply Chain Risks
Client Alert | 1 min read | 01.15.21
The Department of Defense (DoD) recently implemented additional procedures for the mitigation of cybersecurity risks in its supply chain. Designed to identify and mitigate cybersecurity and related supply chain risks throughout a program’s lifecycle, DoD Instruction 5000.90, Cybersecurity Acquisition Decision Authorities and Program Managers, requires program managers to:
- Assess contractors’ cybersecurity posture, including, where applicable, verifying compliance with the DoD’s newly introduced Cybersecurity Maturity Model Certification (CMMC);
- Consider the extent to which contractors have experienced “significant” incidents resulting in network breaches or data loss;
- Avoid program requirements that may necessitate the use of contractors or suppliers that are owned or controlled by a foreign adversary government or are subject to the jurisdiction of a foreign adversary government;
- Manage any supply chain risks associated with foreign ownership, control, or influence (FOCI); and
- Mitigate supply chain risks using a framework that prescribes escalating risk management actions across four risk tolerance levels.
Alongside the DoD, the General Services Administration (GSA) recently introduced, as part of a draft solicitation for the Polaris small business government-wide IT contract, its own Vendor Risk Assessment Program (VRAP). According to the draft solicitation, the VRAP is designed to identify, assess, and monitor supply chain risks associated with FOCI, cybersecurity, and other factors, such as financial performance.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 07.20.26
On July 6, 2026, the U.S. Department of Justice (DOJ) and the U.S. Department of Homeland Security (DHS) published an Interim Final Rule (IFR) setting up a new federal framework that allows state, local, Tribal, and territorial (SLTT) law enforcement and correctional agencies to detect, track, and, in some cases, disable or seize drones. The rule directly affects SLTT agencies looking to stand up counter-drone programs, as well as drone and counter-drone technology companies whose products will be subject to federal review and approval. Although the IFR bypassed the Administrative Procedure Act’s standard notice-and-comment process on good cause grounds — citing the statutory 180-day deadline and urgent public safety needs — the rule is already legally binding and effective as of July 1, 2026. The Departments are nonetheless accepting post-promulgation comments through September 4, 2026.
Client Alert | 3 min read | 07.20.26
QFMA Introduces International Licensing Regime for Financial Services Firms
Client Alert | 3 min read | 07.17.26
Client Alert | 2 min read | 07.15.26
CMMC Phase II Suspension Requires Reconsideration of Such Requirements in Solicitations

