Off the (Supply) Chain: Director of National Intelligence Issues First Exclusion and Removal Order Under the Federal Acquisition Supply Chain Security Act
Client Alert | 5 min read | 09.22.25
On September 18, 2025, the Director of National Intelligence (DNI) issued the first order under the authority conferred by the Federal Acquisition Supply Chain Security Act (FASCSA), requiring exclusion and removal of products and services by an identified source.[1]
This first order comes almost two years after the FAR Council issued the FAR clauses that dictate contractor compliance with FASCSA exclusion or removal orders. (Read more about the contractor obligations here.)
FASCSA established the Federal Acquisition Security Council (FASC), which is an inter-agency body created to assess supply-chain risk and make removal and exclusion recommendations to three order-issuing agencies: DNI, with respect to the Intelligence Community (IC) agencies, the Department of Homeland Security (DHS), with respect to civilian agencies, and the Department of Defense (DOD), with respect to defense agencies. This specific order, issued by the DNI, is applicable to the IC agencies[2] and contracts involving sensitive compartmented information (SCI) systems. It has two parts. First, Acronis, its parent Acronis AG, and its affiliate companies (collectively, Acronis), are excluded from IC procurement actions. Second, the order designates as “covered articles” all Acronis products or services and requires contractors to remove all such Acronis “covered articles” from information systems “applicable to” the IC and SCI systems.
To carry out a FASCSA order, impacted contractors must undertake a reasonable inquiry into their supply chains to identify any provision or use of the “covered articles” in the performance of an applicable contract, pursuant to FAR 52.204-30. If a contractor identifies covered articles, then FAR 52.204-30 requires the contractor to notify the contracting officer within three business days and update that report with mitigation actions within ten business days.
With the FASCSA gates now open, contractors should continue to monitor both for additional FASCSA orders and impacts to their supply chains.
[1] FASCSA orders can be located by navigating to SAM.gov at https://sam.gov/supplychainorders and downloading the FASCA supply chain orders list. This excerpt is the FASCSA supply chain order list as of September 19, 2025.
[2] On September 18, 2025, the GSA blog also stated all MSA contracts were being revised to remove Acronis products. Details of this effort have not yet been provided. Crowell will continue to monitor these changes.
Contacts
Insights
Client Alert | 3 min read | 02.27.26
On February 17, 2026, the U.S. Equal Employment Opportunity Commission (EEOC) filed a complaint against Coca-Cola Beverages Northeast, Inc., in the United States District Court for the District of New Hampshire, alleging that the company violated Title VII of the Civil Rights Act of 1964 (Title VII) by conducting an event limited to female employees. The EEOC’s lawsuit is one of several recent actions from the EEOC in furtherance of its efforts to end what it refers to as “unlawful DEI-motivated race and sex discrimination.” See EEOC and Justice Department Warn Against Unlawful DEI-Related Discrimination | U.S. Equal Employment Opportunity Commission.
Client Alert | 6 min read | 02.27.26
Client Alert | 4 min read | 02.27.26
New Jersey Expands FLA Protections Effective July 2026: What Employers Need to Know
Client Alert | 3 min read | 02.26.26




