Trump Executive Order Mandates Full Mapping of Defense Supply Chains
President Donald Trump has signed a sweeping executive order directing the Department of War to develop new regulations that require defense contractors to map every tier of their software, services, and technology supply chains supporting national security systems. The order frames the mandate as a defense against "physical, cyber, and economic subversion," and explicitly calls for greater visibility into subcontractors several layers removed from the prime contractor. Within 180 days, the Secretary of War must issue policies mandating supply chain mapping, with implementing regulations to follow within 90 days thereafter. The scope of "critical supply chain" is broad enough to potentially capture software developers, managed service providers, and cloud vendors that may never directly contract with the federal government.
A centerpiece of the order is the requirement that contractors submit an "indentured Bill of Materials" tracing components, equipment, software, and raw materials back to their point of origin. This document goes well beyond a traditional Software Bill of Materials (SBOM), weaving software and firmware dependencies together with physical components, manufacturers, maintenance records, and countries of origin. Defense suppliers concerned about exposure of third-party dependencies can use tools like the WHOIS lookup to verify the registration details and ownership of vendor domains, while an SSL/TLS checker can quickly assess whether supplier endpoints meet baseline cryptographic standards. The combined documentation is designed to expose hidden dependencies that adversaries could exploit to compromise mission-critical systems.
Contractors will also be required to implement written procedures for vetting every supplier and subcontractor, evaluating financial stability, manufacturing capacity, and foreign ownership, control, or influence (FOCI). FOCI is defined in part by whether a foreign interest could gain unauthorized access to sensitive information or impair the performance of a national security contract, a definition that effectively forces organizations to scrutinize cross-border data flows and offshore engineering teams. Cybersecurity teams should expect renewed pressure to validate the integrity of upstream software artifacts, review vendor network postures with a port scanner, and document risk decisions in language that satisfies federal acquisition regulators.
The regulation's downstream effects are likely to extend well beyond traditional defense primes. As prime contractors push new mapping and vetting requirements down their subcontractor stacks, commercial software firms, SaaS providers, and MSPs will inherit compliance obligations that mirror frameworks such as NIST SP 800-161 and CMMC. For CISOs, the practical takeaway is clear: the era of treating the software supply chain as a black box is ending, and continuous visibility into every dependency, library, and service provider is becoming a contractual, not just a best-practice, requirement.