The Challenge
The National Reconnaissance Office (NRO) faces a common issue in defense programs: supply chain risks often remain hidden until they disrupt schedules. Critical threats and single-point-of-failure manufacturers can be buried several tiers down, shielded by privity of contract, which creates a legal barrier between the government and the actual sources of risk.
Darwyn Banks, director for systems engineering at the NRO, addressed this during an Intelligence and National Security Alliance webinar: "We just need to know where they are so that we can manage them appropriately." These risks include small manufacturers whose failure could halt production, foreign vendors with security concerns, and vulnerabilities that only become apparent when a program is already underway.
Privity of contract allows prime contractors to withhold details about proprietary supplier relationships, leaving the NRO without visibility into where critical components originate or which subcontractors pose concentration risks.
The Environment and Constraints
The NRO operates in a space where supply chain transparency clashes with commercial proprietary interests. Primes gain competitive advantage through their supplier networks, which are considered trade secrets involving negotiated pricing and technical partnerships.
However, the NRO can't afford to discover mid-program that a critical component comes from a single, unreliable source or that a foreign vendor with questionable practices is involved in the supply chain.
Banks acknowledged this tension: "Totally understand, those relationships, that's all proprietary. But we on the government side know how to manage proprietary and engage with that."
The agency also faced a knowledge gap. Without dedicated intelligence on the supplier market, program offices couldn't effectively evaluate supply chain risk during source selection. They needed both the authority to ask tougher questions and the capability to interpret the answers.
The Approach Taken
The NRO adopted a two-part strategy: formal acquisition requirements and enhanced internal analytical capability.
First, the agency added an acquisition clause to its supplement to the Federal Acquisition Regulation, addressing supply chain transparency expectations. This clause, in place for three years, is applied to new contracts, giving the NRO the contractual right to require otherwise proprietary information.
Second, the NRO invested in business intelligence contracts to independently map the supplier market. Banks described building "supply chain illumination and supply chain due diligence capabilities" that program offices can access during procurement. This allows them to identify concerns with specific subcontractors, vendors, or suppliers before awarding contracts.
While this approach doesn't eliminate privity of contract, it creates a framework for structured conversation. Banks emphasized the need for primes and second-tier subs "to do a better job of knowing who their vendors and suppliers are," adding, "Realistically, we're not asking for anything that industry doesn't already do."
The goal isn't to eliminate risk but to gain early warning and shared awareness, so when problems arise, the government and contractor can resolve them more quickly.
Results and Self-Assessment
Banks rated the NRO's supply chain efforts as a B or B-. This self-assessment indicates progress but also room for improvement.
The acquisition clause is now a standard part of the contracting process, creating a consistent mechanism rather than ad-hoc requests. Program offices have access to market intelligence they lacked three years ago. Banks noted that industry partners manage their supply chains thoroughly, suggesting the gap is more about communication than capability.
The NRO's efforts are also informing broader federal initiatives. The White House is reviewing how agencies report on cyber supply chain security risks, and the NRO's experience with structured transparency requirements could serve as a model.
What They Would Do Differently
Banks didn't specify regrets, but his focus on engagement suggests a key lesson: start the conversation earlier and make it routine rather than reactive.
The phrase "when these problems pop up, not if, when they pop up" indicates the NRO now treats supply chain disruption as a planning assumption. This mindset shift likely came from experience, and it's a lesson learned through practice.
If starting fresh, the NRO would likely integrate the acquisition clause and business intelligence capability from the beginning rather than incrementally. The three-year rollout means some contracts still operate under old rules, leading to inconsistent visibility.
Takeaways for Your Team
Build the contractual authority first. You can't compel transparency through goodwill. The NRO added specific language to its FAR supplement, giving program managers the standing to require information about lower-tier suppliers. Review your flow-down requirements in DFARS 252.204-7012 contracts and consider whether your subcontractor management plan requirements actually give you visibility or just paperwork.
Invest in independent market intelligence. The NRO didn't rely solely on what primes volunteered. They contracted for business intelligence to understand the supplier landscape independently. Your team needs similar capability, whether through commercial risk intelligence platforms, industry association data, or dedicated supply chain analysts who can interpret what a subcontractor management plan actually tells you about concentration risk.
Treat privity of contract as a negotiation, not a wall. Banks emphasized that government knows how to manage proprietary information. If your primes cite proprietary concerns to avoid supply chain discussions, you're not asking the right questions or offering the right protections. Non-disclosure agreements, limited distribution, and government-purpose rights exist specifically to enable these conversations.
Make supply chain visibility a source selection factor. If you only ask about lower-tier suppliers after contract award, you've lost your leverage. The NRO's program offices now use their market intelligence during procurement to evaluate subcontractor management plans as part of source selection. That's when contractors are most motivated to demonstrate their supply chain maturity.
Accept that you're managing risk, not eliminating it. Banks's statement that "we're not going to get these risks out of the food chain" should inform your expectations. The goal is early detection and faster response when a supplier fails, gets acquired, or turns out to have security issues. Perfect visibility is impossible; actionable visibility is the standard.
The NRO's B-minus grade should resonate with anyone managing defense supply chains. You're not aiming for perfection. You're aiming for enough transparency that you're not blindsided when a tier-three vendor becomes your program's critical path.



