The White House is revamping how agencies report cyber supply chain risks, with new metrics soon prioritizing adversarial threats before they infiltrate government systems. If your team conducts supply chain reviews post-contract award, you're already behind the threat curve.
Federal acquisition teams need a structured, repeatable process for evaluating vendor supply chain risk during the pre-award phase. Here's a script you can adapt to your agency's procurement workflows.
Purpose of the Script
This pre-award supply chain review script helps contracting officers, program managers, and security teams systematically evaluate vendor cybersecurity posture and supply chain integrity before awarding contracts for information systems, cloud services, or technology products. It aligns with NIST SP 800-161 guidance on Cybersecurity Supply Chain Risk Management and supports compliance with the SECURE Technology Act of 2018 framework.
Use this during source selection, especially for acquisitions involving:
- Systems processing Controlled Unclassified Information
- Cloud services requiring FedRAMP authorization
- Hardware or software with potential foreign adversary connections
- High-priority assets identified in your agency's risk register
The script structures vendor interviews, document reviews, and risk scoring so your acquisition team can make defensible exclusion or award decisions before contract execution.
Prerequisites
Before running this review, ensure you have:
Documentation Access
- Vendor's System Security Plan or equivalent security documentation
- Software Bill of Materials for any proposed software components
- List of manufacturing locations, assembly facilities, and development centers
- Subcontractor and component supplier disclosure (at least two tiers deep)
- Previous government contract performance history, if available
Team Alignment
- Contracting Officer's Representative assigned and briefed
- Security team representative familiar with NIST SP 800-161
- Program manager who understands mission criticality
- Access to Federal Acquisition Security Council guidance and any agency-specific exclusion lists
Risk Context
- Asset criticality rating for the system this vendor will support
- Data classification levels the vendor will access or process
- Geographic restrictions or foreign ownership concerns specific to your mission
If you're procuring for intelligence community systems or handling sensitive compartmented information, coordinate with your agency's supply chain risk management office before proceeding.
The Review Script
Phase 1: Vendor Disclosure Review (30 minutes)
Start by reviewing written documentation before any vendor interview. Use this checklist:
Ownership and Control Structure
- Identify ultimate parent company and country of incorporation
- Document any foreign ownership, control, or influence (FOCI) factors
- Note any subsidiaries or affiliates in countries of concern
- Verify if vendor appears on any Federal Acquisition Security Council recommendations
Supply Chain Transparency
- Review Software Bill of Materials for open-source components with known vulnerabilities
- Identify all third-party libraries, frameworks, and dependencies
- Map hardware component sourcing (chips, assemblies, firmware) to countries of origin
- Document subcontractor relationships and their security certifications
Security Posture Baseline
- Confirm FedRAMP authorization level matches your requirement (if cloud service)
- Review most recent Third-Party Assessment Organization report findings
- Check for CMMC certification if DoD contractor (must align with 32 CFR Part 170 requirements)
- Verify FIPS 140-2 validated cryptography for any encryption modules
Phase 2: Vendor Interview (45-60 minutes)
Schedule a structured call with the vendor's security lead and supply chain compliance officer. Use these questions:
Development and Manufacturing Practices "Walk us through your software development life cycle. Where are code repositories hosted, and who has commit access?"
"Describe your hardware assembly process. Which facilities perform final integration, and what security controls govern those facilities?"
"How do you validate the integrity of components from your suppliers? What testing or inspection occurs before integration?"
Adversarial Risk Mitigation "Have you identified any components or subcontractors from countries identified as foreign adversaries in your supply chain? If yes, what compensating controls are in place?"
"Describe your insider threat program. How do you vet developers and engineers with access to source code or sensitive designs?"
"What mechanisms do you use to detect counterfeit components or unauthorized modifications in your supply chain?"
Incident History and Transparency "Have you experienced any supply chain compromises, malicious functionality discoveries, or security incidents in the past 24 months? Describe your response."
"How quickly can you provide detailed supply chain provenance data if we identify a vulnerability or threat intelligence indicator?"
Phase 3: Risk Scoring (20 minutes)
Rate the vendor on these dimensions using a 1-5 scale (1 = high risk, 5 = low risk):
Supply Chain Visibility: Can the vendor trace components to origin and provide evidence?
Adversarial Exposure: Does the vendor's supply chain include entities in countries of concern without adequate controls?
Security Program Maturity: Does the vendor demonstrate continuous monitoring, vulnerability management, and incident response capability?
Transparency and Responsiveness: Did the vendor provide complete, timely answers, or were there evasions or gaps?
Calculate a composite score. Any dimension scoring 1 or 2 requires mitigation planning or may justify exclusion for high-priority acquisitions.
Customizing the Script
For Cloud Service Procurements Add questions about the Shared Responsibility Model and how the vendor monitors for supply chain risks in their infrastructure provider's stack. Request the Customer Responsibility Matrix and verify alignment with your agency's FedRAMP baseline requirements.
For Hardware Acquisitions Expand Phase 1 to include detailed hardware component sourcing maps. Request test reports for firmware integrity validation and anti-tamper mechanisms. If procuring for National Security Systems, verify alignment with Committee on National Security Systems Instruction No. 1253 requirements.
For High-Priority or Classified Systems Coordinate with your Sector Risk Management Agency or the Federal Acquisition Security Council before beginning the review. Add questions about the vendor's facility security clearances under the National Industrial Security Program if handling classified information.
For Rapid or Emergency Procurements Compress Phase 2 to 30 minutes and focus only on adversarial exposure and security program maturity dimensions. Document the abbreviated review in your contract file with justification for the accelerated timeline.
Validation Steps
After completing your review, validate your findings:
Cross-Reference Exclusion Lists: Check the vendor and all disclosed subcontractors against any Federal Acquisition Security Council removal orders or agency-specific exclusion guidance. The first such order was issued against Acronis AG for intelligence community procurements in September 2024.
Document Risk Decisions: Record your risk scoring, any red flags identified, and the rationale for award or exclusion in the contract file. If you're awarding despite identified risks, document required compensating controls or enhanced monitoring provisions.
Establish Ongoing Monitoring Triggers: For awarded contracts, define what supply chain changes require notification (new subcontractors, facility relocations, ownership changes). Include these as contract terms under 48 CFR provisions.
Brief the Contracting Officer: Provide a written summary of supply chain risk findings to support the source selection decision. Highlight any factors that could affect the contractor's ability to safeguard Controlled Unclassified Information or maintain system security.
Coordinate with Security Teams: Share your risk assessment with the team responsible for ongoing authorization and continuous monitoring. Supply chain risks you identify during pre-award should inform the system's Risk Management Framework assessment and ongoing security posture reviews.
The federal government is moving to address supply chain security proactively. Your acquisition decisions today determine whether adversarial risks become embedded in your agency's infrastructure tomorrow. Use this script to make those decisions with rigor before the contract is signed.



