Federal Acquisition Security Council
The Federal Acquisition Security Council (FASC) is a U.S. executive branch group made up of representatives from multiple agencies that works to reduce security risks in the technology and products the federal government buys. It was created by Congress in 2018 to establish a coordinated, government-wide process for deciding whether certain products or vendors pose supply chain risks. Its goal is to help protect federal information technology from vulnerabilities and exploitation.
The FASC is an executive branch interagency council, established by Congress in 2018 and chaired by a senior-level official from the Office of Management and Budget, responsible for coordinating a centralized, deliberative process for managing information and communications technology supply chain risk across the federal government. Its statutory responsibilities generally include facilitating information sharing among agencies and determining whether covered articles or sources present supply chain risks that may warrant removal or exclusion orders. Administrative and information-sharing support functions, including support to a supply chain risk management Task Force, are provided by a designated information sharing agency (identified in the evidence as CISA). Note that specific procedural mechanics, the scope of covered articles, and the effect of exclusion or removal orders are governed by the implementing rule and subsequent orders, which readers should verify against the current authoritative text; this entry does not cover contractor compliance obligations triggered by specific FASC orders.
Why it matters
Supply chain compromises in information and communications technology (ICT) can undermine federal systems in ways that traditional perimeter defenses do not address, because the risk is introduced through products, components, or vendors the government has chosen to acquire. Before the FASC, agencies generally lacked a coordinated, government-wide mechanism for deciding whether a particular product or source posed an unacceptable supply chain risk, which could lead to inconsistent decisions across the executive branch. The FASC was created by Congress in 2018 to establish a centralized, deliberative process for making these determinations and for sharing supply chain risk information among agencies.
For compliance officers, contractors, and authorizing officials, the FASC matters because it can serve as the source of exclusion or removal orders that affect which products and vendors may be used across federal agencies. The implementing rule published in 2021 and subsequent orders define how these determinations translate into obligations, so a FASC action is not merely advisory background, it can carry operational consequences for procurement and system authorization decisions. Readers should note that the precise effect of any given order, the scope of covered articles, and the resulting contractor obligations are governed by the implementing rule and the specific order, which must be verified against the current authoritative text.
Because the FASC's authority sits alongside, and does not replace, other risk management frameworks and suspension and debarment mechanisms, practitioners should be careful not to treat a FASC determination as interchangeable with those separate authorities. A product or vendor addressed by the FASC may also be subject to other regulatory or contractual requirements, and compliance with one process does not automatically satisfy another.
Who it's relevant to
Inside FASC
Common questions
Answers to the questions practitioners most commonly ask about FASC.