# Executive Order: Defense Contractors Ordered to Map Software Suppliers Across Critical Supply Chains ("Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials")

> On July 20-21, 2026, President Trump signed the executive order 'Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials,' directing the Department of War to require defense contractors to submit an indentured Bill of Materials tracing software, components, equipment, and materials to their raw-material origin, and to implement written supplier-vetting procedures covering foreign ownership/control/influence (FOCI), manufacturing risk, and sole-source dependency, with waiver restrictions on critical materials from covered nations taking effect January 1, 2027.

- **Published:** 2026-07-21T00:00:00Z
- **Last reviewed:** 2026-07-21T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1591
- **ID:** TL-2026-1591
- **Severity:** INFORMATIONAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

The executive order broadens defense-industrial-base supply chain oversight beyond the traditional software bill of materials (SBOM) model. Contractors performing national security contracts must produce an 'indentured Bill of Materials' connecting software and firmware dependencies, physical components, manufacturers, subcontractors, maintenance data, countries of origin, and underlying raw-material sources across all tiers of the supply chain -- not just prime contractors, but subcontractors, software developers, cloud providers, and managed service providers several layers removed from the prime. The order defines the covered 'critical supply chain' broadly as 'all tiers of suppliers and subcontractors providing goods, materials, systems, software or services essential to contract delivery, mission assurance, security or resilience.' Contractors must also establish and follow written procedures to proactively vet suppliers and subcontractors against a minimum set of risk factors: financial stability, foreign ownership or influence (FOCI), manufacturing and supply risk, sole-source dependency, production capacity adequacy, and supplier concentration. 'Foreign ownership or influence' is defined in part as whether a foreign interest could obtain unauthorized access to information related to a national security contract or adversely affect contract performance. Identified risks must be reported to the Department of War within 15 days of vetting, with corrective action plans due within 45 days of risk identification. The Secretary of War has 180 days to develop implementing policy, with implementing regulations due 90 days after policy completion. The order separately tightens waiver authority under 10 U.S.C. 4872 governing critical materials and 'processed critical minerals and derivative products' (PCMDPs) sourced from 'covered nations' (unspecified in public text, understood to reference geopolitical adversary nations), directing the Secretary of Defense/War toward new limitations on waiver issuance and requiring defense contractors to begin 'qualifying new domestic sources'; in some cases contractors must submit supply-chain onshoring mitigation plans in lieu of a waiver. These waiver restrictions take effect January 1, 2027. Non-compliance exposes contractors to contractual penalties for fraud or knowing failure to execute approved mitigation plans, suspension or termination of task orders, decline to exercise contract options, outright contract termination, and potential referral to the Attorney General. The order directs the Department of War to apply AI-assisted tools to analyze contractor acquisition information and identify national security vulnerabilities, bottlenecks, and single points of failure across the supply base. The order does not define what constitutes a 'significant' supply chain risk, nor does it clarify whether the provision covers specific software vulnerabilities, compromises, or other cybersecurity findings -- these details are deferred to the forthcoming implementing regulations. The order follows, and is complicated by, the Pentagon's July 13, 2026 suspension of Cybersecurity Maturity Model Certification (CMMC) Phase 2 third-party assessment requirements (originally slated for November 10, 2026), driven by an acute shortage of accredited third-party assessment organizations (C3PAOs) relative to the roughly 100,000 defense-industrial-base companies requiring certification. The suspension was announced under Department of War CIO Kirsten Davies and Undersecretary of War for Acquisition and Sustainment Michael Duffey; a CMMC Reform Task Force is conducting a 60-day review of scaled-back security measures while CMMC Phase 1 self-assessment (effective since November 10, 2025) and DFARS 252.204-7012/7019/7020 obligations remain in force. CMMC Phase 3 (Level 3 third-party certification) remains planned for November 2027 and Phase 4 (full implementation) for 2028, both now clouded by the ongoing reform review. Security researchers and compliance analysts quoted in coverage of the order warn that the comprehensive supply-chain maps it requires could themselves create significant cybersecurity risk by exposing 'single points of failure, difficult-to-replace suppliers, [and] vulnerable software dependencies' if the consolidated iBOM data store is compromised, and recommend contractors apply strict access controls, encryption, audit logging, data loss prevention, and compartmentalization to BOM data stores. The order sits alongside a string of related 2025-2026 defense-acquisition and critical-minerals executive actions: a January 2025 defense acquisition modernization order, a March 2025 mineral production and permitting order, a January 2026 processed critical minerals trade agreement order, and the February 2026 America First Arms Transfer Strategy.

## MITRE ATT&CK

- T1591 Gather Victim Org Information
- T1591.002 Business Relationships
- T1596 Search Open Technical Databases
- T1195 Supply Chain Compromise
- T1195.001 Compromise Software Dependencies and Development Tools
- T1195.002 Compromise Software Supply Chain
- T1195.003 Compromise Hardware Supply Chain
- T1199 Trusted Relationship
- T1518 Software Discovery
- T1552 Unsecured Credentials
- T1213 Data from Information Repositories
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1041 Exfiltration Over C2 Channel
- T1485 Data Destruction

## Sources

- [Trump Orders Defense Contractors to Map Software Suppliers Across Critical Supply Chains](https://www.securityweek.com/trump-orders-defense-contractors-to-map-software-suppliers-across-critical-supply-chains/)
- [Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials](https://www.whitehouse.gov/presidential-actions/2026/07/securing-americas-defense-supply-chains-and-ensuring-domestic-acquisition-of-critical-materials/)
- [Fact Sheet: President Donald J. Trump Secures America's Defense Supply Chains and Ensures Domestic Acquisition of Critical Materials](https://www.whitehouse.gov/fact-sheets/2026/07/fact-sheet-president-donald-j-trump-secures-americas-defense-supply-chains-and-ensures-domestic-acquisition-of-critical-materials/)
- [U.S. executive order restricts critical material waivers from covered nations and mandates supply chain mapping](https://kpmg.com/us/en/taxnewsflash/news/2026/07/us-executive-order-defense-supply-chains.html)
- [Trump executive order hopes to patch vulnerabilities in defense supply chain](https://www.washingtonpost.com/politics/2026/07/20/trump-executive-order-hopes-patch-vulnerabilities-defense-supply-chain/)
- [Trump signs order to make U.S. supply chains more secure, less reliant on foreign nations](https://www.washingtontimes.com/news/2026/jul/20/donald-trump-signs-order-make-us-supply-chains-secure-less-reliant/)
- [Trump Orders Defense Contractors to End Reliance on Suppliers From Adversary Nations](https://www.pymnts.com/supply-chain/2026/trump-orders-defense-contractors-to-end-reliance-on-suppliers-from-adversary-nations)
- [Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules](https://www.securityweek.com/pentagon-suspends-cmmc-phase-2-as-it-rethinks-contractor-cybersecurity-rules/)
- [Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program](https://www.wilmerhale.com/en/insights/client-alerts/20260720-pentagon-suspends-cmmc-phase-2-requirements-and-launches-review-of-cybersecurity-certification-program)
- [Pentagon suspends CMMC phase two requirements, launches review of program](https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/)
- [BREAKING: Pentagon Suspends Phase 2 of CMMC Program](https://www.nationaldefensemagazine.org/articles/2026/7/13/breaking-pentagon-suspends-phase-2-of-cmmc-program)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1591
