(301) 788-8198info@williamsonlawgroup.comBethesda, Maryland
Cybersecurity ·

New Cybersecurity Contract and Supply Chain Requirements

The Federal Acquisition Security Council (“FASC”) has issued three new FAR clauses intended to prevent U.S. adversaries from exploiting vulnerabilities in information and communications technology and services. The new FAR clauses build on earlier bans on Chinese and Russian products and proposed FAR rules that significantly tighten cybersecurity incident reporting requirements. The three new clauses go into effect on December 4, 2023, and must be incorporated into all solicitations and contracts (including modifications), of any value, issued after that date. The rules allow the FASC to issue both “exclusion” and “removal” orders (together, “FASCSA orders”) for “covered” products or services identified in a FASCSA order.

Removal requirement: FAR 52.204-28

Contractors are required to comply with any FASCSA orders published in SAM.gov, or that are included in the RFP. Subsequently issued FASCSA orders will be included in contracts with a contract modification. During the performance of the contract, upon notification from the contracting officer, the contractor must promptly make any changes or modifications required to remove any covered articles, products or services subject to a FASCSA order.

Representation and disclosure: FAR 52.204-29

Offerors are required to represent they will not provide or use as part of performance any specified covered article, or any products or services from a source subject to a FASCSA order. Submitting the offer is a representation that the contractor has conducted a “reasonable inquiry” that no covered articles, products or services were provided or used in the contract. If any covered product or service is used, the contractor may disclose the items and seek a waiver.

Prohibition: FAR 52.204-30

Contractors may not provide or use as a part of the performance of the contract any covered article, products or services prohibited by a FASCSA order. This clause is a mandatory flowdown to all subcontracts. In addition, the contractor must review SAM.gov to identify any other FASCSA orders that may be effective and apply to the contract. The contractor must review SAM.gov at least once every three months to check for covered articles subject to a FASCSA order, or for products or services that are not currently included in the contract. If the contractor discovers new covered products or services, the contractor must conduct a reasonable inquiry to determine whether a covered item or service was provided or used during contract performance. If a covered article, product or service subject to a new FASCSA order was provided or used, the contractor must report it to the contracting officer within three business days with required information on the product or service. If it is a DoD agency, the contractor must also report it to the Defense Industrial Base Cybersecurity Portal. The contractor must update the report within 10 business days to include the additional mitigation efforts. Subcontractors must make the same reports to the prime contractor.

Together, the new supply chain cybersecurity requirements will require contractors to develop additional procedures to ensure they identify, and comply with, all FASCSA order restrictions and the new requirements are incorporated in contracts and subcontracts.

Additional information

If you have questions regarding the new supply chain rules or other federal government contract issues, contact the professionals at Williamson Law Group at (301) 788-8198 for confidential assistance and counsel, or e-mail Scott Williamson at srw@williamsonlawgroup.com.

This Contract Compliance Update is to keep readers current on government contract matters and is not intended to be legal advice. If you have any questions, please contact Williamson Law Group for legal advice regarding your particular case.

Discuss your matter with an attorney

Tell us about your contract, protest or investigation, and an attorney will follow up.

Request a Consultation

(301) 788-8198info@williamsonlawgroup.com6701 Democracy Blvd., Suite 300
Bethesda, MD 20817