FASCSA Order

Generate AI summary:

A FASCSA Order is an official exclusion or removal order issued under the Federal Acquisition Supply Chain Security Act to address supply chain security risks involving certain sources or covered articles used by the federal government. Depending on its scope, an order can prohibit agencies from acquiring specified products or services, restrict the use of products or services from a particular source, or require affected covered articles to be removed from federal information systems.

FASCSA Orders are part of the governmentwide supply chain security framework implemented in FAR Subpart 4.23. The relevant FAR requirements became effective on December 4, 2023. For federal contractors, including GSA Schedule holders, these orders are important because they can affect products, technologies, suppliers, and services that may otherwise be commercially available or offered through an established government contract vehicle.

What Is a FASCSA Order and What Can It Cover?

FASCSA provides the federal government with a formal mechanism for responding to supply chain security risks. When the required process results in an exclusion or removal determination, the government can issue a FASCSA Order identifying the affected source or covered article and defining the scope of the restriction.

Under FAR 4.2301, a “covered article” is broader than a conventional piece of IT hardware. The definition includes information technology, telecommunications equipment and services, information processing systems, and certain hardware, systems, devices, software, and services containing embedded or incidental IT.

A FASCSA Order can therefore potentially involve:

  • information technology products;
  • cloud computing services;
  • telecommunications equipment or services;
  • software and software-based services;
  • hardware and IT devices;
  • building access control systems;
  • physical security systems involving information processing;
  • products or services incorporating embedded or incidental IT.

The term “source” is also important. FAR defines it as a non-Federal supplier or potential supplier of products or services at any tier. This means the relevant source does not necessarily have to be the prime contractor dealing directly with the government. A manufacturer, technology provider, supplier, or another entity deeper in the supply chain can potentially fall within the scope of an order.

This distinction makes FASCSA compliance a supply chain issue rather than simply a vendor eligibility check. A contractor may itself be eligible to conduct federal business while using a technology, product, service, or supplier affected by a FASCSA Order.

Exclusion Orders and Removal Orders

FASCSA Orders can serve different purposes. The two central concepts are exclusion and removal. An exclusion order generally prevents the federal government from obtaining certain covered articles or products and services from a specified source. A removal order addresses covered articles already present in federal information systems.

The difference is important because one restriction primarily affects future acquisition activity, while another can require action concerning technology already being used.

Type of FASCSA OrderPrimary EffectPractical Contractor Impact
Exclusion OrderRestricts acquisition of specified covered articles or products and services from identified sourcesContractor may be unable to offer or use an affected source or article
Removal OrderRequires specified covered articles to be removed from federal information systemsExisting technology may need to be removed or replaced
Combined OrderIncludes both exclusion and removal requirementsCan affect both future acquisitions and existing systems

GSA explains that a FASCSA Order can be an exclusion order, a removal order, or both. Contractors should therefore read the actual order rather than assuming that every FASCSA action produces the same restrictions.

FAR 4.2303 establishes the basic prohibition. When an applicable FASCSA Order applies, an executive agency may not procure or obtain, or extend or renew a contract to procure or obtain, the covered article or products or services from the source identified by the order. The prohibition also applies to certain uses of affected covered articles or sources in contract performance.

The exact scope matters. Contractors need to determine what source or article is identified, which agencies are affected, when the order becomes effective, and whether additional conditions or limitations apply.

Who Can Issue FASCSA Orders?

FASCSA authority is distributed among designated federal officials rather than assigned to a single agency. FAR Subpart 4.23 identifies orders associated with the Secretary of Homeland Security, the Secretary of Defense, and the Director of National Intelligence.

Their general applicability differs:

Issuing OfficialGeneral Applicability
Secretary of Homeland SecurityCivilian executive agencies, within the applicable scope
Secretary of DefenseDepartment of Defense and applicable national security systems
Director of National IntelligenceIntelligence Community and applicable sensitive compartmented information systems

For civilian agency acquisitions, contracting personnel generally apply relevant DHS FASCSA Orders unless the program office or requiring activity provides different instructions. DoD acquisitions generally apply relevant DoD orders. Specific rules also address acquisitions involving different funding sources and information systems.

The Federal Acquisition Security Council, or FASC, has an important coordinating role in the broader process. FASCSA established the council to support governmentwide efforts to identify and address supply chain risks. The FASC can recommend exclusion or removal actions after evaluating relevant risk information, while the designated officials have statutory authority concerning the issuance of orders.

This framework allows the government to respond to risks that may extend across multiple agencies rather than requiring every contracting office to independently discover and address the same problematic source.

Governmentwide FASCSA Orders can have particularly broad effects. FAR 4.2303 requires agencies responsible for Federal Supply Schedules, Governmentwide acquisition contracts, and multi-agency contracts to facilitate implementation of applicable collective Governmentwide orders by removing covered articles or sources identified in those orders from the relevant contract vehicles.

How Contractors Identify Applicable FASCSA Orders

SAM.gov serves as the primary public location for contractors to identify publicly available FASCSA Orders. FAR 4.2303 specifically directs users searching SAM for these orders to use the phrase “FASCSA order.”

GSA also advises contractors to search SAM for applicable exclusion orders and provides information about using the SAM API to automate checks. Automation can be useful for companies with large catalogs or complex technology supply chains because FASCSA compliance is not necessarily a one-time review performed only when a contract is awarded.

A practical review should include several steps:

  1. Review the solicitation for FAR Subpart 4.23 provisions and clauses.
  2. Identify which FASCSA Orders apply to the agency and acquisition.
  3. Search SAM.gov for publicly available applicable orders.
  4. Review the actual scope of each relevant order.
  5. Compare affected sources and covered articles against products and services involved in contract performance.
  6. Evaluate relevant suppliers and other sources within the supply chain.
  7. Address required representations, disclosures, or contracting officer instructions.

Checking SAM alone is not always sufficient. FAR 4.2303 recognizes that some FASCSA Orders may not be identified in SAM. When such an order applies to a specific acquisition, it must be identified in the solicitation. Contractors should therefore review both public FASCSA information and the actual solicitation or order documentation.

The need to evaluate suppliers is particularly significant for technology contractors. A company selling an integrated solution may rely on third-party software, cloud infrastructure, telecommunications components, hardware manufacturers, and other sources. FASCSA restrictions can reach relevant sources at different tiers.

FASCSA Orders in Federal Contracts and GSA Schedules

FASCSA implementation is reflected in several FAR provisions and clauses, particularly FAR 52.204-28, 52.204-29, and 52.204-30. Contractors working with federal agencies should understand when these requirements appear and what obligations they create.

FAR 52.204-29 addresses representations and disclosures concerning FASCSA Orders. The provision requires offerors to review applicable orders and make the required representations concerning covered articles and sources. It also addresses disclosure when an offeror cannot represent that it will not provide or use affected products, services, or sources.

FAR 52.204-30 addresses prohibitions associated with FASCSA Orders during contract performance. The exact requirements depend on the contract and applicable version of the clause.

GSA Schedule contractors should pay particular attention to order-level applicability. FAR 4.2306 establishes procedures for Federal Supply Schedules, Governmentwide acquisition contracts, and multi-agency contracts when FASCSA Orders are applied at the order level.

This has an important practical consequence. A product’s presence on a GSA Schedule does not automatically mean it can be supplied under every federal order without additional review. An applicable FASCSA Order may affect the product, service, or source at the order level.

Contractors should therefore avoid relying solely on the compliance review performed when the underlying GSA Schedule contract was awarded. Each relevant RFQ or order should be checked for FASCSA requirements, especially when the offering contains ICT, telecommunications technology, cloud services, software, security systems, or products containing embedded IT.

FASCSA restrictions can also arise after contract award. FAR clauses provide mechanisms for addressing affected articles or sources when a new Governmentwide FASCSA Order becomes applicable. Depending on the circumstances and contracting officer instructions, a contractor may need to remove or replace an affected covered article, product, service, or source.

Managing FASCSA Order Compliance

Effective FASCSA compliance requires contractors to understand their supply chains well enough to identify potentially affected sources. For a simple commercial product, that may involve a manufacturer and a small number of suppliers. For an integrated technology solution, the chain can include hardware manufacturers, software developers, cloud providers, telecommunications services, subcontractors, and other technology vendors.

A contractor’s internal process should cover at least:

  • regular monitoring of applicable FASCSA Orders;
  • review of new solicitations and RFQs for order-specific restrictions;
  • identification of manufacturers and relevant technology providers;
  • documentation of reasonable inquiries required by applicable FAR provisions;
  • procedures for escalating possible matches to compliance or contract management personnel;
  • communication with contracting officers when clarification is required;
  • plans for replacing affected products or sources when necessary.

Contractors should also distinguish FASCSA Orders from other federal technology restrictions. The FAR contains separate requirements concerning certain telecommunications and video surveillance equipment, Kaspersky Lab products and services, ByteDance covered applications, and other prohibited technologies. A product affected by one restriction is not automatically a FASCSA-listed product, and each rule has its own legal authority and compliance requirements.

For GSA contractors, the central point is that FASCSA Orders can affect both acquisition and contract performance. Compliance is not limited to checking whether the prime contractor itself appears on a prohibited list. Contractors may need visibility into products, manufacturers, service providers, and other sources throughout the relevant supply chain.

A FASCSA Order should therefore be treated as an active procurement restriction with a defined scope, not simply as a general cybersecurity warning. Understanding what the order covers, who issued it, where it applies, and whether affected sources are present in the proposed solution is essential for accurate representations and compliant federal contract performance.

Contact our GSA Expert
Call 201.567.6646 or provide your details for a free consultation:

    Click to rate
    [Total: 0 Average: 0]

    Get a Consultation

    Fill out the form below and one of our experts will contact you to discuss next steps.






      We'll get back to you within one business day.