The Federal Acquisition Supply Chain Security Act (FASCSA) is a federal law that established a governmentwide framework for identifying and addressing supply chain security risks in federal acquisitions. Enacted as Title II of the SECURE Technology Act of 2018, FASCSA created authorities that can be used to exclude certain sources or covered articles from federal procurement and to require their removal from federal information systems when they present unacceptable supply chain risks.
For federal contractors, FASCSA is important because an applicable order can affect which technologies, suppliers, products, and services may be provided or used in performing a government contract. The implementing FAR rules became effective on December 4, 2023, and FASCSA requirements are now addressed primarily in FAR Subpart 4.23 and related provisions and clauses.
Why FASCSA Was Created
Federal agencies purchase enormous amounts of technology from commercial supply chains. A product delivered to an agency may contain hardware, software, cloud services, telecommunications components, and technologies supplied by multiple companies at different tiers. Security concerns can therefore arise from a source or component even when the government’s direct contractor is not itself considered a security risk.
FASCSA established a coordinated mechanism for dealing with these risks across the federal government. It works alongside other federal supply chain and cybersecurity requirements, but its central function is specific: it provides authority for exclusion and removal orders addressing sources and covered articles that present supply chain security concerns.
The Federal Acquisition Security Council, commonly abbreviated as FASC, plays an important role in this framework. Executive agencies are required to share relevant supply chain risk information with the FASC when they determine that there is a reasonable basis to conclude that a substantial supply chain risk associated with a source or covered article exists. Contracting officers work with program offices or requiring activities according to agency procedures when relevant risks are identified during procurement.
FASCSA authority is not permanent under current law. FAR 4.2300 states that the authority implemented by Subpart 4.23 expires on December 31, 2033.
What Is a Covered Article Under FASCSA?
The scope of FASCSA extends beyond a single category of IT equipment. FAR 4.2301 uses the statutory definition of “covered article,” which includes several types of technology and related products or services. This allows the government to address supply chain risks involving modern IT environments rather than focusing only on physical hardware.
Covered articles include:
- information technology, including cloud computing services of all types;
- telecommunications equipment and telecommunications services;
- information processing systems, including building access control and physical security systems;
- hardware, systems, devices, software, and services that include embedded or incidental information technology.
Another important term is “source.” Under FAR 4.2301, a source is a non-Federal supplier or potential supplier of products or services at any tier. As a result, contractors need to consider more than their own corporate identity when evaluating FASCSA exposure. Suppliers and other sources within the supply chain can also be relevant.
This is one reason supply chain visibility matters. A prime contractor can be responsible for providing a solution containing technologies obtained from other sources. If an applicable FASCSA order covers one of those sources or covered articles, the fact that the prime contractor obtained it indirectly does not necessarily eliminate the issue.
FASCSA Exclusion and Removal Orders
The principal enforcement mechanism under FASCSA is the FASCSA order. Depending on its scope, an order can prevent agencies from acquiring certain covered articles or products and services from specified sources, or require covered articles to be removed from federal information systems.
FASCSA orders can be associated with three issuing authorities:
| Issuing Authority | General Scope |
|---|---|
| Secretary of Homeland Security | Civilian agencies, subject to the scope of the order and other applicable authorities |
| Secretary of Defense | Department of Defense and certain national security systems |
| Director of National Intelligence | Intelligence Community and certain sensitive compartmented information systems |
For a typical civilian agency acquisition, DHS FASCSA orders generally apply unless the program office or requiring activity provides different instructions. DoD contracts generally apply DoD FASCSA orders. The precise applicability of an order can depend on the contracting agency, funding, scope of the order, and the information systems involved.
FAR 4.2303 prohibits executive agencies from procuring or obtaining, or extending or renewing a contract to obtain, a covered article or products or services from a source when an applicable FASCSA order establishes that prohibition. The restriction can also extend to contractor use of affected covered articles or sources during contract performance.
Governmentwide orders can have broader consequences. When a collective Governmentwide FASCSA order applies, agencies responsible for Federal Supply Schedules, Governmentwide acquisition contracts, and multi-agency contracts must facilitate implementation by removing identified covered articles or sources from those contract vehicles.
How FASCSA Requirements Affect Federal Contractors
FASCSA implementation introduced specific FAR provisions and clauses that contractors may encounter in solicitations and contracts. Three of the most important are FAR 52.204-28, 52.204-29, and 52.204-30. Their application varies depending on the type of contract and whether FASCSA orders are applied at the basic contract level or order level.
FAR 52.204-29 addresses representations and disclosures. It states that contractors are prohibited from providing or using during contract performance a covered article, or products or services produced or provided by a source, when an applicable FASCSA order establishes the prohibition.
For contractors, practical compliance can involve several activities:
- Review the solicitation and contract for applicable FASCSA provisions and clauses.
- Determine which DHS, DoD, or DNI orders apply to the acquisition.
- Search SAM for applicable publicly available FASCSA orders.
- Conduct the required reasonable inquiry into products, services, and sources used in contract performance.
- Address required representations and disclosures accurately.
- Respond to contracting officer instructions if an affected article or source must be removed.
SAM is a central source for publicly available FASCSA orders. FAR 4.2303 directs users to search for the phrase “FASCSA order.” However, contractors should not assume that SAM is always the complete source for a particular solicitation. The FAR specifically provides that some orders may not appear in SAM and instead must be identified in the solicitation to apply to that acquisition.
This makes solicitation review essential. A contractor that checks SAM but ignores the specific FASCSA language in an RFQ, solicitation, or contract could overlook an order that applies to the procurement.
FASCSA and GSA Schedule Contractors
FASCSA has specific implications for GSA Schedule contractors because Federal Supply Schedules are expressly addressed in the FAR implementation. FAR 4.2306 requires FAR 52.204-28 in Federal Supply Schedules, Governmentwide acquisition contracts, and multi-agency contracts when FASCSA orders are applied at the order level. FAR 52.204-30 is then used at the order level with Alternate II in applicable RFQs or notices of intent to place an order.
This structure means that a contractor cannot assume that acceptance of a product on a GSA Schedule makes it permissible under every future order. FASCSA restrictions can become relevant at the order level, depending on the applicable order and acquisition.
GSA advises contractors to check SAM for FASCSA exclusion orders and provides guidance for automating these checks through the SAM API. GSA also notes that a FASCSA order can be an exclusion order, a removal order, or both, with the applicable information identified in the order.
For Schedule contractors, a practical compliance process should include:
- monitoring applicable FASCSA orders rather than relying only on an initial contract review;
- checking relevant manufacturers, technology providers, and other sources within the supply chain;
- reviewing each RFQ for order-specific FASCSA requirements;
- maintaining enough supply chain information to perform required inquiries;
- having a process for replacing affected products, services, or sources when required.
FAR 52.204-28 also addresses changes during contract performance. When notified by the contracting officer, a contractor must promptly make necessary changes or modifications to remove a covered article, product, service, or source subject to an applicable Governmentwide FASCSA order.
FASCSA compliance should therefore be viewed as an ongoing supply chain responsibility rather than a one-time certification made when a company obtains a federal contract. Contractors that sell technology through GSA or other governmentwide vehicles need to understand both the sources behind their offerings and the FASCSA requirements that may apply to individual contracts and orders.
FASCSA Compliance in Practice
FASCSA adds another layer to federal supply chain risk management, but it should not be confused with every other procurement restriction affecting technology. The FAR contains separate prohibitions covering areas such as certain telecommunications and video surveillance equipment, Kaspersky Lab products and services, and ByteDance covered applications. FASCSA has its own statutory authority, orders, definitions, and contracting procedures.
For contractors, the most important principle is to know what is actually being supplied and used in contract performance. This can require visibility beyond the immediate product name to the manufacturers, software providers, cloud services, telecommunications components, subcontractors, and other relevant sources involved in delivering the solution.
Compliance also needs to continue after award because the supply chain and applicable restrictions can change. Contractors should monitor applicable orders, maintain supplier information, review new contract and order requirements, and communicate with the contracting officer when questions arise.
FASCSA ultimately gives the federal government a mechanism to act when a source or technology creates an unacceptable supply chain security concern. For GSA contractors, its practical significance is equally clear: an affected product or source can be restricted even when it would otherwise be available through a federal contract vehicle, making supply chain awareness an important part of contract compliance.
