Federal · Title 10 — Armed Forces

10 U.S.C. § 4819: Modernization of acquisition processes to ensure integrity of industrial base

Read the full statutory text
The Secretary of Defense shall streamline and digitize the Department of Defense approach for identifying and mitigating risks to the defense industrial base. The objective of subsection (a) shall be to employ digital tools, technologies, and approaches to ensure the accessibility of relevant defense industrial base data to key decision-makers in the Department. The Under Secretary of Defense for Acquisition and Sustainment, in coordination with the Director of the Defense Counterintelligence and Security Agency and the heads of other elements of the Department of Defense as appropriate, shall develop an analytical framework for risk mitigation across the acquisition process in implementing subsections (a) and (b). material sources and fragility, including the extent to which sources, items, materials, and articles are mined, produced, or manufactured within or outside the United States; telecommunications services or equipment; counterfeit parts; cybersecurity of contractors; video surveillance services or equipment; vendor vetting in contingency or operational environments; other electronic or information technology products and services; and other risk areas as determined appropriate by the Secretary of Defense. fraud; ownership structures; trafficking in persons; workers’ health and safety; affiliation with the enemy; foreign influence; and other risk areas as deemed appropriate by the Secretary of Defense. market research; responsibility determinations, including consideration of the need for special standards of responsibility to address the risks described in subparagraphs (A) and (B); facilities clearances; the development of contract requirements; the technical evaluation of offers and contract awards; contractor mobilization, including hiring, training, and establishing facilities; contract administration, contract management, and oversight; contract audit for closeout; suspension and debarment activities and administrative appeals activities; contractor business system reviews; processes and procedures related to supply chain risk management and processes and procedures implemented pursuant to section 3252 of this title ; and other relevant processes and procedures. balance sheets, revenues, profitability, and debt; investment, innovation, and technological and manufacturing sophistication; finances, access to capital markets, and cost of raising capital within those markets; corporate governance, leadership, and culture of performance; and history of performance on past Department of Defense and government contracts. limitations and acquisition guidance relevant to the national technology and industrial base; limitations and acquisition guidance relevant to section 4862 of this title ; the Industrial Base Analysis and Sustainment program of the Department, including direct support and common design activities; the Small Business Innovation Research Program (as defined in section 9(e) of the Small Business Act ( 15 U.S.C. 638(e) ); the Manufacturing Technology Program established under sections 4841 and 4842 of this title; programs relating to the Defense Production Act of 1950 ( 50 U.S.C. 4511 1 et seq.); and 1 See References in Text note below. programs operating in each military department. the Under Secretary of Defense for Acquisition and Sustainment, including the Office of Defense Pricing and Contracting and the Office of Industrial Policy; service acquisition executives; program offices and procuring contracting officers; administrative contracting officers within the Defense Contract Management Agency and the Supervisor of Shipbuilding; the Defense Counterintelligence and Security Agency; the Defense Contract Audit Agency; each element of the Department of Defense which own or operate systems containing data relevant to contractors of the Department; the Under Secretary of Defense for Research and Engineering; the suspension and debarment official of the Department; the Chief Information Officer; and other relevant organizations and individuals as deemed appropriate by the Secretary. The Under Secretary of Defense for Acquisition and Sustainment, in consultation with the Chief Data Officer of the Department of Defense and the Director of the Defense Counterintelligence and Security Agency, shall assess the extent to which existing systems of record relevant to risk assessments and contracting are producing, exposing, and maintaining valid and reliable data for the purposes of the Department’s continuous assessment and mitigation of risks in the defense industrial base. Identification of the necessary source data, to include data from contractors, intelligence and security activities, program offices, and commercial research entities. A description of modern data infrastructure, tools, and applications and an assessment of the extent to which new capabilities would improve the effectiveness and efficiency of mitigating the risks described in subsection (c)(2). The Federal Awardee Performance and Integrity Information System (FAPIIS). The System for Award Management (SAM). The Federal Procurement Data System–Next Generation (FPDS–NG). The Electronic Data Management Information System. Other systems the Secretary of Defense determines appropriate. An assessment of systems owned or operated by the Department of Defense, including the Defense Counterintelligence and Security Agency and other defense agencies and field activities used to capture and analyze the status and performance (including past performance) of vendors and contractors. the ability to continuously collect data on, assess, and mitigate risks; data analytics and business intelligence tools and methods; and continuous development and continuous delivery of secure software to implement the activities. In connection with the assessments described in this section, the Secretary shall develop capabilities to map supply chains and to assess risks to the supply chain for major end items by business sector, vendor, program, part, and other metrics as determined by the Secretary. Nothing in this section shall be construed to limit or modify any other procurement policy, procedure, requirement, or restriction provided by law. harmonize the cybersecurity requirements applicable to the defense industrial base across the Department of Defense; reduce the number of such requirements that are unique to a specific contract or other agreement of the Department; and submit to the congressional defense committees [Committees on Armed Services and Appropriations of the Senate and the House of Representatives] a report on the actions taken to carry out the harmonization described in paragraph (1) and the reduction described in paragraph (2). a process and governance structure for assessing whether future proposed cybersecurity contractual requirements for contracts or other agreements of the Department of Defense are duplicative of other applicable requirements of the Department of Defense that are published in the Federal Register; a process for coordinating, centralizing, approving, and publishing any proposed cybersecurity requirement not published in the Federal Register; and a mechanism included in the process described in paragraph (2) for ensuring the visibility to and input from internal and external stakeholders.” a timeline for issuance of regulations, development of training for appropriate officials, and development of systems for reporting of beneficial ownership and FOCI by covered contractors or subcontractors; the designation of officials and organizations responsible for such implementation; and interim milestones to be met in implementing the plan and schedule. Not later than July 1, 2021 , the Secretary of Defense shall revise relevant directives, guidance, training, and policies, including revising the Department of Defense Supplement to the Federal Acquisition Regulation, to fully implement the requirements of such section 847. In this subsection, the term ‘beneficial ownership’, ‘FOCI’, and ‘covered contractors or subcontractors’ have the meanings given, respectively, in section 847 of the National Defense Authorization Act for Fiscal Year 2020 ( Public Law 116–92 ; 133 Stat. 1505 ; 10 U.S.C. 2509 note [now 10 U.S.C. 4819 note]).” The terms ‘beneficial owner’ and ‘beneficial ownership’ shall be determined in a manner that is not less stringent than the manner set forth in section 240.13d–3 of title 17, Code of Federal Regulations (as in effect on the date of the enactment of this Act [ Dec. 20, 2019 ]). The term ‘company’ means any corporation, company, limited liability company, limited partnership, business trust, business association, or other similar entity. The term ‘covered contractor or subcontractor’ means a company that is an existing or prospective contractor or subcontractor of the Department of Defense on a contract or subcontract with a value in excess of $5,000,000, except as provided in subsection (c). The terms ‘foreign ownership, control, or influence’ and ‘FOCI’ have the meanings given those terms in the National Industrial Security Program Operating Manual (DOD 5220.22–M), or a successor document. In developing and implementing the analytical framework for mitigating risk relating to ownership structures, as required by section 2509 of title 10 , United States Code [now 10 U.S.C. 4819 ], as added by section 845 of this Act, the Secretary of Defense shall improve the process and procedures for the assessment and mitigation of risks related to foreign ownership, control, or influence (FOCI) of covered contractors or subcontractors doing business with the Department of Defense. A requirement for covered contractors or subcontractors to disclose to the Defense Counterintelligence and Security Agency, or its successor organization, their beneficial ownership and whether they are under FOCI. A requirement to update such disclosures when changes occur to information previously provided, consistent with or similar to the procedures for updating FOCI information under the National Industrial Security Program Operating Manual (DOD 5220.22–M), or a successor document. A requirement for covered contractors or subcontractors determined to be under FOCI to disclose contact information for each of its foreign owners that is a beneficial owner. A requirement that, at a minimum, the disclosures required by this paragraph be provided at the time the contract or subcontract is awarded, amended, or renewed, but in no case later than one year after the Secretary prescribes regulations to carry out this subsection. A requirement for the Secretary to require reports and conduct examinations on a periodic basis of covered contractors or subcontractors in order to assess compliance with the requirements of this section. whether to establish a special standard of responsibility relating to FOCI risks for covered contractors or subcontractors, and the extent to which the policies and procedures consistent with or similar to those relating to FOCI under the National Industrial Security Program shall be applied to covered contractors or subcontractors; procedures for contracting officers making responsibility determinations regarding whether covered contractors or subcontractors may be under foreign ownership, control, or influence and for determining whether there is reason to believe that such foreign ownership, control, or influence would pose a risk or potential risk to national security or potential compromise because of sensitive data, systems, or processes, such as personally identifiable information, cybersecurity, or national security systems involved with the contract or subcontract; and modification of policies, directives, and practices to provide that an assessment that a covered contractor or subcontractor is under FOCI may be a sufficient basis for a contracting officer to determine that such a covered contractor or subcontractor is not responsible. Requirements for contract clauses providing for and enforcing disclosures related to changes in FOCI or beneficial ownership during performance of the contract or subcontract, consistent with subparagraph (A), and necessitating the effective mitigation of risks related to FOCI throughout the duration of the contract or subcontract. Pursuant to section 2509(c) of title 10 , United States Code [now 10 U.S.C. 4819(c) ], designation of the appropriate Department of Defense official responsible to approve and to take actions relating to award, modification, termination of a contract, or direction to modify or terminate a subcontract due to an assessment by the Defense Counterintelligence and Security Agency, or its successor organization, that a covered contractor or subcontractor under FOCI poses a risk to national security or potential risk of compromise. A requirement for the provision of additional information regarding beneficial ownership and control of any covered contractor or subcontractor on the contract or subcontract. Procedures for appropriately responding to changes in covered contractor or subcontractor beneficial ownership status based on changes in disclosures of their beneficial ownership and whether they are under FOCI and the reports and examinations required by subparagraph (A)(v). Other measures as necessary to be consistent with other relevant practices, policies, regulations, and actions, including those under the National Industrial Security Program. The requirements under subsections (b)(2)(A) and (b)(2)(C) shall not apply to a contract or subcontract for commercial products or services, unless a designated senior Department of Defense official specifically requires the applicability of subsections (b)(2)(A) and (b)(2)(C) based on a determination by the designated senior official that the contract or subcontract involves a risk or potential risk to national security or potential compromise because of sensitive data, systems, or processes, such as personally identifiable information, cybersecurity, or national security systems. The Secretary of Defense shall ensure that the requirements of this section are applied to research and development and procurement activities, including for the delivery of services, established through any means including those under section 2358(b) of title 10 , United States Code [now 10 U.S.C. 4001(b) ]. The Secretary shall ensure that sufficient resources, including subject matter expertise, are allocated to execute the functions necessary to carry out this section, including the assessment, mitigation, contract administration, and oversight functions. Nothing in this section shall be construed to limit or modify any other procurement policy, procedure, requirement, or restriction provided by law, including section 721 of the Defense Production Act of 1950 ( 50 U.S.C. 4565 ), as amended by the Foreign Interference Risk Review Modernization Act of 2018 (subtitle A of title XVII of Public Law 115–232 ). Not later than 180 days after the date of the enactment of this Act, the Secretary of Defense shall establish a process to update systems of record to improve the assessment and mitigation of risks associated with FOCI through the inclusion and updating of all appropriate associated uniquely identifying information about the contracts and contractors and subcontracts and subcontractors in the Federal Awardee Performance and Integrity Information System (FAPIIS), administered by the General Services Administration, and the Commercial and Government Entity (CAGE) database, administered by the Defense Logistics Agency. not made public; made available via the FAPIIS and CAGE databases; and made available to appropriate government departments or agencies.”

Verify at the official source: Federal legislative text

Facing this? Know exactly what happens next.

MOFRD turns this code section into your situation: the deadlines that apply to you, the forms your county uses, and the resolution paths people in your position actually take. Free for 3 days — no card required.

This page is legal information, not legal advice. Code text is sourced from official publications and may lag amendments — always confirm at the official source linked above. Plain-English summaries and relationship data are AI-derived and reviewed on an ongoing basis; verify with a licensed attorney before acting.