Anti-counterfeit Hardware

Counterfeit electronic components represent a direct supply chain threat to space mission integrity, introducing hardware that may fail prematurely, perform outside specification, or contain malicious functionality deliberately embedded by an adversary during manufacture or distribution. A formal anti-counterfeit program must establish policy and procedures that span the entire component acquisition and integration lifecycle, from supplier qualification and procurement through incoming inspection, storage, and installation. The program must address two distinct but related risks: counterfeit components that fail to perform their intended function, degrading mission reliability; and deliberately tampered components that introduce malicious hardware functionality or create pathways for malicious code execution. Anti-counterfeit controls must include measures appropriate to component criticality and supply chain risk to authenticate components, detect evidence of tampering, and resist unauthorized modification. Detection and prevention must be treated as complementary objectives: prevention through qualified sourcing and procurement controls, detection through inspection and authentication techniques applied before components enter the system.

ID: CM0024
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should mandate a documented anti-counterfeit program as a contract deliverable, specifying the policy, procedures, and technical measures the contractor will implement to prevent counterfeit or tampered components from being incorporated into deliverable systems. Requirements should address both procurement controls, such as sourcing restrictions to authorized distributors and original equipment manufacturers, and physical inspection and authentication requirements applied to incoming components before acceptance into the program's inventory. Contract language should require that anti-counterfeit procedures apply at all tiers of the supply chain, with prime contractors responsible for flowing requirements to subcontractors and component suppliers and for verifying subcontractor compliance. Requirements should address tamper-evidence and tamper-resistance measures for mission-critical components, specifying that hardware destined for critical functions be inspectable for signs of modification and that tamper-evident packaging or sealing be maintained through the supply chain. Evaluation criteria should assess offerors' existing anti-counterfeit programs, their supplier qualification and monitoring processes, and their demonstrated experience detecting and responding to counterfeit component incidents in analogous programs. Verification should include review of incoming inspection records and supplier qualification documentation at relevant integration milestones.

Pre-Operations Developer/Supplier

Anti-counterfeit program design should begin during the component selection and procurement planning phase, before purchase orders are issued, establishing approved sourcing channels and inspection requirements as procurement constraints rather than after-the-fact quality checks. Component sourcing should prioritize original equipment manufacturers and authorized distributors with documented traceability. Procurement from independent or otherwise non-authorized sources should require documented approval, a supply chain risk assessment, and enhanced authentication and inspection before acceptance. Incoming inspection procedures should be defined for each component category, specifying the authentication and verification techniques to be applied, which may include visual inspection, electrical testing, X-ray or computed tomography imaging, chemical analysis, or third-party laboratory testing depending on the component type and criticality. Authentication, tamper-evident, and tamper-resistant measures should be selected based on component criticality, the applicable threats, and the point in the supply chain at which assurance is required. The selected measures should provide evidence of component authenticity or unauthorized modification before integration. All inspection results, chain-of-custody records, and supplier qualification documentation should be retained as controlled program records, providing an auditable trail from component origin to system integration.