Supplier Review

A supplier review is a structured pre-contract assessment conducted before entering into any agreement with a contractor or subcontractor for the acquisition of systems, system components, or system services. The review evaluates the prospective supplier's security posture, trustworthiness, and capability to deliver components or services that meet the mission's integrity and assurance requirements, before contractual commitments are made and before the supplier gains access to mission information or influence over mission systems. Supplier reviews reduce the risk of introducing supply chain vulnerabilities through poorly qualified, compromised, or adversary-influenced suppliers at any tier of the acquisition chain. The rigor and depth of the review should be calibrated to the criticality of the components or services being acquired, with suppliers of mission-critical hardware, software, or services subject to the most intensive assessment. Supplier review findings should inform not only the decision to contract but also the specific security requirements, oversight provisions, and flow-down obligations included in the resulting agreement.

ID: CM0025
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition strategy should establish supplier review as a mandatory gate before contract award for suppliers providing systems, components, or services that affect mission security or operational integrity. The scope and depth of reviews across lower supply-chain tiers should be based on the criticality of the supplied item, the supplier’s access to mission information or systems, and the assessed supply-chain risk. Requirements should define the minimum elements of a supplier review, including assessment of the supplier's ownership structure and potential for foreign influence, security practices and certifications, financial stability, manufacturing or development environment controls, and history of security incidents or compliance failures. Contract language should require prime contractors to conduct and document supplier reviews for all subcontractors and component suppliers, with review results made available to government oversight authorities upon request. The depth of review documentation and the required approval authority should scale with the criticality of the supplied item and the assessed supplier risk. Government review or approval should be required for designated critical suppliers when established by program policy, contract requirements, or defined risk thresholds. Evaluation criteria for prime contractor source selection should include assessment of the offeror's supplier review process, their existing approved supplier list, and their demonstrated ability to identify and manage supply chain risk across complex, multi-tier supplier networks.

Pre-Operations Developer/Supplier

Supplier review processes should be established as a formal program function before procurement activities begin, with defined review criteria, required evidence, approval authority, and documentation requirements that apply consistently across all supplier categories. The review should examine the supplier’s ownership, control, jurisdiction, potential foreign influence, cybersecurity practices, relevant third-party assessments, and security and performance history. Personnel-related review should be limited to individuals whose roles provide access to sensitive mission information, systems, or development and manufacturing processes and should be conducted under applicable security, contractual, and legal requirements. For software or service suppliers, the review should assess the security of the supplier's development environment, their software assurance practices, their incident response history, and their data handling practices for any mission information they will access or process. Review findings should be formally documented and retained as program records, with the approval decision and its rationale recorded so that future procurement decisions involving the same supplier can reference the prior assessment. Supplier reviews should be repeated or updated when a previously approved supplier undergoes significant changes, such as acquisition by a new owner, relocation of manufacturing operations, or a reported security incident, that could affect the basis on which the original approval was granted.