Original Component Manufacturer

Hardware components that cannot be sourced directly from the original component manufacturer (OCM) or an authorized franchised distributor, and software that cannot be obtained from the original publisher, developer, or an authorized distribution channel, represent elevated supply-chain risk and must not be procured or incorporated into the mission system without documented approval from the program’s supply-chain governance authority. Sourcing hardware from the OCM or authorized franchised distributors provides greater assurance of component authenticity, traceability, and conformance to specification. Obtaining software from the original publisher, developer, or an authorized distribution channel similarly reduces the risk of unauthorized, altered, fraudulent, or malicious software. Deviations from these approved sourcing channels introduce additional supply-chain risk that must be assessed before acceptance. The approval process for non-OCM-sourced items must evaluate the specific risk posed by the alternative source, the criticality of the component or software to mission function, the availability and adequacy of compensating inspection and authentication measures, and whether a compliant source can be identified before accepting the deviation. This governance requirement applies to hardware components, firmware, and software, although the applicable sourcing and authentication methods differ. Hardware controls should address component authenticity and traceability, while software controls should address publisher or developer provenance, distribution-channel integrity, license legitimacy, and cryptographic verification where available.

ID: CM0026
Tier: II
Ground CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should establish OCM or authorized franchised distributor sourcing for hardware, and original publisher, developer, or authorized distribution channels for software as the mandatory default for all components and software, with explicit prohibition on procurement from non-authorized sources without documented approval from a designated supply chain governance authority. Contract language should define the composition, authority, and approval process of the supply chain board or equivalent body responsible for reviewing and approving sourcing deviations, and should require that all deviation approvals be documented with supporting risk assessments and retained as controlled program records. Requirements should flow down to all subcontractors and lower-tier suppliers, requiring them to apply the same sourcing discipline and to seek approval through the prime contractor's governance process for any component or software they cannot source from OCM or authorized channels. Evaluation criteria should assess offerors' existing supplier qualification and sourcing governance processes, their approach to managing component obsolescence that forces consideration of alternative sources, and their demonstrated experience operating supply chain governance boards for space or similarly critical programs. Verification should include review of procurement records and deviation approvals at integration milestones to confirm that sourcing compliance is being maintained and that approved deviations are accompanied by adequate compensating controls.

Pre-Operations Developer/Supplier

Sourcing policy should establish OCM and authorized distributor channels as the exclusive default procurement pathway, with all other sources classified as requiring supply chain governance approval before purchase orders are issued. The supply chain board or equivalent governance body should be established early in the program with defined membership, quorum requirements, approval criteria, and documentation standards, so that the process is operational before procurement activities begin and does not become an ad hoc decision made under schedule pressure. When OCM or authorized distributor sourcing is unavailable due to component obsolescence, long lead times, or market conditions, the governance process should evaluate alternative sources against a structured set of criteria including the source's reputation and traceability, available authentication and inspection options, the criticality of the component, and whether redesign to use an available compliant component is preferable to accepting a sourcing deviation. For software procured outside official vendor channels, the governance review should assess the integrity of the software distribution pathway, the availability of cryptographic verification of the software package, and the provenance of the license under which the software is being acquired. All deviation approvals, supporting risk assessments, and compensating inspection results should be retained as controlled program records linked to the specific components or software lots to which they apply.