White House Orders Defense Contractors to Chart Every Software Tool and Supplier in Their Supply Chains

A new executive order requires companies that sell to the US military to map their entire software stack and flag any foreign ownership lurking in their supply chains.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • A new US executive order requires defense contractors to produce full maps of their software dependencies and supplier relationships.
  • The order covers foreign ownership of suppliers, meaning companies must check whether any part of their supply chain is controlled by a foreign government or entity.
  • The directive aims to give the US government end-to-end visibility into the technology underpinning its military contracts.
  • No compliance deadline has been publicly confirmed as of the order's release.

The Trump administration has signed an executive order telling every company that supplies the US military to do something most have never formally done: draw a complete map of their own supply chain, right down to the individual pieces of software their products depend on.

Think of it like a food-traceability rule, but for technology. If a defense contractor builds a radar system, the government now wants to know every software library inside that radar, who wrote it, who owns the company that wrote it, and whether any foreign government has a stake anywhere along the line.

That last point matters enormously. Foreign ownership buried inside a supply chain is one of the quieter ways hostile states can insert themselves into sensitive technology. A subcontractor two levels down might be majority-owned by a holding company registered in a country the US considers a security risk. Under the old system, the prime contractor often had no idea.

Why should ordinary people care about this?

Because the same supply-chain blind spots that threaten military hardware also threaten civilian infrastructure. The 2020 SolarWinds attack, where criminals working for Russian intelligence secretly planted malicious code inside a widely used IT management tool, reached thousands of organisations including US government agencies, precisely because nobody had a clear picture of every software component in use. Visibility is the first line of defence.

The order, first reported by SecurityWeek, calls for what the industry calls a software bill of materials, or SBOM. An SBOM is essentially an ingredients list for a software product: every open-source library, every third-party component, every version number. Security teams use these lists to spot quickly whether a newly discovered flaw, known as a vulnerability, affects anything they run.

For defense contractors, producing that list is a significant piece of work. Large weapons systems can contain millions of lines of code spread across hundreds of components, many sourced from outside the prime contractor's own engineers.

The order also flags cyber-related supplier risks more broadly, meaning companies will need to assess whether their suppliers follow basic security practices, not just whether they are foreign-owned.

For employees at defense contractors, this order likely means new internal audits and a lot of spreadsheet work in the months ahead. For the rest of us, it signals that the US government is finally treating software supply chains the same way it treats physical ones: as something that needs a paper trail.

© 2026 Threat Vectr