The wider regime · 5.4

Suppliers outside the United States

Suppliers outside the United States. What it costs, who decides, and what usually goes wrong.

For an independent reference point, see Microsoft Zero Trust guidance.

The situation

Defence supply chains are not confined to one country

Manufacturers in allied countries sit inside programmes governed by United States requirements, and suppliers inside the United States buy from abroad. Both directions raise questions the requirement was not written with in mind.

Applicability

Ask the prime rather than assuming

Whether and how the certification requirement applies to a supplier outside the United States, and what an equivalent looks like, is a question with a developing answer and one that depends on the programme and the contract.

The reliable route is to ask the contracting party what they will require of you and by when, in writing. Guessing produces either wasted preparation or a surprise.

Not yet confirmed

This claim is the company's own and has not been confirmed for publication. It is shown as outstanding rather than stated.

How the requirement applies to suppliers outside the United States is a matter of the programme rules and the contract, not of this company's opinion, and is held here as an open question rather than answered.

The practical obstacles

Four that are real regardless of the rules

Assessor availability. Fewer accredited assessors operate outside the United States, and the constraint described in the entry on slippage is sharper.

Data location. Requirements about where covered information may sit interact with local law about where data must sit.

Export control. Cross-border arrangements engage it more readily than domestic ones. The entry that names it applies with force here.

Language and interpretation. The standard is written in one legal and technical idiom, and translating a control into another regulatory culture produces genuine ambiguity rather than laziness.

What travels and what does not

Controls travel; evidence conventions do not

The technical controls are the same everywhere. What differs is what counts as acceptable evidence, what records local employment or privacy law permits you to keep, and how monitoring must be notified.

The entry on what staff are told is the clearest example: the same deployment requires different steps in different countries, and the strictest applies to that part of your workforce.

Working with a US prime

Three things to establish early

What standard they will hold you to and on what timescale. Whether they will accept evidence in the form you can produce. And who at their end owns the answer, because supply chain security questions are frequently routed between procurement and security with neither answering.

Working with a non-US supplier

The same six questions

From the entry on your own suppliers, plus one: where are the people who administer your systems and hold your data. That question matters for export purposes and it is the one least often asked.

Not advice

Jurisdiction makes this harder, not easier

Everything in this entry sits at the intersection of at least two legal systems and an export regime. It describes considerations and states no position on any of them. Take advice in each jurisdiction you operate in.

Also

Elsewhere in the wider regime