Vendor Risk Management
Third-party assessment and supply chain compliance
DFARS 252.204-7020(g)(2) and (g)(3): a prime may not award a subcontract subject to NIST SP 800-171 unless the subcontractor has completed at least a Basic Assessment within the last three years.
Vendor risk management provides comprehensive oversight of third-party security through assessment, monitoring, and remediation workflows. Thalorin streamlines vendor due diligence with automated questionnaires, continuous monitoring, and risk-based vendor tiering.
Section 889(a)(1)(B) of the FY2019 NDAA is the provision that catches people, because it does not care what you sell. Since 13 August 2020 an executive agency may not enter into, extend or renew a contract with an entity that uses covered telecommunications equipment or services as a substantial or essential component of any system — and FAR 52.204-25 puts it without hedging: the prohibition applies regardless of whether that use is in performance of work under a federal contract. Huawei and ZTE are named outright; Hytera, Hikvision and Dahua are covered for public safety and other national security purposes.
Three federal supplier regimes then run in parallel, with different registries and different clocks. FASCSA orders live in SAM.gov, and FAR 52.204-30 requires a contractor to search there for the phrase FASCSA order at least once every three months during performance, report an identified covered article within three business days and supply further mitigation detail within ten. Section 889 reporting runs to one business day. DFARS 252.204-7020 acts earlier: a prime may not award a subcontract subject to NIST SP 800-171 unless the subcontractor holds a Basic DoD Assessment completed within the last three years.
Reach is what gets underestimated. FAR 52.204-30 defines a source as a non-Federal supplier at any tier and flows the clause down into all subcontracts, including those for commercial products and services — so the obligation follows the article rather than the contracting relationship. The same clause defines reasonable inquiry as one that excludes the need for an internal or third-party audit, which sets a floor and leaves the ceiling to judgement. A programme treating tier-one questionnaires as the whole of due diligence is answering a narrower question than the clause asked.
Supplier obligations, in Thalorin, are carried against the award that imposed them. A quarterly FASCSA search, a Section 889 representation and a subcontractor's SPRS assessment date are held as dated obligations on a named contract and a named supplier, each with a next-due date rather than a completion tick. A questionnaire response becomes evidence with an expiry, and a supplier whose assessment has aged past the window under which it was accepted raises against every award that depends on it.
Compliance operations need modern infrastructure
Section 889(a)(1)(B) reaches your own network
The bar is on contracting with an entity that uses covered equipment, whether or not that use touches a federal contract. Corporate IT, facility cameras and an acquired subsidiary's estate are all inside the question.
A standing search obligation in SAM.gov
FAR 52.204-30 requires the contractor to search SAM.gov for FASCSA orders at least once every three months throughout performance. A newly issued order can put an article already delivered into a reporting position.
A pre-award gate you cannot argue with
DFARS 252.204-7020 forbids awarding a subcontract subject to NIST SP 800-171 unless the subcontractor holds a DoD Assessment no more than three years old. Sourcing has to clear SPRS before award, not after.
Vendor support lifecycle goes unscored
CISA BOD 26-02 treats an end-of-support edge device as the exposure itself and publishes an EOS Edge Device List. No standard security questionnaire asks when support ends, which is the date that decides the risk.
How Thalorin helps
Vendor assessment workflows
Scope the assessment first, the way NIST SP 800-161 Rev 1 intends with its Supply Chain Risk Management Assessment Scoping Questionnaire, so criticality sets depth rather than every supplier getting the same questions.
Questionnaire automation
Answer a Shared Assessments SIG or a customer's own question set from held control state, and take an inbound response back as dated evidence attached to the supplier rather than a file in a folder.
Continuous vendor monitoring
Watch the facts that move between assessments: a newly issued FASCSA order in SAM.gov, a product entering end of support, a subcontractor's DoD Assessment ageing past three years.
Risk-based vendor tiering
Tier on what the supplier actually touches — CUI, a delivered covered article, a system component — so the tier decides which clause obligations attach, rather than a label assigned by annual spend.
Contract compliance tracking
Hold flow-down as an obligation on the subcontract itself: FAR 52.204-25 and 52.204-30 flow into all subcontracts including commercial ones, though 52.204-30 keeps the quarterly SAM.gov search with the prime; DFARS 252.204-7020 excludes off-the-shelf items.
Vendor remediation management
Run remediation on the clocks the clauses set — three business days then ten for a FASCSA finding, one business day for covered telecommunications equipment — with the submitted report itself as the closing evidence.
Vendor Risk Management: common questions
Does Section 889 apply to equipment we use internally, or only to what we sell the government?
Both. Section 889(a)(1)(A) prohibits providing the government equipment or services that use covered telecommunications equipment as a substantial or essential component of any system. Section 889(a)(1)(B), effective 13 August 2020, prohibits the government from contracting with an entity that uses such equipment at all, and FAR 52.204-25 says the prohibition applies regardless of whether that use is in performance of work under a federal contract. Your own corporate and facility systems are therefore in scope.
How often do we have to check SAM.gov for FASCSA orders?
At least once every three months during contract performance, or as the contracting officer directs, under FAR 52.204-30(c)(1). If a new order could affect your supply chain you must then conduct a reasonable inquiry, and if a covered article or a prohibited source turns up you report within three business days and supply further mitigation detail within ten. Department of Defense contracts report through dibnet.dod.mil; for other agencies the report goes to the contracting officer.
Can we award a subcontract to a supplier with no SPRS score?
Not where NIST SP 800-171 applies through DFARS 252.204-7012. DFARS 252.204-7020(g)(2) prohibits awarding such a subcontract unless the subcontractor has completed at least a Basic DoD Assessment within the last three years for the relevant covered contractor information systems. A supplier without a current summary level score can perform and submit a Basic Assessment for posting, but the score has to exist before award, which makes it a sourcing lead-time problem rather than a compliance one.
What is a reasonable inquiry, and does it mean auditing our suppliers?
FAR 52.204-25 and FAR 52.204-30 both define it as an inquiry designed to uncover any information in the entity's possession about the identity of a covered article or the producer of one, and both state that it excludes the need to include an internal or third-party audit. That is a floor rather than a safe harbour. An inquiry that found nothing because nobody asked the suppliers who would have known is difficult to defend once a covered article surfaces.
Does a completed SIG satisfy federal supply chain requirements?
No. The Standardized Information Gathering questionnaire is a shared question set that lets a supplier answer once for many customers, and it genuinely reduces duplicated effort across a third-party programme. It is not a regulatory instrument. FASCSA prohibitions, Section 889 representations and DFARS assessment requirements are contract clauses with their own evidence, reporting channels and deadlines, and none of them are discharged by a questionnaire response held on file.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Vendor Risk Management.
See how one evidence artifact satisfies Vendor Risk Management requirements alongside every other framework you carry.