A proposed DFARS rule would make an eligible foreign-ownership status in a DCSA system a condition of award on contracts above $5 million, cleared or not. Its impact numbers do not reconcile, and the paperwork approval it relies on was enlarged a year before it appeared.
On May 7, 2026, the Defense Acquisition Regulations System published a proposed rule implementing section 847 of the fiscal 2020 defense authorization act. It would require contractors and subcontractors at any tier on contracts above $5 million, including companies with no facility clearance, to disclose their beneficial ownership and any foreign ownership, control or influence to the Defense Counterintelligence and Security Agency. Where the requiring activity, acting on DCSA’s input, finds a risk that can be mitigated, the company must carry out the mitigation.
The requirements go into DFARS part 240, Information Security and Supply Chain Security, under subpart 240.2, Security Prohibitions and Exclusions. The part itself was not created for this rule. It mirrors FAR part 40 under the government-wide Revolutionary FAR Overhaul, and a class deviation has run a DoD version of part 240 since February 1, 2026. Later revisions of that deviation moved the department’s prohibitions on Chinese military companies and foreign-made drones into it, according to the DAR Council’s open-case list.
Where FOCI landed inside that structure was a choice. The deviation’s current text of part 240, issued with its third revision on September 3, already holds one ownership screen: section 240.7004 bars contracts of $200,000 or more, commercial ones included, with a firm in which the government of a state sponsor of terrorism holds a significant interest, and a 5 percent beneficial interest is enough. That rule sits in subpart 240.70, Prohibited Sources. The proposed FOCI rule does not join it there. It goes into subpart 240.2, next to the ban on covered telecommunications and video surveillance equipment in section 240.270 and the authority to exclude sources for supply chain risk in section 240.271. Its placeholder number, 240.27X, continues that sequence. The rules on safeguarding covered defense information and on CMMC sit in the adjoining subpart, 240.3.
The commercial carve-out is written in the same vocabulary. The requirements do not reach commercial products and services unless a designated senior DoD official determines that the contract involves a risk to national security or potential compromise “because of sensitive data, systems, or processes.” In its discussion of Executive Order 14192, the preamble cites Executive Order 14017 on supply chains and Executive Order 14028 on cybersecurity, describing section 847 as an upstream defense that keeps compromised or influenced suppliers out of the supply chain.
The link to cybersecurity is also procedural. The disclosure runs on Standard Form 328 inside DCSA’s National Industrial Security System, and the same form already screens cybersecurity assessors: under the CMMC program rule, third-party assessment organizations must submit an SF 328 to DCSA and receive a non-disqualifying FOCI determination before accreditation. That pipeline is currently idle. The Pentagon paused the move to mandatory third-party CMMC certification on July 13, 2026, and the memorandum issuing the third revision of the part 240 class deviation, signed September 3, directs contracting officers to work with requiring activities to remove or revise CMMC requirements in new and existing solicitations and contracts. The revised part 240 text still carries the CMMC clause and its C3PAO assessment levels, so the ownership screen for assessors remains in the regulation while the assessments themselves are on hold.
What the rule would require
A “covered contractor or subcontractor” is any company at any tier on a DoD contract valued above $5 million. For those companies the rule would:
- Bar contracting officers from awarding, modifying, exercising an option on or otherwise extending a contract, task order or delivery order unless the company holds an eligible status in NISS or the commercial exception applies.
- Require offerors to represent, by submitting an offer, that their SF 328 and beneficial-owner contact information in NISS are current, accurate and complete.
- Require agreed mitigation measures to be implemented within 90 calendar days of award, option exercise, modification or post-award identification of risk.
- Impose three-business-day reporting when a change may place the company or a subcontractor under FOCI, and ten business days to begin a plan of action after DCSA notice.
- Flow down to subcontracts above $5 million, with primes confirming subcontractor NISS status before award and through performance.
The comment period closed on July 6, 2026. On July 29, the director of the Defense Acquisition Regulations Council tasked the Acquisition Technology and Information team to review the comments and draft a final rule, with a report due September 30, 2026.
Where 37,740 comes from
The rule’s headline estimate is that 37,740 entities could be affected. That figure is built from one count and a chain of assumptions.
The count comes from the Federal Procurement Data System, as the rule reports it: an average of 3,774 unique entities with awards above $5 million across fiscal 2022 through 2024, excluding awards made under exclusively commercial procedures. Of those, 2,148, or 57 percent, are small businesses. Everything after that is assumption.
7,548 offerors + 3,774 × 5 subcontractors = 26,418
3,774 × 5 subcontractors = 18,870 First line: the rule’s impact estimate, which attaches five subcontractors to every offeror, losing offerors included, and does not add the offerors themselves. Second line: this publication’s recalculation from the rule’s stated assumptions. Third line: the rule’s own base for update estimates. Source: proposed rule, section IV, 91 FR 24785.
In the next paragraph the same section changes base. To estimate how many contractors would update disclosures during performance, the rule multiplies 3,774 awardees by five subcontractors to get 18,870, halves that to 9,435, and takes ten percent of 18,870 to get 1,887 affected by modifications and options. The offerors that produced 37,740 do not appear in that arithmetic, and the regulatory flexibility analysis later calls the same 37,740 “potentially impacted awardees.”
The only cost the rule puts a number on is $168,534 a year, the time 7,548 offerors would spend verifying their NISS submissions twice a year. The costs of mitigation itself are excluded. The preamble places the technical requirements of FOCI risk mitigation outside the scope of the rule “as described in section VIII,” but section VIII, on the Paperwork Reduction Act, does not discuss them. For cleared companies those requirements are the instruments set out in 32 CFR 117.11, from board resolutions and security control agreements to special security agreements, proxy agreements and voting trusts.
The filing universe was enlarged first
The rule says it needs no new paperwork approval because two existing approvals cover its information collections: SF 328 under OMB control number 0704-0579 and NISS under 0705-0006. It cites their burdens as $7,352,560 and $712,281.
Those are the cost-burden fields of the two collections as approved. The OIRA record for the SF 328 collection shows what changed when that approval was granted on May 1, 2025.
| SF 328 collection (0704-0579) | Previously approved | As approved May 1, 2025 |
|---|---|---|
| Annual responses | 2,650 | 62,950 |
| Time burden, hours | 3,092 | 104,917 |
| Cost burden | $188,684 | $7,352,560 |
Annual responses rose by a factor of 23.8 and hours by a factor of 33.9, a year before the rule was proposed. The revision was prepared with section 847 in view. Both notices supporting it, the 60-day notice of April 2024 and the 30-day notice of September 2024, list section 847 and its disclosure requirement among the form’s uses, alongside the industrial security program, the DHS classified critical infrastructure program, the DoD Enhanced Security Program, SBIR and STTR due diligence and CMMC. The $7.35 million is the burden of the whole collection across those uses. The rule cites it as covering its own costs without separating the share its requirements add.
The second collection moved the other way. The NISS approval, also concluded May 1, 2025, cut annual responses from 23,342 to 11,671, hours from 35,013 to 11,671, and cost burden from $1,272,723 to $712,281. The rule relies on that approval while estimating that as many as 37,740 entities would need an eligible status in the same system. The two figures rest on different counting methods and are not directly comparable, but the approved NISS inventory was cut in half a year before the rule arrived.
The September 2024 notice also lists the respondent’s obligation for SF 328 as voluntary. Under the proposed rule, filing it would be a condition of award.
Two officials, one placeholder
The commercial carve-out turns on a “designated senior DoD official.” The preamble says the official has not yet been designated and that the term is a placeholder.
The statute distinguishes two roles. Section 847(b)(2)(C)(ii) calls for designating the official who approves award, modification or termination actions after a DCSA finding of FOCI risk; section 847(c)(1) gives a “designated senior Department of Defense official” the decision to extend the requirements to commercial contracts. DoD Instruction 5205.87, effective May 13, 2024, merges the two. Under its paragraph 2.4.b the Under Secretary for Acquisition and Sustainment delegates the section 847(c)(1) decision to DoD component heads, and its glossary defines a single designated component official who performs both functions. Designees at component level therefore already exist on paper. The proposed rule’s placeholder names one senior official, and the preamble does not say whether it means the same people.
The instruction is more specific than the rule elsewhere too. It gives DCSA 25 working days to deliver a risk indicator report or a FOCI assessment with a proposed mitigation strategy. The proposed DFARS text carries no such deadline, though it refers contracting officers to a PGI 240.27X-4 that has not been published. The instruction also covers defense research assistance awards, meaning grants, cooperative agreements, technology investment agreements and other assistance or non-procurement transactions, which a DFARS rule does not reach. Its own clocks differ as well: mitigation is to be implemented within 90 calendar days of award, while DCSA is to execute final mitigation measures within 90 working days.
Nearly five years past the deadline
Section 847 was enacted on December 20, 2019. Section 819(c) of the following year’s authorization act set two dates: an implementation plan to the defense committees by March 1, 2021, and revision of the DFARS to fully implement section 847 by July 1, 2021. The proposed rule arrived four years and ten months after the second date.
On June 16, 2025, Representative John Moolenaar, chairman of the House Select Committee on the CCP, wrote to the secretary of defense that the rule had languished, cited press reports about a supplier of fighter, helicopter and missile parts, and asked for a staff briefing by June 30, 2025. The proposed rule followed nearly eleven months later.
DCSA’s public page on section 847 still says publication of the DFARS clause is “anticipated in the next 12-18 months.” The page carries no date. DCSA announced it in its April 2025 newsletter for facility security officers, and the estimate has not changed since.
Congress is now pressing on scope. On June 1, 2026, Senators Elizabeth Warren and Chuck Grassley introduced S. 4648, which would cut the section 847 threshold from $5 million to $500,000 and require beneficial-owner information in every bid. The threshold cut reappears as section 820 of the Senate Armed Services Committee’s fiscal 2027 authorization bill, reported June 15, 2026. Section 842 of the same bill would require the designation, by March 1, 2027, of an office under the assistant secretary for industrial base policy responsible for adversarial-capital risk. The Senate bill has not reached floor debate: cloture on the motion to proceed failed 50–46 on July 14. The House-passed bill, H.R. 8800, contains no amendment to section 847. Its section 1816 would also designate an office for adversarial-capital risk, within the Office of Industrial Base Policy and within 90 days of enactment.
Small entities, by the rule’s own count
The Pentagon does not expect a significant economic impact on a substantial number of small entities under the Regulatory Flexibility Act because, in the rule’s words, it “simply requires certain offerors and contractors to disclose information about FOCI and beneficial ownership and to conduct risk mitigation efforts, if applicable.” The same analysis estimates 21,511 small entities among the 37,740 and states that the rule imposes no reporting or compliance requirements on them beyond those already approved under the two information collections. The rule also invokes a national-security function to stay outside Executive Order 14192.
The question the final rule has to answer
The DAR Council’s report on public comments is due September 30, 2026. A separate case, DFARS 2021-D026, which would implement the beneficial-ownership disclosure requirement in section 6403 of the fiscal 2021 act, has been on hold since August 12, 2026, pending litigation.
Filing ownership vetting under information security makes a company’s owners part of its security posture. The rule leaves open who applies that test to commercial contracts. The official who decides whether a contract involves “sensitive data, systems, or processes” is still a placeholder, and the final text will show whether that role goes to one senior officer or to the component designees the 2024 instruction already created.
Sources
Primary and official documents
- Defense Acquisition Regulations System — Mitigating Risks Related to Foreign Ownership, Control, or Influence (DFARS Case 2021-D011), proposed rule, 91 FR 24783, May 7, 2026
- Office of the Law Revision Counsel — 10 U.S.C. 4819 and statutory notes, including section 847 of Pub. L. 116-92 and section 819(c) of Pub. L. 116-283
- Office of the Under Secretary of Defense for Intelligence and Security — DoD Instruction 5205.87, Mitigating Risks Related to FOCI for Covered DoD Contractors and Subcontractors, May 13, 2024
- Department of Defense — Proposed Collection; Comment Request, SF 328, 89 FR 29313, April 22, 2024
- Department of Defense — Submission for OMB Review; Comment Request, SF 328, 89 FR 74277, September 12, 2024
- Office of Information and Regulatory Affairs — ICR 202404-0704-001, Certificate Pertaining to Foreign Interests (SF 328), OMB 0704-0579
- Office of Information and Regulatory Affairs — ICR 202501-0705-001, National Industrial Security System, OMB 0705-0006
- Defense Acquisition Regulations System — Open DFARS Cases as of September 18, 2026
- Defense Pricing, Contracting, and Acquisition Policy — DFARS Revolutionary FAR Overhaul Class Deviations, including 2026-O0025, DFARS Part 240
- Defense Pricing, Contracting, and Acquisition Policy — Class Deviation 2026-O0025, Revision 3: Revolutionary FAR Overhaul Part 40, DFARS Part 240, memorandum and attached DFARS part 240, September 3, 2026
- Electronic Code of Federal Regulations — 32 CFR 170.9, CMMC Third-Party Assessment Organizations
- Electronic Code of Federal Regulations — 32 CFR 117.11, Foreign Ownership, Control, or Influence
- Defense Counterintelligence and Security Agency — National Defense Authorization Act, Section 847
- Defense Counterintelligence and Security Agency — Voice of Industry newsletter for facility security officers, April 2025
- House Select Committee on the CCP — Letter from Chairman John Moolenaar to Secretary of Defense Pete Hegseth, June 16, 2025
- U.S. Senate — S. 4648, To improve transparency with respect to foreign influence on Department of Defense contractors, introduced June 1, 2026
- U.S. Senate — S. 4784, National Defense Authorization Act for Fiscal Year 2027, as reported June 15, 2026
- Congressional Research Service — FY2027 NDAA: Status of Legislative Activity (IN12704)
- U.S. Senate — Roll Call Vote No. 195, 119th Congress, 2nd Session: Cloture on the Motion to Proceed to S. 4784, July 14, 2026
- U.S. House of Representatives — H.R. 8800, National Defense Authorization Act for Fiscal Year 2027, as passed by the House