Two July actions, one message: the government now treats the structure of the defense supply chain — who owns it, where it sources, how concentrated it is — as a national-security control surface.
On July 20, Executive Order 14415 directed the Pentagon to sharply curtail the waivers that let contractors source covered critical materials from China and other non-compliant suppliers, and to require supply-chain mapping from raw material to finished system across every supplier tier, per Defense News. Waivers get significantly harder to obtain on January 1, 2027, and applicants must document their search for alternatives, material origins, and transition plans.
A week earlier, the Department of Justice announced that TransDigm had abandoned its proposed $960 million acquisition of Stellant Systems after the Antitrust Division prepared to sue, arguing the merger would have left the government a single source for radar components used in the Navy's Aegis combat system and the Air Force F-16 fleet. The Antitrust Division said it will continue to challenge mergers that create sole-supplier risk.
Most primes can name their first tier. Mapping to raw material means resolving thousands of entities several tiers down — many of them small, private, renamed, or foreign-held through intermediaries — and keeping that picture current as suppliers change hands. It is the same problem the proposed DFARS FOCI rule poses from the ownership side: dependency and influence hide in the tiers nobody watches.
- A supplier map is an entity-resolution product: the same foundry, fund, or holding company appearing under different names across tiers has to resolve to one node.
- Mapping is not a one-time deliverable. Ownership changes, sanctions designations, and adverse events move faster than annual refresh cycles.
- The map is also a targeting map. Knowing which single-source nodes your programs depend on is exactly what an adversary wants to know — and what a counterintelligence program should protect and monitor.
OBSIDIAN — Counterintelligence treats supply-chain and foreign-dependency identification as protective intelligence: mapping what an organization depends on to who would exploit it, and watching for the early signals that someone is. The executive order makes that mapping mandatory; making it continuously true is where programs will differentiate.