trade-press
Software sovereignty isn't in any DFARS clause
A Federal News Network commentary defines four pillars of software sovereignty (location, control, toolchain integrity, and isolation) none of which appear in binding DoD procurement rules today.
A Federal News Network opinion piece by a Coder strategic advisor argues that America-first industrial policy has a blind spot: software supply chains. The piece defines software sovereignty as four requirements, code written on U.S.-controlled infrastructure, government-operated servers, U.S.-sourced toolchains, and no foreign-reachable SaaS dependencies. These requirements don't exist in current DFARS supply-chain clauses (252.239-7018 covers IT supply chain risk broadly; Subpart 239.73 addresses covered systems) or in CMMC or FedRAMP. No proposed rulemaking or draft standard from CISA or DoD yet formalizes software-sovereignty mandates. The commentary flags that the SHIPS Act reauthorization defines sovereignty in maritime terms (shipyards, labor, materials) and is silent on where the software that runs a modern destroyer gets developed.