procurementtrade-pressNewsThe Broadside1 min read

DoD CIO mandates cyber supply-chain risk review in IT procurement

The new instruction doesn't just ask for best-in-class purchasing, it embeds supply-chain risk assessment into the category management playbook, meaning program managers now carry a cyber obligation alongside the cost one.


TL;DR

DoD CIO Kirsten Davies approved DoD Instruction 8000.02 on July 23, effective July 29, requiring all components to apply cyber supply-chain risk management processes to IT category management acquisitions. The directive mandates use of enterprise agreements before individual IT investments unless mission or cost dictate otherwise. Program managers and acquisition officials must assess federal category management vehicles, joint enterprise licensing agreements, and component-level enterprise software agreements, and they must do it with supply-chain risk folded in, not as a separate gate.

The directive is the latest in a series of moves by Davies's office to tighten the connection between how DoD buys technology and whether that technology is trustworthy. Since her confirmation, Davies has framed supply-chain risk as inseparable from modernization, a view that now has procedural teeth.

DoDI 8000.02 doesn't create a new supply-chain review process. It grafts SCRM onto the existing category management machinery, meaning the same program managers evaluating best-in-class purchasing solutions are now responsible for assessing cyber supply-chain risk at the procurement stage. That's a structural change, not a rhetorical one: it moves the risk conversation upstream, before contracts land on desks.

The timing fits a pattern. Secretary Hegseth's July 2025 order demanding a two-week supply-chain review followed the ProPublica revelations about China-based engineers on DoD cloud systems. The June 2025 COTS ICT supply-chain memo from the CIO's office had already directed updates to procurement risk management. DoDI 8000.02 operationalizes both impulses into a standing requirement.

For the practitioner, Monday means preparing to justify why a component-level deal is better than an enterprise vehicle, and doing it with a supply-chain risk rationale attached. Program managers who've treated SCRM as a separate compliance checklist now carry it inside the procurement decision itself.


Published ·Deep Fathom