After eight years, White House revamps cyber supply chain risk data calls
The metrics agencies use to report supply chain risk haven't been updated since the SECURE Technology Act passed in 2018, leaving shared adversary threats invisible to systematic detection across government.
TL;DR
The White House Office of the Federal Chief Information Officer is reviewing all practices tied to NIST's cyber supply chain risk management guidelines, with a revamped data-collection process expected "in the near term." Senior advisor Cheri Benedict, speaking at an INSA webinar Tuesday, said the review will emphasize shared risk and adversarial threats, aiming for a "left of boom" posture that flags risky vendors before they're embedded in agency systems. The existing framework hasn't been updated since the SECURE Technology Act of 2018; the FASC created by that law took nearly seven years to issue its first exclusion order.
The White House Office of the Federal Chief Information Officer is reviewing how agencies report on their cyber supply chain security programs, with updated metrics expected "in the near term," according to Cheri Benedict, senior cyber supply chain advisor within the federal CIO's office.
The data-collection practices under review trace back to the SECURE Technology Act of 2018, which established the Federal Acquisition Security Council as the interagency body for supply chain risk standards. Those mechanisms haven't been updated since. The FASC took nearly seven years to produce its first vendor exclusion order, against Switzerland-based Acronis AG last September, and that order applies only to intelligence community procurements and SCI systems.
Benedict, speaking Tuesday at an Intelligence and National Security Alliance webinar, framed the review around "shared risk" and adversarial threats. "We especially focus on adversarial related risk," she said, "and that can take different forms and fashions." The Trump administration's 2026 national cybersecurity strategy has made moving "away from adversary vendors and products" a stated goal.
The gap between aspiration and machinery
The tension Benedict described is real and familiar to anyone in federal acquisition. She wants agencies to conduct secure supply chain reviews "even before award," a "left of boom" posture that identifies risky vendors before they're embedded in government systems. She also acknowledged the obvious problem: "We already have such prolonged acquisition timelines."
Adding pre-award supply chain reviews to already-slow procurement processes isn't a trivial ask, and Benedict didn't pretend otherwise. The instruction to prioritize high-value assets is the pragmatic concession, but it also means lower-tier systems will continue operating without systematic adversary-risk screening.
House lawmakers on the Select Committee on China have proposed moving the FASC into the Executive Office of the President with dedicated staffing, a structural fix aimed at the speed problem. Whether the White House's metrics review produces anything faster than the FASC's seven-year pace is the question "near term" doesn't answer.
Published ·Updated ·Deep Fathom