Comment on FR Doc # 2026-09067
2430 GroupOpposeIndividual
Summary: The commenter argues that the proposed rule lacks clear standards, predictability, and a scalable assessment system, which will create significant administrative burdens and procurement delays for defense contractors. They advocate for the inclusion of third-party certification systems, published risk-tiering methodologies, and the recognition of existing beneficial ownership disclosures to ensure the rule is practical and effective.
The current language of the draft rule does not give contractors a system for evaluating their vulnerabilities and risk; a clear standard to meet for ensuring compliance; a way to certify compliance independently; or predictability about what the government will do with that information.
Contractors must hand over sensitive business information and then wait for DCSA to tell them whether they have a problem, why, and what mitigation is. Such a requirement, without a clear standard for certification reduces the likelihood of compliance or incentivizes companies to share the bare minimum, or to find loopholes that would undermine the effectiveness of the proposed program.
Government reviews do not scale. Other regulatory systems, including CMMC and FedRAMP recognize this and rely on Third Party Assessment Organizations (3PAOs). These are not perfect systems, but they allow the private sector to absorb some assessment burden and give contractors a way to understand and comply with standards before they submit information to USG. This proposed rule creates no equivalent; DCSA is the sole reviewer, decision-maker, and appeals’ path. DCSA currently handles about 2,000 FOCI assessments per year. The new rule would push that number above 40,000. The rule sets a target of 25 working days per assessment, but there is no enforcement mechanism for that timeline, and a DCSA backlog risks creating consequential delays in procurement. DoD needs to build either a third-party certification system or develop a method for DCSA to handle a massive increase in caseload. Moreover, this resource requirement involves only one-time FOCI determinations; to ensure that contractors remain free of FOCI, ongoing monitoring for changes would be required, thus further straining resources.
The rule defines FOCI in terms that give DCSA enormous discretion. This may be appropriate for the small number of cases they handle today, but it will not serve a system that covers tens of thousands of uncleared contractors. Without a published risk-tiering methodology, two similarly situated contractors could receive different scores depending on which analyst reviews their case. That unpredictability has consequences for M&A transactions, fundraising, and basic business planning. DoD should publish clear risk tiers with defined criteria rooted in histories of known cases of influence. This provides a framework so that contractors can self-assess before submitting and have some reasonable expectation of the outcome.
The rule does not specify which mitigation measures apply to which risks. This may be appropriate for cleared contractors with access to classified information. For uncleared contractors performing unclassified work, it creates an unresolvable level of uncertainty. A buyer deciding on an acquisition of a DoD contractor cannot price FOCI risk into the deal if it has no way to predict whether the nature of the mitigation requirement. That uncertainty will chill investment in the defense industrial base.
The rule’s timelines assume a level of institutional capability and expertise that does not exist for companies that have never operated under FOCI requirements. This includes most of the contractors this rule would cover.
The three-day notification window is not realistic for smaller companies seeking investors. Such companies may not even know the full identity and nationality of every LP in every participating fund until well after an investment round closes. Thus, every cap table change becomes potentially reportable, which creates a compliance burden out of proportion to the actual security risk.
The USG already has a beneficial ownership disclosure framework under the Corporate Transparency Act. Allied nations have their own UBO registries under EU Anti-Money Laundering Directives and the UK Persons with Significant Control register. An effective rule would allow contractors to rely on verified UBO filings from these existing systems as a baseline, instead of building a parallel disclosure obligation from scratch. The proposed rule instead creates a standalone, DoD-specific disclosure requirement with no recognition of existing, verified data. A contractor that has already reported its beneficial ownership to FinCEN and whose foreign investors have already been vetted under allied-nation AML frameworks must start from zero with DCSA. That is duplicative.
The rule allows designated DoD officials to override an exemption for commercial products and services if they determine the contract involves sensitive data, systems, or processes. The criteria for such determination are not defined. A commercial company selling an off-the-shelf product to DoD has no way to know whether or when the exemption might be pulled.
The draft rule is necessary but insufficient for solving the problem; defense contractors are exposed to foreign influence and lose intellectual property via other vectors, including employees, vendors, and even strangers.