Comment on FR Doc # 2026-09067
Kongsberg Defense & Aerospace, Inc.SupportBusiness
Summary: The commenter, representing a business entity, supports the security objectives of the proposed DFARS rule but argues for a risk-based, tiered framework to avoid disproportionate burdens on unclassified contractors. They specifically recommend scalable mitigation options for uncleared entities, targeted flowdown requirements, a longer implementation window, and alignment with broader acquisition reform objectives.
We respectfully submit the following comments on the proposed DFARS rule expanding Foreign Ownership, Control, or Influence (FOCI) requirements to unclassified contracts. We support the underlying security objectives but urge DoD to adopt a risk-based, tiered framework that achieves those objectives without imposing disproportionate burden or disrupting defense industrial base participation.
Comment 1: A Scalable Framework Is Needed for Contractors Outside the Cleared Environment
The proposed rule applies FOCI mitigation constructs designed for cleared contractors to entities performing unclassified work. Many foreign-owned U.S. companies supporting DoD do not hold a Facility Clearance and are not positioned to obtain one. Existing DCSA frameworks do not provide scalable pathways for uncleared entities to demonstrate FOCI mitigation on unclassified work. Applying these constructs without defined standards introduces uncertainty misaligned with the actual risk profile of such work.
Recommendation: Establish a tiered, risk-based framework including: scalable mitigation options for uncleared contractors; applicability based on access, control, and program sensitivity — not contract value; and clear, predictable evaluation processes for contractors and contracting officers.
Comment 2: Flowdown Requirements Should Be Targeted, Not Uniform
Broad flowdown across all subcontract tiers imposes compliance burden without commensurate security benefit. FOCI considerations are most relevant where suppliers have access to controlled information or ability to influence performance. Many suppliers of commercial or standardized components lack such access. Uniform requirements extend obligations beyond meaningful risk and may disrupt supply relationships where qualified alternatives are limited.
Recommendation: Adopt a risk-based flowdown approach including: criteria based on actual access, control, and performance sensitivity; targeted inclusion where meaningful FOCI risk exists; and streamlined requirements for suppliers without access to sensitive information.
Comment 3: The Proposed 90-Day Implementation Window Is Not Practicable
The 90-day window does not account for the complexity of aligning mitigation measures across corporate structures and jurisdictions, particularly where defined processes do not yet exist. Multi-jurisdictional coordination and government engagement are inherently iterative. For many entities, 90 days is not realistic for achieving durable compliance.
Recommendation: Extend the implementation period to a minimum of 180 days, with flexibility for complex cases. A phased approach with interim milestones would support more consistent implementation.
Comment 4: FOCI Requirements Should Align with Acquisition Reform Objectives
NDAA NDC provisions, FAR/DFARS modernization, OTA expansion, and commercial-first approaches reflect a policy shift toward agile, accessible procurement. Broad FOCI application to unclassified contracts without scalability risks deterring the commercially oriented and globally integrated suppliers DoD seeks to engage.
Recommendation: FOCI requirements for unclassified work should be proportionate to actual risk based on access and influence; adaptable to non-cleared and commercial entities; and structured to complement DoD's acquisition reform agenda.
We welcome further engagement with DoD as this rule is finalized.