Comment on FR Doc # 2026-09067

Anonymous AnonymousOtherIndividual
Summary: The commenter, a software industry professional, expresses concerns about potential government overreach and the need for clear, transparent criteria for risk determination. They argue that excessive oversight and burdensome requirements could stifle innovation and delay the delivery of critical technologies to the DoD.
I have spent 20 years in the software field, most of it in within organizations subject to a multitude of regulatory standards or holding various state or federal contracts. As such I recognize the ubiquitous nature of supply chain attacks in the current software ecosystem along with the criticality of securing our national software supply chains against adversaries that would see our nation fail. There are reasonable methods to do so that do not require excessive governmental overreach that will further stifle innovation efforts in an race that we are already losing. The development of novel software capabilities requires an organization to be able to move rapidly and make informed decisions based on clear compliance criteria balanced against measured risk. There must be clear criteria for the determination that a “contract involves a risk or potential risk to national security or potential compromise because of sensitive data, systems, or processes.” and a well defined, transparent process for the appeal of such findings to preserve organizational momentum in a hotly contested field for technological advantage where we are competing against adversarial state-backed entities. Furthermore, the additional burden on existing governmental systems to support the increased scope of oversight risks an interruption in the delivery of cutting-edge technologies while systemically shifting risk back on to the organizations the DoD seeks to leverage.

View on Regulations.gov