Comment on FR Doc # 2026-09067

The IVA'AL GroupSupportOther
Summary: The commenter argues that the proposed rule underestimates the time and effort required to verify Foreign Ownership, Control, or Influence (FOCI) information, noting that meaningful verification requires deep investigation into corporate structures. They suggest that the Defense Counterintelligence and Security Agency (DCSA) should implement a standardized, third-party validation model similar to the CMMC program to improve scalability and consistency across the defense industrial base.
We believe the estimated burden of approximately 10 minutes understates the effort required to verify FOCI ownership information. While that estimate may be reasonable if the activity is limited to confirming that required forms and ownership information have been entered into the National Industrial Security System (NISS), determining whether the information is current, accurate, and complete often requires substantially more work. The true cost of the proposed rule should account for the increased number of entities that will need to be evaluated, and the language in the proposed rule does not make the basis of the estimate clear. Meaningful FOCI verification frequently requires review of beneficial ownership, corporate structures, affiliated entities, investments, governance arrangements, and changes in control that may affect foreign ownership, control, or influence. For companies with subsidiaries, investors, or complex ownership arrangements, this process can require analysis and coordination well beyond a simple administrative check. This concern is reinforced by the FAST report prepared by MITRE, dated December 2025, which notes on page 69 that the current FOCI review and mitigation process takes an average of approximately 40 weeks to complete. Although the proposed 10-minute estimate appears focused on administrative data verification, meaningful FOCI review and adjudication often require substantial investigation and validation. The gap between the estimated burden and current processing timelines suggests that the effort required for accurate FOCI verification may be significantly understated. Experience across federal compliance programs, including the CUI program, shows that reliance on contractor self-attestations can create gaps between reported conditions and actual circumstances. If the Government relies on contractor representations regarding foreign ownership, control, or influence, DCSA should implement meaningful mechanisms to validate FOCI-related claims rather than relying solely on attestations. Independent validation would strengthen the National Industrial Security Program, promote consistency, and reduce the risk that inaccurate or incomplete ownership information goes undetected. To support the proposed rule while minimizing disruption to the DIB supply chain, DCSA should consider leveraging qualified third-party organizations to assist with FOCI reviews and investigations. A third-party model could improve scalability, reduce bottlenecks, and allow DCSA to focus on adjudication, oversight, and higher-risk cases. The program should use a standardized process with consistent review criteria, documentation requirements, evidence collection procedures, and quality controls. While DoW components and acquisition portfolios may have unique mission requirements, allowing each organization to establish its own vetting methodology could create inconsistent outcomes and confusion. Instead, those stakeholders should advise DCSA in developing a common framework, with a formal escalation process for additional or accelerated review when unique risks or operational needs exist. DCSA could model this approach on aspects of the CMMC program. While a formal accreditation body may not be necessary, contractors should be able to voluntarily engage qualified third-party reviewers, or work directly with DCSA, to begin FOCI vetting before a contract opportunity is identified. An early-vetting pathway would reduce delays during source selections and awards while increasing transparency for contractors and government customers. DCSA should establish objective eligibility criteria and metrics for participation. After favorable adjudication, contractors should receive a certificate, validation token, or similar mechanism showing that they completed a FOCI review. Prime contractors could rely on that validation when evaluating subcontractor eligibility, reducing duplication and improving confidence in subcontractor representations. This approach would also address a potential gap in subcontractor vetting. Rather than relying only on prime contractors to assess subcontractor ownership information, or requiring repeated reviews across multiple procurements, a standardized DCSA-recognized validation process would provide a consistent mechanism for verifying eligibility across the industrial base. This would improve transparency, reduce administrative burden, and create a more reliable framework for identifying and mitigating FOCI risks. For these reasons, the estimated burden for verifying FOCI ownership information should be reassessed to reflect the diligence needed for accurate reporting and the real-world impact of implementation. A more realistic estimate would better account for the effort required to validate ownership information and support the Government’s objectives for transparency, security, supply chain resilience, and effective risk management.

View on Regulations.gov