Comment on FR Doc # 2026-09067
Kongsberg Discovery US, LLCOpposeBusiness
Summary: The commenter, representing a business entity in the defense industrial base, argues that expanding FOCI requirements to unclassified contracts without a scalable, risk-based framework will create unnecessary complexity and disrupt supply chains. They advocate for a tiered approach that focuses on actual risk and influence rather than uniform requirements, and they request a longer implementation timeline of at least 180 days.
Expanding FOCI requirements to unclassified contracts without a clear, scalable framework may introduce unnecessary complexity and supply chain disruption. A risk-based, tiered approach would help ensure security objectives are met while maintaining participation across the defense industrial base.
1. Scalable Framework for Contractors Outside the Cleared Environment
The rule distinguishes between contractors operating under DCSA-approved mitigation frameworks and those performing unclassified work outside the cleared environment. Many foreign-owned U.S. companies supporting DoD programs do not hold a Facility Clearance (FCL) and may not be positioned to obtain one under current DCSA requirements. For these entities, existing DCSA mitigation frameworks are designed for cleared contractors and do not establish a clearly defined or scalable approach for implementing or demonstrating FOCI mitigation in the context of unclassified contracts. Applying mitigation constructs developed for cleared contractors, without defined standards or alternatives, may introduce uncertainty and may not align with the risk profile of unclassified work. In practice, such constructs may not be applicable or achievable under current DCSA policy. A tiered, risk-based framework would support more consistent implementation across both cleared and non-cleared contractors.
This could include:
- Scalable mitigation options for uncleared contractors
- Applicability based on access, control, and program sensitivity, not contract value alone
- Clear and predictable evaluation processes
2. Flowdown and Supply Chain Impact
Broad flowdown of FOCI requirements across all subcontract tiers may introduce burden without corresponding security benefit, particularly in globally integrated supply chains. FOCI considerations are most relevant where a supplier has meaningful access to controlled or sensitive information, or the ability to influence contract performance. In many unclassified contexts, suppliers do not have such access or influence. Applying uniform requirements across all suppliers extends obligations beyond where meaningful risk exists. Many suppliers, including foreign suppliers, provide commercial or standardized components without access to controlled information or program-level influence. Applying FOCI requirements in such cases may create unnecessary complexity and disrupt established supply relationships, particularly where qualified alternatives are limited. A risk-based flowdown approach could help focus attention on higher-risk relationships while limiting unnecessary burden.
This could include:
- Application based on access, control, and performance sensitivity
- Targeted inclusion of suppliers, domestic or foreign, where meaningful risk is present
- Streamlined requirements for suppliers without access to sensitive information
3. Implementation Timeline
The proposed 90-day mitigation window may not be practicable, particularly where defined processes do not yet exist for contractors outside the cleared environment. Establishing or aligning mitigation measures may require coordination across corporate structures and jurisdictions, as well as engagement with government stakeholders. These efforts are inherently iterative. An implementation period of at least 180 days, with flexibility for more complex cases, would likely support more effective and consistent compliance.
4. Alignment with Acquisition Reform
Expanded FOCI requirements are closely related to broader efforts aimed at streamlining acquisition and expanding participation. NDAA provisions supporting Non-Traditional Defense Contractors (NDCs), continued FAR/DFARS modernization, and expanded use of Other Transaction Authority (OTA) and commercial-first acquisition approaches reflect a shift toward more agile procurement. These efforts are intended to reduce barriers, increase access to innovation, and enable participation from commercially oriented and globally integrated suppliers. Applying broad FOCI requirements to unclassified contracts, without corresponding scalability, may create tension with these objectives, particularly for contractors operating outside the cleared environment and for suppliers providing commercial products or services.
FOCI requirements for unclassified work may be more effective if they are:
- Proportionate to actual risk, including access and influence
- Adaptable to non-cleared and commercial entities
- Supportive of streamlined acquisition pathways