Skip to main content

Third Party Risk Management

#TPRM x #DefenseSector: Why Foreign Ownership, Control or Influence Is Becoming the Defense Sector's Defining Due Diligence Test

Every regulated sector's third-party risk framework asks whether a supplier is financially sound and operationally capable. Defense TPRM must ask a further question with no real equivalent in banking, energy or healthcare: who ultimately owns, controls or can influence this supplier, and could that influence be exercised by a foreign state? That question is moving from a niche concern for cleared contractors to a compliance obligation across the defense industrial base. On 7 May 2026, the US Department of Defense proposed significantly expanding Foreign Ownership, Control and Influence disclosure requirements to any contractor or subcontractor, at any tier, holding a DoD contract above five million dollars, whether or not classified information is involved.

DoD estimates nearly 40,000 companies could be captured. Commercial products and services, including off-the-shelf items, are exempt unless a senior DoD official determines that a contract creates national security risk because of sensitive data, systems or processes. Commercial-item suppliers should not assume automatic exclusion. Covered contractors would need to submit Standard Form 328 through the Defense Counterintelligence and Security Agency's National Industrial Security System before award, disclose beneficial ownership, and report changes in foreign ownership within three business days.

If DCSA identifies a mitigable national security risk, the contractor must submit a plan within 10 business days and implement mitigation within 90 calendar days of the triggering event. Prime contractors must flow the substance of the FOCI clause into subcontracts above the same five-million-dollar threshold. Europe is moving in a parallel direction. NIS2 excludes public administration entities operating in national security, defence and law enforcement, but the carve-out is narrower than it appears.

In practice, NIS2 focuses on entity type rather than the intended use of a product. Private defense companies serving civilian customers, or producing dual-use products, generally remain subject to NIS2, the Cyber Resilience Act and the AI Act, with exemptions applying narrowly to exclusively military end-use. For suppliers with commercial or dual-use revenue, the compliance assumption is that NIS2 applies. Together, these trends point to a structural shift: defense third-party risk is moving beyond technical and financial due diligence into a counterintelligence-adjacent discipline. Beneficial ownership mapping, foreign investment screening and governance analysis are becoming core elements of vendor onboarding alongside cybersecurity controls.

Organisations still treating FOCI and beneficial ownership checks as a one-time qualification step are building assurance programmes against a due diligence standard that both major defense markets are already moving beyond.