FAR and DFARS › DFARS Part 252: Solicitation Provisions and Contract Clauses › Subpart 252.2
DFARS 252.239-7018 Supply Chain Risk.
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
This clause requires contractors to mitigate supply chain risk when providing supplies and services to the Government. It defines information technology and supply chain risk, and allows the Government to use certain authorities to manage that risk, including limiting disclosure of information without review in bid protests or Federal court.
Applies to: Contractors providing supplies and services to the Government under contracts that include this clause.
What it requires
- Mitigate supply chain risk in the provision of supplies and services to the Government.
Key terms: Information technology · Supply chain risk · Covered system · Adversary
Written by AI from this section's text. A guide, not legal advice: the text below rules.
The text
As prescribed in 239.7306(b), use the following clause:
Supply Chain Risk (DEC 2022)
(a) Definitions. As used in this clause—
Information technology (see 40 U.S.C 11101(6)) means, in lieu of the definition at FAR 2.1, any equipment, or interconnected system(s) or subsystem(s) of equipment, that is used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency.
(1) For purposes of this definition, equipment is used by an agency if the equipment is used by the agency directly or is used by a contractor under a contract with the agency that requires—
(i) Its use; or
(ii) To a significant extent, its use in the performance of a service or the furnishing of a product.
(2) The term “information technology” includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
(3) The term “information technology” does not include any equipment acquired by a contractor incidental to a contract.
Supply chain risk means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).
(b) The Contractor shall mitigate supply chain risk in the provision of supplies and services to the Government.
(c) In order to manage supply chain risk, the Government may use the authorities provided by 10 U.S.C. 3252. In exercising these authorities, the Government may consider information, public and non-public, including all-source intelligence, relating to a Contractor's supply chain.
(d) If the Government exercises the authority provided in 10 U.S.C. 3252 to limit disclosure of information, no action undertaken by the Government under such authority shall be subject to review in a bid protest before the Government Accountability Office or in any Federal court.
(End of clause)
Sections it refers to
- 239.7306 Solicitation provision and contract clause.
← 252.239-7017 Notice of Supply Chain Risk. · 252.241-7000 Superseding contract. →
Rule changes for DFARS Part 252
- Defense Federal Acquisition Regulation Supplement: Modifications to Printed Circuit Board Acquisition Restrictions (DFARS Case 2022-D011) ↗ · proposed 2026-07-02 · comments due 2026-08-31
- Defense Federal Acquisition Regulation Supplement: Certification Requirement for Military Recruitment Advertising (DFARS Case 2024-D022) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Small Purchase Exception for the Acquisition of U.S. Flags (DFARS Case 2024-D013) ↗ · proposed 2026-06-25 · comments due 2026-08-24
- Defense Federal Acquisition Regulation Supplement: Mitigating Risks Related to Foreign Ownership, Control, or Influence (DFARS Case 2021-D011) ↗ · proposed 2026-05-07 · comments due 2026-07-06
- Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) ↗ · final rule 2025-09-10 · effective 2025-11-10
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023); Correction ↗ · final rule 2025-08-28 · effective 2025-08-28
- Defense Federal Acquisition Regulation Supplement: Disclosure of DoD Funding in Technical Publications (DFARS Case 2024-D003) ↗ · proposed 2025-08-25 · comments due 2025-10-24
- Defense Federal Acquisition Regulation Supplement: Limitation on Certain Institutes of Higher Education (DFARS Case 2024-D023) ↗ · final rule 2025-08-25 · effective 2025-08-25
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗. Plain words for the terms: glossary.