Beijing’s Backdoor to the U.S. Defense Supply Chain – New DFARS requires contractors to slam it shut by getting Chinese military companies out of their supply chain before June 2027

By: Margaret M. Cassidy & Andrew Swick

Acting on directives from Congress over the course of several National Defense Authorization Acts, the Department of Defense is on the move to get Chinese military companies’ products and services out of the U.S. defense industrial base.

This is a vital exercise for U.S. national defense.

For defense contractors and others in the DoD supply chain, delivering on this requires thoughtful action to eliminate the prohibited Chinese military companies (CMC) from the supply chain.

The Ban: Entities, Products, and Services

The Defense Federal Acquisition Regulation Supplement (DFARS), Subpart 240.70 Prohibition on Procurement Related to Chinese Military Companies, bans CMC products and services as well as CMCs. (Technically, these requirements are in a DFARS deviation that went into effect June 2026.) The bans apply to all DoD contracts and subcontracts, including commercial contracts and subcontracts. Prime contractors must flow the ban down to subcontractors through the entire supply chain.

Products and Services Ban: Contractors and subcontractors are banned from purchasing “covered products and services” from CMCs. Covered products and services are items on the U.S. Munitions List of the International Traffic in Arms Regulations (ITAR).

The product ban does not apply:

  • To components or parts of covered products unless the component or part is on the U.S. Munitions List or a Commerce controlled military-related item listed in the 600 series section of the Commerce Control List;
  • If the products are purchased in connection with a U.S. military aircraft or vessel visit to China;
  • If the products are purchased for testing; or
  • If the products are purchased to gather intelligence.

Entity Ban:

After June 30, 2027, contractors and subcontractors cannot purchase any products or services from a CMC as defined by the DFARS.

The List of Chinese Military Companies

The FY21 National Defense Authorization Act (NDAA) directed DoD, in Section 1260H, to create a list of Chinese Military Companies.

DoD, as keeper of the list. identifies companies that are owned, controlled, or affiliated with China’s military, or that contribute to China’s military-civilian integration strategy. The list is designed to increase transparency around Chinese companies that support the People’s Liberation Army and keep them out of the U.S. defense and intelligence supply chain.

If it were just a list to check, defense contractors would be able to check the list and then compare against their supply chain.

But it is more challenging than that, because the DFARS defines a CMC as an entity on one of these lists:

  • DoD’s CMC list;
  • the U.S. Treasury’s list of Chinese Military-Industrial Complex Companies; and
  • the U.S. Department of Commerce’s list of banned Chinese entities.

Also, defense contractors and subcontractors throughout the supply chain are banned from making purchases from:

  • any entity that is owned, controlled, or affiliated with the Chinese government or its armed forces that the U.S. identified as a security risk; or
  • any entity that is a subsidiary, affiliate, parent or holding company of a company identified as a security risk or any entity controlled by an entity on one of the above lists.

The definition of “control” in this DFARS means having direct or indirect power, whether exercised or not, to determine, direct, decide or influence major business decisions, for example having:

  • Majority or significant minority ownership interests;
  • Board representation;
  • Proxy voting rights;
  • Contractual rights; or
  • Formal or informal agreements to act together.

Chinese Response

In an interesting turn of events, China responded by:

  • Banning U.S. companies from Chinese government procurement;
  • Prohibiting the export of China-origin dual-use products and technologies to certain U.S. companies; and
  • Some Chinese companies, like DJI a global Chinese drone manufacturer, are suing in U.S. courts, arguing to be removed from the DoD’s CMC list.

Lobbyists

DoD and defense contractors are also prohibited from contracting with any entity if the entity is in a contract with a lobbyist that lobbies on behalf of a CMC. 10 U.S.C. § 4663.

The prohibition does not apply if you make “reasonable inquiries” to see whether the lobbyist was lobbying for a CMC and your due diligence reveals they are not.

DoD’s Guidance on Ferreting Out CMCs

DoD recently announced it launched a website that “provides critical resources for companies doing business with the Department.” Beyond linking to the Federal Register that lists the CMCs and providing an email for questions or to request a waiver, the site does not provide much guidance.

Waivers may be applied for if time is needed to come into compliance with these requirements.

DoD’s PGI 240.7003-4 provides some guidance—a list of links to other federal agencies that have industry guidance on how to shore up national security in a company’s operations.

Key Takeaways

Given this, the question for defense contractors and those in the defense supply chain is not, “are our suppliers on the CMC list?”But rather:

  1. Have all suppliers been checked against all the lists?
  2. Does any CMC company have ownership, affiliation or control over our suppliers?

Some Actions to Consider

  1. Map your supply chain, and put a process in place to keep the map current.
  2. Screen every supplier against all the lists the DFARS incorporates—the DoD CMC list, the U.S. Treasury’s Chinese Military-Industrial Complex Companies list, and the U.S. Department of Commerce’s entity list.
  3. Go beyond name-matching: determine whether any CMC owns, controls, or is affiliated with your suppliers, applying the DFARS definition of “control.”
  4. If China is in your supply chain, layer in restricted-party screening, export-control checks, and government-procurement restrictions.
  5. Document all your due diligence on whether any of your lobbyists represent a CMC—you can’t use them if they do.
  6. Update third-party questionnaires, certifications, onboarding process and monitoring to identify relations with CMCs
  7. Make sure screening is continuous, not a one-time check.
  8. Define a process for clearing “hits” – it will be require more analysis then comparing two names to determine if they match.
  9. Update subcontracts to flow the requirements down, including into commercial-item buys—do not assume a commercial exception saves you.
  10. Look for the DFARS in your contracts: the Chinese military company representation (DFARS 252.240-7996), the lobbying representation (DFARS 252.240-7995), and the prohibition clause itself (DFARS 252.240-7007).
  11. Use your ITAR discipline: the bill-of-materials mapping, country-of-origin tracing, and supplier content-and-jurisdiction statements you already maintain are the tools that will surface CMCs in your supply chain.
  12. Keep compliance documentation audit-ready, including evidence of screening, due diligence, and any waiver requests.
  13. Track waiver timelines and apply early if you need time to reach compliance.

My New Stories