Built here. Proven clean.Florida · Texas

For primes and product makers

Every rule you have to meet. One supplier built to meet them.

If you sell UAS, storage, computers or boards into defense or critical infrastructure, these mandates bind you now, and more are coming. Here is each one, what it demands, when it bites, and exactly how we answer it.

Mandate checklist

Your product

UAS, storage, computer or boardWhat we hand you for each rule

  • FCC Covered ListAnswered
  • NDAA 848 · UAS partsAnswered
  • NDAA 5949 · chipsAnswered
  • 10 U.S.C. 4873 · boardsAnswered
  • DFARS 7007 / 7008Answered
  • NDAA 889 · telecomAnswered
  • 1260H · ownershipAnswered
  • NSA assuranceAnswered

Evidence, not a promiseShield report + Component Passport

Per unit

The dates

The clock is already running.

Five deadlines, three of them in the next fifteen months. Dates come from the statutes and rules linked below.

  1. Dec 22, 2025New foreign-made UAS parts blocked (FCC); federal UAS ban in force
  2. June 30, 2026DoD barred from contracting with 1260H-listed companies
  3. Jan 1, 2027Circuit-board ban takes effect; DoD compliance registry opens
  4. June 30, 20271260H ban extends to goods that incorporate listed products
  5. Dec 23, 2027SMIC, CXMT and YMTC chips barred from federal purchases

The mandates

Each rule. What it demands. How we answer it.

Grouped by what you build. Every card links to the statute, rule or official notice behind it.

Uncrewed aircraft and flight controllers

In forceFCC Covered List · December 22, 2025

New foreign-made UAS parts are blocked at the border.

The rule
The FCC added nearly all UAS and critical UAS components made outside the U.S. to its Covered List. Flight controllers, communications systems, navigation systems, sensors and ground stations are named. New foreign-made parts can’t be imported, marketed or sold unless they were already authorized or get a waiver.
Who it binds
Anyone importing or selling UAS or UAS components in the U.S., including UAS makers buying parts.
How we answer it
Our flight controller is built in the U.S. from a licensed design, every chip traced, with a Shield report per unit.
Source: Pillsbury analysis of the FCC public notice
In forceFY2020 NDAA Section 848 · 10 U.S.C. 4872

DoD can’t buy UAS with foreign-made flight controllers.

The rule
The Department of Defense may not procure or operate UAS that use flight controllers, radios, data transmission devices, cameras or gimbals made in a covered foreign country, or ground-control software developed there.
Who it binds
DoD programs, and every UAS maker selling to them.
How we answer it
A U.S.-built flight controller with documented chip origin, so the aircraft you sell to DoD clears this clause.
Source: 10 U.S.C. 4872 at govinfo.gov
In forceAmerican Security Drone Act · FAR 52.240-1 · December 22, 2025

Every federal agency is barred from covered foreign UAS.

The rule
Federal agencies may not procure UAS made or assembled by covered foreign entities, and since December 22, 2025 may not operate them either. The ban is written into contracts through FAR clause 52.240-1.
Who it binds
All executive agencies and their contractors, including grant-funded state and local programs.
How we answer it
Component-level evidence for your airframe: where each board came from and what runs on it.
Source: Federal Register rule at govinfo.gov

Storage and semiconductors

Effective Dec 23, 2027FY2023 NDAA Section 5949 · proposed FAR rule, February 17, 2026

Chips from SMIC, CXMT and YMTC come out of federal purchases.

The rule
Agencies will be barred from buying electronic products that contain semiconductors designed, produced or provided by SMIC, CXMT or YMTC or their affiliates. The proposed rule requires bidders to make a reasonable inquiry into their supply chain, certify, and report a covered chip within 72 hours of finding one.
Who it binds
Any supplier of electronics to the federal government. CXMT and YMTC are memory makers, so storage is squarely in scope.
How we answer it
Every chip in our drives is traced to its maker and recorded in the Component Passport. Your reasonable inquiry is done before you bid.
Source: Covington analysis of the proposed rule

Every circuit board

Effective Jan 1, 202710 U.S.C. 4873 · FY2021 NDAA Section 841 · rulemaking under way

DoD can’t buy covered circuit boards from China, Russia, Iran or North Korea.

The rule
The prohibition turns on where the bare board was fabricated. DoD’s July 2026 notice points to a certification-based rule that may lean on the IPC-1791 trusted-assembly and IPC-1782 traceability standards, with recordkeeping requirements. It applies to contracts signed after the final rule.
Who it binds
DoD contractors supplying boards, or products that contain them.
How we answer it
Boards assembled in the U.S., with the fabrication origin of every bare board documented and retained. We trace the board, not just the parts on it.
Source: Crowell & Moring on the July 2026 notice
In forceDFARS 252.246-7007 and 252.246-7008

Electronic parts must be traceable to the original manufacturer.

The rule
Contractors must run a counterfeit-part detection and avoidance system with risk-based tracking of electronic parts from the original manufacturer to government acceptance, buy from original manufacturers or authorized suppliers, and flow the clause down to subcontractors.
Who it binds
DoD contractors and their suppliers of electronic parts and assemblies.
How we answer it
Parts bought through authorized channels, lots hashed and photographed at intake, chain of custody in the Passport. We hand you the traceability you have to flow down.
Source: DFARS 252.246-7008 at acquisition.gov
In forceFY2019 NDAA Section 889 · FAR 52.204-25

No covered telecom or surveillance gear, anywhere inside.

The rule
Federal agencies can’t buy equipment, systems or services that use covered telecommunications or video-surveillance equipment as a substantial or essential component, and contractors must report it if they find it.
Who it binds
Every federal contractor. The camera inside the Royal Navy’s uncrewed boats shows how it hides inside a part.
How we answer it
Our component trace reaches the modules inside your product, so the representation you sign is backed by a parts list, not a supplier’s promise.
Source: FAR 52.204-25 at acquisition.gov

Computers and systems

PhasedFY2026 NDAA Section 850

Computers from China-owned companies are being phased out.

The rule
A phased restriction on buying computers and printers where the manufacturer, bidder or offeror is owned or controlled by China, including through subsidiaries, regardless of where the unit was assembled.
Who it binds
DoD and its suppliers of computers and printers.
How we answer it
A U.S.-owned company building onboard AI computers in the U.S., with government laptops on the roadmap, and ownership and assembly both documented.
Source: King & Spalding on the FY2026 NDAA
In forceFY2024 NDAA Section 805 · 1260H list · June 30, 2026 and June 30, 2027

DoD can’t contract with listed Chinese military companies.

The rule
Since June 30, 2026, DoD may not enter, renew or extend contracts with companies on the 1260H list or entities they control. From June 30, 2027 the ban extends to goods and services that incorporate their products, with an exception for components.
Who it binds
DoD and its prime contractors.
How we answer it
We’re U.S.-owned and U.S.-operated, and we document who made every part we use.
Source: Section 805 page at businessdefense.gov

Assurance expectations

In forceDoDI 5200.44 · NSA/JFAC ASIC LoA1 best practices · August 25, 2026

Trusted suppliers, or your own validation of the gaps.

The rule
DoD programs must use suppliers accredited through the trusted microelectronics process unless waived, and NSA’s new guidance says that where accredited suppliers don’t cover the whole lifecycle, programs should add their own validation of the steps outside it.
Who it binds
DoD programs using custom microelectronics, and the contractors supporting them.
How we answer it
Firmware inspection, source review and a signed Shield report are the added validation. We give the program office evidence, not a promise.
Source: NSA LoA1 best practices (PDF)
ExpectedNIST SP 800-161 · SBOM minimum elements · signed updates

Program offices ask for SBOMs and country of origin. Most get slideware.

The rule
Federal supply-chain risk management practices and software bill-of-materials expectations mean buyers increasingly ask where each part came from, what software is on it, and whether updates are signed.
Who it binds
Suppliers to agencies and primes that run supply-chain risk management programs.
How we answer it
A Component Passport per part number with hashes, an SBOM, and signed, attestable firmware. We’re not a CMMC assessor; we produce the evidence those programs consume.
Jan 1, 2027FY2026 NDAA Section 836

A public registry of compliant suppliers opens.

The rule
DoD must open a voluntary, public repository where suppliers register and attest that their products meet covered sourcing requirements, possibly alongside ownership, CAGE and NAICS data.
Who it binds
Any supplier that wants to be found.
How we answer it
We’ll register every product line as the repository opens, so you can point to the record instead of writing a memo.
Source: King & Spalding on the FY2026 NDAA

Read this before you quote us

Rules move. Three of these are proposed or still in rulemaking, and effective dates can shift. We aren’t a certification body and we don’t sign your compliance for you. We produce the evidence your certification rests on. Last reviewed October 2026.

The test behind every rule

Four questions. If they aren’t answered, you don’t have a clean claim. You have a PDF.

  1. 01Where did it come from?Every chip and every board, traced to its maker.
  2. 02What software is on it?Firmware inspected, hashed and signed.
  3. 03What doors are still open?Debug consoles, test commands, unexpected hosts, found and listed.
  4. 04Can you prove the work?A signed Shield report and a Component Passport a contracting officer can put in the file.

What you get

What a contracting officer can put in the file.

The same evidence pack with every product we build, and with every unit we certify on your line.

Shield report

A signed, structured report per part number and firmware revision.

Component Passport

Hashes, SBOM, chip origin and watch items, kept current as revisions ship.

Firmware attestation

A hash captured at production and software that verifies it in the field.

Signed firmware

Signed with our hardware security module, post-quantum ready, with U.S.-held keys.

Country of origin, per chip

Not a declaration for the whole product. A record for each part on it.

Bring us the product. We’ll bring the proof.

Tell us what you build and who you sell it to. We’ll map it to every rule above and show you the evidence pack for each one.