Key Takeaways
- The Department of Defense recently issued a proposed rule that would require any defense contractor with a contract above $5 million to undergo a review for foreign ownership, control or influence (FOCI).
- The proposed rule would significantly expand the current requirements for FOCI reviews, which apply only to classified contracts, and potentially require onerous mitigation to be completed shortly after contract award.
- Contractors should start taking steps today to understand their potential FOCI exposure and determine appropriate mitigation on a reasonable timeline.
On May 7, the Department of Defense (DoD) issued a proposed rule that would extend foreign ownership, control or influence (FOCI) requirements to DoD contractors and subcontractors performing unclassified contracts exceeding $5 million, including commercial product and service contracts specifically identified by the designated senior DoD official on a case-by-case basis, as well as certain contracts otherwise identified as sensitive. The long-awaited rule implements Section 847 of the FY 2020 National Defense Authorization Act (NDAA) and Section 819 of the FY 2021 NDAA.
This proposed rule would mark a significant expansion of DoD’s oversight of the Defense Industrial Base (DIB). By DoD’s own estimates, it would increase the number of required FOCI reviews from approximately 2,500 contractors performing classified work to nearly 40,000 companies, plus any additional commercial contractors identified on a case-by-case basis.
Background
In the FY 2020 NDAA, Congress directed DoD to promulgate contract clauses requiring disclosures related to changes in FOCI or beneficial ownership during contract performance and to enforce effective mitigation of FOCI risks throughout the life of the contract or subcontract. The following year, in the FY 2021 NDAA, Congress further required DoD to mandate periodic FOCI reporting. In May 2024, DoD issued DoD Instruction 5205.87, which established procedures for the disclosure of beneficial ownership and FOCI information and for the mitigation of related risk.
Now, five years after the first NDAA provision, DoD has issued a proposed rule to implement Congress’ directive. The proposed rule would add several sections to the Defense Federal Acquisition Regulation Supplement (DFARS), including two new contract clauses.
At the center of the new framework is the “Certificate Pertaining to Foreign Interests” (SF-328).
What Does the Proposed Rule Require?
The proposed rule would prohibit DoD from awarding, modifying or exercising an option on any contract, task order or delivery order valued above $5 million unless the contractor has an “eligible status” in the National Industrial Security System (NISS) or an exception applies. NISS is the Defense Counterintelligence and Security Agency’s (DCSA) web-based platform for managing and overseeing the industrial security of contractors working with classified information.
The solicitation provision, DFARS 252.240-70XX, clarifies that DoD may award contracts only to contractors that (1) have submitted an SF-328, Certificate Pertaining to Foreign Interests, and supporting documentation – including contact information for each foreign beneficial owner – in NISS and (2) either have been determined not to present a risk related to FOCI or beneficial ownership or have agreed to implement “risk mitigation strategies” identified by the requiring activity or program office no later than 90 days after award.
If the requiring activity, based on DCSA input, determines that FOCI or beneficial ownership presents a risk – or potential risk – to national security, but that the risk can be mitigated, the offeror must agree to implement a mitigation strategy within 90 calendar days of award.
In addition, the proposed rule requires contractors to update their disclosures whenever any changes in FOCI or beneficial ownership occur. This includes any notifications that contractors receive from subcontractors.
Who Does the Proposed Rule Apply To?
First, the proposed rule would apply to any “covered contractor or subcontractor,” defined as any company that is an existing or a prospective DoD contractor or subcontractor, at any tier, under a contract valued above $5 million. While that threshold appears to be relatively low, it comes directly from the FY 2020 NDAA and, thus, cannot be changed as part of the final rule absent congressional intervention.
Second, as that definition makes clear, the proposed rule extends to subcontractors and suppliers. It requires prime contractors to ensure that before awarding a subcontract exceeding $5 million, the subcontractor has an eligible status in NISS.
Third, the proposed rule may also apply to covered contractors supplying commercial products or commercial services if a designated senior DoD official determines that the contract presents a risk – or potential risk – to national security or a potential compromise of sensitive data, systems or processes.
What Is FOCI?
Until now, FOCI obligations have generally applied only to classified contracts, requiring beneficial ownership disclosures from government contractors and subcontractors holding a facility security clearance and performing cleared contracts or subcontracts. Beneficial ownership extends beyond what may traditionally be viewed as an owner to include any person who, directly or indirectly, through any contract, arrangement, understanding, relationship or otherwise, possesses or shares voting power (direct or indirect), including the power to vote or direct the voting of such security, or investment power, including the power to dispose of or direct the disposition of such security. Specifically, for example, required disclosures include:
- Foreign ownership of more than 5 percent of an organization’s ownership shares
- The organization’s direct or indirect ownership of more than 10 percent of any foreign interest
- Whether any foreign person serves as a member of the organization’s governing body or holds a management position
- Existence of contracts with foreign persons
- Indebtedness, liabilities or obligations to foreign persons
- Receipt of 5 percent of annual revenue from one foreign person or 15 percent from foreign persons in the aggregate.
If DCSA in its discretion deems any of these disclosed conditions a risk to contract performance or the security of data, mitigation of these conditions may be required as a condition of award. Contractors unfamiliar with DCSA’s FOCI mitigation process should therefore be prepared not only to make the required disclosures but also to assess the existence of potential risk and the organization’s willingness to mitigate disclosed relationships and arrangements that may be very common in commercial markets. In practice, DCSA follow-up often extends well beyond the four corners of the SF-328.
Open Issues
The proposed rule leaves significant room for interpretation and raises several practical questions.
First, the proposed rule does not explain how the government will marshal sufficient personnel to handle this dramatic expansion of FOCI reviews. By its own estimate, the proposed rule would require disclosures from an additional 37,000 contractors. At the same time, it would require contracting officers to confirm compliance before awarding a contract or taking routine actions such as issuing modifications or exercising options. That combination will create substantial pressure to review contractor disclosures quickly and efficiently. Yet, DCSA was recently criticized by the Government Accountability Office for inadequate staffing to meet even its current investigative obligations. It remains unclear how DCSA’s staffing constraints will affect the proposed rule’s implementation and whether they would disrupt the timely award of tens of thousands of important DOD contracts.
Second, the proposed rule offers little guidance for contractors that sell only commercial products or commercial services. Although the proposed rule makes clear that commercial contractors may be swept in on a case-by-case basis, it does not identify the “senior DoD official” who will decide whether the clauses should apply. Nor does it define the operative standard – whether the contract involves a risk or potential risk to national security or a potential compromise of sensitive data, systems or processes. What qualifies as a “potential risk”? What constitutes “sensitive” data, systems or processes? In practice, that ambiguity affords broad discretion to an unidentified official.
Third, the proposed rule creates multiple opportunities for companies to receive inconsistent direction regarding FOCI mitigation. Historically, DCSA has overseen the FOCI risk analysis and mitigation process for companies seeking security clearances. Under the proposed rule, DCSA would provide input on whether mitigation is necessary, but the contracting officer appears to retain final authority. That structure could produce inconsistent recommendations and requirements.
Fourth, the proposed rule leaves several key terms undefined, even though the proposed rule’s scope turns on how those terms are interpreted. For example, the proposed rule generally states that a company is under FOCI if a foreign interest has the power to direct or decide matters affecting the company’s management or operations “in a manner that may result in a risk or potential risk to national security or potential compromise of sensitive data, systems, or processes,” yet it does not define “risk to national security,” “sensitive data,” “sensitive systems” or “sensitive processes.” By contrast, the NISPOM’s FOCI mitigation regime for cleared contractors focuses in part on unauthorized access to classified information – a far more clearly defined category.
Comments on the proposed rule are due by July 6, and DoD is expected to issue a final rule later this year.
Conclusions and Immediate Next Steps
The immediate takeaway is that prime contractors and subcontractors in the DIB should begin preparing now rather than wait for a final rule. At a minimum, that preparation should include internally completing the form SF-328, using this information to assess potential FOCI exposure and gathering supporting documentation. Companies that are likely to be viewed as under FOCI should also begin evaluating mitigation strategies well in advance; once the rule is finalized, an inability to mitigate FOCI promptly could jeopardize awards or delay contract actions.
Although DoD’s implementation of this regime remains uncertain, contractors should assume for now that the department will administer these requirements aggressively. That approach would be consistent with the government’s broader focus on securing the defense supply chain and with DCSA’s increasing willingness to require mitigation based on foreign influence alone, even absent documented foreign ownership or control.
Companies still have an opportunity to shape the rule’s ultimate scope and impact. Comments may be submitted here.
BakerHostetler attorneys have extensive firsthand experience helping clients address DCSA requirements relating to FOCI and beneficial ownership disclosures. For assistance or questions, please contact Kevin Barnett, Joel Roberts, Melissa Mannino or another member of the firm’s Government Contracts or International Trade and National Security teams.




