A community resource for the acquisition workforce not a .gov website
part52.dev Federal Acquisition Clause Monitor
R-DFARS Clause

252.239-7018

Supply Chain Risk
Source deviation PDF →
Effective Date
February 1, 2026
Deviation
Versions
1

This text is not in eCFR or DITA. It is extracted from the Revolutionary FAR Overhaul deviation guide for FAR Part 40. The parsed text is a convenience layer; the Source PDF tab is authoritative. Always verify against the official deviation PDF.

As prescribed in 240.271-7(b). See the Prescription tab for the prescribing policy text.

SUPPLY CHAIN RISK (DEC 2022)

  1. (a) Definitions. As used in this clause— Information technology (see 40 U.S.C 11101(6)) means, in lieu of the definition at FAR 2.1, any equipment, or interconnected system(s) or subsystem(s) of equipment, that is used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the agency.
    1. (1) For purposes of this definition, equipment is used by an agency if the equipment is used by the agency directly or is used by a contractor under a contract with the agency that requires—
      1. (i) Its use; or
      2. (ii) To a significant extent, its use in the performance of a service or the furnishing of a product.
    2. (2) The term “information technology” includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
    3. (3) The term “information technology” does not include any equipment acquired by a contractor incidental to a contract. Supply chain risk means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).
  2. (b) The Contractor shall mitigate supply chain risk in the provision of supplies and services to the Government.
  3. (c) In order to manage supply chain risk, the Government may use the authorities provided by 10 U.S.C. 3252. In exercising these authorities, the Government may consider information, public and non-public, including all-source intelligence, relating to a Contractor's supply chain.
  4. (d) If the Government exercises the authority provided in 10 U.S.C. 3252 to limit disclosure of information, no action undertaken by the Government under such authority shall be subject to review in a bid protest before the Government Accountability Office or in any Federal court.

Prescription: 240.271-7 Solicitation provision and contract clause

As prescribed in 240.271-7(b). Scope applicability here before applying the clause.

  1. (b) Insert the clause at 252.239-7018, Supply Chain Risk, in solicitations and contracts, including solicitations and contracts using FAR part 12 procedures for the acquisition of commercial products and commercial services, for information technology, whether acquired as a service or as a supply, that is a covered system, is a part of a covered system, or is in support of a covered system, as defined at 240.271-2.

Version history

One version on record, first captured 2026-06-11 15:53:20, effective February 1, 2026.

Clause text (pages 56–57)

Rendered from the deviation PDF. Open the full PDF.

Source page for 252.239-7018
Source page for 252.239-7018