Skip to main content
Rule Updates

DoD Expands FOCI Reviews Beyond Cleared Contractors: What the New Instruction Means

A quietly issued DoD Instruction extends Foreign Ownership, Control or Influence reviews to all DoD contractors — not just those holding clearances. Here's the supply-chain picture.

Brandon Hancock, J.D., CMMC-RPPublished May 13, 2024Updated June 5, 20266 min read

Without much fanfare, on May 13, 2024, the Department of Defense published a new DoD Instruction (DoDI) that broadens who gets scrutinized for foreign ties. The headline: Foreign Ownership, Control or Influence (FOCI) review — long a feature of the cleared contractor world — is being extended toward the broader DoD contractor base, including companies doing unclassified work. Here is what defense contractors and their subs should understand.

The Problem DoD Is Targeting

DoD's concern is the integrity of the defense industrial base (DIB) supply chain. As the new guidance frames it, supply-chain risk is asymmetric — a vulnerability can be introduced at any tier, from a prime down to a small business, and in classified or unclassified work alike. A component, a software dependency, or an ownership stake at a lower tier can become a national-security problem regardless of clearance status.

What Changes

Historically, FOCI analysis applied to contractors that hold facility clearances and access classified information, administered through the security-clearance system. The new DoDI expands that review posture so that foreign ownership and influence concerns can be examined across a wider population of DoD contractors — reaching companies that previously sat outside the cleared-contractor framework.

In practice, this means:

  • More entities may face FOCI-style scrutiny, including those performing only unclassified work.
  • Additional filings and information requests about ownership, control relationships, and foreign connections.
  • A larger role for the Defense Counterintelligence and Security Agency (DCSA) in reviewing supply-chain and foreign-influence risk across tiers.

How This Fits the Cyber and Supply-Chain Picture

FOCI is not a cybersecurity rule, but it lives in the same neighborhood. DoD increasingly treats who controls a supplier as inseparable from how secure that supplier is — both are supply-chain integrity questions. Defense contractors already managing DFARS 252.204-7012 and CMMC, SPRS scoring, and NIST SP 800-171 should view FOCI review as another layer of the same diligence: proving the trustworthiness of your company and your lower tiers.

What to Do Now

  • Map your ownership and control structure, including foreign investors, board seats, and significant foreign contracts or debt.
  • Know your lower tiers. If you flow work to subs, understand their ownership too — risk at any tier can reach the prime.
  • Prepare for additional filings. Keep organizational records, ownership disclosures, and foreign-relationship documentation current and retrievable.
  • Coordinate security and corporate functions. FOCI questions cut across legal, security, and finance — assign an owner before a request arrives.

Key Takeaways

  • A May 13, 2024 DoD Instruction extends FOCI-style review beyond cleared contractors toward the broader DoD contractor base — including unclassified work.
  • Expect additional filings and DCSA reviews focused on foreign ownership and supply-chain integrity.
  • Treat FOCI as part of the same supply-chain trust picture as your cyber obligations.

See related defense obligations on the Defense industry page, or confirm your full requirement set with Find My Requirements. Because implementation details evolve, confirm the current DoDI text and any DCSA guidance before acting.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?

Keep reading

Rule UpdatesA New Supply-Chain Prohibition Regime Just Opened Its Comment Window — and a FAR Rule Is Already ScheduledMost contractors read "bulk-power system" and stop. That is a mistake. The executive order behind this rulemaking defines "procurement" in federal-acquisition terms, tasks the FAR Council with a rule, and reaches installation services — which is to say, it reaches contractors.September 10, 2026 · 7 min readRule UpdatesMaryland Just Widened Which State Contracts Carry Cyber and Privacy Clauses — Effective October 1The Maryland Data Privacy and Protection Act of 2026 (Chapter 435, House Bill 264) takes effect October 1, 2026 and rewrites State Finance and Procurement § 13-115. Collecting, storing, or processing personal information is now an independent trigger for mandatory security, data collection, and privacy requirements in Maryland State contracts — no connection to a State system required — and the statutory definition of personal information expanded at the same time.August 31, 2026 · 7 min readRule UpdatesCISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In ScopeCISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.August 27, 2026 · 7 min read