← All briefings

A Map Is Not a Defense: Inside the New Supply Chain EO

On July 21, the President signed an executive order titled “Securing America’s Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials,” and it asks more of defense contractors than any supply chain policy before it. As SecurityWeek reports, contractors must map their critical supply chains end to end, tracing components, equipment, software, and materials back to their origin. The order is a real step forward for the defense industrial base. It is also incomplete in a way worth naming now, before 180 days of policy writing locks in the assumptions: a map tells you where the risk lives. It does not remove it.

What does the executive order actually require?

The centerpiece is an “indentured bill of materials,” documentation the order itself frames as significantly broader than a traditional software bill of materials. Contractors must account for:

  • Software and firmware dependencies, including where they were developed
  • Foreign ownership, influence, and beneficial ownership across suppliers
  • Administrative access arrangements and data-hosting locations
  • Sole-source dependencies, supplier concentration, and countries of origin
  • Changes in corporate control anywhere in the chain

The obligations flow down. Prime contractors, and potentially every subcontractor at every tier, must establish written supplier-vetting procedures, report significant supply chain risks to the Department of War within 15 days of completing vetting, and submit confidential corrective action plans within 45 days. The Secretary of War has 180 days to develop the implementing policies, with regulations due 90 days after that, and tightened waiver restrictions take effect January 1, 2027. The Department also plans to run artificial intelligence tools across the submitted data to surface vulnerabilities and bottlenecks contractors themselves miss.

Why now?

The timing matters. Eight days earlier, on July 13, the Department of War suspended CMMC Phase II requirements that were set to take effect in November, reverting contractors to NIST SP 800-171 Rev 2 self-assessments while a 60-day task force redesigns the program. Taken together, the two moves describe a shift in the compliance center of gravity: away from periodic self-assessment paperwork, toward continuous, verifiable visibility into who and what is actually in the defense supply chain. For the defense industrial base, the message is that knowing your suppliers is no longer a procurement nicety. It is a national security obligation with deadlines attached.

What a map can find, and what it cannot

Supply chain mapping is genuinely valuable. An indentured bill of materials will surface foreign ownership that was buried three tiers down, sole-source dependencies nobody had inventoried, and development work happening in places no program office approved. Those discoveries justify the mandate on their own.

But consider what the map cannot show. More than 40% of reported attacks involve stolen PKI credentials. Static credentials, certificates, service accounts, and machine identities sit in every tier of the defense supply chain, from the prime’s cloud environment down to the firmware build server of a fourth-tier component supplier. No bill of materials lists them. No foreign-ownership disclosure reveals them. An adversary holding a valid credential is invisible to supply chain mapping precisely because the credential is valid: they do not appear as a risk on any report, they appear as an authorized user.

The major supply chain compromises of the last decade were not failures of visibility into suppliers. They were failures of trust architecture. Compromised build systems signed malicious code with legitimate keys. Stolen certificates let implants authenticate as trusted software. Mapping the supply chain after the fact would have documented, in excellent detail, exactly which trusted channel the adversary rode in on.

The question the bill of materials cannot answer

An indentured BOM can trace a component to its origin. It cannot tell you what that component can authenticate to once it is installed. That is the Zero Trust question, and it is the one that determines blast radius when, not if, something in the chain is compromised.

Zero Trust’s core demand, in NIST SP 800-207 and the Department’s own Zero Trust Reference Architecture, is that no session be trusted implicitly and no credential persist as a standing privilege. Measured against that standard, most of the defense supply chain still runs on the opposite model: long-lived certificates, persistent machine identities, and credentials that remain valid for months or years, waiting to be stolen, reused, or quietly exercised by whoever holds them. The new executive order will document that architecture in unprecedented detail. It will not change it.

From visibility to verifiability

This is the layer where AKMSecure works. AKM replaces the static-credential model with autonomously refreshed symmetric keys: every session independently verified, keys refreshed with each session, and no persistent credentials left behind for an adversary to harvest anywhere in the chain. The architecture is quantum-secure by design rather than by bolt-on, operates in air-gapped environments, and fits in an executable under 100kb, small enough for the constrained and embedded devices that populate the lower tiers of the defense supply chain. Provision once, and it runs without human intervention.

For the defense industrial base, the two efforts are complementary and sequential. Mapping tells you who is in your supply chain. Making the credentials in that chain worthless to steal is what turns the map into a defense.

The window is open now

Between the 60-day CMMC task force and the 180-day policy window on the new executive order, the rules governing trust in the defense supply chain are being rewritten this year. Contractors will spend the next two quarters building the visibility the order demands. The ones who come out ahead will use the same window to ask the harder question: once we can see every tier of our supply chain, what are we going to do about the standing credentials in it?

About AKMSecure

AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.

LinkedIn Twitter