Quick answer: Supplier risk in the defense industrial base has outgrown manual, spreadsheet-based review. The Department of War loses visibility beyond tier two despite supply chains that run five to six tiers deep (GAO-25-107283), GAO has documented a “dangerously high dependency” on China for materials in critical U.S. weapon systems across an estimated 200,000-plus suppliers (GAO), and DCSA’s FOCI review population is set to expand roughly three-fold under a proposed 2026 rule (Congressional Research Service, R48110). None of that is reviewable at scale with an annual questionnaire and a shared spreadsheet.


A spreadsheet and an annual vendor survey used to be a defensible supplier risk program. If a supplier looked financially sound, offered competitive pricing, and didn’t raise obvious flags, that was usually enough. What happened below the surface, or upstream in their own supply chain, was their problem to manage.

That model is now failing in ways the defense industrial base’s own oversight bodies are actively documenting. Here’s the data.

The risk surface expanded faster than the tools built to track it

Foreign dependency is deeper than most supplier files reflect. GAO has documented a “dangerously high dependency” on China for materials used in critical U.S. weapon systems, spanning an estimated 200,000-plus suppliers that help produce weapon systems and noncombat goods, with GAO noting the federal government’s primary procurement database provides little visibility into where those goods are actually manufactured or whether upstream suppliers are foreign (GAO-25-107283). RAND testimony puts a finer point on one category: China holds a 30-40% market share of the world’s legacy semiconductors, a component embedded deep in defense electronics (RAND). The Department of Defense’s own 2024 National Defense Industrial Strategy states plainly that DoW’s dependence on adversarial sources, particularly for microelectronics and advanced batteries, is a “mounting national security challenge” (CSIS). A supplier file that only captures a direct vendor’s home address misses all of this.

Sub-tier visibility is where most programs actually break down. The average Department of Defense supply chain runs five to six tiers deep, but the GAO found DoW’s own visibility drops off beyond tier two (GAO-25-107283). DoW recognized this gap itself: in 2020 it stood up the Supply Chain Risk Evaluation Environment (SCREEn) specifically to gain visibility into F-35 microelectronics and propulsion supply chains and flag IP theft and FOCI risk that manual review had been missing (CSIS). If the Pentagon needed purpose-built tooling to see past tier one, a shared spreadsheet isn’t going to get a prime contractor there either.

Cybersecurity compliance has a massive readiness gap behind it. The DoW’s CMMC 2.0 final rule, effective November 2025, made cybersecurity certification a contractual prerequisite for nearly all DoW contractors and their supply chains, an estimated 80,000 companies will need Level 2 certification. As of the most recent CyberAB town hall, only 431 organizations, about 0.5%, had achieved it (Buchanan Ingersoll & Rooney). That gap didn’t happen because contractors weren’t paying attention. It happened because verifying cyber posture across an 80,000-company supply base isn’t a task manual attestation was ever built to handle.

Regulatory and audit pressure keeps compounding, not resetting

FOCI oversight is a useful case study in how fast the compliance surface is growing. DCSA currently subjects roughly 13,000 contractors to FOCI review, conducting full reviews on only 500 to 600 of them in a given year. A proposed 2026 DFARS rule would extend FOCI disclosure requirements to unclassified “covered contracts” over $5 million, pulling in an estimated 37,740 additional entities, more than half of them small businesses, and pushing DCSA’s annual review volume toward 7,000 to 8,000 contractors (Congressional Research Service, R48110). That’s close to a three-fold jump in review scope on the current process, without a three-fold increase in reviewers.

Industry feels this pressure directly. NDIA’s Vital Signs 2026 report, drawing on a record 1,646 respondents from government, industry, and academia, found that 50% of private-sector respondents cite the burden and risk of compliance with government contracting requirements as one of their most pressing issues, behind only procurement process complexity (66%) and federal budget uncertainty (55%) (NDIA Vital Signs 2026). Compliance isn’t a background cost anymore. It’s one of the top three problems the industrial base says it’s facing.

Why spreadsheets and manual review can’t keep up

Line up the numbers and the structural problem is clear. DCSA already reviews only 500 to 600 of the 13,000 contractors currently in scope for FOCI review in a typical year, and that population is about to grow roughly three-fold (CRS, R48110). CMMC verification has an adoption gap measured in fractions of a percent against an 80,000-company requirement. And CSIS’s ongoing analysis of the industrial base has found that DoW isn’t prepared to rapidly surge production against a capable adversary: production lines have gone cold, parts have become obsolete, and sub-tier suppliers have consolidated or gone out of business entirely, largely because the base has been optimized for least-cost efficiency rather than resiliency (CSIS).

None of that is a headcount problem you solve by hiring more analysts to fill out more spreadsheets. It’s a systems problem: risk data that lives in disconnected files, updates on inconsistent schedules, and has no mechanism for continuous monitoring between review cycles. A supplier can clear review in January and pick up a sanctioned investor, a failed CMMC assessment, or a tier-two factory closure in February, and nothing in a static file will surface that until the next scheduled check, if there is one.

What replaced the spreadsheet

The platforms built to close this gap, including the purpose-built tools DoW itself uses, share a few capabilities a spreadsheet structurally cannot replicate:

  • Data integration that connects, cleans, and analyzes data across many sources continuously, instead of relying on periodic exports and self-reported updates.
  • Configurable, risk-weighted alerting that flags what matters to a specific portfolio, a critical vendor, a sanctioned jurisdiction, instead of a flat, one-size-fits-all review schedule.
  • Workflow and case management that gives risk, procurement, cybersecurity, and legal a shared, auditable view instead of five separate trackers.
  • FOCI and sub-tier mapping that traces ownership and upstream relationships structurally, rather than relying on what a supplier chooses to disclose.

None of that is a knock on the teams running spreadsheet-based programs today. It’s a reflection of how fast the compliance surface has widened in a short window of time, and the government’s own oversight bodies are the ones documenting it.

Where this series goes next

This post is part two of a six-part series on evaluating supplier intelligence infrastructure:

  1. Build vs. Buy: A Supplier Intelligence Decision Framework
  2. Why Supplier Risk Has Outgrown the Spreadsheet Era (This Post)
  3. What It Actually Takes to Build Supplier Intelligence In-House (Coming soon)
  4. The Real Cost of Building vs. Buying Supplier Intelligence (Coming soon))
  5. When Building Makes Sense: Hybrid Models for Supplier Intelligence (Coming soon)
  6. How to Evaluate a Supplier Intelligence Vendor: A Buyer’s Framework (Coming soon)

See how Craft maps FOCI, sub-tier, and cyber risk continuously, without the spreadsheet. Request a demo against your current supplier portfolio.