FAR Part 40, titled “Information Security and Supply Chain Security,” is a new part of the Federal Acquisition Regulation that took effect March 13, 2026. It gives the government a single home for security-related procurement rules that used to sit in scattered corners of the FAR. As written today, it does one operative job: it implements the American Security Drone Act of 2023 by banning federal purchase and operation of drones from certain foreign manufacturers. The rest of the part is scaffolding for rules that will be added later.
What Part 40 Covers Today
Part 40 is designed to reach beyond information and communications technology and cover any product or service that raises a security concern. ICT-specific security policies still live in FAR Part 39, and related rules appear in Parts 4, 24, and 46.
Structurally, the part has three subparts, and only one of them is doing anything right now. Subpart 40.1 is reserved. Subpart 40.3 is reserved. Subpart 40.2 contains the drone prohibitions and exclusions. A 2024 Federal Register notice indicated that other requirements, including the NDAA Section 889 telecommunications ban, will eventually move into Part 40, but that consolidation has not been codified in the final rule.
Defense contractors already see a broader version. A DoD class deviation effective February 1, 2026, tells contracting officers to use a revised Part 40 together with a new DFARS Part 240 covering NIST SP 800-171 assessments, the Cybersecurity Maturity Model Certification, and other information security requirements. If you work on DoD contracts, expect those wider requirements to appear in solicitations before the civilian FAR catches up.
The Drone Prohibition
The active rule in Subpart 40.2 prohibits agencies from procuring or operating unmanned aircraft systems manufactured or assembled by a “covered foreign entity.” A covered foreign entity is any entity on the list maintained by the Federal Acquisition Security Council and published in the System for Award Management at sam.gov. Before bidding a drone-related task or buying a UAS for federal work, check that list.
The rule applies to all acquisitions. That includes purchases at or below the micro-purchase threshold and contracts for commercial products and commercial services. There is no small-dollar carve-out. A hundred-dollar drone bought for a survey triggers the same restriction as a large defense buy.
The prohibition phased in. Agencies were first barred from procuring FASC-prohibited drones. Then, beginning December 22, 2025, the ban expanded to cover procuring services to operate those drones and using any federal funds to buy or operate them. Exercising an option on an existing contract counts as extending or renewing it, so agencies cannot ride option years past the rule. These authorities expire December 22, 2028.
Who Is Exempt, and How Waivers Work
Several agencies have built-in exemptions and may still procure and operate covered drones under their existing authorities: the Department of Homeland Security, Department of Defense, Department of State, Department of Justice, Department of Transportation, the National Transportation Safety Board, and the National Oceanic and Atmospheric Administration.
The rule also carves out exceptions for wildfire management and search-and-rescue operations, intelligence activities, and Tribal law enforcement or emergency service agencies. If none of those fit, an agency head can request a case-by-case waiver. A waiver requires approval from the Director of the Office of Management and Budget and notice to the appropriate congressional committees.
Clause 52.240-1 and Flow-Down
Contracting officers must insert the clause at FAR 52.240-1 in all solicitations and contracts, and must assess proposals to confirm that offerors are not proposing to deliver or operate a FASC-prohibited UAS. Any exemption, exception, or waiver has to be documented in the contract file. The clause flows down to subcontracts, including subcontracts for commercial products and commercial services. A prime cannot rely on its own certification and stop asking questions; if a subcontractor shows up on site with a covered drone, the prime’s compliance is compromised.
Related Security Rules That Sit Outside Part 40 for Now
Part 40’s reserved subparts do not mean there are no other supply chain security obligations. Several related rules already run through other FAR clauses and share Part 40’s underlying approach.
FAR 52.204-25 implements Section 889 of the FY2019 NDAA, banning federal procurement of telecommunications and video surveillance equipment or services from Huawei, ZTE, Hytera, Hikvision, and Dahua, along with any entity the Secretary of Defense reasonably believes is owned, controlled by, or connected to the government of a covered foreign country. This one reaches further than most procurement bans: it prohibits contractors from using the covered equipment anywhere in their operations, not only in work for the government.
FAR 52.204-23 bars contracting for any hardware, software, or services from Kaspersky Lab and its covered entities. FAR 52.204-27 prohibits TikTok or any successor ByteDance application on government-owned or government-managed IT, and on contractor equipment used under the contract. Both flow down to all subcontracts, including for commercial products and services.
FAR 52.204-30 implements FASCSA orders. The Secretary of Homeland Security can issue orders for civilian agencies, the Secretary of Defense for DoD and national security systems, and the Director of National Intelligence for the intelligence community. Contractors have an ongoing monitoring duty: search SAM.gov for “FASCSA order,” and re-check at least once every three months during performance. If a new order could affect your supply chain, you must conduct a reasonable inquiry into whether a covered article or prohibited source was provided or used.
None of these currently sit inside Part 40, but the Federal Register notice signaling future consolidation suggests they may migrate. Track them alongside 40.2.
What Non-Compliance Costs
A knowing misrepresentation of compliance can draw a False Claims Act investigation, with civil penalties between $14,308 and $28,619 per false claim plus treble damages on the government’s actual losses. Because the penalty is per claim, false certifications spread across multiple contracts stack quickly.
Administrative remedies run alongside the monetary ones. Debarment blocks a company from all federal contracting and generally lasts up to three years, with certain violations extending to five. The FAR frames debarment and suspension as discretionary actions taken in the public interest for the government’s protection rather than as punishment, but for a business that depends on federal work the effect is the same. Contracting officers can also suspend payments when there is adequate evidence of a compliance failure, subject to notice and an opportunity for discussion except in urgent situations.
What to Do Before Your Next Federal Bid
Start at sam.gov. Pull the American Security Drone Act covered entity list and confirm that no drone you plan to deliver or operate under a federal contract, and none your subcontractors plan to use, comes from a listed manufacturer. While you are there, search “FASCSA order” and set a calendar reminder to repeat the search every three months during performance.
Then look at your subcontracts. Confirm that 52.240-1 flows down for any work touching drones, and that 52.204-23, 52.204-25, 52.204-27, and 52.204-30 flow down where they apply. If you hold DoD contracts, ask your contracting officer which version of Part 40 and which DFARS Part 240 provisions apply under the February 2026 class deviation, because that answer will not match the civilian FAR text.
Documentation is where compliance is usually won or lost. Contractors with strong practices but weak records struggle during audits; contractors with organized files answer a contracting officer’s questions quickly. Build the paperwork habit now, while Part 40 is still narrow. It will not stay narrow for long.