The Federal Acquisition Security Council (FASC) has proposed rules that would require federal contractors to share supply chain risk information with the government. For prime contractors and critical subcontractors, this creates immediate questions: what information will you be required to disclose, what protections exist for proprietary vendor data, and who inside your organization is accountable for getting this right?

The challenge is not purely technical. Leadership is accountable for a security outcome without a clear owner, sequence, or way of measuring progress. Contracts management understands the regulatory timeline. General counsel manages vendor agreements and proprietary data concerns. Supply chain leadership knows the vendor relationships. IT implements technical controls. But the proposed FASC rules demand a coordinated response that cuts across all four domains.

What the Proposed FASC Rules Would Require

The supplied sources do not contain the specific text or requirements of the proposed FASC supply chain risk information sharing rules. Without access to the proposed rulemaking documents, Federal Register notices, or implementing guidance, it is not possible to state what information contractors would be required to share, what threshold triggers the requirement, what format or frequency applies, or what penalties exist for non-compliance.

Organizations evaluating their obligations under proposed FASC rules should obtain the primary source documents directly from the Federal Register or the General Services Administration to understand the specific information sharing requirements, thresholds, timelines, and enforcement mechanisms.

Protections for Proprietary Vendor Data

The supplied sources do not address what protections, if any, would exist for proprietary vendor information shared under the proposed FASC rules. Questions about Freedom of Information Act (FOIA) exemptions, treatment of commercially sensitive data, restrictions on government use or disclosure, and remedies for unauthorized release cannot be answered from the available material.

General counsel should review the proposed rule language directly to understand what statutory or regulatory protections apply to proprietary vendor information, whether additional contractual protections can be negotiated, and what disclosure risks exist under FOIA or other access regimes.

How This Relates to Existing Vendor Oversight Processes

Most federal contractors already maintain vendor risk assessment processes to satisfy contract requirements, comply with the NIST Cybersecurity Framework, or meet sector-specific mandates. The proposed FASC rules would add a reporting layer: not just assessing supply chain risk internally, but disclosing findings to the government in a prescribed format and timeline.

The NIST Cybersecurity Framework provides a structured approach to understanding and improving management of cybersecurity risk, including supply chain considerations. Organizations can use the Framework to identify relevant supply chain risk categories, establish governance processes, and document their risk management approach—all of which would support compliance with information sharing requirements if they become final.

The gap is not whether you have vendor assessments. It is whether those assessments capture the information the government will require, whether findings are documented in a format that supports disclosure, and whether your internal processes can produce timely, accurate reports under audit conditions.

The Accountability Problem

Supply chain risk information sharing sits at the intersection of contracts, legal, supply chain, and IT. Contracts management owns the compliance timeline and contractual obligations. General counsel owns vendor agreements, proprietary data protection, and disclosure risk. Supply chain leadership owns vendor relationships and operational dependencies. IT owns technical assessments and security controls.

None of these groups, in isolation, can answer the question: are we compliant? That requires someone with the authority to define what information will be collected, how it will be protected, who will validate it, and how discrepancies will be resolved. It requires governance: policy, process, accountability, and a single point of decision when those elements conflict.

This is the role of a virtual Chief Information Security Officer (vCISO). A [vCISO](/vciso/) provides executive ownership of the security program, including regulatory positioning, risk decisions, cross-functional governance, and reporting. For federal contractors, that means translating proposed FASC requirements into internal policy, coordinating the response across contracts, legal, supply chain and IT, and ensuring leadership has visibility into compliance status and residual risk.

What Leadership Should Do Next

If your organization holds federal contracts that may fall within the scope of the proposed FASC rules, take the following steps:

  • Obtain the proposed rule text from the Federal Register and review it with contracts management and general counsel to determine whether your contracts are in scope.
  • Inventory your current vendor risk assessment processes. What information do you collect, in what format, and how is it validated? Identify gaps between current practice and likely regulatory requirements.
  • Convene contracts, legal, supply chain, and IT leadership to assign accountability. Who will own the government disclosure process? Who validates vendor data before it is shared? Who signs off on accuracy?
  • Review vendor agreements for provisions that permit or restrict disclosure of security-related information to the government. Identify contracts that may require amendment.
  • Establish a governance process for managing supply chain risk information: what gets collected, who reviews it, what triggers escalation, and who makes disclosure decisions when facts are ambiguous or incomplete.
  • Consider whether your organization has the executive security leadership to coordinate this cross-functional effort and represent your position to auditors and government officials.

This is not a project that can be delegated to IT. It is a governance question with regulatory, legal, and operational dimensions. The proposed FASC rules, if finalized, will require a coordinated response led by someone with authority across all four domains.

How Heights Consulting Group Supports Federal Contractors

Heights Consulting Group provides virtual CISO (vCISO) leadership to organizations navigating complex regulatory environments. For federal contractors, that includes interpreting proposed rules, designing governance processes that satisfy both contract requirements and operational constraints, coordinating response across contracts, legal, supply chain and IT, and representing your security position to auditors and government officials.

If your organization is evaluating its obligations under the proposed FASC supply chain risk information sharing rules and needs executive security leadership to coordinate the response, a confidential consultation can clarify what adequate ownership looks like and how vCISO leadership closes the gap between accountability and execution.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Vendor, MSP and Third-Party Oversight

Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.

Read about Vendor, MSP and Third-Party Oversight