Telecommunications: Better Information Sharing Needed to Ensure Compliance with Foreign-Sourced Equipment Prohibitions
GAO’s review of Section 889 (John S. McCain NDAA FY2019 Section 889) confirms that the statutory prohibitions on procuring covered telecommunications and surveillance equipment and services from five identified foreign companies have materially changed federal procurement behavior since…
Cabrillo Club
Editorial Team · September 22, 2026 · 5 min read

Also in this intelligence package
Executive Summary
GAO’s review of Section 889 (John S. McCain NDAA (National Defense Authorization Act) FY2019 Section 889) confirms that the statutory prohibitions on procuring covered telecommunications and surveillance equipment and services from five identified foreign companies have materially changed federal procurement behavior since implementation in fiscal year 2019. Agencies reduced spending with the five companies through fiscal year 2025 (including three fiscal years with no spending), and GAO found that, as of March 2026, nearly 90 percent of companies with active government contracts in fiscal year 2025 publicly represented that they do not use equipment from those companies. GSA (General Services Administration) and DOD have built processes and tools (including GSA automated removal on Multiple Award Schedule contracts and DOD/GSA search tools tied to the System for Award Management) that materially support compliance.
The report also highlights a critical operational gap: GSA and DOD are not broadly sharing the implementation insights they have developed (for example, affiliates/subsidiary mappings and supply‑chain provenance techniques such as expanded use of customs data) with other agencies. Because GSA and DOD together account for a large share of federal contracting activity, improved information sharing could reduce duplicate effort and help agencies prepare for additional statutory prohibitions noted in the report (for example, on semiconductors). Contractors should pay immediate attention to supply‑chain provenance, SAM representations, and how to document compliance for GSA and DOD procurements and for agencies that will rely on GSA systems.
Impact Matrix
Telecommunications
- Risk Level: Critical
- Opportunity: Provide compliant telecommunications equipment and services; help agencies validate origin and absence of prohibited sources. Relevant NAICS and vehicles from Tags: 517311, 517312, 517410, 334220, 334290; contract vehicles: GSA Multiple Award Schedule (GSA MAS), FSS. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; agencies reduced spending through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Verify and document supply‑chain provenance for telecom products; ensure SAM representations reflect non‑use of prohibited equipment; prepare evidence packages for contracting officers and purchase cardholders.
- Competitive Edge: Offer verifiable origin documentation and supplier attestations, and position on GSA MAS/FSS where eligible to be visible to agencies using those vehicles.
IT Services
- Risk Level: High
- Opportunity: Support agencies in SAM compliance, representations, and supply‑chain assessment for service deliverables. Relevant NAICS from Tags: 541512, 541513, 541519. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; ongoing through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Ensure service delivery does not rely on prohibited equipment or provide mitigations and documented alternatives; update SAM entries and be prepared to respond to DOD/GSA search tool queries.
- Competitive Edge: Develop standard compliance packages (evidence of component sourcing and substitute solutions) to accelerate contracting officers’ reviews.
Surveillance Equipment
- Risk Level: Critical
- Opportunity: Supply non‑prohibited surveillance products or retrofit alternatives; assist agencies with provenance checks. Relevant NAICS from Tags: 334111, 334118, 334210, 334310, 334220, 334290. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; agencies reduced spending through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Audit vendor networks for use of prohibited components, prepare substitution plans, and maintain clear component origin records for agency review.
- Competitive Edge: Demonstrate a cleared supply chain and provide documented replacement roadmaps for legacy systems containing prohibited components.
Network Equipment
- Risk Level: Critical
- Opportunity: Provide compliant network gear and supply‑chain validation services. Relevant NAICS from Tags: 334111, 334118, 334210, 334310, 334220, 334290; contract vehicles: GSA MAS/FSS. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; ongoing through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Eliminate or document non‑use of prohibited equipment in product BOMs; ensure visibility in SAM and be responsive to GSA/DOD search tools.
- Competitive Edge: Use customs‑origin evidence and supplier audit trails to shorten agency review cycles (noting GSA plans to expand use of customs data).
Information Technology
- Risk Level: High
- Opportunity: Provide compliant IT hardware/software stacks and advisory services on Section 889 compliance. Relevant NAICS: 541512, 541513, 541519. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; GAO findings as of March 2026.
- Action Required: Map and remediate any dependencies on prohibited hardware/components; document alternative architectures and compliance attestations.
- Competitive Edge: Bundle compliance assurance with IT offerings to differentiate in procurements where agencies are screening for prohibited sources.
Cybersecurity
- Risk Level: High
- Opportunity: Offer risk assessments focused on risks created by prohibited equipment and remediation services. Relevant NAICS: 541512, 541513, 541519. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; ongoing through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Integrate checks for Section 889‑related vendor risk into cybersecurity assessments and provide documentation for contracting officers.
- Competitive Edge: Combine supply‑chain provenance analysis with cybersecurity assessments to present a unified risk‑reduction offering.
Supply Chain Security
- Risk Level: High
- Opportunity: Provide supply‑chain mapping, customs‑data analysis, and affiliate/subsidiary tracing to support agency compliance. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; GAO notes GSA plans to expand customs data use; GAO findings as of March 2026.
- Action Required: Build traceability systems and data packages that demonstrate origin and absence of prohibited sources; be prepared to share methods with customers.
- Competitive Edge: Develop repeatable provenance workflows and templates that align with GSA/DOD practices to reduce agency verification burden.
Semiconductors
- Risk Level: High
- Opportunity: Prepare for anticipated additional statutory prohibitions (the Summary cites upcoming statutory prohibitions such as on semiconductors) by developing compliant sourcing and documentation services. Specific opportunities TBD pending solicitation language.
- Timeline: Upcoming statutory prohibitions referenced; timeline TBD pending source review.
- Action Required: Monitor agency guidance and GAO/GSA/DOD publications, begin supplier inventories for semiconductor content, and prepare mitigation strategies.
- Competitive Edge: Pre‑position supplier certification and origin documentation for semiconductor components to move quickly when specific procurement guidance or solicitations appear.
Communications Equipment
- Risk Level: Critical
- Opportunity: Supply compliant communications hardware and offer rapid substitution services for banned sources. Relevant NAICS: 517311, 517312, 517410, 334220, 334290. Contract vehicles: GSA MAS/FSS. Specific opportunities TBD pending solicitation language.
- Timeline: Implemented in fiscal year 2019; agencies reduced spending through fiscal year 2025; GAO findings as of March 2026.
- Action Required: Ensure BOMs and procurement flows exclude prohibited companies and affiliates; maintain and make available compliance attestations for contracting officers.
- Competitive Edge: Certify and advertise non‑use of prohibited suppliers in SAM and on GSA vehicles to be readily discoverable by agency buyers.
Cross-Segment Implications
- Procurement restrictions on telecommunications, surveillance, network, and communications equipment cascade into IT services, information technology, and cybersecurity because those services commonly depend on hardware and components covered by Section 889. Vendors in IT and cybersecurity must now validate hardware provenance as part of service delivery.
- GSA and DOD’s experience and tooling (including removal on GSA MAS and DOD/GSA search tools linked to SAM.gov (System for Award Management)) materially reduces some compliance risk for agencies that use those vehicles, but GAO notes limited broad sharing of lessons learned. That lack of information sharing increases duplicate work across agencies and raises the implementation burden for contractors selling outside of GSA/DOD channels.
- The report’s callout of upcoming statutory prohibitions (for example on semiconductors) means supply‑chain security and provenance capabilities built for Section 889 will be reusable across segments — vendors that invest now in traceability, customs‑data analysis, and affiliate identification are positioned to serve multiple segments as agencies apply similar prohibitions to new product classes.
- Because GSA and DOD together account for a substantial share of FY2025 obligations (per GAO’s scope), contractors that align with GSA/DOD compliance methods and the GSA MAS/FSS vehicles can capture outsized demand and also influence how other agencies adopt similar practices.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor see Intelligence Dashboard →

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.