DOD looks for extension on Huawei ban

The 2021 must-pass defense policy bill could be a prime vehicle to give the Defense Department and its contractors more time to comply with a governmentwide ban on Huawei and other China-made telecommunications equipment.

DOD's acquisition head, Ellen Lord, said DOD needed more time and worried about "unintended consequences" in implementing the ban on contracts with companies that use products or services like Huawei in August.

"The thought that somebody in six or seven levels down in the supply chain could have one camera in a parking lot, and that would invalidate one of our major primes being able to do business with us gives us a bit of pause," Lord testified at a House Armed Services Committee hearing on the defense industry base June 10.

Lord said that while she thinks a "majority" of compliance could be achieved, "it is a heavy lift to find all of this equipment everywhere" within two years, and potentially "shutting down major portions of our defense industrial base because of one infraction of a Hikvision camera in a parking lot somewhere, at a level-four supplier."

The issue comes as the Defense Department, and government agencies broadly, have become more reliant on information systems and telecommunications services amid the coronavirus pandemic -- an issue that's sure to be included in the National Defense Authorization Act, making the bill a suitable avenue for deadline modification.

Wesley Hallman, the National Defense Industry Association's senior vice president for strategy and policy, told FCW that as is, Section 889, which was passed in the 2019 NDAA, was basically unimplementable, approaching crisis-level concerns.

"The bottom line is, we don't even have a draft rule to comment on and it's supposed to be implemented on Aug. 13," Hallman said. "As written, it's very near impossible to certify that you are free of this in your supply chain."

Supply chain concerns will likely be a mainstay in the NDAA. The COVID-19 pandemic "exposed and exacerbated supply chain deficiencies across the government, and the FY21 NDAA takes numerous steps to secure the supply chain -- both from over-reliance on foreign nations and from infiltration by our adversaries," the Senate Armed Services Committee indicated in its summary of its version of the 2021 NDAA.

Moreover, it requires DOD to "report on the risk to DOD personnel, equipment, and operations due to Huawei 5G architecture in host countries and possible steps for mitigation." DOD also has to consider security risks with 5G and 6G when using vendors like Huawei and ZTE.

David Berteau, the president and CEO for the Professional Services Council, said Lord's testimony was DOD's "strongest" support of an extension, which has "huge dollar implications" for a requirement that doesn't have a rule and is less than two months away from an implementation date.

PSC and the NDIA are pushing for an extension to February 2021 "to allow contractors time to recover from the effects of COVID-19 and effectively comply," according to a March 31 letter to House and Senate Armed Services Committee leaders.

"Postponement of the deadline will provide the government with better assurance of achieving its supply chain security objectives with the least disruption and harm to the vendor and supplier base," the letter states.

Without it, Berteau said it could be problematic for DOD's thousands of contracts, potentially leaving compliance up to individual companies, which could make it harder for contract officers to verify that banned equipment and services are removed.

"Because we don't know what the procurement rules are, businesses can't begin to budget or prepare," he said. "The government regulation needs to set precise standards and give companies time to plan for and build compliance.”

About the Author

Lauren C. Williams is a staff writer at FCW covering defense and cybersecurity.

Featured

  • Gaining a Competitive Edge

    Ask most companies about their future technology plans and the answers will most likely include AI. Then ask how they plan to deploy it, and that is where the responses may start to vary. Every company has unique surveillance requirements that are based on market focus, scale, scope, risk tolerance, geographic area and, of course, budget. Those factors all play a role in deciding how to configure a surveillance system, and how to effectively implement technologies like AI. Read Now

  • 6 Ways Security Awareness Training Empowers Human Risk Management

    Organizations are realizing that their greatest vulnerability often comes from within – their own people. Human error remains a significant factor in cybersecurity breaches, making it imperative for organizations to address human risk effectively. As a result, security awareness training (SAT) has emerged as a cornerstone in this endeavor because it offers a multifaceted approach to managing human risk. Read Now

  • The Stage is Set

    The security industry spans the entire globe, with manufacturers, developers and suppliers on every continent (well, almost—sorry, Antarctica). That means when regulations pop up in one area, they often have a ripple effect that impacts the entire supply chain. Recent data privacy regulations like GDPR in Europe and CPRA in California made waves when they first went into effect, forcing businesses to change the way they approach data collection and storage to continue operating in those markets. Even highly specific regulations like the U.S.’s National Defense Authorization Act (NDAA) can have international reverberations – and this growing volume of legislation has continued to affect global supply chains in a variety of different ways. Read Now

  • Access Control Technology

    As we move swiftly toward the end of 2024, the security industry is looking at the trends in play, what might be on the horizon, and how they will impact business opportunities and projections. Read Now

Featured Cybersecurity

Webinars

New Products

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3