DOD looks for extension on Huawei ban

The 2021 must-pass defense policy bill could be a prime vehicle to give the Defense Department and its contractors more time to comply with a governmentwide ban on Huawei and other China-made telecommunications equipment.

DOD's acquisition head, Ellen Lord, said DOD needed more time and worried about "unintended consequences" in implementing the ban on contracts with companies that use products or services like Huawei in August.

"The thought that somebody in six or seven levels down in the supply chain could have one camera in a parking lot, and that would invalidate one of our major primes being able to do business with us gives us a bit of pause," Lord testified at a House Armed Services Committee hearing on the defense industry base June 10.

Lord said that while she thinks a "majority" of compliance could be achieved, "it is a heavy lift to find all of this equipment everywhere" within two years, and potentially "shutting down major portions of our defense industrial base because of one infraction of a Hikvision camera in a parking lot somewhere, at a level-four supplier."

The issue comes as the Defense Department, and government agencies broadly, have become more reliant on information systems and telecommunications services amid the coronavirus pandemic -- an issue that's sure to be included in the National Defense Authorization Act, making the bill a suitable avenue for deadline modification.

Wesley Hallman, the National Defense Industry Association's senior vice president for strategy and policy, told FCW that as is, Section 889, which was passed in the 2019 NDAA, was basically unimplementable, approaching crisis-level concerns.

"The bottom line is, we don't even have a draft rule to comment on and it's supposed to be implemented on Aug. 13," Hallman said. "As written, it's very near impossible to certify that you are free of this in your supply chain."

Supply chain concerns will likely be a mainstay in the NDAA. The COVID-19 pandemic "exposed and exacerbated supply chain deficiencies across the government, and the FY21 NDAA takes numerous steps to secure the supply chain -- both from over-reliance on foreign nations and from infiltration by our adversaries," the Senate Armed Services Committee indicated in its summary of its version of the 2021 NDAA.

Moreover, it requires DOD to "report on the risk to DOD personnel, equipment, and operations due to Huawei 5G architecture in host countries and possible steps for mitigation." DOD also has to consider security risks with 5G and 6G when using vendors like Huawei and ZTE.

David Berteau, the president and CEO for the Professional Services Council, said Lord's testimony was DOD's "strongest" support of an extension, which has "huge dollar implications" for a requirement that doesn't have a rule and is less than two months away from an implementation date.

PSC and the NDIA are pushing for an extension to February 2021 "to allow contractors time to recover from the effects of COVID-19 and effectively comply," according to a March 31 letter to House and Senate Armed Services Committee leaders.

"Postponement of the deadline will provide the government with better assurance of achieving its supply chain security objectives with the least disruption and harm to the vendor and supplier base," the letter states.

Without it, Berteau said it could be problematic for DOD's thousands of contracts, potentially leaving compliance up to individual companies, which could make it harder for contract officers to verify that banned equipment and services are removed.

"Because we don't know what the procurement rules are, businesses can't begin to budget or prepare," he said. "The government regulation needs to set precise standards and give companies time to plan for and build compliance.”

About the Author

Lauren C. Williams is a staff writer at FCW covering defense and cybersecurity.

Featured

  • AI Is Now the Leading Cybersecurity Concern for Security, IT Leaders

    Arctic Wolf recently published findings from its State of Cybersecurity: 2025 Trends Report, offering insights from a global survey of more than 1,200 senior IT and cybersecurity decision-makers across 15 countries. Conducted by Sapio Research, the report captures the realities, risks, and readiness strategies shaping the modern security landscape. Read Now

  • Analysis of AI Tools Shows 85 Percent Have Been Breached

    AI tools are becoming essential to modern work, but their fast, unmonitored adoption is creating a new kind of security risk. Recent surveys reveal a clear trend – employees are rapidly adopting consumer-facing AI tools without employer approval, IT oversight, or any clear security policies. According to Cybernews Business Digital Index, nearly 90% of analyzed AI tools have been exposed to data breaches, putting businesses at severe risk. Read Now

  • Software Vulnerabilities Surged 61 Percent in 2024, According to New Report

    Action1, a provider of autonomous endpoint management (AEM) solutions, today released its 2025 Software Vulnerability Ratings Report, revealing a 61% year-over-year surge in discovered software vulnerabilities and a 96% spike in exploited vulnerabilities throughout 2024, amid an increasingly aggressive threat landscape. Read Now

  • Motorola Solutions Named Official Safety Technology Supplier of the Ryder Cup through 2027

    Motorola Solutions has today been named the Official Safety Technology Supplier of the 2025 and 2027 Ryder Cup, professional golf’s renowned biennial team competition between the United States and Europe. Read Now

  • Evolving Cybersecurity Strategies

    Organizations are increasingly turning their attention to human-focused security approaches, as two out of three (68%) cybersecurity incidents involve people. Threat actors are shifting from targeting networks and systems to hacking humans via social engineering methods, living off human errors as their most prevalent attack vector. Whether manipulated or not, human cyber behavior is leveraged to gain backdoor access into systems. This mainly results from a lack of employee training and awareness about evolving attack techniques employed by malign actors. Read Now

New Products

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.