Huawei telecommunications equipment photographed in Hong Kong in 2020; an illustrative device, not an item GAO found in federal procurement.
SWI yIN pWUXG / Wikimedia Commons, CC BY-SA 4.0. Cropped in the share card; this image is illustrative and does not show a federal purchase.

A purchasing rule can name five companies in one sentence. A supply chain cannot be understood in one sentence. It contains subsidiaries, affiliates, distributors, white-label products, embedded components, and contracts in which the government buys a service rather than a box. By the time a camera or network appliance appears in a federal catalog, the name on its listing may say little about the origin of a board inside it or a company elsewhere in its ownership tree.

Congress’s Section 889 restrictions, enacted in the fiscal 2019 National Defense Authorization Act, bar specified telecommunications and video surveillance equipment or services associated with five named Chinese companies and their subsidiaries or affiliates, and address contracts with entities that use covered equipment. The policy’s stated concern is foreign-sourced equipment in sensitive government systems. The question in the GAO’s September 22 audit is more operational: can purchasing officers identify what the rule actually covers, and can agencies share the information they have assembled?

GAO examined the General Services Administration and Department of Defense, selected because together they accounted for nearly two-thirds of the federal government’s $793 billion in fiscal 2025 product and service obligations. That figure is the government-wide spending denominator used to describe the agencies’ importance, not the amount spent on telecommunications or surveillance devices. A discussion that turns it into a “$793 billion camera market” would falsify the report.

The first identity check is a declaration

Federal buyers use contractor representations about whether a company sells or uses covered equipment. According to GAO’s analysis of March 2026 System for Award Management data, almost 90 percent of companies with fiscal 2025 contract activity represented that they did not use covered equipment; those companies received more than 98 percent of obligations. About 2 percent, roughly 1,800 companies, represented that they did use it. These are declarations by companies within the relevant reporting system. They are not an independent component-by-component examination of every contract.

This distinction is ordinary in procurement but crucial for security. A purchasing officer cannot dismantle every electronic product before approving a transaction. Representations create a legally meaningful, scalable initial screen, and officials cited the False Claims Act as a deterrent to false statements. Yet a truthful answer can still rest on incomplete knowledge of upstream parts, and a fraudulent answer is useful to detect only if the government has enough independent information to challenge it. Self-reporting and technical verification are complementary, not interchangeable.

The government has built additional defenses. GAO says GSA’s automated processes removed more than 5,700 noncompliant catalog items in fiscal 2024 and 2025. From October 2025 to May 2026, GSA systems excluded approximately 137,000 products before upload for noncompliance with prohibitions *including* Section 889. That qualification matters: the 137,000 figure is not a count of confirmed Section 889 violations, let alone proven hostile devices. GAO also reports that GSA had identified about 700 subsidiaries and affiliates of the named companies by May 2026, using supply-chain illumination, search algorithms, origin tracing, and news monitoring.

Those numbers show activity, not full coverage. An automated system can remove what it recognizes. It cannot confidently flag every brand relationship when ownership changes, a manufacturer makes identical equipment for multiple labels, or a component’s origin is hidden beneath several contracting tiers. GAO says officials do not know whether they have found all affiliates and subsidiaries. DOD uses similar tools but told auditors it does not maintain a central list because corporate structures change and a static list can become stale or inaccurate. Both concerns can be true: a shared list can age, and the absence of shared findings can leave another buyer needlessly blind.

Follow one hypothetical purchase

Consider a federal office buying a network-connected surveillance camera from an approved catalog. The public listing names a reseller. The camera carries a house brand. A manufacturing partner assembled it, and a subcomponent came from yet another supplier. The reseller submits the required representation. A purchasing officer checks the catalog, perhaps searches a tool for the vendor’s status, and approves an order.

At each step, the question changes. Does the legal prohibition apply to the finished camera, a specific part, a service, or the contractor’s own use of covered equipment? Which company made the relevant component? Is that company an affiliate of one of the named entities under the rule? When was the relationship verified, and did it change? Is a listed product identical to an item already removed under another brand? The GAO report identifies difficulties answering these kinds of questions, but it does not provide the records for our hypothetical purchase. The scenario is a method for exposing where an answer must be supported, not an allegation about any real vendor.

This is why “made in” labels and vendor names cannot carry the entire security analysis. A label may reflect final assembly; a procurement ban may turn on a company relationship or a component used inside the product. Conversely, a resemblance between products is not proof of prohibited origin. The standard must define the entity and component relationship and leave an auditable path for an appeal or correction. Security teams need provenance; vendors need a way to contest false associations.

The missing network among buyers

GAO found that GSA and DOD had not widely shared their affiliate information and implementation lessons with other federal agencies. The agencies began exchanging more during the audit, but officials described that exchange as ad hoc. GSA had submitted information to a federal acquisition-security council in earlier years, while officials were unsure whether it had been disseminated widely. Both agencies said there was no requirement to share their accumulated findings broadly. The audit’s four recommendations ask each agency to share affiliate information and practical lessons, potentially through existing Cybersecurity and Infrastructure Security Agency mechanisms. GSA and DOD concurred, with DOD saying it would assess criteria for identifying affiliates and appropriate sharing forums.

A usable shared system would need more than a spreadsheet of names. It would record entity identifiers, historical ownership and brand relationships, evidence sources, dates, confidence, applicable product categories, review status, and the rule under which a relationship matters. It would need update and challenge paths because companies reorganize and names collide. Those are design implications from the observed problem; GAO does not prescribe that precise database. A poorly maintained central list could generate false positives or give a false sense of completeness.

The prospective rule change makes the timing sharper. GAO reports concern from GSA and DOD officials that a proposed Federal Acquisition Regulation overhaul could remove the annual vendor representation requirement. If adopted as described, a tool that lets purchase cardholders quickly inspect current representations might lose that freshness. The change was proposed, not in force as an established outcome in the audit. Its final text and replacement processes should be checked before describing the effect as a completed rollback.

There are real constraints outside Washington as well. GAO records difficulties complying while operating abroad and obtaining representation information for small card purchases. A policy designed around a domestic catalog and large contract review may meet a different world when an office needs an urgent local service or a purchase cardholder buys a modest electronic item. Risk-based procurement can prioritize high-impact networked devices, but the government still needs a defensible account of how smaller paths are handled.

An effective verification process also has to preserve the date of the decision. A vendor may acquire an affiliate after a contract begins; a brand may change ownership; a component may be substituted during a product’s production run. A record that only says “approved” without the supplier relationship and evidence current on the purchase date will be difficult to audit later. Contracts can require notification of material changes and agencies can periodically recheck high-risk items, but doing so across every low-value purchase has costs. The report does not price an ideal program. It shows that agencies with the largest procurement experience have learned things other buyers have not routinely received.

What the report does not prove

This is not evidence that a Chinese company has remotely accessed every device sold through an affiliate, or that each component from a named manufacturer contains a backdoor. Section 889 is a preventive rule tied to defined entities and uses, not a case-by-case forensic finding that an individual camera was malicious. GAO’s figures describe compliance processes and visibility limits. The report also notes genuine remediation, tools, and contract actions. The precise number of prohibited products that escaped detection is unknown from its public record.

That uncertainty cuts both ways. It prevents an inflated claim about pervasive compromise. It also prevents a comforting claim that a clean representation or catalog listing completely resolves origin. The next useful investigation would sample actual high-risk procurements, reconstruct the component and ownership chain from invoices and manufacturer records, compare agencies’ affiliate lists, and record disagreements. Such work would require access to purchase records and potentially sensitive supply-chain information. A public article should not pretend that a hypothetical camera is that sample.

The broader lesson extends beyond the named countries or the current list. Governments are adding restrictions on chips, network gear, software, and critical-infrastructure components. Every entity-based rule inherits the same maintenance burden: who counts as the entity, what evidence establishes control, how quickly changes propagate, and what a frontline buyer sees at decision time. A ban is a sentence in law. Compliance is an updating map of products, companies, and evidence.

CYBERDELIA ASSESSMENT

The government has meaningful screens and remediation, but supplier identity is a live data problem. Sharing sourced, dated affiliate findings could reduce duplicated blind spots without pretending a list alone verifies every device.

News DeskLeah ReedMore Features