Best Section 889 compliance software
Three different tools are sold as Section 889 compliance software and only one produces the record the FAR actually enforces. What to buy, and why.
By the Scrutineer team
September 2026 · 8 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
Most tools sold as Section 889 compliance software solve one of three different problems, and only one of them is the problem the FAR actually puts on you. The clause is enforced through a representation you sign, and what a contracting officer can test afterwards is not your network. It is whether you ran a reasonable inquiry, when you ran it, and what it returned. Pick the tool that produces that record.
The three kinds of tool sold as Section 889 compliance software
The category is not one category. A product-compliance screening tool, a denied-party screening tool and a compliance records platform all market themselves against the same search, and they answer different halves of the obligation. Section 889 has two prohibitions: paragraph (a)(1)(A) covers what you sell into a federal contract, and paragraph (a)(1)(B) covers what your own business runs, on federal work or not. Part A is a product question. Part B is an operating question. Very little software does both.
| Type of tool | What it actually checks | Which prohibition it serves | Where it stops | Best fit |
|---|---|---|---|---|
| Product and bill-of-materials screening | Component and part data against covered producers, usually inside a hardware BOM | Mostly Part A, what you deliver | It says nothing about the switches and cameras in your own offices | Manufacturers and resellers delivering hardware into federal contracts |
| Denied-party and entity screening | Supplier names against sanctions, debarment and restricted-party lists | Neither, directly | The covered-entity list is statutory, not a screening list, and affiliates are the hard part | Firms that already run export-control screening and want 889 folded in |
| IT asset discovery | What is on your network right now, by make and model | Part B, at a point in time | Discovery is evidence, not an inquiry. It has no record of who you asked or what they answered | Larger contractors with an existing asset management program |
| Compliance records platform | The inquiry itself: method, date, scope, supplier attestations and the representation each one supports | Both, because it holds the reasoning rather than the scan | It does not read your BOM or your network for you | Any contractor whose exposure is the representation rather than the hardware |
If you only buy one, buy the one that produces the file. A scan proves what was true on a Tuesday. A documented inquiry proves you met the standard the FAR set, which is the thing you will be asked about.
Do I need an audit to comply with Section 889?
No, and this is where a lot of money gets spent unnecessarily. FAR 4.2101 defines a reasonable inquiry as one designed to uncover information already in your possession about who produced or provided the equipment you use, and it expressly excludes the need to include an internal or third-party audit. The standard is diligence, not assurance.
The FAR Council has since made that even more explicit. In a proposed rule published on 23 June 2026 it moves Section 889 into a consolidated FAR Subpart 40.2 and applies one reasonable-inquiry standard across every security prohibition, stating that an offeror or contractor does not need to conduct an internal or third-party audit and that due diligence does not require gathering information outside its possession. The preamble is unusually blunt about why: inconsistent standards created uncertainty and added liability risk for industry.
So when a vendor sells you a Section 889 audit, be clear about what you are buying. It may be useful. It is not what the regulation requires, and buying it does not raise the standard you are held to.
What to look for when you compare Section 889 tools
Five things separate a tool that will hold up from a tool that produces a dashboard.
- It records the inquiry, not just the result. Method, scope, date, who was asked, what came back. A green tick with no provenance is worth nothing when a certification is challenged.
- It keeps the two representations apart. FAR 52.204-26 is the annual representation in the System for Award Management. FAR 52.204-24 is answered offer by offer. Teams that treat these as one thing miss the offer-level answer, which is the more common failure.
- It handles flow-down correctly. FAR 52.204-25(e) requires the substance of the clause in all subcontracts excluding the paragraph (b)(2) use prohibition. A tool that pushes the whole clause down to every supplier is asking your subcontractors to certify something the FAR did not ask them to certify.
- It has a report ready to file. On discovery you owe the contracting officer the contract and order numbers, supplier name, CAGE code, brand, model number and your mitigation, within one business day. Assembling that from scratch under a one-day clock is how disclosures go out incomplete.
- It reuses evidence you already have. If you hold a SOC 2 report, an ISO 27001 statement of applicability or a FedRAMP package, you already maintain an asset inventory and a vendor register. A tool that makes you rebuild both as a separate exercise is adding cost, not control.
Does Section 889 flow down to subcontractors?
Yes, and the detail matters more than the headline. The prohibition on what gets delivered into the contract travels to subcontractors at every tier. The broader prohibition on what a company uses in its own operations does not, because the clause carves paragraph (b)(2) out of the flow-down. The FAR Council kept the same structure in its 2026 proposal, excluding paragraphs (d)(1) and (j)(1) from the new clause at FAR 52.240-3(k).
Practically, this means your supplier questionnaire should ask two different things of two different populations, which is an ordinary vendor tiering decision. Suppliers who deliver technology into federal work get the full inquiry. Suppliers who do not can attest to the narrower question. Sending every vendor the same 889 letter is the pattern that produces low response rates and attestations nobody reads.
Is there a Section 889 compliance list I can check a supplier against?
There is no official database that returns yes or no for an arbitrary company. The covered entities are named in statute, Huawei and ZTE for telecommunications equipment and Hytera, Hangzhou Hikvision and Dahua for video surveillance and certain telecommunications equipment, together with their subsidiaries and affiliates. GSA publishes decision trees and FAQs, and agencies screen internally, but nobody maintains a searchable registry that resolves the affiliate question for you.
The affiliate question is the hard one, and it is genuinely a research task rather than a compliance task. Working out whether a supplier is a subsidiary of a covered producer means tracing corporate ownership through public filings, registries and trade records, and the useful output is a sourced, timestamped record of what public sources say rather than a verdict. Attach that record to the inquiry file. Whatever you conclude, the value is in showing your working.
What changes if the June 2026 FAR rewrite is finalized
Quite a lot, and almost none of it is in circulation yet, because published Section 889 guidance still describes FAR Subpart 4.21 and clauses 52.204-24, 52.204-25 and 52.204-26. Those remain the operative text: the June 2026 rule is a proposal, comments closed on 23 July 2026, and no final rule has issued. But the direction is set, and three of the changes are substantive rather than cosmetic.
| Today | Proposed | Why it matters to a buyer |
|---|---|---|
| One business day for the first report, ten business days for mitigation detail | A single report, 72 hours from discovery | Two report templates collapse into one, and the clock gets slightly kinder |
| No definition of what counts as use | Commercial sales, maintenance, testing services, warranty services and an employee's use of personal equipment are not individually considered use | Settles the personal-device argument that has run since 2020 |
| Critical technology defined through export-control lists | A technology in whose absence a system cannot adequately operate or function | A far narrower scoping test, which shrinks the population of systems you have to reason about |
| Section 889 sits in its own subpart | Consolidated into FAR Subpart 40.2 with FASCSA orders and covered procurement actions | One procedure for several prohibitions, so a tool built only around 889 will be solving a smaller share of the problem |
That last row is the buying consideration. If the consolidation goes through, a point solution scoped to Section 889 alone covers one prohibition inside a subpart that governs several. Software that already treats supply chain prohibitions as one records problem does not need rebuilding.
Which tool fits which contractor
| Your situation | What you actually need | What you can skip |
|---|---|---|
| Software or services firm, no hardware delivered | A documented Part B inquiry, an asset and vendor record, and the two representations tracked separately | BOM screening. You have no bill of materials to screen |
| Reseller or integrator shipping hardware | Product screening for what you deliver, plus the Part B inquiry for your own operations | Nothing. This is the profile that genuinely needs both |
| Prime with a deep subcontractor tier | Flow-down tracking, attestation collection and re-request cadence, tiered by what each sub supplies | Sending an identical 889 letter to every supplier |
| Small business chasing a first federal award | A written inquiry method, an equipment list and dated answers. The standard scales to your resources | An audit. The FAR says explicitly it is not required |
| Already running CMMC or FedRAMP | To connect 889 to the inventory and vendor register you already maintain | A parallel program with its own asset list |
Where Scrutineer fits
Scrutineer is the records half. It holds the reasonable inquiry behind each representation with its method and date, stores the supplier and subcontractor attestations that support it, keeps the annual SAM representation and the offer-level provision on separate clocks, and reuses the control evidence and vendor records you already maintain for other frameworks rather than asking you to build a second inventory. If your suppliers are already tracked for supplier risk, the 889 inquiry becomes one more question against a population you have.
It does not read your bill of materials and it does not scan your network. If you deliver hardware, pair it with a product screening tool. What it gives you is the thing the clause is actually enforced on: a file showing you asked, when you asked, and what you were told.
The full obligation map, including the FAR citations for each requirement and what the June 2026 proposal would change, is on the Section 889 compliance software page.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.