Scrutineer.ai
All posts
Comparison

Best Section 889 compliance software

Three different tools are sold as Section 889 compliance software and only one produces the record the FAR actually enforces. What to buy, and why.

By the Scrutineer team

September 2026 · 8 min read

Try it while you read

No account, nothing to install.

Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.

The Scrutiny Desk

Illustrative sample · not an audit attestation

Most tools sold as Section 889 compliance software solve one of three different problems, and only one of them is the problem the FAR actually puts on you. The clause is enforced through a representation you sign, and what a contracting officer can test afterwards is not your network. It is whether you ran a reasonable inquiry, when you ran it, and what it returned. Pick the tool that produces that record.

The three kinds of tool sold as Section 889 compliance software

The category is not one category. A product-compliance screening tool, a denied-party screening tool and a compliance records platform all market themselves against the same search, and they answer different halves of the obligation. Section 889 has two prohibitions: paragraph (a)(1)(A) covers what you sell into a federal contract, and paragraph (a)(1)(B) covers what your own business runs, on federal work or not. Part A is a product question. Part B is an operating question. Very little software does both.

Type of toolWhat it actually checksWhich prohibition it servesWhere it stopsBest fit
Product and bill-of-materials screeningComponent and part data against covered producers, usually inside a hardware BOMMostly Part A, what you deliverIt says nothing about the switches and cameras in your own officesManufacturers and resellers delivering hardware into federal contracts
Denied-party and entity screeningSupplier names against sanctions, debarment and restricted-party listsNeither, directlyThe covered-entity list is statutory, not a screening list, and affiliates are the hard partFirms that already run export-control screening and want 889 folded in
IT asset discoveryWhat is on your network right now, by make and modelPart B, at a point in timeDiscovery is evidence, not an inquiry. It has no record of who you asked or what they answeredLarger contractors with an existing asset management program
Compliance records platformThe inquiry itself: method, date, scope, supplier attestations and the representation each one supportsBoth, because it holds the reasoning rather than the scanIt does not read your BOM or your network for youAny contractor whose exposure is the representation rather than the hardware

If you only buy one, buy the one that produces the file. A scan proves what was true on a Tuesday. A documented inquiry proves you met the standard the FAR set, which is the thing you will be asked about.

Do I need an audit to comply with Section 889?

No, and this is where a lot of money gets spent unnecessarily. FAR 4.2101 defines a reasonable inquiry as one designed to uncover information already in your possession about who produced or provided the equipment you use, and it expressly excludes the need to include an internal or third-party audit. The standard is diligence, not assurance.

The FAR Council has since made that even more explicit. In a proposed rule published on 23 June 2026 it moves Section 889 into a consolidated FAR Subpart 40.2 and applies one reasonable-inquiry standard across every security prohibition, stating that an offeror or contractor does not need to conduct an internal or third-party audit and that due diligence does not require gathering information outside its possession. The preamble is unusually blunt about why: inconsistent standards created uncertainty and added liability risk for industry.

So when a vendor sells you a Section 889 audit, be clear about what you are buying. It may be useful. It is not what the regulation requires, and buying it does not raise the standard you are held to.

What to look for when you compare Section 889 tools

Five things separate a tool that will hold up from a tool that produces a dashboard.

  • It records the inquiry, not just the result. Method, scope, date, who was asked, what came back. A green tick with no provenance is worth nothing when a certification is challenged.
  • It keeps the two representations apart. FAR 52.204-26 is the annual representation in the System for Award Management. FAR 52.204-24 is answered offer by offer. Teams that treat these as one thing miss the offer-level answer, which is the more common failure.
  • It handles flow-down correctly. FAR 52.204-25(e) requires the substance of the clause in all subcontracts excluding the paragraph (b)(2) use prohibition. A tool that pushes the whole clause down to every supplier is asking your subcontractors to certify something the FAR did not ask them to certify.
  • It has a report ready to file. On discovery you owe the contracting officer the contract and order numbers, supplier name, CAGE code, brand, model number and your mitigation, within one business day. Assembling that from scratch under a one-day clock is how disclosures go out incomplete.
  • It reuses evidence you already have. If you hold a SOC 2 report, an ISO 27001 statement of applicability or a FedRAMP package, you already maintain an asset inventory and a vendor register. A tool that makes you rebuild both as a separate exercise is adding cost, not control.

Does Section 889 flow down to subcontractors?

Yes, and the detail matters more than the headline. The prohibition on what gets delivered into the contract travels to subcontractors at every tier. The broader prohibition on what a company uses in its own operations does not, because the clause carves paragraph (b)(2) out of the flow-down. The FAR Council kept the same structure in its 2026 proposal, excluding paragraphs (d)(1) and (j)(1) from the new clause at FAR 52.240-3(k).

Practically, this means your supplier questionnaire should ask two different things of two different populations, which is an ordinary vendor tiering decision. Suppliers who deliver technology into federal work get the full inquiry. Suppliers who do not can attest to the narrower question. Sending every vendor the same 889 letter is the pattern that produces low response rates and attestations nobody reads.

Is there a Section 889 compliance list I can check a supplier against?

There is no official database that returns yes or no for an arbitrary company. The covered entities are named in statute, Huawei and ZTE for telecommunications equipment and Hytera, Hangzhou Hikvision and Dahua for video surveillance and certain telecommunications equipment, together with their subsidiaries and affiliates. GSA publishes decision trees and FAQs, and agencies screen internally, but nobody maintains a searchable registry that resolves the affiliate question for you.

The affiliate question is the hard one, and it is genuinely a research task rather than a compliance task. Working out whether a supplier is a subsidiary of a covered producer means tracing corporate ownership through public filings, registries and trade records, and the useful output is a sourced, timestamped record of what public sources say rather than a verdict. Attach that record to the inquiry file. Whatever you conclude, the value is in showing your working.

What changes if the June 2026 FAR rewrite is finalized

Quite a lot, and almost none of it is in circulation yet, because published Section 889 guidance still describes FAR Subpart 4.21 and clauses 52.204-24, 52.204-25 and 52.204-26. Those remain the operative text: the June 2026 rule is a proposal, comments closed on 23 July 2026, and no final rule has issued. But the direction is set, and three of the changes are substantive rather than cosmetic.

TodayProposedWhy it matters to a buyer
One business day for the first report, ten business days for mitigation detailA single report, 72 hours from discoveryTwo report templates collapse into one, and the clock gets slightly kinder
No definition of what counts as useCommercial sales, maintenance, testing services, warranty services and an employee's use of personal equipment are not individually considered useSettles the personal-device argument that has run since 2020
Critical technology defined through export-control listsA technology in whose absence a system cannot adequately operate or functionA far narrower scoping test, which shrinks the population of systems you have to reason about
Section 889 sits in its own subpartConsolidated into FAR Subpart 40.2 with FASCSA orders and covered procurement actionsOne procedure for several prohibitions, so a tool built only around 889 will be solving a smaller share of the problem

That last row is the buying consideration. If the consolidation goes through, a point solution scoped to Section 889 alone covers one prohibition inside a subpart that governs several. Software that already treats supply chain prohibitions as one records problem does not need rebuilding.

Which tool fits which contractor

Your situationWhat you actually needWhat you can skip
Software or services firm, no hardware deliveredA documented Part B inquiry, an asset and vendor record, and the two representations tracked separatelyBOM screening. You have no bill of materials to screen
Reseller or integrator shipping hardwareProduct screening for what you deliver, plus the Part B inquiry for your own operationsNothing. This is the profile that genuinely needs both
Prime with a deep subcontractor tierFlow-down tracking, attestation collection and re-request cadence, tiered by what each sub suppliesSending an identical 889 letter to every supplier
Small business chasing a first federal awardA written inquiry method, an equipment list and dated answers. The standard scales to your resourcesAn audit. The FAR says explicitly it is not required
Already running CMMC or FedRAMPTo connect 889 to the inventory and vendor register you already maintainA parallel program with its own asset list

Where Scrutineer fits

Scrutineer is the records half. It holds the reasonable inquiry behind each representation with its method and date, stores the supplier and subcontractor attestations that support it, keeps the annual SAM representation and the offer-level provision on separate clocks, and reuses the control evidence and vendor records you already maintain for other frameworks rather than asking you to build a second inventory. If your suppliers are already tracked for supplier risk, the 889 inquiry becomes one more question against a population you have.

It does not read your bill of materials and it does not scan your network. If you deliver hardware, pair it with a product screening tool. What it gives you is the thing the clause is actually enforced on: a file showing you asked, when you asked, and what you were told.

The full obligation map, including the FAR citations for each requirement and what the June 2026 proposal would change, is on the Section 889 compliance software page.

See Scrutineer scrutinize your posture

Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.

Scrutinize on real evidence, not stale spreadsheets

Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and scores vendor risk continuously, and returns a readiness report with a prioritized gap list. AI scrutinizes, you decide.

Automated evidence · Per-control statuses · Prioritized gap list

Mapped controls · evidence-linked rationale for every status · an accredited auditor issues the attestation.