Scrutineer · By framework
889 compliance software for Section 889 and NDAA rules
Section 889 compliance is a records problem, not a scanning problem. The FAR defines the reasonable inquiry behind your representation as one that looks at information already in your possession and expressly excludes the need for an internal or third-party audit. What a contracting officer can test afterwards is whether you ran that inquiry, when, and what it found.
Scrutineer holds the inquiry, the supplier attestations behind it and the dated evidence, so the representation you sign in SAM has a file underneath it.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with section 889
The inquiry the FAR actually asks for, on the record
Section 889 is enforced through a representation you sign, and the thing a contracting officer can test afterwards is not your network. It is whether you ran a reasonable inquiry, when you ran it, and what it turned up. FAR 4.2101 defines that inquiry as one that looks at information already in your possession and excludes the need for an internal or third-party audit. Scrutineer keeps the method, the date and the result attached to each representation.
Supplier attestations, including the paragraph that does not flow down
The clause travels to subcontractors at every tier, but not all of it: FAR 52.204-25(e) tells you to insert the substance of the clause excluding the paragraph (b)(2) use prohibition. That single carve-out is the reason a blanket flow-down letter is both over-broad and hard to defend. Scrutineer tracks which suppliers were asked what, holds the returned attestations, and re-asks on your own cadence.
Two representations, two clocks, and a rewrite already proposed
FAR 52.204-24 is answered offer by offer and FAR 52.204-26 is the annual representation you refresh in SAM, and teams routinely treat them as one thing. Scrutineer keeps them apart, and flags where the FAR Council's proposed rewrite published on 23 June 2026 would change the underlying obligation rather than just the numbering.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Records the reasonable inquiry behind every Section 889 representation, with the date, the method and what it returned
- Holds supplier and subcontractor attestations against the flow-down at FAR 52.204-25(e), and re-requests them on a cadence you set
- Keeps the two prohibitions apart, because 889(a)(1)(A) is about what you sell the Government and 889(a)(1)(B) is about what your own business runs
- Separates the offer-by-offer representation at FAR 52.204-24 from the annual SAM representation at FAR 52.204-26, so neither goes stale unnoticed
- Keeps a discovery report ready to file, with the contract and order numbers, supplier name, CAGE code, brand and model the clause asks for
- Reuses the technology inventory and vendor records you already maintain for SOC 2, ISO 27001 or FedRAMP instead of standing up a separate exercise
- Tracks which award relied on which exception, so a micro-purchase or commercial off-the-shelf carve-out is a documented decision rather than an assumption
- Flags where the proposed move of Section 889 into FAR Subpart 40.2 changes the obligation itself, not just the clause number
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Section 889 change reference
Every Section 889 obligation, what the rule in force says today, and what the June 2026 proposed FAR rewrite would change it to
Published guidance to Section 889 explains the prohibition, and the prohibition is the part almost nobody gets wrong: you already know you cannot ship Huawei or Hikvision into a federal contract. What costs contractors an award is the procedure around it, and the procedure is being rewritten. On 23 June 2026 the FAR Council proposed moving Section 889 out of FAR Subpart 4.21 into FAR Subpart 40.2, reissuing the clause as 52.240-3, collapsing two reports into one 72-hour report, and settling several arguments about scope that guidance written in 2020 still treats as open. Read the third column before you rewrite a policy.
| Section 889 obligation | The rule in force today | Proposed FAR rewrite, 23 June 2026 | Where it is written | What to hold as evidence |
|---|---|---|---|---|
| Where the rule lives | FAR Subpart 4.21, a standalone subpart for this one prohibition | FAR Subpart 40.2, Security Prohibitions and Exclusions, sharing one structure with FASCSA orders, covered procurement actions, Sudan and Iran | FAR 4.2101 to 4.2105 today; proposed FAR 40.201 to 40.205 | Nothing in your file changes, but every internal policy that cites 4.21 needs a second citation |
| The contract clause | FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment | FAR 52.240-3, Security Prohibitions and Exclusions, with an Alternate I | FAR case 2026-001, 91 FR 37550, 23 June 2026 | Your clause register, showing which awards carry which version |
| The representation | Two: FAR 52.204-24 answered offer by offer, and FAR 52.204-26 refreshed annually in SAM | One: FAR 52.240-2, Security Prohibitions and Exclusions, Representations and Certifications, covering every prohibition at once | FAR 4.2105 today; proposed FAR 40.205 | The dated inquiry that supports each signature, not the signature alone |
| The reasonable inquiry standard | Defined at FAR 4.2101, and worded slightly differently across the various security prohibitions | A single standard across all of them, stating plainly that a contractor does not need an internal or third-party audit and that due diligence does not require gathering information outside its possession | Proposed FAR 52.240-2(c) to (g) and 52.240-3(g) and (j)(2) | A written method, plus what you reviewed and on what date |
| Reporting after discovery | Two reports: one business day for the core facts, then ten business days for mitigation detail | One report, 72 hours from discovery, deliberately aligned with incident-reporting timeframes | FAR 52.204-25(d) today; proposed FAR 52.240-3(j)(3) | A pre-drafted report holding contract and order numbers, supplier name, CAGE code, brand and model |
| What counts as use | Undefined at the edges, which is where most of the argument happens | Commercial sales, maintenance, testing services, warranty services and an employee's use of personal equipment are not individually considered use | Proposed FAR 52.240-3(d)(1) | The scoping decision you made and the reason you made it |
| Critical technology | Defense articles on the USML, Commerce Control List items, nuclear equipment, select agents and toxins, and emerging technology under the Export Control Reform Act | A technology in whose absence a system cannot adequately operate or function | Proposed FAR 52.240-3(a) | Which of your systems you concluded were in scope, and why |
| Defined terms | No FAR definition of system, telecommunications equipment, telecommunications services, video surveillance equipment or video surveillance services | All five defined, aligned to the definition of telecommunications at DFARS 239.7401 | Proposed FAR 40.201 and 52.240-3 | Your own working definitions and the source you took them from |
| Subcontractor flow-down | The substance of FAR 52.204-25 in all subcontracts, excluding the paragraph (b)(2) use prohibition | The substance of FAR 52.240-3 at any tier including commercial products and services, excluding paragraphs (d)(1) and (j)(1) | FAR 52.204-25(e); proposed FAR 52.240-3(k) | Executed flow-down language plus the attestation the subcontractor returned |
| Exceptions | Purchases at or below the micro-purchase threshold, and certain commercially available off-the-shelf acquisitions | Scope of the exceptions clarified, and the provision and clause are prescribed for commercial products, commercial services and COTS | FAR 4.2102 today; proposed FAR 52.240-3(b)(3) | The exception you relied on, recorded per award rather than assumed |
| What does not change | Sections 889(a)(1)(A) and (a)(1)(B) of the FY2019 NDAA, Pub. L. 115-232, and the covered entities behind them | Identical. The proposal renumbers, harmonizes and narrows the edges. It does not touch the statute or the covered-entity list | Pub. L. 115-232 | Treat the covered-entity list as fixed and the procedure around it as in flux |
FAR case 2026-001 was published at 91 FR 37550 on 23 June 2026 and comments closed on 23 July 2026. It is a proposed rule, so FAR 52.204-24, 52.204-25 and 52.204-26 remain the operative text until a final rule issues. Scrutineer prepares you for a Section 889 representation and keeps the evidence behind it. It is not a law firm and does not make the representation for you.
Good questions
Questions about section 889
Keep reading
Guides that go deeper on this framework
Best Section 889 compliance software
What the tools in this category actually do, where they differ, and which part of the obligation each one leaves with you.
Read the guideFISMA vs FedRAMP
How federal security obligations reach a contractor through contract terms rather than directly, and which one applies to you.
Read the guideVendor tiering that holds up
How to decide which suppliers get a full inquiry and which get an attestation, without treating every vendor the same.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification