Scrutineer.ai

Scrutineer · By framework

889 compliance software for Section 889 and NDAA rules

Section 889 compliance is a records problem, not a scanning problem. The FAR defines the reasonable inquiry behind your representation as one that looks at information already in your possession and expressly excludes the need for an internal or third-party audit. What a contracting officer can test afterwards is whether you ran that inquiry, when, and what it found.

Scrutineer holds the inquiry, the supplier attestations behind it and the dated evidence, so the representation you sign in SAM has a file underneath it.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with section 889

The inquiry the FAR actually asks for, on the record

Section 889 is enforced through a representation you sign, and the thing a contracting officer can test afterwards is not your network. It is whether you ran a reasonable inquiry, when you ran it, and what it turned up. FAR 4.2101 defines that inquiry as one that looks at information already in your possession and excludes the need for an internal or third-party audit. Scrutineer keeps the method, the date and the result attached to each representation.

Supplier attestations, including the paragraph that does not flow down

The clause travels to subcontractors at every tier, but not all of it: FAR 52.204-25(e) tells you to insert the substance of the clause excluding the paragraph (b)(2) use prohibition. That single carve-out is the reason a blanket flow-down letter is both over-broad and hard to defend. Scrutineer tracks which suppliers were asked what, holds the returned attestations, and re-asks on your own cadence.

Two representations, two clocks, and a rewrite already proposed

FAR 52.204-24 is answered offer by offer and FAR 52.204-26 is the annual representation you refresh in SAM, and teams routinely treat them as one thing. Scrutineer keeps them apart, and flags where the FAR Council's proposed rewrite published on 23 June 2026 would change the underlying obligation rather than just the numbering.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Records the reasonable inquiry behind every Section 889 representation, with the date, the method and what it returned
  • Holds supplier and subcontractor attestations against the flow-down at FAR 52.204-25(e), and re-requests them on a cadence you set
  • Keeps the two prohibitions apart, because 889(a)(1)(A) is about what you sell the Government and 889(a)(1)(B) is about what your own business runs
  • Separates the offer-by-offer representation at FAR 52.204-24 from the annual SAM representation at FAR 52.204-26, so neither goes stale unnoticed
  • Keeps a discovery report ready to file, with the contract and order numbers, supplier name, CAGE code, brand and model the clause asks for
  • Reuses the technology inventory and vendor records you already maintain for SOC 2, ISO 27001 or FedRAMP instead of standing up a separate exercise
  • Tracks which award relied on which exception, so a micro-purchase or commercial off-the-shelf carve-out is a documented decision rather than an assumption
  • Flags where the proposed move of Section 889 into FAR Subpart 40.2 changes the obligation itself, not just the clause number
SECTION 889 readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Section 889 change reference

Every Section 889 obligation, what the rule in force says today, and what the June 2026 proposed FAR rewrite would change it to

Published guidance to Section 889 explains the prohibition, and the prohibition is the part almost nobody gets wrong: you already know you cannot ship Huawei or Hikvision into a federal contract. What costs contractors an award is the procedure around it, and the procedure is being rewritten. On 23 June 2026 the FAR Council proposed moving Section 889 out of FAR Subpart 4.21 into FAR Subpart 40.2, reissuing the clause as 52.240-3, collapsing two reports into one 72-hour report, and settling several arguments about scope that guidance written in 2020 still treats as open. Read the third column before you rewrite a policy.

Section 889 obligation The rule in force today Proposed FAR rewrite, 23 June 2026 Where it is written What to hold as evidence
Where the rule lives FAR Subpart 4.21, a standalone subpart for this one prohibition FAR Subpart 40.2, Security Prohibitions and Exclusions, sharing one structure with FASCSA orders, covered procurement actions, Sudan and Iran FAR 4.2101 to 4.2105 today; proposed FAR 40.201 to 40.205 Nothing in your file changes, but every internal policy that cites 4.21 needs a second citation
The contract clause FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment FAR 52.240-3, Security Prohibitions and Exclusions, with an Alternate I FAR case 2026-001, 91 FR 37550, 23 June 2026 Your clause register, showing which awards carry which version
The representation Two: FAR 52.204-24 answered offer by offer, and FAR 52.204-26 refreshed annually in SAM One: FAR 52.240-2, Security Prohibitions and Exclusions, Representations and Certifications, covering every prohibition at once FAR 4.2105 today; proposed FAR 40.205 The dated inquiry that supports each signature, not the signature alone
The reasonable inquiry standard Defined at FAR 4.2101, and worded slightly differently across the various security prohibitions A single standard across all of them, stating plainly that a contractor does not need an internal or third-party audit and that due diligence does not require gathering information outside its possession Proposed FAR 52.240-2(c) to (g) and 52.240-3(g) and (j)(2) A written method, plus what you reviewed and on what date
Reporting after discovery Two reports: one business day for the core facts, then ten business days for mitigation detail One report, 72 hours from discovery, deliberately aligned with incident-reporting timeframes FAR 52.204-25(d) today; proposed FAR 52.240-3(j)(3) A pre-drafted report holding contract and order numbers, supplier name, CAGE code, brand and model
What counts as use Undefined at the edges, which is where most of the argument happens Commercial sales, maintenance, testing services, warranty services and an employee's use of personal equipment are not individually considered use Proposed FAR 52.240-3(d)(1) The scoping decision you made and the reason you made it
Critical technology Defense articles on the USML, Commerce Control List items, nuclear equipment, select agents and toxins, and emerging technology under the Export Control Reform Act A technology in whose absence a system cannot adequately operate or function Proposed FAR 52.240-3(a) Which of your systems you concluded were in scope, and why
Defined terms No FAR definition of system, telecommunications equipment, telecommunications services, video surveillance equipment or video surveillance services All five defined, aligned to the definition of telecommunications at DFARS 239.7401 Proposed FAR 40.201 and 52.240-3 Your own working definitions and the source you took them from
Subcontractor flow-down The substance of FAR 52.204-25 in all subcontracts, excluding the paragraph (b)(2) use prohibition The substance of FAR 52.240-3 at any tier including commercial products and services, excluding paragraphs (d)(1) and (j)(1) FAR 52.204-25(e); proposed FAR 52.240-3(k) Executed flow-down language plus the attestation the subcontractor returned
Exceptions Purchases at or below the micro-purchase threshold, and certain commercially available off-the-shelf acquisitions Scope of the exceptions clarified, and the provision and clause are prescribed for commercial products, commercial services and COTS FAR 4.2102 today; proposed FAR 52.240-3(b)(3) The exception you relied on, recorded per award rather than assumed
What does not change Sections 889(a)(1)(A) and (a)(1)(B) of the FY2019 NDAA, Pub. L. 115-232, and the covered entities behind them Identical. The proposal renumbers, harmonizes and narrows the edges. It does not touch the statute or the covered-entity list Pub. L. 115-232 Treat the covered-entity list as fixed and the procedure around it as in flux

FAR case 2026-001 was published at 91 FR 37550 on 23 June 2026 and comments closed on 23 July 2026. It is a proposed rule, so FAR 52.204-24, 52.204-25 and 52.204-26 remain the operative text until a final rule issues. Scrutineer prepares you for a Section 889 representation and keeps the evidence behind it. It is not a law firm and does not make the representation for you.

Good questions

Questions about section 889

Section 889 compliance means you can represent truthfully that you do not sell the Government covered telecommunications or video surveillance equipment, and that your own business does not use it as a substantial or essential component of any system. The equipment comes from Huawei, ZTE, Hytera, Hikvision and Dahua, and their subsidiaries and affiliates. The representation is made in SAM and again on individual offers.
No, and the FAR says so directly. FAR 4.2101 defines a reasonable inquiry as one designed to uncover information already in your possession, and it expressly "excludes the need to include an internal or third-party audit." The June 2026 proposed rewrite goes further, adding that due diligence does not require gathering information outside your possession. What you owe is a documented inquiry, not an assessment.
It is the diligence that has to sit behind your representation before you sign it. The standard is what a reasonably prudent person would do with the resources actually available, so a five-person firm and a defense prime are held to different levels of effort. Keep the record: what you looked at, who you asked, when, and what came back.
Part A, section 889(a)(1)(A), stops an agency buying covered equipment or services from you, and has applied since 13 August 2019. Part B, section 889(a)(1)(B), stops an agency contracting with you at all if your own organization uses covered equipment, anywhere in your business, on federal work or not. Part B has applied since 13 August 2020 and is the harder one.
Both, and they are different documents. FAR 52.204-26 is the annual representation you keep current in SAM. FAR 52.204-24 is answered on individual solicitations and can require a second, narrower answer about the specific offer. Refreshing SAM once a year does not discharge the offer-level provision, which is where most avoidable errors happen.
Yes, but not the whole clause. FAR 52.204-25(e) requires you to include the substance of the clause in all subcontracts, expressly excluding the paragraph (b)(2) use prohibition. So subcontractors inherit the restriction on what they supply into the contract, not the wider prohibition on what their own business runs. The proposed rewrite keeps the same shape at FAR 52.240-3(k).
You report it. Under FAR 52.204-25(d) you have one business day to give the contracting officer the contract and order numbers, supplier name, CAGE code, brand, model and what you are doing about it, then ten business days for further mitigation detail. The June 2026 proposal replaces that with a single report due 72 hours from discovery.
Five named producers and their subsidiaries and affiliates: Huawei and ZTE for telecommunications equipment, and Hytera, Hangzhou Hikvision and Dahua for video surveillance and telecommunications equipment used for public safety, security of government facilities, physical security surveillance of critical infrastructure and other national security purposes.
Under the rule as written today this is genuinely contested, which is why it comes up constantly. The FAR Council has now taken a position: its June 2026 proposed rule states that an employee's use of personal equipment is not individually considered use of covered telecommunications equipment. That is a proposal, not law, so document the call you make and the basis for it.
There is no single official database that returns a yes or no for an arbitrary supplier. GSA publishes decision trees and FAQs, and agencies run internal screening, but the covered-entity list is defined by statute rather than maintained as a searchable registry. In practice you rely on supplier attestations plus your own record of what you asked and what came back.
The representation is made to obtain a federal contract, so an inaccurate one is exposure under the False Claims Act as well as grounds for termination and suspension or debarment. That is why the defensible position is a dated, repeatable inquiry rather than a confident answer. A good-faith documented process is what you have when the certification is challenged.
The prohibition at FAR 4.2102 does not apply to purchases at or below the micro-purchase threshold, and there are conditions attached to certain commercially available off-the-shelf acquisitions. Record which exception you relied on for a given award. An exception you can name and date is a defense; an exception you assumed is not.
It is proposed to be. On 23 June 2026 the FAR Council published a proposed rule under the Revolutionary FAR Overhaul moving Section 889 into FAR Subpart 40.2 and reissuing the clause as FAR 52.240-3, with a new representations provision at 52.240-2. Comments closed 23 July 2026. Until a final rule issues, 52.204-24, 52.204-25 and 52.204-26 remain the operative text.
Largely yes. Section 889 reaches commercial products and commercial services, and the June 2026 proposal prescribes both the new provision and the new clause for commercial products, commercial services and COTS acquisitions. The narrow COTS relief at FAR 4.2102 is specific and conditional, so treat COTS as in scope unless you have identified the exact carve-out.
Section 889 is a fixed statutory prohibition on five named producers. A FASCSA order is an exclusion or removal order issued case by case against a particular source or covered article. They have run on separate procedures and separate reporting clocks, which is precisely what the proposed consolidation into FAR Subpart 40.2 is meant to end.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification