DoD Commercial-Off-the-Shelf (COTS) Information and Communications Technology Supply Chain Risk Management : Department of Defense , June 9 , 2025
From the document: “The DoD must ensure information and communication technologies (ICT) deployed in every warfighting domain are capable of securely and reliably operating within contested environments. As the Department's ICT risk manager, the Office of the Chief Information Officer (OCIO) is leading this effort. This intensified effort is driven by the need to adapt our cybersecurity and supply chain risk management (SCRM) practices to the rapid pace of software development and the increasing complexity of supply chain risk. We need to accelerate our ability to adopt secure software and technology solutions across all warfighting domains. Current authorization processes often hinder the rapid deployment of critical capabilities, and we lack sufficient visibility into the security and integrity of our increasingly complex technology supply chains.
On March 6, the Secretary of Defense directed all DoD Components to adopt the Software Acquisition Pathway (SWP) as the preferred pathway for all software development components of business and weapon system programs in the Department. This directive recognizes that software is at the core of every weapon and supporting system we.field to remain the strongest, most lethal fighting force in the world. To that end, on April 24, I initiated a 90-day Software Fast-Track (SWFT) initiative to: (1) define clear, specific cybersecurity and SCRM requirements; (2) establish rigorous software security verification processes; (3) develop secure information sharing mechanisms; and (4) leverage standardized risk determinations to expedite cybersecurity authorizations for rapid software adoption. This initiative directly addresses the need to accelerate secure software adoption within the Department.”
Authors - Chief Information OfficerRelated Resources