Map your defense supply chain to the mine.

EO 14415 directs DoD to require contractors at any tier to map and illuminate critical supply chains from raw materials to end-use products. The rules land in 2027. The mapping starts now.

Run a critical mineral trace →

1 Jan 2027

Waivers close under 10 U.S.C. 4872 for covered materials

16 Jan 2027

DoD implementation guidance due, regulations 90 days after

n-tier

Origin tracing from mine and refiner to finished system

~60%

Of global trade activity sits below the declared customs layer

An indentured bill of materials, seven levels down. Most contractors know their tier ones. The order asks about tier four and the mine underneath it. This is a public-data trace of a seeker section, run in GRID.

Seeker section, precision strike missile

End item · designated national security acquisition

Prime, USCORROBORATED
Tier 1 integrator, US · ArizonaTier 2 supplier, US · MassachusettsTier 3 supplier, DE · Bavaria

Samarium-cobalt magnet blank

Tier 4 material · declared EU origin, observed CN shipment

Tier 4 supplier, CN · NingboDIVERGENT

10 nodes visible, 6 levels deep. 3 carry divergent origin, where observed shipment data contradicts the supplier declaration. A tier-one certification would not surface any of them.

Read full report

The waiver restrictions are the headline. Sections 3 and 4 are the work.

Map and illuminate

Contractors at any tier, for designated national security acquisitions, tracing critical supply chains from raw materials through finished products.

Indentured bill of materials

A new concept in the order. Components traced back to the origin of the raw material, not to the tier one who assembled them.

Foreign ownership and control

Suppliers under the control of prohibited sources identified at any depth, before they threaten production during a conflict.

Alternative source qualification

Domestic and allied sources qualified in advance, with a mitigation plan required for anything still dependent on a restricted supplier.

The regulations are not written yet. That is the opening.

Contractual remedies sit behind all of it. The order directs DoD to consider declining options, suspending task orders, and terminating contracts where alternative sources go unqualified. Supply chain visibility is moving from a certification question to a performance question, on the path cybersecurity took through CMMC.

Now →

Assess readiness before it becomes a contract term

1 Jan ‘27

Waivers close for covered materials

16 Jan ‘27

DoD guidance due

+90 days

Implementing regulations follow

Contemplated rules would require notice to DoD of significant supply chain risks within 15 days of completing supplier vetting, a corrective action plan within 45 days, and a closeout report after mitigation.

Integrate where the data lives. Illuminate the material. Hand over the report.

Unify your data where it lives.

One connected graph across internal ERP and BOM, external bill-of-lading, AIS, sanctions and ownership records, federated queries against willing suppliers in-jurisdiction, and inference where data is missing. Deployable inside your perimeter. No central pool, no migration.

ERP / BOMBILL OF LADINGAISFOCIFEDERATED QUERY

Trace the material, not the vendor name.

GRID surfaces the n-tier supplier graph from your bill of materials and carries origin, ownership and confidence on every edge. Where a supplier declines to report, inference fills the gap with a confidence score attached, never a guess presented as fact.

INDENTURED BOMORIGIN TRACINGOWNERSHIP CHAINSCONFIDENCE

Hand your compliance officer the document.

Exposure ranked by consequence, scoped to a program or a part number, exported as an audit-ready record with provenance on every data point. Scenario modeling for supplier loss, chokepoint closure and sanctions shock, scored across cost, risk and time.

AUDIT-READY EXPORTPROVENANCESCENARIO MODELSOURCE SCORING

A certification is a string on a form. Sourcing compliance today rests on supplier self-attestation. EO 14415 pushes past it. GRID lays what your suppliers declared against what independent trade, vessel and ownership data shows, then labels every node.

Corroborated. Declared, and confirmed in independent transactional data.

Divergent. Observed activity contradicts the declaration. The gap is the finding.

Additional. A supplier the declared graph never mentioned, surfaced from observed activity.

Unobserved. Declared, not yet seen in external data. Reported plainly as unobserved.


We sell synthesis you can defend in an audit, never a guess dressed up as certainty.

Run a trace

A replacement for the process you would otherwise run by hand.

REQUIREMENT

TODAY'S PROCESS

WITH GRID

Sub-tier supplier mapping

Consultant-led mapping exercise. Three to six months, $500K to $2M, out of date on delivery.

41,300+ supplier relationships mapped in days, validated against ground-truth BOM. No survey required.

Raw material origin tracing

Supplier questionnaires and self-attestation, unverifiable past tier one.

Indentured BOM traced to origin, every node labeled corroborated, divergent or unobserved.

Foreign ownership and control

Manual screening against sanctions lists at the vendor level.

Ownership and control chains resolved across tiers, scored against prohibited-source exposure.

Alternative source qualification

Ad hoc sourcing search started after a waiver is denied.

Alternative supply chain designs scored across cost, risk and time, before the mitigation plan is due.

Compliance documentation

Manual filings and legal review, months of effort per submission.

Audit-ready export with Proof-of-Authority provenance on every data point.

When the Strait of Hormuz seized, the companies that moved first already knew which of their inputs ran through it.

We saw the chokepoint close before it was a crisis.

EO 14415 is the same problem with a deadline attached. DoD is not asking who builds the system. It is asking where every critical component originates, and it will start asking in writing next year.

Contractors that map before the regulations land will file mitigation plans from a position of knowledge. Run a trace on public data first, then we run it on your program, privately, to the part number.

Find your exposure before the rule finds it for you.

One program or one critical input. We surface the n-tier dependency from your BOM, resolve ownership and origin, and hand you the exposure picture in weeks.

  1. 01Your n-tier dependency map, traced from BOM to raw material origin
  2. 02Foreign ownership and control exposure resolved across tiers
  3. 03Every node labeled corroborated, divergent or unobserved
  4. 04An audit-ready export with provenance on every data point
  5. 05The readiness assessment to run before DFARS rules land