FOCI in NIST SP 1326: What It Means and What Buyers Will Ask Your Supplier

NIST finalized Special Publication 1326 on July 8, 2026. The C-SCRM Due Diligence Assessment Quick-Start Guide gives procurement teams a structured way to evaluate ICT suppliers across five components. If you are a supplier preparing for those conversations - or a buyer standing up a supplier assessment program - this article covers one of the five components in depth: FOCI, which stands for Foreign Ownership, Control, or Influence.

FOCI is not a technical security question. It is a corporate-governance and disclosure question. Understanding the distinction early saves both sides a lot of confusion.


What FOCI Means in the Context of C-SCRM

The term FOCI comes originally from US government contracting and facility security clearance processes, where it describes situations in which a foreign interest holds enough ownership, board access, or contractual leverage to direct or influence the decisions of a US company in ways that could harm national security.

NIST SP 1326 carries that concept into commercial ICT due diligence. The question buyers are asking is: could a foreign government, state-owned enterprise, or foreign investor with policy leverage direct this supplier's behavior in ways that conflict with the buyer's interests or US law?

This matters for ICT suppliers because software and hardware carry risk vectors that physical goods do not. A storage vendor under undisclosed foreign influence could, in a worst case, be directed to alter firmware, suppress a vulnerability disclosure, or hand over telemetry. Buyers do not have to prove malicious intent to have a legitimate reason to ask these questions - they just have to do reasonable due diligence.


The Five Signals Assessors Examine

When an assessor works through the FOCI component of SP 1326, they are typically looking at a cluster of signals. None of these alone is necessarily disqualifying, but each can trigger a deeper conversation.

1. Ownership structure Who owns equity in the supplier, and in what percentages? Are there foreign parent companies, holding companies registered in offshore jurisdictions, or state-linked investment vehicles? Assessors want to see a complete beneficial-ownership picture, not just the top-of-org-chart entity.

2. Investment sources Who provided capital, at what stage, and under what terms? Foreign venture or private-equity investors with board seats or information rights are a different risk profile than passive minority shareholders. Special attention goes to investors with known ties to foreign governments or sovereign wealth funds.

3. Board and executive composition Do any board members, officers, or advisors hold positions in foreign government bodies, state-owned enterprises, or entities on denied-party lists? Even informal advisory relationships can be relevant.

4. Jurisdictional exposure Where is the company incorporated? Where are key R&D operations, data centers, or engineering teams located? Does the supplier operate under long-term contracts or licensing dependencies on entities in jurisdictions subject to US export controls or sanctions?

5. Contractual control mechanisms Are there licensing agreements, source-code escrows, data-sharing obligations, or supply agreements that effectively give a foreign party control over a product's roadmap, security updates, or customer data?


What Suppliers Need to Prepare

Preparing for a FOCI assessment is a documentation exercise, not a product certification exercise. There is no software tool that produces a "FOCI-compliant" badge - and SP 1326 does not create one. What buyers need is honest, verifiable disclosure.

Practically, that means assembling:

The disclosure statement does not have to be long. It has to be accurate and current. Assessors are not looking for a clean record; they are looking for honest self-awareness and a process that catches changes before they become surprises.

If your corporate structure is genuinely complex - foreign parent, multiple jurisdictions, PE ownership with international LPs - consider involving legal counsel familiar with FARA, CFIUS, and EAR/ITAR frameworks before you draft the disclosure. Those regimes inform how assessors will read what you give them.


FOCI Is One of Five Components - The Others Are Technical

SP 1326 structures supplier due diligence across five areas. FOCI is the corporate-governance piece. The other four - Provenance, Resilience, Foundational Cyber Practices, and Supply Chain Tiers - are where technical evidence matters.

Provenance, for example, asks buyers to understand what is actually in a supplier's software: open-source components, their versions, their known vulnerabilities, and their licenses. That is exactly the problem SBOM generation and software composition analysis (SCA) addresses. A supplier that can produce a current, accurate SBOM - and show a process for keeping it current - is materially better positioned to answer Provenance questions than one that cannot.

Labrador is designed for that kind of work. It runs SAST on proprietary source code, SCA across open-source dependencies, and generates supply-chain / SBOM analysis that gives both internal teams and external assessors something concrete to review. That is a different conversation than FOCI - but it is part of the same SP 1326 assessment, and getting the technical components documented strengthens a supplier's overall posture.

We cover the Provenance and Supply Chain Tiers components in separate articles in this series. If you want to explore how Labrador maps to those technical requirements, start at apona.ai/labrador.


The Takeaway

FOCI is a legitimate and important due diligence question. It is also one that software cannot answer for you. The work is in your cap table, your board minutes, your org chart, and your disclosure process.

Get the governance documentation in order. Be direct about what your structure looks like. Then turn your attention to the technical components of SP 1326 - because buyers will ask both, and the answers need to hold up together.

This post is about Labrador.