Starting with MAS Refresh 33, dated October 2, 2026, GSA evaluates supply chain risk on every new Schedule offer. GSA can look at who owns and controls your company, where your products come from, and whether your paperwork matches. If it finds a risk you cannot fix, it can remove you from consideration.
What is the new supply chain risk evaluation in Refresh 33?
It is three new pieces of text. A new paragraph (d) in SCP-FSS-001, the offer instructions. A new provision, GSAR 552.540-70, that applies while GSA evaluates your offer. And a new clause, GSAR 552.540-71, that applies for the life of your contract. Together they let GSA screen every offeror.
| New text | When it applies | What it says in plain terms |
|---|---|---|
| SCP-FSS-001 (SEP 2026), paragraph (d) | When you submit an offer | GSA will evaluate supply chain risk tied to you, your products and services, and your supply chains |
| GSAR 552.540-70 (provision) | During evaluation | Unacceptable supply chain risk can be grounds to remove an offeror from consideration |
| GSAR 552.540-71 (clause) | After award, through performance | GSA monitors risk and can remove items, decline to extend, cancel, or terminate |
GSA says this formalizes what it was already doing. I agree, and that is exactly why it matters. When I was a Contracting Officer, supply chain questions came up case by case. Now they sit in a numbered provision, and numbered provisions get checked on every file.
What does GSA actually look at?
Ownership comes first. The solicitation says the evaluation "may include reviewing corporate ownership, control, affiliation, and subsidiary relationships" to find connections to entities that are prohibited or restricted by law. GSA can pull that information from government sources, commercial screening tools, public records, and your own offer.
GSA's Part 540 FAQ lists the kinds of risk it considers:
- Foreign Ownership, Control, or Influence (FOCI)
- Company information, meaning who the source really is
- Geopolitical risk
- Cybersecurity risk
- Compliance and legal risk
- Supply chain relationships, visibility, and controls
- Physical and personnel risk
- Functionality, features, and components of what you sell
The same FAQ names how GSA finds these risks. The list includes third-party commercial supply chain illumination tools, agency information sharing, the Federal Acquisition Security Council, and offeror-submitted questionnaires. Read that as a warning. GSA no longer depends only on what you choose to disclose.
Do you have to submit anything new with your offer?
No new form. The Refresh 33 solicitation does not add a supply chain document to the eOffer upload list. But GSA names offeror-submitted questionnaires and information as one way it identifies risk, so a Contracting Officer can ask you questions during evaluation. Be ready to answer them quickly and consistently.
What the solicitation does add is an instruction. Offerors "should ensure their offers are accurate and transparent regarding corporate structure and ownership, product country of origin and authorization (e.g., manufacturer status or Letter of Supply), and applicable compliance representations." That sentence is your checklist.
Does this apply if you only sell services?
Yes. Paragraph (d) covers "the Offeror and its proposed products, services, and related supply chains." The ownership and control review applies to every company. The product pieces, country of origin and Letters of Supply, apply when you offer products.
| What GSA reviews | Services-only offer | Product offer |
|---|---|---|
| Corporate ownership and control | Yes | Yes |
| Affiliates and subsidiaries | Yes | Yes |
| Compliance representations | Yes | Yes |
| Product country of origin | Not applicable | Yes |
| Manufacturer status or Letter of Supply | Not applicable | Yes |
What happens if GSA finds a risk?
GSA says the Contracting Officer will, if possible, work with you to fix it. If one product is the problem, that product can be removed so the rest of the offer moves forward. If the risk cannot be mitigated, the product or the whole offer can be removed from consideration.
| Stage | First response | If it cannot be fixed |
|---|---|---|
| Offer under evaluation | Contracting Officer works with you to mitigate; a single product may be pulled | Product or offeror removed from consideration |
| Active contract | Item may be temporarily removed from your catalog while you respond | Item removed, option not exercised, contract cancelled, or contract terminated |
One detail to notice. GSA's FAQ says it "may" notify you when it identifies a risk. It does not promise to. That is one more reason to find your own inconsistencies before GSA does.
Where do offers get into trouble?
Mismatches. The most common problem is not a hidden foreign owner. It is a company that tells three slightly different stories about itself in SAM.gov, in eOffer, and in its narratives. A screening tool flags the mismatch, and the Contracting Officer has to ask why.
As a Contracting Specialist reviewing offers, I saw this constantly. The SAM registration named one parent company. The corporate experience narrative described another. Nobody was hiding anything. The record was simply out of date. Under Refresh 33, that kind of gap now lands inside a formal risk evaluation.
Run this check before you submit:
- Ownership in SAM.gov. Confirm the immediate owner and highest-level owner in your SAM.gov registration are current.
- Ownership in your narratives. Make sure your corporate experience narrative describes the same parents, subsidiaries, and affiliates.
- Country of origin. For products, confirm every item's country of origin and that it meets the Trade Agreements clause, FAR 52.225-5.
- Authorization to sell. If you are not the manufacturer, confirm your Letters of Supply are current and cover every item.
- Representations. Confirm your answers under FAR 52.240-90, the security prohibitions and exclusions representations, are accurate.
Is this the same as CMMC?
No. GSA says the two are "completely different." The Department of Defense's Cybersecurity Maturity Model Certification checks your internal network and how you protect Controlled Unclassified Information. GSA's supply chain requirements look at the security and integrity of the products, services, and solutions you offer.
- CMMC: a certification of your own systems, required on certain DoD contracts.
- GSA Part 540: a risk review of your company and what you sell, on every MAS offer and contract.
What does this mean if you already hold a Schedule?
The monitoring clause, GSAR 552.540-71, reaches existing contracts through the Refresh 33 mass modification. Once it is in your contract, GSA can monitor supply chain risk for as long as you hold the contract, and the remedies run all the way to termination.
- Accept the mass modification on time. GSA gives 90 days from the date it issues the mod. See how the 90-day window works.
- Tell GSA about ownership changes. A sale, merger, or new investor changes your risk picture. Update SAM.gov and your Contracting Officer.
- Expect formal rulemaking. GSA says it will take this provision and clause through the rulemaking process, so details can still change.
What Should You Do Now?
- Write down your ownership tree. Parents, subsidiaries, affiliates, and any foreign ownership. One page.
- Make SAM.gov, eOffer, and your narratives match it. Fix the record before you submit, not after a question arrives.
- Product sellers: audit country of origin and Letters of Supply. Remove any item you cannot document.
- Answer GSA's questions fast and the same way every time. Inconsistent answers turn a question into a finding.
- Current contractors: accept the mass mod within 90 days. Then report ownership changes as they happen.
I spent eighteen years in federal acquisition as a Contracting Specialist and Contracting Officer at GSA, IRS, DoD, DOI, HHS, FTC, and Energy. I hold FAC-C Level III certification and a Master of Liberal Arts from Harvard University, and Blackfyre has 70+ GSA contract awards behind it. If you want your ownership record and offer checked for mismatches before a Contracting Officer sees them, that review is part of our GSA Schedule program.
Frequently Asked Questions
What is GSAR 552.540-70?
GSAR 552.540-70, Notice of Evaluation of Supply Chain Risk, is a new provision added to the GSA MAS solicitation in Refresh 33. It says the Government may consider supply chain risk information during evaluation and that unacceptable supply chain risks may be grounds to remove an offeror from consideration.
Do I have to submit a new supply chain form with my GSA MAS offer?
No. The Refresh 33 solicitation does not add a new supply chain upload in eOffer. GSA does list offeror-submitted questionnaires and information as one way it identifies risk, so a Contracting Officer can ask for more during evaluation.
Does the supply chain risk evaluation apply to services companies?
Yes. SCP-FSS-001 paragraph (d) covers the offeror and its proposed products, services, and related supply chains. The review of corporate ownership, control, affiliation, and subsidiaries applies to every offeror. Country of origin and Letters of Supply apply to product offers.
Will GSA tell me if it finds a supply chain risk?
Not necessarily. GSA's Part 540 FAQ says GSA may notify you, depending on the degree and nature of the risk and the evaluation factors in the solicitation. GSA also says the Contracting Officer will, if possible, work with offerors to mitigate identified risks.
Can GSA cancel my existing Schedule contract over a supply chain risk?
Yes. Under GSAR 552.540-71, if a supply chain risk cannot be reasonably mitigated, GSA can remove the product, service, or solution from the contract, decline to extend performance, cancel the contract, or terminate it. GSA says a first step may be temporarily removing the item from your catalog.
Is GSA's supply chain requirement the same as CMMC?
No. GSA states the requirements are completely different. CMMC certifies a contractor's internal network for protecting Controlled Unclassified Information on DoD contracts. GSA's requirements focus on the security and integrity of the products, services, and solutions offered to GSA and its customers.