← All articles Compliance

What Does GSA Check About Your Company Under the New MAS Supply Chain Risk Evaluation?

Starting with MAS Refresh 33, dated October 2, 2026, GSA evaluates supply chain risk on every new Schedule offer. GSA can look at who owns and controls your company, where your products come from, and whether your paperwork matches. If it finds a risk you cannot fix, it can remove you from consideration.

What is the new supply chain risk evaluation in Refresh 33?

It is three new pieces of text. A new paragraph (d) in SCP-FSS-001, the offer instructions. A new provision, GSAR 552.540-70, that applies while GSA evaluates your offer. And a new clause, GSAR 552.540-71, that applies for the life of your contract. Together they let GSA screen every offeror.

New textWhen it appliesWhat it says in plain terms
SCP-FSS-001 (SEP 2026), paragraph (d)When you submit an offerGSA will evaluate supply chain risk tied to you, your products and services, and your supply chains
GSAR 552.540-70 (provision)During evaluationUnacceptable supply chain risk can be grounds to remove an offeror from consideration
GSAR 552.540-71 (clause)After award, through performanceGSA monitors risk and can remove items, decline to extend, cancel, or terminate

GSA says this formalizes what it was already doing. I agree, and that is exactly why it matters. When I was a Contracting Officer, supply chain questions came up case by case. Now they sit in a numbered provision, and numbered provisions get checked on every file.

What does GSA actually look at?

Ownership comes first. The solicitation says the evaluation "may include reviewing corporate ownership, control, affiliation, and subsidiary relationships" to find connections to entities that are prohibited or restricted by law. GSA can pull that information from government sources, commercial screening tools, public records, and your own offer.

GSA's Part 540 FAQ lists the kinds of risk it considers:

The same FAQ names how GSA finds these risks. The list includes third-party commercial supply chain illumination tools, agency information sharing, the Federal Acquisition Security Council, and offeror-submitted questionnaires. Read that as a warning. GSA no longer depends only on what you choose to disclose.

Do you have to submit anything new with your offer?

No new form. The Refresh 33 solicitation does not add a supply chain document to the eOffer upload list. But GSA names offeror-submitted questionnaires and information as one way it identifies risk, so a Contracting Officer can ask you questions during evaluation. Be ready to answer them quickly and consistently.

What the solicitation does add is an instruction. Offerors "should ensure their offers are accurate and transparent regarding corporate structure and ownership, product country of origin and authorization (e.g., manufacturer status or Letter of Supply), and applicable compliance representations." That sentence is your checklist.

Does this apply if you only sell services?

Yes. Paragraph (d) covers "the Offeror and its proposed products, services, and related supply chains." The ownership and control review applies to every company. The product pieces, country of origin and Letters of Supply, apply when you offer products.

What GSA reviewsServices-only offerProduct offer
Corporate ownership and controlYesYes
Affiliates and subsidiariesYesYes
Compliance representationsYesYes
Product country of originNot applicableYes
Manufacturer status or Letter of SupplyNot applicableYes

What happens if GSA finds a risk?

GSA says the Contracting Officer will, if possible, work with you to fix it. If one product is the problem, that product can be removed so the rest of the offer moves forward. If the risk cannot be mitigated, the product or the whole offer can be removed from consideration.

StageFirst responseIf it cannot be fixed
Offer under evaluationContracting Officer works with you to mitigate; a single product may be pulledProduct or offeror removed from consideration
Active contractItem may be temporarily removed from your catalog while you respondItem removed, option not exercised, contract cancelled, or contract terminated

One detail to notice. GSA's FAQ says it "may" notify you when it identifies a risk. It does not promise to. That is one more reason to find your own inconsistencies before GSA does.

Where do offers get into trouble?

Mismatches. The most common problem is not a hidden foreign owner. It is a company that tells three slightly different stories about itself in SAM.gov, in eOffer, and in its narratives. A screening tool flags the mismatch, and the Contracting Officer has to ask why.

As a Contracting Specialist reviewing offers, I saw this constantly. The SAM registration named one parent company. The corporate experience narrative described another. Nobody was hiding anything. The record was simply out of date. Under Refresh 33, that kind of gap now lands inside a formal risk evaluation.

Run this check before you submit:

  1. Ownership in SAM.gov. Confirm the immediate owner and highest-level owner in your SAM.gov registration are current.
  2. Ownership in your narratives. Make sure your corporate experience narrative describes the same parents, subsidiaries, and affiliates.
  3. Country of origin. For products, confirm every item's country of origin and that it meets the Trade Agreements clause, FAR 52.225-5.
  4. Authorization to sell. If you are not the manufacturer, confirm your Letters of Supply are current and cover every item.
  5. Representations. Confirm your answers under FAR 52.240-90, the security prohibitions and exclusions representations, are accurate.

Is this the same as CMMC?

No. GSA says the two are "completely different." The Department of Defense's Cybersecurity Maturity Model Certification checks your internal network and how you protect Controlled Unclassified Information. GSA's supply chain requirements look at the security and integrity of the products, services, and solutions you offer.

What does this mean if you already hold a Schedule?

The monitoring clause, GSAR 552.540-71, reaches existing contracts through the Refresh 33 mass modification. Once it is in your contract, GSA can monitor supply chain risk for as long as you hold the contract, and the remedies run all the way to termination.

What Should You Do Now?

I spent eighteen years in federal acquisition as a Contracting Specialist and Contracting Officer at GSA, IRS, DoD, DOI, HHS, FTC, and Energy. I hold FAC-C Level III certification and a Master of Liberal Arts from Harvard University, and Blackfyre has 70+ GSA contract awards behind it. If you want your ownership record and offer checked for mismatches before a Contracting Officer sees them, that review is part of our GSA Schedule program.

Frequently Asked Questions

What is GSAR 552.540-70?

GSAR 552.540-70, Notice of Evaluation of Supply Chain Risk, is a new provision added to the GSA MAS solicitation in Refresh 33. It says the Government may consider supply chain risk information during evaluation and that unacceptable supply chain risks may be grounds to remove an offeror from consideration.

Do I have to submit a new supply chain form with my GSA MAS offer?

No. The Refresh 33 solicitation does not add a new supply chain upload in eOffer. GSA does list offeror-submitted questionnaires and information as one way it identifies risk, so a Contracting Officer can ask for more during evaluation.

Does the supply chain risk evaluation apply to services companies?

Yes. SCP-FSS-001 paragraph (d) covers the offeror and its proposed products, services, and related supply chains. The review of corporate ownership, control, affiliation, and subsidiaries applies to every offeror. Country of origin and Letters of Supply apply to product offers.

Will GSA tell me if it finds a supply chain risk?

Not necessarily. GSA's Part 540 FAQ says GSA may notify you, depending on the degree and nature of the risk and the evaluation factors in the solicitation. GSA also says the Contracting Officer will, if possible, work with offerors to mitigate identified risks.

Can GSA cancel my existing Schedule contract over a supply chain risk?

Yes. Under GSAR 552.540-71, if a supply chain risk cannot be reasonably mitigated, GSA can remove the product, service, or solution from the contract, decline to extend performance, cancel the contract, or terminate it. GSA says a first step may be temporarily removing the item from your catalog.

Is GSA's supply chain requirement the same as CMMC?

No. GSA states the requirements are completely different. CMMC certifies a contractor's internal network for protecting Controlled Unclassified Information on DoD contracts. GSA's requirements focus on the security and integrity of the products, services, and solutions offered to GSA and its customers.

Work With a Former CO Who's Been There

Navigating GSA Schedule strategy doesn't have to be a guessing game. Book a free strategy call with Pedro and let's talk about where you stand.

Book a Free Consultation →