Renewed Focus on U.S. Manufacturing: A Critical Assessment of Software Supply Chains
In recent years, the trend of relocating manufacturing overseas has met with increasing scrutiny, sparking a resurgence of interest in domestic production within the United States.
However, this renewed focus has predominantly concentrated on the tangible aspects of the supply chain, neglecting the equally vital domain of software supply chains.
This oversight raises alarming concerns regarding the reliability and security of the software systems that underpin government operations.
While the physical supply chain’s vulnerabilities can often be assessed through direct inspection of components, the software supply chain presents a more insidious threat—one that is less apparent yet urgently needs addressing.
By failing to rigorously evaluate the origins of software development with the same diligence applied to physical products, the “America First” initiative risks compromising the safety of essential infrastructure.
The Software Supply Chain: A Contested Target
The absence of a robust strategy for ensuring software sovereignty poses grave risks. Such risks include diminished operational control and the potential for compromised systems to be embedded within critical infrastructures.
In the context of military operations, this vulnerability could materialize as an increased likelihood of a denial-of-service strike at a pivotal juncture or intrusive actions within fleet systems by adversaries.
Since 2021, the Volt Typhoon group, linked to actors in China, has infiltrated networks associated with vital U.S. infrastructure spanning communications, energy, transportation, and water management. These incursions are believed to be strategic moves aimed at destabilizing operations during potential conflict scenarios.
Furthermore, preceding Russia’s incursion into Ukraine, Russian operatives targeted Viasat, a satellite communication network utilized by Ukraine, disrupting military communications and connectivity for countless users.
Notably, in both scenarios, the attack vector was not the physical asset itself but rather the software and systems facilitating control and connection.
Defining Software Sovereignty
Considering the software supply chain’s implications on critical U.S. infrastructure, it is imperative for the nation to establish definitive requirements for software sovereignty. This concept comprises four foundational pillars:
- Location: Software development must occur on infrastructure under U.S. control.
- Control: Software must operate on servers that are owned and managed by the government or its contractors.
- Toolchain Integrity: Compilers, dependencies, and build systems should be U.S.-sourced and subject to comprehensive audit mechanisms.
- Isolation: There should be an absence of reliance on external Software-as-a-Service (SaaS) or cloud platforms that could be accessible to foreign adversaries through legal avenues, cyber incursions, or vendor affiliations.
In the absence of such protocols, a contractor engineer could unwittingly push code to a Navy combat system from a personal device interfacing with a foreign commercial cloud server, thereby omitting any enforceable boundaries of sovereignty.
Evaluating Software Sovereignty in Practice
Legislative efforts, such as the Shipbuilding and Harbor Infrastructure for Prosperity and Security (SHIPS) for America Act of 2025, were introduced in Congress last year, aiming to deploy 250 new American-built ships within the next decade.
Despite imposing restrictions on the construction sites, contractors, and materials, the act lacks clarity regarding the development origins of the software that governs these vessels.
Modern naval destroyers function as sophisticated software platforms residing on water. From advanced combat management systems to autonomous software in unmanned vessels, and AI-enhanced maintenance operations, software is integral to their functionality.
Yet, the development of this crucial software often occurs on commercial cloud infrastructures, which may not fall under direct governmental oversight or may rely on globally distributed infrastructures lacking enforceable sovereignty guarantees.
Existing Policy Precedents
Establishing sovereignty standards in software development is not an entirely novel avenue for U.S. policy concerning cybersecurity in governmental programs.
In 2021, the White House issued an executive order on “Improving the Nation’s Cybersecurity,” which set forth standards for secure software development across federal entities and their vendors.
This directive reinforced software supply chain security through mandates for secure development methodologies, information interchange, and the establishment of multi-factor authentication and encryption measures.
Other existing frameworks lend support to this approach. The Defense Department’s Cybersecurity Maturity Model Certification (CMMC) delineates security benchmarks for defense contractors, while FedRAMP specifies security standards for cloud service providers servicing governmental clients.
Nevertheless, current federal security frameworks primarily protect data and operational systems without delineating the necessary conditions for the locations of software development environments or the entities that govern them.
If this administration seeks to promote an “America First” ethos in manufacturing, it should extend this imperative to software development practices as well.
The security of defense mechanisms, critical infrastructures, and industrial functionalities hinges solely on the reliability of the systems administering them. Ignoring the origins of software development leaves a perilous vulnerability unaddressed.
In a contrasting scenario, the Trump administration has initiated a rollback of cybersecurity standards.
In the last days of his presidency, Joe Biden built upon his previous cybersecurity executive order with a new decree that established additional requirements.
However, last summer, President Donald Trump amended the directive, eliminating the requirements for software attestation and reducing the obligation for agencies to perform digital identity work, effectively transferring the responsibility for cybersecurity to vendors rather than ensuring federal oversight.
While the Trump administration’s actions may appear to loosen regulatory measures aimed at enhancing cybersecurity, it is crucial to recognize that a balance between expedience, innovation, and security can coexist.
Sovereign development environments have the potential to facilitate AI-driven development processes and contemporary engineering practices, thereby improving governance across infrastructure layers.
The Ongoing Transition
Currently, a considerable number of federal initiatives operate on a disjointed assortment of local laptops, virtual desktop interfaces (VDI), and isolated virtual machines (VMs).
Although these configurations may satisfy basic security protocols, they fragment workflows, obstruct seamless onboarding, and complicate consistent control enforcement.
The decisive shift is transitioning towards self-hosted, centrally managed cloud development environments embedded within agency infrastructures, traversing unclassified, classified, and air-gapped networks.
The ensuing standardization ensures that the same workspace, audit trail, and toolchain move seamlessly with the developer, irrespective of the physical device.
By confining developers to centrally managed environments, agencies can more straightforwardly enforce security norms, monitor activities, and uphold compliance with federal cybersecurity regulations.
In addition to enhancing security, these environments introduce increased flexibility, allowing developers to operate across varied infrastructures, operating systems, or development stacks.
This adaptability enables quicker responses to evolving requirements, nascent technologies, and shifting security paradigms.

Imposing stronger software sovereignty prerequisites would not create an entirely new operational paradigm; rather, it would crystallize the practices that the most proactive federal agencies are already implementing.
Absent such measures, the U.S. faces the grim prospect of establishing infrastructure that adversaries can potentially breach.
Source link: Federalnewsnetwork.com.





