Flagship practice
Supply Chain Risk Management
All-source intelligence tradecraft applied to the vendors, components, and ownership structures inside federal supply chains.
The tradecraft layer
Supply chain risk management (SCRM) has two layers. Software platforms screen suppliers at scale, flag anomalies, and automate workflow. Cleared analysts take an ambiguous ownership structure, an opaque intermediary, or a suspect IT component and produce a risk judgment a government customer can act on and defend.
Platforms surface anomalies. Cleared analysts render judgments.
Intel Analysis works in the second layer. The practice begins where automated screening stops returning useful answers, and it is staffed by analysts who came out of the intelligence community rather than out of a software company. The firm has worked in supply chain risk since 2016, before the current regulatory wave made it a category.
Supply chain risk is where the firm has most recently proven its tradecraft, not the limit of it. The same all-source discipline described on this page is applied wherever a mission needs cleared analytic judgment — this practice is the worked example.
Where automated screening runs out
Screening tools are good at the suppliers that document themselves. A tier 1 vendor is registered, audited, and verifiable, and so is the tier 2 vendor behind it. Risk concentrates further down, in the tiers a purchase order never names.
- Ownership that resolves to a jurisdiction or a nominee rather than to a person
- Component provenance that cannot be traced past the assembler
- Intermediaries whose records are clean because they are recent
- Corporate structures reorganized faster than public registries update
- Relationships that are visible in aggregate but not in any single record
Illuminating those tiers is analytic work. It means reconciling incomplete and contradictory records, judging which sources carry weight, and stating plainly how confident the judgment is and what would change it.
What we assess
- IT component risk and threat analysis
- Vendor and supplier risk across multiple supply tiers
- Corporate ownership structure and beneficial ownership
- Indicators of foreign ownership, control, or influence (FOCI)
- Analysis related to the Committee on Foreign Investment in the United States (CFIUS)
- Risk assessment and mitigation
- Supply and value chain management support
How the work is done
The method is all-source intelligence analysis. Analysts work the available reporting and open material together, weigh sources against each other, and carry the uncertainty forward into the judgment instead of resolving it silently. The finding says what is known, what is inferred, and what remains open.
The company is analyst-owned and analyst-led, so review happens between people who have done the work themselves. Its analysts are experienced in ICD 203 — the Intelligence Community’s analytic standards directive — and adhere to those and other standards when requested by customers.
Deliverables
What you receive
A finished product, not a data extract. Each of these is written to be read by someone who has to make a decision.
-
Risk statements
A clear judgment on a vendor, component, entity, or supply tier, written so a decision maker can act on it without reading the underlying research.
-
Risk explanations
The reasoning behind the judgment: what the assessment rests on, which sources carried weight, how confident the analyst is, and what new information would change the conclusion.
-
Mitigation recommendations
Options with their tradeoffs stated, rather than a single directive. The customer owns the decision; the analysis is there to make it an informed one.
Context
What drives the requirement
The obligations below are why federal buyers and their suppliers need this work. Each is public regulation or published federal guidance, summarized here in general terms.
Regulatory drivers
| NIST SP 800-161 | Cybersecurity supply chain risk management practices for systems and organizations. The reference framework federal C-SCRM programs are built against. |
|---|---|
| NIST SP 800-171 | Protection of controlled unclassified information in nonfederal systems. The control set defense suppliers are measured against. |
| DFARS 252.204-7012 | Safeguarding covered defense information and cyber incident reporting. Obligates defense contractors to implement NIST SP 800-171 and to report incidents. |
| CMMC | The Department of Defense program for assessing contractor cybersecurity, with requirements that flow down through subcontract tiers to suppliers who rarely deal with the government directly. |
| Section 889 | The FY2019 NDAA prohibition on procuring or using certain covered telecommunications and video surveillance equipment and services, which requires a supplier to know what is inside what it sells. |
| DoD SCRM Integration Center | A Department of Defense focal point for supply chain risk analysis supporting acquisition decisions. |
Evidence
Why this firm
Each claim below is paired with what makes it true. The content model requires the pairing, so a claim cannot be published on its own.
- Analyst-owned and analyst-led
- Founded in 2006 by career intelligence analysts and still owned by one. The president has worked in intelligence since 1984, served as a US Navy intelligence analyst, and is a certified PMP and certified ISSO.
- A decade in this specific practice
- The president has been a supply chain risk management subject matter expert since March 2016. This is a long-standing specialism, not a recent move into a growing market.
- Supporting the mission since 2006
- Continuous all-source analytic support to the Department of Defense, the Department of Homeland Security, national-level agencies, combatant commands, and federal, state, and local law enforcement.
- Recognized analytic work
- Employees have received individual and team Director of National Intelligence awards.
- Works to published analytic standards
- Analysts are experienced in ICD 203 and adhere to those and other standards when requested by customers.
- Straightforward to put on contract
- SBA-certified Service-Disabled Veteran-Owned Small Business — eligible for sole-source and set-aside award under FAR Subpart 19.14. UEI LK5CFHLMKLK1, CAGE 4CDF0.
Procurement
How this is ordered
As an SBA-certified SDVOSB, the firm is eligible for sole-source and set-aside award under FAR Subpart 19.14 — no vehicle required — and it takes subcontracts on programs a prime already holds.
SDVOSB eligibility, NAICS and PSC codes, UEI, CAGE, and the independent verification routes are all on how to buy from us.
Next step
Two ways in
Government
Describe the requirement and we will come back with scope and a named analyst lead. Quote requests reach a principal directly.
Government inquiryPrimes and platform vendors
Software vendors delivering federal task orders routinely need cleared analytic services partners. Socioeconomic status, codes, and vehicles are on one page.
Teaming informationUnresolved — not published
Release approval for the Supply Chain Risk Management capability page — reviewed against the OPSEC checklist and dated
The page is written and complete. What is missing is the sign-off itself: releaseApprovedBy is set, releaseApprovedDate is null, and approving is meant to be a deliberate act rather than a default. Nothing customer-facing publishes without it.
Last reviewed 26 August 2026.