Menu

Flagship practice

Supply Chain Risk Management

All-source intelligence tradecraft applied to the vendors, components, and ownership structures inside federal supply chains.

The tradecraft layer

Supply chain risk management (SCRM) has two layers. Software platforms screen suppliers at scale, flag anomalies, and automate workflow. Cleared analysts take an ambiguous ownership structure, an opaque intermediary, or a suspect IT component and produce a risk judgment a government customer can act on and defend.

Platforms surface anomalies. Cleared analysts render judgments.

Intel Analysis works in the second layer. The practice begins where automated screening stops returning useful answers, and it is staffed by analysts who came out of the intelligence community rather than out of a software company. The firm has worked in supply chain risk since 2016, before the current regulatory wave made it a category.

Supply chain risk is where the firm has most recently proven its tradecraft, not the limit of it. The same all-source discipline described on this page is applied wherever a mission needs cleared analytic judgment — this practice is the worked example.

Where automated screening runs out

Screening tools are good at the suppliers that document themselves. A tier 1 vendor is registered, audited, and verifiable, and so is the tier 2 vendor behind it. Risk concentrates further down, in the tiers a purchase order never names.

  • Ownership that resolves to a jurisdiction or a nominee rather than to a person
  • Component provenance that cannot be traced past the assembler
  • Intermediaries whose records are clean because they are recent
  • Corporate structures reorganized faster than public registries update
  • Relationships that are visible in aggregate but not in any single record

Illuminating those tiers is analytic work. It means reconciling incomplete and contradictory records, judging which sources carry weight, and stating plainly how confident the judgment is and what would change it.

What we assess

  • IT component risk and threat analysis
  • Vendor and supplier risk across multiple supply tiers
  • Corporate ownership structure and beneficial ownership
  • Indicators of foreign ownership, control, or influence (FOCI)
  • Analysis related to the Committee on Foreign Investment in the United States (CFIUS)
  • Risk assessment and mitigation
  • Supply and value chain management support

How the work is done

The method is all-source intelligence analysis. Analysts work the available reporting and open material together, weigh sources against each other, and carry the uncertainty forward into the judgment instead of resolving it silently. The finding says what is known, what is inferred, and what remains open.

The company is analyst-owned and analyst-led, so review happens between people who have done the work themselves. Its analysts are experienced in ICD 203 — the Intelligence Community’s analytic standards directive — and adhere to those and other standards when requested by customers.

Deliverables

What you receive

A finished product, not a data extract. Each of these is written to be read by someone who has to make a decision.

  • Risk statements

    A clear judgment on a vendor, component, entity, or supply tier, written so a decision maker can act on it without reading the underlying research.

  • Risk explanations

    The reasoning behind the judgment: what the assessment rests on, which sources carried weight, how confident the analyst is, and what new information would change the conclusion.

  • Mitigation recommendations

    Options with their tradeoffs stated, rather than a single directive. The customer owns the decision; the analysis is there to make it an informed one.

Context

What drives the requirement

The obligations below are why federal buyers and their suppliers need this work. Each is public regulation or published federal guidance, summarized here in general terms.

Regulatory drivers

NIST SP 800-161 Cybersecurity supply chain risk management practices for systems and organizations. The reference framework federal C-SCRM programs are built against.
NIST SP 800-171 Protection of controlled unclassified information in nonfederal systems. The control set defense suppliers are measured against.
DFARS 252.204-7012 Safeguarding covered defense information and cyber incident reporting. Obligates defense contractors to implement NIST SP 800-171 and to report incidents.
CMMC The Department of Defense program for assessing contractor cybersecurity, with requirements that flow down through subcontract tiers to suppliers who rarely deal with the government directly.
Section 889 The FY2019 NDAA prohibition on procuring or using certain covered telecommunications and video surveillance equipment and services, which requires a supplier to know what is inside what it sells.
DoD SCRM Integration Center A Department of Defense focal point for supply chain risk analysis supporting acquisition decisions.

Evidence

Why this firm

Each claim below is paired with what makes it true. The content model requires the pairing, so a claim cannot be published on its own.

Analyst-owned and analyst-led
Founded in 2006 by career intelligence analysts and still owned by one. The president has worked in intelligence since 1984, served as a US Navy intelligence analyst, and is a certified PMP and certified ISSO.
A decade in this specific practice
The president has been a supply chain risk management subject matter expert since March 2016. This is a long-standing specialism, not a recent move into a growing market.
Supporting the mission since 2006
Continuous all-source analytic support to the Department of Defense, the Department of Homeland Security, national-level agencies, combatant commands, and federal, state, and local law enforcement.
Recognized analytic work
Employees have received individual and team Director of National Intelligence awards.
Works to published analytic standards
Analysts are experienced in ICD 203 and adhere to those and other standards when requested by customers.
Straightforward to put on contract
SBA-certified Service-Disabled Veteran-Owned Small Business — eligible for sole-source and set-aside award under FAR Subpart 19.14. UEI LK5CFHLMKLK1, CAGE 4CDF0.

Procurement

How this is ordered

As an SBA-certified SDVOSB, the firm is eligible for sole-source and set-aside award under FAR Subpart 19.14 — no vehicle required — and it takes subcontracts on programs a prime already holds.

SDVOSB eligibility, NAICS and PSC codes, UEI, CAGE, and the independent verification routes are all on how to buy from us.

Next step

Two ways in

Government

Describe the requirement and we will come back with scope and a named analyst lead. Quote requests reach a principal directly.

Government inquiry

Primes and platform vendors

Software vendors delivering federal task orders routinely need cleared analytic services partners. Socioeconomic status, codes, and vehicles are on one page.

Teaming information

Unresolved — not published

Release approval for the Supply Chain Risk Management capability page — reviewed against the OPSEC checklist and dated

Source
Carl McDonald, President (named release authority)
Blocks
/capabilities/supply-chain-risk-management/

The page is written and complete. What is missing is the sign-off itself: releaseApprovedBy is set, releaseApprovedDate is null, and approving is meant to be a deliberate act rather than a default. Nothing customer-facing publishes without it.

Last reviewed 26 August 2026.