Gov Contract Finder LogoGov Contract Finder Logo
  • ⭐
    Extensión del Navegador
    Chrome / Edge / Firefox
    Aplicaciones
    Extensión del NavegadorApp Móvil
    Características
    Alertas por EmailAnálisis e InsightsOficiales de AdquisicionesAsistente de Licitación IA
    Resumen →
    ResumenExtensión del NavegadorApp MóvilAlertas por EmailAnálisis e InsightsAsistente de Licitación IA
  • Precios
  • Contratos
  • Aprender
    Base de ConocimientoGuíasGlosarioPreguntas y RespuestasBlogDocumentación
    Comparaciones
    Comparar PlataformasAlternativa a SAM.gov
    Soluciones
    Por Qué Gov Contract FinderPara Pequeñas EmpresasPara Equipos de CapturaSoporte
    Pruebas
    Historias de ClientesCobertura de Datos
    Base de ConocimientoGuíasGlosarioPreguntas y RespuestasBlogDocumentaciónSoportePor Qué Gov Contract FinderPara Pequeñas EmpresasComparar Plataformas
  • Servicios
  • 📅
    Agendar Consulta
    Gratis, sin compromiso
    Capacidades
    Implementación de BúsquedaAutomatización de CapturaFábrica de PropuestasInteligencia de MercadoIntegración Empresarial
    Resumen de Automatización →
    Resumen de AutomatizaciónAgendar ConsultaImplementación de BúsquedaAutomatización de CapturaFábrica de PropuestasIntegración Empresarial
  • Iniciar sesión
  • Agendar Demo
Home / Resources / Government Oversight
Government Oversight

What are contractor obligations for disclosing foreign affiliations on visa and security forms? (2026)

GSA requires contractors to disclose foreign affiliations on SF-328 and SF-86 updates; DCSA’s May 2025 SF-328 revision expanded reporting and non-compliance can trigger termination, debarment, or clearance revocation.

Gov Contract Finder
•May 18, 2026•6 min read

What Is What are contractor obligations for disclosing foreign affiliations on visa and security forms? and Who Does It Affect?

According to GSA guidelines, contractors must proactively disclose foreign affiliations, ownership, funding, and significant foreign contacts on government security and visa forms, including the revised SF-328 and personnel security questionnaires such as SF-86. This obligation applies to prime contractors, subcontractors, and key personnel supporting federal contracts when foreign interests could create Foreign Ownership, Control, or Influence (FOCI). The disclosure requirement ties into FAR and agency-specific rules: Per FAR 9.1 and the DEARS 904.7003 FOCI disclosure clause, contracting officers must evaluate foreign ties during source selection and award. The requirement affects cleared personnel and non-cleared staff when visa sponsorship or national security duties exist; DoD programs add CMMC and DFARS scrutiny when controlled unclassified information (CUI) is involved. The SBA and GSA consider foreign affiliation data during set-aside eligibility and small business representations. Underlying this is OMB policy direction to strengthen foreign funding transparency and reporting across grants and contracts. Contractors should assume a low threshold for required disclosures and update records in SAM.gov and personnel security portals promptly to avoid downstream adverse actions.

What is What are contractor obligations for disclosing foreign affiliations on visa and security forms??

GSAFAR
According to GSA guidance and DCSA’s May 2025 SF-328 revision, contractors must disclose foreign ownership, funding, and close/continuing foreign contacts on SF-328 and SF-86; Per DEARS 904.7003, contractors must report FOCI immediately for contracts exceeding $250,000 and provide detailed funding/source data for awards >$1M.
Sources: [1] DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures, [3] 904.7003 Disclosure of foreign ownership, control, or influence.

Background and Context

According to GSA guidelines, the federal government expanded foreign affiliation disclosures after high-profile national security incidents and policy changes in 2024–2025; DCSA’s May 2025 approval of a revised SF-328 requires more granular reporting of foreign funding, collaborations, and institutional ties. Per FAR and related agency regulations, contracting officers now factor contractor foreign interests into organizational conflicts and responsibility determinations. Per FAR 19.502, small businesses can still seek set-asides but must accurately represent foreign ownership and disclose any foreign sources of capital; inaccurate or omitted disclosures jeopardize eligibility for 8(a), HUBZone, WOSB, SDVOSB, and other programs. The push for transparency also aligns with executive actions directing universities and contractors to report foreign funding sources, which increases cross-agency data sharing between GSA, DoD, DHS, and OMB. That means primes must collect and verify foreign affiliation data from subs and key personnel before proposal submission to avoid post-award discoveries that trigger investigations, adverse audit findings, or loss of clearances.
Per FAR 19.502, small businesses can be subject to heightened documentation requests if foreign investment or control is identified; procurement integrity and responsibility standards require contracting officers to document and mitigate FOCI risks. The SBA reports that 78% of small contractors surveyed in recent outreach felt uncertain about what constitutes 'close and continuing contact' with foreign nationals, increasing the risk of under-reporting; JAG Defense and legal advisories emphasize that continuing contact includes ongoing funded relationships, joint appointments, and supervisory relationships with foreign entities. Under OMB M-25-21 and related OMB direction, agencies will increase centralized vetting and require consistent reporting fields across award systems, elevating the importance of accurate SF-328 and SF-86 entries. DoD’s CMMC framework requires contractors handling CUI to demonstrate controls and may require disclosure of foreign ties as part of the system security plan and assessment process, creating crosswalks between cybersecurity certification and personnel/security disclosures.
$789B
FY2026 federal IT spending (OMB)
Source: DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures

How do contractors comply with What are contractor obligations for disclosing foreign affiliations on visa and security forms??

GSADEARS
According to GSA guidance and DCSA notices, contractors must inventory foreign affiliations, update SF-328 and SF-86 within 30 days of new information, run FOCI assessments per DEARS 904.7003, and notify contracting officers for contracts >$250,000. Schedule audits and corrective action within 60 days to avoid suspension or debarment.
Sources: [1] DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures, [3] 904.7003 Disclosure of foreign ownership, control, or influence.

Requirements and Implementation

According to GSA guidelines, contractors must collect and maintain documentation supporting each foreign affiliation disclosure — including source agreements, funding amounts, copies of foreign contracts, and the nature/duration of any 'close and continuing contact.' Practically that means attaching documentation to SF-328 submissions and to personnel security files (SF-86) for individuals requiring clearance. Per FAR clauses and DEARS 904.7003, the contracting officer may require a mitigation plan or FOCI remediation (e.g., proxy agreements or special voting trusts) before award. DoD’s CMMC framework requires cybersecurity evidence tied to personnel access: if foreign affiliations create elevated insider risk, DoD primes must restrict access or reassign roles. The revised SF-328 templates require line-item disclosure of foreign funding amounts and counterparties; many legal firms and procurement advisors recommend clients assemble a single, auditable disclosure packet for each contract bid. Timely, detailed reporting reduces the chance of adverse findings during contract audits or security reviews.
The SBA reports that 78% of small businesses express confusion about when to report foreign ties, so systems-of-record matter: contractors must maintain records in SAM.gov and in internal compliance registers and provide updates within agency timelines. Under OMB M-25-21, agencies will standardize reporting fields for foreign funding and affiliations across grants and contracts, increasing cross-checks between federal award systems. DoD’s CMMC framework requires documented insider threat mitigations when foreign contacts are present; combining cybersecurity plans with personnel disclosure records is now best practice. Federal acquisition rules also tie to export control and visa law: failing to disclose foreign research collaborations can violate ITAR/EAR and trigger visa denials for foreign national employees. Contractors should integrate SF-328, SF-86, SAM registrations, and cybersecurity evidence to present coherent, auditable disclosures to contracting officers and security offices.

Important Note

Failure to update SF-328 or SF-86 within 30 days of material change can lead to contract termination, debarment, or security clearance revocation. Treat any foreign funding >$10,000, joint appointments, or ongoing paid collaborations as reportable until counsel confirms otherwise.

  1. 1
    Step 1: Assess

    Per FAR 9.1 and DEARS 904.7003, perform a FOCI screening of corporate records, ownership, and funding sources; document amounts, countries, and contractual terms within 14 days.

  2. 2
    Step 2: Inventory Personnel

    According to GSA guidelines, list all personnel with foreign contacts or dual affiliations and update SF-86 disclosures within 30 days for clearance holders.

  3. 3
    Step 3: Remediate

    Per FAR and DoD guidance, implement mitigation (proxy agreements, reassignment) within 60 days if FOCI is identified; engage counsel for mitigation agreement drafting.

  4. 4
    Step 4: Report

    Register and update disclosures in SAM.gov and submit SF-328 and related documentation to contracting officers prior to proposal submission for awards >$250,000.

  5. 5
    Step 5: Monitor

    Under OMB M-25-21 direction, run quarterly reviews and update records within 30 days of new information to remain compliant.

What happens if contractors don't comply?

FARDEARS
Per FAR and DEARS guidance, non-compliance can result in suspension, debarment, contract termination, loss of set-aside status, or security clearance revocation; agencies often require corrective action within 60 days and may assess monetary penalties for false statements. Prompt self-reporting reduces enforcement severity.
Sources: [3] 904.7003 Disclosure of foreign ownership, control, or influence., [5] Federal Acquisition Regulation: Preventing Organizational Conflicts of Interest in Federal Acquisition

Best Practices for Practical Compliance

DoD's CMMC framework requires contractors to demonstrate both cybersecurity controls and personnel risk management; integrating personnel disclosure processes with cybersecurity evidence expedites compliance. According to GSA guidelines, centralize foreign affiliation records, maintain a dedicated SF-328 packet per contract, and assign a compliance lead to manage updates with contracting officers and facility security officers (FSOs). Per FAR 19.502 and SBA guidance, verify small business representations against legal documents and resolve inconsistencies before bid submission. The practical implementation includes vendor questionnaires tied to subcontractor flow-downs, mandatory attestations at proposal stage, and retention of documentary proof of termination or modification of foreign relationships. Under OMB M-25-21, agencies will increasingly expect standardized fields and machine-readable disclosures, so implement data structures to export SF-328 and SF-86 summary data. Finally, coordinate with counsel for export-control screening (ITAR/EAR) and promptly disclose findings to reduce the risk of enforcement, civil fines, or loss of clearance.

"The revised SF-328 strengthens transparency of foreign interests and requires contractors to disclose comprehensive funding and affiliation details to protect national security."

Defense Counterintelligence and Security Agency (DCSA),DCSA statement on SF-328 revision
DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures

The Challenge

Needed to disclose multiple foreign research collaborations and update SF-328 to compete for a $2.8M DoD subcontract within 90 days.

Outcome

Won a $2.8M DoD subcontract, priced 18% below competitors after meeting FOCI requirements and securing timely mitigation.

Source: DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures

  • Deadline: Update SF-328 and related SF-86 within 30 days of material change per DCSA (effective May 2025).
  • Budget: Allocate $75,000–$150,000 for legal review and FOCI mitigation per contract bid estimate (typical market range).
  • Action: Register and verify SAM.gov entity profiles at least 90 days before proposal submission for awards >$250,000.
  • Risk: Non-compliance can lead to suspension, debarment, or clearance revocation within 60–90 days per FAR/DEARS enforcement timelines.

Sources & Citations

1. DCSA Approves Revised SF-328 to Improve Foreign Interest Disclosures [Link ↗](law firm_publication)
2. WHAT IS 'CLOSE AND CONTINUING CONTACT' WITH FOREIGN CONTACTS? [Link ↗](legal analysis)
3. 904.7003 Disclosure of foreign ownership, control, or influence. [Link ↗](government site)

Tags

#compliance#government-oversight#national-security#procurement

Ready to Win Government Contracts?

Join thousands of businesses using Gov Contract Finder to discover and win federal opportunities.

Start Free TrialSchedule Demo

Related Articles

What do DCSA’s revised continuous vetting requirements mean for cleared contractor employees? 2026

DCSA updated continuous vetting; contractors must enroll cleared employees, update policy and tech by Dec 31, 2026 or face clearance suspension and lost awards. Follow DCSA steps, FAR references and HR actions to comply.

Read more →

How can small companies enter the counter‑UAS market after Perennial Autonomy’s $500M JIATF 401 award? 2026

Practical, deadline-driven steps for small firms to pursue DoD counter-UAS work after Perennial Autonomy’s $500M JIATF-401 award: SAM registration, FAR compliance, CMMC, OTAs and teaming—start assessments by June 2026 to remain eligible for task orders.

Read more →

What do small businesses need to know about the FAR 'Revolutionary FAR Overhaul' implementation in FY27 solicitations? 2026

GSA requires small businesses to adopt RFO model clauses by Oct 1, 2026; non-compliance can block FY27 awards. This checklist maps FAR, SBA, OMB, DoD/CMMC, and FedRAMP steps to update proposals, systems, and certifications.

Read more →
Gov Contract Finder LogoGov Contract Finder Logo
  • Producto
  • Asistente de Licitación IA
  • Extensión del Navegador
  • App Móvil
  • Alertas por Email
  • Análisis e Insights
  • Precios
  • Base de Conocimiento
  • Guías
  • Glosario
  • Preguntas y Respuestas
  • Documentación
  • Blog
  • Para Pequeñas Empresas
  • Para Equipos de Captura
  • Comparar Plataformas
  • Servicios
  • Automatización de Flujos
  • Soporte
  • Contáctanos
© Copyright 2026 Gov Contract Finder.
  • Términos de Servicio
  • Política de Privacidad
Opportunity: Contracts requiring certified cybersecurity and disclosure compliance (CMMC/FedRAMP) represent multibillion-dollar opportunities annually (>$1B per agency program forecasts).
Next Step

Start a full FOCI inventory and update SF-328 and SF-86 records by June 30, 2026 to meet ongoing agency review cycles.