Representative · R-CO
Restricts federal contracts for software systems holding sensitive data on 500+ federal employees from companies majority‑owned by non‑U.S. citizens, with a national‑security waiver option.
Official title: To prohibit certain Federal contracts with internationally owned software companies, and for other purposes.
Introduced February 20, 2026 by Lauren Boebert · Last progress February 20, 2026
The bill tightens sourcing rules to reduce foreign access to sensitive federal data and increases enforcement and oversight, at the cost of narrowing the vendor pool, potentially raising procurement costs, reducing access to some technology/innovation, and risking rushed implementation.
Federal employees and the systems that hold their data will be less likely to have sensitive information (e.g., credentials, SSNs, medical records) stored with majority-foreign-owned software firms, reducing exposure to foreign access or espionage risk.
Taxpayers and agency users whose personal data (SSNs, medical records, PII) are in covered systems will face stricter sourcing rules, which should lower identity-theft and privacy risks for those records.
Taxpayers will get more transparency and congressional oversight because agencies must report any national-security waivers to Congress within 30 days.
Agencies and taxpayers may face higher costs or delayed deployments because excluding majority-foreign-owned vendors could cut off access to competitively priced or specialized software.
Government contractors, U.S.-based subsidiaries of foreign firms, tech workers, and agencies may lose business or access to products and innovation because an ownership-based test plus certification and debarment risk will narrow the vendor pool and deter certain firms from participating.
Federal employees, contractors, and agencies could face procurement disruptions and inconsistent implementation because the bill requires FAR amendments on a 180-day schedule, risking rushed rulemaking.
Based on analysis of 2 sections of legislative text.
Bars federal agencies from contracting with software companies that are majority-owned by non‑U.S. citizens for systems that store or process sensitive personal data for 500+ federal employees unless the agency head grants a national‑security waiver with a written justification to Congress. Contractors must certify they are not internationally owned; false certifications can trigger contract termination, debarment, suspension, and other remedies; the Federal Acquisition Regulation must be updated within 180 days to implement the rule.