The bill increases DoD cybersecurity and transparency by banning payment equipment tied to adversary-controlled vendors, but does so at the cost of financial disruption and compliance burdens for vendors, potential higher procurement expenses for taxpayers, and possible delays in contracting.
DoD personnel and federal procurement officers will face lower supply-chain cyber risk because the bill bans payment equipment tied to adversary-controlled vendors.
Service members and taxpayers will have a reduced risk of data exfiltration in DoD transactions by requiring vetted, non-covered payment systems.
Congress and oversight bodies will gain greater accountability and transparency because the DoD must report to the Armed Services Committees within one year on covered payment systems.
Small retailers and payment vendors that currently supply the DoD may lose contracts, causing revenue losses and potential job impacts.
Taxpayers and the Department of Defense may face higher costs because phasing out vendors can increase procurement expenses and require replacement of equipment.
Retailers and contracting officers will face compliance uncertainty and potential contracting delays due to broad definitions and Secretary authority to add countries to the covered list.
Based on analysis of 2 sections of legislative text.
Requires DoD to phase out contracts with retailers that use payment equipment, software, or services tied to entities in designated countries of concern and bans new such contracts after Jan 1, 2027.
Official title: To prohibit the Secretary of Defense from contracting with retailers who use covered payment processing equipment, systems, or services, and for other purposes.
Introduced May 13, 2026 by Benjamin Cline · Last progress May 13, 2026
Prohibits the Department of Defense from contracting with retailers that use certain payment equipment, systems, or services that are developed, owned, controlled, or substantially comprised of components from entities tied to designated countries of concern (initially China, Russia, Iran, North Korea). The Secretary of Defense must review current retailer contracts within 180 days, issue guidance within 90 days after that review to modify or terminate contracts unless the retailer stops using covered technology, and may not enter new payment-processing contracts with such retailers beginning January 1, 2027. The bill defines key terms (country of concern, covered equipment/system/service, payment processing, retailer), requires a report to the House and Senate Armed Services Committees within one year, and lets the Secretary expand the country list. It aims to protect servicemember payment data and DoD transactions from foreign-controlled hardware, software, or firmware risks tied to specified countries.