The 90-day window is not arbitrary. It is the distance between the day a foreign parent decides to chase US defense work and the next prime gate that will ask, in writing, whether a foreign entity owns, controls, or can influence the company that wants the contract. Miss the answer and the opportunity does not pause for you. It moves to the next supplier on the list.
This playbook is for the operator standing up that US subsidiary: a Canadian, UK, or Israeli parent that has decided the defense industrial base is worth the cost of entry, and now has one quarter to build an entity that a prime and the Defense Counterintelligence and Security Agency will both accept. The work runs in parallel, not in sequence. Sequencing it is how the window closes.
What FOCI actually means and why it is the first gate, not the last
Foreign Ownership, Control, or Influence (FOCI) is the government's term for the risk that a foreign interest could compromise the protection of classified or controlled US information. Under the National Industrial Security Program Operating Manual, now codified at 32 CFR Part 117, a US company under FOCI cannot be cleared to access classified information until that influence is mitigated to the satisfaction of the Defense Counterintelligence and Security Agency (DCSA).
The mistake foreign parents make is treating FOCI as a closing item, a box checked after the entity is built and the contract is in hand. It is the opposite. The prime's supplier questionnaire asks the FOCI question early, and a credible answer requires structures that take weeks to stand up. You build the mitigation posture first, then the operations fit inside it.
There are five mitigation instruments in ascending order of foreign separation, defined in 32 CFR 117.11:
- Board Resolution for the lightest cases of foreign ownership without control.
- Security Control Agreement (SCA) where foreign ownership exists but does not reach control.
- Special Security Agreement (SSA) where a foreign interest holds control but the US entity is permitted limited access to classified information through a government-approved arrangement.
- Voting Trust or Proxy Agreement where US-citizen trustees hold the voting rights of the foreign owner.
- Combination arrangements layering the above.
The structure you choose is not a legal formality you delegate to counsel and forget. It dictates who can sit on your board, who can see the program data, and how fast you can make an operational decision. Pick it on day one.
The US entity and governance you build in the first 30 days
The first phase is the entity and its governance, because every later step references it. A foreign-parented defense subsidiary typically incorporates a US legal entity, often a Delaware C-corporation, and then populates a board and an officer slate that satisfy the FOCI instrument selected above.
Concretely, in the first 30 days I build:
- The incorporated US entity with bylaws written to accommodate the chosen FOCI structure (an SSA requires Outside Directors and a Government Security Committee written into the governance documents from the start).
- A US-citizen officer slate with real operational authority, not figureheads. DCSA examines whether US management can actually run the company independent of foreign direction.
- A Technology Control Plan (TCP) and an Electronic Communications Plan, both required documents under the mitigation agreement that govern how the US entity is walled off from improper foreign access.
- A Facility Security Officer (FSO) identified and in training, because the entity cannot progress a facility clearance without one.
This phase is governance and legal architecture, and it is where the public guidance runs thin. The rule itself, 32 CFR 117.11, names the instruments and tells you what each one requires. It does not tell you how to seat a board, write bylaws that survive the negotiation, and keep a plant running while DCSA reviews you. It is written for the security officer and the lawyer, not for an operator who has to make payroll while the structure is built. The operational translation is the gap.
Standing up the ITAR posture in parallel
If the work touches defense articles or technical data on the United States Munitions List, the International Traffic in Arms Regulations (ITAR, 22 CFR Parts 120 through 130) apply, and registration is a separate track that runs alongside the entity build.
A US manufacturer of defense articles must register with the Directorate of Defense Trade Controls (DDTC) under 22 CFR Part 122. Registration is a prerequisite for export licensing, and for a foreign-parented entity it interacts directly with FOCI: a foreign person under ITAR cannot access controlled technical data without authorization, which means the same wall the TCP builds for the security agreement also has to satisfy ITAR's deemed-export rules. Build the access controls once, to satisfy both.
The 30-day target for this track is a submitted DDTC registration and a documented technical data access control matrix that names, by role and citizenship, who can touch ITAR-controlled data and who cannot. The matrix is the artifact a prime auditor and a DDTC reviewer both want to see.
The CMMC and CUI environment, built into the IT and OT from the start
A defense subsidiary will hold Controlled Unclassified Information (CUI), so the Cybersecurity Maturity Model Certification (CMMC) program applies. CMMC Level 2 is built on NIST Special Publication 800-171, which specifies 110 security controls for protecting CUI in nonfederal systems. The contractual hook is DFARS clause 252.204-7012, with the assessment and reporting mechanics added by 252.204-7019, 252.204-7020, and 252.204-7021.
The timing pressure is real, and as of July 2026 it comes from the prime's gate rather than a federal date. On July 13, 2026 the Department suspended CMMC Phase II, the phase originally scheduled for November 10, 2026 that would have made mandatory C3PAO Level 2 certification a condition in applicable contracts, and opened a review of the program under 32 CFR Part 170. DFARS 252.204-7012 was untouched, and the suspension notice says so in terms. Level 2 currently runs on a self-assessment every three years against the 110 requirements in NIST SP 800-171 Revision 2, with an annual affirmation.
For a new US entity that changes nothing about the build and quite a lot about the excuse. The prime's supplier questionnaire still asks for a posted SPRS score, and a subsidiary that has operated for ninety days without one has no answer that improves by waiting. A new entity that wants to bid into that environment cannot treat security as a year-two project.
The operational move is to build the IT and OT environment around a CUI enclave from the first server stood up, rather than retrofitting a flat network later. That means:
- A scoped CUI enclave with access limited to authorized US persons, which also satisfies the ITAR access wall and the FOCI technology control plan. One boundary, three regulatory masters.
- A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) drafted as the controls are implemented, not after.
- A Supplier Performance Risk System (SPRS) score posted as soon as the self-assessment supports one, because 252.204-7019 requires a current score on file for the contracting officer to see.
Standing up a clean environment is faster and cheaper than remediating a dirty one. The foreign parent that builds the enclave on day three is the one that posts a defensible SPRS score by day 90.
The 90-day schedule and the gate that closes
The three tracks run together. Governance and entity in the first 30 days, ITAR registration and the access matrix in parallel, the CUI environment and CMMC posture across all 90. The sequence buyers fail with is linear: incorporate, then think about ITAR, then think about cyber, then discover the FOCI question was due at the gate that already passed.
A realistic 90-day shape:
- Days 1 to 30: entity incorporated, FOCI instrument selected with counsel and DCSA pre-engaged, US officer slate seated, TCP and Electronic Communications Plan drafted, FSO in training, DDTC registration submitted, CUI enclave architecture designed.
- Days 31 to 60: mitigation agreement negotiated with DCSA, NIST 800-171 controls implemented in the enclave, SSP and POA&M built as the work proceeds, technical data access matrix operational.
- Days 61 to 90: SPRS self-assessment score posted, facility clearance sponsorship in motion, prime supplier questionnaire answered with the FOCI structure and SPRS score in hand.
The gate that closes is the prime's supplier qualification. When it asks the FOCI question and the cyber question on the same form, the entity that built all three tracks in parallel answers in one pass. The entity that built them in sequence asks for an extension, and the contract moves on.
The bottom line
A foreign manufacturer earns US defense work by building governance, ITAR posture, and the CMMC and CUI environment as three parallel tracks inside one 90-day window, with the FOCI structure chosen on day one because it shapes everything downstream. The published guidance is legal, not operational, which is exactly why the parents that win treat this as an operating build with a hard gate, not a compliance project with a soft deadline. Map the gate first, then build backward from it.
Sources
- 32 CFR 117.11, Foreign Ownership, Control, or Influence (FOCI). The rule behind this whole first section. Paragraph (d)(2) sets out the five ownership mitigation instruments in the order used above: board resolution, security control agreement, special security agreement, voting trust or proxy agreement, and combinations. Paragraph (a)(3) is the ineligibility rule. Paragraph (g) requires the Government Security Committee, (f)(2) covers outside directors, and (h)(1) and (h)(2) require the Technology Control Plan and the Electronic Communications Plan. Part 117 is the codified NISPOM. Retrieved July 16, 2026.
- DCSA, Foreign Ownership, Control or Influence. The agency that makes the determination, its eight assessment factors, and the SF-328. The operative standard is that a company is under FOCI where a foreign interest has the power to direct or decide matters affecting its management or operations, "whether or not exercised, and whether or not exercisable." Retrieved July 16, 2026.
- 32 CFR 117.7, Procedures. The Facility Security Officer requirement: appointed in writing, a US citizen, trained under 117.12, and eligible for access at the level of the entity's own clearance. Retrieved July 16, 2026.
- 22 CFR 122.1, Registration requirements. The DDTC registration track. Two lines matter more than the rest and neither is widely known: "A manufacturer who does not engage in exporting must nevertheless register," and "Registration does not confer any export rights or privileges." Registration is generally a precondition to any license, unless DDTC grants an exception.
- 22 CFR 120.50, Export. The deemed export rule that makes the access control matrix necessary. Releasing technical data to a foreign person inside the United States is an export, and under (b) it is an export to every country in which that person holds or has held citizenship or permanent residency.
- DoD CIO, About CMMC. The July 13, 2026 suspension of Phase II, the reform task force, the pause in Phase 1, and the current shape of Level 2: a self-assessment every three years against the 110 security requirements of NIST SP 800-171 Revision 2, with annual affirmation. Also the source for the Department's own statement that the suspension "does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012." Retrieved July 16, 2026, and worth rechecking before you act on it, because the task force is still sitting.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. The contractual hook that survived the suspension. Its definition of a "covered contractor information system" is any unclassified system "owned, or operated by or for, a contractor" that processes, stores, or transmits covered defense information, which is why a parent's IT department running the subsidiary's systems pulls the parent's environment into scope rather than pushing the obligation offshore.
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements. Why the SPRS score is a day-90 deliverable and not a year-two one. "In order to be considered for award," an offeror must have a current assessment, not more than three years old, posted in SPRS for each relevant covered contractor information system. Retrieved July 16, 2026.
- DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. The Basic, Medium, and High assessment mechanics behind the score, and the rule that a contractor may not award a subcontract subject to 800-171 unless the subcontractor has completed at least a Basic assessment within three years. Retrieved July 16, 2026.
- DFARS 252.204-7021, Cybersecurity Maturity Model Certification Level Requirements. The clause that names the CMMC status levels a contracting officer can insert, and that requires annual affirmation of continuous compliance in SPRS.
- NIST SP 800-171, Revision 2. The controls themselves, for protecting CUI in nonfederal systems. Note that NIST withdrew Revision 2 in May 2024 in favor of Revision 3, and that DoD still assesses CMMC Level 2 against Revision 2. DFARS 252.204-7012 pins the applicable revision to the one in effect when the solicitation is issued, so check the solicitation rather than assuming the newest.
Related case study
This playbook is running live in New Hampshire. Case Study: A Global OEM's Onshoring Landing in New Hampshire follows a global OEM of asset-tracking equipment with Canadian and US R&D standing up a compliant NH manufacturing facility: ISO 9001:2015 audit-ready in three months, an ITAR-grade data border between international R&D and the US enclave, and FAR/DFARS Made-in-USA compliance.
