{"id":26870,"date":"2023-10-20T09:30:00","date_gmt":"2023-10-20T09:30:00","guid":{"rendered":"https:\/\/staging.sightlinemg.com\/federaltimes\/uncategorized\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/"},"modified":"2026-08-08T05:08:50","modified_gmt":"2026-08-08T05:08:50","slug":"gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity","status":"publish","type":"post","link":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","title":{"rendered":"GSA pitches vendor self-assessment on supply chain cybersecurity"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The General Services Administration is testing a voluntary questionnaire for vendors to self-certify the authenticity and security of the IT products and services they sell to government agencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GSA put out a request-for-information on the proposed survey to gather feedback with responses due Nov. 10.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s an interesting, though familiar, idea, said <a href=\"https:\/\/about.gitlab.com\/blog\/2022\/11\/14\/gitlab-names-joel-krooswyk-as-its-first-federal-cto\/\" target=\"_blank\">Joel Krooswyk,<\/a> federal chief technology officer at GitLab Inc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIt\u2019s the first time I\u2019ve seen something that looks like a long running industry standard,\u201d he said in an interview. \u201cAnd I wonder if that\u2019s on purpose for people who have been in product manufacturing or product definition for a long time who are used to getting these kind of questions.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The mix of 200 yes-or-no and short-answer questions are designed to help government assess details on hardware design, data protection and other cybersecurity supply chain risk management features. While responses to the RFI may change what the final questionnaire looks like, it\u2019s the latest potential tool in the government\u2019s arsenal to improve security in the federal industrial base.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there are some practical concerns with the way it\u2019s looking to harness this input, said Chris Hughes, chief security advisor at <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.endorlabs.com%2F&#038;data=05%7C01%7Cmolly.weisner%40federaltimes.com%7C5cd01050a4ad4d5fb22e08dbcf513701%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638331719975324460%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&#038;sdata=MXWjsxh71ZdFhFSl6kahSifp6DJ7HUCB2yVIJCj5x%2FU%3D&#038;reserved=0\">Endor Labs<\/a> and a fellow at <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.cisa.gov%2Ftopics%2Fpartnerships-and-collaboration%2Fcyber-innovation-fellows-initiative&#038;data=05%7C01%7Cmolly.weisner%40federaltimes.com%7C5cd01050a4ad4d5fb22e08dbcf513701%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C0%7C638331719975324460%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&#038;sdata=%2BqZlUTjXAzi92frHN59dOzsHPnJsWhiZBdNgXt%2FJ0Ho%3D&#038;reserved=0\">CISA<\/a>.<\/p>\n\n\n\t<aside class=\"smg-interstitial-link wp-block-smg-interstitial-link\">\n\t\t<a href=\"https:\/\/staging.sightlinemg.com\/federaltimes\/federal-oversight\/watchdogs\/2023\/07\/17\/cyber-implementation-plan-leaves-open-questions-on-sboms-open-source\/\" class=\"smg-interstitial-link__inner\">\n\t\t\t\t\t\t\t<div class=\"smg-interstitial-link__media\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"176\" src=\"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1414627330.jpg.jpg?w=300\" class=\"smg-interstitial-link__image wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"smg-interstitial-link__content\">\n\t\t\t\t<span class=\"smg-interstitial-link__kicker\">Related<\/span>\n\t\t\t\t<h3 class=\"smg-interstitial-link__title\">Cyber implementation plan leaves open questions on SBOMs, open source<\/h3>\n\t\t\t\t\t\t\t\t\t<p class=\"smg-interstitial-link__excerpt\">The plan is sweeping, touching on several challenges that have hamstrung IT modernization at the federal level.<\/p>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/a>\n\t<\/aside>\n\t\n\n\n<p class=\"wp-block-paragraph\">For one, it risks becoming another form to fill out in an \u201cecosystem that already faces cumbersome compliance requirements,\u201d Hughes said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cNow someone at GSA and\/or other agencies will have to ingest and make sense of all these [answers] that are going to get returned to them,\u201d he added.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But Krooswyk said vendors may feel inclined to respond to show they are proactive compared to their competitors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the <a href=\"https:\/\/feedback.gsa.gov\/jfe\/form\/SV_ensD8H1R92nHS7k?Q_DL=ecifitP45JpHjFN_ensD8H1R92nHS7k_CGC_uxsH4RVbkZ9P2Ee&#038;Q_CHL=email%20RE:%20State%20%E2%80%93%20always%20interested\" target=\"_blank\">RFI<\/a>, GSA said one additional objective is to potentially reduce industry burden from responding to several government questionnaires.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since the questionnaire would be voluntary, there\u2019s also a question of whether respondents will self-select among those who are willing, and able, to be transparent on a host of topics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cObviously, when there\u2019s contracts and revenue on the line, companies may give favorable answers, or they may not be as forthcoming as they would be if a third party was evaluating them, for example,\u201d said Hughes. \u201cSo I think it\u2019s not beneficial in that regard, because it\u2019s going to be self-reported.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Though with heightened attention to the National Cyber Security Strategy, shifting software liabilities and IT best practices, suppliers looking to do business with government are used to being tested on their claims, Krooswyk said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThey\u2019re more concerned about that now,\u201d he said. \u201cSo I think people will represent themselves.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And the questionnaire could fill an information gap on aspects of the supply chain that haven\u2019t been as deeply understood, Krooswyk said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Experts also pointed out that the binary questions could yield some subjective answers, especially if a vendor\u2019s response is somewhere between \u201cyes\u201d or \u201cno.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One proposed question asks whether vendors follow operational standards or frameworks for IT and cybersecurity. There are at least a handful of NIST and other frameworks that could be acceptable answers, so one vendor may satisfy that by adhering to just one, while another may follow them all.<\/p>\n\n\n\t<aside class=\"smg-interstitial-link wp-block-smg-interstitial-link\">\n\t\t<a href=\"https:\/\/staging.sightlinemg.com\/federaltimes\/it-networks\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/\" class=\"smg-interstitial-link__inner\">\n\t\t\t\t\t\t\t<div class=\"smg-interstitial-link__media\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"196\" src=\"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg?w=300\" class=\"smg-interstitial-link__image wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t<div class=\"smg-interstitial-link__content\">\n\t\t\t\t<span class=\"smg-interstitial-link__kicker\">Related<\/span>\n\t\t\t\t<h3 class=\"smg-interstitial-link__title\">\u2018SBOM\u2019 disclosure rules loom for federal software procurement<\/h3>\n\t\t\t\t\t\t\t\t\t<p class=\"smg-interstitial-link__excerpt\">Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.<\/p>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/a>\n\t<\/aside>\n\t\n\n\n<p class=\"wp-block-paragraph\">\u201cWhich ones are important? How do I know? &#8230; Are they the same things that are important to GSA? And what does the alignment look like?\u201d Krooswyk said, suggesting that some specificity could help.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hughes vulnerability scans or machine-readable artifacts may be generally more effective ways of showing, rather than telling, a product\u2019s capability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSelf-attestation is a great start because it\u2019s easy, it\u2019s low friction, they can give us the information voluntarily,\u201d said Hughes. \u201cBut maybe it\u2019s not as forthcoming or truthful or rigorous as a third-party attestation. But also [that\u2019s] very cumbersome, complex, time consuming and expensive. So it\u2019s a delicate balance.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for what\u2019s missing, Hughes said he\u2019d like to see more on open source software, given many vendors may integrate it into their products and should have rigorous governance of them in place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Krooswyk said where the questionnaire asks about hardware <a href=\"https:\/\/www.federaltimes.com\/thought-leadership\/2023\/01\/30\/software-bill-of-materials-is-the-key-to-cybersecurity-compliance\/\" target=\"_blank\">bill of materials, <\/a>so too should it incorporate that for software to get a system-level vantage point.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.<\/p>\n","protected":false},"author":7,"featured_media":78162,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":36,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[60,12,36,31,33,6],"tags":[],"coauthors":[3269],"class_list":["post-26870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contracting","category-govcon","category-gsa","category-home","category-newsletters","category-acquisition"],"acf":{"subheadline":"","legacy_arc_id":"APS6XFNP45CQTMPW4YBXG2MIEM","arc_canonical_url":"\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>GSA pitches vendor self-assessment on supply chain cybersecurity - Federal Times<\/title>\n<meta name=\"description\" content=\"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GSA pitches vendor self-assessment on supply chain cybersecurity\" \/>\n<meta property=\"og:description\" content=\"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/\" \/>\n<meta property=\"og:site_name\" content=\"Federal Times\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-20T09:30:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T05:08:50+00:00\" \/>\n<meta name=\"author\" content=\"Molly Weisner\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Molly Weisner\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/f1587e1f8c0d41f0683bf42b02602ad8\"\n\t            },\n\t            \"headline\": \"GSA pitches vendor self-assessment on supply chain cybersecurity\",\n\t            \"datePublished\": \"2023-10-20T09:30:00+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:08:50+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/\"\n\t            },\n\t            \"wordCount\": 699,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1293091089.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"Contracting\",\n\t                \"GovCon\",\n\t                \"GSA\",\n\t                \"Home\",\n\t                \"Newsletters\",\n\t                \"Procurement\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/\",\n\t            \"name\": \"GSA pitches vendor self-assessment on supply chain cybersecurity - Federal Times\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1293091089.jpg.jpg\",\n\t            \"datePublished\": \"2023-10-20T09:30:00+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:08:50+00:00\",\n\t            \"description\": \"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1293091089.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyImages-1293091089.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/2023\\\/10\\\/20\\\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Procurement\",\n\t                    \"item\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/\",\n\t                    \"ad_zone\": \"acquisition\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"GSA\",\n\t                    \"item\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/acquisition\\\/gsa\\\/\",\n\t                    \"ad_zone\": \"gsa\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 4,\n\t                    \"name\": \"GSA pitches vendor self-assessment on supply chain cybersecurity\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"name\": \"Federal Times\",\n\t            \"description\": \"Federal Times\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#organization\",\n\t            \"name\": \"Federal Times\",\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/staging.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/federal-logo-white.png\",\n\t                \"caption\": \"Federal Times\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/#\\\/schema\\\/person\\\/f1587e1f8c0d41f0683bf42b02602ad8\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/staging.sightlinemg.com\\\/federaltimes\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GSA pitches vendor self-assessment on supply chain cybersecurity - Federal Times","description":"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","og_locale":"en_US","og_type":"article","og_title":"GSA pitches vendor self-assessment on supply chain cybersecurity","og_description":"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.","og_url":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","og_site_name":"Federal Times","article_published_time":"2023-10-20T09:30:00+00:00","article_modified_time":"2026-08-08T05:08:50+00:00","author":"Molly Weisner","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Molly Weisner","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#article","isPartOf":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/"},"author":{"name":"migration","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#\/schema\/person\/f1587e1f8c0d41f0683bf42b02602ad8"},"headline":"GSA pitches vendor self-assessment on supply chain cybersecurity","datePublished":"2023-10-20T09:30:00+00:00","dateModified":"2026-08-08T05:08:50+00:00","mainEntityOfPage":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/"},"wordCount":699,"commentCount":0,"publisher":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#organization"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1293091089.jpg.jpg","articleSection":["Contracting","GovCon","GSA","Home","Newsletters","Procurement"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","url":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/","name":"GSA pitches vendor self-assessment on supply chain cybersecurity - Federal Times","isPartOf":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#website"},"primaryImageOfPage":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#primaryimage"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#primaryimage"},"thumbnailUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1293091089.jpg.jpg","datePublished":"2023-10-20T09:30:00+00:00","dateModified":"2026-08-08T05:08:50+00:00","description":"IT experts weigh in on whether the proposed survey could fill information gaps on supply chain security or become a box-checking compliance exercise.","breadcrumb":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#primaryimage","url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1293091089.jpg.jpg","contentUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1293091089.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/2023\/10\/20\/gsa-pitches-vendor-self-assessment-on-supply-chain-cybersecurity\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/staging.sightlinemg.com\/federaltimes\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Procurement","item":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/","ad_zone":"acquisition"},{"@type":"ListItem","position":3,"name":"GSA","item":"https:\/\/staging.sightlinemg.com\/federaltimes\/acquisition\/gsa\/","ad_zone":"gsa"},{"@type":"ListItem","position":4,"name":"GSA pitches vendor self-assessment on supply chain cybersecurity"}]},{"@type":"WebSite","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#website","url":"https:\/\/staging.sightlinemg.com\/federaltimes\/","name":"Federal Times","description":"Federal Times","publisher":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/staging.sightlinemg.com\/federaltimes\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#organization","name":"Federal Times","url":"https:\/\/staging.sightlinemg.com\/federaltimes\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/","url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","contentUrl":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/06\/federal-logo-white.png","caption":"Federal Times"},"image":{"@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/staging.sightlinemg.com\/federaltimes\/#\/schema\/person\/f1587e1f8c0d41f0683bf42b02602ad8","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/staging.sightlinemg.com\/federaltimes\/author\/migration\/"}]}},"jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Federal Times","distributor_original_site_url":"https:\/\/staging.sightlinemg.com\/federaltimes","push-errors":false,"jetpack_featured_media_url":"https:\/\/staging.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyImages-1293091089.jpg.jpg","_links":{"self":[{"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/26870","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/comments?post=26870"}],"version-history":[{"count":1,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/26870\/revisions"}],"predecessor-version":[{"id":26871,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/posts\/26870\/revisions\/26871"}],"wp:attachment":[{"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/media?parent=26870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/categories?post=26870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/tags?post=26870"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/staging.sightlinemg.com\/federaltimes\/wp-json\/wp\/v2\/coauthors?post=26870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}