For the past thirty years, most organizations have built their supply chains on a single premise: that the lowest landed cost available anywhere on earth was the right cost, and that the network connecting you to it would hold. That premise has not survived the past five years. Rather than a series of unrelated shocks (a boat getting stuck in the Suez Canal, a semiconductor shortage, an export control regime rewritten in a week), what we have watched is a structural repricing of distance, concentration, and political risk.
What the Government is Telling the Market
Recent evidence for this shift is found in Executive Order 14415, issued on July 20, which requires defense contractors and their subcontractors at any tier to trace critical supply chains back to the origin of raw materials, to vet suppliers for financial, ownership, and capacity risk, and to qualify alternatives to sources the government considers unreliable. If you build for the Department of War, this is now your operating environment. If you do not, it is still a leading indicator that you should pay attention to.
Regulatory requirements written for national security have a consistent history of migrating outward: into customer flow-downs, into insurance underwriting, into audit standards, into “know your supplier” requirements. While the specific mandate applies to a narrow set of companies, the expectation that a serious manufacturer knows where its subcomponents and materials actually come from will affect the industry more broadly.
To be sure, this is not an argument that all production returns to the United States, and the order itself contemplates allied sourcing rather than pure domestic supply. Supply chain security has also been a durable bipartisan project across administrations, which is the clearest signal available that the direction is not going to reverse. The tools of industrial policy remain debatable, but the overall trajectory does not.
Supply Chain Management is Not a Records Exercise
The natural corporate response to any mapping requirement, whether it arrives from a regulator or from your largest customer, is to treat it as a data collection problem. Stand up a questionnaire, push it down the tiers, warehouse the responses, produce the artifact when a customer or a regulator asks. This is a completely understandable yet profoundly dangerous behavior.
Manufacturers of complex engineered items know why. A drawing does not build a part. A supplier builds a part, and whether that part arrives correct, on time, and to spec depends on whether the engineer at the top of the chain and the shop floor at the fourth tier have a real working relationship, the kind where a tolerance question gets a phone call rather than a change order six weeks later. That relationship also determines something less discussed: where you sit in that supplier's queue. Capacity is allocated by people. When a forging house has three customers and one open slot, the slot goes to the customer they know, trust, and have solved problems with before. A vendor record does not earn that slot.
The commercial case and the compliance case point in the same direction, which is fortunate. You cannot detect a supplier's financial deterioration, ownership change, or capacity constraint from an annual form. You detect it from continuous contact, the kind that surfaces a problem while it is still a scheduling conversation rather than a stop-work.
Relationships Do Not Scale by Themselves
For a small shop with 40 suppliers, relational supply chain management is simply how business is done. For a medium or large organization with hundreds or thousands of suppliers across multiple tiers, it becomes a systems problem, and this is where most programs break. The organization is asked to know its suppliers at a depth that has historically required personal familiarity, at a breadth that makes personal familiarity impossible. Spreadsheets and ERP vendor masters were built to record transactions, not to sustain relationships.
The base is also larger and more fragmented than most executives assume. Most of a supplier base needs monitoring, while a much smaller subset, the one holding the sole sources, the long-lead items, and the parts that impact your ability to drive revenue, needs a genuine relationship. Deciding which suppliers belong in that second group is itself a strategic judgment, and it is one most organizations have never formally made.
What organizations need is not a compliance database but a system of action: one that maintains a living picture of who can build what, tracks qualification status and risk signals continuously, and puts the right engineer in contact with the right supplier at the right moment. Keep people at the center. Let the system carry the scale.
This is the problem we built Sustainment to solve, and we are not alone in working on it. The point is not the tooling. The point is that illumination, qualification, and relationship management have become continuous operational disciplines, and disciplines require systems.
A Strategic Pillar, Not an Administrative Function
Every organization has a supply chain strategy. Most simply inherited it from a prior set of assumptions about cost, distance, and stability that may no longer hold. An inherited strategy is not a decision.
That is why this belongs at the executive table rather than two levels below it. Supply chain decisions now determine which markets you can serve, which contracts you can win, and how much risk sits on your balance sheet, and decisions of that consequence do not get made well by people who are measured only on unit cost.
None of this is free. Mapping a chain to its origin, funding the qualification of second sources, and staffing genuine supplier relationships all cost money now against a disruption that may not arrive this year. That is precisely the sort of tradeoff that belongs to executives rather than to a procurement budget, because the question is not how to be efficient but how much resilience the business is willing to buy.
The cardinal sin of organizational strategy is executing a great strategy that was built for a different environment. The environment has changed, and by all appearances it will keep changing, and risks will continue to increase.

