January 1, 2027 is getting very close – and there’s no time left to find out the hard way.
In 2021, Congress gave the Department of Defense a deadline: by January 1, 2027, no printed circuit board or printed circuit board assembly used in a covered defense system may contain components sourced from China, Russia, Iran, or North Korea. That deadline is now under four months away.
Last week, the Printed Circuit Board Association of America publicly pressed the Department of War to hold the line. PCBAA’s executive director, David Schild[1], put it bluntly: ״every month of delay is a month American warfighters remain dependent on untrusted components״. In a comment to DFARS Case 2022-D011, the association is opposing any postponement or loophole, and it is pointing out something uncomfortable at the same time, that China and other Asian states continue to invest billions in domestic PCB manufacturing while the US supply base remains frail.
A deadline is only good if it can be enforced
Here is the part that should worry a defense contractor more than the politics of the deadline itself. A statutory cutoff date tells you what has to be true on January 1, 2027. It does not tell you how you will know, board by board, whether it already is.
Most defense contractors will answer that question the way the supply chain has always answered it, with paperwork. A supplier declaration. A certificate of conformance. A bill of materials that says which manufacturer part number should be on the board. That system was built for a world where the biggest risk was a late shipment, not an adversary nation embedded three tiers deep in a subcontractor’s subcontractor.
We wrote earlier this year, about DFARS Case 2022-D011[2], a proposed Department of War rule that would required contractors to produce PCB provenance data on demand, for audit. That rule is still just proposed. This deadline is not. It is law, it has a date attached, and PCBAA is now making it clear that nobody expects that date to move.
Declaration is not verification
A supplier declaration tells you what a part is supposed to be. It cannot tell you what is actually soldered onto the board in front of you. That gap does not matter much when the question is quality. It matters enormously when the question is whether a specific component’s country of origin can be traced back to a sanctioned or adversarial source, because a mislabeled, remarked, or substituted part can carry a clean looking declaration and still fail the standard the law is about to enforce.
With under four months left, a contractor cannot retroactively inspect its way through years of assembled inventory. But that is exactly the wrong lesson to take from this deadline. The lesson is that verification has to move to where the risk actually lives, at the point where a component is placed on the board, not at the point where someone signs a form six months later.
Component level verification closes to loop on enforcement
This is where Cybord’s approach differs from the audit trail most contractors currently have. Instead of trusting a supplier’s declaration, Cybord’s AI-driven software inspects every component as it is placed on the line, not a sample, every one, at line speed, using the machines a contractor already runs. It captures the top marking, lot and date code, manufacturer part number, and country of origin for each part, and builds an accurate, verified, evidence-based record of what is actually on the board rather than what the paperwork says should be there.
That is the difference between hoping a supplier’s country of origin claim holds up and having a per component, forensic grade record that either confirms it or flags it before the board ships. For a defense contractor facing a hard compliance date, that record is not a nice to have. It is the only version of “we know” enforcement that will survive an audit.
The micro-traceability described above also does something a one-time compliance sweep cannot: it keeps working after January 1, 2027. New components come from new suppliers, PCBAA itself notes the adversarial supply base is still expanding investment, and a contractor’s own supplier list will keep changing. A verification system that only checks once cannot catch a substitution that happens six months from now. One that checks every board, every time, can.
What this means for contractors right now
If your compliance plan for this deadline is a supplier attestation campaign, you are not wrong to be doing it. Declarations matter. But they answer a question about intent, not about what physically happened on your assembly line. The gap between those two things is exactly where an undetected, non-conforming component gets through.
The clock on this one does not reset. Contractors who treat January 1, 2027 as a paperwork deadline will find out, likely during an audit, that paperwork was never going to be enough. Contractors who treat it as a verification deadline, one that requires knowing what is actually on the board rather than what was declared about it, will be the ones who can prove – and enforce – compliance instead of arguing for it.
[1] https://www.electronicsweekly.com/news/business/pcbaa-urges-pentagon-to-act-on-pcbs-2026-09/
[2] https://www.regulations.gov/document/DARS-2026-0298-0001
