Navigating ICTS Compliance Under Heightened Scrutiny
-
July 31, 2026
-
Geopolitical tensions and the U.S. presidential administration’s desire to bolster national security and keep emerging and critical technology out of the hands of foreign adversaries have intensified scrutiny across the regulatory landscape.1 As a corresponding outcome, Information and Communications Technology and Services (“ICTS”) compliance has emerged as an operational imperative. As a result, organizations must develop an understanding of ICTS requirements and how to build or enhance a compliance program that shifts from reactive to proactive management.
Administered by the Office of Information and Communications Technology and Services (“OICTS”) within the U.S. Department of Commerce’s Bureau of Industry and Security (“BIS”), ICTS regulations are intended to prohibit or limit certain transactions that carry national security risks with foreign adversaries, and to secure and ensure the resilience of the ICTS supply chain.2 The core objectives of ICTS regulations are to prevent foreign adversaries from exploiting vulnerabilities in critical infrastructure, compromising the sensitive data of U.S. citizens or American businesses, and using compromised hardware, software, or services to conduct espionage or cyber attacks.
Understanding ICTS
The definition and applicability of ICTS regulation is broad, encompassing connected vehicles, emerging technologies, and data transmission. To date, key regulations and actions include banning certain antivirus software,3 the connected vehicles rule,4 and Infrastructure as a Service (“IaaS”) requirements for service providers.5
The wide-ranging implications are partially due to both components and end products being subject to ICTS requirements. In other words, component manufacturers and end-product companies are impacted. Further, compliance is an ongoing operational requirement; it extends beyond the deal and is perpetually applicable. The ongoing nature of ICTS regulations means it is especially critical for organizations with a global footprint to possess a comprehensive, proactive compliance program that constantly evaluates risk and determines when sensitive data moves across borders.
The Compliance Gap
ICTS regulation is less well-known, especially in corporate transactions, so it is possible that organizations are not aware of the obligations they face. Creating further gaps, it is not mandatory to submit compliance certification to BIS, which reduces visibility regarding if regulatory requirements are being met.
In our experience discussing ICTS compliance with clients, we’re increasingly seeing that organizations are not even aware of their responsibilities in this space until their customers or key partners begin asking questions. This lack of ICTS knowledge leaves organizations underprepared regarding their compliance efforts and could inadvertently damage relationships with their counterparties and expose them to additional regulatory risk.
For global organizations with complex supply chains, compliance is particularly challenging. An end product can potentially contain components from several sub-suppliers, creating multi-layered and vague dependencies. This can result in difficulties obtaining complete Software Bill of Materials (“SBOM”), “a list of ingredients that make up software components,” leaving organizations in the dark regarding what is actually in their end product, where it came from, and if it’s compliant.6
Consequences of Non-Compliance
Similarly to Committee on Foreign Investment in the United States (“CFIUS”) enforcement, non-compliance with ICTS regulations grant BIS the authority to unwind or invalidate transactions. There is also the risk of deals being shut down entirely, with obvious financial and reputational impacts on the organization responsible for not meeting regulatory requirements.
While penalties focus on operational restrictions rather than monetary fines, enforcement outcomes can be more consequential than an organization just paying a fee. Business and supply chain disruption can impact supply allocations, creating major inventory and allocation issues with cascading and damaging results across industry supplier ecosystems.
Non-compliance also carries the potential of being placed on the BIS Entity List, which imposes specific license requirements (usually with the presumption of denial) for the export, re-export, or in-country transfer of U.S. origin items, software, and technology that are subject to the U.S. Export Administration Regulations (“EAR”).7 For a technology or telecommunications company that relies on U.S.-origin software, hardware, and intellectual property, being added to the Entity List could cripple the company’s supply chain. Additionally, companies placed on the Entity List, as well as their non-listed affiliates, become a high-risk compliance burden to their customers and partners, which for some companies could effectively mean losing access to key markets. For industries such as automotive manufacturing, the practical operational issues caused by an Entity List designation could be catastrophic. For example, a European car company that both sells products in the U.S. market and has a large U.S. manufacturing presence would face severe supply chain disruption if they lost access to U.S.-origin components and technology. Not only would they be unable to procure the U.S.-origin parts needed to build their cars at their U.S.-based facilities, but they would also likely be unable to service existing vehicles, maintain their R&D activities, or acquire semiconductors that are either U.S.-origin or subject to the EAR under de minimis and Foreign Direct Product rules.
Effective ICTS Compliance Programs
Getting started on building an effective ICTS compliance program involves the following four steps, all of which are commonplace in export controls compliance.
- Conduct a comprehensive risk assessment: The goal of the assessment is to identify exposure areas across the enterprise. This analysis should include understanding what a covered transaction is and how it applies to the specific organization. The assessment should also include mapping supply chains and ensuring clean data on all suppliers is available, e.g., complete SBOM with “know your supplier” information included to identify any foreign nexus risks. This step should also include identifying how technology, devices, and products work and if they are secure, e.g., data is not being leaked to foreign adversaries, as well as testing and documenting versus relying on policy alone.
- Address identified gaps: Once vulnerabilities are discovered, a remediation plan for tackling compliance deficiencies should be developed. This plan should include implementing controls tailored to the specific organizational risk profile, accounting for unique threats and compliance considerations.
- Create a compliance infrastructure: Larger organizations likely have dedicated compliance teams, but those that do not will need the support of professionals to set up new compliance programs with robust governance frameworks, escalation protocols, and documentation standards. External experts can help build this infrastructure and then transition to internal management for day-to-day oversight, while providing periodic check-ins to ensure the program is operating efficiently. Developing a balance between internal compliance teams and external support is important in creating a compliance infrastructure that accomplishes the goal of sustainability and effective governance.
- Establish ongoing protocols: Before pursuing transactions or expanding operations, organizations should ensure compliance through ongoing monitoring, audits, periodic reassessments, and continuous monitoring protocols. While these tasks can be handled internally, organizations should consider partnering with an independent third party to audit existing ICTS programs to ensure an impartial assessment.
From Reactive to Proactive
The current global regulatory climate is transitioning ICTS compliance from optional to foundational. A proactive approach reduces transaction risk, builds resilience against operational disruption, and better positions organizations for potential enforcement as regulatory scrutiny intensifies. Establishing a robust ICTS compliance program today, focused on assessing risks, addressing gaps, and building a sustainable infrastructure, is critical. Organizations should seek third-party certification or independent validation of their established processes to demonstrate compliance maturity to customers and regulators. Failing to do so can mean the difference between validated transactions and being placed on an entity list.
Footnotes:
1: Promoting Advanced Artificial Intelligence Innovation and Security, Exec. Order No. 14,409, 91 Fed. Reg. 34,565 (June 5, 2026).
2: Securing the Information and Communications Technology and Services Supply Chain, 86 Fed. Reg. 4,915 (Jan. 19, 2021) (to be codified at 15 C.F.R. pt. 7).
3: Bureau of Industry and Security, U.S. Department of Commerce, “Kaspersky Lab, Inc. Prohibition,”.
4: Bureau of Industry and Security, U.S. Department of Commerce, “Connected Vehicles (CV),”.
5: Bureau of Industry and Security, U.S. Department of Commerce, “Commerce Proposes Rule to Advance U.S. National Security Interests and Implement Biden-Harris Administration’s AI Executive Order and National Cybersecurity Strategy” (Jan. 29, 2024).
6: Cybersecurity and Infrastructure Security Agency, “Software Bill of Materials (SBOM),”.
7: Bureau of Industry and Security, U.S. Department of Commerce, “Export Administration Regulations: Part 744 - Control Policy: End-user and End-use Based,” 15 C.F.R. § 744.16 (2026).
Related Insights
Related Information
Published
July 31, 2026
Key Contacts
Managing Director