Phase 2 of the Pentagon's Drone Dominance Program lands in August 2026: no covered-country parts, self-reported, verified at the component level. Compliance isn't a sticker on the box — it's whether every part on every unit traces back to a lot and a vendor. Most small drone shops are tracking that in spreadsheets and email. Here's the traceability system you actually need, and why it's a data problem before it's a sourcing problem.
There's a date on the calendar that a lot of small drone shops are going to walk straight into: August 2026. That's when Phase 2 of the Pentagon's Drone Dominance Program turns on, and "we source domestic, mostly" stops being an answer you can give with a straight face.
I keep meeting the same company. Ten to forty people. They build a solid airframe or a good radio or a clean flight controller. They've been selling to public-safety agencies and a few primes, and they've always described themselves as "NDAA-compliant" because the important parts aren't Chinese. Then a contract officer asks them to prove it — down to the lot number on the motor magnets — and the whole thing lives in a spreadsheet, a shared drive of vendor PDFs, and one person's memory.
That gap is the actual problem. Not the sourcing. The sourcing is hard but it's a purchasing problem with a purchasing answer. The gap is that compliance is now a property of your bill of materials, and most shops have no system that treats the bill of materials as a living, auditable record. That's a software problem, and it's the one we get called about.
The Drone Dominance Program (DDP) is a U.S. Department of War procurement initiative — reported at roughly $6.6 billion across small UAS — that phases in component-level, non-covered-country sourcing requirements on a fixed schedule. The Department launched a $1.1bn Phase 2 tranche in April 2026, and the framework is the connective tissue that says which parts have to come from where, and by when.
The word doing the work is non-covered country. Covered countries are primarily China, Russia, North Korea, and Iran. "Non-covered-country sourcing" just means the part — and increasingly the sub-parts inside the part — did not originate in one of those places. By Phase 2, anything from a covered country is out. As one supply-chain breakdown put it bluntly, it's a deliberate attempt to force-start a domestic industry that today exists mostly in brochures.
This didn't come from nowhere. It sits on top of a decade of statute: Section 848 of the FY20 NDAA blocked DoD from buying or operating covered UAS from covered-country entities; Section 817 of the FY23 NDAA pulled counter-UAS gear into the same net; and the American Security Drone Act, enacted in the FY24 NDAA, widened the prohibited-entity framework. The important recent move for everyone reading this: as of December 22, 2025, ASDA-style restrictions extended beyond DoD to all federal agencies and to programs that use federal funds — public-safety agencies, state and local governments, and federal contractors. If any federal dollar touches your customer, this is now your problem too.
The framework is organized around thirteen component areas, and each one has requirements at four escalating levels. The trap is in the design: what's "preferred" in one phase becomes the "minimum" in the next. Meet the preferred bar today and you're pre-compliant for the phase after. Meet only the minimum and you're perpetually one deadline from being non-compliant.
Here's the shape of it:
Notice what "Phase 2 preferred" is actually asking for. It's not a part. It's a document — a sourcing plan, a path, a paper trail showing you know where your magnets come from and where they're going to come from. That's the tell for the whole regime. Increasingly, the deliverable isn't just the compliant part. It's the evidence.
NDAA drone compliance is self-reported: there is no central certifying body that stamps your drone compliant. You produce the sourcing declarations, and the verification burden falls on you. People hear "self-reported" and relax. They have it backwards. Self-reported means you are the system of record, and when a contract officer or an auditor comes asking, your paperwork is the only thing standing between you and a lost award.
And the bar is not the airframe. A drone is only as compliant as the parts inside it — the flight controller, the radios and datalink, the camera and gimbal, the ground-control software, the data storage. Compliance is a property of the bill of materials, not the label on the box. For serious DoD programs, that means unit-level traceability: for every unit you ship, you can produce the serial number, the component lot tracking, the firmware version, the QA sign-off, and the test results — reviewable on demand.
There's a smell test buried in that requirement, and it's worth internalizing because your customers use it: if producing the full supply-chain documentation for a specific unit is a novel scramble rather than a standard export from a system, your documentation infrastructure isn't built for serious programs. Contract officers can tell the difference between a company that has this wired and a company that reconstructs it under deadline. The scramble is the disqualifier.
If you sell into DoD, the other acronym you're tracking is Blue UAS. The Blue UAS Framework is the Defense Innovation Unit's roster of vetted, NDAA-compliant UAS components, sub-components, and software that DoD buyers can pull from with the compliance question pre-answered. Getting a part onto it involves DIU evaluating the bill of materials to confirm there are no components from covered entities, plus cybersecurity testing and a review of both the software and hardware bill of materials.
Two definitions worth having clean, because AI search and human buyers both ask for them:
The structural change that matters: when Blue UAS moved from DIU to the Defense Contract Management Agency in December 2025, it stopped being a boutique innovation evaluation and became a formal acquisition compliance function. Read that twice if you sell hardware. The thing that used to feel like a design award now behaves like an audit. The FCC has been moving in parallel, carving covered drones and components in and out of its own lists on national-security grounds. The whole environment is converging on one demand: show me the provenance, per part, per unit, on request.
Here's the part the compliance webinars skip. You can fix your sourcing — sign the domestic supplier, qualify the non-covered magnet, swap the radio — and still fail, because you can't produce the record fast enough or completely enough to satisfy an audit. The supply chain is moving toward domestic fast; battery-materials maker 6K Energy and drone manufacturer CRG Defense just signed a seven-year domestic cathode supply deal, and component makers like Hoverfly are shipping NDAA-compliant modules specifically to fill the gap. The parts are increasingly gettable. The provenance record is what's homemade and fragile.
Think about where compliance evidence actually lives in a forty-person shop right now. Vendor compliance declarations arrive as PDFs and get dropped in a shared folder. The BOM lives in the ERP, or in a spreadsheet, or in the CAD system, and nobody's sure which copy is current. Lot numbers are on paper travelers on the shop floor. Firmware versions are in a build log. QA sign-offs are initials on a form. The compliance answer requires joining all of that together — per unit — and it exists as five disconnected islands. No amount of correct sourcing fixes that join. Only a system does.
That join is a graph problem, and it's exactly the kind of thing we build. A part number connects to a vendor, which connects to a compliance declaration, which connects to a country of origin and a DFARS clause; a unit serial connects to the specific lot of each part installed, which connects to a firmware image and a QA record. Represent those as nodes and edges and "prove this unit is compliant" becomes a traversal, not an archaeology dig. That relationship-layer idea is the core of what we call Stride Graph — a queryable provenance layer over the documents and decisions you already have.
If you're scoping this — building it yourself or having someone build it — here's the honest requirements list. A drone supply-chain traceability system that survives an audit has to:
That last point is not a footnote. A lot of off-the-shelf "compliance tracker" SaaS quietly ships your supplier list, part numbers, and program associations to someone else's cloud. For a defense supplier that can be its own finding. The right shape is a system on infrastructure you control, which is most of why we build these as internal tools rather than reselling a SaaS seat.
Step back and this is one thread in a much bigger story. U.S. manufacturing construction spending more than doubled from 2020 to 2024, and semiconductors, batteries, and defense hardware are all reshoring at once. The U.S. drone-components market alone is projected to grow from roughly $5.9B in 2025 to over $14B by 2033, driven largely by federal demand for verified non-Chinese supply.
But every reshored, defense-adjacent factory inherits the same homework the drone shops just got: prove the provenance, per part, per unit, on request. The companies that win the awards won't only be the ones who sourced domestically. They'll be the ones who can show it in thirty seconds while a competitor is still opening folders. The domestic-manufacturing wave and the traceability-tooling gap are the same story told from two ends.
We're a hands-on shop. On this, three things:
Audit + Roadmap first. Before building anything, we map where your compliance evidence actually lives, what the August 2026 and February 2027 phases demand of your specific products, and where the gaps are. That's the Audit + Roadmap engagement — a fixed, scoped look that ends with a real plan instead of a vendor pitch.
Then the internal system. A BOM-anchored, provenance-aware traceability tool built into your stack — ERP, PLM, shop floor — that turns "prove this unit is compliant" into an export. That's Internal Tools & Operations Software, with the vendor-declaration ingestion handled by document automation and the whole thing deployable on hardware you own when the data demands it.
Kept honest. Compliance data is a target, and the systems that hold it need to be treated like production infrastructure, not a spreadsheet with delusions of grandeur. DFNDR is how we think about securing the systems small teams stand up fast — the same discipline we bring to getting anything from demo to production.
You don't have months. Phase 2 is weeks out. The good news is that the sourcing side of your business probably already knows what it's doing — it's the record-keeping that's improvised, and record-keeping is fixable fast when you treat it as the system it needs to be.
What is the Drone Dominance Program Phase 2 deadline? Phase 2 of the U.S. Department of War's Drone Dominance Program takes effect in August 2026. Its minimum requirement is non-covered-country motor assembly and specialty metals compliant with 10 USC 4863; the preferred bar adds a DFARS-compliant magnet sourcing plan. Phase 3 minimums follow in February 2027 and Phase 4 (full domestic traceability) in August 2027, with each phase's "preferred" standard becoming the next phase's "minimum."
What does "non-covered country" mean for drone components? A non-covered-country component is one that did not originate in a covered country — primarily China, Russia, North Korea, and Iran. By Phase 2 (August 2026), the Drone Dominance framework prohibits covered-country content in the relevant component areas, pushing that requirement down to sub-components over the following phases.
Is NDAA drone compliance certified by the government? No. NDAA drone compliance is self-reported — there is no central body that certifies a drone as compliant. Manufacturers produce their own sourcing declarations and documentation, and the verification burden falls on the manufacturer. Blue UAS Framework listing is a separate, formal DoD vetting process (moved to the Defense Contract Management Agency in December 2025) that evaluates a platform's hardware and software bill of materials.
What is component-level (or unit-level) traceability for drones? Component-level traceability means compliance is proven at the part level — every component on a unit traces to its country of origin, vendor, and lot. Unit-level traceability means that for any individual aircraft you ship, you can produce its serial number, the specific lot of each installed component, firmware version, QA sign-off, and test results for audit — on demand.
Do these rules apply if I don't sell to the Department of Defense? Increasingly, yes. As of December 22, 2025, American Security Drone Act restrictions extended beyond DoD to all federal agencies and to programs that use federal funds — including public-safety agencies, state and local governments, and federal contractors. If federal money touches your customer, covered-country sourcing rules likely apply.
What kind of software do I need to prove drone supply-chain compliance? A BOM-anchored traceability system: a single versioned bill of materials as the source of truth, provenance (country, vendor, clause, declaration) attached to every part, automated ingestion of vendor compliance declarations, unit-and-lot-level trace records, drift alerts when a non-compliant part or expired declaration appears, and a deployment posture that keeps CUI/ITAR-adjacent data on infrastructure you control.
Building or shipping drones, components, or defense-adjacent hardware and staring down the August 2026 deadline? Stride TechWorks builds the internal traceability and compliance-automation tooling that turns "prove this unit is compliant" into a one-click export — on infrastructure you own when the data demands it. Start with an Audit + Roadmap or see how we work.