Pentagon's Section 1260H Chinese Military Company List: Who Got Added, Why, and What It Means for Your Organization
The Department of Defense, now also operating under the secondary title "Department of War" (DOW) per Executive Order 14347 signed September 2025, dropped a significant update to its Chinese Military Companies (CMC) list on June 8, 2026, adding 65 entities: 17 parent companies and 48 subsidiaries [1]. The update also removed 10 previously listed entities, including several associated with CNOOC and COSCO Shipping, bringing the total list to 188 companies [1]. The additions include names that will force compliance teams across the globe to rethink supplier relationships, investment portfolios, and technology procurement decisions. Alibaba. Baidu. BYD. WuXi AppTec. Trina Solar. Unitree Robotics. These are not fringe state-owned defense contractors. They are companies embedded in global commerce, cloud infrastructure, autonomous vehicles, pharmaceutical supply chains, and renewable energy.
The 1260H list is not a sanctions list. It does not ban transactions. But treating it as a toothless roster is a mistake that organizations keep making to their own detriment.
What Section 1260H Actually Does
Section 1260H of the National Defense Authorization Act for Fiscal Year 2021 requires the Secretary of Defense to identify companies operating in the United States that are owned by, controlled by, or affiliated with China's military, government, or defense-industrial base [2]. The list is updated annually, as required through December 31, 2030.
Designation carries no automatic criminal penalty. What it does is establish a formal U.S. government finding of military affiliation. That finding feeds into a web of downstream regulatory consequences:
- DoD Procurement Restrictions: Under Section 805 of the FY2024 NDAA, DoD is prohibited from directly contracting with listed entities effective June 30, 2026, with indirect procurement bans following on June 30, 2027 [1].
- AI Product Prohibition: Section 1532 of the FY2026 NDAA, effective January 17, 2026, prohibits contractors from using AI products developed by 1260H-listed entities during performance of a DOW contract, unless granted a waiver [1].
- NS-CMIC Investment Restrictions: Section 1260H designation increases the likelihood that Treasury's OFAC will add entities to the Non-SDN Chinese Military-Industrial Complex Companies (NS-CMIC) list under Executive Order 14032 (which amended and superseded EO 13959). Placement on the NS-CMIC list prohibits U.S. persons from purchasing or selling publicly traded securities of the designated entity. The 1260H list and NS-CMIC list are separate but overlapping instruments administered by different departments [2].
- COINS Act Reporting: Section 8531 of the FY2026 NDAA requires the President to report to Congress within two years on whether any 1260H-listed entity qualifies for NS-CMIC designation [2].
- BIS Entity List Overlap: Several CMC-designated companies also appear on the Bureau of Industry and Security's Entity List, which imposes hard export control restrictions. Huawei, for example, sits on both lists [2].
DoD procurement rules, OFAC guidance, and congressional scrutiny all treat this list as a primary reference point. Financial institutions, prime contractors, and institutional investors use the list as a core input for due diligence and counterparty risk assessment.
The practical effect: designation creates legal, reputational, and operational risk for anyone doing business with listed entities, even in the absence of a direct prohibition.
The Big Names: Alibaba, Baidu, BYD, and WuXi AppTec
The most consequential additions to the June 2026 list are companies with massive global footprints.
Alibaba Group and Baidu are foundational platforms in Chinese tech. Alibaba's cloud division (Alibaba Cloud) serves international customers across Asia, Europe, and the Middle East. Baidu operates China's dominant search engine and has invested heavily in autonomous driving (Apollo) and AI large language models (Ernie). Both companies were designated based on affiliations with China's State-owned Assets Supervision and Administration Commission (SASAC) and because they qualify as contributors to China's military-civil fusion strategy through projects with the Ministry of Industry and Information Technology (MIIT) [1].
BYD, widely reported as the world's largest electric vehicle manufacturer by unit sales, received the same treatment: SASAC affiliation and MIIT military-civil fusion project involvement [1]. BYD's battery technology, particularly its Blade Battery, is integrated into EV supply chains well beyond China. The company has manufacturing facilities in Hungary, Brazil, Thailand, and Indonesia, and its components show up in vehicles and energy storage systems sold globally.
NIO, another Chinese EV manufacturer, was also designated alongside BYD [2].
WuXi AppTec Co. Ltd., a contract development and manufacturing organization (CDMO) with extensive partnerships across the U.S. biotech and pharmaceutical industry, was one of the most consequential additions [1]. WuXi AppTec's listing has significant implications under the BIOSECURE Act provisions of the FY 2026 NDAA, which restrict the use of federal funds to procure biotechnology equipment and services from designated companies [1].
The designation rationale matters here. The DoD is not claiming these companies manufacture weapons. It is asserting that their structural ties to SASAC and their participation in MIIT-coordinated projects make them part of China's military-civil fusion apparatus [1]. That is a broader theory of affiliation than "this company builds missiles," and it signals that the DoD is applying a wider aperture to what constitutes military entanglement.
New Entrants: Robotics, Solar, Batteries, and Genomics
Beyond the headline names, the June 2026 additions reveal DoD's focus on specific technology sectors it considers strategically sensitive.
Robotics and Autonomy:
- Hangzhou Yushu Technology Co. Ltd. (Unitree Robotics): Known for quadruped robots that went viral on social media, Unitree produces low-cost robotic platforms [1].
- Autel Intelligent Technology Corp. Ltd.: A major drone manufacturer competing with DJI [1].
- Robosense Technology Co. Ltd.: A LiDAR sensor manufacturer whose products are integrated into autonomous vehicles, industrial automation, and robotics platforms globally [1].
Energy and Solar:
- JA Solar Technology Co. Ltd. and Trina Solar Co. Ltd.: Two of the world's largest solar panel manufacturers [1].
- CALB Group Co. Ltd. and EVE Energy Co. Ltd.: Battery manufacturers supplying cells for electric vehicles, energy storage systems, and consumer electronics [1].
Semiconductors and Optoelectronics:
- Tianma Microelectronics Co. Ltd.: A display panel manufacturer supplying screens for smartphones, automotive displays, and industrial equipment [1].
- Zhongji Innolight Co. Ltd.: A major optical transceiver manufacturer [1]. Innolight reportedly supplies transceivers to hyperscale data center operators, which, if confirmed, would put data center procurement teams on notice.
Genomics and Life Sciences:
- Novogene Co. Ltd.: A genomic sequencing services provider with international operations [1].
- Complete Genomics: Also designated, further expanding the genomics and life sciences coverage of the list [2].
The Military-Civil Fusion Theory of Designation
The common thread across these additions is China's military-civil fusion (MCF) strategy. MCF is not a vague concept. It is an explicit national policy, codified under Xi Jinping's leadership, that seeks to eliminate barriers between China's civilian commercial sector and its military-industrial base. The idea is that advances in AI, robotics, quantum computing, biotechnology, and new energy feed directly into PLA modernization.
The DoD's use of MCF as a designation basis has expanded over successive list updates. Early iterations of the 1260H list focused on obvious state-owned defense enterprises: AVIC, CASC, CASIC, CETC, Norinco. These are companies that build fighter jets, missiles, and military electronics. Nobody disputes their military affiliation.
The June 2026 additions represent a different category. Companies like Alibaba and BYD are not arms manufacturers. Their designation rests on the theory that SASAC shareholding structures and MIIT project participation create a conduit through which commercial technology flows to military end users [1]. The DoD is signaling that participation in China's state-directed innovation ecosystem is itself sufficient grounds for designation, regardless of whether a company's primary output is military hardware.
Downstream Consequences: Beyond the List Itself
Organizations need to understand that the 1260H list does not exist in isolation. It interacts with several other regulatory mechanisms.
DoD Procurement: Section 805 of the FY2024 NDAA prohibits DoD from directly contracting with listed entities effective June 30, 2026, and from indirect procurement effective June 30, 2027 [1]. Section 1532 of the FY2026 NDAA already prohibits contractors from using AI products developed by 1260H entities during DoD contract performance, effective January 17, 2026 [1]. Federal contractors and subcontractors face increasing scrutiny over supply chain relationships with CMC-designated entities.
Potential Investment Restrictions: The 1260H list is separate from Treasury's NS-CMIC list, which imposes actual securities transaction prohibitions under EO 14032. However, 1260H designation significantly increases the likelihood of subsequent NS-CMIC listing. Index fund providers, pension funds, and asset managers should assess the risk that newly designated entities may be added to the NS-CMIC list, which would trigger mandatory divestiture requirements [2].
BIS Entity List Overlap: Several CMC-designated companies also appear on the Bureau of Industry and Security's Entity List, which does impose hard export control restrictions. Huawei, for example, sits on both lists. The overlap means that some designations carry both the reputational weight of 1260H and the operational restrictions of BIS controls [2].
BIOSECURE Act Implications: The addition of WuXi AppTec, Complete Genomics, and Novogene to the 1260H list may have significant implications under the BIOSECURE Act provisions of the FY2026 NDAA, which restrict the use of federal funds to procure biotechnology equipment and services from designated companies [1].
Reputational and Counterparty Risk: Even absent a legal prohibition, doing business with a company the U.S. government has formally identified as affiliated with China's military carries reputational exposure. Banks, insurers, and commercial partners increasingly treat CMC designation as a risk factor in due diligence reviews.
Established Designees: Still on the List
The legacy designees remain. Companies that have appeared on previous iterations of the 1260H list continue to carry their designations.
Huawei Technologies remains listed, consistent with its FCC, BIS, and OFAC designations.
ZTE Corporation, which nearly collapsed in 2018 after a BIS denial order over Iran and North Korea export control violations, stays on the list.
Hangzhou Hikvision Digital Technology (Hikvision), the world's largest surveillance camera manufacturer, continues to appear.
Aviation Industry Corporation of China (AVIC), China Aerospace Science and Technology Corporation (CASC), China Aerospace Science and Industry Corporation (CASIC), and China Electronics Technology Group Corporation (CETC) are all longstanding designees. These are the core state-owned defense enterprises with direct weapons production roles.
Entities Removed
The June 2026 update removed 10 previously listed entities upon determining they do not operate directly or indirectly in the United States [1]. Notable removals include entities associated with CNOOC and COSCO Shipping, as well as ChangXin Memory Technologies (CXMT) and Yangtze Memory Technologies (YMTC).
Analysis: What This Means for Organizations
The June 2026 list expansion represents a meaningful escalation in scope. The DoD has moved beyond designating obvious military contractors and is now capturing companies whose military relevance is structural rather than operational. A solar panel company does not build bombs. But a solar panel company with SASAC ownership and MIIT project participation exists within an ecosystem designed to channel commercial innovation toward military applications.
For compliance teams, the practical challenge is supply chain visibility. Zhongji Innolight transceivers may already sit in your data center racks. CALB or EVE Energy cells may power your fleet vehicles or backup battery systems. Trina Solar panels may be on your rooftops. WuXi AppTec may be manufacturing components for your pharmaceutical products. The designation does not require you to rip them out tomorrow, but it creates an obligation to assess and document the risk, particularly for organizations with government contracts or regulated financial activities.
For investors, the immediate concern is monitoring NS-CMIC list developments and index composition. Major index providers will need to determine whether newly designated companies face subsequent NS-CMIC listing, which would require exclusion from benchmarks.
Red Sheep Assessment
Confidence: Moderate
The expansion of the 1260H list into commercial technology, clean energy, pharmaceutical services, and genomics companies reflects a strategic decision by the DoD to treat China's entire state-directed innovation apparatus as a military risk, not just its arms manufacturers. This is a logical extension of the military-civil fusion framework, but it creates a designation regime so broad that it risks losing analytical specificity. When Alibaba Cloud and CASIC (a cruise missile developer) sit on the same list, the analytical value for risk differentiation diminishes.
The SASAC and MIIT affiliation criteria used for Alibaba, Baidu, and BYD could, in principle, capture hundreds of additional Chinese companies. SASAC oversees virtually all major Chinese state-owned enterprises, and MIIT coordinates technology standards and research programs across the Chinese economy. The current 65-entity expansion may be the beginning of a much larger designation campaign.
There is a contrarian read here: broad designations dilute the list's utility as a risk differentiation tool. A compliance officer who sees Alibaba on the same list as a ballistic missile manufacturer may struggle to calibrate an appropriate risk response. The DoD may be optimizing for geopolitical signaling at the expense of operational precision. Organizations should use the 1260H list as one input among several (BIS Entity List, OFAC SDN/NS-CMIC, end-use analysis) rather than treating it as a definitive risk taxonomy.
Defender's Checklist
- ▢[ ] Audit current supply chains against the full June 2026 1260H list (Federal Register notice, June 10, 2026), including all 48 designated subsidiaries. Pay particular attention to optical transceivers (Zhongji Innolight), battery cells (CALB, EVE Energy), solar components (JA Solar, Trina Solar), display panels (Tianma Microelectronics), and CDMO/pharmaceutical services (WuXi AppTec).
- ▢[ ] Review cloud and SaaS vendor dependencies for any reliance on Alibaba Cloud or Baidu AI services, especially in non-U.S. operations where these platforms have market share. Note: Section 1532 of the FY2026 NDAA already prohibits use of AI products from 1260H entities in DoD contract performance, effective January 17, 2026. Contractors should immediately audit systems for compliance.
- ▢[ ] Screen investment portfolios and index fund holdings for exposure to newly designated entities. Monitor whether Treasury/OFAC adds these entities to the NS-CMIC list, which would trigger mandatory divestiture under EO 14032. Assess reputational and policy risk of continued holdings regardless of NS-CMIC status.
- ▢[ ] Assess drone and robotics procurement for Autel or Unitree Robotics products currently deployed in operations, particularly in law enforcement, infrastructure inspection, or logistics.
- ▢[ ] Review pharmaceutical and biotech supply chain relationships for WuXi AppTec CDMO services, particularly if your organization holds federal contracts, grants, or loans subject to BIOSECURE Act provisions.
- ▢[ ] Note critical compliance deadlines: DoD direct procurement ban effective June 30, 2026; indirect procurement ban effective June 30, 2027. AI product prohibition already in effect (January 17, 2026).
- ▢[ ] Document risk acceptance decisions for any continued commercial relationships with listed entities. Formal risk memos with legal review create defensible records for future regulatory scrutiny.
References
[1] Holland & Knight, "Department of War Updates Section 1260H Chinese Military Companies List," July 2026. https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h
[2] WilmerHale, "Pentagon Adds 65 New Entities to the 1260H List of Chinese Military Companies," June 11, 2026. https://www.wilmerhale.com/en/insights/client-alerts/20260611-pentagon-adds-65-new-entities-to-the-1260h-list-of-chinese-military-companies
Visual Intelligence
Timeline (10 events)
Entity Graph (6 entities, 4 relationships)
---
Hunt Guide: Section 1260H Chinese Military Company Supply Chain and Technology Exposure Assessment
Attribution: Rules adapted, ported, or quoted from a public source retain that source's author (e.g. SigmaHQ / Florian Roth, Elastic, Emerging Threats, Abuse.ch, or the cited vendor/researcher) and carry an attribution credit. Rules without a credit were authored in-house by RedSheepSec. If you reuse a rule, preserve its stated attribution.
Hypothesis: If products, services, or network infrastructure from Section 1260H-designated Chinese Military Companies (CMCs) are present in our environment, we expect to observe network communications to associated domains/IP ranges, software artifacts from designated vendors (Alibaba Cloud, Baidu, Huawei, Hikvision, ZTE, DJI, Autel, Unitree), and procurement/asset inventory entries reflecting designated entity products in endpoint, network, cloud, and asset management data sources.
Intelligence Summary: The Department of Defense updated its Section 1260H Chinese Military Companies list on June 8, 2026, adding 65 entities including major technology companies such as Alibaba, Baidu, BYD, WuXi AppTec, Trina Solar, and Unitree Robotics. These designations are based on military-civil fusion affiliations with SASAC and MIIT, creating procurement restrictions, AI product prohibitions, and potential investment restrictions for organizations with DoD contracts. The expanded scope signals DoD is treating China's entire state-directed innovation ecosystem as a military risk, with direct procurement bans effective June 30, 2026 and indirect bans by June 30, 2027.
Confidence: Moderate | Priority: High
Scope
- Networks: All enterprise network segments including DMZ, server farms, OT/IoT networks (camera VLANs), cloud environments (AWS, Azure, Oracle Cloud), and remote/branch office networks. Special focus on medical facility networks where Hikvision cameras, IoT medical devices, or pharmaceutical supply chain integrations may exist.
- Timeframe: 90-day retrospective hunt window recommended (April 14 - July 14, 2026) to establish baseline communications and identify existing relationships with 1260H-designated entities. Ongoing monitoring should be implemented as persistent detections.
- Priority Systems: 1) Data center infrastructure (optical transceivers - Innolight), 2) Physical security systems (cameras - Hikvision/Dahua), 3) Cloud service integrations (Alibaba Cloud, Baidu AI), 4) Medical/pharmaceutical systems with WuXi AppTec or Novogene dependencies, 5) Drone/robotics platforms (DJI, Autel, Unitree), 6) Network infrastructure (Huawei, ZTE equipment), 7) Solar/energy systems (Trina Solar, JA Solar), 8) Fleet/battery systems (BYD, CALB, EVE Energy)
MITRE ATT&CK Techniques
T1195.001 — Supply Chain Compromise: Compromise Software Dependencies and Development Tools (Initial Access) [P2]
1260H-designated companies provide software, cloud services, AI products, optical transceivers, LiDAR sensors, and other technology components that could serve as supply chain vectors. Alibaba Cloud, Baidu AI services, and Zhongji Innolight transceivers embedded in data center infrastructure represent potential supply chain compromise vectors through firmware, SDK, or service-level access. The military-civil fusion strategy explicitly seeks to leverage commercial technology for military purposes, creating inherent dual-use risk in products from designated entities.
Splunk SPL:
index=corelight sourcetype=corelight_dns
| search query IN ("*.alibaba.com", "*.alibabacloud.com", "*.aliyun.com", "*.aliyuncs.com", "*.baidu.com", "*.baidubce.com", "*.bdstatic.com", "*.huawei.com", "*.huaweicloud.com", "*.hikvision.com", "*.zte.com.cn", "*.dji.com", "*.unitree.com", "*.autelrobotics.com", "*.robosense.cn", "*.innolight.com", "*.trinasolar.com", "*.jasolar.com", "*.wxapptech.com", "*.wuxiapptec.com", "*.novogene.com", "*.byd.com", "*.nio.com", "*.calb-tech.com", "*.evebattery.com", "*.tianma.com")
| stats count by query, id.orig_h, id.resp_h
| sort -count
| table query, id.orig_h, id.resp_h, count
Elastic KQL:
dns.question.name:(*alibaba.com OR *alibabacloud.com OR *aliyun.com OR *aliyuncs.com OR *baidu.com OR *baidubce.com OR *bdstatic.com OR *huawei.com OR *huaweicloud.com OR *hikvision.com OR *zte.com.cn OR *dji.com OR *unitree.com OR *autelrobotics.com OR *robosense.cn OR *innolight.com OR *trinasolar.com OR *jasolar.com OR *wxapptech.com OR *wuxiapptec.com OR *novogene.com OR *byd.com OR *nio.com)
Sigma Rule:
title: DNS Resolution to Section 1260H Designated Chinese Military Company Domains
id: a8c3d1e2-f456-4b89-9c12-3d4e5f6a7b8c
status: experimental
author: RedSheepSec
date: 2026/07/14
description: Detects DNS queries to domains associated with companies on the DoD Section 1260H Chinese Military Companies list, including Alibaba, Baidu, Huawei, Hikvision, and other designated entities.
references:
- https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h
- https://www.wilmerhale.com/en/insights/client-alerts/20260611-pentagon-adds-65-new-entities-to-the-1260h-list-of-chinese-military-companies
logsource:
category: dns
detection:
selection:
query|endswith:
- '.alibaba.com'
- '.alibabacloud.com'
- '.aliyun.com'
- '.aliyuncs.com'
- '.baidu.com'
- '.baidubce.com'
- '.bdstatic.com'
- '.huawei.com'
- '.huaweicloud.com'
- '.hikvision.com'
- '.zte.com.cn'
- '.dji.com'
- '.unitree.com'
- '.autelrobotics.com'
- '.robosense.cn'
- '.innolight.com'
- '.trinasolar.com'
- '.jasolar.com'
- '.wxapptech.com'
- '.wuxiapptec.com'
- '.novogene.com'
- '.byd.com'
- '.nio.com'
condition: selection
falsepositives:
- Legitimate business use of services from designated companies in non-restricted contexts
- Research or compliance review activities
level: medium
tags:
- attack.initial_access
- attack.t1195.001
This query identifies network communications to 1260H-designated entity domains. High false positive rate expected in environments with legitimate business relationships with these companies. Use results to build an exposure inventory rather than as direct threat indicators. Tune by excluding known-approved services after compliance review. Cross-reference with DoD contract status to prioritize remediation.
T1195.002 — Supply Chain Compromise: Compromise Software Supply Chain (Initial Access) [P2]
AI products and cloud services from 1260H-designated entities (particularly Alibaba Cloud and Baidu AI) may be embedded in software supply chains through SDKs, APIs, or cloud service dependencies. Section 1532 of the FY2026 NDAA prohibits use of AI products from 1260H entities in DoD contract performance. This technique covers detection of software components, libraries, or cloud service integrations from designated entities.
Splunk SPL:
index=sysmon sourcetype=XmlWinEventLog EventCode=1
| search (CommandLine="*alibaba*" OR CommandLine="*aliyun*" OR CommandLine="*baidu*" OR CommandLine="*huawei*" OR CommandLine="*hikvision*" OR CommandLine="*zte*" OR CommandLine="*dji*" OR CommandLine="*unitree*" OR CommandLine="*autel*" OR CommandLine="*robosense*" OR CommandLine="*innolight*" OR CommandLine="*wuxi*" OR CommandLine="*novogene*" OR ParentCommandLine="*alibaba*" OR ParentCommandLine="*aliyun*" OR ParentCommandLine="*baidu*" OR ParentCommandLine="*huawei*")
| stats count by Computer, User, Image, CommandLine, ParentImage
| sort -count
Elastic KQL:
process.command_line:(*alibaba* OR *aliyun* OR *baidu* OR *huawei* OR *hikvision* OR *zte* OR *dji* OR *unitree* OR *autel* OR *robosense* OR *innolight* OR *wuxi* OR *novogene*) AND event.code:"1"
Sigma Rule:
title: Process Execution Referencing Section 1260H Designated Entity Software
id: b9d4e2f3-g567-5c9a-ad23-4e5f6g7h8i9j
status: experimental
author: RedSheepSec
date: 2026/07/14
description: Detects process execution with command lines referencing software or services from Section 1260H designated Chinese Military Companies, which may indicate prohibited AI product usage or supply chain dependencies.
references:
- https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h
logsource:
category: process_creation
product: windows
detection:
selection_cmdline:
CommandLine|contains:
- 'alibaba'
- 'aliyun'
- 'baidu'
- 'huawei'
- 'hikvision'
- 'zte'
- 'unitree'
- 'autelrobotics'
- 'robosense'
- 'innolight'
- 'wuxiapptec'
- 'novogene'
selection_image:
Image|contains:
- 'alibaba'
- 'aliyun'
- 'baidu'
- 'huawei'
- 'hikvision'
condition: selection_cmdline or selection_image
falsepositives:
- Legitimate approved software from these vendors
- Security research or compliance scanning
level: medium
tags:
- attack.initial_access
- attack.t1195.002
Focus on identifying embedded SDKs, libraries, and cloud service clients. Cross-reference findings with software inventory and procurement records. Priority for systems supporting DoD contracts where AI product prohibition is already in effect.
T1199 — Trusted Relationship (Initial Access) [P2]
1260H-designated entities that serve as cloud providers, CDMO partners, or technology suppliers maintain trusted relationships that could be exploited for access. Alibaba Cloud, WuXi AppTec CDMO services, and Zhongji Innolight hardware in network infrastructure represent trusted third-party access vectors. This technique maps to the supply chain risk where a trusted vendor relationship with a designated entity creates potential access pathways.
Splunk SPL:
index=cloud-azure sourcetype="azure:monitor:aad"
| search (app_displayName="*alibaba*" OR app_displayName="*baidu*" OR app_displayName="*huawei*" OR app_displayName="*hikvision*" OR app_displayName="*zte*" OR resourceDisplayName="*alibaba*" OR resourceDisplayName="*baidu*" OR resourceDisplayName="*huawei*")
| stats count by identity, app_displayName, resourceDisplayName, src_ip
| sort -count
Elastic KQL:
azure.auditlogs.properties.target_resources.display_name:(*alibaba* OR *baidu* OR *huawei* OR *hikvision* OR *zte*) OR azure.signinlogs.properties.app_display_name:(*alibaba* OR *baidu* OR *huawei*)
Review Azure AD / Entra ID for any application registrations, service principals, or OAuth grants associated with 1260H-designated companies. Also review VPN and remote access logs for connections originating from designated entity IP ranges.
T1590 — Gather Victim Network Information (Reconnaissance) [P2]
Network infrastructure components from designated entities (Huawei, ZTE network equipment; Hikvision cameras; Zhongji Innolight transceivers) provide potential reconnaissance vectors if these devices have management plane access or telemetry capabilities that report back to vendor infrastructure. Camera systems from Hikvision in particular have documented callback behaviors.
Splunk SPL:
index=corelight sourcetype=corelight_conn
| lookup dnslookup clientip AS id.resp_h OUTPUT clienthost AS resp_hostname
| search (resp_hostname="*hikvision*" OR resp_hostname="*huawei*" OR resp_hostname="*zte*" OR resp_hostname="*dji*" OR resp_hostname="*dahua*")
| stats count values(id.resp_p) as dest_ports dc(id.orig_h) as unique_sources by resp_hostname
| sort -count
Elastic KQL:
destination.domain:(*hikvision* OR *huawei* OR *zte* OR *dji* OR *dahua*) AND event.dataset:"zeek.conn"
Focus on outbound connections from IoT/OT devices (cameras, network equipment) to vendor cloud infrastructure. Hikvision cameras are known to make management-plane callbacks. Inventory all Hikvision, Huawei, and ZTE network equipment and review their external communication patterns.
T1592.002 — Gather Victim Host Information: Software (Reconnaissance) [P2]
Software from 1260H-designated entities installed on endpoints provides asset inventory exposure. This technique focuses on identifying installed software from Alibaba, Baidu, Huawei, Hikvision, ZTE, DJI, Autel, and other designated entities across the endpoint fleet to assess supply chain exposure.
Splunk SPL:
index=winconfig sourcetype=InstalledSoftware
| search (DisplayName="*Alibaba*" OR DisplayName="*Baidu*" OR DisplayName="*Huawei*" OR DisplayName="*Hikvision*" OR DisplayName="*ZTE*" OR DisplayName="*DJI*" OR DisplayName="*Autel*" OR DisplayName="*Unitree*" OR DisplayName="*Tencent*" OR DisplayName="*WuXi*" OR DisplayName="*Novogene*" OR Publisher="*Alibaba*" OR Publisher="*Baidu*" OR Publisher="*Huawei*" OR Publisher="*Hikvision*" OR Publisher="*ZTE*" OR Publisher="*DJI*")
| stats count by host, DisplayName, Publisher, DisplayVersion
| sort -count
Elastic KQL:
winlog.event_data.DisplayName:(*Alibaba* OR *Baidu* OR *Huawei* OR *Hikvision* OR *ZTE* OR *DJI* OR *Autel* OR *Unitree* OR *WuXi* OR *Novogene*)
Sigma Rule:
title: Installed Software from Section 1260H Designated Chinese Military Companies
id: c0e5f3g4-h678-6dab-be34-5f6g7h8i9j0k
status: experimental
author: RedSheepSec
date: 2026/07/14
description: Detects installed software from companies designated on the DoD Section 1260H Chinese Military Companies list. Presence indicates supply chain exposure requiring compliance review.
references:
- https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h
- https://www.wilmerhale.com/en/insights/client-alerts/20260611-pentagon-adds-65-new-entities-to-the-1260h-list-of-chinese-military-companies
logsource:
product: windows
category: registry_set
detection:
selection:
TargetObject|contains:
- '\Microsoft\Windows\CurrentVersion\Uninstall\'
Details|contains:
- 'Alibaba'
- 'Baidu'
- 'Huawei'
- 'Hikvision'
- 'ZTE'
- 'DJI'
- 'Autel'
- 'Unitree'
- 'WuXi'
- 'Novogene'
condition: selection
falsepositives:
- Approved software installations in environments with documented exceptions
level: medium
tags:
- attack.reconnaissance
- attack.t1592.002
Use software inventory data to build a comprehensive exposure report. Cross-reference with DoD contract systems to identify compliance gaps under Section 1532 (AI product prohibition) and Section 805 (procurement restrictions).
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control) [P2]
IoT devices and software from 1260H-designated entities may communicate with vendor cloud infrastructure over HTTP/HTTPS. Hikvision cameras, Huawei equipment, and DJI drones are documented to establish persistent outbound HTTPS connections to vendor infrastructure for management, telemetry, and firmware updates. These connections represent potential data exfiltration or command-and-control channels.
Splunk SPL:
index=corelight sourcetype=corelight_ssl
| search (server_name="*hikvision*" OR server_name="*huawei*" OR server_name="*huaweicloud*" OR server_name="*zte*" OR server_name="*dji*" OR server_name="*alibaba*" OR server_name="*aliyun*" OR server_name="*baidu*")
| stats count values(id.resp_p) as dest_ports dc(id.orig_h) as unique_sources earliest(_time) as first_seen latest(_time) as last_seen by server_name
| eval first_seen=strftime(first_seen,"%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen,"%Y-%m-%d %H:%M:%S")
| sort -count
| table server_name, unique_sources, dest_ports, count, first_seen, last_seen
Elastic KQL:
tls.client.server_name:(*hikvision* OR *huawei* OR *huaweicloud* OR *zte* OR *dji* OR *alibaba* OR *aliyun* OR *baidu*)
Focus on persistent outbound TLS connections from devices that should not need internet access (cameras, industrial equipment). Review certificate details for Chinese CAs. Consider blocking at the firewall after compliance review.
T1078.004 — Valid Accounts: Cloud Accounts (Persistence) [P2]
Organizations using Alibaba Cloud or Baidu cloud services may have cloud accounts, API keys, or service integrations that provide persistent access channels to designated entity infrastructure. Section 1532 compliance requires identifying and remediating these integrations for DoD contract work.
Splunk SPL:
index=cloud-aws sourcetype=aws:cloudtrail
| search (userAgent="*alibaba*" OR userAgent="*aliyun*" OR userAgent="*baidu*" OR sourceIPAddress="*alibaba*" OR sourceIPAddress="*aliyun*")
| stats count by userIdentity.arn, userAgent, sourceIPAddress, eventName
| sort -count
Elastic KQL:
cloud.provider:"aws" AND (user_agent.original:(*alibaba* OR *aliyun* OR *baidu*) OR source.ip:(*alibaba* OR *aliyun*))
Review AWS, Azure, and Oracle cloud environments for any cross-cloud integrations with Alibaba Cloud or Baidu services. Check for API keys, service accounts, or data pipelines that route through designated entity infrastructure.
T1556 — Modify Authentication Process (Credential Access) [P3]
Network equipment from Huawei and ZTE that provides authentication services (RADIUS, TACACS+, 802.1X) could theoretically modify authentication processes through firmware-level backdoors. This technique covers monitoring authentication infrastructure supplied by designated entities for anomalous behavior.
Splunk SPL:
index=corelight sourcetype=corelight_radius
| stats count by id.orig_h, id.resp_h, result, username
| where result="failed"
| sort -count
| head 50
| lookup dnslookup clientip AS id.resp_h OUTPUT clienthost AS radius_server
| table id.orig_h, id.resp_h, radius_server, username, result, count
Elastic KQL:
event.dataset:"zeek.radius" AND radius.result:"reject"
Identify RADIUS/TACACS+ servers running on Huawei or ZTE hardware. Monitor for authentication anomalies that could indicate firmware-level manipulation. Low probability but high impact scenario.
T1542.001 — Pre-OS Boot: System Firmware (Persistence) [P3]
Hardware from 1260H-designated entities (Huawei network equipment, ZTE infrastructure, Hikvision cameras, Zhongji Innolight optical transceivers) could contain firmware-level implants. This is a strategic concern given the military-civil fusion doctrine. Detection focuses on identifying firmware update activities and anomalous outbound communication from these devices.
Splunk SPL:
index=corelight sourcetype=corelight_http
| search (host="*hikvision*" OR host="*huawei*" OR host="*zte*" OR uri="*firmware*" OR uri="*upgrade*" OR uri="*update*")
| search (uri="*.bin" OR uri="*.img" OR uri="*.fw" OR uri="*.rom")
| stats count by id.orig_h, id.resp_h, host, uri, method
| sort -count
Elastic KQL:
url.path:(*firmware* OR *upgrade* OR *.bin OR *.fw) AND destination.domain:(*hikvision* OR *huawei* OR *zte*)
Focus on firmware download activities from vendor infrastructure. Validate firmware integrity using vendor-provided hashes. Consider air-gapping firmware update processes for network infrastructure from designated entities.
T1005 — Data from Local System (Collection) [P2]
Surveillance equipment (Hikvision cameras) and IoT devices from designated entities may collect and transmit data from the local environment. Camera feeds, audio capture, and sensor data from 1260H-designated equipment represent collection vectors. This is particularly relevant for medical facilities where patient data may be captured.
Splunk SPL:
index=cameras sourcetype IN ("avigilon:daemon", "exacq:log")
| search (vendor="*Hikvision*" OR vendor="*Dahua*" OR camera_name="*Hikvision*" OR camera_name="*Dahua*")
| stats count by host, vendor, camera_name, dest_ip
| sort -count
Elastic KQL:
event.module:"cameras" AND (observer.vendor:(*Hikvision* OR *Dahua*) OR observer.name:(*Hikvision* OR *Dahua*))
Review camera system inventory for Hikvision and Dahua devices. These are both on the 1260H list and the FCC Covered Equipment list. Prioritize removal from sensitive areas including medical treatment facilities and classified spaces.
Indicators of Compromise
| Type | Value | Context |
|---|---|---|
| domain | alibaba.com |
Alibaba Group - Newly designated Section 1260H entity (June 2026). Parent domain for Alibaba services. |
| domain | alibabacloud.com |
Alibaba Cloud - Cloud services division of 1260H-designated Alibaba Group. AI product prohibition applies under Section 1532. |
| domain | aliyun.com |
Alibaba Cloud (Chinese-market domain) - Cloud platform of 1260H-designated Alibaba Group. |
| domain | baidu.com |
Baidu - Newly designated Section 1260H entity (June 2026). Operates search engine, autonomous driving (Apollo), and AI LLM (Ernie). |
| domain | huawei.com |
Huawei Technologies - Longstanding 1260H designee. Also on BIS Entity List and FCC Covered Equipment list. |
| domain | hikvision.com |
Hangzhou Hikvision Digital Technology - Longstanding 1260H designee. World's largest surveillance camera manufacturer. Also on FCC Covered Equipment list. |
| domain | zte.com.cn |
ZTE Corporation - Longstanding 1260H designee. Major telecommunications equipment manufacturer. |
| domain | dji.com |
DJI - Previously designated drone manufacturer. Market-dominant consumer/commercial drone platform. |
| domain | unitree.com |
Hangzhou Yushu Technology (Unitree Robotics) - Newly designated Section 1260H entity (June 2026). Quadruped robot manufacturer. |
| domain | autelrobotics.com |
Autel Intelligent Technology Corp - Newly designated Section 1260H entity (June 2026). Major drone manufacturer competing with DJI. |
| domain | robosense.cn |
Robosense Technology - Newly designated Section 1260H entity (June 2026). LiDAR sensor manufacturer for autonomous vehicles. |
| domain | innolight.com |
Zhongji Innolight - Newly designated Section 1260H entity (June 2026). Major optical transceiver manufacturer reportedly supplying hyperscale data centers. |
| domain | trinasolar.com |
Trina Solar - Newly designated Section 1260H entity (June 2026). One of the world's largest solar panel manufacturers. |
| domain | jasolar.com |
JA Solar Technology - Newly designated Section 1260H entity (June 2026). Major solar panel manufacturer. |
| domain | wuxiapptec.com |
WuXi AppTec Co. Ltd. - Newly designated Section 1260H entity (June 2026). Major CDMO with extensive U.S. biotech/pharma partnerships. Subject to BIOSECURE Act restrictions. |
| domain | novogene.com |
Novogene Co. Ltd. - Newly designated Section 1260H entity (June 2026). Genomic sequencing services provider. |
| domain | byd.com |
BYD - Newly designated Section 1260H entity (June 2026). World's largest EV manufacturer by unit sales. Battery technology in global supply chains. |
| domain | nio.com |
NIO - Newly designated Section 1260H entity (June 2026). Chinese EV manufacturer. |
| domain | tianma.com |
Tianma Microelectronics - Newly designated Section 1260H entity (June 2026). Display panel manufacturer for smartphones, automotive, and industrial equipment. |
IOC Sweep Queries (Splunk):
index=corelight sourcetype=corelight_dns query="*alibaba.com" OR query="*alibabacloud.com" OR query="*aliyun.com" OR query="*aliyuncs.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*alibabacloud.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*aliyun.com" OR query="*aliyuncs.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*baidu.com" OR query="*baidubce.com" OR query="*bdstatic.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*huawei.com" OR query="*huaweicloud.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*hikvision.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*zte.com.cn" OR query="*zte.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*dji.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*unitree.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*autelrobotics.com" OR query="*autel.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*robosense.cn" OR query="*robosense.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*innolight.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*trinasolar.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*jasolar.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*wuxiapptec.com" OR query="*wxapptech.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*novogene.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*byd.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*nio.com" | stats count by query, id.orig_h | sort -count
index=corelight sourcetype=corelight_dns query="*tianma.com" | stats count by query, id.orig_h | sort -count
YARA Rules
CMC_1260H_Software_Artifacts — Detects file artifacts (installers, libraries, configuration files) from Section 1260H designated Chinese Military Company software products. Identifies Alibaba Cloud, Baidu, Huawei, Hikvision, and DJI software components on endpoints.
rule CMC_1260H_Software_Artifacts
{
meta:
description = "Detects software artifacts from Section 1260H designated Chinese Military Companies"
author = "RedSheepSec"
date = "2026-07-14"
reference = "https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h"
severity = "medium"
strings:
$alibaba1 = "Alibaba Cloud" ascii wide nocase
$alibaba2 = "AlibabaCloud" ascii wide nocase
$alibaba3 = "Aliyun" ascii wide nocase
$alibaba4 = "alibaba-inc.com" ascii wide nocase
$baidu1 = "Baidu, Inc" ascii wide nocase
$baidu2 = "BaiduNetdisk" ascii wide nocase
$baidu3 = "BaiduProtect" ascii wide nocase
$huawei1 = "Huawei Technologies" ascii wide nocase
$huawei2 = "HuaweiCloud" ascii wide nocase
$hikvision1 = "Hangzhou Hikvision" ascii wide nocase
$hikvision2 = "HIKVISION" ascii wide
$hikvision3 = "iVMS-4200" ascii wide nocase
$zte1 = "ZTE Corporation" ascii wide nocase
$dji1 = "DJI Technology" ascii wide nocase
$dji2 = "DJI-Innovations" ascii wide nocase
$unitree1 = "Unitree Robotics" ascii wide nocase
$unitree2 = "unitree" ascii wide nocase
$autel1 = "Autel Robotics" ascii wide nocase
$autel2 = "AutelRobotics" ascii wide nocase
condition:
any of them
}
CMC_Hikvision_Firmware — Detects Hikvision camera firmware files and management software artifacts. Hikvision is a longstanding Section 1260H designee and FCC Covered Equipment entity.
rule CMC_Hikvision_Firmware
{
meta:
description = "Detects Hikvision camera firmware and management software"
author = "RedSheepSec"
date = "2026-07-14"
reference = "https://www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h"
severity = "high"
strings:
$magic1 = { 48 49 4B 56 49 53 49 4F 4E } // HIKVISION
$str1 = "Hikvision Digital Technology" ascii wide
$str2 = "ISAPI" ascii wide
$str3 = "hikconnect" ascii wide nocase
$str4 = "iVMS" ascii wide
$str5 = "Hik-Connect" ascii wide
$str6 = "HikCentral" ascii wide
$cert1 = "Hangzhou Hikvision Digital Technology Co" ascii wide
condition:
($magic1 and any of ($str*)) or ($cert1 and any of ($str*))
}
Suricata Rules
SID 2026001 — Detects DNS queries to Alibaba Cloud infrastructure domains from internal hosts, indicating potential use of 1260H-designated cloud services.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - Alibaba Cloud"; dns.query; content:"alibabacloud.com"; nocase; sid:2026001; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation; reference:url,www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h;)
SID 2026002 — Detects DNS queries to Baidu infrastructure domains from internal hosts, indicating potential use of 1260H-designated AI/cloud services.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - Baidu"; dns.query; content:"baidu.com"; nocase; sid:2026002; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation; reference:url,www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h;)
SID 2026003 — Detects DNS queries to Huawei Cloud infrastructure from internal hosts, indicating potential use of services from longstanding 1260H-designated entity.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - Huawei Cloud"; dns.query; content:"huaweicloud.com"; nocase; sid:2026003; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation; reference:url,www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h;)
SID 2026004 — Detects DNS queries to Hikvision domains from internal hosts, indicating Hikvision camera management or telemetry communications.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - Hikvision"; dns.query; content:"hikvision.com"; nocase; sid:2026004; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation; reference:url,www.hklaw.com/en/insights/publications/2026/07/department-of-war-updates-section-1260h;)
SID 2026005 — Detects TLS connections to Aliyun/Alibaba Cloud services, indicating active cloud service usage from 1260H-designated entity.
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"POLICY TLS connection to 1260H designated entity - Aliyun/Alibaba"; tls.sni; content:"aliyuncs.com"; nocase; sid:2026005; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation;)
SID 2026006 — Detects DNS queries to DJI drone management infrastructure from internal hosts.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - DJI Drones"; dns.query; content:"dji.com"; nocase; sid:2026006; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation;)
SID 2026007 — Detects DNS queries to Unitree Robotics domains, indicating communication with newly designated 1260H entity robotics infrastructure.
alert dns $HOME_NET any -> any 53 (msg:"POLICY DNS query to 1260H designated entity - Unitree Robotics"; dns.query; content:"unitree.com"; nocase; sid:2026007; rev:1; metadata:created_at 2026_07_14, updated_at 2026_07_14; classtype:policy-violation;)
Data Source Requirements
| Source | Required For | Notes |
|---|---|---|
| Corelight/Zeek DNS Logs | T1195.001, T1590, T1071.001 | index=corelight sourcetype=corelight_dns — Required for domain-based detection of communications to 1260H-designated entity infrastructure. Ensure DNS logging captures all internal DNS queries. |
| Corelight/Zeek SSL/TLS Logs | T1071.001, T1542.001 | index=corelight sourcetype=corelight_ssl — Required for TLS SNI-based detection of encrypted communications to designated entity services. |
| Corelight/Zeek HTTP Logs | T1542.001, T1071.001 | index=corelight sourcetype=corelight_http — Required for firmware download detection and HTTP-based communication identification. |
| Corelight/Zeek Connection Logs | T1590, T1071.001 | index=corelight sourcetype=corelight_conn — Required for connection-level analysis of communications to designated entity IP ranges. |
| Sysmon (Windows Process Creation) | T1195.002 | index=sysmon sourcetype=XmlWinEventLog EventCode=1 — Required for detecting process execution referencing 1260H-designated entity software. |
| Windows Software Inventory | T1592.002 | index=winconfig sourcetype=InstalledSoftware — Required for identifying installed software from designated entities. |
| Azure AD / Entra ID Logs | T1199, T1078.004 | index=cloud-azure sourcetype=azure:monitor:aad — Required for identifying cloud application integrations with designated entity services. |
| AWS CloudTrail | T1078.004 | index=cloud-aws sourcetype=aws:cloudtrail — Required for identifying AWS API calls referencing designated entity user agents or source IPs. |
| Camera System Logs | T1005 | index=cameras sourcetype IN (avigilon:daemon, exacq:log) — Required for identifying Hikvision/Dahua camera systems. May need additional inventory sources for complete coverage. |
| Palo Alto Firewall Logs | T1071.001, T1590 | index=firewall-pan sourcetype=pan:traffic:aggregated — Required for firewall-level visibility into outbound connections to designated entity infrastructure. |
| CrowdStrike EDR | T1195.002, T1592.002 | index=crowdstrike — Can supplement Sysmon for software and process detection on endpoints with CrowdStrike coverage. |
| RADIUS Authentication Logs | T1556 | index=corelight sourcetype=corelight_radius — Required for monitoring authentication infrastructure on Huawei/ZTE equipment. |
Recommendations
- Deploy all Appendix B DNS, TLS, and process-level detections across Splunk and Elastic instances as persistent saved searches with alerting enabled for any hits on 1260H-designated entity domains.
- Conduct immediate software inventory audit using the winconfig/InstalledSoftware query to identify all installed software from designated entities, particularly on systems supporting DoD contracts subject to Section 1532 AI product prohibition (already in effect since January 17, 2026).
- Inventory all Hikvision and Dahua physical security cameras across all facilities. These are on both the 1260H list and the FCC Covered Equipment list. Prioritize replacement planning for cameras in sensitive areas including medical treatment facilities, server rooms, and command spaces.
- Review Azure AD/Entra ID and AWS environments for any application registrations, OAuth grants, API keys, or service principals associated with Alibaba Cloud or Baidu services. Revoke unauthorized integrations immediately.
- Assess data center hardware inventory for Zhongji Innolight optical transceivers. If present, document as supply chain exposure and include in next hardware refresh planning cycle.
- Coordinate with procurement/contracting to implement screening of the full 188-entity 1260H list (including 48 subsidiaries) in vendor vetting workflows before the June 30, 2026 direct procurement ban deadline.
- Engage pharmaceutical/biotech supply chain stakeholders to assess WuXi AppTec CDMO dependencies, particularly for contracts, grants, or activities subject to BIOSECURE Act restrictions.
- Deploy Suricata rules on network sensors to create persistent alerting for DNS queries and TLS connections to designated entity infrastructure.
- Create a formal risk acceptance memo with legal review for any continued commercial relationships with 1260H-designated entities, documenting the business justification and compliance posture.
- Establish quarterly re-assessment cadence aligned with expected annual 1260H list updates through December 31, 2030.