ARMY DIR 2025-26 governs supply chain risk management policy and responsibilities for Army weapon systems.
View ARMY DIR 2025-26 on armypubs.army.mil
The directive defines SCRM as identifying, assessing, and mitigating supply chain threats, vulnerabilities, and disruptions throughout a weapon system’s life cycle. It addresses funding, security protection, commercial tools, sustainment reviews, and cyber-SCRM compliance.
Applies to: The provisions of this directive apply to the Regular Army, Army National Guard/Army National Guard of the United States, and U.S. Army Reserve.
SCRM is the process for managing risk by identifying, assessing, and mitigating threats, vulnerabilities, and disruptions to the Department of War supply chain, from beginning to end, to ensure mission effectiveness. (paragraph 4)
SCRM will be conducted on systems throughout their life cycle. (paragraph 4)
Organizations will plan, program, budget, and execute funding for SCRM by balancing risk management with mitigations to ensure affordability. (paragraph 4)
System-specific supply chain vulnerabilities and risks will be protected at the appropriate security level determined by the organizations security manager and security classification guide. (paragraph 4)
Organizations conducting SCRM will leverage commercially available tools, standards, and best practices. (paragraph 4)