Wednesday, October 7, 2026

The Supply Chain Question: Made in America Does Not Necessarily Mean Made Entirely in America

 By Staff

There is another question that deserves to be separated from the broader arguments about Dominion, Fox and the 2020 election. Where, exactly, are the individual components inside voting systems manufactured?

This is not a hypothetical question.

Americans sometimes hear that voting machines are "American made" and reasonably assume that this means the chips, processors, memory, firmware components and other critical electronics inside those machines are also manufactured in the United States.

The federal record is more complicated.

In congressional testimony concerning election equipment, industry representatives acknowledged that certain components used in voting equipment are manufactured outside the United States. One witness testified that "most of the voting equipment does use sources from outside the country," while discussing the possibility of reshoring more of the supply chain. The witness also distinguished between requiring U.S. assembly and completely reshoring the components themselves.

That distinction matters.

A voting system can be assembled, configured and tested in the United States while still containing commercially available electronic components manufactured elsewhere.

Nor does federal "Buy American" law automatically mean that every component inside a government purchased electronic product must be American made. Federal acquisition rules define a "domestic end product" using a manufacturing and domestic content test, while also providing specific treatment for commercially available off the shelf products. The legal definition of a U.S. made end product and the country of origin of every individual component are therefore not necessarily the same thing.

This does not establish that any foreign made component in a voting machine is compromised.

It does establish something much narrower and more important.

"American made voting machine" is not necessarily synonymous with "every critical electronic component was manufactured in America."

That creates a legitimate supply chain security question.

The question is not whether a chip manufactured overseas is automatically malicious. That would be an unsupported conclusion.

The question is whether the election security system has adequate safeguards against the possibility that a critical component, firmware image or other piece of the supply chain could be counterfeit, tampered with or otherwise compromised before it reaches the United States.

The federal government itself recognizes supply chain security as an election security issue. The Cybersecurity and Infrastructure Security Agency has identified risks involving election equipment supply chains and recommended measures including identifying supply chain risks, protecting against counterfeit or tampered components, and maintaining the integrity of third party hardware and firmware.

That concern also helps explain why certification cannot reasonably be treated as synonymous with perfection.

The Election Assistance Commission's certification program tests specific voting system configurations against applicable federal standards through accredited laboratories. Its Quality Monitoring Program is designed to help ensure that the systems certified by the EAC are the same systems sold by manufacturers and includes fielded system reviews, anomaly reporting and manufacturing site visits.

Those are meaningful safeguards.

But certification primarily establishes that a particular system configuration has undergone the prescribed testing. It does not mean that every semiconductor inside that system has been independently manufactured in the United States or that every possible hardware level supply chain attack has been mathematically eliminated.

That distinction is especially important when discussing processors, boot components, memory and other electronics that sit beneath the voting application itself.

A malicious change to ordinary application software is one problem.

A malicious modification to the underlying hardware or firmware would be a different class of problem.

That does not mean such a modification occurred.

There is no evidence presented here that a foreign manufactured semiconductor inside a Dominion system was deliberately altered to manipulate the 2020 election.

That claim would require evidence.

It would require identifying the specific machine and component, establishing the component's provenance, demonstrating the alleged modification, showing how the modification affected the system and then connecting that mechanism to actual votes.

Without that chain of evidence, the allegation remains speculation.

But the opposite claim that certification makes such questions illegitimate is also too broad.

Government testing laboratories can miss software defects. Certified systems can contain coding errors. Manufacturers can issue corrections. Supply chains can contain vulnerabilities. The EAC's own investigation of the Williamson County, Tennessee incident demonstrates that certification does not make software infallible.

The appropriate conclusion is therefore neither panic nor complacency.

It is verification.

If critical election components are manufactured overseas, Americans should be able to ask reasonable questions about their provenance and security.

Where was the component manufactured?

Who manufactured it?

Who supplied it?

What firmware does it contain?

Was the component inspected or authenticated when it entered the United States?

Was the production version compared with the tested version?

Were the relevant hashes or signatures verified?

Who had physical access to it?

And most importantly, what independent evidence exists outside the machine itself that would reveal an attempt to alter votes?

Those are not conspiracy theory questions.

They are ordinary supply chain-security questions.

But they must remain questions until the evidence answers them.

The same evidentiary standard that should be applied to Fox, Dominion, election officials and government agencies must also be applied here.

A foreign component is not proof of foreign control.

A vulnerability is not proof of exploitation.

A software defect is not proof of election fraud.

And American assembly is not proof that every component originated in America.

The responsible position lies between those extremes.

Don't confuse foreign manufacture with compromise. But don't confuse American assembly with complete supply chain independence, either.

The same principle applies to the hardware supply chain. The existence of foreign manufactured components does not prove that an election was compromised. But the fact that a machine is assembled and certified in the United States does not, by itself, establish that every component inside it was manufactured domestically or that every possible supply chain risk has been eliminated. Those are questions that should be answered with component level documentation and testing, not assumptions.
Sources:

Election system certification

  • U.S. Election Assistance Commission — Certified Voting Systems

Shows the systems that have received EAC certification, the manufacturer, testing standard, and certification date. EAC: Certified Voting Systems citeturn0search0

  • U.S. Election Assistance Commission — System Certification Process

Explains that the EAC certification program tests and certifies hardware and software through accredited testing laboratories. EAC: System Certification Process citeturn0search6

  • U.S. Election Assistance Commission — Voting Systems Under Test

Useful for showing that certification applies to particular systems/configurations undergoing testing against specified federal standards. EAC: Voting Systems Under Test citeturn0search8

  • EAC — Are Voting Systems Secure?

Discusses security controls including testing, tamper-evident seals, access controls and audits. EAC: Are Voting Systems Secure? citeturn0search11

Foreign components / supply-chain issue

This is probably the most important source for the point you're making.

  • Congressional hearing — election equipment manufacturing/supply chain

This is the congressional record containing testimony discussing the fact that voting equipment can contain components manufactured outside the United States and the distinction between U.S. assembly and completely domestic sourcing. Congressional Record: Election Equipment Supply Chain Hearing

I'd be careful with the article's wording here. The source supports foreign-sourced components in voting equipment; it does not by itself establish that a particular Dominion processor came from China or Taiwan.

Federal “Buy American” rules

  • Federal Acquisition Regulation — FAR 25.101

This is the primary federal regulation explaining the definition of a domestic end product. It says manufactured end products generally have a U.S.-manufacturing requirement plus a domestic-content test, while also addressing exceptions such as COTS products. FAR 25.101 — General citeturn0search2

  • FAR 25.001 — General

Particularly useful because it explicitly distinguishes the test for the country of origin of an end product from the origin of its components. FAR 25.001 — General citeturn0search12

That is the source I'd use to support the article's important distinction:

U.S.-manufactured end product ≠ necessarily every component manufactured in the United States.

Election hardware supply-chain security

  • CISA — Supply Chain Risks to Election Infrastructure

This is particularly strong for your article because it explicitly says election systems contain hardware components that are part of a complex, globally connected supply chain. CISA recommends identifying supply-chain touchpoints, prioritizing critical hardware, protecting against counterfeiting/tampering, physically inspecting components, and continuously checking the integrity of third-party firmware. CISA: Supply Chain Risks to Election Infrastructure CCISA

  • CISA — Supply Chain Risks to Election Infrastructure infographic page

The landing page for the CISA publication. CISA: Election Infrastructure Supply Chain Risk Resources CCISA

  1. EAC — Certified Voting Systems EAC Certified Voting Systems

  2. EAC — System Certification Process EAC System Certification Process

  3. CISA — Supply Chain Risks to Election Infrastructure CISA Supply Chain Risks

  4. Congressional hearing on election-equipment manufacturing/supply chain Congressional Hearing / Election Equipment Supply Chain

FAR 25.101 as the legal source for the distinction between a domestically manufactured end product and the origin of individual components. FAR 25.101




No comments:

Post a Comment

The Supply Chain Question: Made in America Does Not Necessarily Mean Made Entirely in America

 By Staff There is another question that deserves to be separated from the broader arguments about Dominion, Fox and the 2020 election. Wher...