TRAFEED

SpaceX's NCNT Supply Chain and Nationality Demands: Where Contract Terms End and Law Begins

Published2026-08-07濱本 隆太

According to Nikkei Asia, SpaceX is asking suppliers worldwide to keep Chinese nationals off lines making its products and to replace Chinese-made equipment, while building an NCNT (non-China, non-Taiwan) supply chain. I look at the deemed-export rules underneath the demand, the US enforcement record against blanket nationality screens, and what a Japanese supplier should actually check when the request lands.

SpaceX's NCNT Supply Chain and Nationality Demands: Where Contract Terms End and Law Begins
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

What would you do if a customer told you to remove people of a particular nationality from your factory floor? You have employment rules, you have anti-discrimination law, and you would very much like to keep the order. That squeeze is landing right now on companies making parts for space and defense programs.

Nikkei Asia reported exclusively that SpaceX is asking suppliers around the world not to place Chinese nationals at facilities producing SpaceX products1. On equipment, suppliers have reportedly been asked to replace devices made by Chinese companies, including surveillance cameras and network gear from firms such as Hikvision and TP-Link, even where the plant sits outside China. Audit teams are said to verify this on site, and some suppliers reported being warned that future orders would be difficult if they did not comply. Alongside this, SpaceX is reportedly building an NCNT (Non-China, Non-Taiwan) supply chain, spreading disruption risk tied to conditions around the Taiwan Strait.

Let me state my position up front. I am not going to write about people of any nationality as though they were a hazard. That is not this article. What I want to lay out is which rules this demand grows out of, and where legal obligation ends and commercial terms begin. Blur those two and a Japanese company walks into a different body of law. If you want to start by taking stock of your own transactions and technology transfers, the free export control and economic security self-check is a reasonable entry point.

First: this is reporting, not an announcement

Let me fix the evidentiary status before anything else.

This is not an official SpaceX statement. It is Nikkei Asia's exclusive, built on interviews with multiple suppliers and industry figures, and no official comment or denial from SpaceX had been confirmed at the time of publication1. Taiwanese suppliers are reportedly feeling the effects as well, with several cases of pressure to adjust staffing and equipment.

When you circulate this internally, do not let that distinction blur. Not "SpaceX has decided," but "it has been reported that." The difference shows up later. It also changes how the conversation goes when you go back to your customer to verify. Opening from reporting invites an answer; opening as though it were settled fact invites a wall.

The backdrop cited throughout is that SpaceX products are deeply involved in NASA crewed spaceflight and US national security missions. Elon Musk said in 2018 that SpaceX's top priority is and will remain supporting NASA crewed spaceflight and national security missions. The reported measures are at least consistent with that ordering of priorities.

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Underneath it all is the deemed-export concept

Why would staff nationality become a control point? There is an institutional explanation, not an emotional one.

US export control works on a concept called deemed export. Disclosing controlled technical data to a foreign person counts as an export to that person's home country from the moment of disclosure. ITAR defines releasing technical data to a foreign person as an export, and that holds even when the release happens inside the United States2. The definition of foreign person sits at 22 CFR 120.63 and covers natural persons who are neither US citizens nor lawful permanent residents3.

So in the ITAR world, the unit of regulation is not "which country did you ship to" but "who looked at the drawing." Whether the plant is in the US, Japan, or Taiwan, what gets asked is the status of the people touching the technical data. SpaceX reportedly sending audit teams to check staffing on the floor follows fairly naturally from that structure.

The equipment request reads as an extension of the same logic. Surveillance cameras and network devices on a production floor are devices sitting inside the space where drawings and processes live. Give them a path to the outside and you have a potential route for technical data. Cases of shipping firmware containing outbound communication components are not hypothetical, as I covered in the Zbtlink router case. Counting equipment as a data path rather than as an asset is an idea now arriving on the procurement side.

Japan has the same concept in its own law. The clarification of deemed-export control under the Foreign Exchange Act took effect on May 1, 2022. Even when technology is provided to a resident, if that person falls into one of the specified categories indicating strong influence by a foreign government, prior permission from the Minister of Economy, Trade and Industry is required, as it would be for a non-resident4. The important part is that METI itself makes clear that falling into a specified category does not, by itself, mean the person presents a security concern. The framework looks at actual relationships of influence; it does not brand people. The mechanics and how to run them are covered in the human dimension of preventing technology leakage.

US law has itself penalized blanket nationality screens

This is the part I most want to land.

"If export control is the reason, screening by nationality is unfortunate but unavoidable." It is a tempting line of thought, and in the US that judgment has drawn penalties of its own. The Immigration and Nationality Act (8 U.S.C. 1324b) prohibits employment discrimination on the basis of citizenship or national origin. The Justice Department has enforced it against companies that read ITAR too broadly and restricted work to US citizens.

In August 2018, Clifford Chance US LLP agreed to pay a USD 132,000 civil penalty after limiting a large document review involving ITAR-controlled data to US citizens only. The firm reportedly held a good-faith belief that only US citizens could work on ITAR matters. The Justice Department's position was that there is no good-faith exception to the prohibition on discrimination under 1324b5. Honda Aircraft was similarly penalized for requiring citizenship or permanent residency across at least 25 job postings without valid justification5.

You can see the shape of the trap. Screen crudely by nationality in the name of export control and you breach a different statute. Do nothing for fear of discrimination and you breach export control. The answer is neither "exclude by nationality" nor "do nothing." It is to define the scope of the controlled technical data, then run the necessary verification and authorization within the bounds of the actual job. It takes more work. There is no safer route.

One more thing. The people who bear the real cost here are individual engineers and line workers. Someone reassigned because the rules shifted around them did nothing wrong. Even when a company decides to comply with a customer's demand, that ought to be said out loud internally.

What a Japanese supplier should check when the request lands

Down to practice. Four things to do first.

Start by separating legal obligation from commercial term. ITAR and EAR rarely apply directly to a Japanese company; most of the time this arrives as a contractual requirement. Those are entirely different animals. A legal obligation leaves you no options; a contract term leaves room to negotiate and to propose alternatives. Push both down to the floor undifferentiated and people overreact.

Second, define the scope of the controlled technical data. The whole plant, one line, or one drawing? Because ITAR thinks in units of information, narrowing the scope narrows the staffing constraint with it. Before accepting "apparently our entire factory is off limits," establish which data falls into which control classification.

Third, build a register of who touches what. Without a record linking people to information, you cannot answer a customer audit and you cannot satisfy deemed-export requirements under the Foreign Exchange Act either. With the register in hand, you can say "no controlled data flows through this process" and support it, which often pulls the demand back to something workable.

Fourth, put the equipment inventory in the same register. People and devices usually belong to different departments internally, but to the party making the demand they are the same category: things that can touch technical data. Model number, manufacturer, outbound destinations, all in one table. Audit responses get markedly easier.

Taken together, this is the work of continuously understanding the relationships between suppliers, technology, and people. As item counts grow and regulations change across jurisdictions, running it by hand becomes rough. TRAFEED, our export control AI agent, supports classification and counterparty screening in a single flow and is aligned with METI's standards. In a joint proof-of-concept with Okayama University using roughly 30,000 past review records, we confirmed AI judgment accuracy of 95% or higher. Your export control officer still makes the final determination; what changes is the weight of the research and first-pass screening beneath it.

When contract terms become de facto regulation

One step back, to what this case actually signifies.

Export control has traditionally meant governments writing rules and companies following them. The structure being reported here is different. A private company is imposing conditions on its own supply chain that reach further than any statute, backed by the very real leverage of withholding orders. In territory no government regulates, a customer's demand carries the weight of regulation for the supplier.

The hard part for Japanese companies is that the demand does not necessarily align with domestic law. Blanket treatment based on nationality does not simply pass muster under Japanese employment law either. How much to accept and where to push back is not a decision the export control desk can make alone; legal, HR, and the executive team need to be at the same table. When the Economic Security Management Guidelines METI published in January 2026 argue that technology leakage should not be filed as an engineering problem but handled company-wide with HR and legal involved, this is exactly the scenario they have in mind.

Wrapping up

The essentials:

  • Nikkei Asia reported exclusively that SpaceX is asking suppliers to keep Chinese nationals off facilities making its products and to replace Chinese-made cameras and network equipment, while building an NCNT (non-China, non-Taiwan) supply chain
  • This is reporting, not an announcement. No official SpaceX comment or denial was confirmed at the time of publication
  • The foundation is ITAR's deemed-export concept, where the unit of control is who touched the technical data rather than where it shipped. Japan has an equivalent framework effective May 2022
  • However, US enforcement has penalized over-applied citizenship screens under the Immigration and Nationality Act. Good-faith misunderstanding is not a defense
  • When the request arrives: separate law from contract, scope the controlled data, register who touches what, and inventory the equipment in the same place

I will admit this is the article I have been most careful writing. Nationality is a subject where a slightly loose sentence turns into treating a group of people as suspect. What the rules look at is the actual relationship of influence, not an attribute of a person. Holding that line in practice, not just on the page, is what is really being tested.

If you are at the stage of rebuilding the register that connects your technical data to the people who touch it, or working out how far to go in meeting a customer's demands, reach out through TRAFEED's individual consultation.


References

This article reflects public information as of August 7, 2026. Statements about SpaceX's supply chain policy derive from press reporting and are not official company announcements.

Footnotes

  1. Nikkei Asia, "Exclusive: SpaceX moves to keep Chinese nationals, parts out of supply chain" https://asia.nikkei.com/business/technology/exclusive-spacex-moves-to-keep-chinese-nationals-parts-out-of-supply-chain 2

  2. eCFR, "22 CFR Part 120 — Purpose and Definitions" (ITAR definitions of export and release of technical data) https://www.ecfr.gov/current/title-22/chapter-I/subchapter-M/part-120

  3. Legal Information Institute, "22 CFR § 120.63 - Foreign person" https://www.law.cornell.edu/cfr/text/22/120.63

  4. METI Trade Control Department, Security Export Control Policy Division, "On the clarification of deemed export control" (effective May 1, 2022) https://www.meti.go.jp/policy/anpo/law_document/minashi/meikakukanitsuite2.pdf

  5. US Department of Justice, Civil Rights Division settlement with Clifford Chance US LLP (announced August 29, 2018; USD 132,000 civil penalty), among cases where over-application of export control was found to violate the Immigration and Nationality Act (8 U.S.C. 1324b) https://www.justice.gov/opa/press-release/file/1126521/dl 2

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Free download

Recommended materials

Economic Security Management Guidelines (1st Edition): 44-Item Self-Check Worksheet (2026)

A fill-in worksheet built from the appendix checklist of the Economic Security Management Guidelines (1st Edition), published by METI's Trade and Economic Security Bureau on 23 January 2026. All 44 items are transcribed from the original text and laid out in its three-column form: check item, Y/N, and the structures (organisation, internal rules) and track record behind your answer. The breakdown follows the original: 5 items on principles executives should keep in mind, 13 on securing autonomy, 13 on securing indispensability, and 13 on strengthening governance, with the 8 items the original phrases as "it is also useful to" badged separately. Opens with a plain-language primer on what economic security, autonomy, indispensability, governance and duty of care actually mean. Includes METI-published survey data showing that 70.7% of 3,007 manufacturers had heard the term but had no concrete image of it, and that the share expecting lost revenue to outweigh the cost of action rises from 22.3% over one to three years to 31.9% over four to ten. As METI states explicitly, the guidelines are not an obligation imposed on companies and are not premised on transactions with any specific country, company, or person. This worksheet was produced by TIMEWELL and was not prepared or endorsed by METI. Final decisions should rest with your legal and compliance leadership and the latest publications of the relevant authorities.

Event Organiser's Migration & Data-Rescue Checklist (fill-in, 2026)

A fill-in worksheet for event organisers whose ticketing service has shut down. PassMarket closed on June 30, 2026, and its ticket management tool is announced as available until August 31, 2026 (planned). The sheet covers what to rescue before that deadline (attendee records, survey responses, revenue and payout records, event page copy, ticket configuration), an inventory of the channels through which you can still reach attendees, a formula and worksheet for calculating the effective cost of a new platform yourself, and the steps to launch a first event on it. Anything the official announcement does not state — when in-service messaging stops, the export specification for attendee lists and survey data, the timing of payouts — is marked "to be confirmed" rather than asserted. It does not rank providers; it supplies the formula and the checklist.

China-Related Transactions Export-Control Screening Sheet (fill-in / Export Control Law & Dual-Use Regulations, critical minerals, Control List, 2026)

A fill-in working sheet for companies trading with China: screen a single transaction against China's export-control regime (the Export Control Law and the Dual-Use Items Export Control Regulations), the controls on critical minerals (gallium/germanium/graphite/antimony/tungsten etc./rare earths/helium), and the four counterparty-list systems (Control List, Watch List, Unreliable Entity List, countermeasure lists). A procedure for "what to check before the deal," not a roster of "who is listed." With a plain-language intro, based on MOFCOM announcements. Listing is a regulatory category, not a judgment about any company (including the Japanese firms on the Japan-directed lists); controls change continually, so verify current announcements and consult your officer. Match counterparties using the original simplified-Chinese wording.

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles