Electronic Component Sourcing, Authentication & Counterfeit Risk Frequently Asked Questions
Find answers to common questions about SMT Corp’s electronic component sourcing, authentication, testing, and supply chain solutions.
Find answers to common questions about SMT Corp’s electronic component sourcing, authentication, testing, and supply chain solutions.
Requirements depend on the contract. When DFARS 252.246-7007 and/or 252.246-7008 apply, contractors generally must maintain a risk-based counterfeit avoidance system, favor original or authorized sources, preserve traceability, and inspect, test, and authenticate parts when traceability is unavailable. Applicable reporting, quarantine, recordkeeping, obsolescence, and lower-tier flowdown duties also need to be addressed. SAE AS6171 is widely used to turn those risk-based obligations into a defensible test plan, while prime-contractor flowdowns may add program-specific requirements.
UK MOD requirements are normally imposed through the contract and its flowdowns, including DEF STAN 05-135 when invoked, alongside applicable NATO AQAP requirements. A compliant approach typically includes a documented avoidance and control plan, approved-source priorities, supplier controls, traceability, risk assessment, proportionate inspection and testing, quarantine and reporting, training, records, and obsolescence management. The exact obligation depends on the contract, so the first step is to map each clause and prime-contractor requirement to a controlled process.
These documents address different layers of the problem. SAE AS5553 sets requirements for organizations that procure or integrate electronic parts; SAE AS6081 addresses counterfeit avoidance for independent distributors; SAE AS6171 provides risk-based inspection and test methods for suspect or untraceable parts; and IDEA-STD-1010 focuses largely on visual inspection and acceptability. They are complementary, not interchangeable. A robust program may use SAE AS5553 or SAE AS6081 for the management system and sourcing controls, then SAE AS6171 for the technical authentication plan.
A useful policy should define when authorized and open-market sourcing are permitted; who approves exceptions; how supplier and part risk are scored; which standards and test levels apply; and how acceptance, quarantine, reporting, disposition, records, training, and lower-tier flowdowns are handled. It should also address obsolescence and periodic review as threats and requirements change. SMT can help convert contract language and organizational risk tolerance into practical procedures, test-plan rules, and supplier controls.
GIDEP and ERAI are valuable screening and information-sharing tools that help organizations identify potential counterfeit-part risks. GIDEP is particularly relevant for covered U.S. government work, where screening and reporting may be contractually required. A GIDEP “suspect counterfeit” report indicates that information has raised a concern about a part’s authenticity, but it should not by itself be interpreted as a final determination that a part or supplier is counterfeit.
Both systems provide important information that can help organizations identify areas requiring additional review. GIDEP reports are submitted by government and industry members, with responsibility for the accuracy of the information remaining with the reporting organization and an opportunity generally provided for affected manufacturers or suppliers to respond. ERAI applies its own review and substantiation process before publishing reported information. In either case, an alert is best viewed as an important risk indicator that should be considered alongside the underlying evidence, lot history, chain of custody, supplier context, and appropriate technical testing.
Zero trust does not mean “assume everything is counterfeit.” It means that trust is earned through evidence rather than inferred from a logo, certificate, channel label, or prior relationship alone.
The amount of evidence should be proportional to risk: low-risk, fully traceable material may need routine controls, while untraceable or mission-critical parts may require deeper provenance review, physical inspection, and electrical testing. The objective is defensible, risk-based confidence—not blanket testing of every part.
No. A Certificate of Conformance is useful evidence, but it is only as reliable as the issuing party and the chain of records behind it. Documents can be incomplete, altered, misapplied to a different lot, or fabricated.
Confidence comes from corroborating the certificate with source authorization, traceability, purchase and lot records, packaging and marking consistency, and -when risk warrants – independent inspection and testing. Paperwork should support the technical and supply-chain evidence, not replace it.
No. In many cases, using one qualified, experienced provider for sourcing and authentication creates a more effective and defensible risk-control process. Laboratory expertise can inform purchasing, tailor testing to specific sourcing risks, and preserve chain of custody within one auditable quality system.
Findings can also strengthen supplier qualification and future sourcing decisions, with clear accountability from purchase through authentication. This integrated approach may be especially valuable for complex, high-risk, or time-sensitive procurements. The key factors are competence, accreditation, transparency, independent technical judgment, and conflict controls – not separation alone.
Select an independent distributor based on a balanced assessment of commercial fit, capability, transparency, and risk. Price and delivery are important considerations, but they should be evaluated alongside factors such as company reputation and experience, quality-system maturity, relevant certifications, sourcing practices, traceability, performance, alert and legal history, financial stability, returns and disclosure policies, storage and handling controls, and willingness to provide pre-buy photographs or samples.
Risk assessment should also continue lot by lot. Market scarcity, date and lot codes, packaging, documentation, prior test results, and the supplier’s responsiveness when issues arise can all provide important context. A strong independent distributor should be able to support its claims with evidence and maintain transparency throughout the transaction.
Counterfeit or otherwise untrusted parts can originate through reclaimed e-waste, remarking, unauthorized overproduction, reverse-engineered clones, rejected or scrapped material diverted back into commerce, fraudulent returns, mixed lots, and forged documentation.
Parts may then pass through several legitimate intermediaries before an issue is detected, so the last seller is not always the original source of the problem. Effective mitigation examines both the physical part and the full transaction history rather than assuming every anomaly reflects deliberate misconduct by the immediate supplier.
No. Legitimate open-market inventory can come from manufacturer or authorized-distributor excess, OEM or contract-manufacturer surplus, last-time buys, canceled programs, corporate inventory reductions, and properly controlled liquidation.
The risk is that provenance, storage history, handling, or lot consistency may be less complete than in an authorized channel. The right response is not to avoid the open market categorically, but to qualify the supplier, preserve chain of custody, verify available records, and apply risk-based authentication before use.
Authenticity asks whether the part is genuinely what it claims to be and comes from the stated manufacturer and pedigree. Quality and conformance ask whether it meets the applicable specification and is fit for use.
An authentic part can still be aged, mishandled, moisture-damaged, improperly stored, or out of specification; a counterfeit part may initially appear to function. High-reliability assurance therefore needs both identity-focused authentication and performance-focused testing, with acceptance tied to the actual application.
Recycled and remarked parts remain common, and detailed external visual inspection can identify many red flags. But the threat also includes forged documentation, tampered or mishandled material, unauthorized overbuilds, and increasingly sophisticated clones that may look convincing and function under limited conditions.
Microscopy is therefore a starting point, not a complete authentication strategy. Depending on risk, the evidence may need to include X-ray, materials analysis, decapsulation, die comparison, and electrical or environmental testing.
There is no universal test bundle. SAE AS6171 uses a risk-based approach that considers the part type, source, known counterfeit history, available documentation, application, and consequence of failure.
A plan may combine enhanced visual inspection, radiological inspection, XRF analysis, surface or material analysis, decapsulation, die inspection, and electrical testing, with sampling and escalation rules matched to the risk. SMT can help select the appropriate risk level and methods so the plan is technically justified rather than simply a checklist.
A clone is an unauthorized reproduction intended to imitate an original manufacturer’s device. It may carry convincing markings and may even pass basic functional checks, yet differ in die design, process technology, firmware, performance margins, temperature behavior, reliability, or security.
That makes clones especially difficult to detect with visual inspection alone and particularly concerning in long-life or mission-critical systems. Effective detection may require die-level comparison, materials analysis, performance testing across conditions, and expert interpretation of multiple data sources.
AI can help bad actors create more convincing labels, certificates, images, listings, and technical narratives, while advanced design and reverse-engineering tools can reduce the effort needed to imitate devices.
The same technology can help defenders screen documents and images, identify anomalies, prioritize supplier and part risk, and review large test datasets. Its value is highest as a decision-support tool: models can accelerate analysis, but controlled data, validated methods, human expertise, and auditable conclusions remain essential.
Physical and materials inspection can reveal construction and marking anomalies, but it does not show whether a device performs as specified.
Electrical testing can identify the temperature and speed grade, memory behavior, or parameter range; expose clones that pass a simple power-on check; and detect authentic parts that are degraded, damaged, or out of specification. It should be selected to address the device’s likely failure modes and used alongside – not instead of – provenance review and physical analysis.
No. Legitimate manufacturing variation, aging, rework, storage, handling, and packaging changes can all produce unusual features. An anomaly is a reason to contain the lot, gather more evidence, and determine whether the observations are consistent across the sample and with known-good material.
Conclusions should reflect the totality of evidence and clearly distinguish counterfeit, nonconforming, suspect, and inconclusive findings. Experienced interpretation is critical because both false acceptance and false accusation can carry serious consequences.
Stop movement and use of the affected lot, place it in controlled quarantine, preserve packaging, labels, records, photographs, and test data, and notify the appropriate quality, program, customer, and contracting personnel.
Expand the review to related lots and any material already installed or shipped. Do not return suspect material to the supply chain until disposition is authorized. Reporting to GIDEP, ERAI, law enforcement, or other parties should follow contract, regulatory, and company requirements and be supported by a documented technical investigation.
Report content is governed by the applicable SAE AS6171 requirements, the laboratory’s accredited scope, the contract, and the customer-approved test plan. At quotation and test-plan review, the parties should agree on required deliverables and any customer-specific reporting expectations.
Depending on scope, a report may identify the part and lot, sample size, methods performed, observations and test data, photographs, anomalies, limitations, and recommended follow-on work. It should be read together with the sampling plan and test scope; it does not necessarily assign a universal set of outcome labels or establish the condition of every untested unit.
SMT Corp operates under established quality, testing, and counterfeit mitigation standards, including ISO 9001:2015, AS9120:B, ISO/IEC 17025:2017, AS6081, AS6171, and ANSI/ESD S20.20.
Upscreening and alternate qualification can reduce dependence on a scarce exact part by demonstrating that a commercially available or substitute device meets the required temperature, performance, reliability, and application conditions.
This may extend system life and avoid a costly redesign, but it is an engineering qualification process – not simply testing a part and relabeling it. The plan should address form, fit, function, interfaces, environmental stresses, long-term reliability, configuration control, and any customer or regulatory approval.
Counterfeit exposure often rises when a critical part becomes obsolete and procurement turns urgent. Lifecycle monitoring, product-change and end-of-life tracking, forecasted demand, last-time-buy planning, controlled safety stock, alternate qualification, upscreening, and timely redesign decisions reduce the need for emergency open-market purchases.
When independent sourcing is still necessary, early planning creates time to qualify suppliers, budget the right testing, and resolve anomalies before production or sustainment schedules are at risk.
SMT combines qualified sourcing, pre-buy technical review, accredited authentication, and electrical and environmental testing within an integrated quality framework across its U.S. and UK operations. Its Sandy Hook, Connecticut laboratory maintains ISO/IEC 17025 accreditation with SAE AS6171 methods in scope, SAE AS6081 certification, accredited SAE AS6171 High Risk Level 2 testing, and DLA QSLD/QTSL qualification.
SMT Labs UK in Rochester, Kent is also included in SMT’s ISO/IEC 17025 and SAE AS6171 accreditation scopes, with Moderate Risk Level 2 capabilities across accredited non-destructive, mechanical, and passive-component electrical methods. Both sites follow aligned processes, work instructions, and technician training. The practical distinction is the closed loop: sourcing intelligence shapes the test plan, laboratory findings feed back into supplier risk, and one accountable team maintains chain of custody and interprets the evidence through final disposition.