Reference

Cross-border US market entry glossary.

Definitive reference for the regulatory bodies, procurement frameworks, and incentive programs that show up in cross-border US market entry. Each entry carries precise citations and links to the relevant pillar work.

Reference operating map
ProcurementFAR, DFARS, GSA MAS, NAICS, SAM.gov, and CMMC form the federal buyer entry layer.
RegulatoryFDA, MDR, QSR, Q-Sub, ITAR, and EAR define which proof is commercial and which proof belongs with specialists.
QualificationPPAP, APQP, IATF, USMCA, and IRA terms explain why technical strength needs a US buyer frame.

Federal contracting and registration.

FedRAMP

Federal Risk and Authorization Management Program. Standardised approach for assessing, authorising, and continuously monitoring cloud products for US federal government use. Three baselines (Low, Moderate, High), Rev 5 from May 2023.

Read the entry →

CMMC

Cybersecurity Maturity Model Certification. DOD requirement for contractors handling Federal Contract Information or Controlled Unclassified Information. CMMC 2.0 has three levels finalised October 2024.

Read the entry →

FAR

Federal Acquisition Regulation, codified at 48 CFR Chapter 1. Uniform policies and procedures for acquisition of supplies and services by US federal executive agencies. Issued jointly by DOD, GSA, and NASA.

Read the entry →

DFARS

Defense Federal Acquisition Regulation Supplement, codified at 48 CFR Chapter 2. DOD-specific supplement to FAR. Adds defense-mission-specific cybersecurity, domestic-source preferences, and Berry Amendment provisions.

Read the entry →

NAICS code

North American Industry Classification System. Six-digit code identifying business industries. Required field on SAM.gov entity registration and federal RFP responses. Sets size standards for small-business eligibility.

Read the entry →

GSA Schedule (MAS)

General Services Administration Multiple Award Schedule. Long-term governmentwide contract providing federal/state/local agencies streamlined access to commercial products, services, and solutions at pre-negotiated terms.

Read the entry →

SAM.gov registration

System for Award Management. US federal entity registration database. Mandatory for any entity seeking federal contracts above the micro-purchase threshold. Includes UEI, CAGE/NCAGE, NAICS, FAR/DFARS reps and certs.

Read the entry →

ITAR, EAR, and dual-use technology.

ITAR

International Traffic in Arms Regulations, 22 CFR Parts 120-130. Administered by US State Department DDTC. Controls export and temporary import of defense articles and services on the US Munitions List.

Read the entry →

EAR

Export Administration Regulations, 15 CFR Parts 730-774. Administered by US Department of Commerce BIS. Controls exports, re-exports, and in-country transfers of dual-use items via the Commerce Control List and ECCNs.

Read the entry →

FDA pathways and quality systems.

MDR (EU 2017/745)

EU Medical Device Regulation replacing the Medical Device Directive. Full application 26 May 2021. Stricter clinical evidence, mandatory Notified Body involvement for higher classes, UDI, EUDAMED, PRRC. Does not equal FDA clearance.

Read the entry →

FDA 510(k)

Premarket Notification under Section 510(k) of the FD&C Act. 21 CFR Part 807 Subpart E. Most common FDA medical device pathway. Demonstrates substantial equivalence to a legally marketed predicate device.

Read the entry →

FDA QSR (21 CFR Part 820)

Quality System Regulation. Current Good Manufacturing Practice for finished medical devices. Being harmonised with ISO 13485:2016 under QMSR, effective 2 February 2026.

Read the entry →

FDA Q-Submission

FDA CDRH framework for pre-submission interactions. Pre-Sub, Submission Issue Request, Study Risk Determination, Informational and Agreement Meetings. Voluntary but recommended for novel devices and unclear pathways.

Read the entry →

PPAP, APQP, IATF 16949.

PPAP

Production Part Approval Process. AIAG standard, currently Fourth Edition. Five submission levels with 18 elements. Required by Detroit Three (Ford, GM, Stellantis NA) and most global OEMs. European VDA 2 not directly substitutable.

Read the entry →

APQP

Advanced Product Quality Planning. AIAG framework for automotive product development. Five phases with gate reviews, DFMEA, PFMEA, control plans, MSA, SPC. Required by IATF 16949 and customer-specific requirements.

Read the entry →

IATF 16949

International Automotive Task Force quality management standard. IATF 16949:2016 built on ISO 9001:2015. Required by IATF OEMs (BMW, Daimler, FCA/Stellantis, Ford, GM, JLR, Renault, VW). CSRs differ by OEM.

Read the entry →

USMCA and the Inflation Reduction Act.

USMCA Regional Value Content

United States-Mexico-Canada Agreement rules-of-origin requirement. 75% RVC for passenger vehicles and light trucks (phased from 66%), 70% for heavy trucks. Plus 40-45% Labor Value Content at 16 USD/hour and 70% steel/aluminium rule.

Read the entry →

IRA Section 30D

Inflation Reduction Act 2022 Clean Vehicle Credit. Up to $7,500 federal tax credit for qualified clean vehicles. Critical-minerals requirement and battery-components requirement, phased 2024 through 2029. Foreign Entity of Concern restrictions.

Read the entry →

Buy American, Davis-Bacon, McNamara-O'Hara, DCAA.

Buy American Act

41 USC Chapter 83. The federal preference rule for domestic end-products in direct government procurement. Establishes price differentials and waiver criteria that gate foreign-supplier eligibility on US federal files.

Read the entry →

Davis-Bacon Act

40 USC 3141. Prevailing-wage rule for federally funded construction. Wage determinations issued by US Department of Labor. Reshapes how a foreign bidder prices labour into a US federal-funded RFP response.

Read the entry →

McNamara-O'Hara Service Contract Act

41 USC Chapter 67. Federal wage-and-benefits rule for service contracts. Sets the floor for hourly wages and fringe benefits a foreign service provider must price into a US federal service-contract bid.

Read the entry →

DCAA

Defense Contract Audit Agency. Federal audit body that reads contractor cost accounting and indirect-rate structure before cost-reimbursement defense work is awarded. A first DCAA review reshapes a foreign supplier's US cost system.

Read the entry →

CFIUS, FCPA, SOX.

CFIUS

Committee on Foreign Investment in the United States. Interagency body that reviews foreign investment in US businesses for national-security risk. Covers minority positions, JVs, and certain real-estate transactions.

Read the entry →

FCPA

Foreign Corrupt Practices Act. 15 USC 78dd. US anti-bribery statute with extraterritorial reach to foreign-owned operating companies touching US commerce. Books-and-records and internal-controls provisions apply to issuers.

Read the entry →

SOX (Sarbanes-Oxley)

Sarbanes-Oxley Act 2002. US financial-controls regime for public companies and their subsidiaries. Section 302 and 404 shape audit, board, and internal-controls posture inside US-held operating companies.

Read the entry →

EU AI Act, DORA.

EU AI Act

Regulation (EU) 2024/1689. Horizontal AI regulation. Risk-tiered obligations on providers and deployers, GPAI model rules, and reach into AI systems placed on the EU market regardless of provider jurisdiction.

Read the entry →

DORA

Digital Operational Resilience Act. Regulation (EU) 2022/2554. ICT-risk and third-party-provider rules for EU financial entities. Reaches ICT third-party providers serving EU financial entities regardless of provider jurisdiction.

Read the entry →

QFZP and free-zone structuring.

QFZP

Qualifying Free Zone Person. UAE corporate-tax regime for free-zone entities. Defines the 0% rate gate on qualifying income and the conditions that govern DIFC and ADGM structuring.

Read the entry →

Pillar work referencing these terms.

Cornerstone

Germany to USA market entry: 2026 guide.

Cornerstone guide for Mittelstand and DAX-listed operators. References every regulatory framework in this glossary in operator-context.

Read the guide →
Practical

German Mittelstand US procurement RFP handbook.

SAM.gov registration walkthrough, NAICS code mapping, GSA Schedule pathways, FAR Part 9 responsibility determination.

Read the handbook →
Cyber

German cyber: FedRAMP, CMMC, US federal procurement.

Detailed walk through FedRAMP Rev 5, CMMC 2.0 levels, NIST SP 800-171/53, IL2-IL6, ITAR/EAR architecture, FOCI mitigation.

Read the piece →

The framework is one thing. The architecture is another.

Glossary terms describe what exists. Building US-procurement-readable architecture inside those frameworks is the work. Tell us where it stalls.

Start the conversation
Start the conversation