Clearance process · Detailed map

Access authorization and lifecycle

Verify specific access, take any SCI or SAP branch, and continue through reporting, transfer, change and debrief.

Process chart · access and continuing trust

Authorize the defined access, then maintain or close it

Eligibility is checked before a separate access decision. Access continues only while the approved mission or contract need, affiliation and required conditions remain in place.

CONTINUE FROM VERIFIED ELIGIBILITY · STEPS 8–9

8

The access authority grants only the specific authorized access

Government employee

Mission/security authority confirms active eligibility, official duty, need-to-know, NDA, briefing, system/location authorization and any separate compartment or program approval.

Industry employee

Customer/authorized information holder confirms contract task, employment/affiliation, need-to-know, SF 312, briefing and authorized location/system. FSO verifies status; the Government/customer or program authority grants access.

Gate: Every applicable condition must be met. Eligibility does not by itself grant access; SCI/SAP and facility safeguarding follow separate approvals.

References: Executive Order 12968, §4.1 · 32 CFR §117.3 · use the SCI/SAP branches below

9

Maintain eligibility and access; act on changes or separation

Government employee

Employee, supervisor and agency security/personnel-vetting offices follow continuous-vetting, training, update and event-reporting duties. Transfer, changed duties, loss of need or separation routes to review, access withdrawal and record updates.

Industry employee

Employee uses company/customer reporting channels; FSO/company sends required CSA reports; prime/sub keep contract flow-downs aligned; customer controls site access. On separation, withdraw access, update records, recover material and debrief as required.

Next action: New contract or duties → verify the basis and level; upgrade or break in service → revisit Decision 2; no continuing need → remove access; reportable event → follow the event-by-event Reporting Requirements page.

References: ODNI Federal Personnel Vetting Guidelines, §§IV–VI · DCSA contractor continuous vetting · Reporting requirements by framework

This chart shows the common pathways. Agency, population, contract and program rules can add steps or specify different systems. Use the linked authority and your sponsoring security office for a live case.

Conditional branches

Does the work require SCI or SAP access?

If no, continue along the collateral-access path above. If yes, take the applicable branch in addition to the baseline process. Neither branch is automatically granted by a Secret or Top Secret eligibility determination.

Off-ramp A

SCI access required

  1. Government employee: the component with SCI responsibilities confirms the mission requirement, nominates or requests the individual under its current process, and the cognizant SCI authority makes the separate SCI access decision.
  2. DoD contractor: DoDM 5105.21, Volume 3 requires a valid contractual basis to sponsor the company for a final Top Secret FCL; contractor employees performing on SCI contracts must meet SCI eligibility requirements and be indoctrinated. A Secret safeguarding entry for the contractor’s own site does not by itself answer whether the company has the required TS FCL.
  3. Place matters: SCI access at another authorized site does not itself authorize the contractor’s own site to safeguard SCI. If SCI will be used or stored at a contractor facility, the DoD SCI process requires a contractor SCIF review and accreditation path, with the DD Form 254 identifying the location and SCI safeguarding requirement.
  4. Before access: confirm eligibility, need-to-know, program/caveat approval, indoctrination, and the authorized SCI location with the cognizant SSO/security authority.

Primary references: DoDM 5105.21, Vol. 3, Enclosure 3, §§2–6; 32 CFR §§117.3(b), 117.23(b); DD Form 254 Instructions, Item 10e(1).

Off-ramp B

SAP access required

  1. Government employee: the sponsoring program office validates the official need and submits a nomination through the program’s security authority.
  2. Industry: confirm the contract requirement and current, valid SAP DD Form 254/addendum. DoD SAP contractors must hold the applicable Part 117 facility eligibility; the program security manager/office coordinates and approves access and any subcontract support.
  3. Personnel gate: the program authority checks eligibility appropriate to the SAP classification level, need-to-know, continuous-vetting status, nomination, and program-specific criteria. A collateral clearance alone does not grant SAP access.
  4. Facility gate: SAP information may be handled only in an area accredited for that program and at the required level. An FCL is not SAPF accreditation; the security cognizant program office controls the facility approval.
  5. Before access: approval, briefing, nondisclosure and program-specific acknowledgments must be completed. Access is limited to the named program and duties.

Primary references: DoDM 5205.07 (Jan. 17, 2025), §§10, 12–13; DoDI 5205.11 (Sept. 12, 2024), §5.6; DD Form 254 Instructions, Items 10f and 14–15.

Branch complete? Return to the main lane for ongoing reporting, continuous vetting, access reviews, transfer, and debriefing. Add customer- or program-specific duties wherever the governing instructions require them.

Once eligibility and access are in place

A clearance is maintained through the whole affiliation

Eligibility, access, affiliation, and authorization to handle information each have their own owner and can change at different times. A favorable determination does not make access permanent.

  1. Grant and recordThe authorized adjudicative authority records eligibility. The sponsoring agency or contractor security office verifies the level and status in its system of record.
  2. Brief and authorizeThe responsible security authority confirms mission or contract need, need-to-know, signed nondisclosure agreement, required briefing, and any compartment or program approval before access is opened.
  3. Maintain and monitorThe individual follows reporting and training duties. The organization maintains accurate affiliation and access records, responds to continuous-vetting actions, and reviews whether the need remains valid.
  4. Resolve changesTransfer, a new customer or contract, change in duties, loss of need-to-know, or a reportable concern may require a new access decision, record update, investigation, or security review.
  5. Withdraw and debriefWhen access is no longer authorized, the owning security office removes access, conducts any required debrief, recovers credentials and classified material, updates the personnel-security record, and explains continuing obligations.

DoD contractor national-security personnel are subject to DCSA’s current continuous-vetting process. DCSA’s May 2026 update describes a five-year updated questionnaire cycle keyed to the PVQ Date in DISS; agency populations and other vetting domains may follow different implementation schedules.

Official sources

Checked September 23, 2026. Follow current agency and program instructions where they are more specific.