Industrial security · Field reference

Security reviews & corrective actions

Prepare for the review, use the current rating resources, and document how each finding was resolved.

October 2026 updates Facility guide

Use the final October 1 toolset

DCSA fully implemented Security Rating Score Tool 2.0 on October 1, 2026, following its July soft launch. The October briefing says Gold Standard requirements remain the same; the final resources include clarifying language and improvements to how the rating calculation is explained.

These are DCSA’s official resources, listed on its Security Review & Rating Process page. Use the current official files when preparing for a review; a self-assessment does not assign the facility’s official rating.

Choose the follow-up for the finding

Administrative findings

Effective October 1, DCSA no longer immediately validates mitigation of administrative findings or requests formal written administrative mitigation packages. The contractor remains responsible for timely correction and a local record showing mitigation dates.

Aim to resolve administrative findings within the 30-day Gold Standard. When complexity prevents closure, document the plan of action and milestones. Unresolved findings can affect Gold Standard criteria NE-1 and NE-4 at the next review.

Vulnerabilities and other reports

The administrative-finding procedure does not apply to serious or critical vulnerabilities. Continue the corrective-action response and DCSA validation required for those findings.

Keep incident, loss/compromise, adverse-information, and other required reports on their own timelines. The 30-day benchmark is guidance for administrative mitigation, not a new universal statutory deadline or permission to delay a report.

Keep the evidence with the action

Good practice: keep a local corrective-action record with the finding and its classification, date identified, responsible role, target date, mitigation taken, completion date, and evidence reference. Retain enough information to explain the correction at the next review.

  1. Confirm with the ISR whether the issue is an administrative finding or a vulnerability.
  2. Assign responsibility and a realistic target; record milestones if work takes longer.
  3. Document completion and the evidence demonstrating that the issue was corrected.
  4. Review unresolved items before the next self-inspection or DCSA review.

The ITP self-inspection tool already records evidence, corrective actions, owners, target dates, and closure dates for the insider-threat part of the program. It is not a complete facility review or DCSA rating calculator.

FY2026 review context

As of September 29, 2026, DCSA reported 4,475 security reviews: 3,346 on-site and 1,129 remote. Of 4,423 finalized ratings, 99.6% were satisfactory or higher. Review counts and finalized-rating counts have different denominators; these figures describe DCSA’s program and do not predict a facility’s rating.

Sources and preparation

September 2026 VOI, pp. 3–4, distinguishes administrative findings from vulnerabilities. October ISE slides 27–28 address mitigation and final tool implementation; slide 24 supplies the historical metrics.

October operational update reviewed October 9, 2026. DCSA Industry Stakeholder Engagement, October 6, 2026, slides 24, 27–29. Source details and scope.