Personnel reporting · Cleared Industry

Cleared Industry Reporting

Cleared-industry personnel follow three layers: SEAD 3 individual reporting, DCSA ISL 2021-02 implementation guidance for DoD-cognizant contractors, and the contractor’s separate reporting duties under 32 CFR §117.8. The FSO routes qualifying personnel reports; company-level reports remain the contractor’s responsibility.

Lane 2 · NISP contractor population

Cleared-industry individual and contractor

Industry has three layers: the individual’s SEAD 3 reporting baseline, DCSA’s ISL 2021-02 implementation guidance for DoD-cognizant contractors, and the contractor’s separate company reporting duties under 32 CFR §117.8. These duties can overlap, and one report does not automatically satisfy another.

1 · PERSON

SEAD 3 baseline

Covered NISP employees report the applicable SEAD 3 events to the FSO/designee. Use the full SEAD 3 event chart above. ISL guidance clarifies which individuals are covered and how contractors receive and route their reports.

2 · INDUSTRY OVERLAY

DCSA ISL 2021-02

For contractors under DoD security cognizance, the ISL clarifies reporting and adds implementation duties: covered-person scope; written standard practice procedures (SPP); FSO receipt, management and DISS reporting; additional adverse-information examples; and category-specific details in Tables 1–4. It was issued August 12, 2021, revised in 2024, and does not replace the rule.

Open the official ISL 2021-02 ↗

3 · COMPANY

32 CFR §117.8

The contractor/FSO must submit every company report triggered by §117.8, including personnel, facility, contract, security-incident, accountability and review-related reports. The trigger and recipient for each item are shown in the checklist below.

Event-by-event guide · Cleared Industry

SEAD 3 plus DCSA ISL 2021-02 reportable requirements

This chart is for contractor personnel who have, or are undergoing a determination for, classified eligibility through the NISP when the DoD is the Cognizant Security Agency. Report qualifying personal events to the FSO/designee through the company’s approved protected channel. The FSO/designee makes required system submissions. The ISL does not replace SEAD 3, the NISPOM, agency-specific customer directions or the contractor’s independent §117.8 reports shown below.

Framework / areaReportable requirement in plain languageRoute and applicabilityReference
SEAD 3 · Unofficial foreign travelGive the FSO/designee the travel itinerary and required passport/trip details in advance. Report itinerary deviations and unplanned Canada/Mexico day trips within five business days after return. In an emergency, advise the FSO before departure when feasible and complete the report within five business days after return. Mixed personal travel is reportable for its unofficial portion.Employee → FSO/designee → required DISS Foreign Travel submission. Official travel in direct support of an established U.S. Government contract is treated under official-travel rules; check contract and SCI/SAP directions too.SEAD 3 §F.1(b), App. A.1; ISL Table 4; DCSA travel guidance
SEAD 3 · Foreign contacts and relationshipsReport contact with a known or suspected foreign intelligence entity; a continuing relationship with a known foreign national involving bonds of affection, intimate contact, personal obligation or exchange of personal information; and the specified foreign-national roommate, relationship or family events for the person’s category. Casual public interaction alone is not the test.Employee → FSO/designee. Official work contact without personal bonds is generally not reportable as a relationship; report it if suspicious or a security concern. FSO may submit an incident report and notify the DCSA counterintelligence representative when required.SEAD 3 §§D.8, F.2; ISL Tables 2–3
SEAD 3 · Report concerns about another covered personReport known conduct indicating unwillingness to follow security rules, unexplained affluence or excessive debt, alcohol or illegal drug misuse, criminal conduct, behavior affecting safe protection of information, misuse of Government property/systems, or loss, compromise, tampering or unauthorized access.Employee → FSO/designee through the company reporting process. Report factual observations; do not investigate or diagnose a coworker.SEAD 3 §F.3; ISL Table 2
SEAD 3 · Foreign citizenship, affiliation and interestsAs applicable to the person’s eligibility: applying for or receiving foreign citizenship/passport or identity documents; foreign business/employment/government service; foreign financial interests, accounts or property; foreign political activity or election voting; foreign financial benefits/support; and specified family or living-status changes.Employee → FSO/designee. Some financial, political, marriage/cohabitation, roommate and adoption items are limited to TS/Q-level categories. Use the DCSA desktop aid and the precise category that applies.SEAD 3 §§G.1, G.2(d), H.1–2; ISL Tables 2–3
SEAD 3 · Targeting, media and criminal activityReport attempted elicitation, exploitation, blackmail, coercion or enticement; media contact seeking classified or legally protected information; and reportable arrest, charge, criminal conduct, detention or law-enforcement involvement.Employee promptly notifies FSO/designee; the contractor makes required DISS/CSA reports and any separate Government-site, customer or law-enforcement report.SEAD 3 §§G.1(a), G.2(c)–(d), H.1(d), H.2(b)–(c); ISL Table 2
SEAD 3 · Drug, alcohol, health, financial and outside-activity mattersReport the drug/alcohol activity, treatment/counseling, financial concern/anomaly, defined health or behavioral event, or outside activity that meets the applicable SEAD 3 category. These are criteria-based; routine treatment alone is not universally reportable.Employee → FSO/designee. The company handles sensitive details through approved channels and separately evaluates whether §117.8(c)(1) requires an adverse-information report.SEAD 3 §§G.2(d)–(f), §H.2(d)–(h); ISL Tables 1–3
ISL 2021-02 · Foreign cryptocurrency (defined reportable interest)Report ownership of cryptocurrency backed, hosted or managed by a foreign state, and ownership of wallets hosted by foreign exchanges. No report is required when the employee is unaware of the foreign nexus, or when held through a widely diversified fund (such as an index fund), unless the instrument is entirely composed of that foreign-nexus cryptocurrency. The report captures cryptocurrency name, exchange host country and dollar value.Employee → FSO/designee → DISS/successor incident reporting path. This is a defined criterion; ordinary crypto ownership is not automatically reportable.ISL Table 1; Appendix A data elements
ISL 2021-02 · Specified mental-health criteriaReport: a court/administrative finding of mental incompetence; an order to consult a mental-health professional; hospitalization for a mental condition; a qualified professional’s diagnosis of psychotic disorder, schizophrenia, schizoaffective, delusional, bipolar mood, borderline personality or antisocial personality disorder; within seven years, changing/stopping/not starting treatment for one of those diagnoses without first consulting a medical professional; current treatment details for those diagnoses; or any health condition the individual believes substantially and adversely affects judgment, reliability or trustworthiness, whether symptomatic or not.Employee → FSO/designee using the approved protected process. A report is not itself an adverse adjudication or a direction to stop treatment; apply the stated limits exactly.ISL Table 1
ISL 2021-02 · Eligibility-tier clarificationsThe Desktop Aid lists additional foreign election, financial/business interests, foreign accounts/property, cohabitation, marriage/civil union, foreign-national roommate and adoption criteria for TS/Q personnel that are not listed for Secret/L. Category and current agency/customer rules govern.FSO/designee tells personnel which category applies and receives the report. Do not extend TS/Q-only rows to every cleared worker.ISL Table 3; DCSA SEAD 3 Industry Reporting Desktop Aid
ISL 2021-02 · Contractor’s reporting procedureMaintain written SPP instructions so covered personnel know what to report, how the FSO receives/manages it, how peer concerns are handled, and which reports go into DISS/successor systems. Foreign-travel reports use the designated travel module and criteria.Employee reports to FSO/designee; FSO submits the report through the required DISS module/system and follows CSA/customer instructions. This does not replace separate §117.8 contractor duties.32 CFR §117.7(e), §117.8(a); ISL 2021-02, Tables 1–4

Primary references: ODNI SEAD 3; DCSA ISL 2021-02, revised May 2024; and the DCSA SEAD 3 Industry Reporting Desktop Aid. Apply the exact eligibility category, contract and CSA instructions.

What does industry report?

Use this as the practical checklist for the industry path. The individual’s SEAD 3 categories depend on covered status and eligibility level; the company’s §117.8 duties have their own triggers. A report may be required even when it is administrative and not adverse.

PERSON · Employee → FSO / designated company contact

Self-report events under SEAD 3 as clarified for industry

  • Foreign travel: unofficial travel; itinerary deviations; unplanned contact with foreign governments, companies or citizens; suspicious travel anomalies; and foreign legal or customs incidents. Follow advance notice, briefing and post-travel steps that apply. The DCSA bulk tool does not remove the employee’s duty to tell the FSO.
  • Foreign contacts and relationships: foreign-intelligence-entity contact; a qualifying continuing relationship with a foreign national; qualifying exchange of personal information; and specified foreign-national roommate/cohabitation, marriage or adoption events. Limited or casual public contact alone is not the trigger; some relationship items apply only to TS/Q categories.
  • Foreign ties and interests: foreign citizenship, passport or identity documents; foreign business, employment, government service or political activity; foreign bank accounts, property, financial benefits or support; and specified family/partner-related interests when the person’s category requires it.
  • Security targeting or disclosure pressure: attempted elicitation, exploitation, blackmail, coercion or enticement; suspicious contacts; and media contact seeking classified or legally protected information.
  • Conduct and life events: arrests or criminal conduct; defined drug or alcohol events; reportable financial anomalies; specified psychological/emotional-health or behavioral triggers; outside activity that conflicts with security duties; and concerns about another covered person.

Route: notify the FSO/designee through the company’s approved protected channel. The FSO evaluates the applicable rule and submits required DISS/CSA reports. For an urgent threat or incident, use the emergency/security route immediately.

COMPANY · Contractor / FSO → named authority

Submit independent company reports under 32 CFR §117.8

  • Threats and people: possible espionage, sabotage, terrorism or subversion (FBI and CSA); adverse information about an eligible employee (CSA); suspicious contacts, elicitation, exploitation or unauthorized-access attempts (CSA); employee death, name/citizenship change or separation; LAA naturalization; stopping an eligibility/access request; or refusing the classified NDA.
  • Entity and facility changes: ownership/control or stock transfer; operating name/address changes for the entity or cleared location; KMP changes; business termination, reorganization, bankruptcy or other eligibility-changing events; material FOCI changes or negotiations; storage requirement/capability changes; and an emergency that prevents safeguarding.
  • Contracts, material and subcontractors: a prime/subcontractor condition that may prevent adequate protection or affect eligibility; rediscovery of terminated classified material; covered foreign classified contract negotiations/awards; or improper receipt of foreign classified material outside U.S. Government channels.
  • Incidents and oversight: loss, compromise or suspected compromise (preliminary inquiry, prompt initial report when confirmed, then final report); employee culpability findings and corrective action; qualifying cyber incidents for covered defense contractors; and duplicate CSA reviews or entity-eligibility processing (ISOO).

Route: file each report with the recipient and timing specified for that trigger—usually the CSA, with separate FBI, Government-site, customer, prime, DoD CSO or ISOO routes where the rule requires them. Subcontractors also notify the prime for §117.8(c)(7)–(10) reports. Use the detailed §117.8 table below for exact recipients, clocks and follow-through.

Industry criteria sources: SEAD 3 · DCSA NISPOM / SEAD 3 FAQs and ISL resources · DCSA SEAD 3 Industry Reporting Desktop Aid · 32 CFR §117.8.

A required report is not automatically an adverse findingSection 117.8 includes administrative and status changes, facility capability, contract and subcontract notices, rediscovered material, and other security-program events. Reporting means the rule requires notice to a named recipient; it does not, by itself, mean anyone acted improperly or that the information is adverse.

What ISL 2021-02 adds or clarifies for DoD-cognizant contractors

  • Written company procedure: maintain an SPP under §117.7(e) describing how personnel learn about SEAD 3 and adverse-information duties; how the company receives, processes and manages reports; how procedures operate at the facility; and how personnel report concerns about other covered people.
  • Who is covered: NISP personnel granted, or undergoing a determination for, classified eligibility through the NISP. A person subject to SEAD 3 only because of a sensitive Government position follows the Government customer’s route, not the NISP/ISL route.
  • Adverse-information examples: Table 1 clarifies defined psychological/emotional-health events and foreign-state-backed, hosted or managed cryptocurrency or wallets hosted by foreign exchanges. It also states exceptions, including lack of awareness and certain diversified-fund holdings.
  • SEAD 3 implementation details: Tables 2–4 clarify when official foreign contacts are not reportable, when unofficial FIE contacts and continuing relationships are reportable, personal-information exchanges with foreign nationals, peer reporting, foreign citizenship/passports, media contacts, arrests, treatment and debt. For Top Secret/Q personnel, Table 3 further identifies foreign-election voting; unusual financial gains (including an infusion of $10,000 or more); foreign business, bank accounts and property; qualifying cohabitation, marriage/civil unions/domestic partnerships, foreign-national roommates and adoption of non-U.S.-citizen children. Table 4 addresses unofficial foreign-travel reporting. Apply the exact table and category that covers the person; these clarifications are not all universal to every cleared employee.
  • Separate company report: employee self-reporting under SEAD 3 does not replace the contractor’s independent adverse-information report under §117.8(c)(1), nor any other applicable §117.8 report.

Individual → FSO or designated company channel

Covered employees report required personal events and activities under SEAD 3 as implemented for industry, including applicable foreign travel, foreign contacts, legal events, financial concerns and other specified matters. The FSO explains the current reporting process and timing.

FSO / contractor → CSA

The contractor reports the matters assigned to it by 32 CFR Part 117 and CSA procedure, including specified adverse information, suspicious contacts, security violations or incidents, loss or compromise, and required changes in facility or personnel status. Use the CSA’s designated system and preserve a record of submission.

Customer and contract routes

Check the DD Form 254, contract security clauses, program guidance and customer instructions for additional recipient or timing requirements. A customer report may be required in addition to the CSA report; do not assume forwarding one report completes the other.

Employment or affiliation ends

Update the person’s affiliation and access status in the required system, withdraw access and credentials, recover protected material, and conduct applicable debriefing. If relevant adverse information is learned after affiliation ends, assess the applicable CSA reporting duty and submit through the designated process.

IndividualFSO / company securityCSA systemCustomer or program office too, when required

Additional DoD-cognizant contractor criteria

ISL 2021-02: foreign cryptocurrency and mental-health reporting

These are defined SEAD 3 implementation criteria for covered cleared-industry personnel when DoD is the Cognizant Security Agency. They are not a rule to report every cryptocurrency holding or every instance of mental-health care. The employee reports qualifying events to the FSO/designee through the approved channel; the FSO submits the required DISS or successor-system report.

Foreign cryptocurrency interests

  • Report ownership of cryptocurrency backed, hosted or managed by a foreign state.
  • Report ownership of a cryptocurrency wallet hosted by a foreign exchange.
  • Do not report when you are unaware that the cryptocurrency is foreign-state-backed, hosted or managed, or unaware that the exchange hosting your wallet is foreign.
  • Do not report holdings through a widely diversified fund, such as an index fund, unless the instrument consists entirely of foreign-state-backed, hosted or managed cryptocurrency.
  • The FSO report records the cryptocurrency name, exchange-host country and dollar value.

Specified mental-health events

  • A court or administrative order finding the person mentally incompetent.
  • An order to consult with a mental-health professional.
  • Hospitalization for a mental-health condition.
  • A qualified professional’s diagnosis of psychotic disorder, schizophrenia, schizoaffective disorder, delusional disorder, bipolar mood disorder, borderline personality disorder or antisocial personality disorder.
  • Within the last seven years, altering, discontinuing or failing to start treatment for one of those diagnoses without first consulting a medical professional.
  • Current treatment details for one of those specified diagnoses.
  • Any mental or other health condition the individual believes substantially and adversely affects judgment, reliability or trustworthiness, whether or not symptoms are currently present.

A report is not itself an adverse adjudication or a direction to stop treatment. Handle sensitive details only through authorized, privacy-protective channels. Apply the exact ISL criteria and exceptions. Source: DCSA ISL 2021-02, revised May 2024, Table 1.

Contractor and FSO reports under 32 CFR §117.8

These are the contractor’s reporting duties. They are separate from an employee’s SEAD 3 self-report and from customer/program obligations. “Promptly,” “immediately,” and other clocks below are the rule’s wording; CSA instructions can specify submission mechanics or additional timing.

What the company must reportReporter / recipientTiming and required follow-throughAuthority
Covered-person reports required by SEAD 3 and DCSA guidanceEmployee → FSO/designee; contractor → CSA through DISS or its successor/designated channel.Apply the employee’s SEAD 3 category and event-specific timing. Maintain procedures to inform covered personnel, receive and manage reports, route required submissions and handle reports about other covered people. This is the company implementation duty; it does not replace the individual’s responsibility or other §117.8 reports.32 CFR §117.8(a); DCSA ISL 2021-02.
Actual, probable or possible espionage, sabotage, terrorism or subversive activity at any company locationContractor → nearest FBI field office; promptly notify CSA and give it a copy of the written report.Submit a written report promptly. An initial phone report is allowed but must be followed by a written report regardless of FBI disposition.32 CFR §117.8(b)(1)–(2).
Adverse information concerning an employee eligible for classified accessContractor through FSO/responsible official → CSA-designated personnel-security channel; if assigned to a U.S. Government location, also provide the location’s security POC a copy and final disposition.Report verified adverse information; do not report rumor or innuendo. Employment termination does not end the duty. Provide disposition/follow-up through the required channel. If information is learned after employment ends, §117.8(c)(1)(i) still applies.32 CFR §117.8(c)(1); DCSA ISL 2021-02.
Suspicious contacts, efforts to elicit protected information, attempted exploitation, or attempts to gain unauthorized facility/classified accessContractor/FSO → CSA; FBI or other authority as required by the circumstances and law.Report information about contacts with eligible employees and any person’s attempt to obtain unauthorized access, elicit information, or target an employee for foreign-intelligence exploitation. Capture who/what/when/how and follow CSA/CI instructions.32 CFR §117.8(c)(2); §117.8(b) when applicable.
Status change for an eligible employee: death, name change, termination of employment or change in citizenshipContractor through CSA-designated mechanism → CSA.Submit the status change; align personnel/access records and complete separation, debriefing and material recovery as applicable.32 CFR §117.8(c)(3).
Naturalization of an employee previously granted an LAAContractor → CSA.Report city/county/state, date, court and certificate number.32 CFR §117.8(c)(4).
Employee no longer wants an eligibility determination or no longer wants classified access/workContractor → CSA.Report the request and the employee’s reason. Do not treat it as an adjudicative denial.32 CFR §117.8(c)(5).
Employee refuses to sign SF 312 or another approved classified-information NDAContractor → CSA.Report refusal. Do not grant access without the required agreement.32 CFR §117.8(c)(6).
Change that may affect entity eligibility, personnel eligibility, insider-threat risk, safeguarding or classified-information statusContractor/FSO → CSA; customer/prime also when required by contract or rule.Report as required by the specific trigger: ownership/control or stock transfer; operating name/address of entity or cleared location; KMP changes; termination/reorganization/bankruptcy; material FOCI change or negotiations that may lead to foreign ownership/control (including applicable Schedule 13D); other validity-changing events. Submit updated SF 328 for material FOCI changes under CSA instructions. Subcontractors notify their prime for reports under §117.8(c)(7)–(10).32 CFR §117.8(c)(7), (c)(14); SF 328/CSA guidance.
Change in requirement or capability to store/safeguard classified materialContractor → CSA.Report changes in storage requirement or safeguarding capability; update the authorized storage/site records before relying on a changed capability.32 CFR §117.8(c)(8).
Emergency makes a location unable to safeguard classified materialContractor → CSA.Report as soon as possible; protect/recover information under emergency procedures and follow CSA direction.32 CFR §117.8(c)(9).
Prime/subcontractor conditions indicate classified information may not be adequately protected or entity eligibility may be affectedPrime, higher-tier subcontractor or subcontractor → its CSA; subcontractor also notifies prime when report is made under §117.8(c)(7)–(10).Report information indicating inadequate protection or another circumstance affecting the other entity’s eligibility. Coordinate contract/customer protection actions.32 CFR §117.8(c)(10), (c)(14).
Previously terminated classified material is found and returned to accountabilityContractor → CSA.Report the rediscovery and disposition so the accountability record is reconciled.32 CFR §117.8(c)(11).
Foreign classified contract negotiations or award not placed through a CSA/U.S. GCA that may disclose U.S. classified information or provide access to foreign classified informationContractor → CSA.Report during pre-contract negotiation or award when the trigger applies; do not disclose or accept classified information outside approved channels.32 CFR §117.8(c)(12).
Classified material received from a foreign interest outside U.S. Government channelsContractor → CSA.Report improper receipt and follow the CSA’s handling/disposition instructions.32 CFR §117.8(c)(13).
Loss, compromise or suspected compromise of U.S. or foreign classified informationContractor → CSA; if on a Government facility, also facility head; CSA notifies GCA under its process.Immediately start a preliminary inquiry and validate classification. If loss/compromise is confirmed, promptly send initial report unless CSA directs otherwise. After investigation, send final report with new material facts, responsible person when determined, corrective/disciplinary action and basis for conclusion. The CSA may specify timing.32 CFR §117.8(d)(1)–(4).
Employee culpability for security violation or negligenceContractor → CSA.Maintain a system to track violations/patterns and apply graduated administrative/disciplinary action. Submit final culpability report with findings and corrective/disciplinary actions when the responsible individual is determined.32 CFR §117.8(e)(1)–(3).
Cyber incident involving a classified covered information system, or other cyber event covered by contract/DFARSCovered defense contractor → designated DoD CSO for classified system event; use contract-required recipient for unclassified systems; other NISP/FBI/CSA routes may also apply.For a classified covered system, report immediately. Include incident technique/method, isolated malware sample if available, and potentially affected DoD program information. For non-Federal unclassified systems, follow contract terms. This paragraph applies to covered defense contractors and is not a universal rule for all entities.32 CFR §117.8(f); applicable DFARS clause/DoD instructions.
Duplicative CSA security review/audit or duplicate entity-eligibility processingContractor → Director, ISOO.Report the duplication for resolution and provide the records needed to identify the overlapping review/determination.32 CFR §117.8(g)(1)–(2).

NISPOM reporting is not a substitute for the individual’s separate SEAD 3 duty. The particular event, person’s status, contract and CSA instructions determine who files each report and where it goes.