Contract Security Classification Specification
Contract classification requirements and related security guidance. Start here for contract-specific questions.
Reference link checked 2026-09-12. Verify edition and applicability before use.From FSO Wiki — exported reference snapshot; revalidate before use
Personal reference wiki
Sources: approved DCSA Library
The FSO Knowledge Desk collects forms, common questions and reviewed answers for Facility Security Officers. Browse the forms directory, explore the topic index, or review sourced answers.
Articles distinguish accepted answers from drafts and retain source citations, user feedback and revision details. Questions awaiting research are listed to guide future additions.
WHS official directory: DD Forms 1–499 — use the listed form page to check its edition and download. Other form families retain their issuing-agency references.
Official reference links; inclusion does not mean every form applies to every facility.
Contract classification requirements and related security guidance. Start here for contract-specific questions.
Reference link checked 2026-09-12. Verify edition and applicability before use.Security agreement reference for the facility-clearance process.
Reference link checked 2026-09-12. Verify edition and applicability before use.Companion appendix to the security agreement; confirm its use for the entity's organization.
Reference link checked 2026-09-12. Verify edition and applicability before use.Individual nondisclosure agreement. Signing and access authorization are separate questions.
Reference link checked 2026-09-11. Verify edition and applicability before use.Foreign-interest disclosures. Use DCSA's currently linked form and instructions; verify submission-specific requirements.
Reference link checked 2026-09-11. Verify edition and applicability before use.Personnel investigation questionnaire. Review scope, handling and privacy belong in the accompanying Q&A.
Reference link checked 2026-09-11. Verify edition and applicability before use.Container information form reference; use the official listing for availability and instructions.
Reference link checked 2026-09-11. Verify edition and applicability before use.Activity security checklist reference; determine applicable local and agency requirements before use.
Reference link checked 2026-09-11. Verify edition and applicability before use.Security-container check-sheet reference and official form source.
Reference link checked 2026-09-11. Verify edition and applicability before use.Open-storage approval checklist and process guide are linked from DCSA's NISP resources page.
Reference link checked 2026-09-11. Verify edition and applicability before use.0 questions queued for source review. Queued questions have no approved answer yet.
Identify contract direction, classification guidance and subcontract responsibilities.
Distinguish eligibility, access, need-to-know and questionnaire handling.
Entity eligibility, foreign interests, ownership and key management personnel.
Separate individual disclosures, entity reporting and security incidents.
Storage, checks, visitors and access at other locations.
Use source guidance and distinguish original from derivative classification.
Contract-specific information protection and system responsibilities.
Run a documented security program and keep references current.
Reply in Codex with the question title and your agreement, disagreement or revised wording. Accepted revisions and original answers remain in history.
Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
After the normal two-year period, continued possession must have authorization. A follow-on DD 254 can authorize transfer to the new contract. Otherwise, request extended retention from the GCA, with a final DD 254 documenting the retention period and disposition. WHS also recognizes formal written GCA retention authorization, so those two form routes are not exclusive.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What happens to classified material when a contract ends?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Verify need-to-know, appropriate eligibility, a signed NDA and required briefings. Review the DD 254, attachments and classification guidance for the actual work, including government-client requirements flowed through the prime to subcontractors. Satisfy applicable contract and program requirements before granting access.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should I verify before granting an employee classified access?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Post-separation CSR procedure without a DISS relationship remains unverified.
No user wording supplied yet.
Awaiting feedback.
Report separation, document the debriefing and update access records. Departure does not end the duty to report relevant adverse information discovered afterward, including supported information concerning suspected timecard or employment fraud.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What must happen when a cleared employee leaves the company?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
The company issuing the subcontract DD 254 determines who is authorized to certify it. That person may be its FSO, a contracting official, or another authorized representative; certification is not reserved to a particular contractor job title. For a government-issued DD 254, the certifier is the contracting officer or an authorized representative.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Who prepares and revises a subcontract DD 254?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
The DD 254, its attachments and incorporated references communicate the classified contract’s security requirements. The FSO uses them to identify required clearance and safeguarding levels, performance locations, special access or handling requirements, and classification guidance. The form specifies requirements; it does not itself grant a clearance, approve storage, authorize employee access or confer original classification authority. The FSO must verify those prerequisites, resolve missing or conflicting guidance, and track revisions. It also does not replace applicable CUI or cybersecurity contract clauses.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What does DD 254 tell the FSO, and what does it not establish?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Request clarification from the GCA, coordinating through the prime where applicable. If unresolved, use the classification-challenge process. During that challenge, protect the information at the assigned or proposed classification level, whichever is higher.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should I do when the DD 254 conflicts with other contract instructions?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Evaluate new material for authority, applicability and actual change before revising procedures. NISPOM requires implementing applicable provisions and keeping employees informed of changes through refresher training. A new library release or VOI does not automatically prove a new legal obligation. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use Guidance Watch to compare relevant changes and trace any procedure update to controlling authority, contract terms or applicable CSA guidance. Preserve the old procedure and reason for revision. Conservative ISR perspective Treat release comparison and procedure versioning as local quality-control practices; do not label a newsletter or accepted wiki answer as controlling regulation. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Review the relevant approved sources, document the change decision and brief affected staff. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.7(e), (g); 117.12(k); pages 26, 57. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How should new VOIs, ISLs and library releases affect existing procedures?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer For self-inspections, record the review, findings and resolution, retain the report until after the next CSA review, and obtain the SMO annual written certification. That certification covers the inspection, KMP briefing, appropriate corrective action and management support. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use action owners, due dates and closure evidence as practical tracking tools; those tracking fields are a recommended method, not quoted mandatory form fields. Conservative ISR perspective Verify effectiveness before declaring an action closed or asking the SMO to certify it. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Maintain the report and supporting corrective-action evidence and brief management on unresolved items. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.7(h)(2)(i)-(iii); pages 27. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How do I document corrective actions and management involvement?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Provide an initial security briefing before classified access, security refresher education every 12 months, and initial/annual insider-threat awareness training. Derivative classifiers need initial training and refresher training at least every two years. Provide role-specific system training and required debriefings as applicable. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Tailor training to duties, track participation and retain the required records. Special programs or contract provisions can add requirements. Conservative ISR perspective An attendance list alone should not obscure overdue role-specific training; suspend derivative classification authority if the required refresher is overdue. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Reconcile the roster, roles and training dates against each applicable requirement. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.12(e), (g)-(l); pages 55, 56, 57. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What briefings and refresher training apply to cleared employees?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Conduct a formal self-inspection at least annually and at intervals consistent with risk. Cover classified activities and information, classified systems, the overall security program and insider threat, including samples of derivative-classification actions where applicable. Prepare a formal findings/resolution report and retain it through the next CSA security review. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Give the inspection adequate scope, depth, frequency and management support; examine real operations, not just whether a checklist is filled in. Conservative ISR perspective Verify that corrective actions actually address findings and that the SMO certification accurately reflects the review. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Plan the scope, record findings and resolutions, and obtain the required annual SMO certification. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.7(h)(2)(i)-(iii); pages 27. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should an FSO self-inspection cover?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer For suspected classified-information contamination, coordinate immediately through the FSO and ISSM/ISSO using the established spill and incident procedures. The program must include assessment, reporting, isolation, containment, sanitization and recovery procedures. Reporting may also be required under 117.8; unclassified-system cyber reporting depends on the contract. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use the incident plan and qualified responders; avoid ad hoc copying or cleanup that could spread the information or interfere with the investigation. Conservative ISR perspective Preserve the incident record and obtain the appropriate technical and security direction before recovery. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Notify the designated incident contacts and follow the approved containment and reporting process. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.18(b)(2), (c)(2)-(3); 117.8(d), (f)(2); pages 32, 34, 83, 84, 85. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Who should coordinate suspected information-system contamination?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Actual contract, modifications, system boundary and authorizations were not provided.
No user wording supplied yet.
Awaiting feedback.
Short answer The exact clauses and authorizations cannot be determined without the actual contract, modifications, information types and system scope. For contractor systems handling classified information, apply 117.18 and CSA guidance; for unclassified systems, identify the actual contractual requirements rather than assuming the classified-system authorization applies. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Collect the contract clauses, flowdowns, security specification and system boundary/authorization documents. This is a scoping answer, not a determination that any particular DFARS clause applies. Conservative ISR perspective Do not substitute a generic cybersecurity checklist for the actual authorization scope and contract terms. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Have the contracting lead and ISSM or information-security lead reconcile the contract and system documentation. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(f)(2); 117.18(a)-(c); pages 34, 83, 84, 85. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Limited / incomplete: Actual contract, modifications, system boundary and authorizations were not provided. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Which contract clauses and system authorizations apply to this work?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer No. The DD 254 is a classified-contract security specification, and NISPOM does not by itself supply every CUI cybersecurity obligation. Determine CUI protections from the applicable contract requirements and incorporated authorities, including relevant flowdowns. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Read the contract clauses, attachments, modifications and scope of information processing; do not treat the DD 254 as the entire cybersecurity contract. Conservative ISR perspective Keep a documented mapping of each applicable obligation to the contract or controlling authority. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Review the contract with the contracting and information-security leads before selecting controls. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.7(h)(1)(iii); 117.15(l); 117.17(a)(1)(iii); pages 27, 77, 81. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Does a DD 254 alone establish all CUI cybersecurity requirements?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Do not infer that Government-furnished information is unrestricted simply because its CUI marking is absent or unclear. Seek written clarification from the contracting activity about designation, applicable authority and handling. Do not invent a CUI category merely because information seems sensitive; continue the protections that actually apply while resolving the ambiguity. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Review the contract and known information provenance. The CUI rule addresses unmarked information that qualifies as CUI; absence of a marking does not alone settle its status. Conservative ISR perspective Document the uncertainty, interim handling and government determination rather than treating the FSO preference as designation authority. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Ask the contracting activity to identify the information and the governing handling requirements. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.15(l); 32 CFR 2002.20(m), 2002.22; pages 77. Local source: [local source path omitted; use document ID and locator below] 2. dcsa-cfr-32cfr-2002-cui (regulation); page:17;chars:0-4745. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should I do when Government-furnished information is unmarked or ambiguously marked as CUI?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer First request a remedy from the GCA. If none is provided and correction is still needed, make a formal written challenge describing the issue, reasons and recommended correction. Request CSA assistance if no written GCA answer arrives within 60 days; an appeal through ISOO to ISCAP is available if no GCA response arrives within 120 days. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Continue protection at the assigned or proposed classification level, whichever is higher, while the challenge is pending. Conservative ISR perspective Preserve the dated challenge and responses so the escalation timeline can be demonstrated. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Prepare the issue, rationale and recommendation, then track the written response. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.13(e)(1)-(5); pages 59, 60. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How are classification challenges raised and documented?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Notify the GCA when a classified contract lacks its required security classification specification; if it does not provide one, notify the CSA. For improper or inadequate guidance, request a remedy and use the classification-challenge process if needed. During a challenge, safeguard at the assigned or proposed level, whichever is higher. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Describe the missing or conflicting instruction and affected information. Do not invent a classification decision to fill the gap. Conservative ISR perspective Retain the request, interim handling basis and eventual written response. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Request the specific guidance from the GCA and track escalation under the applicable process. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.13(d)(4)(iii), (e); pages 59, 60. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should I do when classification guidance is missing or ambiguous?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Derivative classification rests on OCA guidance: a properly marked source document or a current security classification guide supplied by the GCA. It applies when existing classified information is incorporated, paraphrased, restated or generated in a new form. Mere duplication is not derivative classification. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Carry forward required markings and identify sources. A source with an approved no-portion-marking waiver and a warning prohibiting derivative use cannot be used as a derivative source. Conservative ISR perspective Retain traceability to the actual guidance and ensure the classifier training is current. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Check the source, applicable markings and required training before issuing the document. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.13(b), (c); 117.12(h); pages 56, 57, 58. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What sources support derivative classification?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Only a USG official designated or delegated original classification authority in writing may make an original classification decision. Being an FSO, a cleared employee or a derivative classifier does not itself confer that authority. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use authorized source guidance for derivative work; submit genuinely new classification issues to the responsible government authority. Conservative ISR perspective Keep the distinction between interpreting existing guidance and creating an original classification decision explicit. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Identify the governing classification guide or request the GCA determination. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.13(a), (b); pages 57. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Who may make an original classification decision?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Protect an unsecured container and its contents against further access, notify the FSO and initiate the preliminary inquiry required for a classified-information security violation. Finding a container open does not by itself establish the final compromise finding; the inquiry must determine the circumstances and reporting requirements. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Record the condition, timing and potential access without unnecessarily handling or distributing the contents. Check whether combination changes are required under the applicable standards. Conservative ISR perspective Preserve the record and investigate potential exposure; do not merely close the container and erase the incident. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Apply the loss/compromise inquiry and reporting procedure and document corrective action. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(d); 117.15(c), (e)(4); pages 32, 66, 71. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How do I address a security container found unsecured?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Before disclosing classified information during a visit, verify positive identification, appropriate personnel eligibility and need-to-know. The visit must be necessary, and access must remain consistent with its purpose. The person disclosing the information determines need-to-know. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Verify eligibility through the CSA-designated database or an employer-provided visit authorization as applicable; confirm any additional program or foreign-visit conditions. Conservative ISR perspective A visit letter does not replace the host need-to-know determination. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Reconcile the visitor identity, authorization, purpose and information to be discussed. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.16(a)(1)-(4); pages 77. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What must be checked before a classified visit?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Current DCSA 147 instructions and proposed site approval conditions require verification.
No user wording supplied yet.
Awaiting feedback.
Short answer Use classified storage only within the safeguarding capability approved by the CSA. Open storage must meet the applicable construction and protection standards. DCSA 147 is a process/checklist reference; possession or completion of a checklist is not itself storage approval. The current DCSA 147 instructions were not verified in the approved retrieval for this answer. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Confirm the proposed area, classification level, construction and protection requirements with the CSA before storing classified information there. Conservative ISR perspective Retain the actual approval and its conditions rather than relying on a blank or completed checklist. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Obtain current process instructions and written approval for the intended safeguarding capability. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.9(a)(3), (a)(6); 117.15(c); pages 34, 35, 66. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Limited / incomplete: Current DCSA 147 instructions and proposed site approval conditions require verification. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question When is open-storage approval needed and where does DCSA 147 fit?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer SF 700 records security-container information; SF 701 supports an end-of-day activity security inspection; SF 702 records who opened, closed or checked a container and when. They serve different purposes. Their use and handling must follow the applicable agency/CSA and contract requirements; the form definitions alone do not impose every agency procedure on every contractor. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use the form suited to the activity. Do not place combinations or completed sensitive forms in the wiki. Conservative ISR perspective Confirm local requirements and protect combination information at the required level. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Check the official form instructions and the facility safeguarding procedures. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.15(b), (c), (e)(4); 32 CFR 2001.80 (form descriptions); pages 66, 71. Local source: [local source path omitted; use document ID and locator below] 2. dcsa-cfr-32cfr-2001-classified-national-security-info (regulation); page:41;chars:0-4648. Local source: [local source path omitted; use document ID and locator below] 3. dcsa-cfr-32cfr-2001-classified-national-security-info (regulation); page:41;chars:4479-9221. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How do SF 700, SF 701 and SF 702 differ?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Documentation depends on the reporting category. For loss or compromise, the final report must add relevant information, identify responsible individuals as required, describe corrective and disciplinary actions, and explain the conclusion. A general reporting log is a useful practice, but this answer does not establish one universal retention period for all reports. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Track what was reported, when, to whom, acknowledgments and outstanding actions, with appropriate protections for the information. Conservative ISR perspective Keep the factual record separate from speculation and use a protected case record rather than this public-style wiki for personal details. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Identify the governing report category and apply its content and retention instructions. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(a)(2)-(4), (d)(3), (e)(1)-(2); pages 29, 32, 33. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How should reporting actions and follow-up be documented?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Secure the information against further exposure and immediately initiate a preliminary inquiry upon receipt of a security-violation report involving classified information. If the inquiry confirms loss, compromise or suspected compromise, promptly submit the initial report unless the CSA directs otherwise; submit the final report when the investigation is complete. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Validate the classification and circumstances. Follow any additional CSA reporting time requirements and notify the head of the USG facility as applicable. Conservative ISR perspective Preserve the facts and avoid delaying a required initial report until every investigation detail is known. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Contact the FSO, protect the affected material and begin the documented inquiry. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(d)(1)-(3); 117.15(a); pages 32, 65. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What should I do first after suspected loss or compromise?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Complete current SEAD 3/CSA travel and contact reporting categories, deadlines and exceptions remain unverified.
No user wording supplied yet.
Awaiting feedback.
Short answer Foreign-travel and contact reporting must be evaluated under SEAD 3 and applicable CSA implementation guidance. NISPOM specifically requires reporting suspicious contacts, including attempted unauthorized access or elicitation, regardless of nationality. This research has not established a complete current travel/contact matrix or its timing exceptions. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Do not use nationality alone as the test for suspicious contact. For routine foreign travel or ongoing contacts, verify the applicable SEAD 3 category and CSA instructions before stating a deadline or exemption. Conservative ISR perspective Treat a missing current reporting matrix as an evidence gap, not permission to omit a report. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Obtain the approved current SEAD 3 implementation guidance and verify the employee category and travel/contact facts. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(a), (c)(2); pages 29, 30. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Limited / incomplete: Complete current SEAD 3/CSA travel and contact reporting categories, deadlines and exceptions remain unverified. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Which foreign travel or foreign contacts require reporting?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Evaluate facts against 32 CFR 117.8, SEAD 3 and applicable CSA guidance. Report adverse information concerning employees eligible for classified access; do not report solely on rumor or innuendo. The contractor supplies relevant facts rather than making the government eligibility determination. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Distinguish observed facts, supporting records and unverified assertions. Departure does not remove an otherwise applicable reporting duty. Conservative ISR perspective Preserve the factual basis and reporting decision, and avoid treating an internal resolution as a substitute for a required report. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Use the designated reporting route and obtain clarification on a genuinely uncertain trigger. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(a), (c)(1); 117.10(a)(1); pages 29, 30, 39. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question How should an FSO evaluate potentially adverse information?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Current DD 441/DD 441-1 instructions and submission-specific checklist still require verification.
No user wording supplied yet.
Awaiting feedback.
Short answer The evidence establishes that the CSA assesses the entity business structure and requires requested documentation, identification of the SMO, FSO and ITPSO, and processing of applicable KMP. It does not establish a single universal attachment checklist for DD 441 and DD 441-1. The current form instructions and CSA package requirements must be checked. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Use the CSA-requested entity package and reconcile its names and organization details with the agreement. Do not infer that an illustrative document list is exhaustive. Conservative ISR perspective Keep the signed agreement and original CSA-designated forms according to the applicable retention requirements. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Verify the current WHS form instructions and the CSA checklist before submitting the package. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.9(d)(1), (p); pages 36, 39. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Limited / incomplete: Current DD 441/DD 441-1 instructions and submission-specific checklist still require verification. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What documents support DD 441 and DD 441-1?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer Report changes in ownership or control, operating name or address, previously submitted KMP information, relevant business termination or reorganization, and material changes in FOCI information. Discussions that may reasonably lead to effective foreign ownership or control also require written reporting to the CSA. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Apply the precise reporting category and current CSA submission instructions; identify replaced KMP and the required updated information. Conservative ISR perspective Do not wait until a foreign-control transaction closes to consider the reporting trigger. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Route the proposed change to the FSO and appropriate corporate officials early and preserve the report. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.8(c)(7); pages 31. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Which ownership or management changes must be reported?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Short answer A facility clearance is an entity eligibility determination; a personnel clearance concerns an individual eligibility determination. Neither alone establishes every condition for actual access. Entity eligibility is also separate from approved classified safeguarding capability. FSO practical answer Assumption: ordinary NISP contractor work; no specific contract or special-program direction was supplied. Verify the entity, the person, the information level and the need-to-know separately. Conservative ISR perspective Avoid treating a cleared company as permission for every employee to see classified information or for any site to store it. This is a conservative review approach, not a statement from an individual ISR. Recommended next steps Check entity eligibility and storage capability, then apply the employee access prerequisites. Sources 1. dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026 (regulation); 117.9(a)(1)-(4); 117.10(a)(1); pages 34, 39, 40. Local source: [local source path omitted; use document ID and locator below] Confidence / unresolved issues Moderate: the general rule is supported by the approved robot corpus; specific contract, program and CSA conditions still need applicability review. Do you agree with this answer, or do you have changes or revisions before I save it as an accepted answer in your Q&A wiki?
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What is the difference between a facility clearance and a personnel clearance?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Revision responding to user feedback on revisions 2-3 (annual certification). Verified from the official SF 328 (REV. 7/2026) as supplemental evidence; the approved library still lacks the 7/2026 form and current DCSA SF 328 guidance (Custodian intake gap). Certification timing and submission channel remain unverified CSA guidance. No source-review attestation recorded because material propositions rely on non-library evidence.
No user wording supplied yet.
Awaiting feedback.
Short answer A company must submit an SF 328 during the process for an entity eligibility determination (for example, a facility clearance) and must update it when significant changes occur to the information previously submitted. The current form, SF 328 (REV. 7/2026), also requires an annual certification affirming that previously submitted responses have not changed, in accordance with guidance from the reviewing CSA. Negotiations toward a foreign merger, acquisition or takeover require a separate written notice to the CSA. FSO practical answer 1. Initial submission (must): complete an SF 328 during the entity eligibility determination process (32 CFR 117.11(c)). A corporate family may submit a consolidated response based on CSA guidance. 2. Material change (must): when significant changes occur to information previously submitted, update the SF 328 (117.11(c)). Any material change to previously reported FOCI information is a reportable changed condition, reported by submitting an updated SF 328 in accordance with CSA-provided guidance, without repeating unchanged answers (117.8(c)(7)(v)). The current form adds that the update must include a complete explanation of how FOCI has changed since the last submission. 3. Annual certification (current form, supplemental evidence): the SF 328 (REV. 7/2026) instructions state that annual certification is required to affirm that previously submitted responses have not changed, in accordance with guidance from the reviewing CSA. Part 117 does not itself state this general requirement; its annual certification in 117.11(i)(2) is a separate implementation and compliance report for contractors under a voting trust, proxy agreement, SSA or SCA. Get the certification timing and submission method from DCSA guidance. 4. Related notices (must, if applicable): report in writing to the CSA discussions, consultations or agreements that may reasonably lead to effective foreign ownership or control, and forward any Schedule 13D received (117.8(c)(7)(v)). Notify the CSA when negotiations begin for a proposed merger, acquisition or takeover by a foreign interest, with the details and documents listed in 117.11(c)(2). 5. Other uses of the form (supplemental evidence): the current form states it is also collected for eligibility to be awarded or continue performing certain Department of War contracts (section 847 of Public Law 116-92) and for the DoW Enhanced Security Program. If a contracting activity requests the form for those purposes, follow that request and its instructions. Strict compliance reading Read strictly, the company should use the current form edition (the form states the previous edition is obsolete) and keep a dated record of each submission, each annual certification and each materiality decision. It should report promptly after a change occurs rather than waiting for the next annual certification, and should treat an unresolved question about whether a change is significant as a reason to ask the CSA in writing. This is the strictest defensible reading, not a position of DCSA or any ISR. Recommended next steps 1. Obtain the SF 328 (REV. 7/2026) and read its instructions. 2. Confirm with your DCSA ISR or the FOCI office when the annual certification is due and how to submit it. 3. Set a recurring review of FOCI facts against the last submitted SF 328, and document each materiality decision. 4. Ask the Custodian to add the 7/2026 SF 328 and current DCSA SF 328 guidance to the approved library. Sources Primary, approved local library (release nist-172-r3-intake-20260911): - 32 CFR Part 117 (up to date as of 7/24/2026), controlling regulation (document ID dcsa-cfr-32-cfr-part-117-up-to-date-as-of-7-24-2026): 117.11(c) and (c)(2), page 47; 117.8(c)(7)(v), page 31; 117.11(i)(2), page 54. Supplemental external sources (not in the library): - Standard Form 328, Certificate Pertaining to Foreign Interests (REV. 7/2026, updated 2026-07-08; OMB 0704-0579): instructions on Annual Certification and Material Change, and the authority statement. Official form page: https://www.gsa.gov/reference/forms/certificate-pertaining-to-foreign-interests Confidence / unresolved issues High for the Part 117 initial-submission and material-change triggers. Moderate-high for annual certification: the requirement is stated in the official 7/2026 form but is not yet in the approved library. Unresolved: the certification due date, submission channel, effective date for entities already on file, and any related Industrial Security Letter. Whether a particular change is significant depends on the facts.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question When must a company submit or update SF 328?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
Signing the NDA alone does not authorize classified access. The employee also needs valid need-to-know and favorable eligibility at the appropriate level; access must remain within the contractor's clearance and applicable contract/program requirements. Based on 32 CFR 117.10(a)(1)(iii) and (g).
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Does signing SF 312 by itself authorize access to classified information?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
No user wording supplied yet.
Awaiting feedback.
The FSO or designated reviewer reviews it for adequacy and completeness, provides the required written notice, and must not share its information within the entity or use it for another purpose. A management request does not change that restriction. Based on 32 CFR 117.10(d)(1)-(2); separate reporting duties require separate analysis.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question May an FSO share an employee's SF 86 with management for other purposes?: Agree / Disagree / My revision: ...Source release needs revalidation · nist-172-r3-intake-20260911
Resolves the annual-certification point raised on 'When must a company submit or update SF 328?' using the official SF 328 (REV. 7/2026) as supplemental evidence. Custodian gap: the approved library holds no copy of the 7/2026 form or current DCSA SF 328 guidance; the certification cadence and submission mechanics remain CSA guidance not yet in the library.
No user wording supplied yet.
Awaiting feedback.
Previously answered? Partly. The FSO Wiki has a related draft, "When must a company submit or update SF 328?" Your review of that draft asked that it cover the new form's annual certification; that point was unverified until now. This answer covers the update requirements and resolves that point. Short answer Under 32 CFR Part 117, an entity must update its SF 328 when significant (material) changes occur to FOCI information it previously submitted, and it reports those changes by submitting an updated SF 328 in accordance with CSA guidance, without repeating unchanged answers. The current form, SF 328 (REV. 7/2026), adds two requirements of its own: a material-change update must include a complete explanation of how the organization's FOCI has changed since its last submission, and an annual certification is required to affirm that previously submitted responses have not changed, in accordance with CSA guidance. Negotiations toward a foreign merger, acquisition or takeover trigger a separate written notice. FSO practical answer 1. Trigger (must): 32 CFR 117.11(c) requires an SF 328 during the entity eligibility determination and when significant changes occur to information previously submitted. 32 CFR 117.8(c)(7)(v) makes any material change to previously reported FOCI information a reportable changed condition. 2. Method (must): report the change by submitting an updated SF 328 "in accordance with CSA-provided guidance"; it is not necessary to repeat answers that have not changed (117.8(c)(7)(v)). A corporate family may use a consolidated response based on CSA guidance (117.11(c)). 3. Content of the update (current form, supplemental evidence): use the REV. 7/2026 edition, since the form states the previous edition is obsolete. Include a complete explanation of how FOCI changed since the last submission. Any response that references supporting documentation must give the document's name and date. Responses that miss the form's mandatory items are treated as incomplete. The certification must be signed by a person duly appointed with authority to bind the entity, with a witness signature. The completed form is CUI. 4. Annual certification (current form, supplemental evidence): the form states that annual certification is required to affirm that previously submitted responses have not changed, in accordance with guidance from the reviewing CSA. Part 117 itself does not contain this general requirement; its only annual certification, in 117.11(i)(2), is the implementation and compliance report for contractors under a voting trust, proxy agreement, SSA or SCA. Treat the form's instruction as current, and get the timing and submission method from DCSA guidance. 5. Related notices (must, if applicable): when discussions, consultations or agreements may reasonably lead to effective foreign ownership or control, report the details to the CSA in writing, and forward any Schedule 13D received (117.8(c)(7)(v)). For negotiations toward a foreign merger, acquisition or takeover, 117.11(c)(2) requires notice of the negotiations, including the transaction type, the potential foreign investor's identity and a FOCI mitigation plan, with the listed agreements and organizational documents. Also report associated changes such as ownership or control, KMP, name or address under 117.8(c)(7)(i)-(iii). Strict compliance reading Read strictly, the entity should use the current form edition, document the basis for deciding whether a change is material, and submit promptly after the change. The submission should include a narrative explaining what changed and named, dated supporting documents, and the entity should retain proof of each annual certification. When in doubt, report or ask the CSA in writing rather than deciding a change is immaterial. This is the strictest defensible reading, not a position of DCSA or any ISR. Recommended next steps 1. Download the current SF 328 (REV. 7/2026) and read its instructions in full. 2. Compare current facts with the last submitted SF 328 and document the materiality decision. 3. Confirm with your DCSA ISR or the FOCI office the annual-certification timing and submission channel, and whether a change also requires 117.11(c)(2) negotiation notice. 4. Retain the submitted form, change narrative, supporting documents and any CSA correspondence. 5. Ask the Custodian to add the 7/2026 SF 328 and current DCSA SF 328 guidance to the approved library. Sources Primary, approved local library (release nist-172-r3-intake-20260911): - 32 CFR Part 117 (up to date as of 7/24/2026), controlling regulation: 117.11(c) and (c)(2), page 47; 117.8(c)(7)(i)-(v), page 31; 117.11(i)(2), page 54; 117.5(a), page 20. Local source: [local source path omitted; use document ID and locator above] Supplemental external sources (not in the library): - Standard Form 328, Certificate Pertaining to Foreign Interests (REV. 7/2026, updated 2026-07-08; OMB 0704-0579), form instructions on Annual Certification and Material Change, plus the certification block. Official form page: https://www.gsa.gov/reference/forms/certificate-pertaining-to-foreign-interests Confidence / unresolved issues High for the Part 117 update trigger and method. Moderate-high for the form's annual-certification and change-narrative requirements: the wording was read directly from the official 7/2026 form, but it is not in the approved library. Unresolved: the annual certification's due date, submission channel (for example NISS), effective date for entities already on file, and any related Industrial Security Letter. DCSA's guidance pages blocked automated access, so confirm these with your ISR. Whether a specific change is material depends on the facts.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question What is required for an SF 328 update?: Agree / Disagree / My revision: ...Source release needs revalidation · dd254-dec1999-lifecycle-fix-20260915
No user wording supplied yet.
Awaiting feedback.
There is no fixed time limit for maintaining an employee’s eligibility record under a contractor’s DISS Security Management Office (SMO) merely because the employee is not currently performing classified work. The important distinction is whether a continuing requirement for classified access exists. If that requirement has ended but the contractor reasonably expects future classified access, the contractor should remove the access entry while retaining the SMO affiliation and continuing required vetting, reporting, and training; DCSA sets no fixed deadline for restoring access under that arrangement. If future classified access is not reasonably expected, the contractor should follow the out-processing procedure unless a separate, legitimate unclassified duty supports continued SMO affiliation. DCSA permits such affiliation for purposes including unclassified system access and positions of trust, with the Government Contracting Activity responsible for funding, submitting, and managing those investigations. A customer’s requirement for an “active T3” therefore needs to be clarified in writing: a T3 investigation, favorable adjudication, clearance eligibility, and classified access are distinct, and a CUI-related investigation requirement alone does not establish a need for classified access. The FSO should maintain accurate DISS records and document the basis for each access entry and SMO relationship. This follows 32 CFR 117.10(a)–(b) and (i), 117.12(l), and [DCSA’s DISS Management guidance, pages 1–3](https://www.dcsa.mil/Portals/128/Documents/CTP/tools/Guidance%20for%20DISS%20Management%20Final%2020250127.pdf); the specific customer’s T3 requirement must still be verified.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question how long should a clearance be maintained in DISS if there is no active cleared work: Agree / Disagree / My revision: ...Source release needs revalidation · release-change-summaries-20260919
No user wording supplied yet.
Awaiting feedback.
**Short answer:** No. A location where only CUI is handled does not belong in the DD Form 254's classified performance blocks (Item 8, or Item 7 for a subcontractor). Item 8 covers only locations where classified information is accessed and stored, or only accessed. Listing a location there limits classified performance to the listed locations, so adding a CUI-only site would misstate where classified work happens. On a DD 254, CUI is handled through Items 10j and 11l, plus GCA-provided protection guidance in Item 13. That applies only when the classified contract also requires CUI. Where CUI may be handled is governed by the contract's CUI requirements, not by the NISPOM. **FSO practical answer** - *Must:* Comply with the CUI protection and CUI training provisions that a classified contract includes. Part 117 says these are outside the NISPOM but still binding as contract requirements (32 CFR 117.15(l); 117.12(f)). - *Should:* Keep Items 6 through 8 limited to cleared facilities and locations with classified access or storage. The instructions define Item 8 as all locations where classified information will be accessed and stored, or only accessed. They also warn that an Item 8 entry limits all classified performance to the listed locations (DD 254 Instructions, Item 8 and 8(2)). - *Should:* Confirm that Items 10j and 11l are marked and that Item 13 contains the GCA's CUI protection guidance. The instructions say the NISPOM gives no CUI guidance, so the GCA must supply the protection procedures in Item 13 (DD 254 Instructions, Items 10j and 11l). If the GCA's guidance or the contract requires you to identify the sites or systems where CUI is processed, follow that requirement. It comes from the contract, not from Item 8. - *May:* The CUI location does not need a facility clearance just because it handles CUI. CUI does not include classified information (32 CFR 117.3, definition of CUI), and the NISPOM's safeguarding rules for classified information do not reach it. - Designation stays with the Government. Do not treat material at that site as CUI, or as unrestricted, unless the contracting activity has identified it. Send ambiguous cases back to the contracting activity for a written determination. **Strict compliance reading:** The strictest reading is to leave Items 7 and 8 as the cleared or classified-performance locations only. It also requires every CUI obligation, including any site-location or information-system requirement, to be traceable to the contract, its clauses, or the GCA's Item 13 guidance. Records that show compliance: the DD 254 with Items 10j, 11l and 13 completed; the contract's CUI clauses; and written GCA or contracting officer direction on any CUI handling locations. If Items 10j and 11l are marked but Item 13 is blank, request the missing guidance in writing rather than filling it in yourself. **Recommended next steps** 1. Check the contract and its clauses for CUI safeguarding or information-system requirements that cover the additional location. 2. Confirm that Items 10j, 11l and 13 reflect the CUI requirement. If the guidance is missing or unclear, ask the GCA or contracting officer in writing. 3. If you issue subcontract DD 254s, apply the same rule: list only cleared, classified-performance locations in Items 7 and 8, and flow down the CUI guidance through Item 13. 4. Keep the GCA's written answer with the contract security file.
None
Reply in Codex using the question title. No response leaves this draft unaccepted.
For question Should our DD254s identify the additional corporate location because CUI is handled there, even though classified information is not?: Agree / Disagree / My revision: ...