Written and maintained by CASRAI Editorial Board
Last updated
32 CFR Part 117 is the codified National Industrial Security Program Operating Manual (NISPOM) — the federal regulation that governs how contractors, including universities, must safeguard classified national security information under contract with the U.S. government. For research institutions that hold or are pursuing classified research contracts, NISPOM compliance is not optional guidance; it is a binding regulatory condition of holding a facility clearance, enforced through a signed security agreement with the government.
This guide covers what 32 CFR Part 117 actually requires, who at a university needs to know about it, how it differs from export control regimes like ITAR and EAR that research offices more commonly encounter, and where NISPOM obligations intersect with the broader research-security landscape. You can read the current regulatory text directly at eCFR’s Part 117 page, which reflects the amendments described below.
What 32 CFR Part 117 is and where it came from
NISPOM began in 1995 as DoD guidance issued through a series of Department of Defense manuals (most recently DoD 5220.22-M), not as a standalone federal regulation. That changed on December 21, 2020 (85 FR 83300), when the rule was published in the Federal Register, and it took effect as a binding federal regulation — 32 CFR Part 117 — on February 24, 2021, with a compliance deadline of August 24, 2021. Codifying NISPOM as a Code of Federal Regulations part (rather than leaving it as internal DoD guidance) gave it the direct force of law across all agencies participating in the National Industrial Security Program (NISP), not just the Department of Defense. NISPOM has been amended more than once since that initial codification — see “What has changed since the 2021 codification” below for the dated, sourced list.
The NISP itself predates the CFR codification by decades — it was established by Executive Order 12829 (1993) to create a single, uniform system across the federal government for safeguarding classified information held by contractors, rather than each agency running its own parallel security program. 32 CFR Part 117 is the operating manual for that system.
What has changed since the 2021 codification
| Date | Federal Register citation | Status | What it did |
|---|---|---|---|
| Aug 19, 2021 | 86 FR 46597 | Final rule, effective on publication | Technical amendment to the newly-codified NISPOM text. |
| Dec 13, 2023 | 88 FR 86288 | Proposed rule — comment period closed Feb 12, 2024 | Would clarify FSO citizenship requirements and review cadence (§117.7), add a FOCI facilities-location-plan requirement (§117.11), and expand safeguarding/reproduction-accountability procedures (§117.15). Not adopted as a final rule as of this writing — the current eCFR text linked below is the authoritative source for what is actually in force. |
eCFR’s current text also reflects revisions to several individual sections dated after the original 2021 codification. Because NISPOM has moved more than once since 2021 and a proposed further amendment is still pending, check the current eCFR text directly before relying on a specific section number or paragraph letter for anything more than the general framework described here.
Who this applies to at a university
NISPOM applies to any entity that holds, or is applying for, a Facility Clearance (FCL) — formal government authorization for a specific facility to access classified information at a defined level (Confidential, Secret, or Top Secret). A university becomes subject to NISPOM when one of its facilities (often a specific lab, research center, or federally funded research and development center rather than the institution as a whole) needs an FCL to perform a classified contract or subcontract, most commonly for the Department of Defense, Department of Energy, NASA, or the intelligence community.
Within a cleared university facility, several roles carry direct NISPOM obligations:
- Facility Security Officer (FSO) — the individual NISPOM requires every cleared facility to designate, responsible for implementing and administering the facility’s security program day to day.
- Insider Threat Program Senior Official (ITPSO) — a senior management official NISPOM requires to be designated to establish and lead the facility’s insider threat program.
- Key Management Personnel (KMP) — officers, directors, and other individuals whose positions give them the ability to adversely affect the facility’s classified contract performance; NISPOM requires most KMP to hold a personnel clearance or be formally excluded from access.
Research administrators, grants and contracts offices, and export-control officers are typically not the ones executing NISPOM’s day-to-day security requirements — that sits with the FSO and security office — but they need to recognize when a proposed award triggers an FCL requirement, since it changes the compliance posture and reporting obligations for that specific facility well beyond ordinary sponsored-research administration.
What NISPOM actually requires
32 CFR Part 117 sets out the standard procedures a cleared contractor facility must follow across the classified-information lifecycle. Core elements include:
- Facility and personnel clearances (FCL/PCL) — the process and standards for a facility, and the individuals working within it, to be authorized to access classified information at a given level.
- The Insider Threat Program — a mandatory program to detect, deter, and mitigate risks posed by cleared personnel, including monitoring, employee reporting obligations, and coordination with counterintelligence and security offices. This became a formal NISPOM requirement following a 2016 DoD change and carried through into the 32 CFR Part 117 codification.
- Safeguarding requirements — physical security, storage, transmission, and destruction standards for classified material, scaled to classification level.
- Security training and briefings — initial and refresher training obligations for cleared personnel.
- Reporting requirements — including the adverse-information and foreign-contact reporting obligations that 32 CFR Part 117 aligned with Security Executive Agent Directive (SEAD) 3.
- Foreign Ownership, Control, or Influence (FOCI) — provisions (117.11) addressing how a facility must identify and mitigate foreign ownership or influence that could affect its ability to protect classified information, a provision with particular relevance for universities with significant international funding, partnerships, or leadership ties.
The Defense Counterintelligence and Security Agency (DCSA) serves as the Cognizant Security Agency (CSA) for most NISP facilities, including the great majority of cleared university facilities, and conducts the oversight inspections that verify NISPOM compliance. When a facility is granted an FCL, the institution signs DD Form 441, the DoD Security Agreement, formally committing to follow NISPOM’s requirements as a condition of the clearance.
NISPOM vs. export control (ITAR/EAR): a common point of confusion
NISPOM and export control are related but distinct compliance regimes, and research offices frequently conflate them because both restrict the flow of sensitive technical information and both matter heavily for classified or dual-use research programs.
- NISPOM (32 CFR Part 117) governs how a cleared facility protects classified national security information it has been authorized to access under a specific contract — it is fundamentally about facility and personnel security clearances and safeguarding practices.
- Export control — the International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) — governs the transfer of controlled technology, technical data, and defense articles, including ‘deemed exports’ to foreign nationals working in a U.S. lab, regardless of whether classified information or a facility clearance is involved at all.
A university research program can be subject to export control obligations without ever touching classified information or holding an FCL, and it can hold an FCL for one program while a completely different lab down the hall is separately subject to ITAR/EAR for unclassified but controlled technology. The two frameworks require separate compliance infrastructure, though in practice both often report through the same institutional research-security or export-control office. See CASRAI’s guide to Export Control (EAR/ITAR) and International Research Collaboration for how the export-control side works.
How NISPOM fits into the broader research-security landscape
NISPOM sits alongside, but is legally distinct from, several other frameworks universities engaged in sensitive or federally funded research increasingly encounter:
- Controlled Unclassified Information (CUI) requirements, which govern unclassified-but-sensitive information under a separate framework (32 CFR Part 2002 and agency-specific rules such as DFARS 252.204-7012), split into CUI Basic and CUI Specified handling categories, and typically implicate CUI safeguarding and cybersecurity controls like NIST SP 800-171 rather than NISPOM’s classified-information framework.
- Federal research security requirements stemming from National Security Presidential Memorandum 33 (NSPM-33), which direct disclosure of research support, affiliations, and foreign-influence risk — a policy area distinct from, but often administered by the same office as, classified-contract compliance. See CASRAI’s entry on research security policy.
- CFIUS review, which examines foreign investment for national-security risk and can intersect with a university’s foreign funding relationships in ways that overlap with NISPOM’s FOCI provisions. See CASRAI’s entry on CFIUS.
An institution with a cleared facility typically needs all of these programs coordinated — NISPOM compliance for the classified contract itself, export control for controlled technology, CUI safeguarding for sensitive-but-unclassified data, and a broader research-security program for foreign-influence disclosure — rather than treating any one of them as a substitute for the others.
Practical implications for research administration
For research administrators and sponsored-programs offices, the practical NISPOM touchpoints are usually at the edges of the process rather than the center of it:
- Proposal stage — recognizing when a solicitation or contract will require an FCL, since obtaining one is a lengthy process (often many months) that must be initiated well before award, and involves a formal sponsorship request from the contracting agency or a prime contractor.
- Award and subaward stage — flagging classified-contract flow-down clauses correctly, since a university acting as a subcontractor under a cleared prime may inherit NISPOM obligations even without contracting directly with the government.
- Personnel — coordinating with the FSO on personnel security clearance processing timelines, which can materially affect when a researcher can actually begin work on a classified effort.
- Ongoing compliance — supporting DCSA inspection readiness and understanding that FCL status is facility-specific, not institution-wide, so a clearance for one lab does not extend automatically to other parts of campus.
What DCSA actually checks, and where universities get this wrong
DCSA’s oversight of a cleared facility is built around the security agreement signed on DD Form 441 and the specific commitments 32 CFR 117 attaches to it — an inspection is a check against that document and the CFR text, not a general security audit. Four failure modes recur at university facilities specifically, because they stem from the mismatch between how a university operates and how NISPOM assumes a facility operates:
- Treating the FCL as institution-wide. An FCL attaches to a specific facility — often one lab or center — not the university. A researcher or grants office assuming clearance status carries across campus is the most common source of scope errors.
- Foreign-contact and foreign-travel reporting lapses. §117.8’s reporting obligations (aligned to SEAD 3) require cleared personnel to report specific foreign contacts and travel — a research environment with high international-collaboration turnover makes this easy to miss procedurally, not maliciously.
- FOCI review gaps on international funding or leadership ties. §117.11 requires identifying and mitigating foreign ownership, control, or influence. A university with international donors, joint appointments, or foreign board members on an affiliated foundation can trigger a FOCI review it did not anticipate.
- Subcontract flow-down blindness. A university acting as a subcontractor under a cleared prime can inherit NISPOM obligations without ever contracting directly with the government — sponsored-programs offices that only screen their own direct awards for classified-work triggers miss this.
Ownership in practice: the Facility Security Officer and the security office run day-to-day compliance, but the trigger point — recognizing that a solicitation or subaward will require an FCL — sits with whoever reviews the award before signature. That is almost always the sponsored-programs or contracts office, not the security office, which is why the miss happens at proposal stage rather than at the security office’s desk.
Checking this against the current guidance
Whether your own facility needs its own FCL, or the FSO’s obligations extend only to the personnel accessing classified information at the sponsor’s site, depends on the specific security agreement, classification level, and prime/subcontract structure in your award — the page above states the general framework, not your case.
It searches CASRAI’s indexed corpus of research-administration guidance and cites the passage behind each claim, so you can open the source and check it rather than take its word — and it says so when the corpus does not cover something instead of guessing. Your first free question is the one in that link; save the second for the classification level and contract structure specific to your award. Two questions a day are free while you are signed out, no account and no card. Everything CASRAI publishes stays free to read.
Frequently asked questions
Does our university need its own facility clearance under 32 CFR Part 117 if the classified work will be performed entirely at the sponsor’s site, and what does the FSO have to do either way?
It depends on where the classified work actually happens and who needs access to it. If your researchers only travel to the sponsor’s cleared facility to do the classified work there — using the sponsor’s spaces, systems, and safeguarding, and never bringing classified material back to campus — the university itself typically does not need its own FCL; only the individual researchers may need personnel clearances (PCLs) sponsored through that facility, and the facility-level obligations (safeguarding, insider threat program, FOCI review) stay with the sponsor’s cleared site rather than transferring to the university. If any classified material, systems, or storage come onto campus, or the university signs its own DD Form 441, the university facility becomes the cleared entity and takes on the full set of NISPOM obligations directly. Either way, the FSO’s job does not disappear: a university with personnel cleared to work off-site still needs an FSO to track who holds a PCL, coordinate foreign-contact, foreign-travel, and adverse-information reporting with the sponsor’s security office, and confirm in writing — not by assumption — which entity’s security agreement actually covers the work before anyone begins it.
Does NISPOM apply to universities?
Yes, but only to the specific facility or unit within a university that holds, or is applying for, a facility clearance to perform a classified government contract or subcontract — not to the institution as a whole. Most university research does not involve classified information and is not subject to NISPOM.
Is NISPOM the same as export control (ITAR/EAR)?
No. NISPOM governs how a cleared facility protects classified information under a specific contract, including facility and personnel clearances. Export control (ITAR/EAR) governs the transfer of controlled technology and technical data, including to foreign nationals in a lab, independent of whether any classified information or facility clearance is involved. A university can be subject to one, both, or neither, depending on the specific program.
Who administers NISPOM oversight for universities?
The Defense Counterintelligence and Security Agency (DCSA) serves as the Cognizant Security Agency for most NISP participants, including most cleared university facilities, and conducts the compliance oversight and inspections.
What is a Facility Clearance (FCL)?
An FCL is a government determination that a specific facility is eligible to access classified information up to a defined level (Confidential, Secret, or Top Secret) for a specific classified contract. It is granted after a sponsorship process, review of foreign ownership/control/influence, and completion of a formal security agreement (DD Form 441) with the government.
What is the NISPOM Insider Threat Program requirement?
NISPOM requires every cleared facility to establish an insider threat program, led by a designated Insider Threat Program Senior Official, to detect, deter, and mitigate risks posed by cleared personnel with access to classified information.








