32 CFR Part 117 is the codified National Industrial Security Program Operating Manual (NISPOM) — the federal regulation that governs how contractors, including universities, must safeguard classified national security information under contract with the U.S. government. For research institutions that hold or are pursuing classified research contracts, NISPOM compliance is not optional guidance; it is a binding regulatory condition of holding a facility clearance, enforced through a signed security agreement with the government.
This guide covers what 32 CFR Part 117 actually requires, who at a university needs to know about it, how it differs from export control regimes like ITAR and EAR that research offices more commonly encounter, and where NISPOM obligations intersect with the broader research-security landscape.
What 32 CFR Part 117 is and where it came from
NISPOM began in 1995 as DoD guidance issued through a series of Department of Defense manuals (most recently DoD 5220.22-M), not as a standalone federal regulation. That changed on December 21, 2020, when the rule was published in the Federal Register, and it took effect as a binding federal regulation — 32 CFR Part 117 — on February 24, 2021, with a compliance deadline of August 24, 2021. Codifying NISPOM as a Code of Federal Regulations part (rather than leaving it as internal DoD guidance) gave it the direct force of law across all agencies participating in the National Industrial Security Program (NISP), not just the Department of Defense. A further rule amendment was published in the Federal Register on December 13, 2023, updating provisions related to reporting and other program elements.
The NISP itself predates the CFR codification by decades — it was established by Executive Order 12829 (1993) to create a single, uniform system across the federal government for safeguarding classified information held by contractors, rather than each agency running its own parallel security program. 32 CFR Part 117 is the operating manual for that system.
Who this applies to at a university
NISPOM applies to any entity that holds, or is applying for, a Facility Clearance (FCL) — formal government authorization for a specific facility to access classified information at a defined level (Confidential, Secret, or Top Secret). A university becomes subject to NISPOM when one of its facilities (often a specific lab, research center, or federally funded research and development center rather than the institution as a whole) needs an FCL to perform a classified contract or subcontract, most commonly for the Department of Defense, Department of Energy, NASA, or the intelligence community.
Within a cleared university facility, several roles carry direct NISPOM obligations:
- Facility Security Officer (FSO) — the individual NISPOM requires every cleared facility to designate, responsible for implementing and administering the facility’s security program day to day.
- Insider Threat Program Senior Official (ITPSO) — a senior management official NISPOM requires to be designated to establish and lead the facility’s insider threat program.
- Key Management Personnel (KMP) — officers, directors, and other individuals whose positions give them the ability to adversely affect the facility’s classified contract performance; NISPOM requires most KMP to hold a personnel clearance or be formally excluded from access.
Research administrators, grants and contracts offices, and export-control officers are typically not the ones executing NISPOM’s day-to-day security requirements — that sits with the FSO and security office — but they need to recognize when a proposed award triggers an FCL requirement, since it changes the compliance posture and reporting obligations for that specific facility well beyond ordinary sponsored-research administration.
What NISPOM actually requires
32 CFR Part 117 sets out the standard procedures a cleared contractor facility must follow across the classified-information lifecycle. Core elements include:
- Facility and personnel clearances (FCL/PCL) — the process and standards for a facility, and the individuals working within it, to be authorized to access classified information at a given level.
- The Insider Threat Program — a mandatory program to detect, deter, and mitigate risks posed by cleared personnel, including monitoring, employee reporting obligations, and coordination with counterintelligence and security offices. This became a formal NISPOM requirement following a 2016 DoD change and carried through into the 32 CFR Part 117 codification.
- Safeguarding requirements — physical security, storage, transmission, and destruction standards for classified material, scaled to classification level.
- Security training and briefings — initial and refresher training obligations for cleared personnel.
- Reporting requirements — including the adverse-information and foreign-contact reporting obligations that 32 CFR Part 117 aligned with Security Executive Agent Directive (SEAD) 3.
- Foreign Ownership, Control, or Influence (FOCI) — provisions (117.11) addressing how a facility must identify and mitigate foreign ownership or influence that could affect its ability to protect classified information, a provision with particular relevance for universities with significant international funding, partnerships, or leadership ties.
The Defense Counterintelligence and Security Agency (DCSA) serves as the Cognizant Security Agency (CSA) for most NISP facilities, including the great majority of cleared university facilities, and conducts the oversight inspections that verify NISPOM compliance. When a facility is granted an FCL, the institution signs DD Form 441, the DoD Security Agreement, formally committing to follow NISPOM’s requirements as a condition of the clearance.
NISPOM vs. export control (ITAR/EAR): a common point of confusion
NISPOM and export control are related but distinct compliance regimes, and research offices frequently conflate them because both restrict the flow of sensitive technical information and both matter heavily for classified or dual-use research programs.
- NISPOM (32 CFR Part 117) governs how a cleared facility protects classified national security information it has been authorized to access under a specific contract — it is fundamentally about facility and personnel security clearances and safeguarding practices.
- Export control — the International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) — governs the transfer of controlled technology, technical data, and defense articles, including ‘deemed exports’ to foreign nationals working in a U.S. lab, regardless of whether classified information or a facility clearance is involved at all.
A university research program can be subject to export control obligations without ever touching classified information or holding an FCL, and it can hold an FCL for one program while a completely different lab down the hall is separately subject to ITAR/EAR for unclassified but controlled technology. The two frameworks require separate compliance infrastructure, though in practice both often report through the same institutional research-security or export-control office. See CASRAI’s guide to Export Control (EAR/ITAR) and International Research Collaboration for how the export-control side works.
How NISPOM fits into the broader research-security landscape
NISPOM sits alongside, but is legally distinct from, several other frameworks universities engaged in sensitive or federally funded research increasingly encounter:
- Controlled Unclassified Information (CUI) requirements, which govern unclassified-but-sensitive information under a separate framework (32 CFR Part 2002 and agency-specific rules such as DFARS 252.204-7012), and typically implicate CUI safeguarding and cybersecurity controls like NIST SP 800-171 rather than NISPOM’s classified-information framework.
- Federal research security requirements stemming from National Security Presidential Memorandum 33 (NSPM-33), which direct disclosure of research support, affiliations, and foreign-influence risk — a policy area distinct from, but often administered by the same office as, classified-contract compliance. See CASRAI’s entry on research security policy.
- CFIUS review, which examines foreign investment for national-security risk and can intersect with a university’s foreign funding relationships in ways that overlap with NISPOM’s FOCI provisions. See CASRAI’s entry on CFIUS.
An institution with a cleared facility typically needs all of these programs coordinated — NISPOM compliance for the classified contract itself, export control for controlled technology, CUI safeguarding for sensitive-but-unclassified data, and a broader research-security program for foreign-influence disclosure — rather than treating any one of them as a substitute for the others.
Practical implications for research administration
For research administrators and sponsored-programs offices, the practical NISPOM touchpoints are usually at the edges of the process rather than the center of it:
- Proposal stage — recognizing when a solicitation or contract will require an FCL, since obtaining one is a lengthy process (often many months) that must be initiated well before award, and involves a formal sponsorship request from the contracting agency or a prime contractor.
- Award and subaward stage — flagging classified-contract flow-down clauses correctly, since a university acting as a subcontractor under a cleared prime may inherit NISPOM obligations even without contracting directly with the government.
- Personnel — coordinating with the FSO on personnel security clearance processing timelines, which can materially affect when a researcher can actually begin work on a classified effort.
- Ongoing compliance — supporting DCSA inspection readiness and understanding that FCL status is facility-specific, not institution-wide, so a clearance for one lab does not extend automatically to other parts of campus.
Frequently asked questions
What is 32 CFR Part 117?
32 CFR Part 117 is the National Industrial Security Program Operating Manual (NISPOM), codified as a binding federal regulation effective February 24, 2021. It sets the security requirements that contractors, including universities, must follow to hold a facility clearance and perform work involving classified national security information.
Does NISPOM apply to universities?
Yes, but only to the specific facility or unit within a university that holds, or is applying for, a facility clearance to perform a classified government contract or subcontract — not to the institution as a whole. Most university research does not involve classified information and is not subject to NISPOM.
Is NISPOM the same as export control (ITAR/EAR)?
No. NISPOM governs how a cleared facility protects classified information under a specific contract, including facility and personnel clearances. Export control (ITAR/EAR) governs the transfer of controlled technology and technical data, including to foreign nationals in a lab, independent of whether any classified information or facility clearance is involved. A university can be subject to one, both, or neither, depending on the specific program.
Who administers NISPOM oversight for universities?
The Defense Counterintelligence and Security Agency (DCSA) serves as the Cognizant Security Agency for most NISP participants, including most cleared university facilities, and conducts the compliance oversight and inspections.
What is a Facility Clearance (FCL)?
An FCL is a government determination that a specific facility is eligible to access classified information up to a defined level (Confidential, Secret, or Top Secret) for a specific classified contract. It is granted after a sponsorship process, review of foreign ownership/control/influence, and completion of a formal security agreement (DD Form 441) with the government.
What is the NISPOM Insider Threat Program requirement?
NISPOM requires every cleared facility to establish an insider threat program, led by a designated Insider Threat Program Senior Official, to detect, deter, and mitigate risks posed by cleared personnel with access to classified information.







