Social Media on the SF-86: What You Must Disclose and What Investigators May Review

Posted by Ashley Jones

Key takeaways

  • “Social media” appears exactly 4 times in the 136-page SF-86 PDF (revised November 2016), all four on the release page, none in any of the 29 numbered sections.
  • Section 27, Use of Information Technology Systems, does ask three seven-year questions about your online conduct.
  • SEAD 5 (effective 12 May 2016) lets agencies “choose” to collect public social media. It forbids passwords, private-account logins, friending you, third-party workarounds, and agency-account connections.
  • Once cleared, it is not optional. 5 U.S.C. 11001(b)(1): an agency’s program “shall integrate” sources including social media, in reviews run “not less than 2 times every 5 years.”
  • The release covers “ongoing evaluation” and lasts as long as you hold eligibility.

The phrase “social media” appears exactly four times in the 136-page Standard Form 86. All four sit on one page, the Authorization for Release of Information, and none inside any of the 29 numbered sections.

That absence is real, and narrower than the relief people take from it. The form asks nothing about your accounts. It does ask what you have done on IT systems. And the release outlives the investigation.

Not legal advice, and no guidance on what to post or delete. Questions about your own record belong with your security officer.

For employers
Hiring cleared professionals?
Post your cleared req where security-cleared candidates already search.

Post a Cleared Job

For job seekers
Holding a clearance?
Browse cleared roles from employers hiring right now.

Browse Cleared Jobs

Does the SF-86 ask for your social media handles?

No. Searching the form for social media, username, screen name, handle, profile, alias and the platform names returns no question requesting an online identifier. Section 27 asks about conduct on IT systems, a different thing.

Read the form itself, revised November 2016 under OMB control number 3206-0005. What it does not name, it does not collect, the enumeration logic of Section 21 and the mental health questions. Two page counts run here: 136 is the PDF’s; the form’s own footers end Section 29, Association Record, on printed page 129.

One caveat about that PDF. OPM’s 9 July 2026 renewal notice says applicants do not fill it in: eApp, the NBIS electronic application, is “the primary system used to collect this information,” its branching logic tailoring questions to your answers. One change matters now. Security freezes no longer restrict credit reports used for background screening, so “individuals are no longer required to lift a credit freeze during a background investigation.” The PDF still carries the old instruction, twice over. It is superseded; do not act on it. The notice proposes renewal without change, comments closing 8 September 2026, ahead of an approved Personnel Vetting Questionnaire still in development; OMB has not acted. The handle finding holds either way, but page and section numbers here describe the PDF, not eApp.

Sections 18 and 19 are the only place it asks about online interaction as such. You must “provide methods of contact” and check all that apply, one option being “Electronic (Such as e-mail, texting, chat rooms, etc).” Note the trigger, wider than usually reported: the block fires twice per relative entry, at item 18.4 where a non-citizen relative “has a U.S. address” and at 18.5 where they have “a foreign address.” A green-card parent in Ohio triggers it, and Section 19 repeats it for foreign contacts. It asks about the channel, not your accounts. Those contacts carry their own SEAD 3 reporting threshold.

One numbered section does collect your online conduct; omitting it would be the selective reading this piece argues against. Section 27 asks three seven-year questions: whether you have “illegally or without proper authorization accessed or attempted to access any information technology system” (27.1); whether you have modified, destroyed, manipulated or denied others access to information on one (27.2); and whether you used hardware, software or media on one without authorization (27.3). Each “Yes” demands the incident, its date, its location and the action taken. No handle is requested, but this is a disclosure obligation about your online life, and an omission is the falsification problem below.

One boundary: this is a finding about the SF-86. Some SCI and special access programs add questionnaires, none examined here.

What does the release you sign authorize?

It names “publicly available social media information” among the categories an investigator may obtain, and states three things it does not require of you. It is not confined to the investigation in front of you: it covers ongoing evaluation and lasts as long as your eligibility.

The operative sentence authorizes any accredited representative “conducting my background investigation, reinvestigation, or ongoing evaluation (i.e. continuous evaluation)” to obtain information that “may include, but is not limited to … employment, criminal, financial, and credit information, and publicly available social media information.”

The form defines the term as information “published or broadcast for public consumption, … accessible on-line to the public, … available by subscription or purchase, or … otherwise lawfully accessible.” The limit is on the same page: the authorization “does not require me to provide passwords; log into a private account; or take any action that would disclose non-publicly available social media information.”

So is its duration, in the sentence most readers never reach: “This authorization shall remain in effect so long as I occupy a national security sensitive position or require eligibility for access to classified information.” Not one look, then, but a standing permission.

Section E.3 of Security Executive Agent Directive 5 closes the loop: collection “shall only be conducted after obtaining the signed Authorization for Release of Information.”

What actually authorizes the look?

SEAD 5. Not 5 U.S.C. 11001, which governs ongoing review of people already cleared.

SEAD 5 names its authorities, and the wrong one circulates: “The National Security Act of 1947, as amended; Intelligence Reform and Terrorism Prevention Act of 2004, as amended; Executive Order (EO) 10450 …; EO 12968 …; EO 13467 …; EO 13549 …; Performance Accountability Council Memorandum … 2012; and other applicable provisions of law.” That closing catch-all means the list is not a closed set, so absence from it settles nothing on its own. Neither the Consolidated Appropriations Act, 2016 nor 5 U.S.C. 11001 appears in the six-page directive.

Section 11001 came in at Section 306 of division M of Public Law 114-113, the Intelligence Authorization Act for Fiscal Year 2016, enacted 18 December 2015. Name the division: that omnibus has several sections numbered 306. It aims elsewhere. Subsection (b)(1): an agency’s “enhanced personnel security program shall integrate … information from various sources, including … social media.” Shall, not may. But (d)(3) limits its “covered individual” to someone already “determined eligible for access to classified information or eligible to hold a sensitive position,” and (c)(6) makes its reviews “in addition to” investigations under the Intelligence Reform and Terrorism Prevention Act of 2004. Already cleared, and on top of the investigation rather than its source.

Statutory categories are not a roster of things that cost people clearances. Subsection (b)(2)(C) reaches material suggesting “ill intent, vulnerability to blackmail, compulsive behavior, allegiance to another country, change in ideology, or that the covered individual lacks good judgment.” Changing your politics is not disqualifying.

At the applicant stage SEAD 5 is permissive: agencies “may choose to collect publicly available social media information,” and only where it “pertains to the adjudicative guidelines.” It remains current as of ODNI’s May 2026 listing, the NCSC policy page carrying it with nothing marking it rescinded. That ran against a 22 May 2026 capture, the most recent available: evidence of currency, not same-day confirmation.

What are investigators forbidden from doing?

Inside a background investigation, five things: passwords, a private-account login, any action disclosing non-public material, accounts used to friend or follow you, and asking you to connect to an agency account. Third-party workarounds are barred separately. None of it bars every other federal inquiry.

Section E.6 governs the agency, in two sentences. The first forbids creating or using accounts “for the purpose of connecting (e.g., ‘friend’, ‘follow’) to a covered individual,” or enlisting “a third party in order to bypass privacy controls.” The second is the one summaries drop: “Agencies shall not request that a covered individual connect to an agency account or access their account from an agency system in order to provide access to information which would otherwise be protected from public view.” Asked to open your profile on the investigator’s terminal, that is your sentence.

Read it against the directive’s scope. SEAD 5 binds “authorized investigative agencies” and “authorized adjudicative agencies,” and its Purpose section adds that “nothing in this Directive prohibits agencies from conducting other legally permissible investigations or inquiries.” The ban is real where it applies, not a guarantee that a connection request is never an approach.

Two more limits, one with a carve-out. E.4 restricts intentional collection to you: absent a national security or criminal reporting concern, information about others “will not be investigated or pursued.” Its third sentence answers the real worry, and not the way people hope: material inadvertently collected about others “will not be retained unless that information is relevant to a security determination of the covered individual.” E.7 requires “reasonably exhaustive efforts” to verify discrepant material is yours.

What the SF-86 asks for What SEAD 5 permits What SEAD 5 forbids
No handles or profile URLs, in any of the 29 sections Public social media, at agency discretion (Sec. E) Requiring passwords (E.5.a)
Home and work e-mail (Section 7) Collection only after the signed release (E.3) Requiring a private-account login (E.5.b)
Three seven-year IT-misuse questions (Section 27) Only material pertaining to the adjudicative guidelines Any action disclosing non-public information (E.5.c)
Contact method for a non-citizen relative, U.S. or foreign address (18.4, 18.5), and foreign contacts (19) Retaining third-party material relevant to your determination (E.4) Accounts used to “friend” or “follow” you (E.6)
A signature covering ongoing evaluation, for as long as you hold eligibility A gaining agency collecting afresh under reciprocity (E.9) Asking you to connect to an agency account (E.6)

Sources: SF-86 (revised November 2016), Sections 7, 18, 19, 27 and the release page; SEAD 5, Sections B and E.3 to E.9. Columns are independent lists, not paired rows.

Can something you posted cost you a clearance?

Yes, if it is verified, attributed to you, and raises one of the thirteen adjudicative guidelines. SEAD 5 rules out something narrower: an action resting solely on uncorroborated material.

Section E.8 bars unfavorable actions “solely on uncorroborated or unverified discrepant information collected pursuant to this Directive.” Read the qualifiers. It protects you from a decision resting on a screenshot nobody confirmed was yours. It does not say a post cannot be disqualifying, and grants nothing once attribution is settled.

The guidelines are the thirteen in SEAD 4, signed 10 December 2016, from allegiance and foreign influence through personal conduct and finances to use of information technology. Social media is not a fourteenth. A post matters only where its content lands inside one of them.

Two SEAD 4 sentences must be read together; pieces quoting only the first sell comfort. The whole-person concept: “all available, reliable information about the person, past and present, favorable and unfavorable, should be considered.” Then: “a single criterion may be sufficient to make an unfavorable eligibility determination even in the absence of a recent occurrence or a recurring pattern.” Any doubt “will be resolved in favor of the national security.” For an old post, “the frequency and recency of the conduct” and “age and maturity at the time” are two of nine weighing factors, considerations rather than exemptions. More in the whole-person concept.

SEAD 4 also governs the interview: “any incident of intentional material falsification or purposeful non-cooperation with security processing is of significant concern.” There is no handle question to conceal. Misrepresenting a post, or an incident Section 27 reaches, is a personal conduct problem in itself, like Section 23 and past drug use. Adverse determinations carry Executive Order 12968 Part 5 proceedings, our Statement of Reasons guide.

Do agencies actually run these checks?

At the applicant stage, unknown: SEAD 5 permits without requiring, and no federal source publishes which agencies collect or how often. Once cleared, the statute is not permissive at all.

Publicly there is the permission in Section E and the reciprocity requirement in E.9, which only makes sense if practice differs. Anyone quoting a percentage is quoting nothing federal. E.9’s second sentence then undercuts its first: an agency that uses social media must accept an investigation by one that does not, but “the gaining agency may collect social media information on the covered individual pursuant to this policy.” Reciprocity is not immunity from a fresh look on transfer.

Ongoing review is a different question, and there the answer is not silence. Section 11001(b)(1) directs an agency’s enhanced personnel security program to integrate sources “including government, publicly available, and commercial data sources, consumer reporting agencies, social media.” Subsection (c)(1)(A) sets the cadence: “not less than 2 times every 5 years,” the agency head runs “automated record checks and checks of information from sources under subsection (b) to ensure the continued eligibility of each covered individual.” The release you signed authorizes it by name.

Unpublished is the operational detail. DCSA’s October 2021 description of continuous vetting says checks “pull data from criminal, terrorism, and financial databases, as well as public records,” never naming social media. That release is nearly five years old and describes a transitional phase of the Trusted Workforce rollout, not the 2026 configuration; an absence in it is not a denial. No federal source we found describes how any agency implements the statutory element today. The floor is not zero. See continuous vetting versus continuous evaluation.

ClearedJobs.NET connects cleared talent with the employers who need it.
Whether you are hiring for a cleared req or holding a clearance and looking, start here.

Post a Cleared JobBrowse Cleared Jobs

Frequently Asked Questions

Do I have to list my social media accounts on the SF-86?

No question asks for handles, usernames, profile URLs or platform names. Section 27 does require disclosure of IT-system misuse over the last seven years. Agency supplemental forms were not examined here.

Can an investigator send me a friend request?

Not within a personnel security background investigation. Section E.6 bars agencies from creating or using accounts to “friend” or “follow” a covered individual, from using a third party to bypass privacy controls, and from asking you to connect to an agency account. But nothing in SEAD 5 “prohibits agencies from conducting other legally permissible investigations or inquiries.”

Is my social media checked after I am cleared?

The statute says it should be. 5 U.S.C. 11001(b)(1) directs each agency’s enhanced personnel security program to integrate sources including social media, and (c)(1)(A) requires those checks “not less than 2 times every 5 years.” No federal source describes how a given agency implements that today. See also interim clearances.

Has anyone been denied a clearance over social media?

The government publishes no data on how often social media contributes to adverse determinations, and no verified case was available here. Verified, attributed material is adjudicated under the thirteen SEAD 4 guidelines, and a single criterion may suffice.

What to carry into the form

The panic and the false comfort come from one confusion. Nothing on the SF-86 asks you to inventory your accounts, and Section 27 asks about conduct, not identity. Your signature authorizes review of what the public can already see, bounded by a directive naming what investigators may not do and requiring reasonably exhaustive efforts, not proof, that a post is yours. It is also open-ended: it reaches continuous evaluation, lasts as long as your eligibility, and once you are cleared a statute directs that social media be integrated into review twice or more every five years. Read it before signing.

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts

Comment

Notify me of updates to this conversation

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts
This entry was posted on Wednesday, July 22, 2026 6:42 am