NISPOM in 2026: What 32 CFR Part 117 Requires of a Cleared Employer

Posted by Ashley Jones

February 24, 2021 is the day the National Industrial Security Program Operating Manual stopped being a manual. On that date it became a federal regulation at 32 CFR Part 117, with the force of law behind every paragraph, and contractors had six months to implement it. If you run a cleared facility, the consequence is permanent: the security program a Defense Counterintelligence and Security Agency assessor checks is no longer measured against guidance you could argue with, but against a rule you meet or violate. Here is what Part 117 asks of a cleared employer in 2026, by paragraph designator.

Key takeaways

  • The NISPOM became a federal rule at 32 CFR Part 117, effective February 24, 2021, with a 6-month implementation deadline written into 117.1(b)(3).
  • The rule requires a formal self-inspection at least annually plus a written senior-management certification to the government each year (117.7(h)(2)).
  • In FY2026 a Tier 3 investigation behind a Secret clearance bills at $735 and a Tier 5 behind a Top Secret or SCI clearance at $6,240 under the DoD bundled rate, both up 10 percent from FY2025.
  • The CMMC program rule took effect December 16, 2024, and the DFARS rule that writes CMMC into contracts took effect November 10, 2025.
  • Executive Order 11246 affirmative action was revoked January 21, 2025; the veteran (VEVRAA) and disability (Section 503, a 7 percent goal) obligations survive because Congress wrote them into statute.
For employers
Hiring cleared professionals?
Post your cleared req where security-cleared candidates already search.

Post a Cleared Job

For job seekers
Holding a clearance?
Browse cleared roles from employers hiring right now.

Browse Cleared Jobs

What is the NISPOM now that it lives at 32 CFR Part 117?

The NISPOM is no longer guidance. Since February 24, 2021 it has been a federal regulation at 32 CFR Part 117, implementing Executive Order 12829 and DoD Instruction 5220.22. For DoD contracts, the Defense Counterintelligence and Security Agency administers and inspects against it.

Section 117.1(a) says the rule “implements policy… consistent with E.O. 12829” and DoD Instruction 5220.22. A manual describes practice. A rule creates liability. Section 117.1(b)(3) set the clock: contractors had to implement the part “no later than 6 months from February 24, 2021.” The inspector changed names inside that window too. On June 20, 2020 the Defense Security Service became DCSA, which “serves as the DoD CSO” under 117.6(b). The rule sits under the distinction between contractor work and federal employment, and it is the book your facility security officer answers to first.

Which security officials must you appoint, and what do they owe?

The rule makes you name people in writing. A senior management official appoints an FSO and an insider threat program senior official, both U.S. citizens; a facility that processes classified information on a system also names an information system security manager. Each role carries inspectable duties, including a formal self-inspection every year.

Under 117.7, security officials “will… be U.S. citizens, except in exceptional circumstances.” The senior management official must “appoint… in writing, as the FSO and appoint… a different employee as the ITPSO” under 117.7(b)(2)(ii); one person can hold both. The FSO “will supervise and direct security measures” under 117.7(b)(3)(i). The ITPSO “will establish and execute an insider threat program” under 117.7(b)(4), tied to Executive Order 13587 and the National Insider Threat Policy at 117.7(d). Process classified information on a system and 117.7(b)(5) requires an ISSM eligible to the highest level on it. The rule then makes you audit yourself. Section 117.7(h)(2) requires “a formal self-inspection at least annually,” and 117.7(h)(2)(iii) requires the SMO to “annually certify to the CSA, in writing,” that it happened, that key management personnel were briefed, and that corrective actions were taken. A signature goes to the government every year, which is worth weighing against what the FSO role actually runs day to day.

What must a cleared contractor report, and to whom?

Reporting is the spine of the rule. Espionage, sabotage, terrorism, or subversion go to the nearest FBI field office first. Adverse information, suspicious contacts, employee status changes, an SF 312 refusal, and anything that changes your facility eligibility go to the government. The regime rests on Security Executive Agent Directive 3.

Most inspection findings live in 117.8, because these obligations run continuously. The gravest category leaves the security chain entirely: under 117.8(b) the contractor “will promptly submit a written report to the nearest field office of the FBI” about “actual, probable, or possible espionage, sabotage, terrorism, or subversive activities.” Everything else routes to the CSA. Adverse information is reportable under 117.8(c)(1), and the rule is blunt about two edges of it: terminating the employee “does not negate” it, and you “will not make reports based on rumor or innuendo.” Suspicious contacts fall under 117.8(c)(2); status changes such as death, name change, termination, and change in citizenship under 117.8(c)(3); an SF 312 nondisclosure refusal under 117.8(c)(6); and a change of ownership, control, name, or address that affects entity eligibility under 117.8(c)(7). The framework beneath all of it is Security Executive Agent Directive 3, incorporated at 117.8(a), which also drives the foreign-travel reporting your employees owe. Make sure every holder knows their own reporting duties before an assessor asks.

Reportable event Paragraph Where it goes
Espionage, sabotage, terrorism, subversion 117.8(b) Nearest FBI field office, in writing
Adverse information on a cleared employee 117.8(c)(1) CSA (termination does not cancel it)
Suspicious contacts 117.8(c)(2) CSA-designated reporting mechanism
Status change (death, name, termination, citizenship) 117.8(c)(3) CSA-designated reporting mechanism
Refusal to sign the SF 312 NDA 117.8(c)(6) CSA
Change of ownership, control, name, or address 117.8(c)(7) CSA (affects entity eligibility / FCL)

What training does the rule require before and during access?

No one touches classified information cold. Before access, every cleared employee gets an initial briefing covering threat and insider-threat awareness, counterintelligence, the classification system, reporting duties, and cybersecurity. Insider-threat training then repeats annually, and derivative classifiers retrain at least every two years or lose the authority.

Training under 117.12 is sequenced, and it starts before anyone reads a classified word. Under 117.12(e), “prior to being granted access,” the initial briefing covers threat awareness including insider threat, counterintelligence awareness, the classification system, reporting obligations, and cybersecurity. Under 117.12(g)(2), the contractor provides insider-threat awareness training “to all cleared employees on an annual basis,” and to newly cleared employees before access. Under 117.12(h), anyone conducting derivative classification must be trained before doing so and “at least once every two years,” or the contractor “will suspend” that authority. Miss the refresher and the authority stops, a compliance failure and a production bottleneck at once.

How do the clearance mechanics run day to day, and what do they cost?

The FSO drives the paperwork and the clock. An applicant completes the SF 86 in e-QIP, the FSO reviews it, and once eligible the employee falls under continuous vetting and periodic reinvestigation. The investigation behind that eligibility is billed to your government customer by tier, and the tiers are priced far apart.

The mechanics live in 117.10. The SF 86 “must be completed in e-QIP or its successor system… and reviewed by the FSO,” per 117.10(d). Eligibility does not end the watching: under 117.10(a)(5) employees “follow CSA guidance to complete reinvestigation and continuous evaluation or continuous vetting,” the enrollment behind modern continuous vetting. The eligibility itself flows from an adjudication. Cost follows the tier, which follows the clearance: a Tier 3 backs a Secret, a Tier 5 backs a Top Secret or SCI, and the gap between the levels of clearance is a gap in price. The rates below come from DCSA Federal Investigations Notice 24-01, effective October 1, 2025. The bundled column is mandatory for DoD customers; the base column is the standard non-DoD rate; both rose 10 percent from FY2025. At the bundled rate a Tier 5 costs more than eight times a Tier 3, so naming a TS/SCI clearance when a Secret would do is an expensive habit.

Investigation tier Clearance it backs FY2026 DoD bundled rate FY2026 base non-DoD rate
Tier 1 Low-risk / non-sensitive (not a clearance) $338 $197
Tier 3 Secret $735 $455
Tier 5 Top Secret / SCI $6,240 $5,890

How does CMMC change what a cleared contract must secure?

The NISPOM protects classified information; CMMC protects the controlled unclassified information around it. A cleared contract in 2026 increasingly carries a CMMC level, assessed with rising rigor from a self-check at Level 1 to a government assessment at Level 3, and it eventually reaches your bill rate.

Section 117.18 already requires a risk-based information system security program; the CSA issues guidance “based on requirements for federal systems” under the Federal Information Security Modernization Act and NIST Special Publication 800-37. CMMC layers on top for controlled unclassified information, and it is now in contracts. The program rule at 32 CFR Part 170 was published October 15, 2024 and took effect December 16, 2024; the DFARS acquisition rule that writes CMMC clauses into contracts took effect November 10, 2025. Section 170.14 defines Level 1 as the 15 safeguarding requirements in FAR 52.204-21(b)(1)(i) through (xv), Level 2 as the security requirements of NIST SP 800-171 Revision 2, and Level 3 as selected requirements from NIST SP 800-172.

CMMC level Requirement basis Who assesses it
Level 1 15 requirements in FAR 52.204-21(b)(1)(i)-(xv) Annual self-assessment, posted to SPRS
Level 2 Security requirements of NIST SP 800-171 Rev 2 Self-assessment or a C3PAO certification
Level 3 Selected requirements from NIST SP 800-172 Government assessment by DCMA DIBCAC

All of it eventually lands on price through the wrap rate: the ratio of a contractor’s fully burdened, billed labor rate to its base direct labor rate, bundling direct labor with the indirect pools of fringe, overhead, and general and administrative expense, plus fee. No regulation sets that number. FAR 31.203 governs how the indirect pools are built and allocated; every contractor’s rates are its own, subject to Cost Accounting Standards and DCAA audit. Fee is negotiated under the weighted-guidelines method in FAR 15.404-4, which does cap cost-plus-fixed-fee work at 15 percent of estimated cost for research and development, 6 percent for architect-engineer services, and 10 percent for other such contracts. A purely hypothetical 2.0 wrap would turn a $50-an-hour salary into a $100 billed rate; treat it as illustration only: no industry-standard multiple exists, and any source quoting one is guessing.

Which affirmative-action rules still bind cleared contractors in 2026?

One big affirmative-action obligation ended in 2025, and two did not. Executive Order 11246, the race-and-sex program OFCCP long enforced, was revoked; its regulations are only proposed for rescission. The veteran and disability duties, written into statute by Congress, remain fully in force for cleared contractors.

Dated advice does real damage here. Executive Order 11246, the 1965 order behind race, color, religion, sex, and national-origin affirmative action, was revoked by Executive Order 14173 on January 21, 2025. The regulations have not caught up: OFCCP’s proposal to rescind the rules at 41 CFR parts 60-1, 60-2 and related sections was published July 1, 2025, and a proposed rule is not a final one. Two duties sit outside the rollback because Congress created them. VEVRAA, at 41 CFR 60-300.45, still requires a veteran hiring benchmark set “on an annual basis.” Section 503 of the Rehabilitation Act, at 41 CFR 60-741.45, still carries the “utilization goal of 7 percent for employment of qualified individuals with disabilities.” Both remain current through 2026. The honest summary for a cleared contractor is narrow: the race-and-sex plan is gone, the veteran and disability duties are not.

Two 2025 memoranda reshaped the market your cleared roles compete in, though neither is a NISPOM duty and both target the federal workforce. A federal-civilian hiring freeze was ordered by a presidential memorandum signed January 20, 2025, and a return-to-in-person-work memorandum was signed the same day. The DD Form 254, the DoD Contract Security Classification Specification referenced throughout Part 117 at 117.5, remains the instrument that tells you what a contract is cleared to touch.

ClearedJobs.NET connects cleared talent with the employers who need it.
Whether you are hiring for a cleared req or holding a clearance and looking, start here.

Post a Cleared JobBrowse Cleared Jobs

Frequently Asked Questions

Is the NISPOM still a manual, or is it a regulation now?

It is a regulation. The NISPOM was codified as a federal rule at 32 CFR Part 117, effective February 24, 2021, implementing Executive Order 12829 and DoD Instruction 5220.22. Contractors had six months to implement it. A DCSA assessment now measures your program against the rule, not against guidance you could debate.

Who has to be a U.S. citizen under 32 CFR Part 117?

The security officials. Under 117.7(b), contractors appoint security officials who are U.S. citizens, “except in exceptional circumstances.” That includes the FSO and the insider threat program senior official, both of whom the senior management official appoints in writing under 117.7(b)(2)(ii). A single employee may hold both roles, or you may split them.

How often does a cleared contractor have to self-inspect?

At least once a year. Section 117.7(h)(2) requires a “formal self-inspection at least annually.” The result is not internal-only: 117.7(h)(2)(iii) requires the senior management official to certify to the CSA in writing, each year, that the self-inspection happened, that key management personnel were briefed, and that corrective actions were taken.

Does CMMC replace the NISPOM?

No. They protect different things. The NISPOM at 32 CFR Part 117 governs classified information; CMMC at 32 CFR Part 170 governs controlled unclassified information on contractor systems. One cleared contract can carry both. The CMMC program rule took effect December 16, 2024, and the DFARS acquisition rule November 10, 2025.

Did the 2025 rollback of Executive Order 11246 end affirmative action for cleared contractors?

Only part of it. Executive Order 11246, the race-and-sex program, was revoked on January 21, 2025, and its regulations are proposed for rescission. But VEVRAA for protected veterans, at 41 CFR Part 60-300 with its annual hiring benchmark, and Section 503 for people with disabilities, at 41 CFR Part 60-741 with its 7 percent utilization goal, both remain in force in 2026 because they are statutory.

Through 2026, the contracts crossing your desk will name a CMMC level beside the clearance level and still demand the same annual signature that a self-inspection was done and its findings fixed. The FSO who treats 32 CFR Part 117 as a live inspection standard, not a binder on a shelf, is the one whose facility clears its certification without a finding and whose hires start on schedule instead of stalling behind a lapsed briefing. Read the rule by its paragraph designators, because that is how the assessor reads it back to you.

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts

Comment

Notify me of updates to this conversation

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts
This entry was posted on Tuesday, July 14, 2026 12:59 pm