Trusted Workforce 2.0 and NBIS: What Replaced the Periodic Reinvestigation

Posted by Ashley Jones

Agencies scheduled 7,716 periodic reinvestigations in the second quarter of fiscal year 2025. In the second quarter of fiscal year 2026 they scheduled 100.

The change that ended it for cleared industry was announced on 19 May 2026, when the Defense Counterintelligence and Security Agency published updated continuous vetting guidance for National Industrial Security Program contractors, superseding guidance from August 2022. Periodic reinvestigations for NISP contractor national security personnel “will no longer be required.” DCSA’s file name dates the guidance itself to 16 April 2026; that server refuses automated requests, so the date comes from the file name, not from a page we read. What replaced the reinvestigation is not nothing, and it is not finished.

Key takeaways

  • DCSA announced on 19 May 2026 that for NISP contractor national security personnel the periodic reinvestigation gives way to a questionnaire every five years. It does not govern federal civilian, military or IC employees.
  • Reinvestigations requested fell from 7,716 in FY2025-Q2 to 100 in FY2026-Q2. Reinvestigations still being completed did not fall that far.
  • Continuous vetting produced about 1.13 new actionable alerts per quarter per hundred enrollees (FY2026-Q1), and alert volume has been falling since FY2025-Q4.
  • 74 percent of the entire vetted federal workforce was enrolled at FY2026-Q2, flat on the prior quarter.
  • NBIS has a development goal of FY2027 and $2.2 billion more projected through 2031, and does not run continuous vetting today.
For employers
Hiring cleared professionals?
Post your cleared req where security-cleared candidates already search.

Post a Cleared Job

For job seekers
Holding a clearance?
Browse cleared roles from employers hiring right now.

Browse Cleared Jobs

What exactly did DCSA change in 2026?

The scheduled investigation went away. The paperwork did not. Every NISP contractor national security employee now submits an updated Personnel Vetting Questionnaire, or an SF-86 through eApp with releases, every five years regardless of eligibility level. The clock runs off the PVQ Date in DISS.

The shorthand circulating in cleared workplaces gets this wrong in both directions. No more reinvestigation on a calendar cycle. Still a long form roughly every five years. The guidance rides on DISS Release 14.5, whose underlying change was implemented on 2 April 2026. The difference between DISS and Scattered Castles covers the databases.

One caveat the announcement omits. The PAC’s supplemental metrics say periodic reinvestigations “have largely been replaced with continuous vetting” and that national security PRs “remain low and are now primarily used for significant issue resolution under continuous vetting until the new TW 2.0 products are available.” That trailing clause matters. The surviving use is an interim arrangement, not a settled end state. Dead as a scheduled event; alive, for now, as the tool the government reaches for when something serious surfaces.

Requests are also not completions. The scheduled-reinvestigation chart names no population, while the two charts in the same report labelled government-wide show roughly 5,200 national security reinvestigations adjudicated in FY2026-Q1 and roughly 1,900 public trust ones in FY2026-Q2, work flowing from requests made in earlier quarters. Neither prints data labels; those figures are ours, read off the bars.

How does a presidential requirement disappear without being repealed?

It does not. Executive Order 12968 still requires periodic reinvestigation of cleared employees, and since 2017 it also requires continuous evaluation. What changed is the method of compliance: an ODNI and OPM issuance established that enrollment in a conforming continuous vetting program satisfies the reinvestigation requirement.

That is why a memo rather than a rulemaking was enough. Section 3.4(b) of Executive Order 12968 as signed in August 1995 says cleared employees “shall be the subject of periodic reinvestigations,” and 3.4(c) hands the frequency to a separate standards document. Read that 1995 text with a correction. Executive Order 13764, on 23 January 2017, amended EO 12968 to strike “Security Policy Board” for “Security Executive Agent” in each instance, and to add a Sec. 3.5 requiring that anyone eligible for access “shall be subject to continuous evaluation as further defined by and under standards (including, but not limited to, the frequency of such evaluation) as determined by the Director of National Intelligence.” Continuous evaluation has been a presidential requirement since 2017. The president ordered the re-look; the DNI sets how often.

The NISPOM behaves the same way. 32 CFR 117.10(b)(5), in the edition in force since 1 July 2025, tells contractor employees to “follow CSA guidance to complete reinvestigation and continuous evaluation or continuous vetting requirements.” No interval appears in the regulation, which is why guidance could retire it. See what 32 CFR Part 117 requires.

The bridging step is a joint ODNI and OPM executive correspondence dated 6 February 2020. We never obtained the correspondence. What we read is a fact sheet about it, hosted on a third-party network, its title and date confirmed by the PAC’s Personnel Vetting Policy Index. The fact sheet says individuals “in national security positions enrolled in a continuous vetting program that meets interim minimum standards, as outlined in the EC, are deemed to be in compliance with periodic reinvestigation requirements,” and that agencies “must demonstrate ability to comply” by filing documentation with the executive agents. Deemed compliance is scoped and conditional, and this is a summary of an issuance, not the issuance.

What was the old reinvestigation schedule?

Tier 3 covered Secret and Confidential; Tier 5 covered Top Secret and SCI. A March 2017 job aid puts Tier 3 at ten years and Tier 5 at six, recording both as backlog-driven extensions endorsed by the DNI, not the standing rule. It describes 2012 standards, so read it as history.

The tier structure underneath is being demolished too. The PAC’s Personnel Vetting Basics fact sheet says the count drops from five tiers to three, a transition it warns “will take several years to complete.”

Position and access type Legacy tier New tier
Non-Sensitive / Low Risk 1 Low
Non-Sensitive / Moderate Risk (Public Trust) 2 Moderate
Non-Critical Sensitive (Secret, Confidential, “L” access) 3 Moderate
Non-Sensitive / High Risk (Public Trust) 4 High
Critical and Special Sensitive (Top Secret, SCI, “Q” access, most SAPs) 5 High

Source: PAC, Personnel Vetting Basics fact sheet, live on performance.gov as of 22 July 2026.

Do not put that model in your present tense: at FY2026-Q2 the first investigative service provider was only expected to start offering the new products in FY2026-Q3, the rest by September 2027.

What does continuous vetting actually check?

The government describes automated record checks, agency-specific information, and investigative actions triggered by time or by an event. Higher maturity states check more data sources.

A research limit belongs here. DCSA’s one-sheet enumerating the categories sits on dcsa.mil, which 403s every automated client, with no archived copy, and the secondary write-ups claiming to reproduce it contradict each other. So we print no list. For terminology, start with continuous vetting versus continuous evaluation.

The capability arrives in three maturity states: 1.25, 1.5 and 2.0. The national security population sits at 1.5. The PAC expects 2.0 in FY2028, gated on new NBIS capabilities. What replaced the reinvestigation is at its middle setting.

How often does continuous vetting flag someone?

About 1.13 new actionable alerts per quarter for every hundred enrollees, per the PAC’s FY2026-Q1 report. Enrollees, not cleared people. An actionable alert means new information requiring review. It is not a finding, not a suspension, and not an adverse action.

Read “enrollees” literally. The rate spans everyone enrolled in continuous vetting: 74 percent of the whole vetted federal workforce, including public trust employees at a lower maturity state where fewer data sources get checked. No cleared-only rate is published. It could run higher, and we cannot tell you by how much.

Absolute volume rose, then fell. GAO reported in February 2026 that alerts requiring review climbed from roughly 30,000 a quarter in fiscal year 2023 to over 100,000 in FY2025-Q3. The PAC’s FY2026-Q2 metrics file carries that series four quarters further and it turns over: actionable alerts peaked near 125,000 in FY2025-Q4, then fell to roughly 50,000 in FY2026-Q1 and 53,000 in FY2026-Q2. The chart prints no data labels, so we measured its bars against its own axis; the method reproduces both of GAO’s published points, which is our check on it. The PAC offers no explanation, and one quarter of slight recovery is not a trend. Our guides to a clearance suspended under continuous vetting and answering a Statement of Reasons trace what follows an alert that escalates.

Is NBIS running your continuous vetting?

No. GAO states that the PAC is enrolling personnel in legacy continuous vetting IT systems while DCSA builds NBIS. NBIS is the intended future home, not the current engine.

DOD has been building NBIS since 2016 and originally expected completion in 2019. GAO testimony of 24 February 2026 puts the current goal at fiscal year 2027, and warns that the absence of a reliable schedule will likely keep affecting whether it hits that goal.

On money: DOD projects an additional $2.2 billion on NBIS development through fiscal year 2031, on top of $2.4 billion previously spent on NBIS and legacy systems through fiscal year 2024. That earlier figure is not NBIS alone, whatever the press has printed.

A third of the agencies GAO surveyed in May 2025 said NBIS delays had disrupted their continuous vetting. Trusted Workforce 2.0 was meant to finish by the end of fiscal year 2026; it now sits at the end of fiscal year 2028, and at least 46 percent of NBIS milestones slipped after April 2025.

How fast is the process now, and which number should you believe?

Two very different numbers circulate. DCSA’s investigation phase runs 44 days for Secret and 57 for Top Secret. The government-wide end-to-end process, which also counts initiation and adjudication, runs 92 days for an initial Secret and 205 for an initial Top Secret.

They are not competing measurements of one thing; treating them as such would tell you clearances got four times faster than they did. The first pair, from the PAC’s FY2026-Q2 report, covers one agency and one of three phases: DCSA averaged 44 days on Secret-level investigations and 57 on Top Secret-level by the end of the quarter, the closest both have come to this pace since the third quarter of fiscal year 2012. Two qualifiers travel with it. The PAC’s companion metrics file, published the same day, prints 60 days rather than 57 for the same quarter’s High Risk cases. And FY2026 tightened the standards these are judged against, to 60 days for High Risk and 20 days for Moderate Risk, so Top Secret now lands inside its standard while Secret, at 44 days, is more than double its. GAO’s testimony adds that agencies “have not met timeliness goals for the investigative phase for initial Secret and Top Secret clearances since 2021.”

The second pair is the whole journey. ODNI measures it from agency initiation of information collection to the date adjudication is reported in a repository, and the data lags the quarterly report. At FY2026-Q1 it stood at 205 days for an initial Top Secret and 92 days for an initial Secret.

Every timeliness number above excludes the slowest ten percent of cases. That “fastest 90 percent” convention was set by Congress in 2004, and the PAC is replacing it with a measure covering 100 percent of cases, phased in from the very next report, which it says “will decrease reported timeliness.” If your case sits in the slow tenth, no figure here describes you.

The most actionable number is duller. A rejected case initiation (incomplete package, missing fingerprints, wrong investigation level) takes an average of 12.5 days to resolve. The rejection rate improved from 3.9 percent in FY2026-Q1 to 3.4 percent in FY2026-Q2, against a target of 1 percent by FY2028; the PAC revised that Q1 figure between reports, from 4.0 to 3.9 percent.

Where is the reform failing?

In its own scorecard. The PAC downgraded Optimize Risk Management, the goal containing continuous vetting, from Fair to Poor in FY2026-Q2 while upgrading two other goals. Its stated reason: reform improved issue identification, but adoption has been too slow.

Enrollment is where the slowness shows, and the populations must be kept apart. Across the entire vetted federal workforce it reached 74 percent in FY2026-Q1 and stayed there in FY2026-Q2. Within the non-sensitive public trust subset only, it sits at 35 percent against a milestone calling for full enrollment by September 2025, plateaued because several large agencies hit scaling problems. The PAC expects most of that population enrolled before the end of FY2026, so the plateau carries a stated expiry.

For a cleared reader the 35 percent is somebody else’s shortfall: national security sensitive populations are already enrolled. Behind you sit the public trust workforce and the low-risk population, for whom OPM issued planning guidance in August 2025 covering FY2027. Full enrollment is targeted for September 2028.

Does continuous vetting replace your duty to report?

No. Nothing in the 2026 guidance or the quarterly reports removes a cleared person’s self-reporting obligations under SEAD 3. Automated checks run alongside those duties, not instead of them.

The mistake is reasonable-sounding. If the government checks records continuously, why report a foreign contact it will find anyway? Because the obligation is separate, with its own thresholds, and an alert raised without a prior report reads differently from one that follows a disclosure. The reporting threshold under SEAD 3 has not moved. This piece describes what policy documents said on 22 July 2026; it is not legal advice, and reporting questions go to your FSO.

ClearedJobs.NET connects cleared talent with the employers who need it.
Whether you are hiring for a cleared req or holding a clearance and looking, start here.

Post a Cleared JobBrowse Cleared Jobs

Frequently Asked Questions

Do I still need a periodic reinvestigation?

Not on a schedule. DCSA’s April 2026 guidance removed the requirement for NISP contractor national security personnel. One can still be initiated: the PAC states that national security reinvestigations are now used primarily for significant issue resolution, and only “until the new TW 2.0 products are available.”

What is the PVQ Date, and can I look mine up?

It is a field in DISS, equivalent to your SF-86 date, and it drives the five-year cycle. DISS is a facility and government system, so your FSO pulls the DISS Subject Report and submits to PSMO-I. That is no longer the whole picture: DCSA released an Individual Engagement Platform in FY2026-Q2 that lets an individual check case status, and the PAC dates individual self-reporting and the five-year PVQ update inside it to September 2026. We did not verify a public sign-in path; ask your FSO.

Does continuous vetting mean I am under investigation all the time?

No. It is automated record checking, agency-specific information, and investigative actions triggered by time or by an event. An investigation follows only if a check produces an alert a reviewer decides needs resolving.

Will I still fill out an SF-86, or is it the PVQ now?

Both, for a while. The first PVQ forms were collected in FY2026-Q2, but the PAC expects adoption to be slow, and the questionnaire is not scheduled to cover every vetting scenario until September 2027. DCSA’s rule asks for “PVQ or SF-86 eApp and releases,” which describes a transition in progress.

What to watch next

A rising day count in the next few quarterly reports will read as collapse when it is a system finally counting its outliers. Two dates are worth marking: FY2027, when NBIS development is meant to finish, and the end of FY2028, when Trusted Workforce 2.0 is now due to complete after slipping two years. Until then the honest description of your status is narrow. The calendar reinvestigation is gone, a five-year form refresh took its place, and the one event that can still summon a full reinvestigation is an alert serious enough to need resolving. Ask your FSO when your PVQ Date lands.

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts

Comment

Notify me of updates to this conversation

Author

  • Ashley Jones is ClearedJobs.Net's blog Editor and a cleared job search expert, dedicated to helping security-cleared job seekers and employers navigate job search and recruitment challenges. With in-depth experience assisting cleared job seekers and transitioning military personnel at in-person and virtual Cleared Job Fairs and military base hiring events, Ashley has a deep understanding of the unique needs of the cleared community. She is also the Editor of ClearedJobs.Net's job search podcast, Security Cleared Jobs: Who's Hiring & How.

    View all posts
This entry was posted on Wednesday, July 22, 2026 6:42 am