Major Shift in DoD FOCI Rules: Why DoD Contractors Need Facility Security Officer (FSO) Now

Jul 30, 2026

The Defense Counterintelligence and Security Agency is about to oversee a dramatically larger universe of defense contractors. A major policy expansion is extending Foreign Ownership, Control, or Influence disclosure rules beyond classified programs applying them to all unclassified defense contracts valued over $5 million. That single change pushes DCSA’s oversight footprint from approximately 2,000 companies today to over 41,000 by October 1, 2026. More than 37,000 contractors that have never been subject to FOCI disclosure requirements will soon need to comply and most of them do not have the internal infrastructure to do it.  

At the center of that infrastructure is a dedicated Facility Security Officer, and demand for qualified FSOs is spiking faster than the supply can meet it. 

What the FOCI Policy Expansion Actually Means 

Foreign Ownership, Control, or Influence rules exist to protect U.S. national security interests by ensuring that entities with foreign ties cannot access sensitive defense information or exert influence over defense contractor operations in ways that compromise mission integrity. Until now, those rules have applied primarily to contractors holding facility security clearances on classified programs; a relatively contained population that DCSA could manage with its existing oversight capacity. The policy expansion changes that calculus entirely. 

By extending FOCI disclosure requirements to unclassified defense contracts above the $5 million threshold, the DoD is acknowledging that national security risk does not begin at the classified program boundary. Unclassified defense work infrastructure support, logistics, IT services, maintenance, professional services can expose sensitive operational information, supply chain dependencies, and technology that adversaries value even without a classification marking. The new framework treats that exposure as a compliance obligation, not just a risk to be managed informally. 

For contractors currently performing unclassified DoD work above $5 million, the implications are immediate. Per DCSA’s industrial security program guidance, firms subject to FOCI disclosure must assess their ownership structures, identify any foreign interests, and report those interests through the appropriate channels before their compliance deadline. Firms with foreign ownership, foreign board members, foreign investors above defined thresholds, or foreign-controlled parent companies face additional mitigation requirements including Board Resolutions, Special Security Agreements, or Proxy Agreements depending on the nature and degree of the foreign interest involved. None of those mitigations can be assembled quickly. Each requires legal structuring, DCSA review, and in some cases negotiation with agency security officials that takes months to complete. 

The FSO Shortage Is Already Critical 

A Facility Security Officer is the designated individual responsible for managing a contractor’s security program under 32 CFR Part 117, the National Industrial Security Program Operating Manual. The FSO serves as the primary interface between the contractor and DCSA, manages personnel security clearances, oversees physical and information security protocols, conducts security education and training, and ensures that the contractor’s security posture meets government requirements continuously not just at the time of an inspection. 

For the approximately 2,000 contractors currently operating under FOCI oversight, FSOs are a known and established function. For the 37,000 contractors entering that environment for the first time, they are an urgent and unfamiliar requirement. Many of those firms have never employed an FSO, never interacted with DCSA as a compliance authority, and never built the internal security documentation infrastructure that DCSA examinations require. The learning curve is steep, the deadline is fixed, and the consequences of noncompliance contract suspension, loss of eligibility for future DoD awards, and potential debarment are severe. 

The FSO talent market is not positioned to absorb 37,000 new demand signals simultaneously. Qualified FSOs with DCSA program experience, active clearances, and familiarity with the National Industrial Security Program are a finite and already-competitive talent pool. Contractors that wait until late 2026 to begin their FSO search will find that pool significantly depleted. iQuasar’s cleared staffing and FSO support services help contractors identify, place, and onboard qualified security professionals before the deadline pressure makes that process significantly harder and more expensive. 

Also Read: Cleared Talent Pipeline Strategy: Building a Bench Before You Need It 

Building the Compliance Infrastructure DCSA Will Examine 

An FSO without a supporting compliance infrastructure is a title without a function. DCSA examinations assess not just whether a contractor has designated an FSO but whether that FSO has built and is maintaining a security program that meets NISPOM requirements across every applicable area. That includes a current facility security plan, documented visitor control procedures, insider threat program elements, personnel security records for all cleared employees, security education and training completion records, and where foreign interests exist documentation of the applicable mitigation agreement and the contractor’s compliance with its terms. 

Firms entering the FOCI compliance environment for the first time should treat the October 1, 2026, deadline as a build deadline, not a start date. The security program that DCSA will examine on that date needs to be operational, documented, and tested before the deadline arrives. Gaps discovered during an initial DCSA examination do not produce a grace period they produce findings that can affect contract eligibility while remediation is underway. 

The DCSA FOCI Division publishes guidance on mitigation instruments and disclosure requirements that newly impacted contractors should review immediately. The National Industrial Security Program Operating Manual governs the full scope of what an FSO’s security program must address and is the baseline document for every compliance decision the FSO will make. Understanding both before building the program saves significant remediation time after an examination identifies structural gaps. 

What Contractors Should Do Before October 1, 2026 

  1. Resolve foreign influence and ownership issues first
    Conduct a FOCI assessment of your ownership structure, investors, board, and any foreign contractual ties. If reportable foreign interests turn up, bring in FOCI mitigation counsel immediately and start negotiating an SSA or Proxy Agreement — this process is slow and the deadline is close. In parallel, make sure your SAM.gov registration accurately reflects current ownership and control, since any mismatch between that filing and what DCSA finds later becomes a much bigger problem than the original issue. 
  2. Stand up your security infrastructure and personnel
    Decide now whether you’ll hire a dedicated FSO, train an internal employee for the role, or use an outsourced FSO service. Give that person time to complete DCSA/CDSE training, build the facility security plan, and implement the insider threat program before oversight begins.  
  3. Registery our facility
    Register in DCSA’s Industrial Security Facilities Database and ensure your SAM.gov registration accurately reflects your company’s ownership and control information. Discrepancies between what DCSA finds in an examination and what your firm has represented in federal registration systems create compounding compliance exposure that is far more difficult to resolve than the underlying issue would have been on its own. 

The DoD’s FOCI expansion is not a future problem. For contractors performing unclassified defense work above $5 million, it is a present obligation with a fixed deadline and real contract consequences for firms that are not ready. The FSO shortage, the compliance infrastructure build requirement, and the FOCI mitigation timeline all argue for starting now not when the deadline is visible in the rearview mirror. 

If your firm needs support identifying a qualified FSO, assessing your FOCI exposure, or building the security program infrastructure that DCSA will examine, iQuasar’s cleared staffing and security compliance team works with defense contractors at every stage of this process. Contact us today to get ahead of the October 2026 deadline before the talent market makes it harder. 

 

Talk To Our Expert

Share

Subscribe To Our Newsletter


Skip to content