Scope
This guide outlines the assessment, inventory, and standardization requirements introduced by National Security Presidential Memorandum 12 (NSPM-12) for agencies operating National Security Systems (NSS). You'll find implementation steps, requirement breakdowns, and practical guidance for compliance officers managing the shift from self-assessment frameworks to third-party evaluation models.
This guide does not address classified systems under Committee on National Security Systems Instruction No. 1253 or contractor obligations under DFARS 252.204-7012, though many principles overlap.
Key Concepts and Definitions
National Security Systems (NSS): These are information systems operated by an agency that involve intelligence activities, cryptologic activities, command and control of military forces, equipment integral to a weapon system, or systems critical to direct military or intelligence missions. They fall outside FISMA's scope but are now subject to NSPM-12's assessment regime.
National Manager of NSS: This is the authority designated under the Director of the National Security Agency responsible for security assessments and recommendations across NSS environments government-wide.
Third-Party Assessment Model: This model shifts from agency-created checklists and self-evaluation to external validation of cybersecurity frameworks and controls. It parallels the Third-Party Assessment Organization structure in FedRAMP and the Certified Third-Party Assessment Organization (C3PAO) model under CMMC 2.0.
Annual NSS Inventory: A living catalog of all NSS owned or operated by each agency, updated annually to reflect current system boundaries, authorization status, and security posture.
Requirements Breakdown
Assessment Authority (NSA/National Manager)
NSPM-12 designates the National Manager of NSS, operating under the Director of NSA, with responsibility for security assessments and recommendations across government NSS environments. This creates a centralized assessment authority where none existed consistently before.
Your action: Identify which of your systems qualify as NSS. If you're uncertain whether a system meets the NSS definition, document your rationale and coordinate with your agency's authorizing official. Systems you've been treating as FISMA-covered may actually fall under NSS criteria.
Conflict risk: Multiple federal entities currently conduct cybersecurity assessments across agencies. You need clarity on whether NSA's assessment authority supersedes, complements, or conflicts with existing oversight from your Inspector General, the Cybersecurity and Infrastructure Security Agency, or your Sector Risk Management Agency. Request written guidance from your agency's Chief Information Security Officer on deconfliction procedures before your first assessment cycle.
Annual NSS Inventory Requirement
Each agency must maintain and annually update an inventory of all NSS owned or operated by that agency. This isn't a one-time documentation exercise; it's an ongoing accountability mechanism.
Your action: Build your inventory structure around these minimum elements:
- System name and unique identifier
- System owner and authorizing official
- Mission criticality and impact level
- Current authorization status and expiration date
- Assessment date and assessing entity
- Known vulnerabilities or Plan of Action and Milestones items affecting authorization
If you're already maintaining a system inventory under FISMA or OMB Circular A-130, you can't simply repurpose that inventory. NSS and FISMA systems are mutually exclusive categories. You need separate inventories with separate update cycles.
Consistency and Uniformity Across Civilian and Defense Organizations
NSPM-12 calls for greater consistency and uniformity of cyber standards across both civilian and defense organizations. The directive explicitly encourages civilian agencies to adopt protections that defense organizations have implemented more effectively.
Your action: If you're in a civilian agency, review the DoD Cloud Computing Security Requirements Guide and Committee on National Security Systems Instruction No. 1253 for controls that exceed your current NIST SP 800-53 Rev 5 baseline. Look specifically at:
- Continuous monitoring frequencies
- Incident response timelines
- Vulnerability remediation windows
- Supply chain risk management practices
You won't be required to adopt DoD-specific controls wholesale, but you should be prepared to justify any gaps during third-party assessments.
Implementation Guidance
Preparing for Third-Party Assessment
You've likely been assessing your cybersecurity frameworks using checklists your team created internally. That model ends under NSPM-12's assessment regime.
Before your first assessment:
Document your current control implementation. Don't wait for the assessor to ask. Have evidence ready for each control in your baseline: policies, procedures, configuration screenshots, log samples, and interview schedules.
Identify assessment criteria gaps. Your self-assessment criteria may not align with what the National Manager uses. Request sample assessment procedures or criteria from NSA if available, or reference NIST SP 800-53A Rev 5 assessment procedures as a proxy.
Remediate obvious deficiencies now. Third-party assessments will surface control gaps you've been deferring. If you have open Plan of Action and Milestones items older than 180 days, close them or document why they're still open with evidence of progress.
Building and Maintaining Your NSS Inventory
Your inventory update cycle should align with your authorization boundary reviews. If you're adding systems, decommissioning systems, or significantly changing system architectures, update your inventory within 30 days of the change.
Inventory maintenance workflow:
- Quarterly: System owners confirm no boundary changes
- Annually: Full inventory review and update submitted to National Manager
- Event-driven: Updates within 30 days of major changes (new interconnections, mission changes, authorization renewals)
Use your existing Enterprise Mission Assurance Support Service instance if you're in DoD, or build a comparable tracking mechanism if you're in a civilian agency without access to eMASS.
Standardization Across Agency Boundaries
Consistency doesn't mean identical. Your agency's mission drives your risk tolerance and control selection. But you can't justify weaker controls simply because "we've always done it this way."
When you're selecting controls that deviate from what defense organizations implement, document your risk-based rationale. "We're a civilian agency" isn't sufficient justification. "Our mission doesn't involve CUI Basic or classified processing, so we implemented AC-6(5) using a different technical mechanism appropriate to our environment" is.
Common Pitfalls
Treating this as a documentation exercise: NSPM-12 isn't asking for better paperwork. It's asking for measurable security outcomes validated by external assessors. If your current controls wouldn't pass a Third-Party Assessment Organization review under FedRAMP, they won't pass NSA's assessment either.
Assuming your existing FISMA inventory satisfies the NSS inventory requirement: These are separate systems with separate requirements. Don't merge them.
Waiting for detailed implementation guidance before acting: You won't get a 200-page implementation guide with step-by-step procedures. NSPM-12 is outcome-based. Start with the requirements as written and refine your approach as assessment criteria become clear.
Ignoring the funding dependency: NSPM-12's objectives require resources. If your agency hasn't budgeted for third-party assessments, continuous monitoring tools, or remediation efforts, flag that gap to your leadership now. Congressional appropriators may withhold funding from non-compliant agencies.
Overlooking assessment authority conflicts: If you receive assessment taskings from multiple entities (your IG, CISA, NSA, your SRMA), you need a deconfliction process. Coordinate through your agency's senior cybersecurity official to avoid redundant or conflicting assessment activities.
Quick Reference Table
| Requirement | Frequency | Responsible Party | Key Deliverable |
|---|---|---|---|
| NSS Inventory Update | Annual (minimum) | Agency CISO / System Owners | Complete inventory submitted to National Manager |
| Third-Party Assessment | TBD by National Manager | NSA / Designated Assessor | Assessment report with findings and recommendations |
| Inventory Event Updates | Within 30 days of change | System Owner | Updated inventory entry |
| Control Baseline Review | Annually or at reauthorization | Authorizing Official | Documented control selection rationale |
| Assessment Readiness Review | 90 days before assessment | ISSO / System Owner | Evidence package for all baseline controls |
| Deconfliction Coordination | As needed when multiple assessors involved | Agency Senior Cybersecurity Official | Written assessment schedule and scope agreements |
Next steps: Review your current NSS portfolio against the inventory requirements. Identify systems where you lack current authorization or where your last assessment used self-created criteria. Those systems are your highest risk for adverse findings when third-party assessments begin. Start evidence collection now.



