Cognizant Security Agency
A Cognizant Security Agency (CSA) is a designated Executive Branch agency that has been authorized to run industrial security programs for protecting classified information handled by contractors. These agencies were established under Executive Order 12829, which created the National Industrial Security Program (NISP). Their role is to oversee and safeguard classified information within the portions of the NISP for which they are responsible.
Under the National Industrial Security Program (NISP), a Cognizant Security Agency (CSA) is an agency of the Executive Branch authorized by Executive Order 12829 (as subsequently amended) to establish an industrial security program for safeguarding classified information disclosed to or developed by industry. The CSA designation is distinct from a Cognizant Security Office (CSO), which is generally the operational component that implements a CSA's industrial security responsibilities; practitioners should not treat CSA and CSO as interchangeable. Historically the designated CSAs have included the Department of Defense, the Department of Energy, the Nuclear Regulatory Commission, and the Office of the Director of National Intelligence, with the Department of Homeland Security added by later amendment of E.O. 12829. This entry describes the general concept and does not resolve agency-specific delegations, current CSA rosters, or implementation details; readers should verify against the current governing authorities, including the NISPOM as codified at 32 CFR part 117 and related provisions such as 32 CFR 2004, rather than relying on superseded regulatory text.
Why it matters
The Cognizant Security Agency designation determines who is accountable for protecting classified information once it leaves government hands and enters the contractor environment. Because the National Industrial Security Program spans multiple Executive Branch agencies, knowing which CSA has authority over a given contract or program is foundational: it dictates whose industrial security rules, oversight processes, and clearance procedures apply to a cleared facility. Misidentifying the responsible CSA can lead a contractor to follow the wrong guidance or assume the wrong entity is monitoring compliance.
The CSA concept also clarifies a division of labor that practitioners frequently blur. A CSA is the Executive Branch agency authorized under Executive Order 12829 to run an industrial security program, while a Cognizant Security Office (CSO) is generally the operational component that implements that agency's responsibilities. Treating the two as interchangeable can cause confusion about where authority actually resides versus where day-to-day oversight is carried out. For example, the Defense Counterintelligence and Security Agency (DCSA) serves as the CSO administering industrial security for the Department of Defense portion of the NISP, but DCSA is not itself the CSA.
Because CSA designations and their governing regulations evolve, relying on outdated rosters or superseded regulatory text is a recurring risk. The Department of Homeland Security, for instance, was added as a designated CSA when Executive Order 13691 amended Executive Order 12829 in 2015. Compliance officers should confirm the current CSA structure and its authorities against the applicable current sources rather than assuming a static list.
Who it's relevant to
Inside CSA
Common questions
Answers to the questions practitioners most commonly ask about CSA.