Skip to main content
Category: Classified Information Management

Cognizant Security Agency

Also known as:
Simply put

A Cognizant Security Agency (CSA) is a designated Executive Branch agency that has been authorized to run industrial security programs for protecting classified information handled by contractors. These agencies were established under Executive Order 12829, which created the National Industrial Security Program (NISP). Their role is to oversee and safeguard classified information within the portions of the NISP for which they are responsible.

Formal definition

Under the National Industrial Security Program (NISP), a Cognizant Security Agency (CSA) is an agency of the Executive Branch authorized by Executive Order 12829 (as subsequently amended) to establish an industrial security program for safeguarding classified information disclosed to or developed by industry. The CSA designation is distinct from a Cognizant Security Office (CSO), which is generally the operational component that implements a CSA's industrial security responsibilities; practitioners should not treat CSA and CSO as interchangeable. Historically the designated CSAs have included the Department of Defense, the Department of Energy, the Nuclear Regulatory Commission, and the Office of the Director of National Intelligence, with the Department of Homeland Security added by later amendment of E.O. 12829. This entry describes the general concept and does not resolve agency-specific delegations, current CSA rosters, or implementation details; readers should verify against the current governing authorities, including the NISPOM as codified at 32 CFR part 117 and related provisions such as 32 CFR 2004, rather than relying on superseded regulatory text.

Why it matters

The Cognizant Security Agency designation determines who is accountable for protecting classified information once it leaves government hands and enters the contractor environment. Because the National Industrial Security Program spans multiple Executive Branch agencies, knowing which CSA has authority over a given contract or program is foundational: it dictates whose industrial security rules, oversight processes, and clearance procedures apply to a cleared facility. Misidentifying the responsible CSA can lead a contractor to follow the wrong guidance or assume the wrong entity is monitoring compliance.

The CSA concept also clarifies a division of labor that practitioners frequently blur. A CSA is the Executive Branch agency authorized under Executive Order 12829 to run an industrial security program, while a Cognizant Security Office (CSO) is generally the operational component that implements that agency's responsibilities. Treating the two as interchangeable can cause confusion about where authority actually resides versus where day-to-day oversight is carried out. For example, the Defense Counterintelligence and Security Agency (DCSA) serves as the CSO administering industrial security for the Department of Defense portion of the NISP, but DCSA is not itself the CSA.

Because CSA designations and their governing regulations evolve, relying on outdated rosters or superseded regulatory text is a recurring risk. The Department of Homeland Security, for instance, was added as a designated CSA when Executive Order 13691 amended Executive Order 12829 in 2015. Compliance officers should confirm the current CSA structure and its authorities against the applicable current sources rather than assuming a static list.

Who it's relevant to

Facility Security Officers (FSOs) and cleared contractors
FSOs must know which CSA has cognizance over their classified work, because the responsible agency's industrial security program governs how they safeguard classified information and interact with oversight. They should also distinguish the CSA from the CSO that provides day-to-day administration, and confirm current designations against the NISPOM at 32 CFR part 117 rather than relying on legacy guidance.
Government program and contracting officials
Officials issuing classified contracts need to identify the correct CSA for the information being disclosed to or developed by industry, since the CSA's program frames the security requirements imposed on contractors. Given that CSA designations have changed through amendments to Executive Order 12829, these officials should verify the current authorities before assigning responsibilities.
Compliance officers and industrial security auditors
Those assessing NISP compliance must map obligations to the appropriate CSA and its implementing CSO, and avoid treating the two as interchangeable. They should anchor their reviews to current governing authorities, including 32 CFR part 117 and 32 CFR 2004, and confirm agency-specific delegations rather than assuming a fixed CSA roster.

Inside CSA

Designated Agency Authority
A Cognizant Security Agency (CSA) is an executive branch agency designated under Executive Order 12829 (as amended) with authority to establish and administer an industrial security program on behalf of the government within its area of responsibility. The current designated CSAs are the Department of Defense, the Department of Energy, the Nuclear Regulatory Commission, the Office of the Director of National Intelligence, and the Department of Homeland Security (added when Executive Order 13691 amended EO 12829 in 2015). Practitioners should verify the current list against the governing text.
Governing Framework
The role and definition of a CSA are anchored in the National Industrial Security Program (NISP) framework. Current governing definitions appear in 32 CFR 2004.4 and the NISPOM codified at 32 CFR Part 117; older references to 32 CFR 148.12 are superseded. Readers should confirm against the current authoritative CFR text, as regulatory citations and definitions can change across revisions.
Industrial Security Program Administration
A CSA is generally responsible for administering the industrial security program for classified information within its jurisdiction, including oversight of cleared contractors and facilities under its cognizance. The Defense Counterintelligence and Security Agency (DCSA) performs industrial security oversight functions for the Department of Defense (DoD) and, by agreement, for other federal agencies.
Scope and Jurisdiction
Each CSA's authority is bounded by its assigned area of responsibility. The applicability of CSA oversight is specific to the protection of classified information under the NISP and is distinct from requirements governing Controlled Unclassified Information (CUI) or civilian agency systems under FISMA. State, local, tribal, and territorial obligations generally fall outside the CSA construct.

Common questions

Answers to the questions practitioners most commonly ask about CSA.

Is the Cognizant Security Agency the same thing as a Cognizant Security Office (CSO)?
No. These are distinct concepts and should not be treated as interchangeable terms. A Cognizant Security Agency (CSA) is an agency designated with responsibility for administering security under the National Industrial Security Program (NISP) for entities within its purview. A Cognizant Security Office (CSO) generally refers to the organizational component that a CSA designates to carry out its industrial security responsibilities. In other words, the CSO typically operates under the authority of a CSA rather than being another name for it. Readers should verify the specific relationship and delegations against the current NISPOM at 32 CFR part 117 and 32 CFR 2004.4.
Is the Department of Defense the only Cognizant Security Agency?
No. While the Department of Defense is a designated CSA, it is not the only one. Executive Order 12829 established the NISP and designated CSAs, and Executive Order 13691 (2015) amended EO 12829 to add the Department of Homeland Security as a designated CSA. Other agencies have also been designated as CSAs. Because designations and their scope can change over time, readers should confirm the current list of CSAs and their respective responsibilities against the governing authorities, including 32 CFR 2004.4 and the NISPOM at 32 CFR part 117.
Which authorities govern the definition and responsibilities of a CSA?
The concept of the CSA arises from the National Industrial Security Program, established under Executive Order 12829 as amended (including by Executive Order 13691). Current governing definitions and responsibilities are generally found in 32 CFR 2004.4 and in the NISPOM codified at 32 CFR part 117. Note that some older references cite provisions that have since been superseded or recodified, so practitioners should anchor their work to the current text of these authorities rather than to legacy citations.
How does a contractor determine which CSA has cognizance over its facility?
Cognizance generally depends on the contracting relationship and the agency for which classified work is performed, as administered under the NISP. Because a facility may perform classified work for more than one agency, the applicable CSA and any delegated Cognizant Security Office should be confirmed based on the specific contract and program arrangements. Contractors should verify their current cognizant authority through official channels and the governing provisions in 32 CFR part 117, as this entry does not resolve facility-specific determinations.
Can cognizance for a single contractor facility involve more than one CSA?
In many implementations, a contractor performing classified work for multiple agencies may fall within the purview of more than one CSA, with responsibilities allocated according to the NISP framework and any interagency arrangements. The precise allocation of oversight, inspections, and security responsibilities in such cases depends on the applicable agreements and the governing NISPOM provisions. Contractors should confirm how cognizance is divided or delegated for their particular situation with the relevant CSAs and against 32 CFR part 117 and 32 CFR 2004.4.
Does a CSA's role under the NISP address unclassified information security requirements?
The CSA construct is oriented toward administering security responsibilities under the National Industrial Security Program, which centers on the protection of classified information within industry. Requirements applicable to Controlled Unclassified Information or to systems governed by other frameworks are generally addressed through separate authorities and should not be assumed to fall within the CSA's NISP role. Readers should determine the applicable requirements for their information type against the relevant governing sources, as this entry does not cover unclassified information programs.

Common misconceptions

The term Cognizant Security Agency (CSA) and Cognizant Security Office (CSO) are interchangeable.
They are distinct concepts. A CSA is the designated executive branch agency with authority to administer an industrial security program, while a CSO is a separate designation. The two should not be treated as aliases for one another; consult the governing definitions in 32 CFR 2004.4 and the NISPOM (32 CFR Part 117) for the precise distinctions.
The Department of Defense is the only Cognizant Security Agency.
The DoD is one of several designated CSAs. Under Executive Order 12829 as amended, the Department of Energy, the Nuclear Regulatory Commission, the Office of the Director of National Intelligence, and (since EO 13691 in 2015) the Department of Homeland Security are also designated CSAs, each within its area of responsibility.
CSA industrial security oversight and cybersecurity compliance under frameworks like FISMA or RMF are the same thing.
CSA responsibilities center on the protection of classified information under the NISP, which is a different scope than information system authorization and cybersecurity compliance obligations under FISMA, the Risk Management Framework, or CUI protection requirements. Compliance with one set of obligations does not automatically satisfy the other.

Best practices

Identify which CSA has cognizance over your facility or activity based on its assigned area of responsibility, rather than assuming the Department of Defense by default.
Verify current CSA definitions and designations against the governing text in 32 CFR 2004.4 and the NISPOM at 32 CFR Part 117, and avoid relying on superseded citations such as 32 CFR 148.12.
Distinguish the CSA role from that of a Cognizant Security Office (CSO), and confirm which entity performs oversight functions in your specific case.
Confirm the current list of designated CSAs against Executive Order 12829 as amended (including the 2015 amendment by EO 13691), since designations can change over time.
Treat CSA industrial security obligations for classified information as distinct from cybersecurity compliance requirements under FISMA, the RMF, or CUI rules, and address each within its proper scope.
When authoritative details such as effective dates or exact regulatory language are needed, consult the current official CFR text and applicable executive orders rather than secondary summaries.