Skip to main content
Category: Classified Information Management

Facility Clearance

Also known as: FCL, Facility Security Clearance
Simply put

A Facility Clearance (FCL) is a determination by the U.S. Government that a company or organization is eligible to access classified information. Any facility performing on a classified contract, whether as a prime contractor or subcontractor, generally must hold an active FCL to work on the classified requirements. It reflects the government's assessment that the organization can be trusted to safeguard classified information.

Formal definition

An FCL is an administrative determination that a contractor entity is eligible for access to classified information, made in connection with classified contract performance. As described in the available evidence, the determination involves an assessment of an organization's eligibility and its ability to safeguard classified information, including its security posture. Per DCSA guidance, any facility awarded a classified contract as prime or subcontractor generally must hold an active FCL to perform on the classified requirements; the evidence also associates FCL adjudication with entity vetting and Foreign Ownership, Control, or Influence (FOCI) considerations. Note that an FCL pertains to an entity's eligibility to access classified information and is distinct from individual personnel security clearances; the specific procedural, revalidation, and FOCI mitigation requirements are not detailed in the evidence provided and should be verified against current DCSA and applicable official sources.

Why it matters

A Facility Clearance is the gateway that determines whether an organization can lawfully participate in classified contract work at all. Because any facility awarded a classified contract, whether as a prime or subcontractor, generally must hold an active FCL to perform on the classified requirements, the FCL functions as a threshold eligibility condition for a significant segment of the defense and national security marketplace. Without it, an otherwise capable organization cannot be placed on classified requirements, and prime contractors must confirm that their subcontractors are appropriately cleared before flowing down classified work.

The FCL also reflects a government judgment that is broader than a checklist: it represents a determination that the organization is eligible and can be trusted to safeguard classified information, an assessment that considers the entity's security posture and, per DCSA guidance, entity vetting and Foreign Ownership, Control, or Influence (FOCI) considerations. This distinguishes the FCL as an assessment of an organizational entity rather than of any single individual. A common and consequential mistake is to conflate a Facility Clearance with individual personnel security clearances; the two are related but distinct, and holding one does not establish the other.

Compliance leaders should also treat an FCL as a status to be maintained rather than a one-time achievement. The specific procedural, revalidation, and FOCI mitigation requirements are not detailed in the evidence available here, and organizations should verify current obligations against DCSA and other applicable official sources rather than assuming an FCL is permanent or self-sustaining once granted.

Who it's relevant to

Prime Contractors Pursuing Classified Work
Organizations bidding on or performing classified contracts generally must hold an active FCL to work on the classified requirements. Prime contractors are also positioned to flow classified work to subcontractors and should confirm that those subcontractors hold appropriate active FCLs before doing so.
Subcontractors on Classified Requirements
A facility awarded classified work as a subcontractor generally must hold an active FCL to perform on the classified requirements, just as a prime does. Subcontractors should not assume that a prime's clearance covers their own eligibility.
Facility Security Officers and Industrial Security Staff
Personnel responsible for industrial security are central to establishing and sustaining the organization's eligibility to safeguard classified information. They should track the entity's security posture and verify current procedural and revalidation requirements against DCSA guidance, since the specifics are not detailed in the evidence here.
Corporate Leadership and Owners Subject to FOCI Review
Because FCL adjudication is associated with entity vetting and Foreign Ownership, Control, or Influence (FOCI) considerations, ownership and executive leadership are directly relevant to eligibility determinations. Organizations with foreign ownership or control interests should confirm applicable FOCI mitigation requirements with DCSA and other official sources.
Contracting and Compliance Officers
Those managing classified contract eligibility should treat the FCL as an entity-level determination distinct from individual personnel clearances, and should not assume it is permanent. Confirm current maintenance and revalidation obligations against authoritative DCSA and applicable government sources.

Inside FCL

Administrative Determination of Eligibility
An FCL is an administrative determination that a contractor is eligible to access classified information at a given classification level. It is a determination about the organization as a legal entity, not about any individual employee.
Relationship to Personnel Clearances (PCLs)
An FCL establishes the entity's eligibility, while individual access still depends on separate personnel security clearances at the appropriate level and a validated need-to-know. The FCL and the PCL are distinct and neither substitutes for the other.
Classification Level Scope
An FCL is granted for a specific classification level. Eligibility to handle information at a higher level generally requires the corresponding higher-level FCL, and readers should confirm the specific level authorized against the governing determination.
Foreign Ownership, Control, or Influence (FOCI) Considerations
The eligibility determination generally involves evaluating whether foreign ownership, control, or influence could affect the contractor's ability to safeguard classified information, and mitigation measures may be required in some cases.
Governing Framework
FCL requirements are associated with the National Industrial Security Program and its operating manual (commonly referenced as the NISPOM). Readers should verify the current authoritative text, as specific procedures and cognizant security agency responsibilities may vary and change over time.
Sponsorship Requirement
An FCL generally cannot be self-initiated; a contractor typically must be sponsored, often in connection with a classified contract or a legitimate prospective classified requirement.

Common questions

Answers to the questions practitioners most commonly ask about FCL.

Does a Facility Clearance (FCL) mean my company's employees are automatically cleared to access classified information?
No. An FCL is an eligibility determination for the legal entity (the company or facility), not for individuals. Personnel who need to access classified information must hold their own Personnel Security Clearances (PCLs) at the appropriate level. The FCL establishes that the organization is eligible to access or store classified information under the applicable government contract; individual access still depends on a separate PCL, a valid need-to-know, and any additional access requirements. Confirm current requirements against the governing NISPOM guidance and your Cognizant Security Agency.
If my company holds a Secret-level FCL, can it handle Top Secret information as well?
Not on the basis of the Secret FCL alone. An FCL is granted at a specific classification level, and a facility is generally eligible to access classified information only up to the level of its FCL. Handling information at a higher level would require an FCL at that higher level, and storage of classified material carries its own separate safeguarding and storage capability requirements that are distinct from the eligibility to access. Verify level-specific requirements with your Cognizant Security Agency before assuming any capability.
How does a company obtain an FCL?
In most implementations, a company cannot self-initiate an FCL. It is typically sponsored, either by a government contracting activity or by another cleared contractor (a prime), in connection with a legitimate requirement to access classified information, such as a classified contract or a bid on one. The sponsoring entity generally initiates the request through the applicable government process, after which the facility works with its Cognizant Security Agency to complete the required steps. Confirm the current sponsorship and submission process with the relevant security agency, as procedures and systems may change.
What organizational elements are typically reviewed as part of the FCL process?
The process generally examines factors such as the company's ownership and organizational structure, foreign ownership, control, or influence (FOCI) considerations, and the designation of appropriate security officials to manage the classified environment. Where FOCI concerns exist, a mitigation arrangement may be required before an FCL can be granted. This entry does not cover the specific instruments or thresholds involved; confirm current criteria and required documentation against the governing NISPOM guidance and your Cognizant Security Agency.
Is a Facility Clearance a permanent status once granted?
No. An FCL is a continuing eligibility status that depends on the facility maintaining compliance with applicable security requirements and on the ongoing existence of a valid need. It can be affected by changes such as shifts in ownership, FOCI status, or the company's designated security officials, and it may be reviewed or terminated if the underlying conditions or requirements are no longer met. Facilities should treat maintenance of the FCL as an ongoing obligation and verify current requirements with their Cognizant Security Agency.
How does an FCL relate to other cybersecurity compliance obligations like CMMC or DFARS requirements?
An FCL addresses eligibility to access classified information and is administered under the National Industrial Security Program framework, which is distinct from requirements governing Controlled Unclassified Information (CUI). Obligations such as DFARS safeguarding clauses and CMMC generally address CUI and covered defense information rather than classified information, and holding an FCL does not by itself satisfy those separate requirements. Organizations may be subject to both classified-information obligations and CUI-focused obligations depending on their contracts. Confirm which frameworks apply to your specific work against the applicable contract terms and current official sources.

Common misconceptions

An FCL clears the company's employees to access classified information.
An FCL is an entity-level eligibility determination only. Individual employees still require appropriate personnel security clearances (PCLs) and a validated need-to-know before accessing classified information.
A company can obtain an FCL on its own to make itself more competitive for classified work.
An FCL generally requires sponsorship tied to a classified requirement or contract; it typically cannot be self-initiated absent a legitimate need.
An FCL at one classification level covers work at any higher level.
An FCL is scoped to a specific classification level, and access to information at a higher level generally requires the corresponding higher-level eligibility. Confirm the authorized level against the governing determination.

Best practices

Confirm the specific classification level authorized under the FCL and do not assume it extends to higher levels of classified information.
Track personnel security clearances separately from the FCL, ensuring individual PCLs and need-to-know are validated before any access to classified information.
Secure appropriate sponsorship tied to a legitimate classified requirement before pursuing an FCL, rather than attempting to self-initiate.
Assess and, where applicable, plan for mitigation of any foreign ownership, control, or influence (FOCI) that could affect the eligibility determination.
Verify current FCL procedures and cognizant security agency responsibilities against the applicable version of the governing NISP operating manual rather than relying on prior practice.
Distinguish the FCL as an eligibility determination from actual security implementation, and confirm contractual and safeguarding obligations against current official sources.