NISPOM (32 CFR Part 117)
The NISPOM is the U.S. government's set of rules that tells private companies how to protect classified information when they work on government contracts that require access to such information. It was historically issued as a Department of Defense manual and was later codified into federal regulation as 32 CFR Part 117, giving it the force of a binding rule. Companies participating in the National Industrial Security Program must follow it to be trusted with classified material.
The NISPOM establishes the baseline security requirements for cleared contractors and other non-government entities participating in the National Industrial Security Program (NISP) to safeguard classified information entrusted to industry. It was historically maintained as a DoD operating manual and was subsequently codified as a federal regulation at 32 CFR Part 117, which is intended to make its requirements directly enforceable rather than advisory. Its scope generally covers the protection of classified national security information in industry, including facility clearances, personnel security clearances, safeguarding, marking, and reporting obligations, and it should be distinguished from frameworks governing Controlled Unclassified Information (CUI) such as NIST SP 800-171 and from the Risk Management Framework (RMF) applied to DoD information systems. Practitioners should note that classified information systems accreditation and specific technical controls may be governed by additional guidance beyond the NISPOM itself, and applicability, cognizant security agency roles, and specific provisions should be verified against the current authoritative text of 32 CFR Part 117.
Why it matters
For companies that hold classified contracts, the NISPOM is the governing rulebook that determines whether they can be trusted with classified national security information at all. Its codification as a federal regulation at 32 CFR Part 117 is significant because it is intended to give the requirements the force of a binding rule rather than the status of an internal government manual. In practice this means that facility clearances, personnel security clearances, safeguarding, marking, and reporting obligations are enforceable regulatory requirements, and failure to meet them can jeopardize a contractor's ability to participate in the National Industrial Security Program.
The NISPOM also matters because it occupies a distinct place in the compliance landscape that is easy to misread. It governs the protection of classified information in industry and should not be conflated with frameworks that address Controlled Unclassified Information (CUI), such as NIST SP 800-171, or with the Risk Management Framework (RMF) applied to DoD information systems. Treating these as interchangeable is a common and consequential error, because the obligations, oversight roles, and enforcement mechanisms differ. Compliance with a CUI framework does not satisfy NISPOM obligations, and vice versa.
Because the historical DoD manual was codified into regulation, practitioners should be careful to work from the current authoritative text at 32 CFR Part 117 rather than older manual versions. Specific provisions, cognizant security agency roles, and the technical controls applicable to classified information systems may be governed by additional guidance beyond the NISPOM itself, and readers should verify current applicability against the official regulatory text.
Who it's relevant to
Inside NISPOM
Common questions
Answers to the questions practitioners most commonly ask about NISPOM.