Skip to main content
Category: Classified Information Management

NISPOM (32 CFR Part 117)

Also known as: NISPOM, National Industrial Security Program Operating Manual, 32 CFR Part 117, NISPOM Rule
Simply put

The NISPOM is the U.S. government's set of rules that tells private companies how to protect classified information when they work on government contracts that require access to such information. It was historically issued as a Department of Defense manual and was later codified into federal regulation as 32 CFR Part 117, giving it the force of a binding rule. Companies participating in the National Industrial Security Program must follow it to be trusted with classified material.

Formal definition

The NISPOM establishes the baseline security requirements for cleared contractors and other non-government entities participating in the National Industrial Security Program (NISP) to safeguard classified information entrusted to industry. It was historically maintained as a DoD operating manual and was subsequently codified as a federal regulation at 32 CFR Part 117, which is intended to make its requirements directly enforceable rather than advisory. Its scope generally covers the protection of classified national security information in industry, including facility clearances, personnel security clearances, safeguarding, marking, and reporting obligations, and it should be distinguished from frameworks governing Controlled Unclassified Information (CUI) such as NIST SP 800-171 and from the Risk Management Framework (RMF) applied to DoD information systems. Practitioners should note that classified information systems accreditation and specific technical controls may be governed by additional guidance beyond the NISPOM itself, and applicability, cognizant security agency roles, and specific provisions should be verified against the current authoritative text of 32 CFR Part 117.

Why it matters

For companies that hold classified contracts, the NISPOM is the governing rulebook that determines whether they can be trusted with classified national security information at all. Its codification as a federal regulation at 32 CFR Part 117 is significant because it is intended to give the requirements the force of a binding rule rather than the status of an internal government manual. In practice this means that facility clearances, personnel security clearances, safeguarding, marking, and reporting obligations are enforceable regulatory requirements, and failure to meet them can jeopardize a contractor's ability to participate in the National Industrial Security Program.

The NISPOM also matters because it occupies a distinct place in the compliance landscape that is easy to misread. It governs the protection of classified information in industry and should not be conflated with frameworks that address Controlled Unclassified Information (CUI), such as NIST SP 800-171, or with the Risk Management Framework (RMF) applied to DoD information systems. Treating these as interchangeable is a common and consequential error, because the obligations, oversight roles, and enforcement mechanisms differ. Compliance with a CUI framework does not satisfy NISPOM obligations, and vice versa.

Because the historical DoD manual was codified into regulation, practitioners should be careful to work from the current authoritative text at 32 CFR Part 117 rather than older manual versions. Specific provisions, cognizant security agency roles, and the technical controls applicable to classified information systems may be governed by additional guidance beyond the NISPOM itself, and readers should verify current applicability against the official regulatory text.

Who it's relevant to

Cleared Government Contractors
Companies participating in the National Industrial Security Program must follow the NISPOM to be entrusted with classified material. This includes obligations around facility clearances, safeguarding, marking, and reporting. Contractors should confirm their specific requirements and the role of their cognizant security agency against the current text of 32 CFR Part 117.
Facility Security Officers and Security Personnel
Those responsible for administering a contractor's security program rely on the NISPOM as the baseline for facility clearances, personnel security clearances, safeguarding classified information, and meeting reporting obligations. They should note that classified information system accreditation and specific technical controls may be governed by additional guidance beyond the NISPOM itself.
Compliance and Audit Professionals
Practitioners assessing contractor compliance should distinguish NISPOM obligations from frameworks governing Controlled Unclassified Information, such as NIST SP 800-171, and from the Risk Management Framework applied to DoD information systems. Compliance with a CUI framework does not satisfy NISPOM requirements, and the two should not be treated as interchangeable.
Contract and Legal Advisors
Advisors supporting classified contract work should treat 32 CFR Part 117 as the codified, binding text rather than relying on the historical DoD manual. Applicability, cognizant security agency roles, and specific provisions should be verified against the current authoritative regulation, as this entry does not cover contract-specific or legal specifics.

Inside NISPOM

Rule Codification (32 CFR Part 117)
The National Industrial Security Program Operating Manual is codified as a federal regulation in Title 32 of the Code of Federal Regulations, Part 117, giving it the force and effect of law for covered contractors rather than existing solely as DoD-issued policy guidance. Readers should verify the current text against the official regulation, as amendments may occur.
Scope of Application
The rule generally applies to contractors that require access to classified information under the National Industrial Security Program (NISP). Its focus is on the protection of classified information within industry, which is a distinct scope from the protection of Controlled Unclassified Information (CUI) addressed by other authorities such as NIST SP 800-171 and DFARS clause 252.204-7012.
Facility Security and Clearances
The framework addresses requirements associated with facility clearances (FCLs) and personnel security clearances for individuals who require access to classified information, as administered within the NISP. Specific eligibility, adjudication, and processing details should be confirmed against current authoritative sources.
Safeguarding of Classified Information
The rule sets expectations for the protection, handling, storage, and control of classified information held by contractors participating in the NISP. Implementation specifics are subject to agency and contract-level direction and should be verified.
Relationship to Oversight Authorities
The NISP involves oversight from cognizant security agencies, and administration of industrial security functions is generally associated with the relevant DoD components. The precise allocation of oversight responsibilities should be confirmed against the current regulation and applicable agency guidance.

Common questions

Answers to the questions practitioners most commonly ask about NISPOM.

Is the NISPOM still just a DoD manual (DoD 5220.22-M) that I can reference by its old designation?
No. The NISPOM was codified as a federal regulation at 32 CFR Part 117, giving it the force and effect of law rather than the status of a departmental issuance. The prior DoD 5220.22-M manual designation should not be treated as the current authoritative source. Contractors should reference the 32 CFR Part 117 text directly and confirm any implementation detail against the current version, as regulatory language can be amended.
Does complying with the NISPOM mean my systems handling Controlled Unclassified Information (CUI) are also covered?
Not necessarily. The NISPOM at 32 CFR Part 117 governs the protection of classified information under the National Industrial Security Program, which is a distinct scope from the safeguarding of CUI. CUI obligations for defense contractors generally flow through separate authorities and control sets and should not be assumed to be satisfied by NISPOM compliance. Readers should map each information category to its governing requirement rather than conflating classified and CUI protection regimes, and verify current applicability against official sources.
Who is required to comply with the NISPOM as codified in 32 CFR Part 117?
In general, the NISPOM applies to contractors and other entities participating in the National Industrial Security Program that require access to, or that store or handle, classified information. Applicability is tied to the classified work and contractual relationships rather than being universal to all defense contractors. Because participation criteria and cognizant security agency arrangements can vary, confirm your specific obligations against the current regulatory text and applicable contract terms.
How does a facility begin operating under the NISPOM if it needs to access classified information?
Facilities generally must be sponsored and processed for an appropriate facility clearance before they may access or store classified information, following the procedures administered by the cognizant security agency. This entry does not cover the step-by-step clearance workflow, eligibility determinations, or timelines, which are subject to agency-specific processes and can change. Verify current procedures with the responsible oversight authority.
What role does the cognizant security agency play in NISPOM implementation?
Oversight of NISPOM implementation is generally exercised through a cognizant security agency, which administers program requirements, conducts security reviews, and provides guidance to cleared entities. The specific agency and the division of responsibilities can differ depending on the entity and the nature of the classified work. Because these assignments and oversight arrangements are subject to change, confirm the current responsible authority for your situation.
Does meeting NISPOM requirements mean my organization is secure against threats to classified information?
No. Compliance with the NISPOM establishes a baseline of required safeguards, but compliance is not equivalent to security. Meeting regulatory requirements does not by itself guarantee protection against insider threats, advanced adversaries, or evolving attack techniques. Organizations should treat NISPOM adherence as a floor and confirm that their actual security posture, monitoring, and personnel practices are effective in context.

Common misconceptions

The NISPOM and the CUI protection requirements under NIST SP 800-171 / DFARS 252.204-7012 cover the same information and can be treated interchangeably.
The NISPOM (32 CFR Part 117) is generally focused on the protection of classified information within industry under the NISP, which is a distinct scope from the protection of Controlled Unclassified Information addressed by NIST SP 800-171 and the DFARS safeguarding clause. Compliance with one does not automatically satisfy the other, and the applicable requirements should be confirmed against the governing authorities.
The NISPOM is only internal DoD policy guidance without binding legal effect.
Because the NISPOM is codified in the Code of Federal Regulations at 32 CFR Part 117, it generally carries the force and effect of a federal regulation for covered contractors, rather than functioning solely as non-binding guidance. Practitioners should treat it accordingly and verify the current regulatory text.
Holding a facility or personnel clearance is a permanent status once granted.
Access to classified information under the NISP is conditioned on continued eligibility and adherence to applicable safeguarding requirements, and is subject to ongoing oversight rather than being a one-time, permanent designation. Current conditions and processes should be confirmed against authoritative sources.

Best practices

Confirm which classes of information are actually in scope for your contract, distinguishing classified information governed by the NISPOM from CUI governed by separate authorities such as NIST SP 800-171 and DFARS 252.204-7012, and do not assume compliance with one satisfies the other.
Work from the current codified text at 32 CFR Part 117 rather than relying on prior DoD-issued manual versions or informal summaries, and verify that you are referencing the applicable revision.
Coordinate with your cognizant security oversight authority to confirm facility clearance, personnel clearance, and safeguarding obligations as they apply to your specific engagement.
Maintain documentation that demonstrates ongoing adherence to safeguarding and access requirements, recognizing that clearances and access are subject to continued eligibility and oversight rather than being permanent.
Establish internal processes to monitor for amendments to the regulation and to associated agency guidance, and update your program when the governing text changes.
Where implementation, contractual, or legal specifics are involved, validate them against current official sources and appropriate security or legal counsel rather than relying on general reference material alone.