FSO Training Priorities for DCSA Compliance
Executive Brief
Most Facility Security Officers (FSOs) don't get one training moment and then move on. Training is ongoing, and it is expected to keep pace with changes to the National Industrial Security Program Operating Manual (NISPOM), insider threat requirements, and Defense Counterintelligence and Security Agency (DCSA) review priorities.
When training lapses, it tends to surface fast, often during a Security Review and Rating Process (SRRP) rating, and sometimes before a single classified document is ever involved.
In this blog, you’ll learn:
- What DCSA and the Center for Development of Security Excellence (CDSE) require for FSO training under 32 CFR Part 117
- Which courses make up the core FSO training curriculum, including required insider threat training
- How annual refresher training obligations work under the NISPOM Rule
- Practical habits that keep training current between formal reviews
Dig deeper below.
Why FSO Training Isn't a One and Done Requirement
FSO training is not a box you check once at appointment and forget.
The regulatory reality:
- 32 CFR Part 117 (the NISPOM Rule) requires cleared contractors to provide security training "commensurate with their involvement with classified information"
- Training requirements are set by the Cognizant Security Authority (CSA) and can change as your facility's clearance level, contracts, or insider threat program grow
- DCSA reviews evaluate whether training happened, not just whether a policy says it should
New FSOs are especially exposed here. If you were recently appointed, DCSA expects your training curriculum to be underway, and a possessing facility has a hard deadline for one specific course.
What DCSA and CDSE Require
The Department of War relies on DCSA to oversee the National Industrial Security Program (NISP), and DCSA relies on CDSE to deliver the required training.
The FSO Program Management Course
- If your facility is approved to store classified information on site (a "possessing" facility), 32 CFR 117.12(d) requires the FSO to complete an FSO program management course within six months of that CSA approval
- Non-possessing facilities have their own baseline curriculum, and it is lighter, but it is not optional
- CDSE delivers this training through the Security Training, Education, and Professionalization Portal (STEPP), and completion certificates should be saved, not just completed
What DCSA Expects You to Keep
- STEPP completion certificates for every required course
- A record of who on your team has completed insider threat and counterintelligence training
- Evidence that training maps to your facility's actual clearance level and Controlled Unclassified Information (CUI) footprint, not a generic template
For more on how the FSO role has expanded alongside cybersecurity and Cybersecurity Maturity Model Certification (CMMC) obligations, see How to Become a Facility Security Officer (FSO).
The Core FSO Training Curriculum
CDSE organizes FSO training around a handful of recurring subject areas. Most are self-paced through STEPP and run one to three hours per course.
- Facility and personnel clearance basics. How Facility Clearances (FCLs) and personnel clearances are granted, maintained, and what actions can affect their status
- Self-inspection. How to prepare for, conduct, and follow up on an internal review of your own security program against the NISPOM
- Reporting requirements. What must be reported to DCSA, on what timeline, and how to submit it correctly
- Counterintelligence (CI) awareness. Recognizing collection methods used by foreign intelligence entities and understanding your reporting obligations
- Insider threat. Covered in detail below, since it carries its own regulatory checklist
Contractors with international program involvement or a formal insider threat program will layer in additional, more specialized courses on top of this baseline.
Insider Threat Training Has Its Own Rules
Insider threat training is not just a recommended topic inside your broader curriculum. It is a distinct, named requirement. DCSA's insider threat training slick sheet lists all four courses in one place.
Under 32 CFR 117.12(g)(1), contractor insider threat program personnel must complete training on four specific areas, and CDSE has designated a course for each:
- Counterintelligence and security fundamentals, covered through the Protecting Assets in the NISP course
- Procedures for conducting insider threat response actions, covered through the Insider Threat Mitigation Responses course
- Applicable laws and regulations on gathering, retaining, and safeguarding records and data, covered through the Insider Threat Records Checks course
- Legal, civil liberties, and privacy requirements applicable to insider threat programs, covered through the Insider Threat Privacy and Civil Liberties course
Contractors can build their own training program around these four topics, or rely on the CDSE-designated courses to satisfy the minimum standard. Either way, the training must reach every person assigned insider threat program responsibilities, not just the FSO.
Annual Refresher Training Keeps You Current
Initial training gets an FSO appointed. Refresher training is what keeps a program compliant year over year.
- 32 CFR 117.12(k) requires all cleared employees, not just the FSO, to complete annual refresher security training
- Refresher training should reflect current threats, policy changes, and lessons learned from your own self-inspections, not a recycled slide deck
- Operations Security (OPSEC) awareness is commonly folded into refresher cycles alongside counterintelligence and insider threat topics
- DCSA reviewers will ask when the last refresher cycle happened and who completed it, so track dates at the individual level
A missed refresher cycle is one of the more avoidable findings in a security review, since the training itself is short and the tracking burden is the real work.
Building a Training Habit, Not Just a Checklist
The FSOs who stay ahead of DCSA reviews treat training as a maintained system, not an annual scramble.
- Set calendar reminders tied to appointment dates, not just calendar year end, so six-month and annual deadlines don't collide
- Store STEPP certificates in one place that survives staff turnover
- Fold training gaps discovered during self-inspection directly into your next training cycle
- Review CDSE's course catalog periodically since new and updated courses are added regularly
ISI Insight: A training tracker that lists course name, completion date, and renewal date for every cleared employee is a small lift that pays off during every review cycle.
Where DCSA Reviews Catch Training Gaps
A few patterns show up repeatedly during security reviews.
- Missing certificates. Training happened, but no one saved proof of it
- Stale content. The same refresher material has been reused for years without updates
- Incomplete rosters. New hires with clearance access who haven't completed initial briefings
- Insider threat gaps. Program personnel who were never trained on all four required topics
- FSO-only training. A program built around the FSO's knowledge with no backup or succession plan
How to Build Your FSO Training Plan
Start with these steps if you are building or refreshing your FSO training plan:
- Confirm whether your facility is possessing or non-possessing, since that determines your baseline curriculum
- Map your insider threat program roster against the four required training topics
- Set your six-month and annual training clocks against actual appointment and approval dates
- Centralize STEPP certificates and refresher records in one accessible location
- Build refresher content around real findings from your own self-inspections
- Revisit CDSE's course catalog at least twice a year for new or updated offerings
Training that maps cleanly to these steps gives DCSA reviewers a clear, defensible picture instead of a scramble to reconstruct history.
FAQs
How long does a newly appointed FSO have to complete training?
It depends on your facility type. Possessing facilities have a defined six-month window from CSA approval to complete the FSO program management course. Non-possessing facilities follow a lighter baseline curriculum, but DCSA still expects it to be underway soon after appointment.
Does insider threat training apply to the whole company or just the FSO?
It applies to anyone assigned insider threat program responsibilities, which is often broader than just the FSO. If your program has multiple personnel, each of them needs training on all four required topics.
How often does refresher training need to happen?
Annually, at minimum, for all cleared employees under the NISPOM Rule. Many contractors also refresh insider threat and counterintelligence content on the same cycle to keep tracking simple.

.png?width=715&height=418&name=COMSEC_LinkedInEvent%20(1).png)
