Skip to content

How FOCI Boards Work: A Guide for Defense Contractors

ComputerShadow_L
ACCELERATE FACILITY CLEARANCE APPROVAL

Facility Control helps defense contractors prepare cleaner, DCSA-ready packages built for faster approvals.

Listen: How FOCI Boards Work: A Guide for Defense Contractors
20:47

This post is part of a series based on our recent webinar, When FOCI Stops the Deal: A Guide for FSOs and Executive Teams. Watch the full recording for more context.

Executive Brief

For defense contractors operating under a Foreign Ownership, Control, and Influence (FOCI) mitigation agreement, the board is not a typical corporate governance structure.

It is a regulated governance instrument with composition, duties, reporting, and recordkeeping requirements set by 32 CFR Part 117 (National Industrial Security Program Operating Manual (NISPOM) Rule) and overseen by the Defense Counterintelligence and Security Agency (DCSA).

  • FOCI-mitigated boards include a mix of inside directors representing the foreign shareholder and DCSA-vetted outside directors who are required by regulation to be “completely disinterested” U.S. citizens with no prior involvement with the entity, its affiliates, or the foreign owner.
  • Outside directors carry standard fiduciary duties and a regulatory duty to insulate the cleared entity from foreign influence. That is the friction point with the rest of the board.
  • Under 32 CFR 117.11(g), every Security Control Agreement (SCA), Special Security Agreement (SSA), Voting Trust, and Proxy Agreement requires a permanent Government Security Committee (GSC) of the board.
  • The Facility Security Officer (FSO) serves as the principal advisor to the GSC and operates under the GSC’s authority. The GSC chairman must concur on FSO appointment and replacement.
  • Education and documented training are how you manage built-in board tension and demonstrate compliance during DCSA reviews.
  • The proposed Defense Federal Acquisition Regulation Supplement (DFARS) FOCI expansion rule (published May 7, 2026) would push FOCI mitigation onto unclassified contracts over $5 million. Existing FOCI-mitigated contractors are ahead of the curve.

Dig deeper below to learn more.


What is a FOCI-Mitigated Board?

When DCSA determines a company is under FOCI and that risk cannot be addressed through a simple board resolution, it requires a more structured mitigation instrument. 32 CFR 117.11(d)(2) lays out the available methods. Three of them involve restructuring the board of directors:

  • Security Control Agreement (SCA): Used when a foreign interest does not effectively own or control the entity but is entitled to representation on the governing board. Under 32 CFR 117.11(d)(2)(ii), at least one cleared U.S. citizen must serve as an outside director. There are no access limitations under an SCA.
  • Special Security Agreement (SSA): Used when a foreign interest does effectively own or control the entity. Under 32 CFR 117.11(d)(2)(iii), the SSA “preserves the foreign owner’s right to be represented on the entity’s board or governing body with a direct voice in the entity’s business management, while denying the foreign owner majority representation and unauthorized access to classified information.” Access to proscribed information (Top Secret, Sensitive Compartmented Information (SCI), Restricted Data (RD), Communications Security (COMSEC), Special Access Program (SAP)) under an SSA generally requires a National Interest Determination (NID).
  • Voting Trust (VT) or Proxy Agreement (PA): The most restrictive instruments. The foreign owner’s voting rights are vested in cleared U.S. citizen trustees or proxy holders who become members of the board and exercise all prerogatives of ownership independent of the foreign owner.

For more background on the full range of FOCI mitigation instruments, see our companion blog: When FOCI Stops the Deal: A Guide for FSOs and Executive Teams.

Inside Directors vs. Outside Directors

The defining feature of a FOCI-mitigated board is the tension built into its design.

Inside directors represent the foreign shareholder. They sit on the board, participate in business management consistent with the mitigation agreement, and often view the FOCI board as secondary to the parent company structure. That perspective creates friction from the start.

Outside directors must meet specific regulatory requirements under 32 CFR 117.11(f). They must be:

  • Resident U.S. citizens
  • Eligible for a personnel security clearance at the level of the entity’s facility clearance
  • Able to “exercise governance and management prerogatives relating to their position in a way that ensures that the foreign owner can be effectively separated from the entity’s classified work”
  • “Completely disinterested individuals with no prior involvement with the entity, the entities with which it is affiliated, or the foreign owner”

That last point is broader than people sometimes assume. The disqualifying relationship is not just with the foreign shareholder. It includes the entity itself and any affiliated entities.

As Paul Michaels, CEO of Monoc Securities LLC and a longtime industrial security professional, described it:

“You have a group that is a mixture of representatives of the shareholder who want things to happen a certain way, and then another group that was selected by the shareholder but could not have a preexisting relationship with them, who has been tasked to look out for DCSA’s interests.”

The practical effect: outside directors carry the standard fiduciary duties of any board member plus a regulatory duty to insulate the cleared entity from foreign influence. When those duties pull in different directions, the regulatory duty governs. That is the structural source of the tension every FOCI board has to manage.

The Government Security Committee (GSC)

Under 32 CFR 117.11(g), any contractor operating under an SCA, SSA, VT, or PA must establish a permanent committee of its board of directors called the Government Security Committee. The GSC is where the day-to-day work of FOCI compliance lives.

Composition. Unless DCSA approves otherwise, the GSC consists of all cleared outside directors, proxy holders, or voting trustees, plus any cleared officer-directors. The FSO and Technology Control Officer (TCO) typically serve as advisors.

Meeting frequency. The Center for Development of Security Excellence (CDSE)’s Outside Director / Proxy Holder training materials confirm the standard cadence: the GSC and the broader board are expected to meet quarterly, at minimum. Many GSCs meet more often during periods of organizational change or active compliance activity.

Primary responsibilities under 32 CFR 117.11(g)(2). The GSC ensures the contractor:

  • Adheres to U.S. laws and regulations and maintains internal policies and procedures to safeguard classified information
  • Promptly investigates and reports violations to the appropriate authority

In practice, that translates into a defined set of operational responsibilities laid out across the NISPOM Rule and DCSA guidance. The GSC and outside directors are responsible for putting in place, and maintaining oversight of, the supplements required under 32 CFR 117.11(h):

  • Technology Control Plan (TCP): Required for all VT, PA, SSA, and SCA companies. Prescribes security measures to prevent unauthorized access by non-U.S. citizens to information they are not cleared for.
  • Electronic Communications Plan (ECP): Verifies technical and logical separation of networks, email, and electronic communications between the cleared entity, the foreign parent, and affiliates.
  • Affiliated Operations Plan (AOP): Required when there are services or arrangements between the cleared entity and the foreign interest or its affiliates. The GSC must approve any affiliated services in advance, and DCSA must approve the AOP.
  • Facilities Location Plan (FLP): Required when the cleared entity is potentially collocated with or in close proximity to the foreign parent or an affiliate. Collocation is generally prohibited.
  • Visitation Procedures: Govern visits between the cleared entity and the foreign parent, affiliates, and other foreign nationals, whether physical or virtual. The plan defines who must be pre-approved before a visit, what areas visitors may access, escort and documentation requirements, and any DCSA notification obligations for classified or export-controlled discussions. The purpose is to ensure that a site visit from a foreign parent executive, or a foreign engineer joining a program call, cannot become a vector for unauthorized access to classified information.
  • Compliance-Quality Management Plan (C-QMP): An emerging supplemental document DCSA is increasingly requiring, even though it is not explicitly enumerated in 32 CFR 117.11(h). The C-QMP ties together the mitigation agreement and the other supplements (TCP, ECP, AOP, VP) into a single program of standard practices and procedures covering safeguarding of classified information and Controlled Unclassified Information (CUI), classified program performance, insider threat deterrence, and alignment with the NISPOM Rule and DFARS cybersecurity requirements (e.g., 48 CFR § 252.204-7012). Typical C-QMPs include sections on policy, management, required documentation, compliance assurance procedures, and compliance assurance checks, all under GSC and Senior Management Official (SMO) oversight. If DCSA has not asked for one yet, expect it.
  • Annual certification. Under 32 CFR 117.11(i)(2), the GSC chairman must submit to DCSA, one year from the effective date of the agreement and annually thereafter, an implementation and compliance report. That report covers acts of compliance and noncompliance, changes to security procedures, Key Management Personnel (KMP) and board changes, and ownership or organizational changes. This is not optional, and it is not boilerplate. It is the formal record DCSA relies on between annual reviews. 

The FSO’s Role on a FOCI Board

The job description most FSOs read describes their role as “an advisor to the board.” That undersells what the regulation actually says.

Per 32 CFR 117.11(g)(3): “The contractor’s FSO will be the principal advisor to the GSC and attend GSC meetings. The chairman of the GSC must concur with the appointment and replacement of FSOs selected by management. The FSO functions will be carried out under the authority of the GSC.”

Three things matter here:

  • The FSO is the principal advisor to the GSC, not “an” advisor among several. This is a defined role with a defined seat at the table.
  • The GSC chairman must concur with FSO appointment and replacement. Management cannot unilaterally hire or remove the FSO at a FOCI-mitigated company. This is the regulatory mechanism that gives the FSO independence from management pressure.
  • The FSO functions are carried out under the authority of the GSC. Operationally, the FSO reports to the Senior Management Official (SMO) for day-to-day matters, but security functions sit under GSC authority. That dual structure is the source of the dual reporting lines FSOs navigate every day.

Key FSO responsibilities in a FOCI-mitigated environment:

  • Advise the GSC and the board on NISPOM Rule and mitigation agreement obligations
  • Support the GSC in oversight of the TCP, ECP, AOP, FLP, and visitation procedures
  • Help prepare the annual GSC implementation and compliance report
  • Maintain documentation of board and GSC actions and training in meeting minutes
  • Serve as the day-to-day liaison between the company and DCSA’s assigned Industrial Security Representative (IS Rep)

Managing Board Tension: Education as the Primary Tool

The structural tension between inside and outside directors is expected. The job of leadership is to manage it, not eliminate it.

Education is the most effective tool. Michaels recommends bringing in independent outside counsel, separate from your regular corporate legal team, to train the full board on the requirements of the mitigation agreement.

This approach accomplishes two things:

  • It gives both inside and outside directors a shared, authoritative foundation for understanding their roles and obligations under the mitigation agreement and 32 CFR 117.11
  • It creates a documented record in board minutes that everyone received the training, which matters significantly during DCSA security reviews and in any compliance inquiry

DCSA also provides direct training resources you should be using. CDSE offers a baseline Outside Director / Proxy Holder curriculum (IS175) that walks individuals through the regulatory framework, GSC responsibilities, and compliance expectations. DCSA convenes initial meetings with new outside directors and proxy holders and conducts annual compliance meetings. Outside directors are expected to attend.

Having board training on the record is not just administrative housekeeping. It is the difference between a manageable DCSA finding and a serious compliance issue if something goes wrong later.

The goal is not to eliminate disagreement between inside and outside directors. It is to ensure that everyone understands the boundaries when disagreements occur, and that the outside directors have the standing, the regulatory backing, and the documented training to enforce them.

If You Are Already FOCI Mitigated

Companies that have already been through FOCI mitigation and established a functioning board structure are in a stronger position than many realize, particularly as the proposed FOCI expansion rule moves forward.

On May 7, 2026, the Department of Defense (DoD) (also known as the Department of War) published a proposed DFARS rule that would extend FOCI disclosure and mitigation requirements to unclassified DoD contracts and subcontracts valued over $5 million. The comment period closed July 6, 2026, with a final rule anticipated later this year. DoD projects the rule will expand DCSA’s annual FOCI caseload from roughly 2,000 cases to approximately 41,000, covering up to $200 billion in acquisitions not currently subject to FOCI vetting.

Cate Pearson, President of Managed Security Services at ISI, put it like this: “This presents a really good opportunity for you to go to your board, to your inside directors who were reluctant to be FOCI mitigated, and explain to them how their peers, your competitors, are all going to have to go through fresh FOCI reviews. You have already been through it, you have already passed it, and you are going to be a little bit ahead of the game.”

For companies with existing FOCI boards, the priority now is keeping the structure current:

  • Ensure outside directors are active, informed, and properly documented in board minutes
  • Review the mitigation agreement annually and after any organizational change
  • Keep the GSC operating on its required cadence with documented minutes
  • File the annual GSC chairman’s implementation and compliance report on time
  • Update Standard Form 328 (SF-328) whenever a material change occurs
  • Refresh the TCP, ECP, AOP, FLP, and visitation procedures as the business evolves

What to Do Now

Whether you are building a FOCI board for the first time or running one that has been in place for years, the fundamentals are the same:

  • Confirm your outside directors meet the 32 CFR 117.11(f) qualifications and have completed CDSE OD/PH baseline training
  • Bring in independent outside counsel to conduct board training on the mitigation agreement, separate from your regular corporate legal team
  • Document all board and GSC training in meeting minutes
  • Ensure the FSO has direct access to both the SMO and the GSC, and that the GSC chairman is involved in any change to the FSO role
  • Confirm your TCP, ECP, AOP (if applicable), FLP (if applicable), visitation procedures, and Compliance-Quality Management Plan are current and operational
  • Review board composition whenever KMP change or the mitigation agreement is updated
  • Calendar the GSC chairman’s annual implementation and compliance report. It is a hard requirement, not a courtesy

For background on the FOCI mitigation process and what instruments are available, see: When FOCI Stops the Deal: A Guide for FSOs and Executive Teams. 


FAQs

What is the difference between an SCA and an SSA?

The two instruments are used in different ownership scenarios. Under 32 CFR 117.11(d)(2)(ii), a Security Control Agreement (SCA) is used when a foreign interest does not effectively own or control the entity but is entitled to representation on the governing board. An SCA requires at least one cleared U.S. citizen to serve as an outside director, and there are no access limitations under an SCA. Under 32 CFR 117.11(d)(2)(iii), a Special Security Agreement (SSA) is used when a foreign interest does effectively own or control the entity. The SSA preserves the foreign owner’s right to board representation while denying the foreign owner majority representation and unauthorized access to classified information. Access to proscribed information under an SSA generally requires a National Interest Determination (NID).

Can inside directors be involved in decisions about classified programs?

The FOCI mitigation structure is specifically designed to insulate cleared operations from foreign influence. Under an SSA, the foreign owner is denied majority board representation and “unauthorized access to classified information.” Decisions involving classified programs, personnel security, and FOCI compliance run through the cleared outside directors and the Government Security Committee. Inside directors representing the foreign shareholder do not participate in those decisions and do not have access to classified information unless they are independently cleared and an NID supports that access.

What happens if an outside director violates their obligations?

DCSA takes outside director conduct seriously. A violation can result in the director being removed and replaced, additional scrutiny of the company’s FOCI mitigation program, and in serious cases, suspension or revocation of the facility clearance under 32 CFR 117.11(a)(7). That is why training, documented compliance, and clear governance procedures are not optional.

How does the FSO navigate dual reporting lines?

Under 32 CFR 117.11(g)(3), the FSO is the principal advisor to the GSC, FSO functions are carried out under the GSC’s authority, and the GSC chairman must concur with FSO appointment and replacement. Operationally, the FSO still reports to the SMO for day-to-day matters. Most experienced FSOs handle this by establishing written protocols at the outset: which decisions go through management, which go through the GSC, and which require GSC chairman concurrence. Putting it in writing prevents ambiguity when an issue is moving fast.

How often should the FOCI board meet?

CDSE’s Outside Director / Proxy Holder guidance directs quarterly board and GSC meetings at minimum. More frequent meetings are appropriate during periods of significant organizational change, mitigation agreement updates, or active compliance activity. DCSA also conducts annual compliance meetings that outside directors are expected to attend.

What is the proposed FOCI expansion rule and does it affect us?

On May 7, 2026, DoD published a proposed DFARS rule that would extend FOCI disclosure and mitigation requirements to unclassified DoD contracts and subcontracts valued over $5 million. The comment period closed July 6, 2026, and a final rule is anticipated later in 2026. If you already operate under a FOCI mitigation agreement for classified work, you are already inside the framework the rule is designed to expand. The practical implication is competitive: many contractors who have never been through FOCI review are about to be, and they will be working against your existing track record of compliance.


Helpful ISI Links

Related Posts