Special Board Resolutions and QMPs: A Guide for FSOs and Executives
This post is part of a series based on our recent webinar, When FOCI Stops the Deal: A Guide for FSOs and Executive Teams. For background on board structure under Security Control Agreements (SCAs), Special Security Agreements (SSAs), Voting Trusts (VTs), and Proxy Agreements (PAs), see our companion post, How FOCI Boards Work: A Guide for Defense Contractors.
Executive Brief
Most Foreign Ownership, Control, or Influence (FOCI) conversations focus on the heavyweight mitigation instruments: Security Control Agreements (SCAs), Special Security Agreements (SSAs), Voting Trusts (VTs), and Proxy Agreements (PAs). They get attention because they require restructured boards, Defense Counterintelligence and Security Agency (DCSA) vetted outside directors, and standing committees.
But the most common FOCI action plan in DCSA's portfolio isn't any of those. It's the Special Board Resolution (SBR). And the SBR is where DCSA's practice has shifted most significantly in recent years: DCSA is increasingly requiring the Quality Management Plan (QMP) as a catch-all supplement.
Key things to know:
- An SBR is a more rigorous version of the basic board resolution under 32 Code of Federal Regulations (CFR) § 117.11(d)(2)(i), used when there is foreign interest in the company but not at a level that requires an SCA, SSA, VT, or PA
- Unlike the standard board resolution, an SBR imposes detailed disclosure schedules, exclusion requirements, controlled entity binding, ongoing Senior Management Official (SMO) and Facility Security Officer (FSO) obligations, and annual certification to DCSA
- The current SBR template requires the contractor to implement a QMP and a Technology Control Plan (TCP) as integrated obligations of the resolution itself
- In our experience, DCSA is using the QMP as a catch-all compliance document for SBR-tier companies, in lieu of requiring the full supplement set that SCA, SSA, VT, and PA companies must produce
- If you operate under an SBR and DCSA has not yet asked you for a QMP, expect it. See DCSA's FOCI mitigation agreements guidance for the full range of instruments
Dig deeper below to learn more.
What an SBR Actually Is
The National Industrial Security Program Operating Manual (NISPOM) Rule does not use the term “Special Board Resolution.” The regulation enumerates a basic board resolution at 32 CFR § 117.11(d)(2)(i), used when a foreign interest does not possess sufficient voting interests to elect, or is not entitled to, representation on the entity's governing board. In its plain form, that basic resolution is short: identify the foreign shareholder, describe the type and number of shares, acknowledge industrial security obligations, and certify that the mitigation measures effectively preclude the foreign owner from unauthorized access to classified information.
The SBR is the operational name DCSA uses for a substantially more demanding instrument that sits in the same regulatory family. The current SBR template invokes 32 CFR § 117.11(d)(1), the section addressing FOCI factors not related to ownership, which authorizes DCSA to impose measures such as “assignment of specific oversight duties and responsibilities to board members” and “formulation of special executive-level security committees to consider and oversee issues that affect the performance of classified contracts.”
In practice, the SBR is what DCSA uses when:
- There are some foreign interests present: passive equity, foreign debt, foreign suppliers, or non-controlling investor relationships
- That interest does not rise to the level that requires an SCA, SSA, VT, or PA
- A basic board resolution under 117.11(d)(2)(i) is insufficient given the nature and extent of the FOCI factors, as defined in the CDSE FOCI glossary
Industry data places SBRs as the single most common FOCI action plan in use across the cleared contractor base, per CDSE's FOCI Toolkit. If you have FOCI but you don't have a foreign owner sitting on your board, an SBR is the most likely outcome.
What the SBR Template Actually Requires
The SBR is not a one-page formality. The current DCSA template imposes a structured set of obligations that touches governance, disclosure, classified contract performance, and ongoing reporting.
Disclosure schedules. The SBR requires four schedules attached to the resolution:
- Schedule 1: All foreign shareholders, members, or investors, with country of incorporation, type of ownership, and direct and indirect ownership percentages
- Schedule 2: All foreign creditors, with type of indebtedness, agents and trustees, maturity dates, outstanding principal, and ratio to the contractor's equity
- Schedule 3: All controlled entities (subsidiaries and other companies in which the contractor holds a controlling interest), with Commercial and Government Entity (CAGE) codes where applicable
- Schedule 4: All foreign suppliers used or to be used on classified contracts, with country of incorporation, the contractor's product line or project, and the foreign percentage of the final product delivered to the Government Contracting Activity (GCA)
Covered Persons exclusion. The SBR designates every individual and entity listed in Schedules 1, 2, and 4, along with their employees, officers, directors, representatives, and agents, as a “Covered Person.” The SBR bars Covered Persons from unauthorized access to classified and export-controlled information, and from occupying any position that could adversely affect the contractor's policies or practices on classified contracts.
Controlled entity binding. The resolution applies to all present and future controlled entities. Each controlled entity must execute a document agreeing to be bound by the SBR, and the contractor must send a copy to DCSA.
SMO and FSO obligations. The Senior Management Official (SMO), in consultation with the Facility Security Officer (FSO), is responsible for implementing the SBR, overseeing operations to confirm the protective measures are effective, and briefing employees. A DCSA representative briefs the SMO on responsibilities under the DD Form 441, the resolution itself, U.S. Government contract security provisions, export control laws, and the NISPOM Rule upon the SMO taking office.
Two mandatory supplement plans. This is where the SBR diverges most sharply from what people assume a “board resolution” is. The template explicitly requires the contractor to develop and implement:
- A Quality Management Plan (QMP) that demonstrates compliance with classified government contracts and with generally accepted software, manufacturing, and service standards, and describes the quality assurance and quality control measures the contractor takes to ensure that foreign software or foreign products are not subjecting classified contract performance to unmitigated risks
- A Technology Control Plan (TCP) containing measures designed to ensure compliance with U.S. export control laws and regulations
For classified contracts in which the contractor uses foreign supplier technology, the SBR requires written notification to the applicable GCA, including the foreign supplier's name, the technology product or service, and the contractor's related quality control measures, unless the GCA opts out in writing.
Annual distribution and certification. The contractor must provide a copy of the SBR to all board members and principal officers at least annually, and bring the substance to the attention of appropriate employees through a written security procedure or equivalent. The contractor must submit an annual certificate to DCSA confirming the resolution and all schedules remain true and correct, with updated schedules showing any changes from the prior year.
FCL enforcement acknowledgement. The board explicitly acknowledges that the contractor's facility clearance (FCL) is subject to invalidation or revocation by DCSA if the contractor does not meet and maintain the SBR's provisions.
If you have been thinking of an SBR as a “lightweight” FOCI instrument, that picture is out of date.
Why DCSA Is Leaning on the QMP
For SCA, SSA, VT, and PA companies, 32 CFR § 117.11(h) lists a specific set of supplemental documents the Government Security Committee (GSC) and outside directors are responsible for maintaining: TCP, Electronic Communications Plan (ECP), Affiliated Operations Plan (AOP), Facilities Location Plan (FLP), and visitation procedures. These supplements exist because DCSA imposes those instruments in higher-risk ownership scenarios where the foreign owner has board representation or control, and DCSA needs detailed mechanical safeguards to enforce insulation. See our companion post, How FOCI Boards Work, for a full walkthrough of GSC composition and duties.
SBR-tier companies don't have a foreign owner on the board. They generally don't have collocation issues with a foreign parent. They typically don't have a portfolio of affiliated services routed through a foreign affiliate. The full supplement stack would be overkill.
What DCSA does need from an SBR-tier company is a structured, documented program that:
- Maps the contractor's classified work to its broader quality management practices
- Identifies the foreign software, foreign products, and foreign suppliers in the contractor's supply chain
- Specifies the quality assurance and quality control measures used to mitigate FOCI risk on classified contracts
- Aligns with the NISPOM Rule (32 CFR Part 117) and Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity requirements (notably 48 CFR § 252.204-7012, “Safeguarding Covered Defense Information and Cyber Incident Reporting”)
- Defines compliance assurance procedures and compliance assurance checks under GSC and SMO oversight
- Ties together insider threat deterrence and Controlled Unclassified Information (CUI) safeguarding
The QMP, which DCSA and industry sometimes call a Compliance-Quality Management Plan (C-QMP), is the document that does all of that. In ISI's experience, DCSA is increasingly treating it as the integrating document for SBR-tier compliance, pulling the substance that would otherwise live in a TCP, ECP, AOP, and visitation plan into a single, internally consistent program.
Formal rulemaking moves on a multi-year cycle. National security risk and supply chain risk do not. DCSA built the NISPOM Rule with that reality in mind: 32 CFR § 117.11(a)(7) gives DCSA the authority to impose “any security method, safeguard, or restriction” necessary to protect classified information and the performance of classified contracts. That is the authority DCSA is using to incorporate the QMP into SBR-tier compliance ahead of any explicit listing in 117.11(h).
For contractors, that has two practical implications:
- Expectations will continue to evolve as DCSA refines its program. Staying close to current DCSA practice matters as much as knowing the regulation
- A well-built QMP can carry more weight in a DCSA security review than a checklist of separate supplements that don't reference each other, because it shows how the pieces work together
What This Means for FSOs and Executives at SBR-Tier Companies
If you are operating under an SBR, here are the practical implications:
- DCSA will ask you for a QMP if it hasn’t already. Build it now, on your timeline, instead of scrambling under DCSA pressure
- The QMP needs to be more than a binder. A good C-QMP includes, at minimum: an introduction, policy section, management structure, required documentation, compliance assurance procedures, and compliance assurance checks. It cross-references the mitigation arrangement, identifies foreign suppliers and products, and explains how quality controls protect classified performance. The GSC and the SMO should review and approve it
- Your SBR schedules need to be live documents. Schedules 1 through 4 are not one-time disclosures. The annual certification requires updated schedules reflecting changes. If a new foreign supplier enters your classified supply chain, Schedule 4 needs to reflect it before the next certification, and that change may trigger the GCA notification requirement immediately
- Annual certification is a regulatory deadline, not a courtesy. Calendar it. The SBR explicitly conditions your facility clearance on compliance
- Controlled entities are on the hook too. The SBR binds any subsidiary or controlled company you acquire and must execute a document agreeing to be bound. That document goes to DCSA. If your corporate development team is moving on an acquisition, FOCI is part of the diligence, not an afterthought at close
- The SMO has personal regulatory obligations. DCSA must brief a new SMO on responsibilities under the SBR. If you have an SMO transition coming, build the DCSA briefing into the transition plan
Where ISI Sees the Practice Diverging from the Textbook
A few patterns we see in current DCSA practice are worth flagging if you are managing an SBR-mitigated company:
- DCSA is increasingly using the QMP as the integrating document for SBR-tier compliance, in lieu of asking for a separate TCP and a separate set of additional supplements
- DCSA is using the foreign supplier disclosures in SBR Schedule 4 as a basis for follow-up review of supply chain risk under classified contracts
- DCSA is using the annual certification as a real review event, not a rubber stamp. DCSA is also scrutinizing updated schedules for material changes that may warrant a remediation plan or, in some cases, escalation to a more restrictive mitigation instrument
- DCSA is asking companies that built minimalist SBR programs in earlier years to bring their compliance posture up to current DCSA expectations, which often means building the QMP for the first time
These are operational refinements DCSA is making within its authority under the NISPOM Rule, ahead of any formal update to the rule text. Staying current with DCSA practice, not just the regulation, is exactly where having an experienced advisor matters.
What to Do Now
If you operate under an SBR:
- Pull your current SBR and confirm Schedules 1 through 4 are accurate as of today
- If you do not have a current QMP, build one, or have one built, before DCSA asks
- Confirm your TCP is current and consistent with the QMP
- Schedule the annual certification and confirm the SMO and FSO are aligned on the review process
- Confirm any controlled entities have executed binding documents and that copies are on file with DCSA
- Review your foreign supplier inventory and confirm GCA notifications are current for classified contracts using foreign supplier technology
If you do not yet have a FOCI mitigation instrument and you suspect one is coming:
- Submit an accurate SF-328 with the relevant foreign interest disclosures. Facility Control can help you prepare a clean, DCSA-ready package
- Engage with DCSA early on the proposed mitigation method. You negotiate SBRs with DCSA; DCSA doesn't impose them unilaterally
- Plan for the QMP requirement up front. It is faster and cleaner to build it in parallel with the SBR than to bolt it on after the fact
For background on FOCI board structure under SCAs, SSAs, VTs, and PAs, see: How FOCI Boards Work: A Guide for Defense Contractors
FAQs
Is the SBR the same as the basic board resolution in 32 CFR § 117.11(d)(2)(i)?
No. The basic board resolution under 117.11(d)(2)(i) is a short instrument used when foreign ownership exists but the foreign interest is not entitled to board representation. The SBR is a more rigorous instrument DCSA uses when the FOCI factors require more than the basic resolution but do not rise to the level of an SCA, SSA, VT, or PA. The SBR template draws its regulatory authority from 32 CFR § 117.11(d)(1), which lists measures DCSA can impose when FOCI factors not related to ownership are present, including assignment of oversight duties to board members and formation of special executive-level security committees.
Does an SBR require outside directors or a Government Security Committee?
Not in the same way an SCA, SSA, VT, or PA does. SBRs do not require DCSA-vetted outside directors or the permanent GSC structure required under 32 CFR § 117.11(g). The compliance machinery sits with the SMO and the FSO, with reporting to the board and annual certification to DCSA. That is a significant difference in operational burden compared with the heavier mitigation instruments. For more information on GSC structure, see How FOCI Boards Work.
How is the QMP becoming a standard requirement for SBR-mitigated companies?
National security threats and the supply chain environment evolve faster than the federal rulemaking process. Formal updates to 32 CFR Part 117 take years, but DCSA must protect classified information and classified contract performance in real time. The NISPOM Rule anticipates this: 32 CFR § 117.11(a)(7) gives DCSA the authority to impose “any security method, safeguard, or restriction” necessary to protect classified information and ensure classified contracts aren't adversely affected. The current SBR template itself requires the contractor to implement a QMP, and as DCSA has matured its program for SBR-mitigated companies, the QMP has become the integrating compliance document for that tier, covering substance the contractor would otherwise spread across multiple separate supplements at higher mitigation levels.
ISI Insight: For contractors, the practical takeaway is straightforward: build a strong QMP, and you are aligned with where DCSA is heading.
What goes into a Quality Management Plan?
A typical C-QMP includes an introduction, policy section, management structure, required documentation, compliance assurance procedures, and compliance assurance checks. It identifies foreign software, products, and suppliers in the contractor's supply chain, describes the quality assurance and quality control measures used to mitigate FOCI risk, and aligns with the NISPOM Rule and the applicable DFARS cybersecurity requirements (notably 48 CFR § 252.204-7012). The GSC reviews and approves it where one exists, or the SMO and FSO where one does not, and serves as a primary reference during DCSA security reviews.
What happens at the annual certification?
Under the SBR, the contractor submits an annual certificate to DCSA confirming the resolution and all schedules remain true and correct, with updated schedules showing changes from the prior year. DCSA reviews the certification for material changes and may follow up with questions, request additional documentation, or in some cases initiate a discussion about whether a more restrictive mitigation instrument is warranted. It is a real review event.
What happens if a controlled entity is not properly bound by the SBR?
The SBR explicitly applies to all present and future controlled entities, and each controlled entity must execute a document agreeing to be bound. The contractor sends a copy of that executed document to DCSA. If a controlled entity is acquired and the contractor misses that step, they are out of compliance with the SBR and the facility clearance is subject to invalidation or revocation under the terms of the resolution. Build this into your mergers and acquisitions (M&A) integration checklist.
Helpful ISI Links
- When FOCI Stops the Deal: A Guide for FSOs and Executive Teams (Webinar)
- What Every FSO and Executive Needs to Know About FOCI Compliance
- How FOCI Boards Work: A Guide for Defense Contractors
- Who Is Responsible for Protecting CUI?
- Facility Control: Prepare Your SF-328 and FCL Package
- Facility Security Officer & Clearance Services


