This post is part of a series based on our recent webinar, When FOCI Stops the Deal: A Guide for FSOs and Executive Teams. For background on board structure under Security Control Agreements (SCAs), Special Security Agreements (SSAs), Voting Trusts (VTs), and Proxy Agreements (PAs), see our companion post, How FOCI Boards Work: A Guide for Defense Contractors.
Most Foreign Ownership, Control, or Influence (FOCI) conversations focus on the heavyweight mitigation instruments: Security Control Agreements (SCAs), Special Security Agreements (SSAs), Voting Trusts (VTs), and Proxy Agreements (PAs). They get attention because they require restructured boards, Defense Counterintelligence and Security Agency (DCSA) vetted outside directors, and standing committees.
But the most common FOCI action plan in DCSA's portfolio isn't any of those. It's the Special Board Resolution (SBR). And the SBR is where DCSA's practice has shifted most significantly in recent years: DCSA is increasingly requiring the Quality Management Plan (QMP) as a catch-all supplement.
Key things to know:
Dig deeper below to learn more.
The National Industrial Security Program Operating Manual (NISPOM) Rule does not use the term “Special Board Resolution.” The regulation enumerates a basic board resolution at 32 CFR § 117.11(d)(2)(i), used when a foreign interest does not possess sufficient voting interests to elect, or is not entitled to, representation on the entity's governing board. In its plain form, that basic resolution is short: identify the foreign shareholder, describe the type and number of shares, acknowledge industrial security obligations, and certify that the mitigation measures effectively preclude the foreign owner from unauthorized access to classified information.
The SBR is the operational name DCSA uses for a substantially more demanding instrument that sits in the same regulatory family. The current SBR template invokes 32 CFR § 117.11(d)(1), the section addressing FOCI factors not related to ownership, which authorizes DCSA to impose measures such as “assignment of specific oversight duties and responsibilities to board members” and “formulation of special executive-level security committees to consider and oversee issues that affect the performance of classified contracts.”
In practice, the SBR is what DCSA uses when:
Industry data places SBRs as the single most common FOCI action plan in use across the cleared contractor base, per CDSE's FOCI Toolkit. If you have FOCI but you don't have a foreign owner sitting on your board, an SBR is the most likely outcome.
The SBR is not a one-page formality. The current DCSA template imposes a structured set of obligations that touches governance, disclosure, classified contract performance, and ongoing reporting.
Disclosure schedules. The SBR requires four schedules attached to the resolution:
Covered Persons exclusion. The SBR designates every individual and entity listed in Schedules 1, 2, and 4, along with their employees, officers, directors, representatives, and agents, as a “Covered Person.” The SBR bars Covered Persons from unauthorized access to classified and export-controlled information, and from occupying any position that could adversely affect the contractor's policies or practices on classified contracts.
Controlled entity binding. The resolution applies to all present and future controlled entities. Each controlled entity must execute a document agreeing to be bound by the SBR, and the contractor must send a copy to DCSA.
SMO and FSO obligations. The Senior Management Official (SMO), in consultation with the Facility Security Officer (FSO), is responsible for implementing the SBR, overseeing operations to confirm the protective measures are effective, and briefing employees. A DCSA representative briefs the SMO on responsibilities under the DD Form 441, the resolution itself, U.S. Government contract security provisions, export control laws, and the NISPOM Rule upon the SMO taking office.
Two mandatory supplement plans. This is where the SBR diverges most sharply from what people assume a “board resolution” is. The template explicitly requires the contractor to develop and implement:
For classified contracts in which the contractor uses foreign supplier technology, the SBR requires written notification to the applicable GCA, including the foreign supplier's name, the technology product or service, and the contractor's related quality control measures, unless the GCA opts out in writing.
Annual distribution and certification. The contractor must provide a copy of the SBR to all board members and principal officers at least annually, and bring the substance to the attention of appropriate employees through a written security procedure or equivalent. The contractor must submit an annual certificate to DCSA confirming the resolution and all schedules remain true and correct, with updated schedules showing any changes from the prior year.
FCL enforcement acknowledgement. The board explicitly acknowledges that the contractor's facility clearance (FCL) is subject to invalidation or revocation by DCSA if the contractor does not meet and maintain the SBR's provisions.
If you have been thinking of an SBR as a “lightweight” FOCI instrument, that picture is out of date.
For SCA, SSA, VT, and PA companies, 32 CFR § 117.11(h) lists a specific set of supplemental documents the Government Security Committee (GSC) and outside directors are responsible for maintaining: TCP, Electronic Communications Plan (ECP), Affiliated Operations Plan (AOP), Facilities Location Plan (FLP), and visitation procedures. These supplements exist because DCSA imposes those instruments in higher-risk ownership scenarios where the foreign owner has board representation or control, and DCSA needs detailed mechanical safeguards to enforce insulation. See our companion post, How FOCI Boards Work, for a full walkthrough of GSC composition and duties.
SBR-tier companies don't have a foreign owner on the board. They generally don't have collocation issues with a foreign parent. They typically don't have a portfolio of affiliated services routed through a foreign affiliate. The full supplement stack would be overkill.
What DCSA does need from an SBR-tier company is a structured, documented program that:
The QMP, which DCSA and industry sometimes call a Compliance-Quality Management Plan (C-QMP), is the document that does all of that. In ISI's experience, DCSA is increasingly treating it as the integrating document for SBR-tier compliance, pulling the substance that would otherwise live in a TCP, ECP, AOP, and visitation plan into a single, internally consistent program.
Formal rulemaking moves on a multi-year cycle. National security risk and supply chain risk do not. DCSA built the NISPOM Rule with that reality in mind: 32 CFR § 117.11(a)(7) gives DCSA the authority to impose “any security method, safeguard, or restriction” necessary to protect classified information and the performance of classified contracts. That is the authority DCSA is using to incorporate the QMP into SBR-tier compliance ahead of any explicit listing in 117.11(h).
For contractors, that has two practical implications:
If you are operating under an SBR, here are the practical implications:
A few patterns we see in current DCSA practice are worth flagging if you are managing an SBR-mitigated company:
These are operational refinements DCSA is making within its authority under the NISPOM Rule, ahead of any formal update to the rule text. Staying current with DCSA practice, not just the regulation, is exactly where having an experienced advisor matters.
If you operate under an SBR:
If you do not yet have a FOCI mitigation instrument and you suspect one is coming:
For background on FOCI board structure under SCAs, SSAs, VTs, and PAs, see: How FOCI Boards Work: A Guide for Defense Contractors
No. The basic board resolution under 117.11(d)(2)(i) is a short instrument used when foreign ownership exists but the foreign interest is not entitled to board representation. The SBR is a more rigorous instrument DCSA uses when the FOCI factors require more than the basic resolution but do not rise to the level of an SCA, SSA, VT, or PA. The SBR template draws its regulatory authority from 32 CFR § 117.11(d)(1), which lists measures DCSA can impose when FOCI factors not related to ownership are present, including assignment of oversight duties to board members and formation of special executive-level security committees.
Not in the same way an SCA, SSA, VT, or PA does. SBRs do not require DCSA-vetted outside directors or the permanent GSC structure required under 32 CFR § 117.11(g). The compliance machinery sits with the SMO and the FSO, with reporting to the board and annual certification to DCSA. That is a significant difference in operational burden compared with the heavier mitigation instruments. For more information on GSC structure, see How FOCI Boards Work.
National security threats and the supply chain environment evolve faster than the federal rulemaking process. Formal updates to 32 CFR Part 117 take years, but DCSA must protect classified information and classified contract performance in real time. The NISPOM Rule anticipates this: 32 CFR § 117.11(a)(7) gives DCSA the authority to impose “any security method, safeguard, or restriction” necessary to protect classified information and ensure classified contracts aren't adversely affected. The current SBR template itself requires the contractor to implement a QMP, and as DCSA has matured its program for SBR-mitigated companies, the QMP has become the integrating compliance document for that tier, covering substance the contractor would otherwise spread across multiple separate supplements at higher mitigation levels.
ISI Insight: For contractors, the practical takeaway is straightforward: build a strong QMP, and you are aligned with where DCSA is heading.
A typical C-QMP includes an introduction, policy section, management structure, required documentation, compliance assurance procedures, and compliance assurance checks. It identifies foreign software, products, and suppliers in the contractor's supply chain, describes the quality assurance and quality control measures used to mitigate FOCI risk, and aligns with the NISPOM Rule and the applicable DFARS cybersecurity requirements (notably 48 CFR § 252.204-7012). The GSC reviews and approves it where one exists, or the SMO and FSO where one does not, and serves as a primary reference during DCSA security reviews.
Under the SBR, the contractor submits an annual certificate to DCSA confirming the resolution and all schedules remain true and correct, with updated schedules showing changes from the prior year. DCSA reviews the certification for material changes and may follow up with questions, request additional documentation, or in some cases initiate a discussion about whether a more restrictive mitigation instrument is warranted. It is a real review event.
The SBR explicitly applies to all present and future controlled entities, and each controlled entity must execute a document agreeing to be bound. The contractor sends a copy of that executed document to DCSA. If a controlled entity is acquired and the contractor misses that step, they are out of compliance with the SBR and the facility clearance is subject to invalidation or revocation under the terms of the resolution. Build this into your mergers and acquisitions (M&A) integration checklist.