Skip to content

What Is a DCSA Facility Inspection?

Cate_250x300
Not Sure Where Your FOCI Risk Stands?

A new FOCI rule could pull up to 40,000 defense contractors into DCSA review. Spend 20 minutes with Cate Pearson, ISI President, FSO & Clearance Services, to find out if you're exposed.

Executive Brief

If your organization holds a Facility Security Clearance (FCL), a Defense Counterintelligence and Security Agency (DCSA) facility inspection isn't a matter of if. It's a matter of when.

Understanding what happens during this review, who shows up, and how ratings work is the difference between a smooth assessment and a stressful one.

  • DCSA conducts recurring facility inspections of every cleared contractor under the National Industrial Security Program (NISP)
  • Inspections confirm your organization protects classified information the way your paperwork says it does
  • Ratings run on a five-level scale, and a minimum "satisfactory" rating is required to maintain your FCL
  • Inspection frequency is risk based, not fixed to a set calendar
  • Strong self-inspections are one of the best predictors of a strong DCSA rating

Dig deeper below to learn more.


What Is a DCSA Facility Inspection?

A DCSA facility inspection is a formal review of how well your organization complies with the National Industrial Security Program Operating Manual (NISPOM), codified at Title 32 of the Code of Federal Regulations (CFR) Part 117. DCSA now refers to this process as the Security Review and Rating Process (SRRP). Many contractors still call it a

This process sits at the center of how the Defense Counterintelligence and Security Agency (DCSA) protects classified information across the defense industrial base on behalf of the Department of Defense (DoD) (also known as the Department of War). If your organization holds an FCL, participation isn't optional.

For more background on how ratings evolved under the refined framework, see DCSA Vulnerability Assessments: How to Know If You're Ready.

  • It's not a paperwork check. Investigators look for alignment between written policy, system configurations, personnel training, and what's happening on the ground
  • It's tied directly to your FCL. A weak outcome can put your clearance, and your ability to work on classified contracts, at risk
  • It's recurring. Every NISP facility is subject to this review on a regular basis

Who Conducts the Inspection

Each cleared contractor is assigned an Industrial Security Representative (ISR) from DCSA. The ISR is responsible for confirming that your organization is complying with the policies and procedures outlined in the NISPOM.

Your ISR is also typically the same point of contact you work with throughout the life of your FCL, not just during a formal review.

  • Conducts the recurring security review and assigns your facility's rating
  • Serves as your primary point of contact for reporting requirements and questions
  • Reviews updates in the National Industrial Security System (NISS) between formal reviews

If you're still working through initial sponsorship, A Guide to Obtaining a Facility Security Clearance walks through how an ISR is involved from day one.

What DCSA Reviews During an Inspection

A DCSA facility inspection covers far more than a single filing cabinet or a single system. Investigators are looking at how security is built into daily operations.

  • FCL status, including Key Management Personnel (KMP) listings and any exclusion resolutions
  • Foreign Ownership, Control, or Influence (FOCI) documentation, where applicable
  • Personnel security processes, including clearance eligibility and briefings
  • Physical security controls for storing and handling classified material
  • The Insider Threat Program, evaluated as an operating program rather than a policy statement
  • Classified information systems and whether required security controls are consistently applied
  • Self-inspection records and how well they mirror DCSA's own review process

For a closer look at what's commonly missed, our 2026 DCSA Inspection Prep Checklist breaks down what Industrial Security Representatives review and where contractors tend to fall short.

How DCSA Ratings Work

DCSA rates facilities on a five-level scale. Where your facility lands affects your standing, and in some cases, your ability to keep your FCL at all.

  • Superior
  • Commendable
  • Satisfactory
  • Marginal
  • Unsatisfactory

DCSA also distinguishes between general conformity and not in conformity. A facility found not in conformity may be placed into a Compliance Improvement Process to address the gaps.

  • A minimum of "satisfactory" is required to maintain your FCL
  • A single unmitigated critical or serious vulnerability can disqualify a facility from a superior or commendable rating
  • Repeated or unaddressed findings can escalate into more serious consequences over time

How Often Inspections Happen

There isn't a universal calendar for DCSA facility inspections. Every NISP facility is subject to a recurring review, but the exact timing is risk informed.

  • Facilities with complex operations, larger CUI footprints, or prior findings can expect more frequent attention
  • Lower-risk organizations may see longer intervals between formal reviews
  • Regardless of interval, continuous readiness matters more than knowing an exact date

DCSA's refined rating framework under the Security Review and Rating Process took effect in October 2024, and it was designed to reduce subjectivity and increase consistency across ratings.

Why Self-Inspections Matter

DCSA expects contractors to run their own internal reviews using a process that mirrors its own. This isn't a formality. It's how most organizations catch and fix problems before an ISR ever walks in.

  • Self-inspections should be customized to your facility's actual operations, not copied from a generic template
  • Identified gaps should be mitigated and, where required, disclosed to DCSA promptly
  • Your Senior Management Official should certify the self-inspection and document it as complete

ISI Insight: If DCSA finds several issues during a formal review that should have been caught during your own self-inspection, that gap itself becomes a finding. A thorough self-inspection protects your rating twice over.

How to Prepare for a DCSA Facility Inspection

  • Keep records current across NISS, the Defense Information System for Security (DISS), and the National Background Investigation Services (NBIS)
  • Run self-inspections with the same rigor you'd expect from an ISR
  • Make sure personnel understand their role in protecting classified information, not just the FSO
  • Document your Insider Threat Program as an active process, including who reviews anomalous behavior and what triggers escalation
  • Loop in FSO support early if your team is stretched thin or your facility has grown since your last review

Our blog, How to Prepare for Your DCSA Assessment, goes deeper on building a repeatable readiness routine.

Why It Matters

A DCSA facility inspection isn't just an administrative event. It's how your organization proves, on a recurring basis, that it can be trusted with classified information.

  • Your FCL depends on it
  • Your standing with primes and government customers can depend on it
  • Your Facility Security Officer (FSO) plays a central role in making readiness a year-round habit, not a scramble before a review

Contractors that treat readiness as ongoing, rather than reactive, tend to walk into these reviews with far less friction.


FAQs

Is a DCSA facility inspection the same as a Vulnerability Assessment?

Yes, they refer to the same review. "Vulnerability Assessment" is the informal, longstanding industry term. DCSA's current formal name for the process is the Security Review and Rating Process (SRRP).

What rating do we need to keep our FCL?

A minimum of "satisfactory" is required to maintain your Facility Security Clearance. Ratings below that level can trigger a Compliance Improvement Process or further review.

How much advance notice do we get before an inspection?

Notice practices can vary, and frequency itself is risk based rather than fixed to a set calendar. The safest approach is to treat readiness as continuous rather than something to prepare for only once notified.

Who is responsible for preparing for a DCSA facility inspection?

The Facility Security Officer (FSO) typically leads readiness efforts, but a strong outcome depends on cooperation across personnel security, IT, and leadership, not the FSO alone.


Helpful ISI Links

Related Posts