If your organization holds a Facility Security Clearance (FCL), a Defense Counterintelligence and Security Agency (DCSA) facility inspection isn't a matter of if. It's a matter of when.
Understanding what happens during this review, who shows up, and how ratings work is the difference between a smooth assessment and a stressful one.
Dig deeper below to learn more.
A DCSA facility inspection is a formal review of how well your organization complies with the National Industrial Security Program Operating Manual (NISPOM), codified at Title 32 of the Code of Federal Regulations (CFR) Part 117. DCSA now refers to this process as the Security Review and Rating Process (SRRP). Many contractors still call it a
This process sits at the center of how the Defense Counterintelligence and Security Agency (DCSA) protects classified information across the defense industrial base on behalf of the Department of Defense (DoD) (also known as the Department of War). If your organization holds an FCL, participation isn't optional.
For more background on how ratings evolved under the refined framework, see DCSA Vulnerability Assessments: How to Know If You're Ready.
Each cleared contractor is assigned an Industrial Security Representative (ISR) from DCSA. The ISR is responsible for confirming that your organization is complying with the policies and procedures outlined in the NISPOM.
Your ISR is also typically the same point of contact you work with throughout the life of your FCL, not just during a formal review.
If you're still working through initial sponsorship, A Guide to Obtaining a Facility Security Clearance walks through how an ISR is involved from day one.
A DCSA facility inspection covers far more than a single filing cabinet or a single system. Investigators are looking at how security is built into daily operations.
For a closer look at what's commonly missed, our 2026 DCSA Inspection Prep Checklist breaks down what Industrial Security Representatives review and where contractors tend to fall short.
DCSA rates facilities on a five-level scale. Where your facility lands affects your standing, and in some cases, your ability to keep your FCL at all.
DCSA also distinguishes between general conformity and not in conformity. A facility found not in conformity may be placed into a Compliance Improvement Process to address the gaps.
There isn't a universal calendar for DCSA facility inspections. Every NISP facility is subject to a recurring review, but the exact timing is risk informed.
DCSA's refined rating framework under the Security Review and Rating Process took effect in October 2024, and it was designed to reduce subjectivity and increase consistency across ratings.
DCSA expects contractors to run their own internal reviews using a process that mirrors its own. This isn't a formality. It's how most organizations catch and fix problems before an ISR ever walks in.
ISI Insight: If DCSA finds several issues during a formal review that should have been caught during your own self-inspection, that gap itself becomes a finding. A thorough self-inspection protects your rating twice over.
Our blog, How to Prepare for Your DCSA Assessment, goes deeper on building a repeatable readiness routine.
A DCSA facility inspection isn't just an administrative event. It's how your organization proves, on a recurring basis, that it can be trusted with classified information.
Contractors that treat readiness as ongoing, rather than reactive, tend to walk into these reviews with far less friction.
Yes, they refer to the same review. "Vulnerability Assessment" is the informal, longstanding industry term. DCSA's current formal name for the process is the Security Review and Rating Process (SRRP).
A minimum of "satisfactory" is required to maintain your Facility Security Clearance. Ratings below that level can trigger a Compliance Improvement Process or further review.
Notice practices can vary, and frequency itself is risk based rather than fixed to a set calendar. The safest approach is to treat readiness as continuous rather than something to prepare for only once notified.
The Facility Security Officer (FSO) typically leads readiness efforts, but a strong outcome depends on cooperation across personnel security, IT, and leadership, not the FSO alone.