Understanding FOCI: A Comprehensive Guide
Your Trusted Resource for Navigating Foreign Ownership, Control, or Influence (FOCI) and DCSA Mitigation Requirements
What Is FOCI? Understanding Its Role in Security
Foreign Ownership, Control, or Influence (FOCI) is the standard the Defense Counterintelligence and Security Agency (DCSA) uses to determine whether a foreign interest could compromise a cleared U.S. company's ability to safeguard classified information.
It applies to any organization that holds, or is pursuing, a facility clearance under the National Industrial Security Program (NISP).
Not just Department of War (DoW) contracts. Classified defense work is the most common trigger, but FOCI can also apply to contracts supporting:
- The Intelligence Community
- The Department of Energy
- The Nuclear Regulatory Commission
- The Department of Homeland Security
- Other federal agencies that share classified information with industry partners
A foreign investor, board member, or creditor at your company puts your facility clearance and future contract eligibility on the line, regardless of which agency you work with.
For a closer look at how FOCI plays out for FSOs and executive teams, see What Every FSO and Executive Needs to Know About FOCI Compliance.
FOCI and 32 CFR Part 117
FOCI determinations and mitigation are authorized by the National Industrial Security Program Operating Manual (NISPOM) Rule, codified at Title 32 of the Code of Federal Regulations (CFR) Part 117. Why this matters:
- FOCI is not a one-time snapshot. The latest revision to the Standard Form 328 (SF-328) requires it to be submitted and validated at least annually, and any change to your leadership or ownership at any point in the contract's lifecycle can also trigger a new SF-328 submission and, potentially, a new mitigation agreement
- Once cleared, companies operating under a Security Control Agreement (SCA), Special Security Agreement (SSA), Voting Trust (VT), or Proxy Agreement (PA) also submit quarterly reports, on top of the required annual SF-328 validation, and remain under continuous DCSA monitoring for any ad hoc material change. A new SF-328 with each contract award is not yet required, though that change has been proposed as part of the FOCI expansion rule under Section 847
- DCSA oversees FOCI determinations under its authority in 32 CFR Part 117, and can require a range of mitigation instruments depending on the level of foreign ownership, control, or influence involved
- A proposed rule would soon expand FOCI requirements well beyond classified contracts, meaning far more contractors will need to understand this framework in the years ahead
How the Proposed FOCI Expansion Rule Could Reshape the Requirement
In May 2026, DoW proposed a rule to expand FOCI requirements by implementing Section 847 of the FY2020 National Defense Authorization Act (NDAA) and Section 819 of the FY2021 NDAA.
- The rule will extend FOCI disclosure and mitigation requirements to unclassified DoW contracts and subcontracts valued at $5 million or more, targeting contracts that access sensitive data, systems, or processes
- The change is expected to increase the number of impacted companies from roughly 2,000 to more than 40,000, covering an estimated $200 billion in acquisitions not currently subject to FOCI vetting
- This obligation attaches once a contract is bid, not only once it's won, so the figures above reflect bids as well as awards
- The comment period closed July 6, 2026, and DCSA is targeting a final rule by October 1, 2026
If your company works on DoW contracts, expect it to be subject to this rule once it's finalized. Dig deeper into the proposed rule.
For more on which contractors are newly in scope, see FOCI Requirements Set to Expand to Non-Classified Contractors.
- Self-Disclosure Through the SF-328
-
Contractors self-identify potential FOCI by submitting the SF-328 to DCSA. The form was updated May 1, 2025, condensing it to nine questions and lowering the foreign ownership reporting threshold to 15%. A newer version was published in July 2026, and contractors should confirm they are using the current version before submitting.
- Ownership, Control, and Influence Thresholds
-
DCSA evaluates three thresholds of exercisable power:
- Ownership. A quantifiable stake, often measured by shares or equity class.
- Control. The power to direct business operations or leadership appointments.
- Influence. Informal pathways that fall short of direct power but could still shape outcomes, such as supply chain relationships or financial review rights.
DCSA also weighs a foreign investor's history with espionage, unauthorized technology transfers, and compliance.
- Mitigation Instruments
-
If DCSA determines mitigation is necessary, it selects from a range of instruments depending on the level of risk, from a board resolution or Special Board Resolution (SBR) on the lighter end, to a Security Control Agreement (SCA), Special Security Agreement (SSA), Voting Trust (VT), or Proxy Agreement (PA) for more significant foreign ownership or control.
- Governance and the Government Security Committee (GSC)
-
Companies under an SCA, SSA, VT, or PA must establish a permanent Government Security Committee of the board, composed of cleared outside director(s), with the Facility Security Officer (FSO) serving as principal advisor.
See How FOCI Boards Work: A Guide for Defense Contractors for a full breakdown of board composition, inside versus outside directors, and GSC responsibilities.
- Supplemental Documentation
-
Depending on the mitigation instrument, companies must also maintain a set of supplemental plans, including a Technology Control Plan (TCP), Electronic Communications Plan (ECP), Affiliated Operations Plan (AOP), Facilities Location Plan (FLP), Visitation Plan (VP), and, increasingly, a Quality Management Plan (QMP).
- Ongoing Reporting Requirements
-
FOCI-mitigated companies must submit annual certifications confirming their mitigation agreement remains accurate, and must proactively disclose any material change in ownership, leadership, or foreign relationships. DCSA will not remind a company when an update is due. Many companies also hold required quarterly meetings, in addition to the annual certification. Outside directors play a central role in that cadence, and resources like Monoc's FOCI Leadership Forum can help outside directors and proxy holders stay current.
Why FOCI Compliance Matters
- FOCI Protects National Security: Mitigation ensures foreign interests cannot direct or influence a cleared company in ways that could compromise classified information
- Compliance Maintains Your Contract Eligibility: Contractors must resolve any FOCI finding to remain eligible for classified work. Non-compliance can lead to disqualification or a revoked facility clearance
- Compliance Supports Your Business Reputation: Companies that manage FOCI transparently build trust with DCSA, primes, and government partners
- FOCI Increasingly Overlaps with Broader Compliance Requirements: As the proposed expansion rule moves forward, FOCI will intersect more directly with Cybersecurity Maturity Model Certification (CMMC) and Controlled Unclassified Information (CUI) safeguarding obligations many contractors already manage
- It Future-Proofs Your Business Operations: With FOCI review expanding to tens of thousands of additional contractors, understanding the framework now positions your company ahead of competitors who have never been through the process
Loss of Facility Clearance
Failing to resolve a FOCI finding can result in suspension or revocation of your facility clearance, preventing your organization from bidding on or maintaining classified contracts.
Contract Termination
Non-compliance may lead to termination for default on classified contracts, resulting in immediate revenue loss.
Invalidated Mitigation Instruments
An outdated or non-compliant mitigation agreement can be invalidated, exposing your classified work to renewed DCSA scrutiny.
Regulatory and Legal Exposure
Serious or repeated FOCI issues involving a foreign transaction can draw the involvement of the Committee on Foreign Investment in the United States (CFIUS) or DoW, in addition to DCSA.
Loss of Teaming Relationships
Primes managing their own supply chain risk may distance themselves from subcontractors with unresolved FOCI findings.
Ineligibility for Future Work
Non-compliant organizations may be barred from bidding on new classified work, limiting growth opportunities.
what our customers say
A U.S. subsidiary of a Europe-based company came to ISI caught between two requirements: satisfy an existing FOCI mitigation agreement and build the IT infrastructure to support the defense and federal work it was pursuing. Most vendors could do one or the other. Security advisors understood the mitigation instruments but not the infrastructure; managed service providers could build the environment but not interpret the FOCI agreement it had to satisfy.
ISI brought both under one engagement, standing up a new commercial Microsoft tenant fully separated from the parent company and aligned to the subsidiary's ECP and TCP, while preserving the cross-tenant collaboration the parent company's board required for non-defense work. The subsidiary passed its DCSA self-inspection and formal review with its FOCI mitigation documentation fully implemented, not just filed, and is now positioned to pursue CUI-eligible work as its defense business matures.
READ THE FULL CASE STUDY: Two Requirements, One Project: A FOCI Problem That Needed an IT Solution.
CORE FOCI REQUIREMENTS
FOCI compliance is built on several core requirements. Here's a closer look at what each one involves.
WATCH: Cate Pearson, ISI President, Managed Security Services, and Paul Michaels, CEO, Monoc Securities LLC, break down how DCSA determines FOCI risk, the mitigation instruments companies use to resolve it, and what the proposed FOCI expansion rule means for the tens of thousands of contractors it will newly cover.
The SF-328 and Self-Disclosure
The SF-328 is the primary document DCSA uses to evaluate FOCI. It must be submitted at the start of the facility clearance process and updated whenever a material change occurs, such as a merger, acquisition, new foreign board member, or change in foreign supplier relationships. The May 2025 update condensed the form to nine questions, lowered the foreign ownership reporting threshold to 15 percent, and added a mandatory Statement of Full Disclosure of Foreign Affiliations for management-level individuals with foreign ties.
For companies preparing their first Facility Clearance (FCL) package, Facility Control, a preparation platform ISI developed under a Defense Advanced Research Projects Agency (DARPA) award, is built to catch the SF-328 errors that trigger most FCL package returns, incomplete FOCI disclosures, Key Management Personnel (KMP) mismatches, and inconsistencies with your legal organization chart, before DCSA ever sees them. The platform is now in public beta.
Mitigation Instruments
32 CFR 117.11(d)(2) sets out the instruments DCSA can require, in increasing order of restrictiveness:
Board Resolution or Special Board Resolution (SBR): Acknowledges security responsibilities and walls off any foreign board representation from classified matters. The SBR is the single most common FOCI action plan in use today
Security Control Agreement (SCA): Used when foreign ownership exists but the foreign owner can be effectively insulated without full independent board control. At least one cleared U.S. citizen must serve as an outside director
Special Security Agreement (SSA): The most common instrument for majority foreign-owned U.S. companies. Requires a Government Security Committee of cleared U.S. citizens who control classified access while the foreign parent retains normal business control
Voting Trust (VT) or Proxy Agreement (PA): The most restrictive instruments. Voting rights are transferred to cleared, independent U.S. citizen trustees or proxy holders, severing the foreign owner from classified access and day-to-day control
For a closer look at the Special Board Resolution specifically, including its disclosure schedules and the Quality Management Plan requirement, see Special Board Resolutions and QMPs: A Guide for FSOs and Executives.
Government Security Committee (GSC) Governance
Companies under an SCA, SSA, VT, or PA must maintain a permanent Government Security Committee of the board, composed of cleared outside directors, proxy holders, or voting trustees, plus any cleared officer-directors. The GSC and full board must meet quarterly at minimum, and the GSC chairman must submit an annual implementation and compliance report to DCSA.
Supplemental Documentation
Depending on the mitigation instrument, contractors maintain a Technology Control Plan, Electronic Communications Plan, Affiliated Operations Plan, Facilities Location Plan, Visitation Plan, and, for Special Board Resolution companies, a Quality Management Plan. Each plan ties back to how the company insulates classified work from foreign influence.
Roles and Responsibilities
Legal responsibility for FOCI compliance sits with the Senior Management Official (SMO), typically the company's president, CEO, or executive director. The FSO usually manages the FOCI program day to day, serves as the principal advisor to the GSC where one exists, and is the day-to-day liaison with DCSA's assigned Industrial Security Representative. Legal counsel frequently plays a significant role in completing and updating the SF-328.
Executive leadership sets the tone for FOCI compliance across the organization. Senior executives allocate resources, brief the board on mitigation obligations, and ensure the company treats FOCI as an ongoing discipline rather than a one-time filing.
A Step-by-Step Guide to FOCI Compliance Planning:
1. Determine IF Your Contract Triggers FOCI Requirements
Check for the FAR 52.204-2 clause and review your DD Form 441 to see whether 32 CFR Part 117 is referenced.
2. Map Your Ownership, Control, and Foreign Relationships
3. Submit Your SF-328
4. Understand DCSA's Determination
If your answers indicate potential FOCI, DCSA will review the submission and determine whether mitigation is required.
5. Select and Negotiate a Mitigation Instrument
Work with DCSA to determine which instrument, from a board resolution to a Voting Trust or Proxy Agreement, resolves the government's concerns.
6. Build Required Governance and Documentation
Stand up your Government Security Committee where required and put your supplemental plans in place.
7. Maintain Annual Certification and Disclosure Updates
8. Prepare for the Proposed FOCI Expansion Rule
If you have never held a classified contract, map your ownership and familiarize your team with DCSA's registration process now.
When done correctly, FOCI compliance not only meets regulatory requirements but strengthens your organization's overall security posture. A well-executed approach helps you:
- Reduce Compliance Risk – Stay ahead of regulatory changes and avoid a revoked facility clearance
- Protect Classified Information – Insulate your cleared operations from foreign influence
- Build Trust with Government Partners – Demonstrate transparency and reliability to DCSA and prime contractors
Navigating FOCI Changes
FOCI compliance is evolving alongside the proposed expansion rule. Stay ahead of regulatory changes that could impact your operations by regularly monitoring updates from DCSA and other relevant government agencies.
That evolution isn't limited to the proposed rule itself. DCSA has already updated the SF-328 twice in recent years, and the agency regularly refines its expectations for FOCI-mitigated companies ahead of any formal change to the underlying regulation. Treating FOCI compliance as something you revisit only when a rule changes, rather than a program you monitor continuously, is one of the most common ways contractors fall behind.
Proactive Monitoring
Subscribe to agency alerts, newsletters, and publications from trusted sources in the defense and industrial security sectors. Engage with peer communities, such as outside director and proxy holder forums, to stay ahead of regulatory shifts and new standards before they pose a risk to your operations.
DCSA's own Voice of Industry newsletter is one of the more direct signals available where the agency has previewed changes like SF-328 updates before they take effect. Pair that with training resources such as CDSE's Outside Director/Proxy Holder curriculum and a regular check-in with your legal counsel or FOCI advisor, and you build a monitoring habit that catches a shift in DCSA's expectations before it becomes a compliance gap.
Building a Strong FOCI Governance Program
A strong FOCI program depends on documented board and Government Security Committee (GSC) training, accurate and current disclosure schedules, and a Facility Security Officer with direct access to both the Senior Management Official and the GSC.
Your FOCI Governance Checklist
- Confirm your SF-328 reflects your current ownership and leadership structure
- Confirm outside directors meet regulatory qualifications and have completed required training
- Confirm the GSC and full board are meeting at the required quarterly cadence
- Confirm your supplemental plans (TCP, ECP, AOP, FLP, VP, QMP) are current
- Calendar your annual GSC certification. It’s a hard requirement, not a courtesy
Partnering with ISI means gaining access to unparalleled expertise in FOCI mitigation, from your first SF-328 filing to ongoing board governance. Let us help you navigate DCSA's requirements and stay ahead of the proposed expansion rule. FOCI has traditionally been the domain of outside counsel and boardroom advisors; ISI's compliance team works alongside your legal counsel, bringing hands-on DCSA experience and documentation expertise to complement that guidance, not replace it.
FOCI FREQUENTLY ASKED QUESTIONS
- What is FOCI?
-
Foreign Ownership, Control, or Influence (FOCI) is the standard DCSA uses to determine whether a foreign interest could compromise a cleared company's ability to safeguard classified information. It applies to organizations that hold or are pursuing a facility clearance.
- What’s the difference between FOCI and NISPOM?
-
NISPOM, the National Industrial Security Program Operating Manual, is the broader regulation governing how cleared contractors protect classified information, covering facility clearances, personnel clearances, and systems security. FOCI is one specific area within that framework, focused on whether foreign ownership, control, or influence over a company could compromise its ability to meet those obligations.
- Who is responsible for FOCI compliance within an organization?
-
Legal responsibility sits with the Senior Management Official (SMO), typically the company's president, CEO, or executive director. The Facility Security Officer (FSO) usually manages the FOCI program day to day, and legal counsel plays a key role in completing the SF-328.
- How does the SF-328 process work?
-
The SF-328 must be submitted at the start of the facility clearance process and updated whenever a material change occurs. DCSA reviews the submission and determines whether mitigation is necessary based on the level of foreign ownership, control, or influence involved.
- What are the different FOCI mitigation instruments?
-
Instruments range from a basic board resolution or Special Board Resolution (SBR) to a Security Control Agreement (SCA), Special Security Agreement (SSA), Voting Trust (VT), or Proxy Agreement (PA). DCSA selects the instrument based on the level of foreign ownership, control, or influence involved.
- How does the proposed FOCI expansion rule affect non-classified contractors?
-
If your company holds or pursues DoW contracts or subcontracts valued at $5 million or more, the proposed rule would apply to you even without a classified contract. DCSA is targeting a final rule by October 1, 2026.
- What happens if our ownership changes after a FOCI review?
-
FOCI is not a one-time determination. Any material change to leadership or ownership can trigger a new SF-328 submission and, depending on the nature of the change, a new mitigation agreement.
- How can companies stay up to date with FOCI changes?
- Regularly monitor updates from DCSA and other relevant government agencies, subscribe to agency alerts and industry publications, and engage with peer communities focused on industrial security and FOCI governance. ISI is also actively tracking FOCI developments, including the proposed expansion rule, and will keep this page updated as new guidance is finalized. Subscribe to our newsletter to get updates like this delivered directly to your inbox. Lastly, you can use our DIB FOCI Compliance Status Tracker to learn where the regulations that govern defense contractors stand right now.