In Part 1 of this series, we examined the Department of Defense’s Proposed Rule and how it would broaden the reach of Foreign Ownership, Control, or Influence (FOCI) obligations across the defense industrial base. Before looking ahead, it helps to understand how the current framework works. In this installment, PilieroMazza attorneys walk through the foundation of the existing system: obtaining and maintaining a facility security clearance, securing personnel security clearances for the people who run and safeguard the business, and, where a company is under FOCI, implementing mitigation measures.

Obtaining and Maintaining a Facility Security Clearance

A facility security clearance (FCL) is a determination that a company is eligible to access classified information in connection with a legitimate government requirement. A company generally needs an FCL when it holds, or is competing for, a classified contract or subcontract, signaled by a solicitation or contract issued with a DD Form 254.

Notably, an entity cannot apply for its own FCL. The clearance must be sponsored, either by a government contracting activity (e.g., a specific office within a government agency) or by an already-cleared prime contractor that needs the company to access classified information to perform its work. Sponsorship can occur at any point in the contracting life cycle, including during the solicitation or competition phase.

Once sponsored, the company must satisfy several of the Defense Counterintelligence and Security Agency’s (DCSA) eligibility criteria. The criteria includes being organized and located in the United States, having a record of integrity in its business dealings, and appointing U.S. citizens to serve as its Facility Security Officer (FSO), Insider Threat Program Senior Official (ITPSO), the highest-level officer of the company, and, if relevant, likely the chairman of the board. Critically, the company cannot be under FOCI unless it can be sufficiently mitigated, as discussed in detail below. Neither the company nor its employees may access classified information until DCSA issues the determination.

To maintain an FCL, a company must continue to meet the same eligibility requirements that supported the initial determination, maintain enough cleared and authorized employees to run its security program, and comply with the ongoing obligations of the National Industrial Security Program Operating Manual. The most important requirement is keeping DCSA informed. Contractors must report changed conditions that affect the clearance, such as changes in ownership or control, changes in key management personnel, and any material change in FOCI status. Part 3 of this series will address the reporting obligations in detail.

Personnel Security Clearances

An FCL depends on people. Certain individuals, including the company’s senior management officials (which likely includes the highest-level officer but could include others), FSO, ITPSO, and other key management personnel identified by DCSA—mostly at the discretion of the reviewing official—must obtain personnel security clearances (PCLs) as part of the FCL. More broadly, any employee who needs access to classified information to perform their work must obtain a PCL.

Three conditions must be present before an employee accesses classified information: the employee must have a valid need-to-know, a favorable eligibility determination at the appropriate level, and a signed nondisclosure agreement. The scope of the background investigation is tiered to the sensitivity of the position and the level of access required, ranging from Confidential and Secret up to Top Secret and Sensitive Compartmented Information. The individual clearance process can take six months to a year, and sometimes longer.

Like an FCL, a PCL must be maintained. Cleared employees are subject to continuous vetting. In appropriate cases, DCSA can grant interim clearance while a full investigation is completed; however, interim eligibility is generally only issued where the facts and circumstances indicate that access to classified information is consistent with U.S. national security interests.

Required FOCI Mitigation Measures

If DCSA determines that a company is under FOCI, the company becomes ineligible for classified access unless and until effective measures are in place to negate or mitigate that influence to DCSA’s satisfaction. The right measure depends on the nature and degree of the foreign interest, and DCSA applies an escalating set of tools.

  • Exclusion Resolution: An exclusion resolution blocks any non-U.S. owner or entity from accessing or exercising control or influence over any of the classified information, the work where access to classified information is necessary, or any action that could adversely impact the classified contracts performed by the entity holding the FCL. This is the lowest tier of mitigation and is generally utilized when there is foreign ownership above a cleared entity, but that owner does not exercise control over the entity or its decision making (e.g., a French citizen owns 10% of a cleared entity but that owner cannot appoint a board member or manager of the company). In more complex business structures, however, these can be quite detailed and include officers, board members, and other key personnel in the company.
  • Security Control Agreement (SCA): Where a foreign interest is entitled to board representation, or has voting rights as a manager or member, but does not effectively control a U.S.-controlled company, an SCA may be used. This is the second tier of mitigation and requires at least one cleared U.S.-citizen outside director and formation of a Government Security Committee (GSC) to oversee the mitigation measures, which may include the adoption of an accompanying Affiliated Operations Plan (AOP), Electronic Control Plan (ECP), and Technology Control Plan (TCP).
  • Special Security Agreement (SSA): As the third tier of mitigation, an SSA is often required where one or more foreign interests effectively own or control the company. The SSA preserves the foreign owner’s voice in management through inside directors while denying majority representation and unauthorized access to classified information, and it institutionalizes a detailed set of security practices. It includes many of the same requirements as the SCA.
  • Voting Trust or Proxy Agreement: The most stringent measures vest the voting rights of the foreign-owned stock in cleared U.S. citizens approved by the government—trustees under a voting trust or proxy holders under a proxy agreement. Unlike an SSA, these arrangements place no restriction on the company’s eligibility for classified access or its ability to compete for classified contracts.

Implementing FOCI mitigation is best approached as a collaborative, negotiated process with DCSA rather than an adversarial one. The stakes are always heightened when national security is at risk. A company that cannot reach agreement with DCSA on acceptable mitigation, or whose business ethics are called into question due to non-compliance with DCSA requests, will not obtain an FCL and may lose classified and even unclassified contracts that require it.

PilieroMazza attorneys are well-versed in helping clients navigate FCL, PCL, and FOCI mitigation requirements. If you need assistance or have questions, please contact Cy Alba, Daniel Figuenick, Cole Fox, or another member of the Firm’s Government Contracts and Corporate & Organizational Governance practice groups.

____________________

If you are seeking practical insights to gain a competitive edge by understanding the government’s compliance requirements, tune into PilieroMazza’s podcasts: GovCon Live!Clocking in with PilieroMazza, and Ex Rel. Radio.