Official websites use .mil
Secure .mil websites use HTTPS
The National Access Elsewhere Security Oversight Center (NAESOC) provides consistent oversight and security management for cleared facilities that do not store classified information on-site — known as 'access elsewhere' facilities.
Review the resources below to find tools that support your facility's security program. If you cannot find what you need, email the NAESOC General Mailbox.
Email Email: dcsa.naesoc.generalmailbox@mail.mil
Government Service Portal and NISS messaging is available at all times.
For industry and GCA support, NAESOC offers an escalation process for inquiries already submitted to the Help Desk. Use the blue escalation button above to submit escalation requests.
Phone: 878-274-1344
Email: dcsa.ITSupport@mail.mil
Hours: Monday–Friday, 5:00 a.m.– 8:00 p.m. ET; Saturday, 8:00 a.m.–2:00 p.m. ET
https://www.dcsa.mil/Industrial-Security/Controlled-Unclassified-Information-CUI/Cybersecurity-Maturity-Model-Certification-CMMC/
https://dodcio.defense.gov/CMMC/
A security violation is defined as a failure to comply with NISPOM policies and procedures that could reasonably result in the loss or compromise of classified information. Security incidents involving classified information must be reported to DCSA.
Facilities assigned to NAESOC must report security violations immediately through NISS Messenger. The Security Incident Job Aid provides guidance on incident response, remediation, and submitting initial and final security violation reports.
Contractors must report all relevant and available information indicative of a potential or actual insider threat. When reporting includes Personally Identifiable Information (PII), submit through NISS Messenger.
The Reporting the Threat job aid and CDSE Insider Threat Content have been developed to support reporting and Establishing Insider Threat Programs.
Facilities must report cyber incidents or intrusions regardless of the classification level of the information or systems involved, provided the contractor has determined that: (1) the circumstances qualify as actual, probable, or possible espionage, sabotage, terrorism, or subversive activities; and (2) these activities constitute a threat to classified information, systems, or programs covered by the NISPOM.
NAESOC Facilities shall report cyber intrusions via NISS messenger.
All Suspicious Contact Reporting shall be reported to your local DCSA CI Special Agent.
Foreign Vetting in Academia: A tri-fold
Counterintelligence Awareness and Reporting: A tri-fold
Counterintelligence Best Practices for Industry Booklet
Counterintelligence Awareness and Reporting for NAESOC Facilities
Adverse information is any information that negatively reflects on the integrity or character of a cleared employee, suggests that the employee's ability to safeguard classified information may be impaired, or indicates that their access to classified information may not be in the interest of national security.
Revised ISL
Change Conditions are those organizational changes that could affect the Facility Clearance.
Ownership, including stock transfers
Legal Structure
Operating Name
Principal Address
Key Management Personnel
Foreign Ownership, Control, or Influence (FOCI)
Bankruptcy
FCL Termination
Cage Code changes (rare)
Formal submission of Changed Conditions are required to be completed in NISS as an FCL Change Condition Package. Please ensure all business documentation is submitted to substantiate the reporting.
*Note: When entering discussions, consultations, or agreements that may reasonably lead to effective ownership or control by a foreign interest, the contractor shall immediately report the details to DCSA via NISS messenger.
Facility Profile Update Requests–Information that can be edited by Industry users includes, but is not limited to new contracts, program assets, and essential Key Management Personnel and security staff contact information. Facility profile updates have replaced Requests For Information (RFI); so ensure that you review your profile and submit timely updates. *Note: Please ensure all of your appropriate DD Form 254s are submitted via NISS. *Note: FCL Change Conditions should not be submitted as a Facility Profile Update Request.
An insider threat program plan endorsed by the Insider Threat Program Senior Official (ITPSO) (32 CFR Section 117.7(b)(4))
Formal appointment by the contractor of an ITPSO who is a U.S. citizen employee and a senior official of the company (32 CFR Section 117.7(b)(1)(iii)).
Contractor reviews, certified annually (32 CFR Section 117.7(h)(2))
Reporting (32 CFR Section 117.8).
Insider threat training (32 CFR Section 117.12 (g))
User activity monitoring on classified information systems (as required) (32 CFR Section 117.18 (b)(4)(i).
Risk Management Framework (RMF) (as required) (32 CFR Section 117.18 (e)
Mandatory training is required for all insider threat program personnel appointed on or after July 1, 2025. Personnel appointed before this date who have completed training aligned to previous guidance are exempt.
Audience and Responsibility: "Program personnel" are individuals who manage the insider threat program, including the Insider Threat Program Senior Official (ITPSO). The ITPSO is responsible for identifying all program personnel and ensuring they complete the required training.
Training Options: Insider threat program personnel must complete one of the following two options to satisfy the DCSA training requirement (see below).
INSIDER THREAT WEBEX. In order to identify the risks and mitigations regarding Insider Threat for Access Elsewhere facilities, the NAESOC has specifically prepared this webex for the requirements of the non-possesing facility.
You can find additional information on Insider Threat reporting on the new Counterintelligence Awareness and Reporting for NAESOC Facilities webex
CHECK OUT INSIDER THREAT CASE STUDIES
CDSE has added a new case study to the case study library:
Ahmedelhadi Serageldin – A case of an insider’s mishandling of classified information
Russel Langford – A case study of an insider’s kinetic violence