Video summary
The 76th meeting of the National Industrial Security Program Policy Advisory Committee (NISPPAC), held at the National Archives on September 2, 2026, opened with Director Mike Thomas framing the committee's evolving mission within a historical context that spans from post-Cold War reforms to modern challenges involving AI and quantum computing. Outgoing industry spokesperson Isaiah Rivers delivered a farewell address before his retirement, praising the committee's role in fostering dialogue between the government and cleared industry while presenting commemorative items to departing members. The session included updates on legacy system stabilization and modernization efforts, with representatives emphasizing the need for clear operational roadmaps, formal feedback loops, and strengthened partnerships with the Intelligence Community to resolve high-priority issues efficiently.
Significant progress was reported across various technical and procedural fronts, particularly regarding the transition from legacy systems to the new NI2 platform and the rollout of Trusted Workforce 2.0. Allison Renzella from DCSA detailed the migration from the Central Verification System to the Joint Verification System, noting that while investigative backlogs exist, mitigation strategies like virtual methodologies and the upcoming Individual Engagement Platform will streamline self-reporting for applicants. Updates on the Personnel Vetting Questionnaire highlighted early adoption success with hundreds of submissions already processed, while discussions on NIST 800-53 Rev 5 implementation clarified timelines for system authorization and solid-state drive sanitization. Additionally, agencies like DHS and DOE shared performance metrics showing improved processing times for clearances despite workforce changes, though concerns remained regarding data integrity issues and the need to avoid redundant requirements that hinder mission readiness.
The meeting also addressed critical policy disconnects affecting small businesses and legacy facilities, including discrepancies between current regulations and older statutes that require congressional-level resolution. Speakers emphasized the importance of balancing administrative burdens with actual national security work, advocating for common-sense security tools and better guidance on AI usage to enable rather than limit operations. Legal updates from the Defense Office of Hearings and Appeals reinforced the independent role of adjudicators in ensuring fair hearings, while new initiatives like the NISPAC Industry Award were announced to recognize excellence within the Defense Industrial Base. The committee concluded by expressing gratitude to retiring members and outlining a robust agenda for future collaboration, with the next meeting scheduled for March 17th to continue advancing these shared goals.
Read the full video transcript
Thank you everybody for being here
today. Welcome to the stately McGawan
Theater and the 76th meeting of the
National Industrial Security Program
Policy Advisory Committee. My name is
Mike Thomas. I'm the director of the
information security oversight office
and I have the honor of being your host
today and serving as our chair. For over
three decades, the NISPAC has served as
a critical bridge between our government
and the elements of American industry
that provide the methods and the means,
the critical innovations and the
commercial infrastructure that help
guarantee the continuing security of our
nation. Each time we gather here for a
meeting of the NISPAC, I aim to use
these opening moments to situate this
shared mission in its wider historical
context. We are at the National Archives
after all. But I see it as a chance
every time for me to learn, to pay my
respects, and to share with you how I
see your work. And I hope that in that
you all really do feel seen and that you
feel proud of what we're striving for
together. a single integrated cohesive
industrial security program protecting
classified information while preserving
our nation's economic and technological
interests without redundant overlapping
or unnecessary requirements that would
impede those interests with security
based on actual risk rather than the
disjointed accumulation of bureaucratic
corrupt. Security requirements that are
duplicative and yet somehow also
contradictory. the sort of requirements
that focus on near absolute risk
avoidance for a very specific set of
circumstances rather than serving
reasonable and holistic risk management.
This is for government. I grant you a
pretty audacious goal. In fact, my long
ago predecessor, former ISU director
Bill Leonard, once said that in
government, anything that is intended to
be integrated and cohesive is not easily
achieved and once achieved not easily
preserved. Which is exactly why this
forum, the NISPAC, remains so vital. The
National Industrial Security Program was
born as a postcold war government reform
project. William Perry, the deputy
secretary of defense under President HW
Bush, acknowledged that with the fall of
the Soviet Union, we should be able to
dismantle a significant part of this big
complex expensive apparatus.
At the same time, in 1993, they could
not have predicted the global war on
terror to come, much less a new wave of
international authoritarianism or the
return of great power competition. the
impact of new electronic capabilities
for espionage, cyber warfare, drone
weaponization, the tidal wave of AI
adoption, or the power of quantum
computing to throw all of our accepted
security norms into disarray.
And these dramatic shifts over ensuing
decades make our continued attention to
the NISK mission more important than
ever.
Time and again, we've seen how our
government turns to industry to address
emerging gaps arising from the
everchanging landscape of threats and
opportunities that shape the contours of
our national security.
And the federal government found itself
in a moment almost exactly like this one
in 1917. We found ourselves confronted
by international conflict amongst great
powers following on the heels of a
global pandemic.
This was a conflict in large part
defined by the emergence of new military
and intelligence technologies and the
need to think about the battlefield in
new ways.
In January of 1917, our British allies
intercepted and decoded a telegram from
German Foreign Secretary Arthur
Zimmerman, which shockingly proposed a
military alliance between Germany and
Mexico against the United States,
offering up Texas, New Mexico, and
Arizona if Mexico came over to the
German imperialist cause in the ongoing
war in Europe. This was the tipping
point, catalyzing American public
opinion against Germany, bringing the
United States militarily into World War
I.
But there was a major problem and the
incident of the Zimmerman telegram
called it out starkly. The United States
in 1917 completely lacked the technical
capability to intercept and decode
German transmissions the way the British
had. Nor at that time did we have the
ability to protect our own
communications from similar
exploitation. Literally not one federal
department was engaged in cryptographic
activities which had been almost
entirely neglected since the end of the
American Civil War 60 years earlier. As
it happens, telegraphic communication
was the backbone of the Union strategic
command, giving them a decisive edge
against in helping them win the war.
Both sides, the Union and the
Confederacy used the telegraph. Um but
only the Union was able to centralize
its command while maintaining near
absolute operational security. They they
accomplished this by successfully
industrializing the technology. They
created a dedicated civilian military
hybrid organization, the US military
telegraph cores. It lay over 15,000
miles of wartime cable, employed over
12,000 telegraphers, and transmitted
more than 6.5 million messages. Would
you be surprised to know that not a
single one of those messages was decoded
by the Confederacy during the entire
war? And you want to talk about a
situation room? Let me talk to you about
the situation in the War Department
telegraph office where President Abraham
Lincoln spent countless hours
coordinating the Union's multi-theater
battle strategy. Incredible and
completely abandoned in that window
between healing this historic breach in
our history and America's emergence as a
global power.
In the meantime, from the telegraph to
the radio to trans oceanianic cables, by
1917, there was both an enormous new
intelligence gathering opportunity, as
well as an absolutely terrifying new
attack service for which we as a nation
were fully unprepared. And there was
only one answer, one place for America
to turn. That was to the theater. Or
more specifically, to the plays of
William Shakespeare. Let me explain. It
all starts way back in the 1500s with a
conspiracy. Some of you more
literary-minded friends may already know
this, but some claim that William
Shakespeare was not in fact the author
of the famous plays that bear his name.
Hamlet, McBth, Romeo, and Juliet. These
conspiracies,
>> these
>> the anti stratordians are checking in
right now.
Uh they claim that there are clues to
the true author of Shakespeare's plays
to be found in the plays themselves.
Secret messages waiting to be decoded.
Enter George Fabian. Fabian was a
Midwestern textile magnate and the sort
of a turn of the century Tony Stark
complete with epic facial hair. And he
counted himself amongst these
anti-stratfordians fingering Sir Francis
Bacon as the true bard. and he set about
trying to prove it. At Fabian's
pioneering Riverbank Labs facility,
built in 1913 on 300 acres an hour
outside of Chicago, he assembled a team
and they went to work on his pet theory.
Now, let me say this was far from the
weirdest thing going on at Riverbank
Labs. Fabian was also interested in
experimenting with the healing powers of
musical harmonics, and the grounds were
littered with all sorts of novelties. a
windmill, a lighthouse, Japanese
gardens, a grotto, green houses, a zoo,
a farm, and a villa designed by
Franklidd Wright. Amongst Fabian's early
recruits was Elizabeth Freriedman, who
was at the time a 24year-old
multilingual expert in the classets, who
who had last worked as a substitute
principal in Wabash, Indiana. At the
time, Fabian rolled up in his black
limousine to sell her on life at
Riverbank. Elizabeth was jobless, having
quit the school and returned home to
live with her parents. You got to think
joining his sort of particularly bookish
Avengers was an easy yes at that point.
In the course of her research at
Riverbank, exploring this bacon
Shakespeare theory, Elizabeth with no
formal training and with only pen,
paper, and her substantial intellect as
her tools, she became one of the one of
the foremost cryptographic experts in
the entire world. And with the onset of
World War I, the US government came
calling with their particular problem.
They had nobody like Elizabeth
Freriedman. and Riverbank Labs
Department of Cypress was formed to aid
in the war effort. Now, Elizabeth
eventually went to work for the War
Department directly and later still she
led coast guard efforts to bust rum
runners during prohibition, cracking
some 12,000 messages from smuggling
rings, gathering the evidence that was
ultimately used to indict Al Capone. In
fact, she was the most prominent crypt
analyst in the world during the inner
war period due to her testimony in these
many high-profile cases. and her service
continued into World War II where she
led a clandestine unit that broke the
complex axis and enigma cipher ciphers
neutralizing Nazi spirings in South
America. These contributions would
remain classified until 2008. Although
Jay Edgar Hoover was happy to take
credit back in the 1940s for the FBI,
Elizabeth was in a word extraordinary.
And along with her husband William, the
Freedmans mentored a generation of cryp
analysts, becoming the mother and the
father of America's cryptographic
capabilities and modern signals
intelligence. And it all began at a
private research facility with the
government sharing its most sensitive
information in the interest of solving
technical challenges that the government
could not solve on its own.
Freriedman passed away in 1980 and we
sit here today barely one working life
beyond her legacy. A legacy that might
never have existed without the
partnership between the government and
the private sector at Riverbank Labs.
This is a good time to mention that
George Fabian offered his services to
the government for free. Being a Tony
Stark style millionaire playboy
philanthropist has its perks, I guess.
Once again, we sit at the unnerving
precipice of challenging questions about
how how our government will be able to
field the capabilities it will need to
deter and defeat a new array of global
antagonists and adversaries. And that
brings us to the present day and the
work ahead. We have been diligently
seeking to adapt not just our military
and intelligence capabilities, but the
NISP itself to a new global threat
environment that demands new ways of
doing business. This 76th meeting of the
NISPAC I am confident will carry us
further down that road and I look
forward to the comments from both
industry and government today and the
conversation that ensues which will
further flesh out both the journey ahead
and the destination that it's leading us
towards. Thank you and let's get
started.
Thank you, Michael. Good morning,
everyone.
I'm Heather Harris Pagon, the designated
federal officer for the NISPAC. Before
we begin, I want to thank the volunteers
for their work today in making today's
meeting possible. Thank you.
For those in the theater, please take a
moment now to silence all mobile
devices. We have restrooms located
outside the theater. When exiting the
theater, the men's room is to the left
and the woman's room is to the right.
Food and drinks except water are not
permitted in the theater, but we do have
a cafe to the left when exiting the
theater for food and drinks during the
break.
In the event of an emergency, please go
out the way you came in and exit the
building immediately. Please use the
microphone on the stand towards the
front middle um if you have questions.
For the NISPAC members on stage, this is
a reminder that your microphones cannot
be muted or unmuted manually, so please
avoid sidebar conversations.
All NISPAC meeting announcements are
posted in the Federal Register
approximately 30 days before the meeting
along with being posted to the ISU blog.
Today's meeting is being recorded and
will be available on the ISU website
within 90 days along with the slides and
meeting minutes.
to help our recordkeeping. If you are
virtual and your name is not visible
through Zoom forgov, please email your
name to nispac@nara.gov
for our attendance records. This
includes those watching live on YouTube
and those calling in on the phone. For
questions, we prefer our virtual
attendees email nispac@nar.gov
or utilize the Zoom forgov chat. If you
are on the phone and cannot email, press
star 9 to raise your hand and star six
to unmute as a last resort, please.
For speakers, if you are in person,
please use the podium and advance your
own slides. If you are a virtual
speaker, simply say next slide to our
team. Please note, all audio connections
via telephone and computer should be
muted when not speaking. We have
scheduled a 20-minut break at the
halfway point. A reminder to our
government members, please ensure your
financial disclosure is on file with
NAR's Office of General Counsel. This is
an annual requirement for your service
to this committee. If you require
technical assistance, please send an
email to NISPACNAR.gov.
We will now begin the roll call. When I
call your agency your name, please state
your name for the record. Department of
War,
>> Office of the Director of National
Intelligence,
>> President Lisa Perez.
>> Thank you, Lisa. Department of Homeland
Security.
All right. No one from DHS. Department
of Energy.
>> Thank you.
Nuclear Regulatory Commission.
>> This is Mike England for the Nuclear
Regulatory Commission.
>> Thank you, Mike. The Defense Counter
Intelligence and Security Agency.
Thank you, Allison. Central Intelligence
Agency.
>> This is Don with say
>> Thank you, Don. Department of Commerce.
>> This is Daniel Bowling with the
Department of Commerce.
>> Thank you, Dan. Department of Justice.
No. Department of Justice.
Uh, Glenn Benley, Department of Justice,
and Lori Ellison.
>> Thank you.
National Aeronautics and Space
Administration.
>> This is Von Simon from NASA.
>> Thank you, Von. National Security
Agency.
No. NSA.
Department of the Air Force.
>> Bakus.
>> Thank you, Annie. Department of the
Army.
Laura.
>> Thank you, Laura.
Department of the Navy.
>> Good morning. This is Jason Steinau. I'm
joined by Dr. Andrew Jones and Rob and
Robin Nickel.
>> Thank you. Department of State.
>> Thank you, Kim. Thank you. I'll now move
on to the industry members. Isaiah
Rivers,
>> thank you. Ike Jane Dinkle,
>> present. Thank you, Jane. Katherine
Andrews,
>> I'm online.
>> Thank you, Kathy. Christopher Stokkey,
>> present.
>> Thank you, Chris. Latoya Coleman,
>> present.
>> Thank you, Latoya.
Charles Sell,
>> present.
>> Thank you, Charlie. Leonard Moss,
>> present.
>> Thank you, Leonard. Jenny Hardy,
>> present.
>> Thank you. I'll tell now take the roll
call for speakers. Thomas Jen Gian Gian
Kohley
Tom are you there?
Tracy Brown.
>> Thank you. Tracy
Perry Russell Hunter. If anyone else is
speaking during the NISPEC that we have
not heard from or we don't know about,
please speak now.
We request that everyone identify
themselves by name and agency if
applicable before speaking each time for
the record. We have had a few changes to
the NISPAC membership. Mr. Robert McCrae
departed DHS. Miss Brianna Palmer will
remain the alternate for DHS. Mr. Daniel
Bowling has been designated as the
alternate for commerce.
Mr. Steve Barier remains the primary for
commerce at this time. Mr. John Borhees
is no longer the primary for the Air
Force. Miss Annie Bakis is still the
alternate. Miss Robin Nickel has been
added as an alternate for the Navy.
There has been no change to the primary
other alternate for the Navy. This is
also the last public meeting for a few
members. Mr. Jeff Spininger, the
Department of War member, is set to
retire next month. He held off on
retirement just for this meeting. So,
thank you, sir.
I'm just kidding. He didn't really. They
won't let him go.
This is also the last public meeting for
two of our industry members, Miss Jane
Dinkle and Mr. Ike Rivers, who was also
our industry spokesperson.
Jeff, Jane, and Ike, thank you so much
for your contributions over the years to
the NISP and security mission as NISPAC
members. The new industry members will
be announced at the next public meeting
along with the new industry
spokesperson. For all of the departed
members, thank you for your
contributions over the years. We look
forward to continuing the work you have
done with the new representatives.
The last public meeting was held March
18th, 2026. The minutes from that
meeting were certified to be true and
correct and were finalized by Michael
Thomas on June 16th, 2026 and posted to
the ISU website on that same day. I will
now address the items of interest from
that meeting.
The Department of War asked ISU to
assist in engaging with the Small
Business Administration regarding
military department's ability to meet
small business requirements. This is
still open.
Industry asked OSWs
to work with military departments to
expand the SEI indoctrination authority
for industry and work with them for a
better process moving forward. This
action item is still considered open.
Industry requested cooperation from
government entities in devising
sanitization procedures for solid state
drives involved in spills. This item is
still considered open.
Industry requested that ISU coordinate
with the CSAs to provide guidance to
industry on all executive orders with
suspected NISP implication implications.
This item has evolved and is currently
with NISPAC industry to help ISU focus
in on their priorities.
industry requested that ISU convene a
meeting of the CSAs to discuss CUI. This
item is still considered open. In
addition to those action items, we also
had questions that were asked but not
answered during previous public meetings
but are answered on our public facing
web page as an additional link for the
report to the last meeting and sent to
those that asked the questions. Are
there any questions or comments on the
action items from the last meeting?
>> Heather, I have one.
Um, Alexis, can we
>> It's giving me try.
>> I just wanted to note that on the CUI
item. That's one that's been
long-standing since I think the my first
NISP pack meeting May of last year. And
when you go back to your desks today,
you check the ISU notice board, which I
know you probably check every day like I
do for um you'll see a couple of new
notices concerning CUI trying to bring
some clarity to the current reg.
landscape and addressing in particular
some of the questions that industry have
had and I think that puts us in a good
moment in the coming months to sit down
and have that conversation. So I just
want to note that we're we're taking
action on that.
>> Thank you sir.
>> Absolutely.
>> Now moving on to the next item on our
agenda. We will now introduce our
speakers for their updates. Mr. Isaiah
Rivers, the NISPAC industry spokesperson
will provide the industry update. Ike.
Hello.
>> Hello.
>> All right.
>> Hello.
Oh.
>> Um,
this is a little bittersweet.
Um, so I can't just wing something
that's bittersweet. So I'd had to jot
down a couple little words and, um, I'll
kind of talk through these words here.
Give me one minute, please.
a minute.
>> Um, first, thank you, U Michael. Um,
thank you to you and to Heather for
always taking care of industry um, and
bringing both bridges together from our
government partners and our industry
partners. Um but before I begin um with
the industry NISPAC updates um uh I just
want to take a moment to acknowledge
that as Mike said this uh meeting in
particular is meaningful one for not
only for me um but for Jane Dingle as
well. Um this is our final NISPAC public
uh meeting serving as both the NISPAC
member and the industry spokesperson. Um
but I still got 28 more days left at the
helm. So we do still got a lot of things
to get after um the next over this next
month. Um for me um as I reflect on the
past four years um it's been incredible.
Um I'm grateful for the opportunity to
serve in this capacity and to be part of
an organization that actually plays such
an important role in strengthening uh
the partnership between government and
cleared industry. Um when I first came
on in this pack, you know, you think
that you know everything. Um, I
understood the importance of the
mission, but I really did not think I
fully appreciated the relationship and
the trust and the shared commitment that
would come with this responsibility. Um,
over these past four years, I've had the
privilege of working alongside some
incredible talented people across the
government and the DIB. Um, I've learned
a tremendous amount um, from our
government partners. Um, but I want to
give a big special shout out to ISU
again for for for bridging this. Um, one
of the things I can truly that I truly
value about the NISPAC is ISU's
commitment to making sure that both
sides of the table have a seat, the
government and industry. That commitment
to bringing people together, creating an
environment for candid dialogue, and
giving both perspectives and opportunity
to be heard is what makes this
partnership so valued. Um, I would be
remiss if I did not give a big special
shout out um to Miss Heather. So,
Heather, if you can please come up here
real quick.
I want to present Heather with our
industry NISP pack coin um that we kind
of put together about a year ago. So
Heather, here's our coin. So thank you
very much.
Um Heather, you have truly been a a
ground pillar of this organization.
um a steady presence, a connector, and
someone who constantly helped keep the
government and industry moving in the
same direction. Um and if you didn't
know, Heather, um you would find out
real quick if you don't give something
to her at a timely basis. She is yelling
at you. So trust me, over the last four
years, I've been yelled at quite a bit
from her and stuff. So, thank you,
Heather, for everything that you have
done to continue uh for this community.
Um I have also have a deeply value for
working with industry partners. Um one
of the things that makes NISPAC industry
unique is that uh we can bring together
companies from different sizes,
different missions and different
perspective um and find a common ground
around challenges facing cleared
industry. Um but above all else, I do
want to thank and recognize what I
affectionately call my industry
NISP pack andou fam. Right. And just in
case you don't know what fam mean, this
family. Um, that group has meant the
most to me. Um, we have spent countless
hours together on calls and meetings,
working groups, conferences, and
sometimes in very spirited discussions
about issues uh that affect our
companies, our employees, and ultimately
our uh security mission. And if you've
never sat in a conference call with
Leonard and uh Charlie South, then you
will be in a treat if you sit next to
them two. So um it it's been great. We
didn't always agree and frankly I think
that's one of the strengths of this
organizations because in order to
protect the war fighter, we had to
challenge one another. We asked
difficult questions. We pushed for
clarity. We advocated for industry. And
more importantly, we did it with a
shared understanding that the objective
was never simply to make things easier
for industry. Our objective was to make
the national industrial security program
better and protect the war fighter.
Being a NISPAC member has never been
about representing someone's one
company, one sector or one individual's
perspective. It has been about listening
to industry and identifying common
concerns, finding constructive solutions
and making sure that those perspectives
are here by are heard by our government
partners. Um, but I leave this role in a
tremendous confidence because of the
people sitting around this particular
table and the relationships that have we
have built for government and industry.
To my government partners, thank you so
much for your partnership, your
professionalism, and your willingness to
listen to uh your to listen and your
commitment to the mission. To ISU,
thanks again for continue to create the
space where government and industry can
come together, have honesty
conversations, challenge one another,
and work towards solutions. To my
industry partners, thank you for your
trust for giving me an opportunity to
help carry out a collective voice of for
you. And to my NISPAC industry andou
fam, thank you. Thank you. Thank you for
everything. Serving alongside of you has
been one of the most rewarding
experience in my whole entire career.
Today does not mark the end of my
commitment to the mission or to the
people who make this community. I will
always be an advocate for a strong
government industry partnership, strong
national industrial security, and a
secure and resilient um defense
industrial base. We have indeed been
better together. Um Mr. Matt Roach, that
was one of our sayings back in the days
when he was our our our NISPAC DCSA rep.
We have been indeed better together as
we built relationships, created
dialogue, and helped move conversations
forward. But there is no time to relax
as there is so much more work to do. I'm
grateful, I'm proud, and I'm humbled to
have the opportunity to serve. And so
with that, we're going to go ahead and
start with today's meeting um updates
for the industry NISPAC and and continue
to work ahead. But before we get
started, I also would like to call my
good friend Jeff Spinager up here. Jeff,
can you please come up, please? Hurry
up, Jeff. Let's go. We got time.
>> Um,
this guy um has been a true advocate um
for industry
um for this particular group right here
uh NISPAC industry and
he has also been our voice as well. And
what I love about Jeff is the fact that
he keeps it real. Sometimes when we get
to these situations, we like to
sugarcoat some things. If you know Jeff,
he doesn't sugarcoat anything. He may
talk a little bit more, but he doesn't
sugarcoat anything. But but Jeff, al all
jokes aside, we truly appreciate and
value everything that you have done for
this community from the government side,
from the industry side, but really for
the war fighter. And we just want to say
thank you and we love you.
Um, I have to say this because um, I
wasn't going to give any shouts out to
them, but I have to because they've been
in my face for four years. There's a
couple of folks in DCSA that that's
always been there for us and they're in
the audience today. Um, Mr. Justin
Walsh, Mr. Dave Scott, Mr. Matt Kissman,
Mr. Booker Bland and the guy who
actually was the DCSA NISP pack uh
representative for years with Heather
Sims is Mr. Matthew Kitsman. So, thank
you very much for your duty for us.
And one of my favorites that's sitting
over there now, Miss Allison Rosilla has
is she has taken care of us. So, um, and
if there's anybody else that I I I
forgot out there, then, you know, you
have to excuse me. Um, um, so what we're
going to do is we're going to Can I flip
these slides, Hannah, for the updates?
Okay.
Oh,
I did forget about this. Um, we have
been busy o over the last few months.
I'll flip the slide here. Okay. We've
been busy over the last few months,
right? Um here are just some of the
thing places we've been at over the last
few minutes. Uh NDIA, NCMS, ISWIG, DCSA,
CAB, ODNI, SCSSE, and Doha. Those
are just some of the things that we've
been up to over the last few months. We
have been having a lot of
accomplishments, and I'm just going to
throw some out here, but you can add to
this list. ICD 705 initiative security
review rating scorecard self
self-certification open storage DCSA 140
amendments inside a threat ISL
classified infrastructure as a service
rewrite at the FCL handbook uh NISPAC
insider threat training for the program
officials C4 rewrite uh multiple
policies with ODNI NCSE the list can go
on that these fabulous individuals have
been doing right and sometimes you just
don't see it. Sometimes we just don't
talk about it because before we have
these conversations with you, we want to
make sure that we have that true
evidence, right? Because you all will
fact check us in a in a heartbeat and
that's what you're supposed to do. But
this group has been tremendous and I
just want to give this group of
individuals to include our MU a round of
applause. So,
so,
so with that, uh, as I said, Jane and I
will be coming off, um, starting one
October, we are in the midst of our
elections. Um, September 9th, um, we
have our last part of the elections. Um,
thank you, Greg Satler, uh, our former
NISPAC member, for running elections for
us. So, next week, Heather and Michael,
we'll send you over the list of
individuals. Once the the new members
are selected, those individuals will get
together and then they will vote on who
the next spokesperson is, right? And so,
we'll make sure the public un we'll make
sure that we pass that on to the public
when we have when we get the
opportunity.
Um, and so we're going to get right into
this. I'm going to turn it over to the
clearance working group chair which is
Miss Latoya Coleman from Mante.
>> Thank you.
>> No.
>> Can we get someone
need to go up there? Oh, no. They can
hear me now. I can hear myself now.
Okay. Thank you. And um Keith, I wasn't,
you know, very um I wasn't observant
enough to see how much you look like
Matt.
You were thinking You were thinking
Keith but said Matt.
>> No.
>> No. It's on here. It says Keith Miner
and Matt Kitsman.
>> Okay. All right. So, we'll go ahead and
go with the clearance working group. Um
so, as we close out the fiscal year
2026, I want to start by acknowledging
the progress we've had um and made
together. Industry remains fully
committed to our partnership with the
government to ensure a secure, agile,
and efficient vetting landscape.
However, as we look to the future, we
need to we need clarity and actionable
status updates in a few critical areas
to ensure we are operating as
effectively as possible. This by all
means is not all-encompassing, but we
are going to cover a few of those areas.
First, regarding the DCSA modernization
and operations, while we appreciate the
ongoing efforts to manage investigation
inventories and mitigate backlogs,
industry remains deeply concerned about
the rollout of Trusted Workforce 2.0.
know specifically phase three
implementation of wrapback fingerprint
collection. We are seeing many
individuals being asked to uh refing
despite having already completed
wrapback enrollment initiatives with
other CSAs. This duplication of effort
is mission hindering and uh and
administratively burdensome. We need to
identify the specific policy and
technical blockers preventing
fingerprints for wrapback from being
shared across the federal government. We
look forward to a solution that
streamlines this process rather than
adding unnecessary friction.
Additionally, we would appreciate
further status updates on the broader
roadmap for the um migration from MBIS
to DIS as well as clear timelines for
key initiatives like PQ.
Second, regarding uh OSDINS initiatives,
we've previously expressed concerns
regarding military departments SEI
processing timelines and advocated for a
review of the contributing factors. We
are encouraged by the Department of the
Air Force pilot program aimed at
reducing these processing times and we
appreciate Annie for um for working
through this and we are seeking an
update on that pilot and an
understanding of when industry can
expect to see those results.
Additionally, we request an update and
status of expected outcomes from the GAO
report and the MITER fast study. With
over 170 plus recommendations on the
table, industry needs a clear roadmap on
how to best prepare for these upcoming
changes.
Finally, regarding the ODNI oversight,
we have engaged with NCSC and continue
we have engaged with them and continue
to engage on policies concerning the the
submittal of applications for access to
classified information for contractor
personnel that was released June 2026.
And we look forward to further revisions
that incorporate the feedback uh we've
provided. So what we've done as a as a
result of this policy being released is
we've had um subsequent conversations
and meetings with NCSC and expressed
those concerns that we had with that
policy and the language that it
included. So uh NCSC has uh also
graciously agreed to review that policy
and um and take into consideration the
recommendations that we provided. So we
hope to see something from that very
soon. Furthermore, we are looking for a
status update on the comprehensive
overhaul of seed 4. We've provided
substantial comments this past July and
we are eager to understand the timeline
for adjudication of those comments and
the expected final outcome of the
directive. We are eager to hear your
updates on these items and we look
forward to the continued collaboration.
>> Uh thank you Heather. Let me put this on
record to get it right. Appreciate you,
Matthew Kitsman. Appreciate you, Mr.
Keith Miner. Also, two individuals that
are a few individuals that are regular
uh former NISP pack members. They always
come back. Mr. Quentyn Wilks, Miss Tracy
Durkin, and Mr. Derek Jones, and Mr.
Greg Satler. Truly appreciate you all
continued commitment after leaving the
Nispack. Sometimes people get on and go
away. You have been constant and steady.
It's like you've never went away. It's
like we have a ninth member, a 10th
member, and a left member. And that's
how we can get some things done. So,
I'll turn it over to one of our current
members, Mr. Lynard Moss from John
Hopkins, and he'll go over Oh, I'm
sorry. I'm turning it over to Jenny
Hardy. She's going to go over the Miss
Systems Working Group. Go ahead, Jenny.
>> Thank you, Ike. And um good morning. It
is always an honor to get to be here to
represent industry, but really, it's all
of us here sharing the same mission.
It's not about you, DCSA. It's not and
industry. It's about us collectively. Um
and and everything that we're we are
working toward in supporting a strong
resilient defense industrial base with
systems that are intuitive, stable and
let us work efficient efficiently. I
can't remember in my tenure a time where
we worked with the quickness that we are
working with now with the implementation
schedules of these systems and the rapid
changings the changes that we are
adapting to. So the points that I'm
speaking of today address just that um
first uh stabiliz stabilizing the
systems that will feed into NI2 and
better connecting common processes. NIT
will bring together tools for vetting
entity vetting in the 847 process.
Industry sees this as a chance to
address longstanding NIS challenges by
modernizing and connecting workflows to
reduce redundancies.
NCCS for the the DD254 workflow was
deployed just before we met the last
time and we continue to appreciate the
partnership that we have with DCSA in
the ongoing development of that system.
But that system illustrates an
opportunity as does the future uh
movement of NIS into NI2 to modernize
and connect the processes. Doing so
helps to enable trust from industry in
adopting new processes and getting users
to adopt these systems um uh across uh
all stakeholders DCSA, the government
and industry.
So we ask to stabilize these legacy
systems as they move into NI2 first.
Ensure the systems work so that we don't
have additional redundancies or work
that's required that costs all
stakeholders time and money. Design an
integrated model where related workflows
are connected and not fragmented.
In point two under um the INBIS and NI2
transparency in the last public meeting
we talked about road mapaps and we've
been talking about road maps for a while
specifically the request for operational
road maps that make sense to industry
that we can follow. I would like to
follow up on that and be a little bit
more specific. What we're looking for
are more capability schedules so that
when we have these rapid rollouts,
understanding when we're working with
the minimum viable product that goes
live, which features are in use day one,
which features are deferred to later
updates and timelines and delivery
milestones that we can plan against.
It's often in the details of this what's
live versus what's not that we have mass
confusion in industry and that erodess
the trust in the modernization of the
systems that we're all working toward
together.
Greater transparency into that will go a
long way in helping us all prepare and
reduce the burden on on all all
stakeholders and on DCSA who has to
answer questions and provide support and
feedback and training and followup.
This helps organizations prepare
earlier, coordinate across teams, manage
risk, and builds confidence in the
modernization path because people can
see how the journey will unfold.
For point three, we are asking for a
different way um for us to provide and
receive feedback through a 360 feedback
loop. We are all together. Again, it's
in us working behind the scenes on these
systems. What many people don't see is
that we're often in daily meetings
together. We have ad hoc meetings. We
have regularly scheduled meetings. And
in all of those, we are providing
industry asks on behalf of all
industries, big and small, companies.
What we would like to see um is a formal
feedback loop that gathers input from
the stakeholders. So industry,
government, DCSA all together alike
provides updates on how that feedback is
used and identifies ownership and
timelines for resolving high priority
issues. And one of the critical pieces
to the feedback loop is also
understanding what will not be available
for implementation, what cannot be done,
uh suggestions that industry is making
and why. So that we can understand and
be able to tell the story and help
communicate to industry.
So these asks won't slow the pace of
change. We're not slowing down here, but
they can help us stay focused
safeguarding uh national security and
supporting the defense industrial base.
We appreciate so much the ongoing
efforts and the partnerships that we
have uh industry to government. Thank
you for your time.
>> Thank you, Jenny. Um I'd be remiss if I
did not give shouts out to the person
who actually nominated me four years
ago. Without her, I probably would not
be here. And that's Miss Heather Sims um
from General Dynamic. She was the one
that was a a great pusher for me to do
this. And I I'm so grateful for that
because I've learned so much from her as
well. So, Miss Heather Sims, if you
online, thank you very much. All right,
turning this over to Mr. Leonard Moss um
from John Hopkins um who chairs the NSA
working group.
>> Thank you, Ike. And I just wanted to
first start out by
highlighting and thanking the fabulous
Jane Dinko, Ike Rivers, and Jeff Spager.
You three are amazing. Thank you for
your contributions to this nation. You
will not be forgotten, but you will be
missed. So, thank you all for your
contributions. So, I also want to thank
everybody in this room because many of
you were at Iswig last week. And I want
to thank all of you who supported Iswig.
For those of you who don't know, that
was my other world, you know, been the
chair of his wig for the last six years,
Latoya.
Um, and it's been a rem it's been a
remarkable remarkable um
run serving in that capacity chairing
because that's that's the opportunity we
have to partner with our intelligence
community, right? And when I get into my
update, one of the things I'm asking is
to strengthen the partnership, the Nissa
working group with the intelligence
community. So what I'm trying to do is
to leverage as I leave the ISWIC that um
partnership that we had with ISWIG with
the NISSA working group because I see a
tremendous opportunity and that's one of
the big asks that I took this role in
October of last year and since October
of last year we've been trying to
strengthen our partnership with the IC
community in the NISSA working space and
the reason this is so important is
because what the NISSA working group
does is we focus on classified systems
Right? And everybody can imagine um one
of the biggest challenges we have in
industry is getting our classified
systems accredited in a timely fashion.
Right? So, one of the things we're
trying to do is to say, well, let's look
for opportunities where we can build
some synergies like what we've done with
DCSA. And I and I foot stomp DCSA a lot
and I get beat down for it because it's
the truth. But we have a tremendous
partnership with DCSA and I have to, you
know, I acknowledge him, but I have to
give another shout out to Mr. Dave Scott
because Dave Scott served in the role of
leading this organization where we built
this partnership where it really works.
And I and I really want to say that. I
want to talk about something that's
working. I'm up here to try and find
some solutions, right? And I think
that's what we're all here for. We want
to find solutions. We're not here to
beat up on anybody. We're not here to
complain and cuz, you know, that's just
not going to get us anywhere. We want to
find some solutions. So, I say when you
got something that's working, why not
model it, right? So, the partnership
that we have with DCSA, we're trying to
model that. And that's the first bullet
I have here. We've been trying to
strengthen this engagement with the IC.
And we did have a wonderful meeting with
OD and II and NCSC a few weeks ago and
they offered to help in this regard and
we're going to take them up on that. Um
so but that's the first ask I have is
for all of you all of all of you um CSAs
we need your partnership to strengthen
that relationship in the NISA working
space. Um one of the things we're trying
to do is just begin with metrics right
we get some great metrics with DCSA
where we can hold each other
accountable. We want to do the same
thing with our IC partners so that we
can again not talk past each other
because one when you talk to them I can
give you a great example when we have
the ISW conference um we'll have a
wonderful panel all the IC leaders and
they're amazing and I really appreciate
them for showing up for us but sometimes
their numbers don't match our numbers
right and so what we want to do is to
make sure that when we when we talk
numbers we're talking from beginning to
end because at the end of the day we're
all here for the mission Right. And so
if we're saying it take us, I don't
know, a year to get a CSA approved and
you're saying it takes three weeks,
that's a big disconnect. So we want to
say, well, where what if all those
months where we have a disconnect? So
what we want to do is let's have a
conversation where we can really get to
what is really causing the challenge and
find some solutions. So that's that's my
first ask is really to help us get
metrics in the area of the Nissa space
specifically the classified systems with
all of our IC partners and all of our
other CSA partners. The other area I
wanted to talk to real quickly is on the
CSFC front. I want to again give a shout
out to Jeff Spiner and to Dave Scott and
to DCSA because at the last public
meeting we identified a challenge that
we were having with the CSFC and
industry and that is you know a lot of
our folks are getting these devices but
there's not a whole lot of guidance. So
our concern was national security and
protecting the information that they're
they're processing on these systems that
they can have in their car in their
hotel and but we couldn't have them in
our facilities. So I, you know, Jeff and
and Dave after the last NDIA meeting,
they they got together and they put out
a voice of industry article on this
particular topic and they and they
allowed us to have them in our spec in
our spaces, which is great. So that's a
great step forward, but now we need to
go to the next step and provide guidance
because our folks are saying, well, now
what does that mean? Can I bring them
into closed areas? Can I bring them into
this space? Can I bring them into that
space? So, one of one of the things
we're doing within this working group is
we put together a white paper and some
recommendations and we're working with
my good friend Mr. Bond and the
wonderful Tracy Brown and we're bringing
that to them to first start with DCSA
and say, you know, how do we work with
them in this space? But then we need to
go back to our partners who are actually
issuing these devices to say next steps.
And thank you Annie for stepping up.
Annie was one of the first entities that
agreed to work with us to help us come
up with some guidance and some
guidelines around this because we we
love these devices, don't get me wrong,
the ones saying take them away because
they're amazing. But one of the things
we want to do is say, you know, we could
probably and I'm going to get in trouble
for saying this. We could probably save
a lot of money, right, if we used more
of these devices. So having said that
you know I understand you know we have
our process for cypernnet but we can
save a lot of money with these devices.
So we really want to look at that and
say you know what's the pragmatic real
solution for the government and for
industry. I think you know there's a
happy medium there. So we want to work
that's that's the next step but we'll
follow up on you know guidelines and
guidance after the voice of industry
because a lot of folks appreciated the
voice of industry but after that voice
of industry I got a bunch of emails and
a bunch of calls and saying okay now
what Leonard what's what's the next step
so I appreciate you all for getting that
out for us and then the next thing we
wanted to talk about real quickly was um
artificial intelligence this is this is
taking uh and I want to I want to give a
shout out to my good friend Larry Clark
who's up there in the booth operating
and making us all look good. Thank you,
Larry. Um, Larry has um been part
working with his leadership to try and
stand up an um sub team to focus on AI
and I and I hope that you know this gets
moved sooner than later. And the reason
I say that is because you know AI is
here and what and I know half of you
probably wrote half your speeches with
AI. So we all use it, right? And and and
and you'd be foolish if you didn't use
it because it's a wonderful wonderful
tool. But there's also a lot of risk
that comes with AI, right? And as
security professionals, we have to be
mindful that in order for us to enable
the mission, we need to get ahead of
this risk. So that's one of the things
that Larry's sub team is going to try
and focus on. Industry has put together
some brilliant folks who do AI for a
living and we're ready to support this
initiative that um Larry's standing up.
We've had, I think, three, two or three
meetings so far and um I think we're off
to a great start, but I really would
like to see that move forward, but I
think um Larry's in the process of
getting it approved through his
leadership. So, I really encourage you
all to support that initiative. Okay,
real quick on DCSA. Again, I can't I
can't I can't um sing their praises
enough, but we really did make great
progress since I've been here in
October. The the primary focus has been
the DAG, right? Right. The DAG was
released October of 2025 and I became a
NISPback member, industry member um
October 2025. So, all of our focus was
on the DAG. We had lots and lots and
lots of feedback for DCSA. And again,
thank you DCSA for willingly taking our
feedback. Now, it's been a year now and
we still have some of those feedback,
but we haven't reconciled, but the
majority of it has been reconciled. And
and I tell you, Tracy don't mess around.
you know, you give something to Tracy
Brown, she's gonna get you an answer.
So, Tracy, wherever you are, shout out.
Um, but Tracy, don't mess around. She's
she gets us some answers. And we may not
always agree, but she will get you some
answers. So, um, we still have a few
more items that we haven't reconciled
yet, but we're getting close on the DAG.
And then the the big um elephant in the
room for us is Rev Five, right? Let's
just let's just be honest and
straightforward. We were all thrown for
a loop with Refi because we were told
Refi was going to be published and and
and implemented October 1st, right? And
that all of the summer industry was
going to work with DCSA to, you know,
address concerns and challenges. And
then we we got a loop in July and said,
"Hey, Leonard, you guys, we're going
have to do this in two weeks." The voice
from on high said this has to be
implemented now. So, it was actually
implemented July 31st and we're all, you
know, trying to make sure we can catch
up and we have given a lot of feedback
again and most of that feedback DCSA has
responded but we haven't had a chance to
discuss it uh because we had a meeting
that was going to happen before the
public meeting that we had to
reschedule. So, we're going to regroup
in September, later this this month, and
address the feedback because we what we
have to do is even though we had this
expedited implementation of Rev Five, we
have to still make sure that, you know,
we take the concerns of industry and the
challenges, you know, seriously and make
sure that even though it's already been
implemented, you know, if you go to
EMAs, it's Rev Five now. So, you can't
do any more Rev four. But the great
thing about it was that they have this
wonderful person at DCSA called Lucy
Rodriguez. I don't know if y'all know
her, but you should get to know Lucy
Rodriguez. She's awesome. She did these
demos for us and she did this training
for us and I'm telling you, it's yman.
It's phenomenal and I want her to do
more of it. I know she's busy, but
because of the expedited, you know,
implementation and I tried to set up
some more training with ISC, but you
know, we weren't able to make that
happen, but um Mr. Von did arrange some
additional training for us, but I think
we need more because there's a lot of
small companies out there who are not
able to participate in some of those
those demos and training and they're
going to need some help. So, I just
encourage you to um conduct some more of
those trainings where you can. I know
there's I think there's one more
scheduled in October, but I it's it's a
lot of folks who are impacted by this.
And again, we got a two-eek notice that
it was going to be implemented July 31st
and it was supposed to be October 1st.
So, we got to take that into
consideration and consider the impact on
all of those especially those small
companies that have to um operate within
this environment. And then the last
thing I have is to just ask everyone if
you have these CSFC
um items and you have info and
recommendations, please send those my
way because we're going to be sending
that white paper that we put together on
CSFC starting with DCSA, but then we're
going to send it to all of our partners
and hopefully we can work together to
move this forward in the right
direction. I believe that's all I got
for you. Oh, I'm sorry, one more Ike. We
wanted to also just remind you that we
brought up at the last meeting this
challenge that we're having with
destruction of SAP IT material and this
is a problem because we have just one
vendor and and you know we have to find
solutions that's going to work for all
of industry. So, we have some
suggestions, we have some
recommendations. Again, we love our
white papers. We wrote another white
paper and we would like to get some
support on implementing some of these
cost-effective solutions because again,
this impacts all of you and your
mission. Thank you for your time.
>> All right, we turn it over to uh uh Mr.
Chris Stoki from BAE. He is the chair of
the insider threat working group.
>> Thanks. An update from the insider
threat working group. We have a a couple
subworking groups as you can see on the
slide working a couple issues that that
are impacting industry. The first one is
insider threat for employees that sit at
customer sites. This is a gap uh a gap
the group identified that impacts a good
chunk of the div. So just think of
sending an employee that go sits at a
customer site and oftent time we don't
hear anything about an employee. There
may be bad things happening and they're
not telling us about it. Sometimes that
employee is just sent back without
giving a reason. Uh the challenging part
is often our government partners will
say, "I would love to tell you, but I
can't. Our hands are tied because of
law, policy, something or another." Uh
it's a difficult position to be in and
we need to get better on it. I'm going
to touch touch on that a bit more when I
get to my my last comment there or my
last bullet. The other group is uh
they're focusing on mitigating threats
from fraudulent applicants. The good
news is this group worked really hard
and they put together uh some great
training material and if it's not up
today, it'll be up shortly on the NISPAC
page on the NCMS site. So, if you get a
few minutes, I recommend checking that
out. Some great pointers on how how to
deal with this potential threat. Uh, as
it says on the slide, we continue to
have a good relationship with DCSA. We
really appreciate the ability to review
the insider threat ISL that came out. If
you haven't seen it, recommend reading
it. Uh, it just put uh in place the
requirements that were put out by DCSA
last year. Also appreciate DCSA updating
the ISL to include a link to the NISPAC
develop training. If you looked at the
first version of the ISL and you tried
the link, it may not work. They went
back and they corrected it. So, so
please check that out. Well, I also
applaud DCSA for taking action starting.
We understand why they released the
initial guidance in a BOI, but
eventually following up and actually
putting it in an ISL is something that
industry really appreciates because it
allows us to go to an official source
for information. Lastly, uh like Leonard
said, we're trying to increase our
collaboration with the IC. Um we've
taken some steps to do that. Just
recently we had our meeting at OD and
specifically NCSC. They're really open
to the idea. Last week at at Leonard's
conference iswig met with many of the
agencies. They are all open to the idea
and that's great because it's really
important uh for all insider threat
programs to have good information
sharing. And related to that and again
this ties to the the comment I first
brought up with employees that sit at
customer sites. Uh a few months ago,
maybe spring, we saw an early draft. It
was not widely circulated of a memo
called sharing covered insider threat
information pertaining to contract
employees. Uh specifically, it created
steps that the government could take
that would allow them allow them not
require them, allow them to share
insider threat information with
industry. Uh we provided comment on
that. We've not seen an updated memo on
that. Um, while certainly the memo
didn't give us all we asked for, rarely
are we so lucky, it was a step in the
right direction and we want to continue
that momentum. So, we ask OD and I to
stay on that. We talked with NCSC a few
weeks ago on that and we're looking
forward to receiving an update on that.
Thank you.
>> Thanks, Chris. I turn it over now to uh
Jane Dinkle, um, Lhee Martin, the entity
vetting working group chair.
>> Is this on?
>> It is. Okay.
Um, I'm really pleased to announce some
significant projects that we're been
able to bring to a close recently. Even
within the last two weeks since these
slides were provided to Heather, uh,
there's been some additional progress
that's taken place. So, I'm really
pleased to say that the four years I've
spent on the NISPAC, we actually
accomplished something.
Thank you. Thank you. So, first of all,
um the FCL orientation handbook, we
worked very closely with DCSA on
updating that document. Uh and it is
published, it is published on the DCSA
website and available for industry to
use. It is incorporated with 10 job aids
that have also been updated uh that are
also posted there on the DCSA website.
The we also worked on a project called
the electronic control plan and the
intent of that was to uh those
facilities that are under folky that are
required to have an electronic control
plan uh were able to uh combine their
CMMC certification plan to meet some of
those ECP requirements. So rather than
duplicating that document, if a facility
had achieved level two CMMC
certification, they could use that or
kind of use that as an appendix uh to
meet those ECP requirements. Now, with
the CMMC program being reassessed,
the um the ECP template that we produced
is uh kind of on pause till we see
what's going to happen uh with the ECMMC
program going forward, but that is
available and ready to launch once that
reassessment is uh completed.
Uh also we have been working on a
government security committee desktop
reference guide and again this is for
facilities that are under FOI mitigation
instruments and they have a government
security committee with outside
directors or proxy holders and and this
is really a compilation of guidance
templates uh and references for members
of that government security committee to
use uh to help them implement ment their
duties. So, it tells them things like um
what's required during an annual
meeting, what to expect during an annual
meeting, what they need to be
accomplishing during their quarterly
meetings, if they're reviewing a visit
request, what kind of things must be
incorporated into that visit request. So
it really simplifies and gives a very
practical application guide for uh
committee security government security
committee members especially those that
are new to that role. So it leaves much
uh less to guess work for them. So I'm
very very pleased to say that that uh
tool is ready to be launched. We're
going to be working on implementing that
out to industry. So you'll probably see
that within the next week or so.
the NDAA847
clause. Um that clause public comment
period has closed. Um hopefully you had
an opportunity submit to submit some
comments. Those comments have been
reviewed and adjudicated and there will
be a response that will be posted back
on the Federal Register where those uh
comments were originally submitted. So
th those comments will be or responses
to those comments will be will be posted
there. Going forward, there will be a
public notice once the um clause has
been officially approved and there will
be um a six-month implementation period.
DCSA, I just spoke with Matthew Kitsman
yesterday and their expected
implementation date of execution of day
one will probably be March one. So, you
can put that on your calendar. And
again, keep in mind that that has to be
quoted in that clause has to be quoted
in your contract. So it's not just
applicable across the board, but it has
to be uh quoted in your contract to be
applicable.
And then finally, the Turbo FCL project
that is still in beta testing uh through
the DARPA website and uh through
December. Its use is voluntary. It's not
required for you to use it. Uh but it
does it can help you prepare your FCL
package for DCSA to make sure that it is
more complete and finalized uh when you
go to submit that to DCSA.
And I would not I would be remiss in
exiting my swan song without
acknowledging the wonderful folks that I
have worked with and partnered with both
within industry and government. uh
they've made the last four years just a
um it's just an amazing uh experience
for me. Uh I consider them friends and I
especially want to thank Ike Rivers for
his leadership uh for the last two years
as our spokesperson. He refers to all of
us as fam or family and we really feel
like that toward each other and we
really uh like working with each other
and and work with each other like a
family and I also want to acknowledge
and express my appreciation to the
government for their partnership. I'm a
firm believer that both industry and
government want to do the right thing.
We just need to know what that is. We
want
we really want to do the right thing. We
want to meet in the middle. We want to
partner with each other and make sure
that you know our end goal is the same
which is the protection of national
security. So I am extremely grateful for
the four years that I got to serve on
the NISPAC as an industry member and I'm
I'm very humbled by any acknowledgement
that is given to any contribution that
I've made. And I just want to say thank
you to all of you for your time.
>> Appreciate you, Jenny.
>> Okay, we're going to turn it over.
Heather, I think my slide is not my
thing is not working now.
You take care of it. Okay. Um, uh, Miss
Kathy Andrews, I think she's online
here. Um, she's from North of Grumman.
She is the physical security working
room chair. Um Kathy had um some um
conflict far as work. She had some much
needed stuff she had to be um at her
duty uh section to take care of. Um but
she is online. Um Kathy, want to turn it
over to you. Can can I go back here?
Hold on. All right, Kathy.
>> Thank you, Ike, and good morning
everybody. My apologies for not being
able to be with you in person. Um, as
many of you guys know, ICD75 has been at
the forefront of our priorities over the
past few years. And while the
requirements are demanding, um, we have
also seen a meaningful increase in
government industry collaboration as we
work to understand and address the,
excuse me, the real world implementation
challenges behind the policy. I think
we've made some um substantial progress
recently due to some site visits that
have been especially valuable allowing
us and industry to demonstrate the
difficulties of implementing 705
especially in those legacy facilities
and the practical constraints our
operators and engineers navigate every
day with the recent recision of the 2025
memo establishing facility upgrade
deadlines followed closely thereafter by
ODNI's director directive to maintain
operations and currently accredited
skiffs. We believe that policy decisions
are starting to be appropriately
balanced um balancing the speed to the
war fighter as well as ongoing cost
pressures. So, thank you very much for
for recognizing this.
Next slide, please. Despite this
positive progress, industry continues to
remain concerned about the inconsistent
implementation of policies. We
appreciate the opportunity to continue
to engage with both NCSC and the
Department of War at all levels to
achieve a balanced approach. I believe
we can get there, but much like my
colleagues have mentioned, it's going to
take the maintenance of the continued
transparency and collaboration that has
has increased so much um in in the
coming months. So, I I thank everybody
for for their efforts and look forward
to taking us to the next level and
reporting that at our next public
meeting.
>> Uh, thank you, Kathy. Uh, Kathy can't
see him, but uh, Mr. Adrien Shepard is
in here from DIA. Adrian, um, industry
NISPAC, thanks you so much. I know you
get pulled so many different places. Um,
but your partnership um, from a DAI
perspective and from a personal
perspective to industry um, is so
invaluable and so thank you so much for
always being here. We know it's tough,
but we thank you for that. I turn it
over to Mr. Charlie S. Um, he is the
policy working group chair.
>> Thank you, Mike. Uh,
couple of things that we're tracking.
Uh, first that's not on the slide, but
is important. We are following the FY27
NDAA and IAA uh, draft legislation and
reporting on industry impacts of that.
Uh, one of our key areas that we've been
working with, uh, ISU and our government
partners on is guidance related to all
of the executive orders that have come
out uh, since 2025. Uh, there have been
hundreds of executive orders and many of
those executive orders directly impact
uh, cleared industry and most companies
supporting the US government. Um, I'm
pleased uh that we're hearing progress
uh where uh through ISU's leadership and
through DO, it sounds like we're going
to be getting some uh some helpful
guidance from the US government at large
on how these executive orders impact
cleared industry and industry more
broadly. And we really appreciate the
effort that's gone into that. So, thank
you for for the hard work and the
crossgovernment coordination that's led
to that. Um,
uh, industry continues Oh, can you go
back to the Thanks. Industry continues
to, uh, look at the CMMC pause from
DODW. Uh, we applaud that pause. We
appreciate uh, uh, the reviews that have
gone along with that and we have
contributed our recommendations for
future implementation. So thank you for
the work on that. Uh and then um lastly
uh the government studies update. uh
we've been working with ISU and through
the policy working group to explore uh
an AI enabled review of the NISP and
we've completed the document collection
uh uh we have a library of information
of past uh NISP documents and we also
interviewed uh the original NISP
industry members for their insights on
why the NISP was established you know
from an industry perspective and what
was different today than was from there.
So, our next steps are reviewing that
information and creating AI enabled but
human-led
uh reviews of that and coming up with
some recommendations. So, with that,
I'll turn it back over to Ike. Thank
you.
>> Oh, thank you. We'll move the slides
around.
>> Okay. Um that slide is there. Um um I
think that was Lisa. Um where's Lisa at?
Does everybody know Lisa Rei? All right.
So, she really is the backbone of Miss
PAC industry and theus because she is
the coordinator and she's the one that
puts all the meetings together and all
the slides together. So, Lisa, none of
the things that we do is not possible
without you. So, thank you so much for
your dedication with this. So, thank
you.
Um,
uh, I do have an ask. So, Heather, um,
she talked about, um,
a lot of the things that were still
open, right, industry, in this pack and
we, we we
need some help with that. I don't think
we can continue to go meeting after
meeting and without getting some of
these closed. So, whatever industry
NISPAC can do to help get some of these
items closed or some clarifications,
we are here, right? And and we need to
do that. It really be nice to go down
that list at the next public meeting and
says, "Hey, we have no open items." Now,
mind you, the NIS pack has been around
since 1993. There's always been open
items, but let's see if we can kind of
knock some of those open items off the
list. that is extremely important for
national security but it's really
important for the war fighter. So that
would be my personal acts if we can try
to get at that and again industry NISPAC
is here uh to help with that and that is
all that we have from an industry NISPAC
perspective.
>> Thank you Ike. Any uh any questions for
Nispack Industry?
hearing none, we'll turn it over to
Heather.
>> Thank you, sir.
Next, we have Mr. Jeffrey Spininger, the
director of the information and
acquisition protection directorate for
the office of the under secretary of war
for intelligence and security, who will
give the update on behalf of the
department of war as the NISP executive
agent. Jack.
All right. Well, good morning. Um it's a
bit bigger crowd than the last one. It
was just really um uh encouraging
because uh when we were doing these
things remotely um it's amazing what you
could start talking about without really
any fear of being able to read the room
or what people are thinking about what
you say. Uh which is maybe where some of
the cander comes from. Uh but I I'd like
to start out by uh just sort of joining
the the chorus of uh and and and some of
the thank yous. uh you know first and
foremost um you know for the you know
the the kind remarks that were made uh
you know regarding my tenure I
appreciate it very much uh this really
is kind of a labor of love uh I used to
be in that in the in the audience uh you
know with my boss and I really did have
aspirations to do exactly uh what I'm
doing right now and uh and it's um it's
going to sound a little trit but it's
entirely true of a dream come true to be
able to do this because it's very high
consequence stuff um uh and God help us
and God help me, but I love it. So,
thank you for that. Uh, but none of that
is capable uh you're not able to get
much done uh without just just oceans
and oceans of collaboration. Um uh and
occasional nashing of the teeth. Um I
was going to try to make my ringtone
play for what my ringtone is when Ike
calls me. And um and then I decide maybe
I shouldn't do that because it needs to
stay rated uh PG I think. And so uh but
uh you know all all kidding aside you
know it's how how uh how beneficial is
it that you know one we you know have
the ability that we can communicate and
it's it's birectional and I won't ask
him what my ringtone is. Um uh but it's
birectional because it's necessary. It's
incredibly important. Um and uh the
opportunity for cander is really kind of
built on a foundation of of trust. Uh I
promise you there's not a lot of
happiness engineering going on. And I
think if you were keeping score the
number of times where the answer isn't
like it's not the pristine answer but it
comes from hey this is what we can do.
This is what reality looks like. There's
common understanding and from that
common understanding then we can get to
uh what he frankly what Ike what you
said so uh so eloquently you know
related to you know our priority which
is uh which is on the war fighter and if
it's not that then really you don't have
any business being here. So, uh, sorry,
I want to say thank you, uh, to to as a
spokesperson, but it's a it's a team
sport, right? He can't do any of it on
his own. And the fantastic cast that,
you know, that is represented by the
folks that are here in industry today.
And all of those that have been in the
seat before have been, uh, you know,
fantastic partners. So many of them are
in the room today, which is really
great. Um, and that cander has been kind
of a consistent theme. Um, and that's
how we're able to get stuff done. That
was a wonderful laundry list. That might
conclude all my remarks that that Ike
laid out there, but those are real
accomplishments. Uh, you know, the work
continues. Uh, you know, and again, as
you said, the I'm sure there were
dooouts in 1993. Uh, some hopefully
there not any dou from 1993. That'd be
bad. But, uh, but I think I think it's
really great and and Jane, as a
departing member, I just want to
particularly call out. So, you know, you
know, the the partnership here and some
real controversial issues uh, you know,
to put points on the board we like to
talk about here is uh, is really great.
if if if I may ask for a round of
applause for for all of these folks.
Uh and and so um we don't do anything
alone. Uh and you know, sometimes it it
does feel a little bit lonely uh in a in
a building that has 30,000 people that
come to work in it every day. Um uh but
this can be kind of isolating work. It's
it's it's very difficult and so
frequently uh you know um uh you know
the the building can kind of feel like
it's kind of falling in on us. But we
have really uh you know great team
within I in in INS and so you all get to
see me kind of a lot but the fact of the
matter is that you know we have really
great team right I many of you all know
I want to introduce so Patrick Harris is
here and Jamie Long in the audience we
stole Matt Roach um uh from uh from DCSA
we're going to return them at some point
I'm not sure how they feel about that
but the uh but we've been happy to have
them and so uh you know they'll continue
to do uh you know to to uh you know to
to do the work uh that that we continue
in support of the the you know the the
importance of the industrial security
program. But I'm really happy to have uh
you know kind of my my my battle buddy
uh in the audience today. Right. So and
also right now my boss just by the way
so just please be nice. Uh but you know
Jill Baker uh is just sort of you know I
mean you know everyone knows her uh is
fantastic but we get into some pretty
weighty stuff and um and then
occasionally a little bit of bourbon.
I realize this is on the record, but it
doesn't matter now. So, um, and none
this morning. I should clear clarify,
but yeah, not yet. So, uh, but yeah, I'm
really happy to have have, uh, you know,
Jill here. And so, we don't want to get
inside any decision loops within the
department. Um, but you know, Jill is,
uh, you know, just been steady at WINA
across the board, I would say. And, uh,
and I'm really happy to have her here
today, uh, as well. So, thank thanks a
lot, Jill, for making some time today
to, uh, to to be here. Um, before I dive
in, just a couple things I think might
be a little bit easier. Of course, I
have some good jokes and and uh just as
if on Q, right, since there've been 76
of them. I was a little concerned
because I'm pretty sure Perry's been
here for like 74 of the public meetings
and he showed up and it was good because
otherwise I was going to have to talk
about how old Miner is and you know, but
it's it's just it kind of speaks for
itself, right? So, and and I can see how
they confuse you and Matt, right? They
do look a lot alike and so although the
glare off your like it's just perfect
right now. So, uh, but yeah, really
happy to have, uh, you know, Perry here
as well, right? So, we've known each
other a long time and, um, and, uh, glad
glad to see you here today as well. Um,
so with that, uh, before I kind of go in
just just because, uh, you know, I
appreciate the the uh the, um, the the
the updates that came from all of the,
uh, various working groups. But just
sort of in no particular order be uh I
just because I wrote it at the top of my
notes u I was going to ask Annie if you
wanted just to provide a brief update on
the access uh work and partnership with
air force.
>> Yes. Thank you Jeff. So the department
of the air force recognizes the
challenges that industry is experiencing
when it comes to SEIN and doctrinations.
Um but not just that also skip
accreditation timelines system access
all things to get your personnel that
need access to SEI to work as quickly as
possible. We also experienced that
somewhat on the government side and so
Air Force A2 specifically with the NAF
has worked with INS on a pilot an
automation pilot right now which is
tenatively right now called skip
workflow tool but it's more than just
skips like I said it's SEIN docs skip
accreditation paperwork and uh
classified system activities as well the
goal is really to modernize and automate
what we within that process where the
daff has touch points to streamline it
and improve the timelines as well as
improve the quality of of paperwork that
goes between different offices. We are
in a stage right now where we're
collaborating internally within the
department of the air force including
the space force as well as INS and DIA.
So there's not much there not many
specifics to share right now in the
public forum. We would do have a
tenative initial deployment uh within
FY27, but of course that can fluctuate
based off of government shutdowns,
possible furlows, funding issues, new
priorities,
personnel
going to greener pastures,
etc.
>> Locusts,
>> right?
>> But we are absolutely committed to
making sure that we include industry in
those efforts so that whatever is
developed does work for you. it does not
detract from any efforts that DIA is
working on and that we have a system
that works which Jenny you spoke earlier
about DCSA systems the same applies to
ours we don't want to be duplicative we
just wanted to make things better so we
will continue to p provide updates and
make sure industry is an active member
in these conversations
>> thank you um Annie yeah uh I just yeah
just to piggyback on that one just a
little bit as we we kind of scroll
scroll through these things, you know,
uh, you know, this problem surfaced for
us. We we've, you know, obviously we've
all known about it for quite some time,
right? But to me, I like a little bit
of, you know, show and tell about the
how NISPAC works, right? So, being able
to kind of surface these issues with
some data and put some real, you know,
teeth behind it. Uh, you know, that's
that's very valuable for us from, uh,
you know, within the policy slog, uh,
but as a function of active what I
describe as active oversight. And so
being able to continue to note that, you
know, there's, you know, we're taking
some initiative here. We're trying to
build some efficiency in it. I I would
be remiss though if I um I don't want to
be accused of not being candid uh in my
last one of these things. So their goal
isn't just to try to be better at a bad
process, right? So let's be very crystal
clear about that. And so we want to
continue to shine attention on it. And
so the first of probably what will end
up being several asks here for both the
working group uh NISPAC as a whole but
uh and and reminder right we just heard
a lot from industry but NISPAC is is
highly reliant and maybe a little bit
more so on the government themselves
because it's all of our policies right
so uh you know that that uh that are the
tension that we're trying to address. no
guarantees that we're going to change
it, but at the very least we need to
understand it a little bit more and to
see what the value is in a million hours
of folks, you know, reading the
newspaper while they wait for
administrative process leading to
access, right? So, and the and that's
all after eligibility was established.
And so we need to continue to surface
this and I can tell you that it creates
unsatisfying looks on the faces of
seniors in the department and we all
work for the same guy when we get to the
top of the food chain. But we have to be
able to make it make sense to understand
why the best thing that we can do today
is to is to drive just two t tons of
efficiency related to eligibility.
something that actually don't think
anybody mentioned as a function of all
the updates which is just an amazing uh
you know turn of uh you know a show of
progress uh you know with with chiefly
aimed at DCSA which is really quite
remarkable and it happened and we didn't
even say anything about it which is
really great but as we turn the
conversation and the access side of it
we have to be grounded in what our
baseline in you know way contract terms
are today right so the contract begins
when eligibility is established right
that's when the you the till begins to
run as it were. And so you will have no
stronger defender certainly from uh you
know me and my office and the folks that
come beyond to be able to defend and
understand the value in that delta if it
makes sense. And so the blunt truth of
it is and just the first that we would
ask to continue to to to hold us to task
here on this issue is to really
understand what that looks like. And so
with the shout out to the initiative of
the air force, nobody asks the air force
or the you know the command that's doing
this work to to undertake this right
they took it on their own initiative.
That's fantastic. The thing that will
continue to move it forward and maybe
create real options to use the word
efficient uh in the way it's actually
defined um is is more attention on it.
So that's kind of a continuing ask here
as this continues to report out because
it's a hugely consequential issue. All
the conversation is about SEI, but we
could put the SAP moniker on the same
issue and we probably have maybe even a
more stark uh problem within the
department and it's a huge cost. So uh
so thank you for the continued attention
on it uh Latoya and team uh and the
continuing work of Air Force and so uh I
love uh asking for people to do work
that I don't won't have any
responsibility for. Uh and I I hope that
you will ask Annie specifically uh about
this at the next update. Um, so you're
welcome. Right. So, uh, we were passing
notes earlier. She didn't see that part
in there. So, um, so anyway, um, so just
to just wanted to jump on that one, uh,
first and foremost, uh, I really
appreciate the the the comments made
several several, uh, industry members,
uh, you know, mentioned the GAO and the
fast, right? These are tools for the
department, right? So, we uh, you know,
we we didn't ask the GAO, I don't know
if the go is listening, but we're really
happy that you did it. Um, that's on the
record, right? So, um, I got to try to
erase that whole bourbon thing from
earlier, but the, uh, but we did ask for
the fast, right? We, we did that. We
were very deliberate, uh, in the fast
and some other things that we'll talk
about, you know, a little bit deeper in
my remarks because these became just
incredible opportunities. And, you know,
for the work that Charlie and uh, and
and uh, and some of the really gray
beards are thinking about as it relates
to the origin stories of the NIS, but
maybe what the future needs to look like
from a policy perspective. Um data needs
to tell the story and uh my experience
here and and uh and in in in prior
positions tells me that the most
valuable data that relates to industrial
security probably ought to come from
industry. Um thank you that that that
was really profound set of revelation
there. Um and you know so we when we
when we commissioned fast right we
really aimed it out in into industry and
right you've heard us kind of you know
extol the the the scope of it and I'm
glad to see our MITER partners here uh
and uh you know for the great work but
as Latoya said and maybe a few others
like the whole goal wasn't just to like
hey a new study like we can put it next
to the old study and then in 10 years
from now we can use those to make
another study that wasn't the whole
purpose right we tried to be a little
bit more actionoriented and we did ask
for Hey, there's recommendations and uh
you know there's litany of findings and
then and then recommendations and
there's no chance in heck that we're
going to deliver on 76 recommendations
and you know the answer at the other end
on the other hand those some of those as
we continue to examine them and I will
say we got top of the food chain
attention on it right so uh the deputy
under secretary in particular has taken
a very keen interest uh you know in the
in the um in the mother of all poems
I'll call it uh that we've built out of
this thing uh to really try to hold
ourselves to some degree of of
accountability to lay out options,
right? So, that's ultimately what we're
really fighting for here. Uh and um and
I and I think we're delivering on that,
but the continuing attention and the uh
is is necessary. Uh again, um you know,
we we should be prepared um certainly in
the beginning of the year, uh to be able
to provide a bit of a more um
substantive update kind of across those
particularly a handful of the those that
are prioritized and which are reflected
in in in some of the remarks. I think we
could do a little bit better job of
being able to align some of what the
working groups are looking at to those
things that that have connective tissue
to the uh to the study itself. that's
very beneficial for this audience and
for the, you know, for the the program
as a whole, but I think maybe more
importantly, it'll continue to help and
make it make sense to the leadership
that we're really trying to influence as
it relates to some of the decisions that
we're we're we're pushing after. Um,
with that, I do want to um, you know,
call out, right? So, one of the open
items that that kind of remains and I
appreciate it, Heather, uh, and, you
know, to kind of pushing through, but
the issue related to small business is
really quite critical. uh many hopefully
uh you know many of you saw you know the
secretary himself spoke about the value
and the and the the just the incredible
importance uh you know of the innovation
side of things right those smalls we
want to make sure the NISP is is
incredibly important national security
uh you know and and all the protections
that we're aiming at are incredibly
important but if we we create a scenario
where it appears that there are barriers
that we're creating decisions uh you
know for our leaders that that we're not
giving them good options here and
securities about, you know, among other
things about creating creating those
options. We have a real disconnect as it
relates to some small business rules and
some statute that were laid in now
several years ago and and uh and some
disconnects with uh within the CFR
itself. We've talked about it a long
time. I'm a little disappointed that I'm
not going to be able to see some option
or resolution of that during my tenure.
And uh and I'm gonna have to chalk that
one up in the last column. Uh because
this was a big issue before. It's not
getting smaller. And so um it's not
something that the department can solve.
We can continue to call it out. But as
the purveyors of the 2004 uh we really
need to first step call a meeting. Let's
get the Small Business Administration.
We'll certainly get the the the smart
people from the department uh and see if
we can't lay out some options. But I do
think um I can't really think of
anything more consequential right now uh
that we could be doing uh that really
kind of gets after what is um a very uh
prominent theme within the national
defense strategy. So um okay that's the
tough stuff. Okay. Um so we uh couple
things just on the on the policy front
here and as I'll continue to try to map
these to some of the the updates. Right.
So um you know volume one thank you to
very much to NISPAC uh industry and to
uh to anybody who helped to participate
right but the reissuance of volume one
is it's a little bit behind the clock uh
we've been banging on a lot of policy um
uh within uh within our portfolio for
quite some time and so um and we were
intentionally prioritize this a little
bit behind some of the others that have
you know a connection to industry
particularly special access um but it's
out now we were able to uh you know to
really you know, appreciate one you you
kept pace with the clock, right? Unlike
not all of the department's components,
industry met our timeline and uh Patrick
and Jamie weren't nashing too much at
teeth based on the comments and inputs
that we got and so we're in a pretty
good place. I will tell you we are all
the way through at 46 Department of War
components have uh provided uh you know
their editorializing and inputs to uh to
um to the draft manual. There are no is
that right? No non-concursors. Do I have
that right? is they're like, "What?" Oh,
is that right? Or almost no. Almost no.
All right. Well, damn. All right. So,
but nothing insurmountable. Is that
fair? Okay. All right. Patrick's like,
"Stop talking about that." Right. So, uh
yeah. So, we're we're closing in. Uh you
know, it's it's always difficult to put
timelines to things, but it's very
important. We could use some industry
support here because frankly, there are
some deltas uh in terms of what the
NISPOM says and what the volume one
says. This creates real problems for
DCSA. uh little thing like a little more
flexibility and key management
personnel. I'm working on it, Matt. I
promise. Um so I told you I was going to
mention your name. I just thrown myself
under the bus. Uh you know, Matt and his
team kind of surfaced an issue that
would provide a little more flexibility
uh in as a function of the the process
that leading leading to facility
clearances. This is a particularly acute
problem for uh in academia where we have
sort of this cookie cutter idea in our
policy statement about how would a board
uh you know ought to look like in a
university and it turns out that they're
all very different. Um and this is uh
this is a bit of a vexing problem.
There's quite a bit of latitude within
the NISPOM. Hopefully you're familiar
with that. Um um but uh but less so in
the department's policy. uh and there's
a there's several others of these kinds
of examples particularly on the IT side
of things uh that's not really
reflective of the way in which we work
today and so being able to iron those
things out DCSA certainly uses the
volume one as a as as a playbook more
than any others but the fact of the
matter is that you know all the
components uh you know do as well and of
course everybody who signs up to have uh
DCSA provide their the you know the the
industrial security services across the
government um they might not read the
fine print but it also says is you have
to follow our policy. And so, um, so,
um, so we we need to get that out the
door. So, it it's it's up there. Uh, our
new boss, Timothy Brown, the new DDI for
counter intelligence, law enforcement,
security, understands that. Uh, we've
been getting him, uh, you know, spun up
on on what it's like to be responsible
for federal regulation, and the
department's implementing policy on
that. Um, and he still took the job. So,
um, so we'll see. But uh but but you
know continuing attention and I really
do appreciate one of the things that
helps us be able to get over the line
inside the the debates that can happen
uh you know across mil components uh
particularly within the military
departments. But we're able to say hey
we got industry you know to take a look
on this and here's what their comments
and edits look like. It honestly
bolsters us right we're pretty smart
group especially with Matt on the team.
uh but like we don't have a complete you
know clairvoyance uh over the entirety
of the department but industry being
able to you utilize these folks to get
broader allows us for you know a degree
of confidence uh in the process that
maybe we wouldn't I'm very sure we
wouldn't have u you know but for the
work appreciated um I think Jane
mentioned u turbocl
really happy for that glad that my team
you know we've been working with DARPA
and with DCSA to try to be, you know, be
mindful of the application, you know,
put it to practice and use. Um, you
know, to create some efficiencies. I'll
continue to foot stomp. We got to do
better than just be efficient at
lumbering process. Um, the simp simple
fact of the matter is we we are right to
say that things are getting better, but
they're nowhere close to where they need
to be. Not within the framework of the
industrial security program. Uh, where
the flash to bank from contract award to
performance needs to be as close to
instantaneous as is possible. and and uh
and we are not ready for that yet. Um
you know the continuing work the FCL
handbook and other things that were
mentioned today those are reflections of
how the process needs to work but our
goals have to be um you know with
mindful of real security work the real
purpose of the industrial security
program isn't all this administrative
stuff that really defines or occupies
most of our minds. It's the actual
performance of the in support of
national security work that's supposed
to happen when the contracts themselves
are underway. um we're not quite ready
to have that be the primary
conversation. Um but I think we're we
are trending in the right direction. We
don't want to miss the opportunity to
applaud the improvements, but we have to
be mindful of the fact that we are
nowhere close to where we need to be. Uh
and that becomes even more of an acute
issue when we think about 847 going out.
It's not going to be this deluge kind of
issue that had been, you know, been laid
out before, but as it begins to, and I
appreciate Jane saying it the way that
she did, but as it makes it starts to
make its drips and drabs onto contracts,
right, the requirements themselves are
going to have us, you know, do what they
do, uh, you know, to to move them
forward. The timelines are being shape
up pretty well with the way in which
DCSA has prioritized um, NI2, which is
really convenient. Uh, and I'm also
pleased to say, you know, the CSA
through a lot of its own internal work
and some partnering with our team, uh, I
use the analogy that like if we had to
do this in a remember anybody ever I use
this really fun bowling analogy. I think
it's kind of fun and what the hell I'm
talking anyway, but you ever learn how
to score bowling like by hand, right?
Today you go to like maybe like nobody
goes bowling, but if you do uh, right,
it's all electronic, but in the old days
you had to do it by hand. It was this
kind of weird wonky math, right?
especially if you get a strike and all
this other stuff. And in in gym class
when I was a kid, we actually learned
how to do that. Well, that's kind of
where DCSA is right now, right? They're
not waiting on the system in terms of
their preparation. And as a function of
the way in which, you know, we need to
be able to drive down some of these
timelines, particularly as it relates to
new entrance, which are tend to be
dominated by small companies. You see
where we're going with this, right?
Which is very responsive to the
priorities of the secretary. Uh we can't
wait on the system. We cannot continue
pineing away about that stuff. And so
these guys are now really good at score
and bowling uh you know in any analog if
necessary. Um but it's looking like the
timelines are going to line up pretty
well. There's a homework assignment
though as it relates to the the roll out
of this particularly as it relates to
the NISP and nobody's looking for
redundant processor requirement right.
So every company that's represented in
this room and sort of on this table you
already have a couple of advantages
where A47 go in the form of you have a
328 on file particularly if you're
performing now it needs to be probably a
little more current right so part part
of our oversight has been that hey those
things can get a little stale and we can
be looking at we saw some examples where
you know currency was defined you know
at a time you know like the date on the
328 was like I'm like hey I turned 30
that year and and I remember it really
well But it's hard to imagine that a
company hasn't changed at all in its
posture over uh you know you 24 year
time period right and I'm being a little
bit exaggerating mostly because I forgot
how long ago that I turned 30 I should
have said 40 uh because it have been a
little bit more close to the example but
there's going to be need to be some
currency DCSA is recognizing that that's
where the data and the data systems will
be helpful in it but that's not
something that that industry should be
passive about also right so you can
watch the news and you can see it just
the same as we can and being able to
kind of be in front of that, right? And
the affirmative responsibilities that
companies that participate in the
program have to make sure that their
information is current, just like we all
have to do with our personnel security,
uh, I think will go a long way to
dialing down any concerns that an
existing clear defense contractor should
have, even if that company is under
folky mitigation today. And so I put
that out there and if it turns out I'm
wrong about that then well it doesn't
really matter now but the uh but I'm I'm
very conf I'm very confident that I'm uh
that I'm not and I think they've uh
really rightly postured to take the best
pieces and parts of it and I wouldn't be
remiss if I didn't continue to remind
folks right that when Congress put the
provision in place like let's see the
compliment folks right so the idea hey
folk is a real concern and the congress
believes as they I think in the right to
do so that the way in which we consider
it as a function of industrial security
which has been going on for a long time
works right it works so well that we
should start to use it as an acquisition
criteria as a function of award. So
that's a there's a real there is a
there's a serious compliment in there
and there's a real challenge but leading
from the front programmatically is a
public is a government and industry
opportunity uh that I I really think we
should take uh very firm advantage of
all the more as uh as NI2 moves uh you
know moves in in a very good direction
which which certainly it is um the other
thing related to that and I didn't want
to miss it and I'm I'll start to wrap up
here and that is you know the other
thing that's happening where NI2 is
concerned and and and just data just in
general. And I think it was Jenny. I
can't remember. But I'm going to just
give you some credit because I've like
I've talked about Ike and you know
Leonard set me up last week and I'm
standing too close to Charlie. So it's
uh you know so anyway uh but I think it
was you you know like uh you know where
you were talking you I think you
mentioned transparency right like I I
will tell you when I first joined the
NISPAC I it was Kim Bogner used to sit
like right there where the monitors are
and continuously kind of talk about the
challenges that she would have as a as a
as a government person being able to be
able to access and utilize the data that
is collected principally by DCSA but
from industry and the own and her own
execution and requirements uh you know
within state department's program and
over the time period since then real
testament to the leadership and
foresight of DCSA you know and and and
some of the evolving requirements here
and that is that you know the there's
greater access across government and
industry right so your comments related
to its importance in industry are really
fantastic but I have to be very very
candid with you it's really government
itself that needs to be the beneficiary
DCSA is is a data services provider in
this way because industrial security
becomes a team sport when we get to the
performance on the contracts and I love
the fact that we're really starting to
be able to have that conversation in a
in a more uh objective way. Uh and I I
would continue to see it uh to move
forward uh particularly as as NI2 comes
online. It's not going to be perfect
system, right? DCSA is DCSA. They're not
Microsoft, right? And so they're having
to build this thing at the same time
period but making it kind of dynamic.
Our office will certainly uh you know uh
continue to play an active role in the
requirements and and and such. But you
know you know it's always going to be
you know it's a journey that won't ever
end. But I think the fact is that
there's more use and utility that's
coming from it is a real opportunity. Uh
and that's the thing that we really need
to focus on. uh because if the goal is a
perfect thing on the way out the door,
then that's that's that's not realistic
and it's also not it's it's not purpose
purposeful uh as it relates to mission.
Um okay, so uh let's see last couple
things here. Uh appreciate Michael.
Thank you very much for saying cy so I
don't have to. Um oh AI, right? So yeah,
I think it's I think it's great the work
that Larry's doing. Right. I continue to
volunteer. I'm going to volunteer twice.
Devin Casey who's not here with me. He's
on my team. He might be listening. He
probably just hung up. Uh but he's an
active participant in the in the work
with respect to uh you know the the 45
or 60 I don't remember the timeline that
CIO established where CMMC is concerned.
There's a fun little intersection there
between CUI and CMMC uh and uh and Devon
Case is pretty much the smartest guy in
the department on that. So we're really
happy to have that. So for my uh
industry uh working group uh you know
counterparts here, right? So happy to
lend that voice. They're meeting pretty
regularly uh to try to put out some
options here on uh you know, hey, let's
let's relieve some of the burden, but
let's also keep our eye on the prize
that there's there's real national
security uh interest in uh in cyber
security on those uh commercial side
systems. Uh and then finally on the AI
front, um well, two other things, right?
So, thank you for the the flyaway kits
conversation. Lenon, I just wanted to I
I am going to I will talk to you in this
moment. No, I'm kidding. The uh iswig
was fantastic uh really opportunity for
cander, but you said, "Hey, I don't want
to get in trouble uh for what you said,
but we can't we can save a lot of
money." Absolutely. And be more
communicative and be more expedient and
be more secure and spend less money,
right? Those are the benefits that kind
of come from this. So again, testament
to how this all works, right? you all
raising the issue so that we can get
past the absurdity of yeah, by all means
go out and make the classified call in
the car, but do not dear God, don't come
into the open air open storage area,
right? Like that feels um it feels like
Ashton Kutcher should parachute out of
the ceiling because we're being punked,
right? And so uh so you know, like hey,
allowing common sense to enter into the
mix here, but really that's not where
the conversation needs to end. So
certainly we need some more guidance,
although I think our friends at Dissa do
a pretty good job of that. I know and
and became a a student of it. Uh you
know remember the training I took
because I had one of those things for a
while very happy among other things that
I've gotten to turn in was that
particular little device. Uh because it
does become oh crap it's ringing again
kind of a thing right so like you can't
you run out of reasons to like well I'm
sorry I didn't see that over the weekend
or whatever. But but all kidding aside
right there's real use and utility and
beneficial security and so I don't think
this is where the work ends at all and
certainly we need some more guidance. We
should have that. But again, one of the
asks that we have of industry, you're
starting to hear resistance in this. We
need to know that. DCSA needs to know
that so they can make sure that they're
empowering their workforce to be more
understanding. DCSA also needs to be
able to know that so that if if a
military department or somebody's
issuing these things that they need to
know, right? They need to be aware of
that. To me, it is entirely within the
remitt of industrial security. I don't
care if the people work on a military
installation or they work at, you know,
in, you know, whatever a facility in,
you know, Arkansas someplace. And so it
makes no difference. Being able to be
knowledgeable of that, I think, is key
because as we continue then to refine
the guidance and whatnot, both to
industry and to government, uh, that
becomes kind of a wash, rinse, repeat
part of it. But more than that, it
should also be the thing that invites
larger considerations of the use and
utility of these things. uh we we're
talking about yesterday with a colleague
talking to my boss and said look these
like we need to spend more time talking
about what security limits us from doing
with our industry partners not what it
enables or what it secures and in it
it's more it's no more fundamental than
this and so the real vexing problem here
that we can get after is today I can
send an email to any contractor on my
team on any network that I want to and
they'll be able to respond to that
within the confines of our spaces the
promise of these things is a greater
degree of interoperability ility not
just for those contractors that provide
services and support you know mostly
administratively but in a production
environment it's the same security
requirement why don't we have the same
core capability and the answer isn't
because of something that's written in
the NISPOM or in the NISP it doesn't
trace itself to the EO which doesn't
even contemplate systems the word does
not appear in the executive order uh and
so what it it is it's a we're in a we've
always done it this way and because
we're we've always done it this way
that's a real limb fact for us well this
is the time to really throw that out the
window and now we can capitalize on
something that's kind of happening on
its own and uh and and really advance it
and I think we should be quite
provocative in that so that we can be
more communicative uh with industry
right we constantly are talking about
information sharing you know the latest
cyber this that or the other thing well
how much better would we be if we'd be
able to share using these devices right
imagine if a scenario where every FSO in
the NISP has one of these things and
when we need to tell them something that
we really can't can't send them. We
can't secure it any other way. Uh and
probably shouldn't use signal. I'm not
sure if that's a fun joke or not today.
Damn, I was doing pretty well, I
thought. So, but uh but all kidding
aside, right, like this is something
like these exist, right? So, we should
be thinking about that. And Leonard's
point is exactly right. And I really do
think it should be called out. That is
not an expensive solution, right? You
know, we've tried something like this
before, right? Some of you are old
enough to reme remember Dimnet S, right?
You know, this is way beyond that. And
so, you know, one of the challenges that
that I'm leaving for my office is to
we're pretty good at issue papers. This
how we get some money and that's where
we're able to help Annie. I was looking
for a little credit there from Latoya's
question for earlier to help with the
SEI things. But we can go find some
scoop up money, right, to be able to
kind of show the value of that. But if
you think about this thing
programmatically, and we really did put
one of these in every FSO's hands, it's
not we're not going to break the bank at
all, but we are going to do is we're
going to enable security. And so that's
the way that we should be looking at it.
And I think because of the power of
NISPAC, if we keep our eye on that, I
think we'll create that kind of options
for our leadership, uh, you know, pretty
fast. And so that would be the
challenge. And then finally, uh, just on
the AI front, you know, just just to
kind of close out from there. Yeah, it's
gamechanging kinds of stuff. I mentioned
it in one of the working groups. I want
to do so here. And I I really am trying
to be a little bit um uh deliberate
about trying to sign us up for for work
that's going to be beyond my my tenure.
But this one's real high consequence,
but it's also high opportunity, right?
So, uh, there are a couple of studies
that our team has commissioned, uh, you
know, that are going to start to come to
fruition in the fall. Uh, Devin Casey
again is kind of our our lead for that
because he's got a I mean, he doesn't,
if those of you know him, he's got a
devious mind. Uh, he hides it pretty
well. Um but it's starting to come out
and I think it's really good for us
because there's challenges and there's
opportunities uh you know where where uh
you know some of the you know
conventional AI certainly leading edge
is its own concern so other people are
working on that but from a security
vantage point right kind of wanting to
understand what those are because
there's just a whole lot of you know
nobody's telling me not to so I'm going
to so we you know helping to to define
what some of the guard rails need to
look like but with some of the
opportunities to really utilized the
word efficient in a in a way that's
consistent with its definition. Uh said
more directly, the department's got a
lot of classified information that we
kind of foisted in your direction that
probably shouldn't be. And I think AI is
going to help us kind of get after that
pretty fast. And so uh with that, I
would ask uh to add to the to-do list
here. But beginning with the working
groups and certainly leading up to the
next NISPAC, uh we would look to be able
to carve out a little space uh to be
able to provide us provide a little bit
of an update of what our findings are
telling us because it will be
immediately consequential uh to to
national security work particularly
where classified is. So um and Devon
will love that. So um so with that I I
think I'll just close out by saying uh
you know you know where I'm thank you
very much. just uh it's just been it's
been, you know, just a tremendous uh
honor to to to to serve in this role in
this capacity. Uh you know, some great
teammates across the board. Uh and it's
um uh um I'll miss it. So, thanks a lot.
>> Anyone questions for
one more chance to take a swing at Jet?
All right. Thank you, Jeff.
We will now hear from Miss Allison
Renzella, the senior policy adviser for
industrial security at DCSA. Allison.
All right. Good morning. Um, I know I'm
standing between you and a break, so I
will try to keep my remarks as brief as
I can, but I did have a lot of asks from
industry, so I'm going to try my best to
get through it all. And I apologize.
Guys, I am going to rely on my notes
because I want to make sure I address
your uh your excuse me, all your topics
to the best of my ability. Um, but
before I do that, I just want to
acknowledge Ike, Jane, Jeff. Um, really
thank you for your leadership,
partnership, and commitment. Um, we've
had a lot of spirited discussions over
the years and we didn't always agree,
but you know, that's okay because I take
it at that's because we care, right? So,
that's the important part. So, you'll be
hard to replace, but I'm sure we're
going to run into you still and uh be
involved. So, look forward to to
continuing the relationship.
Okay. Um so, for personnel vetting,
trusted workforce 2.0, um I have some
updates. Um the investigation inventory
that'll be covered later on and the
clearance working group updates. Um and
we understand, you know, we know there's
still quite the investigative backlog.
um and you know acknowledge industry's
continuing concern. Um but we have
multiple mitigation strategies underway
to address uh to try to get after this
um for the high request and submission
rate the program is experiencing. Um
we're trying to posture ourselves for
the near future expectation of also
increased requests. Um so to address
some of these we are strategically
assigning work to areas that have
capacity to complete it in the most
efficient way possible. Uh we continue
to leverage virtual methodologies.
Uh we are aligning internal resources to
areas with the greatest need and we're
assessing future inventory changes.
Um as far as trusted workforce 2.0
implementation, um I've also got some
updates on that. Um we are on track
through several concurrent initiatives
and aggressive efforts by different DCSA
directorates. Um embis delivery and
implementation is the highest agency
priority right behind NI2. Um, and we're
currently focused on dismantling a
legacy system landscape and replacing it
with a modern user centric platform. I'm
going to talk more about NI2 and Embassy
here in a little bit. Um, but as of the
end of this month, uh, we will de be in
development for the individual
engagement platform self-reporting. Um,
it's expected to be completed and
deployed. Then, um, in the important
note, we hear you. Uh, the FSO will not
be left out of the self-reporting
process and will be included.
uh wrapback. That's another I know topic
uh that everyone's interested in. So we
have phase one, two, and three
populations. Uh they're all being
enrolled concurrently at the fastest
possible rate. Um we're exploring
technical options to further increase
that rate. Uh more importantly, um the
list of all phase three personnel, these
are people with no prints on file, have
been communicated out to industry um
with specific instructions on how to
proceed to obtain the fingerprints. Um
that is with a deadline of next year
September 30th 2027.
Um so as long as you have claimed your
employees through your security
management office uh your subjects um
that are enrolled with IC specific
wrapback programs um we are trying to
obtain those prints first uh through
those IC specific programs um instead of
having all your people go get new
fingerprints. So I understand that is
still occurring it sounds like. Um, so
we'll have to look into those instances
because, um, you know, we are trying to
focus on not having to rebringing for
people if we already have them on file
through someone else. Um, so as of
August 20th, uh, we're about halfway
done. There are currently 633,936
industry personnel enrolled in RAPback,
uh, with approximately another 600,000
remaining.
Um, okay. Moving on to the personnel
vetting questionnaire.
We're currently refactoring the PVQ
initiative in DIS. Uh, changes will be
expected to make the platform more
easily readable with less issues
pertaining to validation. Um,
additionally, there will be a prefill
capability for future submissions and
form navigations.
uh roll out began June 1st with a small
group of early adopter companies um
initiating the PBQ for five-year updates
and a broader roll out will follow in
the future. As of 18th October, excuse
me, August, 13 industry companies have
submitted 214 PBQs.
Um I'll talk again more about this
during the update here in a little bit.
Um but developers are working to resolve
the issues identified by industry.
Um, okay. So, with Nissa working group,
uh, I know you guys brought up the, um,
implementation, the roll out to Rev 5
for NIST 800-53. Um, Tracy Brown is
going to talk about that during the NISA
working group updates. Um, and then I'd
be remiss, um, you also brought up
sanitization procedures from solid state
drives, um, as an open action item. I
think from DCSA's perspective, we
consider it kind of closed. Um, we we
formalized our procedures through our
DCSA assessment and authorization guide.
Excuse me. We've worked with NISPAC
industry to address any consistencies or
confusion that they were seeing out in
the field. Um, and we provided an update
to them in June. Um, spillage mitigation
policy is found on the committee on
national security systems instruction
10,01.
Um, we also would let industry know, you
know, you should work with the
information owner for allowable
dispositions of equipment involved in
the spill and ensure those procedures
are approved within your incident
response plan.
Okay,
excuse me. Moving on to entity vetting,
FCL modernization,
um, and folky expansion efforts. Um,
there's a lot going on in this arena.
Um,
ENT vetting is working very hard to get
their timelines down. Um, current stats,
77% of mitigation actions are being
completed within 45 days or less. 38% of
vetting actions are being completed
within 14 days. Um, NA vetting has
several initiatives underway to meet the
evolving needs of stakeholders both
through process changes and planning
efforts to support the migration of this
into increment 2 and also support the
FOI expansion efforts. Um, Jane stole my
thunder. Uh, the FCL handbook was
published just uh the other day. So,
thank you again you guys for working
with us and providing feedback.
Excuse me. Some changes to highlight in
the handbook. Um we have now FCL
adjudication and appeals processes. Um
so you know that is kind of a due
process. If someone gets denied um an
FCL or gets their FCL revoked that
process has been codified now um in ways
if they choose to appeal they can. Uh we
also included simple and complex or
structures um for all business types.
That's one of the many job aids that's
out there now. Excuse me. Um, and I we
also hope that will help with the FOCA
expansion efforts to make, you know, it
more readily available, excuse me, what
we're looking for, what we need to vet
companies. Um, we also worked with all
our stakeholders, um, government
partners, NISPAC industry on revisions
to the SF328 instructions. Um, the goal
was to make enable a more efficient and
streamlined process to complete the
SF328.
Uh the instructions have been updated
and posted to the GSA form site as of
July. Uh the instructions were modified
to scope requirements to the information
necessary to render a risk determination
while reducing the burden on industry.
Uh this will also become increasingly
important as we get closer to
implementation of folky expansion.
Excuse me. We've also drafted um
guidance for change conditions. Uh we
have a draft industrial security letter
making its way through the coordination
process. Um this will excuse me provide
industry guidance on when you need to
submit a new SF 328. Um and includes a
reminder that your annual
self-certification
should include that validating that 328
is still accurate. Um and there's also a
recommendation to report change
conditions. So this is a recommendation
um to report change conditions as soon
as they become known rather than waiting
until after an acquisition for example.
Um many times we see once uh company you
know you're in a merger and acquisition
talks um when you get close to
finalizing that acquisition we've found
that typically the the main details of
the acquisition don't change all that
much. So, we're encouraging companies to
go ahead and report that once it becomes
known so we can start working with you
earlier on potential mitigation uh for
especially obviously I'm talking about
foreign ownership.
All right. Um some other changes we're
working on related to folky and folky
expansion. Um we are updating our folky
templates as Jane also mentioned the
electronic communications plan. Um but
we're also working on the other folky
templates too. So it's a little early
yet. Um, we're not ready to share those
drafts. We're working through them
internally. Excuse me. But when they are
ready, we will work through NISPAC to
make sure we get your feedback. Um, also
to prepare for FOGA expansion coming
early next year. Um, FOGI assessments
will be reviewed and updated as
necessary for those companies currently
in the NISP so that as new companies
come online with FOGA expansion, we can
focus our efforts there and not on
companies that are already cleared.
Um, and I know we had a question from
industry about our denials or adverse
folky determinations from other federal
agencies reportable to DSA, excuse me,
DCSA. Um, and yes, these determinations
would presumably coming from other
cognizant security agencies in the
respective role to mitigate folky and
make FCL determinations. It will most
likely be shared for reciprocity reasons
when both entities have equities.
Um we also are tracking that NISPEC
industry has requested a comprehensive
implementation plan for FOGI expansion.
Uh we've been doing a lot of work behind
the scenes on this to be prepared. Um
primarily we've been focused on internal
processes, requirements for NI2 to
support it, training um and trying to
get our DOW acquisition counterparts um
engaged. Um and you you can't separate
folky expansion from NI2. um it's an
integral part of the successful roll
out. Um so industry as a key stakeholder
will be included in the requirements and
process mapping review first. So that's
that's the first thing we're going to
ask is that you come in, you share with
us what you need from a requirements
perspective and then testing will begin
in earnest probably uh early in the new
calendar year.
Okay. Now I'm going to rely on my slide.
So NI2, excuse me, I know you guys have
been
asking for a roadmap, excuse me,
particularly focused on capabilities.
Um, so we are committed to providing a
clear, concrete and achievable roadmap
that focuses on delivering real value in
the near term. Our plan is centered on
transparency, clear timelines and
realistic approach to this
modernization.
So first of all, what is an I2? It's a
modern secure web-based platform
replacing our outdated fragmented legacy
systems. Uh think of it as it will be a
central hub for industrial security that
brings everything into one place.
Uh why it matters? It moves us from slow
manual paperbased processes to a digital
first operation.
This eliminates redundant data entry,
reduces human error, and provides a
single authoritative source of
information.
And the key benefit um that we're
working toward is that it creates a
shared operational picture for both
government and industry. It's pro
designed to provide the right
information to the right person at the
right time.
Um timelines and milestones. So our road
map to 2027
um our path forward is defined by two
parallel tracks. Um track one is
retiring our legacy systems and
automating workflows.
So over the summer um we've been working
to finalize our data assessment and lock
in the requirements for migrating from
our old system. Uh this upfront work is
crucial to ensure a secure and stable
transition.
uh our current timeline. So by December
uh this will be a critical cut over.
We'll deploy the new modernized
industrial security capability within
within the NI2 platform and begin phased
user testing. Early 2027
uh we'll officially decommission in case
I can attest that it's an outdated and
vulnerable access management system. Uh
this will simplify and secure user
access by managing it directly within
the NI2 platform.
Um and then track two folky. Um I know
there's a check mark that says delivered
down there. From a technical perspective
it has been delivered. I know you guys
it's not out there. You can't use it. We
are fully aware of that. Um we get it.
Um
excuse me. Late this year, we're going
to launch the individual engagement
platform, which is al also the same term
you've heard for inbus. Um, so for the
first time, you can submit folky
documentation directly even before
making a bid. Um, so we hope this makes
the process more efficient. Um, and then
the goal February 2027, um, that is when
we will finalize incorporating uh the
def rule. So we we know it's out. Um
there were comments made but we haven't
seen the final def rule. So once it if
it goes out again once it's finalized we
have to make sure that the system
supports whatever those final
requirements are.
Excuse me. So and then by March and
that's when we're tracking that BOKI
expansion could be start to be
implemented. Um, we will be ready to
shift from manual reviews to automated
real-time threat detection. Um, by
integrating new data sources, NI2 will
automatically flag potential FOI risks,
allowing our teams to focus on the most
critical threats.
Okay. Um, the trajectory for NI2. So,
our new approach is built on providing
clear, consistent, and actionable
information.
Uh, you there will be a unified view.
and I2 will replace siloed tools with a
single integrated system. This means
everyone is working from the same
playbook, enhancing oversight and
operational efficiency.
Our workflows should be automated. The
platform automates the routing and
tracking of tasks from start to finish.
This eliminates offline communication,
emails, manual handoffs, um ensuring
that the process integrity
is there and providing clear visi
visibility into the status of any action
or milestone. Um and we want to have a
collaborative environment by creating a
shared secure operational picture. We
are fostering transparent collaboration
between government and our industry
partners. This accelerates vetting and
oversight timelines, building trust and
strengthening our collective security
posture.
So over the coming weeks and months, we
we will not be operating in a vacuum. We
are actively committed to a robot robust
feedback loop to ensure the system meets
your operational needs. Our product
development and customer success teams
will be conducting direct hands-on
outreach. The initial outreach will be
to obtain input and feedback on DCSC's
update industrial security clearance
processes and workflow. All strategic
coordination, feedback, collection, and
updates will be channeled directly
through NISPAC to ensure your voice
directly shapes the near evolution
near-term evolution of NI2.
Okay.
And last but not least, inb everyone's
favorite topic. Um, so, excuse me. We
have our strategic tra trajectory laid
out here. Um, we're much of the same as
NI2. We're executing a systematic
modernization of the federal
government's personnel vetting
infrastructure. We are actively
dismantling legacy IT landscape that has
long been limited by fragmented
databases, siloed software, and manual
handoffs.
Historically, systems like BI, and I'm
sorry if I'm mispronouncing them, BIES,
PIPS, and Midor handled initial case
work and ongoing monitoring. These
legacy systems are highly transactional,
disconnected, and scheduled to be
permanently retired in FY28.
In their place, we are establishing
integrated vetting and monitoring or
IBM. Uh, this is targeted for full
capability in Q2 of FY27.
IBM is a modernized unified data
environment. It automates workflow the
moment an investigative request is
received, enrolling the individual in
continuous vetting and seamlessly
rounding it to the final eligibility
determination
by transforming from legacy PIPS and BIS
to IBM, excuse me. We are turning a slow
multi-layered administrative process
into a highly automated endto-end
pipeline speeding up the investigative
process and getting people to work
faster.
On the front end, uh we have the
applications you may be more familiar
with such as the individual engagement
platform or IEP which acts as our direct
portal for applicants. IEP feeds into
DIS which houses our joint verification
system for security officers, our case
adjudication tracking system for
adjudicators and our specialized appeals
module.
Um okay and then my final slide the
embis progress overview. This is our
highle road map. Um so to support the
planning and preparation and ensure
absolute transparency our roadmap is
structured around clear incremental
software releases. This is a very high
level snapshot based on capability
releases and trusted workforce
milestones.
We are building an operational customer
road map. This will be our external
customerf facing guide. It will be
written in plain jargon-free operational
language specifically designed to
showcase critical process functions and
outcomes. It will map out clear software
release windows, transition periods, and
exactly when legacy systems will retire,
giving your team plenty of runway to
adjust without any operational hiccups.
We are targeting to have this ready for
you this month in September.
Um, to back that up, we also have our
internal product delivery roadmap. This
maps out the deep underlying technical
execution and deployment phases required
to make sure we actually hit our
customerf facing commitment and
milestones. By running these road maps
in parallel, our ultimate goal is to
give you alignment, execution, and
compliance. We want to take the
guesswork out of deployment so you know
exactly what is coming, when it's
coming, and how to prepare.
Um, and then just really quickly, I
wanted to kind of walk through
um, a few of our key applications. So,
I'll give you a few more details. I'm
not going to go through this entire
timeline. Um, but a few things I want to
point out. Excuse me, CVS to JBS,
excuse me.
The goal to transition from central
verification system to the disc joint
verification system JVS is our single
lowside repository.
So hard milestones and releases. Um in
May we enabled the federal agency
adjudication roles. We automated script
successfully uh to migrate and assigned
those federal adjudication federal
agency adjudication roles to active CBS
users. In July, we delivered mass
adjudication and file release requests
to support the data quality initiative.
And this month, uh, CBS transitions to
read only and JBS becomes the system of
record.
Current action items and support.
So in agency action, uh, we are ensuring
all personnel are correctly mapped to
their security management office and
DIS. Um our target window is Q4 of FY26.
That's our final lowside data migration
and lowside repository consolidation.
And then CVS becomes read only. Um and
then we have support availability. We
have system liaison office hours Monday,
Wednesday, Friday from 12 to 2 Eastern
Standard Time. Um another initiative is
the initiate review authorized migration
to DIS JVS. Um so we have transition
deadlines with no downtime migration. Um
so by September 30th uh we will have new
case initiation completely uh ceased in
the legacy IM agency system. Um and then
by November 30th is a hard deadline for
processing in-flight cases. Legacy IM
agency system sunset begins.
And then future uh rollout scheduled uh
resolving MVP operational gaps. Um in
July we completed we delivered prefill
case reports and email editing.
In August, we deployed the split case
and capabilities mass subject initiation
and dis IRA tracking and the IE status
tracker.
September by September 24th, we will
deliver uh return case submissions,
progress saving tools, and countdown
timers. And then the goal uh for by
October 30th, finalizing correction
email previews, multiple order form
templates, and auto required field
indicators.
Excuse me. Um and then uh more details
on the individual engagement platform
and self-reporting. IEP is our unified
unifi userfacing web portal. It
transition our process from ad hoc
reactive um actions to a proactive
self-service model. So as I said this
month we'll launch the self-reporting
capability IEP. It will allow applicants
to report outofcycle life events such as
foreign travel or marriage directly via
an interactive PBQ mapped online module.
Um the FSO paradigm shift enhances the
FSO FSO role from manual data entry to
high level strategic oversight. FSOs
remain integral to the process but
rather than transcribing data into a
blank form they receive a prevalidated
digital package to review.
Um, okay. So, what's next for FY27 in Q1
and Q2? Uh, there will be event driven
notifications allowing agencies and
industry partners to configure custom
alerts for self-reported changes.
Um, and then finally, the PVQ phased
roll out. Um,
we are tying our initiation and
self-reporting systems together in the
refactored PBQ access through the EAP
interface.
So PBQ will be implemented in phases. Um
in July we launched an NGA industry
pilot and DCSA employee five-year
updates. Um by the end of this month we
will begin integrations with the MILDEPs
HR systems and EAP. And then Q1 FY27 PVQ
will be live for DCSA as an
investigation service provider followed
by nonDCSA ISPs.
Um and then by March 2027 uh we will
launch PBQ for all initial vetting
scenarios and then by this time next
year we should have full operation
operalization of the PBQ for all vetting
scenarios enterprisewide
and sunset uh standard legacy forms like
the SF86 will be sunset. So this
concludes my remarks for today but I
will pause for any questions. All
right, Alison, thank you very much for
question.
>> Allison, thank you so much for those
remarks and for being such a great
partner to us. I want to just shout out
how much I appreciate the updates that
you provided for INBS, but but mainly
for NI2. That was really helpful to see
that information and we look forward to
continuing to work with you. Um, the
comment I'm about to make, you may not
be able to answer, but I want to say it
early before it for the sake of the
other people that are going to
participate in today's forum that they
may have answers to this too and it has
to do with ratback phase three and the
lack of reciprocity between agencies. So
we appreciate that DCSA is willing to
reach out to other agencies to pull
prints. Um the superheroes formerly
known as the um liaison have been
wonderful to clarify that they need the
individual's name, agency, and a PO and
they will reach out to those agencies.
It's a very painstaking process, but to
attempt to get prints. All that said, um
to my knowledge, DCSA is the only agency
reaching out to other agencies to get
prints. And with all agencies having the
wrapback requirement, um I I'm curious
to know if you are receiving requests
from other agencies to do the same to
manually request reciprocity.
>> That's a great question and you're
right, I'm not able to answer that, but
I would be curious to hear from other
people presenting if they are undergoing
the same initiatives. Um but I will take
that back. That's a that's a great
question.
So,
>> so I actually have a question in regards
to the IEP. You mentioned that um that
the FSO will be a part of that workflow
for the IEP. This is actually the first
time I've heard that since the CAB where
it was kind of a bit of of confusion um
in regards to the FSO being involved.
industry looks forward to seeing that um
hopefully ahead of it being deployed
because one of the things that stood out
to me was um that you mentioned is
strategic oversight
>> and further definition on that is what
I'm looking for because
>> is this going to be you know there's a
lot of questions that I have when when
you say strategic oversight
>> right so yeah the way I understood it
and what I was provided is that yeah you
will receive those prefilled
questionnaires so that you can review it
validate it and it would be then
submitted. Um I don't know if I have
anyone here on the line who can
elaborate. Um but that is my
understanding.
I don't want to speak.
>> No pressure. No pressure at the moment,
but we definitely want to have a
follow-up conversation um sooner than
later to make sure that we understand
exactly what we are going to receive at
the point of the IEP being deployed.
>> Absolutely.
>> Thank you,
>> Allison. I just want to say and this is
really for you Heather as well for the
record that I concur the solid state
drive matter is closed. It is done. It's
it was resolved and addressed.
>> Great.
Thank you. See we can cross one item off
the list.
>> CSA is concerned. I think we might have
some work to do on the IC side. Right.
So, but I'll take the win. Right. So,
thank you.
>> Other questions?
All right. With that, we are ready for a
break.
>> Next, we will hear from Miss Lisa Perez,
the chief of the policy and
collaboration group, security director
at National Counter Intelligence and
Security Center Security Center, Office
of the Director of National
Intelligence, Lisa.
>> Yes. Can you hear me?
>> Yes. Great. Thank you, Lisa.
>> Good afternoon, everyone. And so to
Jeff, Jane, and Ike, um I always want to
take a moment to say thank you for your
years of engagement as a member of the
NISPAC as well as for um the many
accomplishments made as part of uh your
involvement. Um a lot of great things
have been said about you all today. So
know that you uh essentially leave a
legacy.
And then seed 4 was one of the things we
were asked to provide an update about.
Uh so we're thankful for the NISPAC
industry representation um during the
comprehensive research phase that led to
the recommendations for the revisions
with the security executive agent
directive for the national security
adjudications. Um we did complete an
initial draft of the directive which
NISPAC industry representatives provided
review and perspective via comments um
which have since been adjudicated into a
draft. Um that we are in the early
stages of inter agency um coordination
and currently of course uh that
engagement is happening with our legal
council. Um we are aiming for October
for issuance of that. And then the ICD75
is another topic we were asked to
provide an update on. Um so in relation
to ICD75
um the director of national counter
intelligence and security center had
issued I think the last memo that came
out was um 6 August 2026 and in that
memo it clarifies how currently um
accredited legacy skiffs um built per uh
to like preicd 705 standards um such as
if it was built under DKID 69 um how
they may continue operating um but of
course not indefinitely they must be
evaluated at least every 5 years um uh
with uh normal maintenance uh and
repairs as the way of addressing
deficiencies. And of course, if
protections um do find are found to be
obsolete or if they cannot be remedyed,
this gift needs a waiver to keep
operating and must be scheduled for
upgrade or a reacreditation to the ICD75
or decommissioning. Now, going forward,
right, a lot of changes are happening.
Uh so going forward we are working on
revisions to the intelligence community
standard documents to incorporate
feedback from government and industry
partners and uh update language to
reflect guidance issued in these recent
memos. The one I just mentioned and then
the one previously.
Um sharing of covered insider threat
information policy. I did hear that come
up as well today. Uh so as you heard
earlier about that a policy on sharing
covered insider threat information was
developed and coordinated. We are
thankful to NISPAC industry leadership
for their review and sharing of
perspectives that were helpful in
drafting the vision excuse me the the
version submitted into our internal
agency review process. We've had some
staffing changes within ODNI that led to
a pause in the internal coordination of
this particular policy document. So,
good news is we do now have personnel in
place uh to revive this coordination.
I'm expecting work will pick up um
within probably the next few weeks. So,
if focus can stay on the final
coordination efforts um I'm confident
the policy will be issued well before
the next NESPAC meeting.
And um I
saw in the agenda online that there was
um a topic of Taurus and so many of you
have probably recently heard heard um
about Taurus or heard some more
information about Taurus. Um so I don't
have a whole lot new that I can share
but uh just to provide you a little bit
more information or reiterate
information you may already know. So the
transparency of reciprocity information
system Taus will make a relevant
intelligence community uh personnel
security data make it available to
agency decision makers when they need it
as part of the personnel vetting. So
what this means for industry is improved
applicant experience where individuals
um who will become part of the
intelligence community will use uh the
same form for filling out security
paperwork. Um a reduction of duplicative
personnel security paperwork. That's the
goal. And then such as the personnel
vetting questionnaire um where that
individual will fill out once rather
than u multiple times or once per
customer or employer. So greater
mobility of course um um for cleared
contractor personnel with faster
transfer of trust decisions because the
right information will be available to
the right people in the process of these
transfers. and then improve data sharing
amongst agencies with uh standardized
security data formats and sharing uh
mechanisms within the intelligence
community um birectional sharing within
this of course and then moving towards
uh the personnel vetting record
standardization for the community. So we
look forward to continued engagement on
this advancement of tourist development
and the first uh iteration of that
personnel vetting questionnaire um will
be launched on JWIX in February 2027.
And of course I am hopeful to have more
implementation news at our next NISPAC
meeting.
And that's all of the um updates that I
have or at least all the things I heard
that may need to provide some more
response on. But happy to try to answer
any questions.
Thanks. Any questions for OD and I?
>> Yeah, I do.
>> We'll go to the table and then go
>> Oh, I'm sorry. Okay. Um Lisa, thank you
so much for those updates. I do have um
I do have two questions. The first
question um is referencing what you said
at the very end about the first
iteration of the PVQ um being released
next year. Is that what is that a
different version of PVQ or what PVQ is
that?
No, I'm referring to the functionality
of it. Um, so it's the same form. It's
just that, um, when it's there, um, I
think initially, right, it'll be a first
full form completion. I don't know that
it will have the ability to go in and do
updates of just sections yet. That will
just be the, in other words, someone
maybe potentially coming in new. They'll
fill out that full form for the first
time. That's what will be available in
February 27.
>> Okay. Okay. And is the goal of that PVQ
to be uh utilized across the IC agencies
or is it specific agencies that will or
won't be using this form?
>> So our ultimate goal is that it will be
used by um all the IC agencies. However,
you know, it'll be an iteration of of
how it's adopted.
>> Okay. Um the followup the following
question I have is in regards to uh the
policies that you've stated are in
coordination. So you've mentioned that
the comments that we've provided and
this is in reference to all of them that
you've talked about uh in your in your
briefing but you've mentioned that
you've that the comments that industry
provided have been adjudicated. Is there
an appetite to uh to allow a review of
those adjudicated comments to ensure
that the comments uh the intent of what
we provided in the comments are received
in a way that uh helps implementation
and doesn't drive us backwards once the
policy is released.
Um so the instructions from our
leadership was to get the comments,
conduct the adjudication and not just
with industry but with the internal um
other agencies review as well um and
then to move forward because they were
trying to truncate the issuance of it.
>> Okay. So um industry would like to
request um a follow-up conversation as
in regards to those adjudicated
comments. We provided quite a few of
them and some of them um we are afraid
that they could be misunderstood. Um and
this is just from the respect of how the
uh policy that was released in regards
to what we consider the overhead billets
policy um how that was put out and I
think that some of that information may
have been misunderstood. So, um, again,
industry would like to have a follow-up
conversation to review or to discuss,
uh, how those comments may or may not
have been included in the uh, the policy
that's currently going through
coordination.
>> Um, yeah, we're happy to to set up
something with leadership. I would say
with respect to the overhead blets or
not the overhead bills, the key
management personnel, is that what
you're talking about? And the oversight
personnel.
>> Um, yeah. So that one was constrained by
what specifically is in the statute. So
not so much our decision on adjudication
of comments just for everyone's
awareness.
>> Thank you.
>> Hey Lisa.
>> Hi.
>> Hi. This is Ike. Um
I don't want to beat the dead horse when
it comes to the inside of threat for
covered employees. However, we started
talking about this at the public meeting
in 2022.
>> Um, yes mentioned, right? I'd be remiss
if I didn't sit here in front of a a
room full of industry personnels to say
that four years is a lot of years and I
know we've been changing administrations
but industry was asked numerous
occasions to provide those comment I
mean to provide um some input and we did
and
we have to move this across because we
have industry companies that are out
there that have to take individ iduals
back from agencies that is sending them
back with no information and companies
has to make a decision whether or not
they're going to keep that individual
um not knowing why they were sent back.
That is a risk um in a huge way and we
don't want to be we don't want to have
to come together again and say we really
got to do it now because somebody just
went into an office and shot up the
place. Right. I I only can say it that
way because that's what really could
happen here when you don't know why
someone has been sent back from an
agency. So, industry NISPAC and and the
industry at large pleads with um OD and
I to try to see how we can get this
pushed over the finish line because four
years is a long time over.
>> I fully understand. Thank you very much.
Again, I'm hoping hopeful that um um
this will be revised um here in the next
coming weeks. Again, it was in the
internal agency process. It just paused
in there uh with a change of personnel,
but again, people are now in place again
and um we'll be able to pick back up on
that.
>> And Lisa, we have another question for
you in the room.
>> Um hello Lisa.
>> Thank you.
>> Uh Lisa, my name is Mike Delmuth with uh
Delu Security Services. Um, I want to
take you back to ICD 705. Um, based on
your comments, I'm not sure you're going
to be able to answer this question, but
let me at least ask it. Um, just in
case. Um, I've received numerous or
several inquiries from uh my industry
colleagues on when will the next update
to the ICD75 tech specs uh be published?
And the big concern is uh at least for
the the people that I'm working with in
construction is the lack of the uh
templates and the checklists that were
in the previous edition but got deleted
from the current edition but are
expected to be in the upcoming edition.
Um and so there's there's a constant um
inquiry like when is the next edition
going to be published. And a second
question sort of related to that. um
about a year year and a half ago,
somewhere around that time, um I believe
the government said they were going to
update or publish some new ICS 705s
dealing with the construction of uh data
centers, uh medical devices, inside
skiffs, things of that nature. Um like I
say, about a year, year and a half, give
or take. any idea when any of those ICS
documents will be published and any idea
as to when we can expect an update into
the text specs uh for 705?
>> I do not have an expect expected um
completion for any of these items and
the latter two I'll certainly have to
take back and inquire um where those are
in terms of um are they being worked or
who's working them. Um but with regard
to the ICD75 stuff, they are feverishly
working and again there will be um
coordination with agencies and um
industry representatives um to try to um
get it all finished and but again it's
they're definitely um working
feverishly. Like I said, the other memo
I just mentioned, it just came out a
matter of days ago. So they are working
hard.
>> Fair fair enough. Thank you. Um, for the
young that just spoke, just make sure
you reach back out to industry NISPAC.
Um, Kathy Andrews will be your point
person and we can get that information.
Um, we she will work together, work
through ODNI to try to get that
information and as she do, she'll ensure
that she pulls that back out and shares
that with industry. Over.
>> Thanks.
>> Thank you for adding that, Ike.
>> Yeah. Thank you, Lisa. Any other
questions for OD and I?
All right.
>> Thank you, Lisa. Thank you, everyone
with questions.
Next, we will hear from Don, the chief
of the Central Intelligence Agency's
security policy staff. Don,
>> good afternoon. Uh I think the only
thing we wanted to address was the uh
question for I guess all the agencies
with regard to the memo uh the DNI memo
having to do with u a certain contract
personnel overhead personnel um and
implementation. Um the only thing we can
give at this point that just came out a
couple months ago. So, uh, the agency is
currently reflecting on the requirements
in that memorandum and trying to
determine how implementation will
actually be carried out. Uh, there's a
lot of players, uh, in that as far as
how we do things contractually. Um, and
we'll provide more information as soon
as available. And that is all. I have
less questions.
>> All right. Thank you, Don. Any questions
for CIA?
>> I do actually have um more so of a
comment. Don, um you may want to work
with um get with Lisa Perez on that um
on that policy because there is um a
current review happening of that policy
and the language that's included for
some uh revisions. So you may want to
get with her before you um take too much
time on implementation.
>> Yeah, thank you Latoy. Um, I actually
have been doing that and uh and I have
seen the um we we've talked about the uh
the changes on that uh which aren't
ready for be discussed yet, but yeah,
thank you. We're we're on it.
>> Thank you, Don.
>> Thanks, Don. Any further questions?
>> All right. Thank you.
Next, we will hear from Miss Brianna
Palmer, the deputy director with the
office of the chief security officer at
the Department of Homeland Security.
Bri,
>> so I do know that.
>> Great. Fantastic. You are there.
>> Hi. Yes. Good afternoon. I apologize.
I'm in the field so uh I don't have
camera and I may have to run depending
on the storm status. Um but good
afternoon everyone. Happy to be here. um
DHS really didn't have a lot of
questions that were sent out by
industry. So, uh as far as updates, I
can tell you that we are actively
pursuing or actively working in the
trusted workforce 2.0 space and I do
have statistics to show kind of where we
are with that implementation and how
that impacts industry specifically. Um,
we're also pushing out uh what's called
the enterprise secure forms system,
which is ESFSS. And what that does is
our contracting officer representatives,
they reach out to our industry partners,
and it's a way to bulk import all
contract personnel into our integrated
security management system since we
don't necessarily use DISJVS. Um,
>> yeah, what questions can I answer for
everyone today?
questions for DHS.
>> I have a question. You just mentioned
that um you guys don't use DISJVS. Is
the is is that the plan for you all not
to utilize this GBS JBS at all?
>> No, we use it. It's just not our primary
source. Our primary source is the
integrated security management system.
Um and we use DISJVS for reciprocity. Um
currently only TSA uses the NI2 portal.
Everybody else, all of the rest of the
components are currently using ESFS and
the ISM system.
>> So, is it is it safe to say based off of
what I just heard you say that um that
DHS information will not be in DISJVS?
>> No, we so we do we participate we put
our information in there. We do
participate in the information sharing,
but all of the case management occurs in
the integrated security management
system. So we share the information dis
JBS does have it. So for reciprocity and
transfer of trust it's available there.
That's just it's a uh
just a repository for us. It's not
active for case management.
>> Okay. Thank you.
>> Yes.
>> Any further questions?
>> All right.
Thank you very much.
Next, we will hear from Miss Monica
Marx, the director of the office of
departmental vetting and assistance at
the Department of Energy, who will be
providing their update. Monica,
>> thank you.
>> Do you have my slide?
>> Do you have
this is
So we um did anyone have any questions
for DOE?
>> Actually have a um not so much of a
question but more of a comment. Um I've
been receiving quite a few um questions
and concerns across industry as in
regards to DOE. I didn't have a lot of
time to uh to submit anything um you
know to give you time to be able to
research. But I do want to um to follow
up with you at a later point so that way
we can start to engage a little bit
better between DOE and industry NISPAC
uh to to address some of those concerns
that we've been receiving from some of
our industry um members.
>> Absolutely.
>> Okay. Thank you.
>> Did anyone have anything else?
>> Okay.
Next, we will hear from Mr. Michael
England, team leader for the security
operations team with the Nuclear
Regulatory Commission, who will be
providing their update. Mike,
>> good afternoon everyone. Uh, quick
update for the NRC. Um, first we want to
answer the industry questions. Uh, the
NRC went through a historic uh,
reorganization agencywide starting on
June 15th. So what that means for the
group is when it comes to training and
certain CIO u governance models we are
in the
act of uh trying to find uh bodies to
put in those positions. Our chief human
capital officer is working to fill
several vacancies.
So um so for industry we are not not
answering your question. we just don't
have anybody in the position to answer
your question. So, we're quickly trying
to work that out. And also, that goes
for industry also too when it comes to
our clearance timelines. They they went
up a little bit due to the amount of
vacancies we have to fill and we're
trying to fill new newly created
positions.
Um, that's all I have for the NRC.
Any questions?
>> Any questions for the NRC?
>> All right.
Thank you very much.
>> We are now going to hear from Miss Tracy
Brown, an authorizing official
representative for the NIST Cyber
Security Office. Tracy,
sorry.
Just kidding. I'm so sorry, folks. Got a
little bit ahead of myself.
All right, we're now going to hear from
Miss Brie Palmer again, the deputy
director with the Office of Security,
I'm sorry, with the Office of the Chief
Security Officer at the Department of
Homeland Security. Bri,
>> good afternoon again. Um,
so I know that for our industrial
partners, predictability and speed in
personnel vetting are critical to
staffing your programs and delivering on
your contracts. So today, I'm just going
to walk you through our fiscal year 26
quarter 3 metrics, focusing on how our
processing timelines and continuous
vetting programs are impacting the
cleared workforce. At the enterprise
level, DHS has completed 21,545
personnel vetting cases this quarter.
Looking at our overall timeline
averages, reciprocity is around 10 days.
Preliminary determinations average 25
days, and final determinations are
averaged at 100 days. For industry, that
10-day reciprocity number is the key
highlight. We're moving cleared
personnel into the system quickly on the
front end. Our total vetted population
currently stands at roughly 508,000.
Within that 323,000 are national
security eligible uh or the NYSE
category. We know that a significant
portion of this NYSE population relies
on your highly specialized and technical
engineering workforce. Uh on the
continuous vetting front, we're managing
a massive scale. Over 233,000
individuals enrolled in uh continuous
evaluation and over 285,000 in wrap
back. We processed over 500,000 alerts
this quarter maintaining an average uh
continuous vetting adjudication timeline
of 13 days. We're operating at a high
volume but the system is managing the
payload uh efficiently. Next slide
please.
Uh so this slide, oh go back one for me.
There we go. Uh this slide tracks our
entry on duty or EOD timeliness. Uh
overall the time for a favorable
onboarding determination increased from
35 days in quarter 2 to 41 days in
quarter 3 or excuse me 42 days in
quarter 3. Um, and in order to be
transparent, uh, I just want to let you
know what is driving that six-day
increase. Uh, first, we saw a massive
surge in complex national security
cases, which more than doubled, uh, from
79 in quarter 2 to 185 in quarter 3.
Second, the investigation timelines grew
slightly uh, across the board. Um,
however, when we break this down for our
contract workforce, the front-end
numbers remain highly competitive. For
contra for contractors, reciprocity
average just 13 days and preliminary
investigation determinations average 17
days. We know that your time to hire is
critical. These metrics show that if you
bring us a cleared candidate or someone
needing an interim approval, we are
getting them approved and onboarded in
roughly two to three weeks. The
bottleneck remains in the downstream
investigations which average 76 days for
contractors. While this is nearly a
month faster than the federal employees
of 103 days, we know that the delay
impacts your program readiness and it
remains a primary focus for our
leadership.
Next slide, please.
Uh so this slide details um more of our
EOD timeliness broken down by individual
DHS component. As you know, working with
different components within DHS can
sometimes mean navigating different
administrative cases. When reviewing
this component level data, we're looking
at both volume and duration to identify
our bottlenecks for industry partners.
The takeaway here is that we're using
this this data to identify outliers. Our
goal is to standardize the onboarding
experience so that your personnel
experience predictable, consistent
timelines regardless of whether or not
they're supporting SISA, CBP, TSA, or
any other component.
Next slide, please.
Uh, turning to our continuous vetting,
uh, I want to address how this impacts
the cleared contractor workforce. As
mentioned, we generated over 500,000 CES
alerts this quarter. However, I want to
draw your attention to the risk
distribution. 92% of these alerts are
classified as low risk. Only 6% are
medium risk and just 2% are high risk.
This should be highly reassuring to
industry. It demonstrates that the
transition to continuous monitoring is
is working exactly as intended. We're
successfully triaging a massive amount
of data without creating a flood of
false positive clearance suspensions for
your employees. We're also prioritizing
that 2% of high-risisk alerts for
immediate attention while processing the
low-risk alerts efficiently so they
don't disrupt your workforce.
Oh, that
next slide, please.
Uh, so this focus this slide focuses on
seed 3 self-reporting.
Um, we completed 18,000 self-reported
cases primarily driven by foreign travel
and financial disclosures. Uh we
appreciate the rigorous compliance
programs you've implemented within your
companies to educate your workforce on
Ced3. You're doing your report uh you're
doing your part to report these
activities. Uh our operational objective
and our commitment to you is to ensure
that our closure rate keep pace with
your incoming reports. We're actively
monitoring this pipeline to ensure these
self-reports are adjudicated quickly so
your employees clearances aren't left in
administrative limbo. Next slide,
please.
Um,
so to wrap up, DHS is processing vetting
at an immense scale and we are heavily
focused on protecting the rapid
onboarding pathways for our contract
workforce.
Through our quarter 3 data review, we
identified several administrative
challenges that we know cause friction
for industry. Specifically, inconsistent
tracking of reciprocity and legacy
legacy data errors caused by copying
inherent functions in our tracking
system. We know that these are exact uh
that these are system bugs that cause
cleared contractors to get stuck. Uh so
in order to fix this, we've ded we've
launched a data integrity action group
to clean up our data sets and we're
rolling out standardized sessions to
ensure reciprocity is processed
identically across every DHS component.
Um we're also looking at and evaluating
um Go ahead. Next slide for me. I'm
sorry.
Yeah, I think I skipped ahead. I
apologize. Uh, we're looking at uh
implementing AI to work with our data
cleanup. So, we're introducing AI to our
integrated security management system.
It's going to look for uh blank spots,
errors, um numbers that seem erroneous
or out of place, dates where there
should be uh text, text where there
should be dates. Um and we've got our
analysts actively going through those
those responses as we try to
standardize. Um this is just analysis of
the metrics from fiscal year quarter 26
quarter 2 to quarter 3. Um next slide
please.
And I already spoke to this slide again.
It's just our case data integrity data
entry and metric calculation and
reciprocity. Um
it's an ongoing process for us.
Next slide please.
Uh again data cleanup as I mentioned
we're using AI to go through these
reciprocity data issues. Uh identifying
where uh s special sensitive is
identified in a data set. However uh per
policy it the position should have been
preliminary determination. So, we're
seeing lots of errors and we're trying
to correct and standardize that. Um,
we're the intent is that we will be on
one standardized system by quarter 4 of
fiscal year 27. Uh, ISM will look the
same across the board.
Next slide.
All right. Thank you. Uh, does anybody
have any questions for me?
>> I have a question. Sorry.
um from um for um DHS, is there is the
plan for PVQ uh implementation in line
with the path that DCSA is going or do
you guys have a different timeline on
implementation?
>> No, we're on the same path as DCSA.
>> Okay, perfect. Thank you.
>> Further questions,
thank you again. Thank you.
>> Thank you.
We are now moving into the portion of
the meeting where we get reports from
the NISPAC working groups. You have
already heard from industry along with
the CSAs and CSOS on the highle points
of what was discussed during the NISSO
working group which took place on August
18th, 2026 and the clearance working
group which took place on June 24th,
2026. We have also heard from DHS.
In addition to DHS, we will also hear
from DOE and the NRC for their security
metrics along with DCSA for their
information systems and personnel
security metrics. One working group you
have not heard from is the newly
approved artificial intelligence working
group. It is expected to initially be
compromised uh comprised of those in the
NISSA working group. They have not yet
met but updates will be provided as
appropriate.
We are now going to hear from Miss
Monica Marx, the director of the office
of departmental vetting and assistance
at the Department of Energy, who will be
providing the metrics. Monica,
good afternoon again.
Okay.
Okay. So this is um the past year of
DOE's processing timelines. As you can
see, we did have a slight increase last
year based on um the workload um the
work the workforce change we had and the
lapse of appropriations.
However, we have recovered and we're now
meeting all of the former standards. So
just for this last quarter for top
secret clearances our initiate timeline
has been six days where the goal
currently is 14 days. The investigate
timeline by DCSA was 54 days where the
goal is 80 days and the adjudicate
timeline was 17 days where the goal is
20 days which made our average top
secret onboarding for initial 77 days um
versus the 114day goal for secret or
tier three level clearances. Um we
initiated within 5 days where the goal
was 14 days. Investigate 45 days um
where the goal was 40 days. Uh
adjudication timeline was 17 days where
the goal was 20 days bringing us to a 68
day total for favorable to onboard
versus the 74day goal. I've removed uh
the periodic reinvestigation timelines
as we've nearly eliminated that. But in
quarter four we did uh complete six top
secret PRs based on issues we found. Um
the initiate was 16 days,
investigate was 236 days and the
adjudicate was 281 days bringing the
total uh PR timeline to 533 days but
that was based on seriousness issues.
So, we've recovered from the shift in
workforce and the lapse of appropriation
since last summer and autumn and we're
now meeting all goals and working
towards the 2027 and 2028 PMIG goals for
both secret and top secret.
This slide will be provided. It's just a
monthly breakdown so you can actually
see where the times increased and you
can see what was going on across the
government at that time and how we
recovered.
So this one is for top secret. The next
slide is the same for secret.
Excuse me. So for continuous vetting
enrollment um we currently have 120,000
just almost 121,000 um national security
sensitive individuals enrolled between
the ODNI CE system and DCSA CV service.
We've also have um 57,000 nonsensitive
public trust I mean 57% of our
nonsensitive public trust individuals
enrolled um in DCSA CV service. Um our
total CV enrollment is 124,775
people.
So um we plan we are currently in trans
in transition from the ODNI CE system
completely to DCSA CV service
which we expect to be completed by the
end of this quarter this month.
So for continuous evaluation um alerts
for just one quarter we had 52,385
alerts. This is broken down by the seven
categories of information.
We expect this to decline drastically as
we transition from the ODNIC system to
DCSA CV service as they will do our
triage for us and validate the alerts
because a lot of the alerts are either
not valid to our individual or don't
meet an investigative threshold or it
was information already known to the
agency. So, we don't expect to have a
half a million alerts next quarter. Um,
and if we do, we hope to have it by the
second quarter of the fiscal year once
our transition is complete for our
national security sensitive population.
>> I think that's it. It is. Are there any
questions?
>> I have a question, please. Thank you
very much for that update. Um, you
mentioned changing over to DCSA CV
service. Um, how are you handling
wrapback enrollment? Are you also
seeking prints yourself or are you
leveraging the DCSA data?
>> So, we've always used DCSA. So, our
national security sensitive um
population has been fully enrolled in
DCSA for over two years now and we're
also adding our non-sensitive public
trust. So, where you saw that we have
uh 124,000 people enrolled in D um in
CE, that same population is enrolled in
rapback. When we enroll someone in CV,
we also submit them for rideback
enrollment. And understanding that DCSA
CV service is about to encompass
rightback and it won't be a separate
enrollment. We plan to still have that
um transition to be seamless.
>> That's great. And and just a quick
follow-up question um with regard we
heard from DHS on using um DISJVS to
just as a repository for data so that we
can share information for reciprocity.
How does that stand with DOE and NRC?
>> So for DOE, I cannot speak for NRC.
>> Yeah, I know.
>> But for DOE, we've always used CVS and
we hope that all of our data will
transition from CVS to DISJVS. We also
hope to be early adopters for all of the
shared services that DCSA offers.
However, we're working closely with
their system developers and OCS on um
ensuring that the systems meet DOE's
needs. But we do plan to use it as at a
minimum the repository and continue to
meet that requirement.
>> You're welcome.
Are there any other questions?
>> Okay.
>> All right. Thank you very much.
>> Thank you, Monica.
Next, we will hear from Mr. Michael
England, team leader for the security
operations team with the Nuclear
Regulatory Commission. who will be
providing their update. Mike,
>> uh, good afternoon once again. So, first
of all, let me start by saying I'm on
the physical security side. I can see
the personnel security side. So, if I
say something, please don't hold me
exactly to it because I don't want to
get them in any trouble. So,
>> um, next slide.
>> Okay. So overall overall agency
performance is trending in the positive
direction. Our quarter data shows
substantial reduction in processing time
for both top secret and secret
clearances. From FY25Q4
to FY26 Q3 our total average processing
time decline from 163 to 90 days for top
secret about a 45% improvement. and from
148 to 79 days for secret an improvement
of about 47%.
The largest um mover that contributed
the biggest improvement is our is the
investigation phase which fell from 139
to 49 days for top secret and 103 to 48
days for secret. Uh next slide.
Um as you can see though at the same
time um our workload increased
especially in our top secret arena and
increased to 195 as compared to 107 in
Q2 and 58 in Q1. We're contributing this
workload dealing deal uh to the reorg
reorganization and dealing with um
unexpected retirements from the agency.
So and bringing in new people to replace
those that retired. So that bumped our
workload.
Next slide please.
Um so as you can see for our top secret
our processing time improved for both
our top secret clearances and our secret
clearances. Our initial bunch we dropped
to we okay let me let me step back a
minute. For our top secret clearances,
we went to 84 days for processing a full
topseker clearance. And in our secret
clearances, we went down to processing
in 69 days.
The key takeaway from these slides is
our timelines have improved materially
on a quarterly basis from top secret to
secret. Even as our reported
adjudication workload increase, our
investigation timelines increase. one of
the biggest drivers that's kind of
pushing our numbers back in the wrong
direction. Our reorganization and our
hiring push, we're bringing on about 600
new people and we know that's going to
skew our timelines a little bit. So,
we're trying to plan for that and we're
trying to rightsize our workforce to
make sure we can meet this new uh
barrier that's coming our way. Um, next
slide. I think that's it.
Thank you. Any questions?
All right. Thank you very much.
>> I apologize, Tracy. We are now going to
hear from Miss Tracy Brown, an
authorizing official representative for
the NIST Cyber Security Office. Tracy,
>> thank you.
Good afternoon everyone.
As as Heather said earlier, I am Tracy
Brown. I am an authorizing official
designated representative for the NCSO
office at DCSA and I will be providing
of our updates. Currently, we're
overseeing a little over 4,300 systems
with an average authorization time of 58
days. And that's down from 65 um days in
2025.
Last month we started transitioning our
risk management framework controls from
this 800 53 which is for national
security systems um CNSSI 1253 R um
five.
As of August 17th we were tracking um
783 systems as migrating to RA 5. Um
since that time I'm sure um we have more
um but I can provide the
current update um later. In preparation
for the transition, BCSA performed
several internal and industry training
sessions to support rev five bread four
to five migration in coordination with u
working group partners.
We acknowledge the concern industry has
with accelerated transition timeline and
we ask industry um to remember that um
we do have RMF tools in the bank. um
that we can use um industries allowed to
pan uh teleontrols out with
justification
present mitigation strategy to meet the
intent of the controls or rest um risk
acceptance um from the customer. Um DCSA
continues to partner with our partners
as well as their customers um to ensure
that we can assist them to meet mission
requirements as part of our transition
plan.
Um all new systems authorized um
presented to us for authorization must
meet five compliance. Um systems
transition prior to our
um
July 30th date in process under RV 4
will continue through the process. The
authorizing officials can authorize
those systems up to 180 days. Right.
With industry having a mandatory
requirement within the 90 days to do the
administrative migration um workflow
um
workflow. Okay. Um systems.
Okay. Okay. So, the migration workflow,
this is an administrative update
um records and it does not require
industry partners to submit new
authorization workflows nor does it
impact current authorization statuses,
existing termination dates, system
details or assigned personnel roles.
what industry would have to do now for
all of their systems of record. they
will need to initiate the EMAs B vision
um five migration workflow.
Um a formal authorization workflow is
only required if
the system is seeking initial
authorization is approaching its
termination date or you have a security
benefit change that you need a new
authorization decision
in support of this transition. DCSA. Um,
we publish several reference materials
for industry to use and those reference
materials are found in our email section
under the help. We have other industry
engagements that we do meet with the
Nissa working group as requested to
discuss um challenges that people may
experience and we work to help um to
work through those challenges.
Just a little quick update on our pro
our core program.
We are 91%
complete of our goal um for the year. We
will we will meet all of our goals and
we have a 70% um pass rate today.
Questions?
>> All right, I have a question.
>> Okay,
>> we want to present you with a
>> Thank you for all of your amazing
support. You're welcome.
She deserves
a bad.
>> Thank you, Tracy. We are now going to
hear from Mr. Thomas Gian Koli, branch
chief, personnel security with DCSA for
their statistics. Tom.
Hey, good afternoon everyone. Quick
comms check. Can you hear me? Okay.
>> Yes, we can. Thank you.
>> Excellent. Well, good afternoon
everybody. Um, I will be providing you
can go ahead to the next slide, please.
I'll be providing some inventory and I'm
metrics for for all DCSA products and
services. There's a lot of information
here, so I'm not going to go through
every data point. Um but we will have
some time for for questions at the end.
So let's start with our investigative
and adjudicative inventory and that's on
the uh the upper left quad of uh of the
slide here.
So for the investigations program as a
whole, our current inventory stands at
approximately 130,000 cases.
uh again not just for industry but just
in general 130,000 uh cases which is a
decrease of 41,000 cases or 24%
reduction for FY26.
We also have approximately 34,000 issue
resolution cases. And what that means is
so for our continuous vetting service
that we offer, we are conducting issue
resolution based off of TWW2.0 appendix
I requirements and that again that
inventory is about 34,000
uh cases that we're we're working
through and and conducting those
additional investigative actions based
on the on the policy in CW 2.0.
In terms of DOW industry
community
um investigation inventory of the tiered
cases stands at 19,000 which is 7,000
tier fives and 12,000 tier three cases
within uh so during FY26 this inventory
has uh decreased by 5,000.
So, I'm not going to get into the
specifics on why the inventory has
decreased for uh within DCSA as as a
whole and specifically for industry
community. But there's there's a few um
largecale initiatives that we we
undertook over the last year or so that
that have contributed to this reduction
in inventory. One of them is the early
integration of TWW2.0 standards. um a
few initiatives, coverage requirements
that that we implemented ahead of the
target dates as as uh provided by by the
EAS that that was a a significant
contribution to the reduction in
inventory. The elimination of PRs, which
I' I've heard from a couple other
departments and agencies is is something
I think that this is a governmentwide
initiative. Uh so elimination of of PRs
and uh I will say beginning in uh as of
this July all requests for PRs have been
sunset and I know for the industry
community that happened I think in FY24.
So uh and then uh expedited screening uh
this this is a a process that we've
we've implemented to to uh help with our
uh closing of of cases. It's again
detailed the process. I'm not going to
get into right now, but all of these
initiatives have really contributed to
that reduction in in our inventory.
I will say that um despite the inventory
decreasing for FY26 overall, there has
been an uptick uh within Q3
which is primarily due to the elevated
request for the initial vetting uh in uh
scenario investigation that we've
received since um since February and
this includes industry as well. So we
have seen a a slight uptick in the
request for Q3 but overall again
inventory is still down.
Okay. So we can move to timeliness now.
Uh and I will I think I provided this
during the CWG meeting in June but this
is it's an important consideration to to
understand is that so to align with the
uh performance vetting I'm sorry
personal vetting performance management
standards implementation guidance. So
this is the PMIG. These are the
timeliness metrics that are identified
and established by the EAS. So be to to
align with that we have um changed how
we are reporting timeliness. Uh it used
to be the fastest 90%
based on the PMIG we have moved to
overall average. So again something to
to consider as you're looking through
the the timeliness and if you see any
changes over the last year or so that's
a requirement uh that was in the
national level policy.
So, what I'll do is I I know we're kind
of running short on time and and there's
a few other um presentations. So, I I'm
going to focus more on the Q3. So, the
the current timeliness as opposed to
historical timeliness for we'll go with
the initial top secret and then the
initial secret. So, T5 and and T3. Um
so, for the T5 initial investigations,
FY26 Q3, uh you can see the initiation
timeline is 20 days. The investigation
timeline is 97 days and then the
adjudication is 126 days for 243 days
total. And then for our um tier three or
secret uh we have 21 days for the
initiation, 59 days for the
investigation and 117 days for the
adjudication for a total of 197 days.
So that is all the information that I
was going to share. I can try to answer
any questions if there are some
>> questions.
>> Yes, I have a question.
The um CV resolution uh cases, would you
happen to have metrics on um how many
cases you've received? I think DOE did
an amazing job capturing like all of
their um the CV ca, you know, the alerts
they've received and what category they
they kind of fell into and how quickly
they are resolving them. would you
happen to have data on or metrics on
that?
we we are we are trying to obtain uh
more information more data uh on CV just
in general but but yes we we're looking
to that and I will say that um as far as
industry TWW 1.5 CV service enrollments
um I I believe industry is 25% of our
enrollment population which and again
we're still working on on finalizing and
confirming this information but it's
approximately 98 84,000 uh enrollments
into CB. But I think what you're
specifically asking is a breakdown of uh
the the alerts potentially what what
area or information category of trigger
may have been identified by that alert
and then what additional investigative
action is required? Um is that correct?
>> Well, yes. And in addition to that, how
long is it taking you to resolve those?
Which um and and that question is being
driven by the concerns from industry in
regards to how long it's taking for um
for those issues to be resolved, which
is impacting us being able to get people
onto mission.
>> Got it. Yes, I I got you. We we will we
will try and get some in some data on
that. I and I will say so we we are
shifting how we vet individuals from
that static five year periodic
reinvestigation to a continuous flow of
information and this isn't new to
anybody. I'm sure we're all familiar
with this, but but I say that because
these individuals who are being enrolled
into a CV service, and just just the
industry population alone is is close to
a million. Um these are individuals
who've been in service, who are who are
trusted insiders, who are trusted
individuals who may not have um
interacted with the government for a
personal vetting purpose for quite some
time. Not only that, but but these
individuals may longer be no longer be
affiliated with whatever government
service that would have required them to
have that position of trust. I I say
that because that's one of the the
challenges that we're we're facing is is
trying to contact these individuals
because we have a CV alert for for an
individual who who may no longer be in
in a position of of trust or may not
have been uh contacted or or had to I
know within the policy they're required
to update their their SF86 or SF85P
prior to enrollment into CB service, but
that doesn't happen all the time. So
those are the challenges. Um but but
either way we are we are trying to get
some more data on on the CV service that
we offer to include the alert management
issue resolution process.
>> Thank you for that and the challenges
are definitely understood. However, I
would like to emphasize that in some um
in some scenarios, these individuals are
people that have continued access and
when they are attempting to uh to
transition to new positions, new roles
under new programs or new mileps,
whatever, wherever they're going, SAPS
in particular, if there is an open case,
then all all bets are off. The
processing stops and they are no longer
considered for that role. And um the the
concern is that when that is addressed
um with um DCSA, it uh there there's
really no SLA or no time frame that's
given on when this when the issue can be
resolved. So uh we're seeing quite a
delay in being able to get people on
because of those very reasons. So um
that's why that's why the the question
about metrics and understanding how you
know how quickly are you guys resolving
these these concerns and I again I do
understand the uh the impact with being
able to get in contact with people and
things like that. Um I would encourage
you because what we are seeing too is
that uh some of those contacts are being
sent directly to the uh to the
individual. Um, and I'm not sure when
that when that shifted or when that
changed. Um, you know, taking the FSO
out of that equation and kind of putting
them on the back end versus on the front
end. But I would encourage DCSA to
consider um going back to what was
working and put the FSO or the uh
security officer at the beginning of
that process with notification that you
are trying to reach set employee instead
of uh on the back end when it's when
it's impacting uh being able to get the
person on mission.
Yeah, that's excellent feedback and I
will say we do we do have a process for
for notification when when there is a
seer but understood. I took notes of
what you just recommended but yeah I I
appreciate that feedback. Thank you.
>> And one two small footnotes to that. um
when the work is being done to first
verify in the system of record whether
an active affiliation exists um that is
a part of this and reaching out to the
right people and ensuring that that the
work can be done to adjudicate it but
also I'm curious if we're able to drill
down into the metrics to understand um
the types of reports that are being
worked but to also understand the subset
of um issues that are coming from the
wrapback enrollments that occurred
earlier on this
I just took a note of that as well.
Thank you.
So, yeah, def definitely some
enhancements I I I'd say that we're
we're working on on on getting getting
those those data points and metrics for
for CV that that is something that that
I can take back and and look into.
>> All right. And you're not off the hook
yet. We have at least one question for
you from the chat. So, uh let me ask you
this on their behalf. Do you have any
data on how many initial PCL submissions
are rejected?
>> I'm sorry. Is that is that a question
from me?
>> You're the You're the
>> I didn't hear the first part of that.
>> Let me uh let me give it to you again.
Yes, you're the man on the hot.
>> Okay.
>> This is a question from our online
audience.
Do you have any data on how many initial
PCL submissions are rejected?
>> Any any more information? Uh who who
provided that? Greg, I believe. Um any
more information on what it is that
you're looking for as far as those PCL
submissions? That that would be helpful
so that we can track down what data
points we we may need. it it may be
included um depending on the scope of
that it may it may already be included
in in those data points that we're
looking for anyway as as CVI as a whole
but anything else you can provide as far
as specifically what you're looking for
as far as the the data on those PCL
submissions would would be helpful
>> so if I could if I could provide some
clarity what he's asking what the online
um person is asking is do you have
metrics on the rejections of those PCL
cases
>> no
>> like how many are are rejected
I I think we do. Um and and I need to I
need to maybe level set with what what
PCL
what what population of of cases that
represents
um before I can say for sure. But yeah,
we we do have as as far as cases that
may be rejected back to the department
or agency or industry partner. Um they
they may be rejected back for a number
number of reasons, but there there
should be some data on that.
But again, I I so any any supporting
information you have, I mean, it's
there's a lot of data. We just need to
know what it is that we're looking for
specifically
before I can start requesting that data.
>> Thank you. You have something Andy?
>> Uh this is Annie Bakis, Department of
the Air Force. Um this is something I
think we we should take back. Certainly
an interest on the government side as
well for investigation requests whether
it's TOC 3 or T5 for both government and
industry. What is DCSA's rejection rate?
Great. Thank you all very much. Any
further questions?
Thank you, Tom.
Now we will hear from Perry Russell
Hunter, the director of the Defense
Office of Hearings and Appeals. Perry,
please come on up.
>> All right. So, I want to start out by
thanking uh Michael and Heather for
another great public meeting. Uh very
very well run. Thank you. U I I also
want to say for our our departing
members um and I I see that well I first
of all I want to say thank you for being
um such a great voice of industry. U
you've been you've been wonderfully
vocal in all the right times and uh from
where I'm sitting. Jane. Uh, I Jane and
I I have to confess I have the honor of
having worked with Jane in one capacity
in her many important jobs over more
than 30 years.
First met Jane uh as a result of a a
Doha hearing because uh I was calling
her as a a witness and uh she did a
phenomenal job and it was also I I
recall the witness prep session was in
an Olive Garden. it was
but uh she did a she did a marvelous uh
job and that and and and everything
before and since she's one of one of the
real stars in in that organization and I
just want to say thank you so much for
your professionalism and partnership and
vigilance and all the things you've been
doing.
>> Thank you.
>> Um and then uh finally uh Jeff uh if
you're still in the room and if you're
not then I completely understand why.
Um, I I uh I I noticed that that Jeff
emphasized uh cander and transparency
and uh as being part of the uh the
gestalt of the the NISPAC. And I I I
want to say that uh in that spirit, I'm
going to do a thing I've been doing in
multiple successive NISPACs, which is to
give you my phone number, which is 703
>> 6964751.
That number rings on my desk. Nobody
answers it but me. The reason I do this,
and I know you must all think I'm crazy
for doing this, is that I get questions
from FSOs, working FSOs who identify
real problems. Uh, and the numbers I'm
about to give you, by the way, for Doha
are infiniteesimally small compared to
the numbers that all of the previous
speakers have have given you. And that's
because these are only uh the cases in
the administrative process for denial of
revocation. And so uh this is this is
well within the 2% that that require
that uh that action. But at the last
public NISPACK meeting uh and thanks to
uh an innovation by uh Michael and
Heather, these meetings are now posted
on YouTube and uh I had the uh the honor
of getting a phone call from a working
FSO who said that he had not been
present for the NISPAC meeting but that
he had seen uh the NISPAC meeting on
YouTube and uh so it's working uh and he
he called my number uh as I had as I had
hoped And I learned through that call
about a what was for him a mystery. And
of course then it became a mystery for
me to solve about why it was that
somebody was saying that a case had been
at Doha for two years that we had in
fact never received. And it turned out
we were able to identify a process
glitch between us and DCSA on on
reapplications which uh in the the
following month we were able to uh have
our first ever Doha help desk at NCMS
which was uh in part due to the fact
that we'd initially heard that DCSA
wasn't going to have a help desk and
then they ultimately did at the last
moment but we were able to have a help
desk right alongside DCSAs which was
super helpful because we were solving
problems together which is really the
way government is supposed to work. And
so I want to say first of all, thank you
to DCSA for being such great partners
because we really do solve a lot of
things on uh the the individual case
level by by working together.
That said, Doha is uh exists to provide
a fair, consistent, and transparent
hearing and appeal process that is
independent of DCSA's investigative and
adjudicative process. Um, in fact, the
uh Department of War's general counsel
and now the Justice Department's Office
of Legal Counsel have specifically uh
opined that it's the the investigating
entity cannot also hold hearings. So,
that solves something that had been um I
I didn't really think it was an open
question, but it's now been it's now
been resolved. Uh I I think uh it's it's
also important to know that uh we are
able uh as we begin the the industry uh
denial revocation process uh DCSA and
Doha work handinand glove on the
issuance of the statement of reasons
which is the first notice to an industry
employee that uh there is an issue. Uh
and so our our independent role in the
collateral uh industry contractor
process begins with the legal review of
the that statement of reasons. And at
this point in in this fiscal year, which
is almost over, uh Doha will have
conducted over 1,200 U legal reviews of
statement of reasons. See, I told you
those numbers were going to be super
small compared to everything else you've
seen.
But we have received almost double the
draft statements of reasons in the last
five months than we received in the
first six months of uh fiscal year 2026.
And uh we're we're still keeping timely
by the way because the the the number
had been low um and it's it's now
increasing which is is by the way proof
of something that both Tom and Allison
talked about which is the the mitigation
strategy for the the investigative
inventory and bringing that inventory
down. Uh typically we at Doha when when
DCSA brings their investigative
inventory down it means that they're
working the harder cases and of course
it's the harder cases that are coming to
us. So, so I I I can stand here and
attest to the fact that what Tom and
Alison have told you is true and and
that that workload really is coming down
because we're seeing we're seeing the
cases that we should see when that
happens.
Uh by the way, uh one of the reasons
that we are still able to to keep timely
in our legal reviews of those statements
of reasons is that uh we at Doha work uh
seamlessly with DCSA in uh a a paperless
uh transfer and review process. So it it
is there it's not like there's a there's
a a box of statements of reasons, you
know, coming down the the BW Parkway
from Fort Me to to Doha, as was as
actually was once the case. Uh bless
bless you. Uh but it's now uh it's now a
uh by the way, there's an old European
tradition that uh you sneeze when
someone's telling the truth. So So thank
you.
Uh I I wanted to uh I I I wanted to
stress that that uh ability for us to
work so seamlessly with DCSA
uh on the the legal reviews and and and
be completely paperless. Uh I owe a debt
of gratitude to now a former DCSA
employee, Heather Green, who made sure
that that we we got that done. So I want
to say just a shout out, Heather, if
you're listening. U thank you for that.
Um so the other thing that uh I can I
can report is that uh Doha
administrative judges have u just 390
cases on hand to decide and have
completed over 1,200 in fiscal year 2026
and that's again a a a lower than
average workload. though we are uh we
are able to keep uh timely that way as
well and and in fact uh as you probably
know uh most uh not more now more than
90% of our hearing cases are conducted
virtually over teams and so uh we are
able to uh get to your case faster get
your case heard faster and decided
faster as a result of that.
So, I I I wanted to um close by saying
uh again how much I appreciate the
opportunity to speak with the NISPAC and
to be accountable to you all for what it
is we're doing at the tail end of the
process. Again, the numbers are small,
but that doesn't matter when you're one
of those numbers. when when you're the
person who receives a statement of
reasons and you're notified that the
government has a concern, uh that
process is has to be done with integrity
and fidelity and consistency, be
transparent and also independent of the
investigation and I'm proud to say that
we are doing all of those things. So
with that, I will take questions. Thank
you.
>> All right, questions for uh for Perry.
Hi Perry. Um,
>> can you explain for industry's benefit
what Doha's part is if any in the
revision of seed 4?
>> Uh, I I wish I could tell you. Uh I I
will say that uh with
con I have been consistently involved on
behalf of Doha and the office of general
counsel and the the department generally
in the the updating of the adjudicative
guidelines for now almost 30 years
certainly certainly 25. uh this is the
first time in the history of my time
doing this and given you know who we are
at Doha we see a lot of cases and just
as I was able to say yep we we can we
can attest that the investigative
workload is coming down because we're
seeing the cases we should see when that
happens I I can also say that we have
been able to contribute to Ced4
revisions because of what we see and and
you all in industry of course can and
should as well because of what you see
because of in your workforces you're
seeing trends. Uh the it was interesting
though one of the slides uh about the
continuous vetting hits uh was was quite
informative because you see the enormous
number for example that are uh financial
that are are are credit reports and and
public records is up there but then
criminal it turns out is super low. uh
those are all things that uh are we
learn because we have these meetings, we
have these discussions and uh and I can
tell you that recent that revisions to
seat 4 uh that became effective in uh
you know now nine years ago
were uh were in in large part informed
by our shared experiences in
adjudicating and hearing cases uh
applying the guidelines. And of course,
the Doha appeal board is the one place
in all of government where you can see
published decisions that where we show
our work that show how the adjudicative
guidelines are applied to real cases.
And of course, we're we anonymize them
so nobody you can't tell who it is, but
you can tell what was done. And so, uh,
there are now about 38,000 cases on the
Doha website, uh, dating back to
November 1st of 1996, which is when we
first started doing that to comply with
the electronic FOYA amendments, by the
way. Uh, and so we have been
uh able to to track the the trends and
and we definitely um have some comments
to offer should that become uh should
that become possible.
So, not yet, but still hopeful.
>> So, Perry, going to the chat, uh, our
colleague Lisa Perez from OD and I had a
question for you. She says, "Going back
to the legal opinion that you
referenced, where and why did the
question originate and what led to the
endeavor that resulted in the opinion?"
>> Okay. So
there is a provision in executive order
12968 which makes it clear that the
investigating entity cannot also hold
the opportunity to appear personally or
what I've been in shorthand calling a
hearing.
The reason for that and I'm going to
paraphrase uh honorable uh Matthews our
our general counsel uh who said you know
the the investigator shouldn't be judge
jury and executioner. there needs to be
some administrative separation. And so
that's that's been well understood for
for fully 30 years. Now what was less
well understood was where how thinly
that uh that interpretive salami was
going to get sliced. And so the the
question was was raised within the
department. I'll be I I won't be any
more specific than that. The the the
question was raised within the
department. uh the general counsel
answered it and as the chief legal
officer of the department, the honorable
Earl Matthews gets to answer that
question. U additional questions were
asked and therefore the office of legal
counsel at the department of justice was
consulted and yes I am using the passive
voice.
>> Noted I'm just I'm still clinging to uh
your salami record. Well, well, so but
but I think sort of lurking within your
question is uh the the question of scope
and the OLC opinion is and by the way we
we published that on our website, you
know, because because the the general
counsel ordered us to uh we have uh you
will see that it is it only applies to
the department of war. It does not apply
more broadly. So it is because because
what happens the way by the way the
office office of legal counsel is a
wonderful thing. You get to ask them
questions and they will answer. And in
your agency gets to apply them. And so
in this case, because it was the
Department of War that asked, the
Department of War, it got the answer.
And the answer only applies to the
Department of War. Very much further
questions.
>> All right. Thank you.
>> Thank you very much,
>> gang. You did it. We're now we're now at
the the time of the meeting where if
there's any additional new business that
anyone would like to bring forward floor
>> I got something
if you didn't indulge me for a moment.
So I'm about to do something I don't
like to do especially in public and it
say something nice about Ike.
So uh as our spokesperson he got to
stand up there say nice things about
Jane, nice things about Jeff. So I
thought it was appropriate that we make
up some nice things to say about you. Uh
so if you don't know as spokesperson,
one of his many jobs is to reach out to
people that have been nominated and gone
through the election process to be on
the NISPAC. And so a couple years ago he
gives me a call and I answer it. Say
hello, no hello. No how you doing? His
his question immediately, are you ready
to go to work?
Are you ready to go to work? I'm like
you're not even gonna say hello. That's
all he wanted to know because that's all
he cared about. And man, he wasn't
kidding. Uh there's an expectation if
you're on the Nispack that you're out
there. you are working hard to support
for industry, our customers, and most
importantly the the war fighter. And he
absolutely leads by example from that
whether it's meetings, calls,
everything. Uh he's there all the time,
which can get annoying sometimes, too.
But, uh there's no doubting his
dedication. There's a lot of things to
like about some things that'll drive you
crazy, but there's a lot of things to
like. Uh the thing that I appreciated
most, and I think many in the group do,
is his willingness to listen. uh even if
he doesn't agree, he wants to better
understand. Uh and it made us better, it
made our group better, made our
relationship better, and we appreciate
you. Uh it made you successful, made us
successful, and thanks for uh letting us
be part of your family.
>> ABSOLUTELY.
Don't give Ike the mic.
>> Well, oh,
um, I'm not afraid. You know, they say
men, you know, shouldn't cry. Listen,
man. I'm an emotional individual. My
mother was an emotional individual. I'm
compassionate about this. You all got
compassion, but I'm really compassionate
and emotional because the feeling that I
get from Chris and the rest are genuine.
I know fake, right? I know fake. I'm a
New Yorker. I'm a hustler, right? So, I
know when I see something that's fake
and the genuiness between everybody in
here in the industry has been real and I
appreciate that. But before I go, I'm
going to leave you with something um
that um the group probably didn't know I
was going to say and I didn't know I was
going to say, but I'm going to say it
anyway. Um a couple of years ago,
industry NISPAC, we sat around a table
and we talked about how we can give back
to the community. Um, and when we say
get back to the community, we're talking
about the DIB, the the defense
industrial base, those security
professionals out there that do the work
day in day and out, right? Most of us
are seniors, right? We get to have the
oversight, but those individuals, what
are we giving back to them, right? What
is industry in what is industry NISPAC
giving back to the community? And so um
uh over the summer, well early on this
summer, um we got together, the group
got together and we said, "Hey, let's
create a NISPAC industry award for
security and excellence um for
industrial security professionals." So
I'm here to announce today that in 2027,
we will be passing out that award to
some lucky representative. industry
NISPAC talked it over with ISU Mike and
and Heather and they love the idea and
so we have a NISPAC award working group.
I chaired a working group but the
working group is for all former NISP
pack members and some of them are here
now. Greg Satler is on the working
group. Tracy Durkin is on the working
group. Derek Jones is on the working
group. Quinton Wils is on the working
group. Heather Sims is on the working
group. Michelle Lambieza is on the
working group. Rosie Barrera Jones is on
the working group. Cheryl Stone is on
the working group. And old school Tom
Langanger is on the working group.
Right? And so these are all former NIS
pack members that are on this particular
working group. And we're so honored that
we can give something back, right? And
so when you talk about legacies and what
you leave on the table, right, we just
want industry to know that we understand
their pain. We understand their
victories and we just want to do
something to give back. I want to give a
big shout out to uh Miss Trish. Uh she's
the president of the NCMS and she's our
industry misspackou. She's going to
allow the NCMS a venue for us to
actually um pass out that particular
award. But this is not a DCSA centric
award. This is for all the in this is
for the entire DIB, right? And so we're
going to be reaching out to the chair of
NDIA, the chair of ISWIG for those
individuals that maybe not go to NCMS
but maybe just go to NDIA and we're
going to f we're going to find them and
take that award to them. So there's
going to be more information coming
about that. But this group, this body
right here cares about industry and
about the government. But we we love our
we love the industry and we want to give
back. So, I want to thank the group for
taking the vision that we had a few
years ago and then just putting it out
there on the surface now. So, thank you
everybody. I appreciate y'all.
>> Does anybody else have anything nice to
say about I
think
>> Well, in closing, I have two things to
share. One is that our next meeting will
be right back here on March 17th. got a
lot of work to do between now and then,
a lot of questions to answer. So, uh,
and I'd be remiss if we didn't close in
thanking one more time Jane Ike, not
just for their service to the NISPAC,
but for their service to this country
country. Both of them had long and
distinguished careers in different
aspects of public service and uh, we are
very very grateful for that as well as
for the work that you've done.
>> Mike, by the way, I miss Jane. Jane is
also on that working group because we're
both uh as of one October, we'll be both
former NISPAC uh industry members.
>> I tried to get out
>> and they keep pulling me back in.
>> All right. Thank you everyone and thank
you to the ISU staff who facilitated
this meeting today. So many of them were
here amongst you doing different jobs
that are outside of the regular
portfolio. And most of all, thanks to
Heather Vaggon for bringing us all
together.