Section 847 Proposed Rule — May 7, 2026: FOCI requirements expanding to ~37,740 unclassified DoD contractors. Comment period closes July 6, 2026. What this means for you
DCSA • Updated May 2025 • Section 847 Expansion

The SF-328: What Every
Defense Contractor Needs to Know

The SF-328 (Certificate Pertaining to Foreign Interests) is the form DCSA uses to evaluate whether your company has foreign ownership, control, or influence — and what to do about it. It was overhauled in May 2025. Section 847 is about to require it from 37,000 contractors who have never seen it. This is your complete guide.

9 Questions Updated May 12, 2025 CUI when completed Avg. DCSA processing: 155–266 days

What is the SF-328?

The Standard Form 328 — officially the Certificate Pertaining to Foreign Interests — is the primary form the Defense Counterintelligence and Security Agency (DCSA) uses to evaluate Foreign Ownership, Control, or Influence (FOCI) in defense contractors.

When you submit an SF-328, you are telling DCSA everything about who owns your company, who controls it, and whether any foreign nationals or foreign entities have the ability to influence how it operates. DCSA uses this information to determine whether your company poses a national security risk — and if so, what mitigation is required before you can access classified information or, under the new Section 847 rule, perform certain unclassified defense work.

The form was significantly updated on May 12, 2025 — the first major revision since 2018. The new version is now mandatory for all submissions. When completed, it is classified as Controlled Unclassified Information (CUI) and protected from FOIA disclosure.

Key fact: Submitting an SF-328 does not mean you have a FOCI problem. The vast majority of companies that submit one receive a favorable determination and proceed with their FCL application. The form is a disclosure tool, not an accusation.
Official name
Certificate Pertaining to Foreign Interests
Administered by
Defense Counterintelligence and Security Agency (DCSA)
Current version
May 2025 (9 questions + 6 pages of instructions)
Submitted via
National Industrial Security System (NISS)
Classification
CUI when completed — protected from FOIA
Regulatory basis
32 CFR Part 117 (NISPOM) + Section 847 NDAA FY2020

Does your company need to submit an SF-328?

Two separate tracks. Know which one applies to you.

Current requirement

Track 1: Facility Security Clearance (FCL)

You must submit an SF-328 if your company is:

  • Applying for an initial Facility Security Clearance (FCL)
  • Upgrading an existing FCL to a higher classification level
  • Submitting a changed condition package (ownership change, new foreign investor, M&A activity, KMP change)
  • Renewing a FOCI mitigation agreement

This has been required since the NISP was established. If you hold an FCL today and have not submitted a 2025-version SF-328, you will need to when your next changed condition or renewal occurs.

Incoming — Section 847

Track 2: Unclassified DoD Contracts over $5M

Under the proposed DFARS rule (May 7, 2026), you will need to submit an SF-328 if:

  • You are bidding on a DoD contract or subcontract valued over $5 million
  • The contract is non-commercial (FAR Part 12 commercial exceptions apply)
  • You are a subcontractor at any tier on a covered prime contract over $5M
  • Your prime contractor flows down the DFARS clause to your subcontract

Comment period closes July 6, 2026. Final rule expected late 2026. Compliance required within 90 days of contract award once finalized. Start preparing now.

Section 847 Details

Common events that trigger an SF-328 submission

🏢Initial FCL application
💰New foreign investor (any %)
🤝Merger or acquisition
👤Foreign national joins board
📊Foreign ownership crosses 5%
🏦Foreign bank financing (15%+ revenue)
🎓Foreign endowment or gift received
📋$5M+ unclassified DoD contract bid (Section 847)

The 9 Questions — What DCSA Is Actually Asking

The updated 2025 SF-328 consolidated 10 questions into 9 and significantly expanded the instructions. Here is what each question covers and what trips companies up.

Q1

Foreign ownership — 5% threshold

Does any foreign person, entity, or government own 5% or more of any class of your company's securities or voting interest? This question was expanded in 2025 to require disclosure of the entire beneficial ownership and control structure for any entity holding 5%+. Nominee shares and street name holdings previously in Q8 are now consolidated here.

Common issue: PE/VC-backed companies with foreign limited partners often undercount here. Each foreign LP must be traced.
Q2

Foreign control of board or management

Do foreign persons hold board seats, officer positions, or other positions that give them the ability to direct or decide company policy? Includes foreign nationals on advisory boards with meaningful access to operations.

Common issue: Foreign national founders who remain on boards post-acquisition are frequently overlooked.
Q3

Foreign government interests

Is any foreign government, or entity owned/controlled by a foreign government, involved in ownership or control? Sovereign wealth funds, state-owned enterprises, and government pension funds all trigger this question — even through intermediary entities.

Q4

Technology licensing and intellectual property

Do you have licenses, agreements, or other arrangements with foreign entities that give them access to your technology, technical data, or intellectual property? This includes source code escrow arrangements and joint development agreements.

Q5

Foreign financing and debt

Are you indebted to a foreign person or entity? Includes loans, lines of credit, bonds, and other debt instruments. The 2025 update expanded this to cover arrangements that give foreign creditors covenants or consent rights over company operations.

Q6

Foreign contracts and sales arrangements

Do you have contracts, agreements, or understandings with foreign persons that give them a right to appoint personnel, influence management decisions, or receive preferential treatment in business decisions?

Q7

Foreign revenue, gifts, and endowments

Do you derive revenue, net income, gifts, tuition, or endowments from foreign sources? The 2025 update lowered the reporting threshold from 30% to 15% of total revenue or net income, and added tuition, gifts, and endowments to the list. For contractors, focus on revenue concentration from foreign customers.

Key change: The threshold drop from 30% to 15% catches many more companies than before.
Q8

Key Management Personnel (KMP) with foreign affiliations

Do any of your KMP (directors, officers, and others who influence management) hold positions with foreign entities? The 2025 form adds a supplemental FDFA (Statement of Full Disclosure of Foreign Affiliations) for each KMP with foreign affiliations — a two-page questionnaire covering the nature of the foreign role, length of association, and degree of operational involvement.

New in 2025: The FDFA supplement significantly increases the burden for companies with internationally mobile leadership.
Q9

Other foreign interests

A catch-all for any other foreign interest, arrangement, or relationship not captured above. DCSA uses this as a prompt for companies to disclose anything that a reasonable person would consider relevant to a foreign influence assessment — even if it does not fit neatly into questions 1–8.

Best practice: When in doubt, disclose. Omissions are far more damaging to your DCSA relationship than over-disclosure.
The CUI designation matters: The completed SF-328 is Controlled Unclassified Information. Store it in a system that meets CUI handling requirements. Do not email it unencrypted. Do not store it in commercial cloud without appropriate CUI controls.

Section 847: FOCI Is Coming for Uncleared Contractors

📢
Proposed DFARS Rule published May 7, 2026. Public comment period closes July 6, 2026. If finalized, this rule will be the single largest expansion of FOCI requirements in history.

Who it affects

  • Any company bidding on DoD contracts over $5 million
  • Subcontractors at any tier on covered prime contracts over $5M
  • Companies that have never had a facility security clearance
  • An estimated 37,740 entities — 57% small businesses

What it requires

  • Submit SF-328 via NISS before contract award
  • Maintain eligible NISS status throughout performance
  • Implement DCSA-directed mitigation within 90 days of award
  • Report ownership/control changes within 3–10 business days
  • Flow down requirements to covered subcontractors

What is exempt

  • Contracts at or below simplified acquisition threshold
  • FAR Part 12 commercial products and services
  • COTS items (unless designated a national security risk)
  • Contracts not covered by the DFARS clause

Timeline

  • May 7, 2026 — Proposed rule published
  • July 6, 2026 — Comment period closes
  • Late 2026 est. — Final rule expected
  • 90 days post-award — Mitigation implementation deadline
  • Now — Time to assess your ownership structure
What to do right now, before the rule is finalized:
  1. Map your beneficial ownership structure — identify any foreign persons or entities with 5%+ interest
  2. Review your board and KMP for foreign affiliations requiring FDFA supplemental disclosures
  3. Check your revenue sources — are any foreign customers approaching the 15% threshold?
  4. Assess whether your existing technology licensing or debt arrangements involve foreign entities
  5. Brief your CEO, CFO, and General Counsel — this requires C-suite involvement
  6. Consider submitting comments to the proposed rule by July 6, 2026 if the requirements affect your business

What happens after DCSA receives your SF-328?

1

DCSA review

DCSA reviews your submission for completeness and accuracy. The 2025 form was redesigned to reduce back-and-forth by requiring more information upfront. Expect DCSA to contact you if clarification is needed — respond promptly, as delays count against your processing timeline.

Timeline: Varies — incomplete submissions add weeks
2

FOCI determination

DCSA makes one of three findings: (A) No FOCI — proceed with FCL application, no mitigation required; (B) FOCI exists, mitigable — mitigation agreement required before FCL can be granted; (C) FOCI exists, not mitigable — FCL cannot be granted (very rare).

Processing: Avg. 155 days (no FOCI) • 266 days (FOCI, Tier 2) • 263 days (full mitigation)
3

Mitigation negotiation (if FOCI found)

DCSA will propose a mitigation instrument. Options range from a simple Board Resolution (least restrictive) to a Special Security Agreement (SSA) or Proxy Agreement (most restrictive). The right instrument depends on the nature and degree of foreign ownership and the classification level of work you intend to perform.

Negotiation: 30–90 days typical
4

Ongoing compliance obligations

Once a mitigation agreement is in place, your obligations do not end — they begin. Annual GSC compliance reports, self-inspections, DCSA vulnerability assessments, changed condition notifications, and document library maintenance are all recurring requirements.

Recurring: Annual reports • Annual self-inspection • Periodic DCSA visits

FOCI Mitigation Agreement Types

Board Resolution
Least restrictive

Foreign ownership is disclosed but the foreign parent agrees not to exercise control. Used when foreign interest is limited and passive.

Security Control Agreement (SCA)
Moderate

Foreign parent has minority ownership. US-citizen board majority required. Annual compliance reporting to DCSA.

Special Security Agreement (SSA)
Most common for majority foreign-owned

Foreign parent owns majority. Government Security Committee (GSC) of US-citizen directors required. Most extensive compliance obligations including ECP, TCP, AOP.

Proxy Agreement
Most restrictive

Foreign parent's voting rights held by US-citizen proxy holders approved by DCSA. Reserved for highest-risk situations or Top Secret level work.

Need help with your SF-328?

Fulcrum Advisory has experience with FOCI compliance across the full lifecycle — from initial SF-328 assessment through mitigation agreement navigation, ongoing compliance management, and DCSA engagement preparation.

  • SF-328 review and gap analysis
  • Beneficial ownership mapping for complex structures
  • FOCI risk assessment and mitigation type recommendation
  • ECP, TCP, AOP, and GSC formation support
  • Section 847 readiness assessment
  • Ongoing FOCI compliance program management
  • DCSA engagement support
🏛 16+ years inside a DCSA-scrutinized, FOCI-mitigated defense contractor
📄 NISPOM, CMMC, and RMF expertise
🛡 SSA, Proxy, SCA, and Board Resolution experience
🔒 ECP compliance program management

Get a free initial assessment

Tell us about your situation. We will respond within one business day.

No spam. No sharing. Your information is handled with discretion.

Request received.

A Fulcrum Advisory consultant will review your situation and respond within one business day. You can also reach us directly at info@fulcrumadvisory.us.

Frequently Asked Questions

No — existing submissions are not required to be resubmitted solely because the form changed. However, any new submission, changed condition package, or FCL renewal initiated after May 12, 2025, must use the updated form. If you submitted under the old form and your package is already in NISS, DCSA will process it under the prior version.

DCSA requires disclosure of any foreign person or entity owning 5% or more of any class of securities or voting interest. This threshold was expanded in 2025 to require mapping the entire beneficial ownership chain — not just the immediate shareholder. A foreign LP in a VC fund that holds 5%+ of your company must be traced and disclosed.

Finding FOCI is not a disqualifier. The vast majority of companies with FOCI receive a mitigation agreement (Board Resolution, SCA, SSA, or Proxy) that allows them to proceed with FCL and classified contract work. The key is to engage DCSA transparently and early. Companies that disclose completely tend to receive favorable treatment versus those where DCSA discovers undisclosed interests.

Processing times vary significantly based on FOCI complexity. DCSA averages approximately 155 days for companies with no FOCI concern, 266 days for Tier 2 (some FOCI mitigation required), and 263 days for full FOCI mitigation cases. Incomplete submissions and slow responses to DCSA inquiries are the most common sources of delay.

NISS (National Industrial Security System) is DCSA's online portal for all facility security clearance applications and FOCI submissions. Your company's Facility Security Officer (FSO) or authorized representative initiates the submission through NISS. If you do not yet have an FCL or NISS account, submission typically occurs through a sponsoring contracting officer or agency.

Not yet in most cases. As of mid-2026, Section 847 is still in proposed rulemaking — the DFARS proposed rule was published May 7, 2026, with comments due July 6, 2026. The final rule is not yet in force. However, DCSA has stated it is already conducting FOCI assessments for mission-critical unclassified acquisitions, and the rule is widely expected to be finalized in late 2026. The smart move is to assess your ownership structure now, before a contract award triggers the requirement.

The Statement of Full Disclosure of Foreign Affiliations (FDFA) is a two-page supplement added to the 2025 SF-328. It must be completed by any Key Management Personnel (KMP) — directors, officers, and others who influence management — who hold positions with foreign entities. The FDFA requests information about the nature of the foreign role, length of association, and degree of operational involvement. Companies with internationally mobile leadership teams should expect this to significantly increase their SF-328 preparation burden.