
DISCO is tied to the historical structure of the U.S. Defense Security Service (DSS). Most of what DISCO once handled now sits with the Defense Counterintelligence and Security Agency (DCSA), established on 1 October 2019 as DCSA's own history confirms. For Australian firms chasing U.S. defence work, subcontracting roles, or access to classified information, getting this distinction right matters.
This article covers what DISCO actually means today, how facility and personnel clearances differ, how sponsorship and foreign ownership reviews work, and why DISP membership in Australia won't substitute for a U.S. clearance. We'll also flag where Australian obligations run in parallel with U.S. ones.
Key Takeaways
- A facility clearance and a personnel clearance are separate authorisations, both tied to a genuine need for classified access.
- Contractors generally need a U.S. sponsor (a contracting activity or cleared prime) before starting the facility-clearance process.
- DISP membership and U.S. industrial security clearance are not interchangeable frameworks.
- Reviews can cover ownership, foreign interests, information systems, and security governance.
- Always confirm current requirements directly with DCSA, the contracting authority, or specialist counsel.
What Is DISCO and How Does It Fit Into the U.S. Security-Clearance System?
DISCO was a DSS office that adjudicated contractor-employee clearance eligibility after personnel investigations moved to the Office of Personnel Management in 2005, according to DSS's own ACCESS publication.
It's a historical name, not a standalone agency you'll be dealing with today. If you see DISCO referenced in older documents or forum posts, treat it as shorthand for a function DCSA now performs.
The NISP and NISPOM Framework
Industrial security in the U.S. runs through the National Industrial Security Program (NISP), created by Executive Order 12829. The current operating manual is 32 CFR Part 117, which took effect on 24 February 2021 and governs how contractors handle classified information under DCSA's NISPOM rule.
Key players include:
- DCSA — the cognizant security agency overseeing most industrial security matters
- Contracting officers or cleared prime contractors — who sponsor a company into the clearance process
- Facility Security Officers (FSOs) — who manage day-to-day compliance at the contractor level
- Adjudicating authorities — who determine individual eligibility
Holding a clearance doesn't open every door. Eligibility, access, and need-to-know are three separate concepts. An employee can be cleared at the Secret level and still be denied access to a specific programme if they have no legitimate need for that information.

Who Needs a U.S. Industrial Security Clearance?
Not every company bidding on defence work needs a Facility Security Clearance (FCL). You'll typically need one if your organisation will:
- Hold a classified prime contract or subcontract
- Receive, store, or process classified information
- Require physical or network access to classified material as part of contract performance
A company can often bid on a contract before securing an FCL, but it generally cannot perform classified work or receive classified material until the determination is complete. The exact rule depends on the solicitation, so verify it with the contracting activity.
Who Needs a Personnel Security Clearance
A Personnel Security Clearance (PCL) applies to individuals (employees, directors, officers, or consultants) who need access for their specific duties. Not everyone at a cleared company needs one. Access should follow the need-to-know principle: only those with a genuine, task-based reason for seeing classified material should be cleared and granted access.
It also helps to separate classified information from adjacent categories that get confused with it:
- Classified information: protected under national security classification
- Controlled Unclassified Information (CUI): sensitive but explicitly not classified
- Export-controlled technical data: covered under ITAR, including design and manufacturing information for defence articles
- Commercially sensitive information: protected by contract or trade secret law, not national security rules
Treating these as equivalent is a common mistake that leads to either over-restricting ordinary business information or under-protecting genuinely controlled data.
How Does the Clearance Process Work?
The process follows a general sequence, though specific steps vary by contract and entity.
- Identify the classified requirement — confirm the contract or subcontract actually demands classified access.
- Secure a sponsor — a government contracting activity or an already-cleared contractor submits the sponsorship request.
- Submit organisational information — including corporate structure and key management personnel.
- Complete required forms and reviews — ownership, foreign interest, and security reviews follow.
- Establish safeguards — physical and information-security measures appropriate to the classification level.
- Await the entity eligibility determination — from DCSA or the relevant cognizant security agency.

What Foreign Companies Should Prepare
An Australian parent or affiliate should expect to disclose:
- Corporate structure and beneficial ownership
- Directors, officers, and their citizenship
- Foreign investors, parent entities, and affiliates
- Financing arrangements and outsourcing relationships
The FOCI Review
Foreign Ownership, Control, or Influence (FOCI) is central to the assessment. DCSA evaluates whether foreign interests could affect how a company manages classified information or performs a classified contract.
Foreign ownership alone is not an automatic disqualifier. It can be mitigated through governance structures matched to the risk profile:
- Security Control Agreement
- Special Security Agreement
- Proxy Agreement
- Voting Trust Agreement
Personnel preparation runs alongside this: accurate employment and residence history, foreign contacts and travel disclosures, and financial information where required. Changes need to be reported promptly — this isn't a one-time disclosure exercise.
DCSA is upfront that it cannot provide a standard processing timeline, because outcomes depend heavily on how complete and accurate the submitted documentation is, as noted on DCSA's facility clearance page.
Clearance is not a finish line. Ongoing training, reporting, access reviews, and incident procedures remain mandatory for as long as the facility clearance stays active.
Facility Clearance, Personnel Clearance, and Contractor Responsibilities
| Element | Facility Clearance (FCL) | Personnel Clearance (PCL) |
|---|---|---|
| Applies to | The organisation | The individual |
| Determines | Entity eligibility to access classified information | Individual eligibility for access |
| Who decides | Cognizant security agency (e.g., DCSA) | Government adjudicator |
| Prerequisite for | Classified contract performance | Specific role-based access |
Key Roles Inside the Organisation
Once an FCL is in place, specific roles carry ongoing responsibility:
- Facility Security Officer (FSO) — directs day-to-day security measures
- Insider Threat Program Senior Official (ITPSO) — runs the insider-threat programme (one person can hold both FSO and ITPSO roles)
- Information-system security personnel — manage system accreditation and access controls
- Senior management — appoints these officials in writing and bears ultimate accountability
Those officials also oversee physical and information-security controls.
Physical-security expectations typically include:
- Controlled storage areas
- Visitor management
- Approved containers for classified material
- Secure destruction procedures
On the information-security side, contractors need cognizant security agency authorisation before using any system to process classified information. Ordinary commercial cloud tools generally don't qualify without that approval.

Before pursuing a U.S. classified opportunity, ask:
- Who is the sponsor for this opportunity?
- What classification level is actually involved?
- Which legal entity needs the FCL?
- Which individuals genuinely need PCLs?
- Where will classified information physically and digitally reside?
- Are there foreign ownership or cross-border staffing issues to resolve first?
What Should Australian and International Contractors Understand?
This is where a lot of Australian companies trip up. The Defence Industry Security Program (DISP) and the U.S. NISP are entirely separate systems, run by different authorities, with different membership and clearance concepts.
Australia's DISP operates across four membership levels:
| DISP Level | Associated Information Level |
|---|---|
| Entry | Official / Official: Sensitive |
| One | Protected |
| Two | Secret |
| Three | Top Secret |
These levels, confirmed in Defence's 2025 DISP membership guidance, govern access within the Australian Defence security domain.
DISP membership does not automatically grant access to U.S. classified information. Holding a U.S. FCL or PCL doesn't automatically satisfy Australian Defence requirements either. Both frameworks require their own, separate determinations.
Australian companies pursuing U.S. work often face overlapping obligations simultaneously:
- DISP membership requirements for Australian contracts
- U.S. export controls and sanctions compliance
- Privacy and data-security rules across both jurisdictions
- Foreign ownership disclosures on both sides
- Cross-border transfer rules for technical information
A 2002 bilateral agreement between the U.S. and Australia supports reciprocal protection of exchanged classified material. It does not create automatic clearance recognition between the two systems.

A practical scenario: an Australian defence manufacturer expanding into a U.S. subcontract should assess security requirements before signing, not after. Review the arrangement before appointing a new foreign investor, before a board control change, and before moving technical work across the Pacific. Waiting until after the ink is dry is usually far more expensive and disruptive.
Practical Preparation Checklist for a Company Exploring U.S. Defence Work
Before chasing a U.S. classified opportunity, map out responsibility across your organisation:
- Board and executives: ultimate accountability for governance decisions
- Facility Security Officer and IT/security leads: day-to-day compliance
- HR: personnel vetting coordination
- Legal advisers and export-control personnel: contract and compliance review
- Contract managers: tying obligations back to specific deliverables
Document readiness matters just as much. Gather:
- Ownership charts and constitutional documents
- Board and officer details, including citizenship
- Foreign-interest disclosures
- Security policies and training records
- Physical-security plans and information-system descriptions
- Current personnel lists
Security review belongs in the planning stage for any transaction: fundraising, acquisition, restructuring, outsourcing, international hiring, or a change in ownership and control. Leaving it until after a deal closes is one of the most common and costly mistakes we see.
This is also where the lines of business matter. Security clearance determinations sit with DCSA, Australian Defence, or specialist security counsel, not with VJM Global.
What VJM Global supports is the surrounding business infrastructure: cross-border accounting, international tax planning, FEMA advisory for companies with Indian operations or investment flows, and entity formation and compliance work for Australian businesses expanding internationally.
If your defence expansion involves restructuring ownership, setting up a new entity, or managing cross-border tax obligations, that groundwork deserves attention alongside your security review, not after it.
Whatever stage you're at, confirm current requirements directly with the contracting authority and relevant government agencies. Clearance terminology, forms, and procedures change, and relying on outdated guidance is a genuine risk.
Conclusion: Treat Clearance as a Business and Governance Requirement
Understanding DISCO is a practical test of whether your company can lawfully take part in a U.S. classified programme.
Keep these distinctions clear:
- Company clearance and individual clearance are separate processes
- Access requires more than eligibility alone
- Sponsorship must be in place before the process starts
- Need-to-know governs who actually sees classified material
Those rules only help if you apply them early. Australian and international contractors should assess both U.S. and Australian security obligations at the start of a contract or transaction — not after commercial commitments are already locked in.
Frequently Asked Questions
What is the difference between DISCO and DCSA?
DISCO was a Defense Security Service office historically associated with contractor-employee clearance adjudication. DCSA, established in 2019, now holds most of these responsibilities. Always verify current terminology against official DCSA sources.
Does an Australian defence contractor need a U.S. security clearance?
It depends on the contract, the classification level involved, and whether you have a U.S. sponsor. DISP membership alone does not automatically satisfy U.S. requirements — a separate determination is generally needed.
What is the difference between a facility clearance and a personnel security clearance?
An FCL applies to the organisation; a PCL applies to the individual. Both may be required before anyone can access classified information under a specific contract.
What are the security clearance levels in Australia?
Australian Government vetting typically includes Baseline, Negative Vetting 1 (NV1), Negative Vetting 2 (NV2), and Positive Vetting (PV). These differ from U.S. clearance tiers, and DISP membership is a separate defence industry requirement.
How can I find current DCSA contact details?
Use official DCSA or U.S. government pages for current phone numbers and email addresses. Third-party blogs and forum posts are often outdated, so do not rely on them.


