EconDefense
INT-36 / Intelligence, counterintelligence and security

Protect classified contractor information and mitigate foreign ownership risks

Conduct industrial-security functions, assist other agencies, and integrate DCSA FOCI assessment with acquisition responsibility, contract conditions and oversight.

Authority / instrument · INT-36

Industrial security and counterintelligence

Intelligence, counterintelligence and security

Statute & instrument
Authority holder

Secretary of Defense; USD(A&S)/DCSA responsibilities in §4819; USD(I&S) security oversight under §137.

What this does not authorize / hard limit

DCSA is not a general regulator of every U.S. company or substitute for CFIUS.

Recorded executor

DCSA Industrial Security and CI/Insider Threat directorates; Service CI: ACIC, NCIS, AFOSI; DCMA/DCAA and program contracting offices as relevant

Continue to actor →

Institutional routing from the recorded executing role. See the office profile for its published responsibilities and engagement routes.

Legal basisSources linkedLegal sources and instrument limits are recorded.
RequirementsGates recordedRead the requirements for this instrument; applicability depends on the proposed action.
Public fundingScale documentedFY2027: $1.036 billion non-cyber O&M request; separate $1.803 billion WCF estimate.. Institutional/program context, not a funding allocation to this specific action.
Assigned rolesRemit sourcedPublic sources describe institutional authority. The instrument identifies approval and execution roles; a specific signature remains transaction-dependent.
EngagementRoutes publishedThe office profile lists public routes and their scope. Not every route accepts applications for this instrument.

Public evidence describes the institution and instrument; it is not approval of an individual transaction.

At a glance

Possible toolINT-36 · Security & information
Legal basis10 U.S.C. § 428

Authority holder: Secretary of Defense; USD(A&S)/DCSA responsibilities in §4819; USD(I&S) security oversight under §137.

Security & information

Mechanism tags describe the source text; they do not expand the authority.

Availability and verification

Existing statutory pathway; conditional on the listed findings, approvals, eligible purpose and actual available funds. Not an obligation-ready certification.

Requirements and limits

Eligibility & prerequisites

  • Classified-contractor scope under §428; separate §847 covered-contractor threshold generally exceeds$5m.
  • Commercial-product/service exemptions to specified §847 requirements unless senior official applies them for national-security risk.
  • Use appropriate disclosure, assessment, mitigation and contract procedures.

Limits & exclusions

  • DCSA is not a general regulator of every U.S. company or substitute for CFIUS.
  • FOCI finding is not identical to a criminal offense.
  • Statutory mandate does not prove implementing rule or capacity fully operational; see audit.

Funding conditions

  • Available security/acquisition resources; legislation requires sufficient resources but does not itself appropriate them.

Read the funding and execution guide

Who contributes what

Need & planning

Resources

  • Program/acquisition security funds
  • DCSA program resource owner
    Office profile

Approval

  • Statutory/appointed acquisition decision-maker and contracting officer
    Office profile
  • DCSA security determination officials within documented delegations
    Office profile

Execution

Partners & review

  • FBI for its domestic CI/criminal jurisdiction
  • Treasury-led CFIUS where covered transaction
  • Contractor security and beneficial-ownership officials

Office links are editorial matches to the original role text, not verified delegations. Composite labels and unmatched actors are preserved.

Coordination pathway

Program/contractor risk → DCSA and Service CI → acquisition/counsel decision → mitigation or permissible contract action → FBI/CFIUS referral when their powers needed.

Actor and execution-role sources

What this research establishes

Legal basisSources linkedLegal sources and instrument limits are recorded.
RequirementsGates recordedRead the requirements for this instrument; applicability depends on the proposed action.
Public fundingScale documentedFY2027: $1.036 billion non-cyber O&M request; separate $1.803 billion WCF estimate.. Institutional/program context, not a funding allocation to this specific action.
Assigned rolesRemit sourcedPublic sources describe institutional authority. The instrument identifies approval and execution roles; a specific signature remains transaction-dependent.
EngagementRoutes publishedThe office profile lists public routes and their scope. Not every route accepts applications for this instrument.

Confidence: High on express statutory capability; execution/delegation and currently available resources require program-specific confirmation.

Currentness: GovInfo 2024 U.S. Code baseline read; relevant FY2026 NDAA (Pub. L. 119-60, enacted 2025-12-18) amendments reviewed. Target 2026-10-02; source-specific OLRC checks and remaining delta are documented in international.md. No certification of current funds or executed delegations. OLRC §4819 snapshot dated2026-09-28 read in index; GAO-26-107861 distinguishes implementation/resource gaps from missing legal authority.

Review scope: Original research target October 2, 2026; no record-specific last-review date supplied. Publication is not legal-currentness certification.