The NISPOM Rule governs classified contractor security under the National Industrial Security Program.
In plain terms. The NISPOM Rule governs classified contractor security under the National Industrial Security Program. It matters to cybersecurity because cleared contractors must protect classified systems and often operate under both classified-security and CUI regimes.
Who it applies to. It applies to cleared contractors, subcontractors, and facilities participating in the National Industrial Security Program.
What it requires. In practice, contractors should maintain facility clearance requirements, protect classified information, follow insider-threat and information-system security rules, report security events, and comply with Defense Counterintelligence and Security Agency (DCSA) oversight.
Why it matters. For GovConCyber, the key is to translate the law into contract-performance terms without overstating the source. The page should tell readers whether the requirement affects eligibility, representations, contract performance, flowdowns, data handling, incident response, or enforcement exposure.
Citation. 32 C.F.R. part 117.