New Guidance on Joint Venture (JV) Facility Security Clearance
There has been uncertainty for a number of years over when a JV must obtain its own separate Facility Security Clearance (FCL), or whether the JV can apply the members’ individual company FCLs to perform under a classified contract. The DoD and the SBA had conflicting JV FCL regulations, until the GAO, in a protest brought by this firm, upheld the SBA rule that an unpopulated small business JV did not require a separate FCL where all the member companies hold an FCL. That case answered some questions, but left others open. To resolve the issues, the Information Security Oversight Office and the SBA, on October 5, 2023, jointly released Joint Notice 2024-01: Joint Ventures and Entity Eligibility Determinations.
The Joint Notice 2024-01 approach
The Joint Notice attempts to present a single, unified approach for analyzing when a JV requires a separate FCL, whether small or large. The unified approach considers whether the JV is a small or large business, a separate legal entity, or is formed by contract (not a separate legal entity), is unpopulated (no employees of the JV itself will be performing work connected with classified information), and will not be involved with or otherwise influencing performance involving classified materials.
Separate entity JVs: the JV may hold an FCL in its own right, and may be populated and its employees can perform on the classified contract. It may also be unpopulated (i.e., has no employees that perform on the classified contract, though it may have administrative employees). In all situations, all entities performing classified work must have an FCL.
Contract JVs: All work (including classified work) is performed by one of the JV members and by their employees, not by the JV entity itself. A NISP Cognizant Security Agency (CSA) will assess the business structure of the legal entity awarded the classified contract to determine the entity’s requirement for an FCL or an appropriate exclusion from classified information under the NISPOM Rule. In general, a CSA will not require a small business JV to hold an FCL where all the members hold an FCL unless the JV’s structure or potential influence over the classified information/contract indicates it must also have an FCL.
Open issue
The Joint Notice attempts to reconcile the old NISPOM rules and the SBA regulations, but there are open issues. The Joint Notice states several times that approved FCLs are not, and cannot, be required before submitting a proposal. The CSA evaluates whether an FCL is required after the award decision. However, case law has long held that RFPs can require an FCL at proposal submission, so long as the agency justifies the requirement. Contractors submitting proposals should comply with RFP requirements, pending further guidance.
Takeaways
The takeaways are that a NISP CSA must always determine what companies require an FCL. All companies that can access or influence performance on classified contracts require an FCL. While the CSA will normally follow the SBA regulation for small business JVs, the key factor for FCL determinations is a legitimate requirement to access classified information.
Additional information
If you have questions regarding facility security clearances or other federal government contract issues, contact the professionals at Williamson Law Group at (301) 788-8198 for confidential assistance and counsel, or e-mail Scott Williamson at srw@williamsonlawgroup.com.
This Contract Compliance Update is to keep readers current on government contract matters and is not intended to be legal advice. If you have any questions, please contact Williamson Law Group for legal advice regarding your particular case.
Discuss your matter with an attorney
Tell us about your contract, protest or investigation, and an attorney will follow up.
Bethesda, MD 20817