Periodic reinvestigations are over for cleared contractor personnel. In their place is a continuous vetting system built around automated record checks and a five-year Personnel Vetting Questionnaire (PVQ) update. A DCSA-certified Facility Security Officer and former CIA security officer explains the April 2026 overhaul — and the 45-day window that can quietly change your Continuous Vetting status when you leave a cleared employer.
For decades, every cleared contractor employee lived on the reinvestigation clock. Secret meant a new investigation roughly every ten years; Top Secret, every five (before earlier deferral policies began stretching those timelines). The cycle was expensive, slow, and — by the time an investigator finally circled back — often years out of date.
On May 19, 2026, the Defense Counterintelligence and Security Agency (DCSA) announced updated Continuous Vetting guidance for National Industrial Security Program (NISP) contractor personnel, superseding its August 2022 guidance and reflecting changes delivered in DISS Release 14.5. The underlying guidance document is dated April 16, 2026, and is available on DCSA's website. The change reflects the federal government's broader Trusted Workforce 2.0 initiative, which replaces infrequent snapshot investigations with continuous evaluation supported by automated record checks.
- Periodic reinvestigations have been eliminated for NISP contractor personnel.
- Every enrolled individual must submit an updated PVQ (SF-86 via eApp, with releases) every five years, regardless of eligibility level.
- Continuous Vetting continues year-round through automated record checks; the five-year PVQ update refreshes the baseline those checks run against.
- Losing your Security Management Office (SMO) affiliation in DISS starts a 45-day clock that can change your Continuous Vetting enrollment status.
- Neither the new process nor a change in enrollment status alters the underlying adjudicative standards or your due-process protections.
The details underneath those takeaways are where FSOs and cleared employees can get hurt — particularly the 45-day administrative window that runs when someone separates from a cleared employer and no new security office picks them up. Here is what changed, what it requires of security offices, and where the practical traps sit.
What the New Guidance Actually Says
Three changes matter.
First, the periodic reinvestigation requirement is eliminated for NISP contractor personnel. In its place, every enrolled individual must submit an updated Personnel Vetting Questionnaire — the PVQ, or the SF-86 completed through eApp, together with signature releases — every five years, regardless of eligibility level. Secret and Top Secret are on the same five-year update cycle. The distinction that used to drive different reinvestigation intervals is gone for this purpose.
Note what this is and is not. The five-year requirement is an updated questionnaire — not another full background investigation. Continuous Vetting's automated record checks — criminal, financial, terrorism, and other public and government data sources — run against you all year, every year. The five-year SF-86 update keeps the baseline information those checks run against current. It is the paperwork that feeds the machine, not the machine itself.
Second, the clock runs from the "PVQ Date" in DISS. The five-year update is measured from the PVQ Date recorded in the Defense Information System for Security, which DCSA states is equivalent to the SF-86 date. For security offices, DCSA directs use of the DISS Subject Report to identify which personnel are approaching their five-year mark, with the PVQ Date as the key reference field. Once due, the organization submits the necessary information to DCSA's personnel security mission for industry (historically PSMO-I, now operating within DCSA's consolidated adjudication and vetting structure) to stay compliant.
Third, enrollment statuses are simplified to three. According to DCSA's May 2026 industry newsletter, Continuous Vetting enrollment in DISS now resolves to one of three states: Enrolled (actively enrolled in the DCSA CV program), Unenrolled (previously enrolled, no longer enrolled), and Not Enrolled (never enrolled). If you have managed personnel through the older, more fragmented status taxonomy, the cleanup is welcome — but it also makes the Enrolled/Unenrolled line consequential.
One distinction to fix in your mind before going further: Continuous Vetting enrollment is not the same as security clearance eligibility. Enrollment governs participation in DCSA's monitoring program. Eligibility is the adjudicative determination that allows access to classified information. The new guidance changes how enrollment is tracked and maintained; it does not change how eligibility is granted, continued, or revoked. Keep that distinction in view, because it is exactly where the next section's trap does — and does not — reach.
The 45-Day Trap: Losing Your SMO Between Jobs
Buried in the same May 2026 DCSA newsletter is the detail most likely to bite real people:
When an individual loses their affiliation with a Security Management Office (SMO) in DISS — typically because they left a cleared employer — a 45-day grace period begins. If a new SMO does not establish the relationship within that window, the individual's Continuous Vetting enrollment status changes automatically.
Think about who that describes. A cleared engineer laid off from one defense contractor, interviewing with three others. A consultant between task orders. A retiree from government service whose contractor onboarding stalls in HR. Anyone whose gap between cleared employers stretches past six and a half weeks. (If your gap began with a termination, see my related article: Can I Lose My Security Clearance If I'm Fired? — employment and eligibility are decided by two different systems.)
Under the old mental model, many cleared professionals assumed their clearance simply sat intact "in the system" between jobs, waiting for the next FSO to pick it up. Current eligibility generally remains reflected in DISS, although Continuous Vetting enrollment is tied to an active SMO relationship — and enrollment is what the modern vetting system runs on. Falling out of Enrolled status is not a revocation and not an adjudicative action. But it is a status change the gaining security office will have to deal with, and depending on timing and the individual's record, it can add friction, delay, or additional processing to what should have been a clean onboarding.
Practice Tip: If you're changing employers, ask your new FSO when the organization will establish your SMO relationship in DISS. Don't assume it happens automatically — make the DISS handoff part of your start-date planning, and follow up in writing until the gaining security office confirms it owns you in the system.
The practical guidance flowing from this is straightforward:
- If you are a cleared employee changing jobs: treat the 45-day window as real. Where you can control timing, minimize the gap between your losing SMO releasing you and your gaining SMO picking you up. Security clearance issues between jobs are stressful enough without an avoidable administrative lapse layered on top.
- If you are an FSO on the losing side: understand that the date you remove the affiliation starts a clock for that individual. You have no obligation to delay a proper separation, but sloppy timing on out-processing has downstream consequences for the person.
- If you are an FSO on the gaining side: do not let DISS onboarding sit in a queue behind badge photos and laptop provisioning. Establishing the SMO relationship inside the window is the difference between a seamless transfer and an avoidable status problem.
What Security Offices Need to Do Now
For facilities operating under 32 CFR Part 117, the new guidance translates into an audit checklist worth running this quarter:
- Pull the DISS Subject Report and review all PVQ Dates — identify everyone approaching the five-year mark now, then repeat quarterly.
- Add PVQ update reminders to your compliance calendar — unlike the old reinvestigation model, you are the tickler system; no investigator will schedule anything to force the issue.
- Make the DISS SMO relationship a day-one onboarding action — ahead of badges, ahead of laptops.
- Document separation dates in out-processing — the date you remove an affiliation starts that individual's 45-day clock.
- Reconcile your population against the three new statuses — after DISS Release 14.5, verify everyone you believe is enrolled actually shows Enrolled, and investigate anyone showing Unenrolled whom you believed was covered.
- Update annual security awareness training — most cleared employees have never heard of a PVQ Date and still believe in the ten-year reinvestigation; a five-minute block covering the five-year update and the between-jobs window is cheap insurance.
Status cleanup during a system transition is exactly the kind of housekeeping DCSA reviewers notice when it has not been done.
What This Does Not Change
A few important constants, because every simplification invites over-reading:
Self-reporting obligations are untouched. Continuous Vetting's automated checks did not replace Security Executive Agent Directive 3. Cleared contractor personnel must still self-report foreign travel, certain foreign contacts, and the other reportable events SEAD 3 and 32 CFR Part 117 require. Automated data feeds catch a great deal; they do not catch everything, and "the system would have flagged it" has never been a defense to a failure-to-report concern.
Adjudicative standards are untouched. The change is to the mechanism of vetting — how often paperwork is refreshed and how monitoring runs — not to the substance of what disqualifies or mitigates under the SEAD 4 adjudicative guidelines. A CV alert still goes to a human adjudicator applying the whole-person concept, and due-process protections for contractor personnel remain in place. I cover how automated flags interact with those protections in When an Algorithm Flags Your Clearance — the short version is that an alert is a trigger for review, not a decision.
Drug-involvement rules are untouched. If any part of the modernization tempts you to think enforcement attitudes have loosened generally, they have not: as I explained after the Supreme Court's June decision, Hemani didn't change security clearance rules for marijuana users, and Guideline H applies with full force inside Continuous Vetting.
This guidance is for NISP contractor personnel. Other federal populations run on their own implementation timelines under Trusted Workforce 2.0. If you hold eligibility through a non-NISP channel, confirm the rules that apply to your population rather than assuming this guidance covers you.
The Bottom Line
The April 2026 guidance completes, for cleared industry, a transition that has been coming since Trusted Workforce 2.0 was announced: from snapshot investigations every five or ten years to continuous monitoring with a five-year paperwork refresh. Problems now surface in weeks instead of years, and cleared personnel are no longer priced and delayed through redundant full-scope reinvestigations.
For most cleared professionals, the new process is an improvement. But unlike the old reinvestigation system, success now depends less on waiting for the government to initiate an investigation and more on maintaining accurate records, timely PVQ updates, and uninterrupted administrative coordination between security offices. The five-year cycle has no external forcing function — facilities must track it — and the 45-day SMO window means the space between cleared jobs now carries a specific, dated, administrative consequence for the unprepared.
If you run a security program, put the Subject Report pull and the day-one DISS action into your SOPs this quarter. If you are a cleared professional contemplating a move, make the DISS handoff part of your negotiation timeline, not an afterthought for week three.
DCSA, "DCSA updates NISP contractor Continuous Vetting process," May 19, 2026; DCSA, Industry Continuous Vetting Guidance (April 16, 2026); DCSA Voice of Industry newsletter, May 2026 (45-day SMO grace period; Enrolled/Unenrolled/Not Enrolled statuses); 32 CFR Part 117 (NISPOM); SEAD 3; SEAD 4. Last reviewed July 23, 2026 — Continuous Vetting implementation is evolving; confirm the current status before relying on it.
Related reading: for how AI-assisted screening inside Continuous Vetting interacts with your due-process rights, see When an Algorithm Flags Your Clearance. If your employment gap began with a termination, see Can I Lose My Security Clearance If I'm Fired?
Facing a clearance issue arising from an employment gap, a CV alert, or a reporting question? This article is for general informational purposes and is not legal advice. I am licensed to practice law only in Maryland, and I spent 26 years inside the security apparatus that now runs Continuous Vetting. If you are navigating a between-jobs status change, an enrollment problem, or a self-reporting question, schedule a consultation to discuss your specific situation.
Related Articles
$400K National Security Jobs: What the New Pay Authority Means for Your Clearance
The government approved salaries up to $400,000 for national security investment roles. A former CIA officer and clearance attorney explains why the clearance — not the salary — is the real gate, and how foreign-influence issues affect these jobs.
Pentagon Legal Opinion Ends the DCSA Clearance Hearing Program: What It Means for Clearance Holders
The Pentagon determined DCSA cannot conduct security clearance personal appearance hearings because it is also the investigating entity. A former CIA officer explains what it means for clearance holders, SOR responses, and cases now referred to DOHA.
How to Start a Classified Government Contracting Company: FCL, Sponsorship, and DCSA Requirements
A Facility Security Clearance isn't something a company applies for — it's something it's sponsored into. A DCSA-certified Facility Security Officer and Insider Threat Program Senior Official explains the FCL process: sponsorship, FOCI review, Key Management Personnel clearances, and the NISPOM obligations that don't end at approval.