On May 19, 2026, DCSA announced updated Continuous Vetting guidance for National Industrial Security Program contractors — a memorandum dated April 22, 2026, superseding guidance that had been in place since August 2022. The headline change: periodic reinvestigations for NISP contractor national security personnel are no longer conducted. In their place, enrolled personnel now submit an updated Personnel Vetting Questionnaire every five years, regardless of clearance level, while automated checks run continuously in the background.
If you’ve been waiting on a “your reinvestigation is due” notice that never comes, this is why. The reinvestigation cycle most cleared people grew up with — five years for Top Secret, ten for Secret — is being phased out across the federal government under an initiative called Trusted Workforce 2.0. Here’s what actually replaced it, what it checks, and what didn’t change.
Quick Answer: Continuous Vetting (CV) is replacing the old periodic reinvestigation cycle with ongoing automated record checks — criminal, financial, terrorism, and public records — run throughout an individual’s period of eligibility instead of once every 5 or 10 years. As of DCSA’s April 2026 guidance, NISP contractors no longer have scheduled periodic reinvestigations; they submit an updated questionnaire every 5 years and are otherwise monitored continuously. You still have to self-report reportable events yourself — CV doesn’t replace that obligation.
What Changed vs. What Didn’t
| Area | Changed? | What happened |
|---|---|---|
| Periodic reinvestigation (NISP contractors) | Yes | No longer conducted, per DCSA guidance dated April 22, 2026, announced May 19 |
| Reinvestigation cycle by clearance level | Replaced | Old 5-year (TS) / 10-year (Secret) cycles phased out in favor of continuous monitoring |
| PVQ timing basis | Yes | The 5-year questionnaire-update cycle isn’t new — the anchor date changed from the CV/Continuous Enrollment date to the DISS “PVQ Date” |
| Automated record checks | No | Already part of CE/CV before the 2026 change — CV has since expanded to carry more of the workload |
| Self-reporting obligations (SEAD 3) | No | Still mandatory, and still varies by eligibility level and position sensitivity |
| Investigative tier structure | In transition | Legacy five-tier model being consolidated to three (Low, Moderate, High) |
| Adjudicative guidelines | No | Still the same 13 guidelines, same whole-person framework |
The Old System: Reinvestigations on a Clock
For decades, staying cleared meant sitting for a full reinvestigation on a fixed schedule — roughly every 5 years for Top Secret, every 10 for Secret. The legacy model relied heavily on those periodic investigative snapshots, supplemented by self-reporting and other adverse-information channels that existed even then. But automated records coverage between snapshots was far thinner than it is today, and self-reporting depends on someone choosing to report — it isn’t a systematic check.
That gap, combined with a federal background investigation backlog that at points left cases taking well over a year to complete, is a large part of why reform became a priority. A system built around point-in-time investigations couldn’t keep pace with a cleared workforce that had outgrown it, and threats, personnel mobility, and the need for reciprocity between agencies all factored into the push for something continuous.
Trusted Workforce 2.0, launched as a government-wide personnel-vetting reform initiative in 2018, set out to modernize that framework. Continuous vetting is the piece of that reform most cleared people actually experience.
- Full reinvestigation every 5 years (TS) / 10 years (Secret)
- Point-in-time snapshots
- Thin automated coverage between snapshots
- Relied on self-reporting to catch events in the gaps
- Contributed to a multi-year investigation backlog
- Automated record checks run throughout eligibility
- No scheduled reinvestigation (NISP contractors)
- Updated questionnaire every 5 years, tied to your PVQ Date
- Events can surface in near-real time
- Same 13 adjudicative guidelines apply
What Continuous Vetting Actually Checks
The foundational authority is SEAD 6, issued by the Office of the Director of National Intelligence in 2018 to establish Continuous Evaluation (CE) — the automated-records framework that continuous vetting is built on. SEAD 6 authorizes checks using government databases, commercial databases, and other lawfully available information, and leaves the specific data sources and periodicity to implementing standards rather than spelling them out itself.
Notably, SEAD 6 as issued in 2018 described Continuous Evaluation as something that supplements — but does not replace — scheduled periodic reinvestigations. The actual elimination of periodic reinvestigations came later, through DCSA’s Trusted Workforce 2.0 implementation. SEAD 6 started the framework; TW 2.0 is what eventually let PRs be retired.
Under DCSA’s current Continuous Vetting implementation, checks cover seven broad categories:
Arrest and criminal records across jurisdictions.
Terrorism watchlist database matches.
Reportable financial events and anomalies.
Ongoing credit activity, not just a one-time pull.
Judgments, bankruptcies, and similar filings.
Foreign travel records surfaced through government data.
Agency-specific eligibility and personnel information.
When a check surfaces something, it generates an alert. An alert is not an adverse determination — DCSA assesses the information for validity and whether it warrants further investigation before anyone acts on it. SEAD 6 also builds in a specific safeguard here: unfavorable personnel-security action cannot be taken solely on uncorroborated or unverified discrepant information surfaced through CE. If something does warrant a closer look, it goes through the same adjudicative framework as anything else — the 13 guidelines, evaluated using the whole-person concept.
Reality check: Continuous vetting exists to close a timing gap, not to lower the bar for what counts as a security concern. The same 13 guidelines and the same mitigating conditions that applied under the old reinvestigation model still apply here — see how that plays out for debt and financial issues under Guideline F. What changed is how fast something can surface. What counts as a concern once it does hasn’t changed.
The April 2026 Update: What NISP Contractors Need to Know
DCSA’s Continuous Vetting guidance for NISP contractors — dated April 22, 2026, and publicly announced May 19 — supersedes guidance dated August 8, 2022, and incorporates changes tied to DISS Release 14.5. Here’s what it actually requires:
- No more scheduled periodic reinvestigations for NISP contractor national security personnel.
- The five-year questionnaire cycle itself isn’t new — contractors were already required to submit an updated PVQ periodically. What changed is the anchor date: DCSA now uses the “PVQ Date” in DISS — which reflects your actual SF-86 date — rather than the older Continuous Enrollment (CE) date.
- Facility Security Officers use their DISS Subject Report to identify personnel approaching their PVQ deadline and route the update through the Personnel Security Management Office for Industry (PSMO-I).
One limitation worth knowing about: DCSA’s guidance states plainly that “CV enrollment reciprocity among agencies is not established.” If DCSA can’t verify your CV enrollment in DISS, an updated PVQ may still be required — including for personnel transferring between companies or agencies, or IC enrollment that isn’t visible in DISS. IC or SAP customers can also impose earlier PVQ requirements through their own contracting activity, which contractors are directed to follow. Reciprocity is a stated goal of Trusted Workforce 2.0, not a finished feature.
You Still Have to Self-Report
This is the part continuous vetting doesn’t change, and it’s the part that trips people up.
CV is an automated backstop that catches what shows up in records — credit reports, court filings, watchlist matches. It is not a substitute for your own disclosure obligations under SEAD 3. Exactly what you must report depends on your eligibility level, position sensitivity, and any additional agency or program requirements — the requirements are not identical across clearance levels.
- Unofficial foreign travel and certain foreign contacts
- Arrests or criminal charges — including a DUI
- Qualifying media contact involving protected info
- Certain alcohol or drug treatment
- Financial anomalies below the Secret-level debt threshold
- Certain foreign business, property, or banking interests
- Foreign national roommates
- Marriage and cohabitation
Reporting under SEAD 3 is mandatory, not discretionary, and it exists independently of whatever continuous vetting might eventually catch on its own. Failing to self-report can itself raise a security concern — the same dynamic covered in what the SF-86 actually asks and in common SF-86 mistakes. An automated system that eventually flags something you didn’t report doesn’t just raise the original issue. It raises the question of why you didn’t say something first.
The Tier System Is Also Changing — Slowly
Alongside continuous vetting, Trusted Workforce 2.0 is consolidating the legacy five-tier investigative model (Tier 1 through Tier 5, roughly mapped to non-sensitive positions through Top Secret/SCI) into three risk-based tiers: Low, Moderate, and High. The new structure is meant to align investigative scope more directly with actual risk rather than a legacy classification scheme, and to standardize vetting across civilian, military, and contractor populations under one framework.
This transition is still in progress, and it’s broader than the NISP-specific change above — but one major legacy piece is already gone. At the end of June 2026, DCSA sunset its legacy periodic-reinvestigation investigative products, with only limited exceptions; previously ordered reinvestigations continue to be processed. Meanwhile, the first two early-adopter Investigative Service Providers (ISPs) — the organizations that conduct background investigations — have transitioned to the new Trusted Workforce 2.0 investigative products, with other early adopters expected to transition during FY2026 Q4 and the remaining ISPs by FY2027. All ISPs are targeted to offer the new products by September 2027. Full population enrollment in continuous vetting — including the lowest-risk population — is targeted for September 2028.
What This Means If You’re Currently Cleared
You won’t get a reinvestigation notice the way you used to — at least not if you’re DoD. DoD’s cleared population has been enrolled in continuous vetting since 2021. Other federal populations are still transitioning: government-wide CV enrollment stood at 78% as of the most recent published reporting, with full population enrollment targeted for September 2028. Don’t wait for a scheduled event — if you’re cleared, assume your record is being checked continuously or will be soon.
Track your PVQ Date. If you’re a NISP contractor, ask your FSO when your questionnaire update is due. It’s tied to your last SF-86 submission, not a calendar year everyone shares.
Keep self-reporting on your own timeline, not CV’s. Report what SEAD 3 requires, when it’s required of your specific eligibility level, as it happens. Don’t treat continuous vetting as a reason to wait and see whether it surfaces on its own.
Financial and life changes still matter, exactly as much as before. A faster-moving check doesn’t change what counts as a concern. It changes how quickly a concern becomes visible. The same mitigation strategies that worked under periodic reinvestigation — disclosure, documentation, demonstrated trajectory — still apply.
Key Takeaways
- DCSA eliminated periodic reinvestigations for NISP contractor national security personnel, per guidance dated April 22, 2026, and announced May 19, 2026, superseding guidance from August 2022.
- The five-year PVQ update cycle isn’t new — what changed is the anchor date, now tied to your “PVQ Date” in DISS rather than the older Continuous Enrollment date.
- SEAD 6 established the Continuous Evaluation framework in 2018 as a supplement to periodic reinvestigations, not a replacement. Trusted Workforce 2.0’s later implementation is what actually let DCSA retire the periodic reinvestigation for NISP contractors.
- DCSA’s current Continuous Vetting implementation covers seven categories — criminal activity, terrorism, financial activity, credit, public records, foreign travel, and eligibility information — through automated checks conducted throughout an individual’s period of eligibility.
- An alert is not an adverse determination. SEAD 6 prohibits adverse action based solely on uncorroborated or unverified information surfaced through CE.
- CV does not replace your self-reporting obligations under SEAD 3, and those obligations vary by eligibility level — Top Secret/Q personnel have meaningfully broader reporting requirements than Secret/L personnel.
- DCSA sunset its legacy periodic-reinvestigation investigative products at the end of June 2026, with only limited exceptions; previously ordered reinvestigations continue processing. The first two early-adopter ISPs have transitioned to the new TW 2.0 investigative products, with the rest targeted for FY2027.
- Trusted Workforce 2.0 is also consolidating the legacy five-tier investigative model into three risk-based tiers (Low, Moderate, High). Government-wide CV enrollment stood at 78% as of the most recent reporting, with full population enrollment targeted for September 2028.
- CV reciprocity across agencies is not established, per DCSA’s own guidance. Moving between contracts or agencies may still require updated paperwork even if you’re already enrolled elsewhere.
Sources
- SEAD 6 — Continuous Evaluation — Office of the Director of National Intelligence. The foundational directive establishing the Continuous Evaluation framework (2018).
- DCSA Industry Continuous Vetting Guidance, dated April 22, 2026 — Defense Counterintelligence and Security Agency. The current guidance eliminating periodic reinvestigations for NISP contractors and establishing the PVQ Date-based five-year cycle.
- DCSA Updates NISP Contractor Continuous Vetting Process — DCSA’s public announcement, May 19, 2026.
- DCSA — Continuous Vetting — Program overview.
- SEAD 3 Reporting Desktop Aid for Cleared Industry — DCSA. Reference for reportable activity by clearance level.
- ISL 2021-02 — SEAD 3 Reportable Activities Guidance — DCSA Industrial Security Letter clarifying SEAD 3 reporting requirements for cleared contractors.
- Trusted Workforce 2.0 Quarterly Progress Report — FY2026 Q3 — Security, Suitability, and Credentialing Performance Accountability Council. Current implementation status for the transition away from legacy periodic reinvestigation products.
- Security Executive Agent Directive 4 (SEAD 4) — National Security Adjudicative Guidelines — Office of the Director of National Intelligence.
For how adjudicators evaluate flagged information using the whole-person concept, see The 13 Adjudicative Guidelines. For what the reinvestigation process replaced, see How Long Does a Security Clearance Take?. For the disclosure form where SEAD 3-adjacent issues originally get reported, see What Is the SF-86? and Common SF-86 Mistakes.
This article is informational, not legal advice. Continuous vetting policy is actively evolving under Trusted Workforce 2.0 — verify current requirements with your FSO, security office, or DCSA directly before relying on specific dates or thresholds.