On May 19, 2026, DCSA announced updated Continuous Vetting guidance for National Industrial Security Program contractors — a memorandum dated April 22, 2026, superseding guidance that had been in place since August 2022. The headline change: periodic reinvestigations for NISP contractor national security personnel are no longer conducted. In their place, enrolled personnel now submit an updated Personnel Vetting Questionnaire every five years, regardless of clearance level, while automated checks run continuously in the background.

If you’ve been waiting on a “your reinvestigation is due” notice that never comes, this is why. The reinvestigation cycle most cleared people grew up with — five years for Top Secret, ten for Secret — is being phased out across the federal government under an initiative called Trusted Workforce 2.0. Here’s what actually replaced it, what it checks, and what didn’t change.


Quick Answer: Continuous Vetting (CV) is replacing the old periodic reinvestigation cycle with ongoing automated record checks — criminal, financial, terrorism, and public records — run throughout an individual’s period of eligibility instead of once every 5 or 10 years. As of DCSA’s April 2026 guidance, NISP contractors no longer have scheduled periodic reinvestigations; they submit an updated questionnaire every 5 years and are otherwise monitored continuously. You still have to self-report reportable events yourself — CV doesn’t replace that obligation.


What Changed vs. What Didn’t

AreaChanged?What happened
Periodic reinvestigation (NISP contractors)YesNo longer conducted, per DCSA guidance dated April 22, 2026, announced May 19
Reinvestigation cycle by clearance levelReplacedOld 5-year (TS) / 10-year (Secret) cycles phased out in favor of continuous monitoring
PVQ timing basisYesThe 5-year questionnaire-update cycle isn’t new — the anchor date changed from the CV/Continuous Enrollment date to the DISS “PVQ Date”
Automated record checksNoAlready part of CE/CV before the 2026 change — CV has since expanded to carry more of the workload
Self-reporting obligations (SEAD 3)NoStill mandatory, and still varies by eligibility level and position sensitivity
Investigative tier structureIn transitionLegacy five-tier model being consolidated to three (Low, Moderate, High)
Adjudicative guidelinesNoStill the same 13 guidelines, same whole-person framework

The Old System: Reinvestigations on a Clock

For decades, staying cleared meant sitting for a full reinvestigation on a fixed schedule — roughly every 5 years for Top Secret, every 10 for Secret. The legacy model relied heavily on those periodic investigative snapshots, supplemented by self-reporting and other adverse-information channels that existed even then. But automated records coverage between snapshots was far thinner than it is today, and self-reporting depends on someone choosing to report — it isn’t a systematic check.

That gap, combined with a federal background investigation backlog that at points left cases taking well over a year to complete, is a large part of why reform became a priority. A system built around point-in-time investigations couldn’t keep pace with a cleared workforce that had outgrown it, and threats, personnel mobility, and the need for reciprocity between agencies all factored into the push for something continuous.

Trusted Workforce 2.0, launched as a government-wide personnel-vetting reform initiative in 2018, set out to modernize that framework. Continuous vetting is the piece of that reform most cleared people actually experience.

Periodic Reinvestigation The old model
  • Full reinvestigation every 5 years (TS) / 10 years (Secret)
  • Point-in-time snapshots
  • Thin automated coverage between snapshots
  • Relied on self-reporting to catch events in the gaps
  • Contributed to a multi-year investigation backlog
Continuous Vetting Trusted Workforce 2.0
  • Automated record checks run throughout eligibility
  • No scheduled reinvestigation (NISP contractors)
  • Updated questionnaire every 5 years, tied to your PVQ Date
  • Events can surface in near-real time
  • Same 13 adjudicative guidelines apply
Figure 1 The shift from a point-in-time model to a continuous one. What counts as a security concern didn't change — how quickly it surfaces did.

What Continuous Vetting Actually Checks

The foundational authority is SEAD 6, issued by the Office of the Director of National Intelligence in 2018 to establish Continuous Evaluation (CE) — the automated-records framework that continuous vetting is built on. SEAD 6 authorizes checks using government databases, commercial databases, and other lawfully available information, and leaves the specific data sources and periodicity to implementing standards rather than spelling them out itself.

Notably, SEAD 6 as issued in 2018 described Continuous Evaluation as something that supplements — but does not replace — scheduled periodic reinvestigations. The actual elimination of periodic reinvestigations came later, through DCSA’s Trusted Workforce 2.0 implementation. SEAD 6 started the framework; TW 2.0 is what eventually let PRs be retired.

Under DCSA’s current Continuous Vetting implementation, checks cover seven broad categories:

Check Criminal History

Arrest and criminal records across jurisdictions.

Check Terrorism

Terrorism watchlist database matches.

Check Financial Activity

Reportable financial events and anomalies.

Check Credit

Ongoing credit activity, not just a one-time pull.

Check Public Records

Judgments, bankruptcies, and similar filings.

Check Foreign Travel

Foreign travel records surfaced through government data.

Check Eligibility Info

Agency-specific eligibility and personnel information.

Figure 2 The seven categories of automated checks under DCSA's current Continuous Vetting implementation. A match generates an alert — not an adverse determination.

When a check surfaces something, it generates an alert. An alert is not an adverse determination — DCSA assesses the information for validity and whether it warrants further investigation before anyone acts on it. SEAD 6 also builds in a specific safeguard here: unfavorable personnel-security action cannot be taken solely on uncorroborated or unverified discrepant information surfaced through CE. If something does warrant a closer look, it goes through the same adjudicative framework as anything else — the 13 guidelines, evaluated using the whole-person concept.

Reality check: Continuous vetting exists to close a timing gap, not to lower the bar for what counts as a security concern. The same 13 guidelines and the same mitigating conditions that applied under the old reinvestigation model still apply here — see how that plays out for debt and financial issues under Guideline F. What changed is how fast something can surface. What counts as a concern once it does hasn’t changed.


The April 2026 Update: What NISP Contractors Need to Know

DCSA’s Continuous Vetting guidance for NISP contractors — dated April 22, 2026, and publicly announced May 19 — supersedes guidance dated August 8, 2022, and incorporates changes tied to DISS Release 14.5. Here’s what it actually requires:

  • No more scheduled periodic reinvestigations for NISP contractor national security personnel.
  • The five-year questionnaire cycle itself isn’t new — contractors were already required to submit an updated PVQ periodically. What changed is the anchor date: DCSA now uses the “PVQ Date” in DISS — which reflects your actual SF-86 date — rather than the older Continuous Enrollment (CE) date.
  • Facility Security Officers use their DISS Subject Report to identify personnel approaching their PVQ deadline and route the update through the Personnel Security Management Office for Industry (PSMO-I).

One limitation worth knowing about: DCSA’s guidance states plainly that “CV enrollment reciprocity among agencies is not established.” If DCSA can’t verify your CV enrollment in DISS, an updated PVQ may still be required — including for personnel transferring between companies or agencies, or IC enrollment that isn’t visible in DISS. IC or SAP customers can also impose earlier PVQ requirements through their own contracting activity, which contractors are directed to follow. Reciprocity is a stated goal of Trusted Workforce 2.0, not a finished feature.


You Still Have to Self-Report

This is the part continuous vetting doesn’t change, and it’s the part that trips people up.

CV is an automated backstop that catches what shows up in records — credit reports, court filings, watchlist matches. It is not a substitute for your own disclosure obligations under SEAD 3. Exactly what you must report depends on your eligibility level, position sensitivity, and any additional agency or program requirements — the requirements are not identical across clearance levels.

Secret / L Baseline Applies broadly
  • Unofficial foreign travel and certain foreign contacts
  • Arrests or criminal charges — including a DUI
  • Qualifying media contact involving protected info
  • Certain alcohol or drug treatment
Top Secret / Q — Additional On top of the baseline
  • Financial anomalies below the Secret-level debt threshold
  • Certain foreign business, property, or banking interests
  • Foreign national roommates
  • Marriage and cohabitation
Figure 3 SEAD 3 self-reporting obligations scale with access. Top Secret/Q and critical/special-sensitive personnel carry meaningfully broader requirements on top of the baseline.

Reporting under SEAD 3 is mandatory, not discretionary, and it exists independently of whatever continuous vetting might eventually catch on its own. Failing to self-report can itself raise a security concern — the same dynamic covered in what the SF-86 actually asks and in common SF-86 mistakes. An automated system that eventually flags something you didn’t report doesn’t just raise the original issue. It raises the question of why you didn’t say something first.


The Tier System Is Also Changing — Slowly

Alongside continuous vetting, Trusted Workforce 2.0 is consolidating the legacy five-tier investigative model (Tier 1 through Tier 5, roughly mapped to non-sensitive positions through Top Secret/SCI) into three risk-based tiers: Low, Moderate, and High. The new structure is meant to align investigative scope more directly with actual risk rather than a legacy classification scheme, and to standardize vetting across civilian, military, and contractor populations under one framework.

This transition is still in progress, and it’s broader than the NISP-specific change above — but one major legacy piece is already gone. At the end of June 2026, DCSA sunset its legacy periodic-reinvestigation investigative products, with only limited exceptions; previously ordered reinvestigations continue to be processed. Meanwhile, the first two early-adopter Investigative Service Providers (ISPs) — the organizations that conduct background investigations — have transitioned to the new Trusted Workforce 2.0 investigative products, with other early adopters expected to transition during FY2026 Q4 and the remaining ISPs by FY2027. All ISPs are targeted to offer the new products by September 2027. Full population enrollment in continuous vetting — including the lowest-risk population — is targeted for September 2028.


What This Means If You’re Currently Cleared

You won’t get a reinvestigation notice the way you used to — at least not if you’re DoD. DoD’s cleared population has been enrolled in continuous vetting since 2021. Other federal populations are still transitioning: government-wide CV enrollment stood at 78% as of the most recent published reporting, with full population enrollment targeted for September 2028. Don’t wait for a scheduled event — if you’re cleared, assume your record is being checked continuously or will be soon.

Track your PVQ Date. If you’re a NISP contractor, ask your FSO when your questionnaire update is due. It’s tied to your last SF-86 submission, not a calendar year everyone shares.

Keep self-reporting on your own timeline, not CV’s. Report what SEAD 3 requires, when it’s required of your specific eligibility level, as it happens. Don’t treat continuous vetting as a reason to wait and see whether it surfaces on its own.

Financial and life changes still matter, exactly as much as before. A faster-moving check doesn’t change what counts as a concern. It changes how quickly a concern becomes visible. The same mitigation strategies that worked under periodic reinvestigation — disclosure, documentation, demonstrated trajectory — still apply.


Key Takeaways

  • DCSA eliminated periodic reinvestigations for NISP contractor national security personnel, per guidance dated April 22, 2026, and announced May 19, 2026, superseding guidance from August 2022.
  • The five-year PVQ update cycle isn’t new — what changed is the anchor date, now tied to your “PVQ Date” in DISS rather than the older Continuous Enrollment date.
  • SEAD 6 established the Continuous Evaluation framework in 2018 as a supplement to periodic reinvestigations, not a replacement. Trusted Workforce 2.0’s later implementation is what actually let DCSA retire the periodic reinvestigation for NISP contractors.
  • DCSA’s current Continuous Vetting implementation covers seven categories — criminal activity, terrorism, financial activity, credit, public records, foreign travel, and eligibility information — through automated checks conducted throughout an individual’s period of eligibility.
  • An alert is not an adverse determination. SEAD 6 prohibits adverse action based solely on uncorroborated or unverified information surfaced through CE.
  • CV does not replace your self-reporting obligations under SEAD 3, and those obligations vary by eligibility level — Top Secret/Q personnel have meaningfully broader reporting requirements than Secret/L personnel.
  • DCSA sunset its legacy periodic-reinvestigation investigative products at the end of June 2026, with only limited exceptions; previously ordered reinvestigations continue processing. The first two early-adopter ISPs have transitioned to the new TW 2.0 investigative products, with the rest targeted for FY2027.
  • Trusted Workforce 2.0 is also consolidating the legacy five-tier investigative model into three risk-based tiers (Low, Moderate, High). Government-wide CV enrollment stood at 78% as of the most recent reporting, with full population enrollment targeted for September 2028.
  • CV reciprocity across agencies is not established, per DCSA’s own guidance. Moving between contracts or agencies may still require updated paperwork even if you’re already enrolled elsewhere.

Sources


For how adjudicators evaluate flagged information using the whole-person concept, see The 13 Adjudicative Guidelines. For what the reinvestigation process replaced, see How Long Does a Security Clearance Take?. For the disclosure form where SEAD 3-adjacent issues originally get reported, see What Is the SF-86? and Common SF-86 Mistakes.

This article is informational, not legal advice. Continuous vetting policy is actively evolving under Trusted Workforce 2.0 — verify current requirements with your FSO, security office, or DCSA directly before relying on specific dates or thresholds.