What is FOCI?
Lightbridge Cloud defines FOCI, Foreign Ownership, Control or Influence, as the condition where a foreign interest holds enough ownership or sway over a cleared U.S. contractor to compromise classified or export-controlled work. The Defense Counterintelligence and Security Agency administers FOCI review and mitigation under 32 CFR Part 117, the NISPOM rule.
FOCI is a security condition that DCSA reviews under 32 CFR Part 117.
A U.S. company falls under Foreign Ownership, Control or Influence when a foreign interest, a foreign person, company, or government, holds enough ownership of or sway over the business that it could gain unauthorized access to classified information or impair performance on classified contracts. The Defense Counterintelligence and Security Agency, DCSA, assesses FOCI whenever a contractor seeks or holds a facility clearance under the National Industrial Security Program.
The governing text is 32 CFR Part 117, the National Industrial Security Program Operating Manual, known as the NISPOM rule. Part 117 sets out how a contractor reports foreign interests, how DCSA decides whether those interests create unacceptable risk, and which mitigation instruments may be applied to bring the foreign interest under control. Because section numbers and procedural details change over time, verify the current language against the eCFR and DCSA before relying on any specific clause.
Lightbridge Cloud is an independent, vendor-neutral advisory firm. This guide describes FOCI from published federal requirements as the field actually stands; Lightbridge helps cleared contractors prepare for review and align their technology, and it does not adjudicate clearances or provide legal representation.
FOCI turns on ownership, control, and influence, which are not the same thing.
The three words in FOCI describe different ways a foreign interest can reach into a cleared U.S. business. DCSA evaluates each because the degree and type of foreign reach drive which mitigation instrument applies. A small minority stake is treated very differently from effective control of the board.
Foreign ownership
A foreign interest holds a stake in the U.S. entity, directly or through intermediate parents. The percentage held and whether it confers control shapes which mitigation instrument applies.
Foreign control
A foreign interest can direct or decide the management or operations of the company, through voting rights, board seats, contracts, or financial dependency, even without majority ownership.
Foreign influence
A foreign interest can affect decisions short of control, for example through a minority stake, debt, or a supply relationship. Influence without control often points toward a Board Resolution or an SCA.
FOCI mitigation instruments scale with the degree of foreign control.
When DCSA finds FOCI, it does not automatically deny a clearance. Instead it looks for a mitigation instrument that reduces the foreign interest to an acceptable level. The instruments form a ladder: the more ownership and control a foreign interest holds, the more restrictive the instrument required. DCSA decides which instrument fits a given ownership structure.
Board Resolution
The lightest instrument, used when a foreign interest is present but does not hold a controlling stake. The board formally resolves to exclude the foreign owner from access to classified information and from decisions that bear on the cleared work, and documents that exclusion.
Security Control Agreement (SCA)
An SCA applies when a foreign interest can influence the company but does not effectively control it. The foreign owner keeps board representation, while the agreement constrains access to classified material and defines the security controls the cleared entity operates under.
Special Security Agreement (SSA)
An SSA is used when a foreign interest effectively controls a U.S. company that still needs facility clearance. It permits foreign ownership while inserting outside and resident directors who hold the security responsibility, and it has historically required a National Interest Determination for access to certain proscribed information, though that requirement has narrowed.
Proxy Agreement
A Proxy Agreement vests the foreign owner's voting rights in cleared U.S. citizens, the proxy holders, who exercise those rights independently. The owner retains economic benefit but relinquishes day-to-day control, severing foreign influence over the cleared operation.
Voting Trust Agreement (VTA)
A Voting Trust is the most restrictive instrument. The foreign owner transfers voting stock to cleared U.S. citizen trustees who run the company free of owner direction. Like a Proxy Agreement, it preserves financial ownership while removing operational control entirely.
Higher instruments such as an SSA, a Proxy Agreement, or a Voting Trust typically come with added requirements, including a Government Security Committee on the board and, for certain proscribed information, a National Interest Determination. Treat the boundaries between instruments as guided by DCSA judgment, not a fixed formula, and confirm current procedures with DCSA.
FOCI sits alongside export control, but the two regimes are distinct.
FOCI under 32 CFR Part 117 protects classified information and the security of cleared facilities. Export controls, the International Traffic in Arms Regulations administered by the State Department and the Export Administration Regulations administered by the Commerce Department, govern the transfer of controlled technology and technical data, including disclosure to foreign persons inside the United States. A company under a FOCI mitigation instrument almost always carries deemed-export and technology-control obligations at the same time.
Treating these as one program avoids gaps. Foreign access restrictions written into a mitigation instrument shape how technology-control plans, identity controls, and data residency are configured. Lightbridge Cloud explains the export side in its ITAR and EAR export control guide, and verify current jurisdiction and licensing details against DDTC and BIS, since classifications and thresholds change.
FOCI mitigation shapes how a cleared contractor configures its cloud.
A mitigation instrument is not only a governance document. It dictates who may administer systems, who may access controlled data, and where that data may reside, which lands squarely in cloud and identity architecture. A contractor under FOCI still has to protect controlled unclassified information in line with CMMC and the underlying NIST controls, so the security architecture has to enforce the foreign access restrictions the instrument requires.
Cloud regions and government-focused offerings from providers such as AWS, including AWS GovCloud, and Microsoft Azure are common starting points for that work. AWS, GovCloud, Azure, and Microsoft are trademarks of their respective owners, and Lightbridge Cloud is not affiliated with, endorsed by, or a partner of those vendors. Lightbridge aligns the environment with both governance and security obligations through its CMMC compliance readiness work.
Lightbridge Cloud prepares cleared contractors for FOCI review, independently.
Lightbridge Cloud helps cleared and aspiring contractors read their own ownership structure, understand which mitigation instrument it points toward, assemble the documentation DCSA expects, and design the cloud and identity architecture that enforces foreign access restrictions in practice. The work is readiness and technical alignment, grounded in published federal requirements rather than any vendor relationship.
Lightbridge does not adjudicate clearances, does not provide legal representation, and does not guarantee a DCSA outcome; those decisions rest with the government and with the contractor counsel. Because Lightbridge is vendor-neutral and independent, its recommendations follow the requirement and the structure, not a partner incentive. The natural companions to this guide are CMMC compliance readiness and the ITAR and EAR export control guide.
This guide is general information, not legal, audit, or accounting advice. Regulations, section numbers, thresholds, and procedures change. Verify against the official sources, including the eCFR for 32 CFR Part 117, DCSA, and DDTC and BIS for export control, before acting.
FOCI and FOCI mitigation: frequently asked questions
- What is FOCI in simple terms?
- FOCI stands for Foreign Ownership, Control or Influence. In simple terms, a U.S. company is under FOCI when a foreign interest, whether a person, company, or government, holds enough ownership of or sway over the business that it could gain unauthorized access to classified information or undermine performance on classified contracts. The Defense Counterintelligence and Security Agency, DCSA, reviews FOCI when a contractor seeks or holds a facility clearance and decides whether the foreign interest can be mitigated. Lightbridge Cloud is an independent advisory firm and helps cleared contractors prepare for that review; it does not adjudicate clearances.
- What regulation governs FOCI?
- FOCI is governed by 32 CFR Part 117, the National Industrial Security Program Operating Manual, commonly called the NISPOM rule. The rule was codified into the Code of Federal Regulations and replaced the prior standalone DoD manual, and it is administered by DCSA. Part 117 sets out how a cleared contractor reports foreign interests, how DCSA assesses whether those interests create unacceptable risk, and which mitigation instruments may be applied. Specific section numbers and procedural details change over time, so verify the current text against the official source at the eCFR and DCSA before relying on any clause.
- What are the FOCI mitigation instruments?
- The recognized mitigation instruments scale with the degree of foreign ownership and control. From lightest to most restrictive they are: a Board Resolution, a Security Control Agreement (SCA), a Special Security Agreement (SSA), a Proxy Agreement, and a Voting Trust Agreement (VTA). A Board Resolution suits a non-controlling foreign interest, an SCA addresses influence without effective control, an SSA permits foreign control under inserted outside directors, and a Proxy Agreement or Voting Trust removes operational control while preserving economic ownership. DCSA determines which instrument fits a given ownership structure.
- What is the difference between an SSA and a Proxy Agreement?
- A Special Security Agreement permits a foreign interest to retain control of a cleared company while outside and resident directors carry the security responsibility, and it often requires a National Interest Determination for access to certain proscribed information. A Proxy Agreement goes further: the foreign owner assigns its voting rights to cleared U.S. citizen proxy holders who run the company independently, so the owner keeps the economic benefit but gives up control. In broad terms, an SSA manages foreign control, while a Proxy Agreement or Voting Trust eliminates it operationally.
- Does FOCI relate to export controls like ITAR and EAR?
- They are distinct regimes that frequently overlap. FOCI under 32 CFR Part 117 concerns access to classified information and the security of cleared facilities, while ITAR and the EAR govern the export and transfer of controlled technology and technical data, including disclosure to foreign persons inside the United States. A company under a FOCI mitigation instrument usually also has to manage deemed-export and technology-control obligations. Lightbridge Cloud covers that intersection in its ITAR and EAR export control guide.
- How long does FOCI mitigation take to put in place?
- Timelines vary widely with the complexity of the ownership structure, the instrument selected, and DCSA workload, so any single figure would be misleading. Lighter instruments such as a Board Resolution are generally faster to document than a Proxy Agreement or Voting Trust, which involve appointing and clearing trustees or proxy holders and standing up governance bodies. Treat published timeframes as directional and confirm current expectations with DCSA. Lightbridge Cloud helps cleared contractors assemble the documentation and security architecture so the review proceeds without avoidable rework.
- How does FOCI connect to CMMC and cloud security?
- A cleared contractor under FOCI mitigation still has to protect controlled unclassified information in its IT environment, which is where CMMC and the underlying NIST controls apply. Foreign access restrictions in a mitigation instrument frequently shape how cloud and identity controls are configured, including who may administer systems and where data may reside. Lightbridge Cloud aligns the technical environment with both obligations through its CMMC compliance readiness work, treating governance and security architecture as one program rather than two.
- How does Lightbridge Cloud help with FOCI?
- Lightbridge Cloud is an independent, vendor-neutral advisory firm. It helps cleared and aspiring contractors understand which FOCI mitigation instrument their ownership structure points toward, prepare the documentation DCSA expects, and design the cloud and identity architecture that enforces foreign access restrictions in practice. Lightbridge does not adjudicate clearances, provide legal representation, or guarantee an outcome; those decisions rest with DCSA and with the contractor counsel. The role is readiness and technical alignment, grounded in published federal requirements rather than any vendor relationship.
From understanding FOCI to being ready for review.
When the question shifts from what FOCI is to whether your structure and systems are ready, Lightbridge Cloud helps prepare the documentation and the cloud architecture, independently and grounded in published requirements.