Can the CEO Be the FSO? What Dual-Hatting Really Costs
Short answer: yes. Under the federal rule governing defense contractors (32 CFR Part 117 or NISPOM), one employee may hold more than one security role, and nothing stops that employee from being the chief executive. At small defense companies, it happens constantly: the company needs a facility clearance, somebody cleared has to take the appointment, and payroll math says it’s you.
So the real question isn’t whether you can. It’s what the hat costs in hours, and whether those hours should come from the person running the company. Below is the workload, straight from the rule.
Key takeaways
- Yes, a CEO can legally serve as the Facility Security Officer (FSO). One employee may hold the FSO, insider threat official, and senior management roles at the same time.
- The role must stay in-house: The official FSO must be a cleared U.S.-citizen employee. You can delegate the workload to outside support, but the appointment itself has to stay in-house.
- It is a real time commitment: 38.5 hours of mandatory federal training within six months of appointment, then an annual cycle of self-inspection, employee training, and government reporting.
- The timing is the government’s clock, not yours. Self-inspections, security reviews, and clearance deadlines arrive on DCSA’s calendar, and the workload grows with every new cleared employee.
- The seat can never sit empty. A dual-hatted CEO cannot hand off the FSO role until a cleared successor exists, which takes months.
First, which FSO we mean
FSO is an overloaded acronym. This article is about the Facility Security Officer at a cleared defense contractor: the person who supervises and directs the company’s security program under the National Industrial Security Program (NISP) and its governing rule, 32 CFR Part 117. Not the maritime facility security officer, and not a Foreign Service Officer.
The rule is specific about who can hold the job. The FSO must be a U.S. citizen, a direct employee of the company, cleared to the level of the facility clearance, and listed as Key Management Personnel (KMP). An outside consultant cannot be your FSO of record. The U.S.-citizen-and-employee requirement is in 32 CFR 117.9(d); the clearance-level and KMP requirements are in 117.7(b)(1)(iv).
The rule allows dual-hatting. That’s exactly the trap.
The rule never says “the CEO can be the FSO” in those words. It gets there in pieces. Section 117.7(b)(1)(i) says a single employee may serve in more than one security position. Section 117.7(b)(2) puts the Senior Management Official (the SMO, usually the CEO at a small company) in charge of appointing the FSO and the Insider Threat Program Senior Official (ITPSO) in writing, and lets the SMO name one person to both roles. Nothing in the rule bars the SMO from appointing themselves. Put those together and one founder can lawfully hold the SMO, FSO, and ITPSO roles at once. That is how the CEO becomes the FSO, not because the rule names the job for them, but because the pieces line up.
That flexibility exists for a good reason: a six-person company can’t staff a security department. But the duties don’t shrink with headcount. The same rule that lets you wear every hat also writes the job description for each one, and none of it is waived because you’re busy.
The up-front bill: training and the clearance package
Start with training. A new FSO must complete the required security training within six months of appointment (117.12(d)). For DoD contractors that means the Center for Development of Security Excellence (CDSE) curriculum: 26.5 hours of courses and exams if your facility won’t store classified material, 38.5 hours if it will. The American Council on Education has evaluated that training at three semester hours of college credit. That’s a college course on the side, while you run the company.
Then there’s the Facility Clearance (FCL) Process itself, where a dual-hatted CEO does double duty: you’re the executive signing the paperwork and the security officer assembling it. A company can’t legally sponsor its own Facility Clearance (FCL), you must first be sponsored by a cleared prime contractor or a government agency. Once sponsored, you will navigate the registration process as a dual-hatted CEO, acting as both the executive signing the corporate agreements and the security official assembling the compliance package. This documentation includes your corporate governance documents (which defines your KMPs), foreign ownership disclosures, and the official appointment letters naming you as the FSO and ITPSO.
The government sets specific target deadlines inside the process. Once the initial FCL package is submitted, DCSA typically aims to initiate the personal security clearance process for your required KMPs within 45 days. However, while your internal submission windows are firm, the agency’s overall processing speeds can be unpredictable, and DCSA does not publish a guaranteed end-to-end timeline for final facility approval.
According to DCSA’s published statistics, 70% of initial facility clearance packages are rejected on the first try due to minor administrative or clerical errors, cycling an average of 2.5 times before acceptance. Industry reporting in 2026 puts routine end-to-end timelines at 180 days or more. Keeping the initial package completely accurate is critical to avoiding extensive manual rework.
After the clearance: the drumbeat nobody budgets for
Getting the FCL is the sprint. Keeping it is what eats the calendar. The recurring obligations are written directly into Part 117:
Securing your company’s FCL is a major milestone. But maintaining it requires an ongoing operational cadence. The federal government mandates a recurring cycle of security maintenance that simply cannot be skipped.
| Cadence | Required Security Duty | Where it’s written |
| Upon Hire / Before Access | Conduct an initial security orientation briefing for newly cleared employees covering basic threat awareness, reporting obligations, and safeguarding duties. | 32 CFR 117.12(e) |
| Upon Hire / Before Access | Provide newly cleared employees with initial insider threat awareness training. | 32 CFR 117.12(g)(2) |
| Annually | Conduct a formal, comprehensive self-inspection of your security program and retain the report for DCSA review. | 32 CFR 117.7(h)(2) |
| Annually | The SMO must certify to DCSA in writing that the self-inspection happened and corrective actions were taken. | 32 CFR 117.7(h)(2)(iii) |
| Annually | Run combined security refresher and insider threat awareness training for all cleared employees, and document completion. | 32 CFR 117.12(k) & (g)(2) |
| Continuous | Clearance & System Administration: Manage personnel security clearances (PCLs), process new investigation submissions, monitor Continuous Vetting compliance, and maintain government databases (NISS, DISS, and NBIS). | 32 CFR 117.10 |
| Continuous | Foreign Travel Reporting: Track, brief, and formally report all official and personal international travel for your cleared employees. | SEAD 3 Mandate |
| Ongoing | Incident Reporting: Report adverse information regarding cleared employees, suspicious foreign contacts, or changes to company ownership, addresses, or KMPs. | 32 CFR 117.8 |
| As Scheduled | Host DCSA agents at your office for formal, in-person security reviews and audits. | 32 CFR 117.7(h)(1) |
Nobody publishes how many hours a week this adds up to at a small facility. Not DCSA, not CDSE, not any industry survey.
What the rule publish, however, the strict cadence listed above, and the pattern is what matters. Managing your company’s security program creates a steady weekly baseline of administrative data entry, system upkeep, and reporting judgment calls. Punctuated by sharp spikes around self-inspection season, security reviews, new hires, and every package DCSA sends back. The hours are real, they land on you according to the government’s timetable rather than when it suits you, and they grow with headcount, because every new cleared employee adds training, vetting, and reporting surface.
What it costs when it slips
The downside isn’t administrative slaps on the wrist. If DCSA reviews your facility and determines that your security program is non-compliant, they have the immediate authority to invalidate your facility clearance.
By law, a company with an invalidated clearance is completely blocked from bidding on or being awarded new classified contracts. Existing classified work can only continue if the specific government agency sponsoring you signs off on a special waiver. If DCSA goes a step further and revokes your clearance, your classified business operations end instantly.
Two more provisions make the dual-hat arrangement brittle. First, the FSO seat can never sit empty: “a cleared employee must always be appointed” (117.9(g)(1)). Before a dual-hatted CEO can hand off the role, a cleared successor has to exist, and clearances take months. Second, that annual certification means one signature attests to both the work and the oversight of the work. A security program that is one overloaded person deep has no slack, and a security review is exactly when that shows.
Your three realistic options
- Keep the hats and budget the real hours. Legitimate for some companies, especially before storage approval, with a handful of cleared employees. If you choose it, block real calendar time: the training up front, the annual cycle, and slack for DCSA’s schedule, not yours.
- Hire a dedicated FSO. The clean fix when classified work is the core of the business. Crowd-sourced salary data puts experienced FSOs in the high five to low six figures: PayScale’s 2025 range runs roughly $61K to $120K, and Glassdoor’s 2026 average total-pay estimate is about $130K. For a company with one classified contract, that’s heavy overhead for a role that isn’t billable.
- Keep the title, delegate the workload. The rule requires the FSO of record to be your employee. It says nothing against putting trained support behind that person.
That’s what Managed Security Services are: the named FSO stays in-house (you, or someone you appoint), while the program work (packages, managing government databases (like NISS, DISS, and NBIS), tracking employee training milestones, and prepping your team for self-inspections) is carried by people who do it every day across many facilities. We’ve made the case for delegating before; the short version is that the hat has to stay on someone’s head in your company, but the hours don’t.
If the hat stays on your head, the hours don’t have to
Nooks Managed Security Services takes on the day-to-day security work for cleared and soon-to-be-cleared companies: FSO support, personnel security, and program security, from first sponsorship through the annual audit cycle, we handle the paperwork, tracking, and database management behind the scenes.
Your named FSO and security program stay safely in-house; we carry the operational weight.
If you’re staring down an upcoming FCL application, or already wearing the FSO hat and feeling the operational drag, talk to us. We’ll tell you plainly which parts to keep in-house and which parts we can carry.
FAQ
Can the CEO or owner of a company be the FSO?
Yes, though the rule never says so in those words. It follows from the pieces: 32 CFR 117.7(b)(1)(i) lets one employee hold more than one security role, and 117.7(b)(2) has the Senior Management Official (often the CEO) appoint the FSO, with nothing barring the SMO from appointing themselves. The person must be a U.S. citizen, a direct employee, cleared to the facility clearance level, and on the Key Management Personnel list.
Can a company outsource its FSO completely?
No. The FSO of record must be a U.S.-citizen employee of the company (32 CFR 117.9(d)). Outside providers can lawfully carry much of the workload behind that named employee, but the appointment itself stays in-house.
How much training does a new FSO need?
Required training must be completed within six months of appointment (32 CFR 117.12(d)). For DoD contractors, CDSE’s curriculum runs 26.5 hours for non-possessing facilities and 38.5 hours for possessing facilities, courses and exams included.
How long does getting an FCL take?
DCSA does not publish a timeline. Its published package statistics show 70% of initial and upgrade FCL packages rejected, cycling 2.5 times on average before acceptance. Industry reporting in 2026 describes 180 days or more as routine.
What happens if the FSO role sits empty?
It can’t. Under 32 CFR 117.9(g)(1), the FSO and ITPSO positions may not be temporarily excluded; a cleared employee must always hold them. Practically: a dual-hatted CEO can’t hand off the hat until a cleared successor already exists.
Sources
- 32 CFR Part 117, current text (sections 117.7, 117.8, 117.9, 117.10, 117.12)
- DCSA, Facility Clearances
- DCSA news, package rejection statistics (Feb 2023)
- CDSE, FSO Orientation for Non-Possessing Facilities (IS020.CU, 26.5 hours)
- CDSE, FSO Program Management for Possessing Facilities (IS030.CU, 38.5 hours)
- DCSA, SEAD-3 unofficial foreign travel reporting
- ISI, The Facility Clearance Bottleneck (June 2026, industry estimate)