← Back to Field notes
WINROVE / Compliance

Understanding the OPM SF-312 Nondisclosure Agreement: A Comprehensive Guide

Learn about the OPM SF-312 Nondisclosure Agreement, its importance, and how to comply with it effectively. Essential for government contractors and employees.

March 15, 2026 · Winrove Team

Cover illustration for Understanding the OPM SF-312 Nondisclosure Agreement: A Comprehensive Guide

A defense contractor's program manager receives her facility clearance approval on a Friday afternoon. By Monday morning, she is expected to be in a classified program review. Before she touches a single controlled document, her security officer hands her one form that must be signed, witnessed, and filed: the SF-312 Classified Information Nondisclosure Agreement. No signature, no access. That sequence is not optional, and it is not bureaucratic theater. The SF-312 is a binding federal legal instrument, and the obligations it creates follow a signatory for life, not just for the duration of a contract.

What the SF-312 Actually Is

The SF-312 is a standard form issued under the authority of the National Industrial Security Program (NISP) and administered through the Information Security Oversight Office (ISOO) under the National Archives and Records Administration (NARA). Its full title is the "Classified Information Nondisclosure Agreement." The legal authority behind it runs through Executive Order 13526 (Classified National Security Information) and the implementing directives of the Information Security Oversight Office (ISOO) and the National Industrial Security Program Operating Manual (NISPOM). When an individual signs the SF-312, they are not acknowledging a policy memo. They are entering a contract with the United States Government that carries enforceable civil and criminal consequences.

The form itself is two pages. Page one contains the agreement language. Page two is the witness and acceptance block, which must be completed by an authorized government representative, typically a security officer or contracting officer's representative. An unsigned witness block renders the form incomplete. Many onboarding processes fail at exactly this step because the witness is not present or the form is routed electronically without a proper execution process in place.

Who Must Sign and When

The SF-312 requirement applies broadly. The following categories of personnel must execute the agreement before being granted access to classified information at any level (Confidential, Secret, or Top Secret):

  • Federal civilian employees receiving an initial or upgraded clearance
  • Military personnel transitioning into positions requiring a formal NDA on file
  • Contractor employees working under a Facility Security Clearance (FCL), including those on classified task orders under IDIQ vehicles
  • Subcontractor personnel whose work brings them into contact with classified program information
  • Foreign nationals granted limited access authorizations under specific program exceptions

Timing matters. The SF-312 must be signed before access is granted, not concurrently with it and not after the fact. A common error in contractor onboarding is granting badged access to a classified facility while the paperwork is still in transit. That sequence creates a compliance gap that can surface during a Defense Counterintelligence and Security Agency (DCSA) audit.

What the Agreement Requires: Specific Obligations

The SF-312 is not a general confidentiality pledge. It imposes specific, enumerated obligations that persist after employment or contract performance ends. Understanding each obligation is necessary before signing.

Non-Disclosure During and After Access

The signatory agrees never to disclose classified information to any person not authorized to receive it. This obligation has no expiration date. A contractor who worked on a classified satellite program in 2010 and left government work entirely in 2015 is still bound by this clause in 2025. The information does not become disclosable simply because the contract ended or the individual changed careers.

Pre-Publication Review

One of the most frequently overlooked provisions is the pre-publication review requirement. If a signatory intends to publish, present, or otherwise release information that might be derived from or related to classified work, they must submit that material for government review before release. This applies to books, articles, conference presentations, blog posts, and social media content. Former intelligence community contractors who have written memoirs have faced civil action under this clause.

Proper Handling and Storage

Classified materials must be stored in GSA-approved security containers (typically a General Services Administration-approved safe rated for the classification level), transmitted only through approved channels, and handled in accordance with the applicable security classification guide. Leaving a classified document on an unattended desk, even briefly, is a reportable security incident.

Reporting Obligations

The SF-312 requires signatories to report any known or suspected unauthorized disclosure of classified information. This is not discretionary. If a contractor employee witnesses a colleague discussing classified program details on a personal cell phone in a cleared facility, they are obligated to report it to the Facility Security Officer (FSO). Failure to report is itself a violation of the agreement.

Return or Destruction of Materials

Upon termination of access, all classified materials in the signatory's possession must be returned to the government or destroyed in accordance with approved destruction procedures (cross-cut shredding to NSA/CSS EPL-listed standards, or burning). Simply deleting a file from a laptop does not constitute proper destruction of classified information.

Consequences of Violation: The Full Picture

The consequences of violating the SF-312 operate on multiple tracks simultaneously, and they are not mutually exclusive.

Criminal Liability

Unauthorized disclosure of classified information can be prosecuted under 18 U.S.C. § 798 (disclosure of classified information), the Espionage Act (18 U.S.C. §§ 793-798), and the Intelligence Identities Protection Act, among other statutes. Penalties range from substantial fines to imprisonment of up to ten years per count, depending on the statute and the classification level of the disclosed information.

Civil Liability

The government may pursue civil remedies including injunctions to prevent further disclosure, disgorgement of any financial proceeds derived from the unauthorized disclosure (relevant in book deals or media appearances), and monetary damages. The pre-publication review violation cases pursued against former intelligence officers have resulted in settlements requiring authors to surrender all profits from non-reviewed publications.

Security Clearance Revocation

A violation of the SF-312 is grounds for clearance revocation under the adjudicative guidelines administered by DCSA. Revocation effectively ends a career in classified contracting. Because clearance status is reported across agencies, a revocation in one program follows the individual across the federal contracting ecosystem.

Executing the SF-312 Correctly: A Step-by-Step Process

For FSOs and onboarding teams managing contractor personnel, the execution process requires attention to several operational details.

  1. Obtain the current version of the form. The SF-312 is available through OPM and GSA Forms Library. Using an outdated version is a common audit finding. Verify the edition date on the form footer before printing.
  2. Brief the individual before signature. The signatory must receive a security briefing that covers the obligations in the agreement. Handing someone a form to sign without a briefing does not constitute informed consent and may not satisfy DCSA requirements.
  3. Execute in the presence of a witness. The witness must be a U.S. Government representative. A contractor employee cannot serve as the witness for another contractor employee. The FSO or a government contracting officer's representative must be present.
  4. Complete the acceptance block. The government acceptance block on page two must be signed and dated. An agreement signed by the employee but lacking government acceptance is not a completed SF-312.
  5. File and track the original. The original signed form must be retained in the individual's security file. A copy may be provided to the signatory. The retention requirement persists for the life of the clearance and beyond.
  6. Document the briefing in the security management system. Record the date of execution, the briefing officer, and the form version in whatever system of record the organization uses for clearance management.

Integrating SF-312 Execution into Contractor Onboarding

For organizations managing multiple cleared personnel across several contracts, tracking SF-312 execution manually creates real compliance risk. A single missed form discovered during a DCSA audit can trigger a broader review of the organization's security program. Onboarding platforms designed for federal contractor workflows can enforce the correct sequence: clearance verification, then briefing scheduling, then form execution, then access provisioning. Winrove, developed by IT Custom Solution LLC, is built specifically for this environment, providing structured onboarding workflows that keep security documentation steps in the correct order and create an auditable record of completion.

The SF-312 is also a useful forcing function for reviewing the rest of a cleared employee's onboarding package. If the form is not yet signed, access should not be granted, and that gate naturally surfaces other incomplete items: DD Form 254 review, program-specific security briefings, and initial security training acknowledgments.

Practical Takeaway

The SF-312 is not a checkbox. It is a permanent legal obligation that attaches to the individual, not to the contract or the employer. FSOs and onboarding leads should treat its execution as a hard gate in the access provisioning sequence, verify the form version before each use, ensure a qualified government witness is present, and retain the original in a trackable security file. Organizations that build this discipline into a documented onboarding workflow, rather than relying on individual memory, are the ones that pass DCSA audits without findings.

Preserved Field Notes article. Original path /blog/understanding-the-opm-sf-312-nondisclosure-agreement/. No unrelated help guide has been substituted.

Related Field notes

Reading a DPAS Priority Rating on a Federal Order: What Contractors Must Know ↗

Wide Area Workflow (WAWF) Invoicing Basics for New Federal Contractors ↗

Provisional Billing Rates and Indirect Rate Structures, Explained Simply ↗

Cost Realism: Surviving the Government Price Analysis ↗

The compliance matrix step most small contractors skip (and how it loses bids) ↗

NAICS Code Selection and Recertification: Avoiding the Small-Business Size-Standard Trap ↗