DI-MGMT-80934D
Operations Security (OPSEC) Plan
The OPSEC Plan identifies and monitors a contractor's OPSEC activities during contract performance, documenting the OPSEC environment, risk analysis, measures, responsibilities, and history.
Approval DateFebruary 25, 2026
AMSC Number10643
Preparing ActivityNS/A5
Project NumberMGMT-2026-008
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The OPSEC Plan is used to identify and monitor a contractor's OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the OPSEC environment to include identification of critical information and indicators, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical information, (2) Documents the OPSEC risk analysis, (3) Identifies proposed and actual OPSEC measures/countermeasures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to the contractor's corporate OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.
a. This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.
b. This DID is applicable only when the contracting activity determines that the sensitivity of the contracted effort warrants OPSEC protections.
c. The contractor's implementation of the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or inspection by the Defense Counterintelligence and Security Agency (previously known as the Defense Security Service) and the contracting activity.
d. This DID supersedes DI-MGMT-80934C.
Preparation Instructions
1Reference documentsThe applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the contract.
1.1Department of Defense Manual (DoDM) 5205.02, DoD Operations Security (OPSEC) Program ManualDated 3 November 2008 (Incorporating Change 2, Effective October 29, 2020). This manual implements policy, assigns responsibilities, and provides procedures for managing DoD OPSEC programs. DoDM 5205.02 is unclassified and cleared for public release. This document is available on the Directives Division Website at https://www.esd.whs.mil/DD/ or the following web address: https://www.esd.whs.mil/portals/54/documents/dd/issuances/dodm/520502m.pdf.
1.2Joint Publication 3-55 (JP 3-55), Joint Operations SecurityDated 20 February 2025. The publication supersedes JP 3-13.3, Operations Security, dated 6 January 2016 and provides fundamental principles and guidance to plan, execute, and assess operations security within joint operations and activities. This publication is available at the Joint Doctrine, Education and Training Electronic Information System (JDEIS) website: https://www.jdeis.js.mil. A Common Access Card (CAC) is required to access the JDEIS website.
1.3Navy Tactics, Techniques, and Procedures (NTTP) 3-13.3, Operations SecurityDated 16 December 2022. While developed for the U.S. Navy, NTTP 3-13.3 provides guidance that is relevant to other DoD components to assist in identifying critical information and applying OPSEC considerations in mission planning and day-to-day activities. NTTP 3-13.3 is unclassified and approved for public release. This document is available at the following web address: https://www.navifor.usff.navy.mil/Portals/48/OPSEC/May%202023%20uploads/NTTP%203-13.3%20OPSEC%20(DEC%202022).pdf.
1.4Department of Defense Contract Security Classification Specification (DD254)This document is included as a part of all Request for Proposals (RFP) and Contracts involving classified data.
1.5Contract Data Requirements List (CDRL)This document is included as a part of all RFP and contracts containing data deliverable requirements.
1.632 Code of Federal Regulation (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM) RuleEffective 24 August 2021. The 32 CFR Part 117, NISPOM Rule replaces the NISPOM previously issued in DoD 5220.22M, dated 24 February 2006. Information on the NISPOM Rule from the Defense Counterintelligence Security Agency (DCSA) is available at the following web address: https://www.dcsa.mil/Industrial-Security/National-Industrial-Security-Program-Oversight/32-CFR-Part-117-NISPOM-Rule/. The 32 CFR Part 117, NISPOM Rule is also available through the eCFR website at the following web address: https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-117.
2FormatThe OPSEC Plans shall be submitted in contractor determined format and, at a minimum, consist of the following sections listed in the Content Section below.
3.1Cover PageThe cover page for an OPSEC Plan shall clearly present, at a minimum, the following information: 1. Title of the Acquisition Program 2. Title of the Document (i.e. "Operations Security Plan") 3. Reference to the government contract number 4. Date of latest revision 5. Name, signature and title of the preparer of the OPSEC Plan 6. Name, signature and title of the approver of the OPSEC Plan. 7. Reference for whom the document was prepared (Contracting activity) 8. Reference by whom the document was prepared (Corporation) 9. All appropriate distribution or classification statements
3.2Table of Contents PageThe Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC Plan.
3.3Preface PageThe purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.
The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.
3.4OPSEC Plan Introduction
3.4.1Purpose and ScopeThe purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).
3.4.2AuthoritiesThe requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate OPSEC Program (Policy) and Plan, DoDM 5205.02, specific contract documents including the DD254 for contracts involving classified data, or other contracting activity specific guidance.
3.4.3OPSEC Plan Major Activity TimelineThis section shall include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Group Meetings, Annual Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and Surveys, Threat and Vulnerability Reviews, etc. This section shall also include scheduled OPSEC Plan reviews.
3.4.4ResponsibilitiesThe OPSEC Plan shall identify whom is responsible for the major activities described in the Plan. For example (not intended as an inclusive list):
The OPSEC Program Manager shall be identified by name and include a list of duties that may include: 1. Coordinate all OPSEC policy responsibilities/ procedures within the program. 2. Revise the Program OPSEC Plan as necessary. 3. Convene and coordinate the annual Program OPSEC Assessment. 4. Disseminate updated threat information to program personnel. 5. Assist in the review of contract requirements for OPSEC considerations. 6. Conduct OPSEC briefing(s) upon customer approval of the plan. 7. Principal advisor to the Contractor Program Manager on all OPSEC matters. 8. Develop/Disseminate Program Critical Information and Indicators List (CIIL). 9. Promote OPSEC awareness within the program.
The Contractor Program Manager shall be identified by name and include a list of duties that may include: 1. Responsible for the overall implementation of the program/contract. 2. Ensure proper OPSEC procedures are implemented by program personnel. 3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan. 4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program. 5. Actively participate in periodic Program OPSEC assessments. 6. Remain cognizant of any changes in critical information and communicate them to the OPSEC Program Manager. 7. Promote OPSEC awareness within the program.
A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include: 1. Remain compliant with all applicable OPSEC Plans. 2. Maintain an awareness of all applicable CIIL. 3. Attend all OPSEC program briefings. 4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the OPSEC Program Manager. 5. Generation of OPSEC Plans (sub-contractors or suppliers only).
3.4.5Organizational OPSEC Communications and InterfacesA description as to how the OPSEC Plan will be communicated to all personnel supporting the program (hardcopy, via a webpage, briefings, etc.).
3.4.5.1InternalIn this section the OPSEC Plan shall identify all anticipated OPSEC interfaces internal to the corporation such as the senior corporate leadership, corporate OPSEC Working Group, OPSEC coordinators, program personnel, etc.
3.4.5.2ExternalIn this section the OPSEC Plan shall identify all anticipated external points of contact such as the contracting activity, Defense Contract Management Agency (DCMA), Defense Counterintelligence Security Agency (DCSA), Federal Bureau of Investigation (FBI) and local law enforcement and their primary role within the OPSEC program (i.e. DCMA audits acquisition management practices, DCSA provides security oversight, FBI and law enforcement may provide threat data). Subcontractor and supplier OPSEC points of contact shall be similarly identified. (The Defense Counterintelligence Security Agency (DCSA) was formerly the Defense Security Service (DSS).)
3.4.6Marking, Handling and Distribution of DocumentsThis section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.
Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.
3.4.7Obfuscation RequirementsThis section includes instructions and procedures to maintain OPSEC, safeguard critical information, and reduce detectable indicators in the course of Department of Defense (DoD) acquisitions and procurements. Specifically, this section identifies the procedures to be used to ensure anonymity between the U.S. Government and the prime Contractor, ensuring that any offshore vendors, suppliers, manufacturers, or distributors are unaware of the relationship between the item being purchased and the DoD.
This section of the OPSEC Plan shall outline the Contractor's offshore procurement procedures used for design, production, or packaging of equipment, components, and parts from sources outside the United States. The emphasis is on how these procedures ensure that the offshore subcontractors, vendors, distributors, or manufacturers of these items are not made aware of the relationship between the prime Contractor and the DoD through any aspect of the procurement or process. These procedures shall be classified in accordance with the program's Classification Guide (if available).
3.5.1General ThreatThis section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following: In DCSA's annual assessment Targeting U.S. Technologies: A Report of Threats to Cleared Industry for Fiscal Year 2025, it assessed that "foreign intelligence entities are persistent in their efforts to steal critical American technology, compromise sensitive data, and undermine our nation's defense capabilities. Using tactics from cyberattacks to supply chain disruption, their objective is not only to exploit vulnerabilities, but also to pilfer technology and talent to advance their own military and economic development at the expense of ours. Vigilance is required to identify understand, and deter these dynamic threats. The cleared national industrial base-which includes academia, corporations of all sizes, and the personnel who research, develop, and field our nation's technologies-is a primary target for these foreign threats. As the cleared national industrial base continues to produce innovative capabilities, it becomes an even more attractive target for our adversaries."
The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.
Note: A general description of intelligence collection methods may be found in DoDM 5205.02, JP 3-55, and NTTP 3-13.3. (The example provided is derived from annual documentation produced by DCSA in 2026. Current assessments may be found at https://www.dcsa.mil/Counterintelligence-Insider-Threat/.)
3.5.2Program Detailed ThreatThis section shall be similar to section 3.5.1 above referencing any known direct threats to acquisition specific elements of critical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classification at the unclassified level. Since detailed threat information may derive from classified sources, reference to source documents as provided by the government contracting activity or other reputable source is permitted.
3.5.3Threat AnalysisEach threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of threat to the corresponding critical information. The results of this analysis shall be presented in this section. A description of the specific threat analysis method used by the contractor to quantify each threat shall be included in this section.
Note: For additional guidance and a sample threat analysis methodology see DoDM 5205.02, JP 3-55, and NTTP 3-13.3.
3.5.4Changes Within Threat EnvironmentThe Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.
3.6Critical Information and Indicators
3.6.1GeneralCritical information and indicators shall be identified within this section of the plan and a comprehensive program CIIL shall be included.
3.6.2Critical Information and Indicators ListGuidance on the creation of a CIIL is contained within DoDM 5205.02, JP 3-55, and NTTP 3-13.3, or may be provided by the contracting activity. Ideally the CIIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.
3.7.1GeneralThe Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.
3.7.2List of OPSEC VulnerabilitiesEach vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable. Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.
Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within DoDM 5205.02, JP 3-55, and NTTP 3-13.3, or may be provided by the contracting activity. These sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailored to the specific acquisition or contract.
3.7.3Vulnerability AnalysisOnce potential program vulnerabilities have been identified, the magnitude of each vulnerability shall be determined using a consistent methodology identified and documented in this section of the OPSEC Plan. The results of this analysis shall also be described in this section.
Note: For additional guidance and a sample vulnerability methodology see DoDM 5205.02, JP 3-55, and NTTP 3-13.3.
3.8.1GeneralThe OPSEC risk of a program represents the probability of compromise of critical information and the impact to the program/contract taking into account the threat and vulnerabilities. The acceptable level of OPSEC risk (as determined by senior leadership, or the contracting activity) shall be described in this section in terms consistent with the selected OPSEC methodology.
3.8.2Risk AssessmentThe specific OPSEC risk shall be described in terms consistent with the OPSEC methodology selected for determining OPSEC threat and vulnerability. The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).
Note: Additional guidance and a sample risk methodology are available in DoDM 5205.02, JP 3-55, and NTTP 3-13.3.
3.9OPSEC Measures/Countermeasures
3.9.1GeneralThis section of the OPSEC Plan shall identify specific OPSEC Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in DoDM 5205.02, JP 3-55, and NTTP 3-13.3. This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential OPSEC measures.
3.9.2Residual RiskThis section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.
3.10OPSEC Program ChronologyThis section shall document significant program OPSEC events throughout the lifecycle of the program. Significant events may include changes to the CIIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition. A known compromise of critical information need only be referenced in keeping with the intended classification of this document.
Note: The history contained herein may be used by the government as a part of an OPSEC or security audit conducted by the contracting activity, DCSA or another authorized agency.
3.11AcronymsThis section shall include a complete list of acronyms used in the Program OPSEC Plan (i.e., CDRL - Contract Data Requirements List, DID - Data Item Description, etc.).
3.12ReferencesThis section shall include a complete list of all references cited in the Program OPSEC Plan (i.e. DoD Manual 5205.02, Contract Number, Corporate OPSEC Plan(s)/Program(s), etc.).
Schema v3.0Community-maintained · Verify against ASSIST