
Security infraction vs. violation: reporting and clearance consequences
How DoD distinguishes security infractions and violations, how contractor reporting works, and why the incident label alone does not determine clearance outcomes.
A security infraction and a security violation are different incident categories. The distinction turns on the facts and the potential for loss or compromise of classified information. Neither label, by itself, tells you whether someone will lose clearance eligibility.
If you discover a suspected incident, report it promptly through your organization's security procedures. Do not wait until a job search or try to decide the reporting threshold on your own.
Where the definitions come from
DoD Manual 5200.01, Volume 3, Enclosure 6 and the glossary, distinguishes infractions, violations, losses, and compromises:
| Term | Practical meaning |
|---|---|
| Infraction | Failure to follow a security requirement that does not cause, and cannot reasonably be expected to cause, loss or suspected or actual compromise |
| Violation | A security failure that results in, or could reasonably be expected to result in, loss or compromise |
| Compromise | Unauthorized disclosure of classified information |
| Loss | Classified information or material cannot be located or accounted for |
A violation does not require proof that an unauthorized person actually read the information. An infraction is still a failure to follow requirements and needs appropriate inquiry and corrective action.
The manual governs DoD information-security procedures. For cleared contractors, the NISPOM Rule, including 32 CFR 117.8, establishes reporting and inquiry requirements. Agency and program procedures determine how the applicable requirements are implemented.

Why context changes the classification
Consider classified material found unattended. Whether it remained inside approved storage or a controlled area, who could access it, the applicable safeguarding rules, and how long it was exposed all matter. “Left on a desk” is not enough information to decide whether an incident occurred or how to classify it.
Likewise, sharing classified information with someone who holds the same clearance level can still be an unauthorized disclosure. Eligibility alone does not establish need-to-know or the specific access authorization. Our clearance guide explains those separate requirements.
A preliminary inquiry establishes the facts. The individual reporting the event should provide an accurate account through the approved channel, rather than deciding that it was harmless or assigning the final label.
What gets reported and investigated
Under section 117.8(d), contractors must inquire into a loss, compromise, or suspected compromise and report through their Cognizant Security Agency's process when the reporting criteria are met. Initial reporting and final inquiry findings serve different purposes; the contractor should not wait for a completed investigation before making a required initial report.
Section 117.8(e) also addresses individual culpability. Reports can be required when conduct shows deliberate disregard, gross negligence, or a pattern of negligence or carelessness. That is why repeated procedural failures can matter even when an individual event did not result in a confirmed compromise.
Three records or processes may be relevant:
- Facility records document the incident, inquiry, counseling, and corrective action as required.
- Industrial-security reporting informs the Cognizant Security Agency of a reportable loss, compromise, or related issue.
- Personnel-security reporting addresses adverse information relevant to an individual's eligibility. For DoD cases, authorized security personnel may use DISS as directed.
These are related, but a DISS incident report is not the universal reporting route for every industrial-security incident. The security office follows the relevant agency and program instructions.
How an adjudicator evaluates the conduct
SEAD 4, Guideline K covers handling protected information. It addresses deliberate or negligent disclosure, failure to follow protection rules, mishandling information on unauthorized equipment, and persistent lax security habits.
Mitigation can include infrequent conduct or unusual circumstances that make recurrence unlikely, a favorable response to counseling or remedial training, and inadequate training followed by corrective action. The adjudicator considers those facts with the whole-person factors and any other relevant guidelines. Concealment can create a separate personal-conduct concern.
A single incident is not automatically mitigated. A pattern is not an automatic denial. Seriousness, intent, recency, surrounding circumstances, and the response all matter. An incident report is information for review; it is not itself a clearance revocation or a guaranteed Statement of Reasons.
Records and a move to another employer
Do not assume that an internal record disappears from consideration because you change employers. Equally, do not assume that every recruiter or future employer can see your entire government security record.
DISS is an authorized personnel-security system with controlled access. What an authorized user can see depends on their permissions and responsibilities. Security officials may review relevant prior information during eligibility or access processing, and record handling depends on the applicable system and policy.
Answer the questions on your current questionnaire and in any interview accurately, using their actual wording and reporting periods. An incident may be relevant to more than one question, depending on what happened. Ask the security office how to provide supporting records through an approved channel; keep classified incident details out of ordinary recruiting messages.

A practical response to an incident
- Follow the immediate safeguarding instructions for your environment and notify the security office promptly.
- Provide an accurate account through the approved process. Do not send classified material to personal email, a recruiter, or a job platform to explain the event.
- Cooperate with the inquiry and complete required corrective action or training.
- Ask how any personnel-security reporting or follow-up will be handled and whether further action is required from you.
For a past, resolved event, the security office can explain how to address it during new processing. For a current reportable event, the obligation does not wait until an offer arrives.
What this means for ClearMatch
ClearMatch helps match your reported qualifications to jobs. It does not access DISS or adjudicate security incidents, and a job match is not a finding that your access is approved.
Keep the recruiting profile focused on unclassified qualifications. Use your organization's security process for incident reporting and the gaining security office for eligibility and access verification.