Cleared and export controlled work · Western and Upstate New York

Security for cleared contractors and secure research

In most buildings the requirements follow the design. Here they come first, they shape the walls, and somebody other than your architect has the final word on whether you got it right.

  • SCIF and secure working environment design and construction management
  • Construction security and escorted access for uncleared trades
  • Restricted area access control with dual verification
  • NYS Dept. of State licensed

The requirements come before the drawings

Most security projects start with a building and add protection to it. Cleared work runs the other way. The requirements exist before there is a design. They determine where the space can sit, what the walls are made of, what is allowed to cross them, and who may stand in the room while it is being built. By the time anybody is discussing a device, the expensive decisions have already been made or already been missed.

This region carries an unusual concentration of that work for a metro its size. Defense manufacturing sits alongside a large optics, photonics, and imaging cluster, a great deal of it doing sponsored or export controlled research. Much of it happens in ordinary looking buildings that contain a few rooms which are not ordinary at all, and which need to be treated very differently from the floor around them.

What makes it different

Six things that do not apply anywhere else

An integrator who has never worked in this environment will produce something that looks competent and misses the point in ways that surface at the worst moment. These are the differences that matter.

Your accrediting official decides

In commercial work the code is the standard and the authority having jurisdiction interprets it. Here the requirements your accrediting official applies govern, interpretations differ, and settling that in writing early is worth more than any amount of design work built on assumptions.

The construction is part of what gets accredited

Who built it, who escorted them, what materials went in, and a record proving all of it. In ordinary construction the process is invisible once the work is finished. Here the process is examined, so it has to be run and documented as though it will be.

A boundary is continuous or it is nothing

Perimeter continuity above the ceiling line and below the floor, and every duct, conduit, pipe and cable that crosses it treated deliberately. One unmanaged penetration undoes a wall, and it is the kind of thing that gets discovered at inspection rather than at design.

The threat model includes people you trust

Intrusion detection assumes somebody outside trying to get in. Cleared environments also have to account for authorized access being used, wittingly or unwittingly, to cause harm. That is a different discipline with different controls, and hardware alone does not address it.

Documentation is a deliverable

What was installed, by whom, when, and witnessed by whom. Records assembled while the work happens are worth considerably more than records reconstructed for an assessment, and the difference is not recoverable afterward.

Uncleared people still have to do the work

Trades during construction, then cleaners, service technicians, and vendors forever afterward. Managing that access is a permanent operational problem rather than something that ends when the project does.

The obligations that come back

Cleared status is not a thing you achieve once

The NISPOM stopped being a manual in February 2021 and became a federal regulation at 32 CFR Part 117. That changed its character. A cleared facility now runs against a rule rather than against guidance, and several of the obligations recur annually rather than at accreditation.

Among them: a formal self-inspection at least annually, covering the security program and the insider threat program, and insider threat awareness training for every cleared employee each year, plus for newly cleared employees before access is granted. That training has required content, including how adversaries recruit trusted insiders, the behavioral indicators of insider threat, and the reporting requirements that go with them.

Your FSO and your ITPSO own all of that, and we are not proposing to be either. What we can do is the physical and training side: making sure the systems your security plan describes are the systems that are actually installed, that the records exist when a self-inspection asks for them, and delivering awareness training where you would rather not build it in house.

  • Physical systems that match what your security plan describes
  • Access and intrusion records available when an inspection asks
  • Insider threat awareness training delivered and documented
  • Restricted area controls that survive a walkthrough
  • Construction and modification history you can produce
  • A contact who already understands the environment

The underserved middle

Sensitive work without a facility clearance

A large share of the organizations in this region doing genuinely sensitive work hold no facility clearance and never will. Export controlled manufacturing, sponsored research, proprietary process technology, and commercial work with defense applications. They have real protection obligations and no framework handing them a checklist.

That middle ground is badly served. Cleared facility specialists price for a world these organizations are not in, and general integrators hear the requirement and quote a locked door. What is usually needed is a controlled area inside an ordinary building, an access record somebody can actually produce, and an arrangement that survives contact with an auditor or a prime contractor's assessment.

A controlled area, not a SCIF

A defined boundary, a controlled entry, and a documented reason for both, designed proportionate to what is inside rather than to the most stringent standard somebody once read about.

Access records that hold up

Being able to say who entered a space and when, months later, in a form somebody outside your organization will accept. This is the single most common gap we find in this group.

Visitor and non-employee access

Determining who may be granted access to export controlled technology is a legal question for your export control officer or counsel. Building a system that enforces and records whatever they decide is ours.

Protecting a process, not a document

In a lot of this region's work the asset is a method, a tolerance, or a piece of tooling on a shop floor. That is a different protection problem from a filing cabinet, and it is one that camera placement and area control can actually address.

Usually what is needed: A defined boundary Controlled entry Producible access records Detection and monitoring

How a project runs here

Five phases, and the first one is not design

On a commercial project you design and then confirm compliance. Here you establish the requirement first, because designing against an assumption is how projects get rebuilt.

  1. 01

    Establish the requirement in writing

    What applies, who says so, and how they interpret it. Interpretations vary between accrediting officials and between programs, and getting the answer documented before design is the cheapest hour on the project.

  2. 02

    Design against it

    Siting and adjacencies, perimeter construction, penetrations, acoustic separation, and entry and circulation, worked through with the design team while the drawings are still inexpensive to change.

  3. 03

    Build under a security plan

    Vetted personnel, escorted trades, material controls, and a running record kept as the work happens. Changes reviewed against the plan when they arise rather than discovered at the end.

  4. 04

    Verify and document

    Interim inspections walked, deficiencies closed before anybody schedules a final review, and the documentation package assembled with the evidence attached rather than promised.

  5. 05

    Sustain

    Monitoring, inspection, records that survive staff turnover, and support at the points in the year when your own obligations recur. Accreditation is a start date, not a finish line.

Across Western and Upstate New York

Organizations we work with

Defense manufacturers and suppliers

Primes and the subcontractor base beneath them, where a security requirement often arrives through a contract rather than from an internal decision, with a date attached.

Optics, photonics, and imaging

The cluster this region is known for, much of it doing export controlled or dual use work in buildings that were never designed with any of it in mind.

Universities with sponsored research

Restricted projects inside open academic buildings, where the security requirement applies to a few rooms on a corridor that is otherwise deliberately public.

Engineering and product development

Firms whose asset is a design, a method, or a tolerance rather than a stock of anything, which changes what is worth protecting and how.

Organizations preparing for a first requirement

Companies that have just won work carrying obligations they have not had before, and need somebody to explain the physical side without selling them a program they do not need yet.

Facilities with an existing accreditation

Where the space exists, the documentation has drifted, and somebody would like an honest account of the gap before an assessment produces one for them.

Why GSMG

People who have sat on the other side of the assessment

Government experience, not just familiarity

Our secure facility and counterintelligence work is led by federally trained security professionals and former counterintelligence agents. They have written these plans, run these programs, and been on the inspecting side of the table.

Licensed engineers in house

All of our engineers are New York State licensed Professional Engineers. Stamped drawings come from inside the same firm that installs the systems and answers to your authority having jurisdiction.

We do the construction side too

Design, construction management, escorted access, and the documentation package. The build and the systems inside it are not handed between two firms who each assume the other covered the seam.

Everything that crosses the boundary

Intrusion, access control, video, and life safety all designed by one team, because the systems that cross a secure perimeter are the ones that cause problems, and they are usually bought from different people.

Common questions

Before you call

Can you act as our FSO or ITPSO?

No, and that is a deliberate boundary rather than a capability gap. Both are appointed roles with their own training obligations, and the ITPSO in particular is a senior management appointment inside your organization. Some firms do provide outsourced support for those functions and that is a legitimate service, but it is not ours and it would be a different engagement from anything on this page.

We do export controlled work but hold no facility clearance. Is this page for us?

Very much so, and you are probably the least well served group in this region. You have genuine protection obligations without a framework handing you a checklist, and the two obvious places to look for help both misjudge you: cleared facility specialists price for a world you are not in, and general integrators hear the requirement and quote a lock. A controlled area, a producible access record, and a proportionate design is usually the honest answer.

Do you handle the accreditation itself?

Accreditation is granted by your accrediting official, not by a contractor, and anybody promising you an outcome there is overselling. What we do is the work that determines whether it goes smoothly: design against the requirement as your accrediting official interprets it, run the construction under a security plan, walk the interim inspections, close the deficiencies, and assemble the documentation package with its evidence attached.

What about CMMC and our information systems?

Not our lane, and we would be the wrong people. CMMC governs controlled unclassified information on contractor information systems and sits under a separate rule from the NISPOM. It is an information systems discipline. One contract can carry both sets of obligations, so your compliance and IT people will likely be working through it in parallel with anything physical we are doing, but they are genuinely different problems.

Can you work inside a space that is already accredited and operating?

Yes, and it is planned very differently from new construction. The perimeter cannot simply be opened, uncleared trades cannot simply walk in, and whatever gets touched has to be provable afterward. That means phasing, temporary boundaries and compensating controls, escort coverage matched to the trade schedule, and a documentation trail built to survive your next review.

Do you deliver insider threat awareness training?

Yes, and it is one of the places an outside party can legitimately help, because the required content is well defined and delivering it well is a skill rather than an institutional secret. Our people come from the government side of this work. The program itself, its senior official, and the reporting channels remain yours.

We think something may already have happened. What now?

Do not put details in a web form or an email to us. Call, tell us only that the matter is sensitive, and we will arrange an appropriate way to discuss it. Your own reporting obligations to your cognizant security agency are yours and they may be time sensitive, so raise it with your FSO in parallel rather than afterward.

Talk before you design, not after

The cheapest version of this work happens while the requirement is still being established and the drawings are still a conversation. If you are further along than that, we would still rather see it now than at an inspection.