NSA watchdog finds gaps in whistleblower language in agency NDAs
An evaluation issued by the National Security Agency’s inspector general found that four of five NSA-developed nondisclosure agreements reviewed omitted language preserving legally protected whistleblower disclosures.
The NSA agreed with all three recommendations and said it will create a compliance process, assign responsibility to senior officials and revise existing agency-developed documents. Those are planned corrective actions, not confirmation that every affected form has already been changed.
What the watchdog found
The NSA Office of the Inspector General issued the evaluation on August 18, 2026. Oversight.gov identifies it as an agency-wide inspection and evaluation of the NSA’s implementation of whistleblower protections in nondisclosure policies, forms and agreements.
The review found that NSA did not have an overarching nondisclosure-agreement policy, a defined development process, a central official or office responsible for the documents, or a single repository containing all NSA-developed agreements.
That lack of centralized control also limited the review. The OIG said NSA could not provide a complete list of all agency-developed nondisclosure agreements, so the watchdog could not assure that the documents examined represented the full universe of forms used by the agency.
Four of five reviewed agreements lacked the protections
The OIG identified five unique NSA-developed nondisclosure agreements. One Security Agreement did not contain the current required whistleblower provisions, although it included related language and some statutory references.
The other four agreements made no mention of whistleblower protections. The documents included agreements for test proctors, people performing system testing and certifying testing materials, and members of an NSA Advisory Board.
The watchdog also identified five additional agreements that were not titled or identified as nondisclosure agreements but still implied nondisclosure obligations without including the required protections.
Electronic brief sheets used for access to compartmented information presented another gap. Individual offices developed the sheets from a template, and an affiliate’s electronic acknowledgment served as the nondisclosure agreement. The OIG found that the template and the brief sheets it reviewed lacked the required whistleblower language.
The OIG noted that the ODNI Form FM4414, used when a hard-copy agreement is required, does contain the statutory language. The evaluation focused on NSA policy and NSA-developed agreements governing employees; documents developed exclusively for nonemployee affiliates were outside the review’s scope.
What federal law requires
Section 743 of Division E of the Consolidated Appropriations Act, 2026, Public Law 119-75, bars the use of appropriated funds to implement or enforce covered nondisclosure policies, forms or agreements that do not contain language preserving legally protected disclosures.
The required provisions address employees’ rights and obligations involving classified information, communications to Congress, reports to inspectors general and other protected whistleblower disclosures involving violations of law, mismanagement, gross waste, abuse of authority or substantial and specific dangers to public health or safety.
The law does not eliminate employees’ duties to protect classified information or authorize the public release of classified material. The OIG also noted that omitting a reference to the Office of Special Counsel alone does not make an agreement noncompliant because the office lacks jurisdiction over counterintelligence and foreign-intelligence disclosures.
NSA response and next steps
NSA management agreed with the OIG’s three recommendations. The agency said it would develop and document a process to keep required whistleblower language current, identify the officials responsible for compliance, and find and revise existing NSA-developed nondisclosure policies, forms and agreements.
Under the response, the NSA chief of staff will lead the accountability effort and hold directorate-level chiefs of staff responsible for their areas. The Engagement and Policy Directorate’s Enterprise Guidance Services will help implement the process and revisions.
The evaluation followed an inquiry from Sen. Charles E. Grassley that prompted the OIG’s initial assessment. Fieldwork for the formal evaluation took place from August 2025 through February 2026.
The main follow-up question is whether NSA produces a complete inventory of its nondisclosure documents and confirms that revised agreements, implied-nondisclosure documents and compartmented-access brief sheets include the required protections. The report identifies a document-governance and notice problem, but it does not find that every NSA nondisclosure agreement was deficient or that personnel were intentionally prevented from reporting misconduct.
Sources
- NSA Office of Inspector General evaluation, Aug. 18, 2026
- Public Law 119-75, Section 743
- Federal News Network, Aug. 25, 2026
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.