"We identified five unique NSA-developed NDAs," the inspector general wrote, "One of the five NDAs, NSA’s Security Agreement, did not include the current required whistleblower provisions but did include language related to whistleblower protections and had some statutory references." That finding—buried in an inspector general report released this week—summarizes an agency-wide pattern: many National Security Agency nondisclosure agreements do not inform employees of their statutory whistleblower rights.
Findings of the NSA inspector general
The inspector general concluded that most of the NSA's nondisclosure agreements lack the statutorily required reference to federal whistleblower protections, and that as a result agency employees "may not be aware" of their rights to disclose violations of law or instances of waste, fraud and abuse. The IG identified five distinct NSA-developed NDAs. One, the agency's Security Agreement, included some language related to whistleblower protections but not the current required provisions; the remaining four made no mention of whistleblower protections at all.
In addition, the IG found another set of five agreements that were not titled or identified as nondisclosure agreements but that nonetheless implied nondisclosure obligations—and those agreements, too, did not include the required whistleblower protection provisions.
Compartmented information access agreements and templates
The report found that the problems extend beyond formal NDAs to the access process for compartmented information. According to the IG, individual offices develop their own access agreement "brief sheets" using a template, and an affiliate’s acknowledgement of one of these electronic brief sheets serves as the nondisclosure agreement for that access.
The IG quoted subject matter experts who opened brief sheets of their own and "noted that the required provisions were not present." The report states that the IG reviewed the template and "noted that it lacked inclusion of the required whistleblower protection provisions," indicating the omission is built into the paperwork many employees encounter when seeking access to sensitive compartments.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadThe Trump administration's proposed standard NDA and Sen. Chuck Grassley
The inspector general’s findings arrive against the backdrop of a broader executive-branch initiative: the Trump administration is considering promulgating a standardized nondisclosure agreement for use across the federal government. That proposal has drawn bipartisan criticism for the potential "chilling effect" it could have on employees who witness misconduct while on the job. The report notes that one of the critics was Sen. Chuck Grassley, R‑Iowa, who requested the IG’s review into NSA NDAs.
What this means for NSA employees, the Office of Special Counsel, and Congress
- NSA employees: According to the IG report, employees who sign the agency’s NDAs or acknowledge access brief sheets might not receive the statutorily required notice of their whistleblower protections—raising the possibility that employees will not know they may disclose violations of law or waste, fraud and abuse.
- Office of Special Counsel (OSC): The report underscores a statutory carve-out: while Congress has used appropriations laws since 1988 to require the NSA to follow most provisions of the Whistleblower Protection Enhancement Act, the exceptions are those enforced by the OSC, which "lacks jurisdiction to review matters involving counterintelligence and foreign intelligence."
- Congress and oversight: The report is a direct response to congressional concern—Sen. Chuck Grassley requested the IG review—and it documents areas where agency practice does not fully mirror the statutory language Congress has sought to extend to the NSA through appropriations riders.
Agency response and the recommended corrective step
The inspector general recommended that the NSA create a process to ensure all nondisclosure policies, forms and agreements include the statutorily mandated whistleblower protection language, and that the agency assign responsibility for that process to an official. The NSA "concurred with the IG’s recommendations" and said it planned to assign compliance to the agency’s chief of staff. That administrative decision is the concrete, named next step documented in the report.
The IG’s findings map a narrow but consequential gap between statutory intent and the paperwork frontline employees sign. The report documents omissions across both named NDAs and the lesser-known access brief sheets used for compartmented information, identifies a congressional trigger for the review, and records the agency's agreement to act by assigning responsibility to its chief of staff. Whether that assignment translates into timely updates to the templates and every agreement the IG flagged is the immediate compliance task the report leaves on the NSA's desk.



