Policy / ODNI

Intelligence-community rules for sensitive commercial data

A signed policy sets assessment, approval, safeguarding and reporting requirements for sensitive commercially available information. A February 2025 amendment updates that policy.

Sources reviewed Sep 9, 2026. 1 primary source linked.

Policy and amendment documented

Last documented position: Feb 6, 2025

The examined policy creates reporting obligations. This collection has not verified report delivery, implementation by every agency, or whether a later policy supersedes it.

Source 1

What the record establishes

  • The document expressly replaces the earlier May 2024 framework. The underlying policy and technical amendment have different signature dates.
    Source 1
  • Annual internal/congressional and biennial public reporting requirements are stated in the text. A reporting requirement does not prove that a report was delivered.
    Source 1

The documented timeline

  1. Document dated

    Policy signed

    ICPM 504 (01) replaces the May 2024 framework and establishes requirements for assessing, approving, safeguarding and documenting sensitive commercially available information.

    Policy document

    Source 1
  2. Document dated

    Technical amendment signed

    The reviewed document includes the signed February technical amendment. Its reporting provisions distinguish annual internal and congressional reporting from public reporting every two years.

    Policy document

    Source 1

What remains unverified

  • Actual report delivery, the first specific public-report deadline and agency-level implementation have not been verified.
  • This governance document identifies no particular procurement, vendor or spending amount.
  • The reviewed amendment is not proof that no later policy exists.

An unavailable or unnamed detail is left open. It is not treated as zero, a negative finding or evidence of unlawful conduct.

Related records