Policy / ODNI
Intelligence-community rules for sensitive commercial data
A signed policy sets assessment, approval, safeguarding and reporting requirements for sensitive commercially available information. A February 2025 amendment updates that policy.
Sources reviewed Sep 9, 2026. 1 primary source linked.
Policy and amendment documented
Last documented position: Feb 6, 2025
The examined policy creates reporting obligations. This collection has not verified report delivery, implementation by every agency, or whether a later policy supersedes it.
Source 1What the record establishes
- The document expressly replaces the earlier May 2024 framework. The underlying policy and technical amendment have different signature dates.
Source 1 - Annual internal/congressional and biennial public reporting requirements are stated in the text. A reporting requirement does not prove that a report was delivered.
Source 1
The documented timeline
Document dated
Policy signed
ICPM 504 (01) replaces the May 2024 framework and establishes requirements for assessing, approving, safeguarding and documenting sensitive commercially available information.
Policy document
Source 1Document dated
Technical amendment signed
The reviewed document includes the signed February technical amendment. Its reporting provisions distinguish annual internal and congressional reporting from public reporting every two years.
Policy document
Source 1
What remains unverified
- Actual report delivery, the first specific public-report deadline and agency-level implementation have not been verified.
- This governance document identifies no particular procurement, vendor or spending amount.
- The reviewed amendment is not proof that no later policy exists.
An unavailable or unnamed detail is left open. It is not treated as zero, a negative finding or evidence of unlawful conduct.