ICS 705-1 §G.2.b limits SCIF access to authorized personnel, with access control methods approved by the AO. The approved methods are:
"automated access control systems using at least two technologies (badge, PIN, biometric, etc.)"
electromechanical or mechanical devices
personal recognition (in small facilities and/or where there is a single monitored entrance)
ICS 705-1 is explicit that these methods are not approved for securing SCIF entrances when the SCIF is unoccupied.
Layer
Job
Governs
Access control system (ACS)
Authenticates people at the door during occupied hours and logs entries
ICS 705-1 §G.2.b; Tech Spec Ch. 8
FF-L-2740 lock on FF-L-2890 hardware
Secures the primary door when the SCIF is unoccupied
Tech Spec 3.E.2
IDS (UL 2050 Extent 3)
Detects intrusion when unoccupied
Tech Spec Ch. 7
CCTV
Supplements entry control only; no cameras inside the perimeter under DoD criteria
Tech Spec 8.E, 11.D; UFC 3-4.17.2
Tech Spec Chapter 8 has six parts:
A. SCIF Access Control
B. ACS Administration
C. ACS Physical Protection
D. ACS Recordkeeping
E. Using CCTV to Supplement ACS
F. Non-Automated Access Control
If the ACS is integrated with the IDS, access control notifications must rank below IDS alarms (Tech Spec 7.A.2.i). DoDM 5105.21 Volume 2 limits IDS and access control device codes to SCI-indoctrinated personnel with a need to know.
An automated SCIF entry point must verify at least two things about the person, such as something they have (a badge) and something they know (a PIN) or something they are (a biometric). ICS 705-1 §G.2.b calls this "at least two technologies (badge, PIN, biometric, etc.)."
Requirement
Source
Automated ACS uses at least two technologies
ICS 705-1 §G.2.b
"At a minimum, provide card reader with keypad at the primary entrance and when provided, the secondary entrance."
UFC 4-010-05 3-4.17.1
The Common Access Card (CAC) is the default DoD ACS credential
UFC 4-010-05
Primary entrance: "An approved access control device (see Chapter 8). May be equipped with a by-pass keyway for use in the event of an access control system failure."
Tech Spec 3.E.2
The Fixed Facility Checklist asks "Is there a by-pass key?" and how it is protected
FFC v1.5 §C.1
Personal recognition is acceptable in small facilities and/or at a single monitored entrance
ICS 705-1 §G.2.b
Only one primary entrance, unless the AO approves otherwise
Tech Spec 3.E.2
How this maps to federal identity. A PIV or CAC card plus PIN is a two-factor "Limited" configuration under NIST SP 800-116 Rev. 1. Adding a biometric makes it an "Exclusion" configuration. Both satisfy the two-technology rule. A proximity card alone, or a keypad alone, does not.
"Is automated access control system located within a SCIF or an alarmed area controlled at the SECRET level?"
UFC 4-010-05
Equipment holding the access control software goes "within the perimeter or a SECRET controlled area"; transmission lines leaving that protection use FIPS AES certified encryption
Vendor paraphrase of the NCSC Tech Spec (DAQ Electronics)
"equipment containing access-control software programs be located within a SCIF or a SECRET controlled area"
Fixed Facility Checklist, §C.1
Also asks whether the ACS is integrated with the IDS and/or a LAN/WAN
Design consequences
A building-wide or cloud-hosted head-end in unsecured space does not meet this unless the AO approves the architecture.
Enterprise E-PACS installations often solve this with a local SCIF controller or partition, or an architecture the AO has approved. Get the AO's approval in writing.
If the ACS shares a networked host with the IDS, the host also has to meet the Tech Spec 7.A.3.c(2)(a) requirements for a "Physically Protected Space": a locked room, UL 437 cylinders, and a UL Extent 3 alarm plus access control unless the room is staffed 24 hours. See: Intrusion Detection & UL 2050 / Extent 3.
Where the ACS is integrated, disclose the integration and the LAN/WAN connections on the checklist.
"Are access control transmission lines protected by 128-bit encryption/FIPS 140?"
FFC v1.5 §C.1
Lines leaving protected space
FIPS AES certified encryption
UFC 4-010-05
Readers and panels outside the SCIF
"Does external access control outside SCIF have tamper protection?"
FFC v1.5 §C.1
ID data and PINs
"Is the access control system encoded and is ID data and PINs restricted to SCI-indoctrinated personnel?"
FFC v1.5 §C.1
Codes
Access codes to IDS and access control devices limited to SCI-indoctrinated personnel with a need to know
DoDM 5105.21 Vol. 2
PIN observation
DISA's Traditional Security Checklist item "AECS Keypad Device Protection" addresses someone observing an authorized user's PIN at a classified storage area entrance
V-245821
What this means in the field
Every run that leaves protected space counts. That includes reader-to-controller wiring. An unencrypted Wiegand run from a corridor reader back to a panel outside the perimeter does not meet the encryption question. Plan for encrypted or secure-channel readers and FIPS-validated controllers.
Tamper protection for outside devices: tamper-switched enclosures, secure mounting, and supervised wiring.
Enrollment, PIN resets, database backups and remote support are restricted to SCI-indoctrinated staff. That rules out routine remote support by uncleared vendor technicians.
FIPS 140-2 moves to the NIST historical list on 21 September 2026. For new controllers, ask for FIPS 140-3 validated modules and the CMVP certificate numbers.
FF-L-2890 deadbolt plus an FF-L-2740 combination lock (or FF-L-2740 integrated hardware the AO previously approved)
Approved access control device; by-pass keyway allowed for ACS failure
Secondary door (3.E.3), AO authorization required
FF-L-2890 egress device with deadbolt
Approved ACS hardware. "The access control system must be deactivated when the SCIF is not occupied."
Emergency egress-only (3.E.4), required by building code
FF-L-2890 emergency egress device, exit-only
No entry hardware. Alarmed 24/7 with a local audible annunciator.
All perimeter doors (3.E.5–3.E.6)
Automatic non-hold closer on the SCIF side; exterior hinge pins made non-removable; alarmed per Ch. 7; TEMPEST per CTTA guidance
—
UFC 4-010-05 3-4.6.8 and 3-4.6.10 prohibit adding separate standalone and flush-mounted deadbolts to secondary and emergency doors.
Why secondary-door ACS must go dark. An unoccupied SCIF has to be secured by the combination lock and the IDS, not by a card reader (ICS 705-1 §G.2.b). A secondary-door reader that still grants access after hours is an unapproved entry point into an unoccupied SCIF.
Doing it reliably
Tie deactivation to the closing procedure, such as the IDS arming sequence or a supervised "SCIF closed" door mode, rather than to a clock schedule alone. Schedules drift, and holidays break them.
Write the procedure into the SCIF SOP, and show the reader's disabled state during the acceptance walk-through.
Emergency egress doors are IDS points, not ACS doors. They get an HSS, motion coverage, and a local annunciator.
FF-L-2890C (22 Feb 2019; supersedes FF-L-2890B) defines pedestrian door lock extensions:
Types II, IV, VII and VIII provide "fail secure, electric release capability for use with existing automated building access control systems." The electric strikes in these assemblies are UL 1034 listed.
Types I and III are stand-alone units with an integrated mechanical or electronic keypad using at least a 4-digit code.
Once the combination-lock bolt is extended, it cannot be unlocked from outside without dialing the combination again.
The exterior key bypass is for ACS failure only. Removing the bypass cylinder must not expose the primary lock mechanism.
UFC 4-010-05 3-4.6.5: "Electric door strikes or electrified mortise locks installed with an access control system (ACS) must have a positive engagement, fail secure, and approved under UL 1034 for burglar resistance."
Component
Controlled by
When
Latch (electric strike or electrified trim)
ACS, after two-factor authentication
Occupied hours
Deadbolt
FF-L-2740 combination lock
Closing and unoccupied hours
Door position
IDS HSS, plus motion coverage
Always monitored; alarms when armed
The qualified products list QPL-FF-L-2890-5 (21 Mar 2022) names Kaba Mas CDX-10, the Lockmasters LKM10K series, and the Sargent & Greenleaf 2890 series. The 2890 hardware provides one-handed, single-motion egress. The DoD Lock Program tells buyers to check with the local fire marshal (AHJ) before buying. A hardware practitioner notes that Type V and VI configurations with escape mechanisms are intended for rooms that are not regularly occupied.
Where visitors are controlled. UFC 4-010-05 3-4.6.7 says: "Unless approved by the AO, provide one primary entrance where visitor control is conducted." Tech Spec Chapter 12.J covers Visitor Access.
Who may visit. DoDM 5105.21 Volume 2 requires the host facility to limit visitors to the areas and information they need for official business. The host verifies clearances through IC or DoD clearance databases (Scattered Castles for the IC).
Example agency practice (Department of State, 12 FAM 717). This is State Department practice only. Other agencies may differ.
Visitors are asked about portable electronic devices (PEDs) before entry.
They cannot enter until those devices are secured outside.
SCIF visitor logs are kept two years.
How the ACS and entry design support visitor control
Single primary entrance. Keep visitor processing, PED lockers and the sign-in point at the primary entrance, outside the perimeter. UFC 3-4.7 prohibits PED lockers recessed into the perimeter wall or placed within 10 ft of NSI processing.
Visitor credentials. Avoid issuing visitor credentials that open SCIF doors on their own. Treat the ACS as the log of cleared staff movements and the sign-in record as the visitor log.
Uncleared presence. UFC 3-4.15 approves a flashing or rotating light, with controls inside the perimeter at each entrance, to warn occupants that non-indoctrinated people are present.
Video intercoms at the door. The UFC allows an exterior camera at the primary entrance for remote door control. It must not look into the SCIF.
What the Tech Spec says. Tech Spec Chapter 8.D (ACS Recordkeeping) and Chapter 12.L (IDS and ACS Documentation Requirements) set documentation rules. The exact ACS retention period was not confirmed in public text for this article.
Related federal records schedules
Record
Retention
Source
Visitor logs, areas under the highest level of security
Destroy when 5 years old
NARA GRS 5.6, item 110
Visitor logs, other areas
Destroy when 2 years old
GRS 5.6, item 111
Key and electronic access card accountability, high security (FSL V)
3 years after return
GRS 5.6, item 020
Key and electronic access card accountability, other
6 months after return
GRS 5.6, item 021
PIV/CAC application records and credentials
Per schedule
GRS 5.6, items 120/121
SF 702 Security Container Check Sheet
Per the component's records schedule (CDSE). State Department: 90 days after the last entry unless an incident occurred.
Keep transaction history long enough to meet the longest retention period the AO sets. Document the setting.
Restrict report and export rights to SCI-indoctrinated administrators, because the history reveals ID data and patterns of movement.
Include ACS database and log backups in the retention plan. Store backups under the same protection as the head-end.
The DISA Traditional Security Checklist has an item titled "Sensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems." Card issuance and recovery records are inspected, not just door events.
PKI-AUTH + PIN + biometric (BIO/BIO-A or OCC-AUTH)
FIPS 201-3 authentication mechanisms: PKI-AUTH, PKI-CAK, BIO/BIO-A, OCC-AUTH (on-card comparison) and SM-AUTH (secure messaging).
Relevance to a SCIF door
The Tech Spec and ICS 705-1 text reviewed here does not require FIPS 201 by name. They require an AO-approved ACS with at least two technologies, encrypted lines and a protected head-end.
A Limited (card + PIN) or Exclusion (card + PIN + biometric) configuration fits the two-technology rule naturally.
DoD: UFC 4-010-05 makes the CAC the default SCIF/SAPF credential.
FIPS 201-3 defines several authentication mechanisms with different assurance. Specify the mechanism (for example PKI-AUTH + PIN), not just "PIV-compatible reader."
The Approved Products List (APL). GSA's FIPS 201 Evaluation Program (idmanagement.gov) runs the FIPS 201 APL. Under OMB M-05-24, agencies must buy products on the approved products list.
APL category
Notes
PACS Infrastructure
Head-end and controllers, approved as part of a tested solution
Validation Systems
Certificate validation for PIV, PIV-I, CAC
PIV PACS Readers
Approved only as part of a complete tested solution
PIV card stock
Legacy card stock purchasing restricted through 30 Jun 2027; all legacy card stock use ends 30 Jun 2032
Topologies. Readers are approved inside specific topologies:
13.01: three separate components
13.02: infrastructure and validation combined, plus the reader
cloud variants
Changing one component can take the system outside its approved topology.
GSA PACS Customer Ordering Guide (Dec 2025)
MAS SIN 334290PACS covers FIPS 201 APL PACS.
SIN 541330SEC covers security system integration.
SIN 334290L covers legacy non-FIPS PACS, for non-Executive-Branch agencies only.
At least one contractor employee on design, installation, configuration, acceptance testing and maintenance must be a Certified System Engineer ICAM PACS (CSEIP).
SCM Microsystems merged with Hirsch Electronics; the combined company became Identive Group, shortened to Identiv in 2014
27 Apr 2017
End of sale for DIGI*TRAC controllers M2N, M2N2, M8N, M8N2, MSPN-8R and MSPN2-8R. Mx controllers are the direct replacements.
3 Apr 2024
Identiv agrees to sell its physical security, access card and identity reader business to Vitaprotech (France)
15 Aug 2024
CFIUS finds "no unresolved national security concerns"
9 Sep 2024
Sale completed
2026
"Vitaprotech became Hirsch Group," operating under the Hirsch and Prysm brands; headquarters in Lyon, France; U.S. operation in Santa Ana, California
Website and documentation. The website is hirschsecure.com, and vitaprotech.com redirects there. Technical documentation moved to hirschdocs.atlassian.net.
Safe wording: "Hirsch (Hirsch Group, formerly Vitaprotech; previously part of Identiv)."
Avoid: "American-owned" (the parent company is French), and "Identiv Hirsch" as a current name.
Velocity Security Management System. Hirsch's 2026 software and federal datasheets describe Velocity 3.9 as "the latest iteration." According to Hirsch, it:
manages access control and security operations "from single high secure rooms to multi-building, multi-location campuses"
includes an Alarm Viewer (forced entry, door open too long)
includes a Who's Inside view for emergency egress
includes enrollment, IDS integrations and video integrations
offers a web client optimized for Chrome-based browsers
The Velocity Certificate Checking Service (VCCS) validates PIV, PIV-I, CAC and TWIC credentials in Hirsch's FICAM solution. VEL-EXPRESS is a reduced edition that lacks some plugins.
All specifications below are as Hirsch's datasheets state them (2025–2026 revisions). They are manufacturer claims. They are not approvals by an AO or CSA.
Product
Datasheet claims relevant to SCIF work
Mx controllers (Mx-2, Mx-4, Mx-8)
2-, 4- and 8-door "fully supervised" models. "UL 294: Access Control Systems Units; UL 1076: Proprietary Burglar Alarm Systems." "FIPS 140-3 certified cryptography, including TLS v1.3." Enclosure door tamper switch and key lock. Up to 500,000 credentials in the SNIB3 database.
Integrated Mx controllers
Supports "two person rule, occupancy counting, individual user tagging, door interlocking, and anti-passback," plus "high-security supervised alarm inputs." UL 294 and UL 1076. Encrypted communication over XNET2/XNET3 on TCP/IP.
Mx-1
Single-door PoE+ edge controller. UL 294 and UL 1076. "FIPS AES 256 encryption." "TLS 1.2 Encryption (Requires Velocity 3.7 SP2 or later)." OSDP or Wiegand.
"High-security line supervision and alarm masking functionality." Circuit resistance measured "100 times per second." 2% supervision (DTLM3/MELM3); 4% (DTLM1/2, MELM1/2). UL 294 and UL 1076.
SBMS-L2HSS door contact
"Meets UL 634 Level 2 high security standards"
How these features map to SCIF needs
Two-person rule and door interlocking: support vault-style entry procedures and airlock (mantrap) vestibules. Interlocks are not addressed prescriptively in the model codes, so each interlocked vestibule needs AHJ approval and must never block egress.
Occupancy counting: supports "is anyone still inside" checks before closing. Hirsch literature does not name a "first-in/last-out" feature, so don't claim one.
Line supervision and masking: support supervised alarm points. When the ACS is integrated with the IDS, its events must still rank below IDS alarms (Tech Spec 7.A.2.i).
UL 1076 with FIPS 140-3 claims: relevant to Tech Spec 7.A.3.b(10), which requires FIPS 140-2 certified encryption for a UL 1076 listed PCU. Whether an Mx is accepted as the SCIF PCU is the AO's accreditation decision.
The PIN observation problem. A standard keypad lets a patient observer, or a camera, learn a PIN from finger position. Worn keys can also give it away. SCIF entrances depend on the PIN as the second factor, so protecting it from observation matters. The DISA Traditional Security Checklist addresses this for classified storage entrances in its "AECS Keypad Device Protection" item.
"Patented scrambling of the illuminated keypad digits." Digits reorder each time START is pressed. Viewing restrictors limit side viewing. Certifications listed: "FCC, UL 294, CE, IC, RCM, RoHS2, REACH, UKCA, GSA APL." Stated "approved by the General Services Administration (GSA) for use in FIPS201/FICAM environments." Credentials: PIV, PIV-I, CIV, CAC, TWIC, DESFire EVx, MIFARE, 125 kHz prox. RS-485/OSDP.
ScrambleFactor SF.1 / SF.3
4.3-inch touchscreen with scrambled PIN, contact and contactless card, and fingerprint. "FBI certified (FIPS 201, PIV, and Mobile ID FAP 10 compliant)." UL 294. "Requires Hirsch Velocity." Launched March 2024.
Where each fits
TS ScramblePad SC is a CAC contact reader with a scrambled PIN. It fits the UFC 3-4.17.1 call for a "card reader with keypad" and can support SP 800-116 Limited (two-factor) use when configured in an approved topology.
ScrambleFactor adds a biometric for Exclusion (three-factor) configurations, or where the AO wants biometric verification.
DMP integration. Hirsch's datasheet says Velocity 3.8 or later integrates with DMP XR150 and XR550 intrusion panels. The integration can:
arm and disarm areas
bypass and reset zones
trigger outputs
silence bells
show status on graphical maps
A Bosch IDS integration datasheet also exists, but the supported panel models were not confirmed.
Integration rules that still apply
IDS alarms rank above access control notifications (Tech Spec 7.A.2.i).
"There shall be no remote capability for changing the mode of operation by non-SCI cleared personnel" (7.B.1). Velocity operator roles must keep uncleared enterprise operators from arming, disarming or bypassing SCIF zones.
The PCU stays inside the SCIF, and mode changes start there (7.A.3.b(1)).
The UL 2050 certificate covers the installed IDS. Any integration change after certification requires renewing the certificate (ICS 705-1).
SCIF requirement
Relevant Hirsch capability (manufacturer claim; not an approval)
ACS lines "protected by 128-bit encryption/FIPS 140" (FFC §C.1)
Mx/SNIB3 FIPS 140-2/140-3 crypto; OSDP readers
Head-end "within a SCIF or an alarmed area controlled at the SECRET level"
Velocity server and Mx panels placed there (a design choice, not a product feature)
ID data and PINs restricted to SCI-indoctrinated personnel
Velocity operator roles and permissions (configuration and procedure)
Tamper protection on external devices
Enclosure tamper switch and key lock; supervised inputs
Card reader with keypad at the primary entrance (UFC 3-4.17.1)
TS ScramblePad SC; ScrambleFactor
Secondary-door ACS deactivated when unoccupied (3.E.3)
Velocity schedules and door modes (site procedure)
Hirsch Mx controllers are UL 294 and UL 1076 listed
"SCIF-certified," "ICD 705 certified" or "ICD 705 compliant" products
Mx controllers use FIPS 140-3 certified cryptography with TLS 1.3 (per Hirsch)
Specific CMVP certificate numbers not published by Hirsch or NIST
Mx supports two-person rule, occupancy counting, door interlocks and high-security line supervision with alarm masking
"First-in/last-out" as a named feature
TS ScramblePad readers scramble keypad digits on every use and include viewing restrictors
"STIG-compliant Velocity" or "meets all DISA Traditional Security STIG requirements"
Hirsch lists its FICAM PACS solution on the GSA FIPS 201 APL (per Hirsch; confirm the listing on the GSA APL)
"DoDIN APL," "Army CoN" or "ATO-ready"
Velocity integrates with DMP XR-series intrusion panels for arm/disarm and zone control
"UL 2050 listed Hirsch." UL 2050 certifies the alarm service company, not a product.
Hirsch (Hirsch Group, formerly Vitaprotech; previously part of Identiv)
"American-owned" or "Identiv Hirsch"
Say instead: "installed under a UL 2050 certificate by a certified alarm service company" and "UL 1076 listed alarm inputs; IDS design subject to AO/CSA approval."
Always add: "Final system design, IDS/ACS integration and door hardware are subject to approval by the Accrediting Official (AO) / Cognizant Security Authority (CSA) and the Certified TEMPEST Technical Authority (CTTA) where TEMPEST applies."
Claim partner or certification status only if the company actually holds it. Hirsch does not publish course names or certification levels on its partner page.
Integrators on SCIF projects often inherit an existing enterprise platform, or must price against one. The table below is a neutral orientation. It is not a ranking. We did not check federal listings (GSA APL, FICAM) for these platforms, so this article makes no comparison of compliance.
Platform
Vendor / owner
Neutral description
Hirsch Velocity
Hirsch Group (France; U.S. operation in California)
High-security PACS with FICAM solution, Mx controllers and scrambled-PIN readers (see Hirsch sections)
LenelS2 OnGuard
Honeywell
Enterprise access control described as "feature-rich, comprehensive," integrating with many building and security systems
Software House C•CURE 9000 / C•CURE IQ
Johnson Controls
Enterprise access control and event management. C•CURE IQ is offered as "part of your standard C•CURE 9000 license" (on-premises, hybrid, cloud).
AMAG Symmetry
Not confirmed
"Intelligent, scalable and integrative access control," with Symmetry CONNECT for identity management
Genetec Synergis
Genetec
Access control module of the Genetec Security Center unified platform
Gallagher Command Centre
Gallagher Group (New Zealand)
Integrated security management; lists a "High Security" category with PIV software
Questions to ask of any platform on a SCIF door
Can the head-end, or a local controller that runs independently, sit inside the SCIF or a SECRET-controlled alarmed area?
Which controller-to-host and reader-to-controller links use FIPS 140-validated modules, and what are the CMVP certificate numbers?
Does the reader perform PKI-based PIV/CAC authentication plus PIN, and is that exact configuration on the GSA APL if the agency requires it?
Can operator roles keep uncleared enterprise administrators from changing SCIF doors, enrollment or integrated IDS zones?
Are the controllers and readers UL 294 listed? If alarm inputs are used, are they UL 1076 listed?
Can secondary-door readers be deactivated by procedure when the SCIF closes?
Supplement only. Tech Spec Chapters 8.E ("Using CCTV to Supplement ACS") and 11.D ("Using CCTV to Monitor Entry Points") treat CCTV as a supplement to access control and entry monitoring. It does not replace the combination lock, the ACS or the IDS.
No cameras inside (DoD). UFC 4-010-05 3-4.17.2: "Cameras are not allowed within the perimeter or enable observation within the perimeter." An exterior camera at the primary entrance is permitted for remote control of the door, and a video intercom system may provide this.
Checklist. The Fixed Facility Checklist §B (Security-in-Depth) asks "Is there external CCTV coverage?" It asks for a description and for monitor and coverage locations on the map. There is no checklist item for CCTV inside the SCIF.
Not a substitute for IDS. IDS must meet UL 2050 Extent 3 (ICS 705-1).
Practitioner guidance
Do
Don't
Aim entrance cameras at faces and the door approach
Capture keypad PIN entry, the FF-L-2740 dial or display, badge data, or a view into the SCIF when the door opens
Treat the video system as an unclassified system evaluated by the CTTA and AO (ICS 705-1 §G.2.d)
Put IP cameras, video doorbells, intercoms with microphones, or cameras built into displays or VTC codecs inside the perimeter without specific AO approval
Keep the camera network off SCIF networks; route camera cabling outside the SCIF
Run camera cable through the SCIF to reach the other side of the building
Specify models without audio, or disable microphones, near SCIF walls
Leave microphones active at the perimeter (acoustic leakage risk)
Document exterior and corridor coverage on the checklist maps to support Security-in-Depth
Present CCTV as a reason to relax the lock, ACS or IDS
Compartmented Area (CA). Tech Spec 2.C defines a CA as "An area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled Access Programs." The AO approves it, with concurrence from the CA Program Manager.
Graded security areas. NIST SP 800-116 Rev. 1 describes Controlled, Limited and Exclusion areas, requiring one, two and three authentication factors.
One-way rule: design concepts, not quoted requirements
Principle
What it means for the ACS
Enter through, never around
An inner area can be reached only through its parent area's controlled entry. No inner door opens directly to uncontrolled space.
Access flows from higher to lower, never the reverse
Authorization for an inner (higher) area may include the outer path. Enrollment in an outer area grants nothing inside an inner area.
People who enroll, configure or report on an inner area are indoctrinated for it. The checklist restricts ID data and PINs to SCI-indoctrinated personnel.
Factors never decrease going inward
An inner door requires at least as many authentication factors as the door outside it
Tools that support the pattern: door interlocks, anti-passback, two-person rule and occupancy counting. Hirsch Mx controllers list all of these, and other enterprise platforms offer similar features.
Treating the electric strike as the SCIF lock. An unoccupied SCIF is secured by the FF-L-2740 lock throwing the FF-L-2890 deadbolt, with the IDS armed.
ICS 705-1 §G.2.b; Tech Spec 3.E.2–3
2
Fail-safe strikes or maglocks. DoD criteria require positive engagement, fail-secure, UL 1034 strikes or electrified mortise locks.
UFC 3-4.6.5; FF-L-2890C
3
Mixing non-2890 hardware onto the door. Extra standalone or flush-mounted deadbolts on secondary and emergency doors are prohibited.
UFC 3-4.6.8, 3-4.6.10
4
Secondary-door ACS left active after hours
Tech Spec 3.E.3
5
REX devices that can be triggered from outside, or that shunt IDS door contacts
Practitioner
6
Head-end, server or database outside the SCIF, or in the cloud, without AO approval
FFC §C.1; UFC
7
Unencrypted reader or panel wiring leaving the SCIF, including Wiegand runs
FFC §C.1; UFC
8
Uncleared vendor technicians with admin rights or remote support
FFC §C.1; DoDM 5105.21 Vol. 2
9
Readers or panels outside the SCIF without tamper protection
FFC §C.1
10
Cameras inside the perimeter, or exterior cameras that see in or capture PIN or dial entry
UFC 3-4.17.2
11
IP cameras, video intercoms or door stations with microphones near SCIF walls
Practitioner; Tech Spec Ch. 9
12
Wireless devices: wireless locks, Wi-Fi/BLE readers or credentials with active radios, wireless IDS sensors, LTE communicators. RF transmitters need CTTA evaluation and AO approval.
ICS 705-1 §G.2.a
13
Buying "GSA" hardware off the wrong list: FF-L-2937 (AA&E) locks or MIL-DTL-43607 key padlocks for classified use. Confirm with the DoD Lock Program.
DoD Lock Program
14
Assuming a GSA FIPS 201 APL listing makes a PACS "SCIF-approved"
IDManagement; practitioner
15
ACS or IDS panels outside the perimeter; standby power not sized
The DoD design criteria turn the idea into layout rules. UFC 4-010-05 §3-3.3.1 notes that "having multiple zones within a facility can enhance the security of the higher security zones." §3-3.3.2 directs designers to "Maximize the vertical and horizontal separation between the lowest and highest security areas," and states the key rule: "Entry into a lower security area cannot be through a higher security area. This would require escorts." §3-3.3.3 adds: "locate other areas that require access control adjacent to or surrounding the SCIF or SAPF." The Tech Spec applies the same logic at building scale: "When the SCIF is an entire building, access control shall occur at the building perimeter" (8.A.1, public copy).
A security clearance says a person may be given classified information. It does not say which information, or which rooms. Executive Order 13526 §4.1(a) sets three conditions before anyone gets access, and all three must be true:
Condition
E.O. 13526 §4.1(a) wording
ACS consequence (derived)
Eligibility
"a favorable determination of eligibility"
Necessary, never sufficient, for any door grant
Agreement
"signed… nondisclosure agreement"
No enrollment on a compartment's doors until the read-in is complete
Need-to-know
"a need to know"
Each inner boundary gets its own authorization list tied to mission need
The Tech Spec makes this concrete for Type III compartmented areas: everyone with "unfettered access… must be formally briefed into all compartments" in that CA (v1.5.1 §2.C.2). Two people with identical clearances can have completely different door grants.
What it means for ACS configuration (derived)
Build a level per boundary. Avoid a single "SCIF plus everything" level. Each inner door group gets its own level, schedule and authentication mode.
Grant explicitly. A higher-access person holds explicit grants for the lower doors they use. Nothing inherits silently.
Tie changes to read-in and read-out. When the security office debriefs someone from a compartment, the door grant comes off at the same time.
Never provision from an HR clearance field. A clearance level in a personnel system is eligibility only. It is not an access decision.
Restrict who administers. "ACS administrators shall be SCI-indoctrinated" (Tech Spec 8.B.1, public copy), and the Fixed Facility Checklist restricts ID data and PINs to SCI-indoctrinated personnel.
Secure space nests in layers, and each layer has a different governing document, credential rule and alarm rule. Mixing the rules from two layers is the most common source of compartmented-design errors.
Layer
Credential required
IDS status
Governing text
Building or floor
Enterprise badge
Building alarms and access control count toward Security-in-Depth
Tech Spec 2.B; UFC §3-3.3
Collateral open storage area (e.g., SECRET)
Controls approved by the CSA
IDS per 32 CFR 117.15(d)
32 CFR 117.15
SCIF
Automated ACS using "at least two technologies (badge, PIN, biometric, etc.)"; UFC card reader with keypad; FF-L-2740 lock secures it when unoccupied
SCIF IDS to UL 2050 Extent 3; PCU inside the SCIF
ICS 705-1 §G.2.b; Tech Spec Chs. 7–8
Compartmented area (CA)
"Visual recognition or mechanical/electronic access control devices"; no spin-dial combination locks
No independent alarm system; the SCIF IDS covers it
Tech Spec v1.5.1 §2.C.4
Adjacent SCIFs (same element or co-use)
Separate authorization list per SCIF
One PCU may be partitioned into independent units
Tech Spec 7.A.2.f; ICS 705-2
SAP inside a SCIF
Program-briefed access list
Compartmented area pattern
DoDM 5105.21 Vol. 2
Reading the table
Credentials escalate inward; alarms do not multiply inward. The SCIF is the alarm boundary. A CA inside it adds access control, not another IDS.
Outer credentials never open inner doors (derived). A collateral-area grant opens nothing in the SCIF.
Each layer has its own paperwork. Security-in-Depth goes in the Fixed Facility Checklist, CAs use the Compartmented Area Checklist, and shared SCIFs use a Co-Use Agreement. DoDM 5105.21 Vol. 2 says that if only part of a SCIF is used for a SAP, "it will be treated as a compartmented area… a CUA must be established."
Two prohibitions every CA design must honor. Tech Spec v1.5.1 §2.C.4:
"Spin-dial combination locks shall not be installed on CA doors."
"Independent alarm systems shall not be installed in a CA."
A compartmented area is an access-control boundary inside a SCIF, not a second alarm boundary. §2.C.1 defines it as "an area, room, or a set of rooms within a SCIF that provides controlled separation between control systems, compartments, sub-compartments, or Controlled Access Programs." The AO approves it "with the concurrence of the CA Program Manager or designee," and access is by visual recognition or mechanical or electronic access control devices.
Type
Purpose (v1.5.1 §2.C.2)
Integrator impact (derived)
I
Viewing and processing; no storage. "Compartmented data shall never be openly displayed on a monitor that faces a primary door or common work area."
Check sight lines at doors and vision lites
II
Discussion; "Must meet existing sound transmission class (STC) requirements per ICS 705-1." No storage.
Acoustic door assembly; reader and REX penetrations must keep the STC
III
Viewing, processing, printing, storage and control of accountable compartmented information, in "a GSA-approved container"
ACS roster must match the compartment roster exactly
UFC 4-010-05 §3-4.2 agrees on acoustics: "Type I is an area where discussion is not authorized so there is no sound rated construction required. Type II & III… require acoustic protection."
Design consequences (derived)
The CA door gets an electronic lock or strike with card plus PIN, or a mechanical pushbutton lock if the AO approves.
CA door events are ACS events: no IDS partition, no separate keypad, no separate control panel.
After hours, the SCIF's own IDS sensors cover the CA as the SCIF design requires.
The CA Checklist v1.5 asks about the access device make and model, "shoulder-surfing," acoustics, briefing of unescorted personnel and GSA containers. It asks no IDS questions.
Separate SCIFs next to each other may share IDS hardware, but they may not share control. The public Tech Spec copy allows contiguous SCIFs that support the same IC element, or that operate under a Co-Use Agreement, to use one premise control unit (PCU) programmed into "multiple logical units or partitions… that function as individual control units… operated independently of one another" (7.A.2.f).
Rule
Text
Tech Spec (public copy)
Partitioning
Partitions "function as individual control units"
7.A.2.f
PCU location
"PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes." UFC §3-4.17.3 agrees.
7.A.3.b(1)
Who arms
"Changing arm/disarm status of the system shall be limited to SCI-indoctrinated personnel"; no remote mode changes by non-SCI-cleared personnel
7.B.1
Shared monitoring
"If a monitoring station is responsible for more than one IDS, there shall be an audible and visible annunciation for each IDS."
7.A.2.g
Keypad placement
"Every effort shall be made to design and install the alarm-monitoring panel in a location that prevents observation by unauthorized persons."
7.A.3.b(5)
False alarms
"False alarms shall not exceed one alarm per 30-day period per IDS partition."
7.A.2.p
Design choices (derived)
Place the PCU in the SCIF whose staff administer it. Record the other SCIF's arm and disarm authority in the Co-Use Agreement and SOP.
Plan where each SCIF's staff arm their own partition, normally from inside their own SCIF.
Issue each partition's codes only to that SCIF's staff.
Partitions are for separate SCIFs, never for compartmented areas inside one SCIF.
SCIF inside a collateral open storage area. The PCU must be inside the SCIF, and only SCIF personnel change its modes. A collateral partition on the SCIF PCU would have non-SCI users operating SCI equipment. Separate panels are the simpler design.
Bid documents often blur three different things: what the rules require, what a product can do, and what good designers usually do. The table keeps them apart.
Pattern
What it does
Status
Basis
Two technologies at the SCIF entrance
Badge plus PIN or biometric
Requirement when an automated ACS is used (ICS 705-1 also permits mechanical devices or personal recognition); DoD UFC calls for a card reader with keypad
ICS 705-1 §G.2.b; UFC §3-4.17.1
Area access levels
Groups doors into zones with their own levels and schedules
Design practice supporting UFC zoning
UFC §3-3.3.1
Card plus PIN at a CA door
Adds a factor at the inner boundary
Design practice; §2.C.4 allows visual recognition or devices
Tech Spec v1.5.1 §2.C.4
Escort for visitors
Visitors under "constant escort"; badge opens no doors
Requirement (escort); badge setup is practice
SAP checklist A-30 (DoDM 5205.07 §9.5.a)
Bypass release inside
Release button inside the SCIF with "continuous visual observation of personnel entering"
Requirement (public copy)
Tech Spec 8.B.2
Two-person integrity
"at least two authorized persons" present
Program requirement where set; ACS supports it
NIST glossary; SAP checklist D-15, H-9; Hirsch Mx "two person rule" [vendor]
Anti-passback
Blocks re-entry without a logged exit (hard, soft or timed)
Hirsch Mx "occupancy counting" [vendor]; a named "first-in/last-out" feature was not verified
Door interlock
One vestibule door open at a time
Vendor feature; needs AHJ approval
Hirsch Mx "door interlocking" [vendor]; Allegion
Internal warning beacon
Signals that non-accessed people are present
Program decision by the PSM/PSO
SAP checklist F-13 (DoDM 5205.07 §9.5.c)
How to use the table
A requirement goes in the specification as a "shall."
A vendor feature goes in only when the AO, SSO or PSO asks for the behavior it provides.
Any added device inside the perimeter, such as an exit reader for anti-passback or a warning beacon, is new wiring at the boundary and needs AO review.
Many SCIFs sit inside organizations that already run an enterprise access control system. The question is whether SCIF doors can live on that system, and if so, how to keep enterprise operators out of them.
Rules that do not change (see "Where the ACS head-end must live")
ACS software is located in the SCIF or a SECRET controlled area (Tech Spec Ch. 8.C, public copy; UFC §3-4.17.1).
"ACS administrators shall be SCI-indoctrinated" (Tech Spec 8.B.1, public copy).
ID data and PINs are restricted to SCI-indoctrinated personnel (Fixed Facility Checklist §C.1).
Operator partitioning (concept). In a shared head-end, software partitions keep enterprise operators from seeing or editing SCIF and CA doors, access levels, PINs and audit logs. Genetec's documentation gives a generic definition: a partition "defines a set of entities that are only visible to a specific group of users." Other platforms use different terms for similar controls.
Hirsch Velocity, as verified. Hirsch documents Velocity operator roles and permissions, which support this separation as configuration and procedure, not as a certification. Velocity's datasheet lists an Alarm Viewer and a "Who's Inside" view, and Velocity 3.8 or later integrates with DMP XR150 and XR550 intrusion panels to arm and disarm areas.
Decision
Constraint
Who decides
Shared enterprise server or a local SCIF server
Partitions do not relax the rule on where SCIF software and data live
AO, in writing
Which operators see SCIF doors
SCI-indoctrinated administrators only
SSO
IDS arming from the head-end
No remote mode changes by non-SCI-cleared personnel (Tech Spec 7.B.1)
Bell–LaPadula (Bell and LaPadula, 1973; unified exposition 1976). Two rules protect confidentiality:
Simple Security Property ("no read up"): "A subject at a given security level may not read an object at a higher security level."
Star Property ("no write down"): "A subject at a given security level may not write to any object at a lower security level."
The model covers confidentiality only. The Biba model addresses integrity.
Data diodes. A unidirectional network lets data travel in only one direction, and the guarantee is physical. It is "often used to move information from low-security domains to secret enclaves while assuring that information cannot escape."
Cross-domain solutions (CDS). CNSSI 4009 defines a CDS as "A form of controlled interface that provides the ability to manually and/or automatically access and transfer information between different security domains." Secondary sources report that U.S. CDS evaluation falls primarily under NSA's National Cross Domain Strategy and Management Office (NCDSMO), and that DoD sites implement solutions from a baseline list.
Direction
Information (Bell–LaPadula)
People
Things carried
High to low
Read down allowed
Allowed, with an explicit grant at each door
High-side material does not go into lower areas
Low to high
No read up
Denied, or escort only
PED policy controls what comes in
Into the high side
Low to high through a diode or CDS
Visitors under escort
Inspection and policy
Out of the high side
Blocked or reviewed
Egress always free
Removal controlled by procedure, such as SAP dual authorization for media
This conceptual example traces one generic facility from the street to a Type III compartmented area. It describes no real site. Every choice in it remains subject to the AO, CSA and CTTA.
Boundary
Who may pass
Credential mode
Device notes
Administered by
B1 Building or floor
All badged employees; visitors after check-in
Card
Enterprise access control; turnstile or lobby reader; counts toward Security-in-Depth
Corporate security
B2 Collateral open storage area (e.g., SECRET)
People eligible and approved for that area
Card plus PIN, per the CSA
IDS under 32 CFR 117.15; a separate area in the ACS
Facility security officer
B3 SCIF primary entrance (vestibule)
SCI-indoctrinated people on the SCIF access list; escorted visitors
At least two technologies; FF-L-2740 lock on FF-L-2890 hardware when unoccupied
Head-end in the SCIF or a SECRET controlled area; encrypted lines outside; tamper-protected readers; PCU and remote release inside
SCI-indoctrinated ACS administrator; SSO
B4 Type III CA
Only people briefed into all compartments in the CA
Card plus PIN; two-person if the program requires it
Electronic lock or strike; no spin-dial lock; no independent alarm; SCIF IDS covers the room
SSO, with CA Program Manager concurrence
Movement check
A B4 person walks B4 → B3 → B2 → B1 freely. Each door is an explicit grant, not inheritance.
A B3 person not briefed into B4 works in the SCIF but cannot open B4.
A B2-only person cannot open B3. Inside B3 they are escorted. Under the UFC layout rule, their daily route never crosses B3 or B4.
A visitor holds a badge that opens nothing and stays under escort in B3.
Alarm check
One IDS boundary at B3 (plus B2's separate collateral IDS). B4 adds no alarm system.