Module 03 · 16 sections

Accreditation Lifecycle

From sponsorship to re-evaluation: concept approval, risk assessment, CSP, CTTA review, FFC, testing, inspection, waivers, co-use and de-accreditation.

On this page
  1. 03.01Accreditation is a lifecycle: the step table
  2. 03.02Sponsorship, concept approval and early AO coordination
  3. 03.03Site survey, risk assessment and the Pre-Construction Checklist
  4. 03.04TEMPEST Checklist and CTTA review
  5. 03.05Design approval and the Construction Security Plan
  6. 03.06Construction surveillance and the evidence trail
  7. 03.07Systems installation, testing and certificates
  8. 03.08Final Fixed Facility Checklist and operating documents
  9. 03.09Final inspection, TSCM and interim accreditation
  10. 03.10Accreditation issuance: what the letter says
  11. 03.11Continuous monitoring and periodic re-evaluation
  12. 03.12Modifications and re-accreditation triggers
  13. 03.13Waiver requests: package contents and consequences
  14. 03.14De-accreditation, withdrawal and re-use
  15. 03.15Co-Use Agreements: process and paperwork
  16. 03.16What to have ready at inspection
03.01

Accreditation is a lifecycle: the step table

ICS 705-2: "Accreditation is the beginning of a life-cycle process of continuous monitoring and evaluation, periodic re-evaluations, and documentation reviews."

# Phase Artifact Produced by → approved by
1 Requirement and sponsorship Sponsorship evidence Government sponsor
2 Concept approval (DoD SCIF) Concept approval; SCIF number Command → Service CSA or SIO
3 Early AO coordination Planning team; SCIF identification number (DoD) AO
4 Risk assessment and SID Risk assessment; SID documentation AO and SSM
5 Pre-Construction Checklist Checklist with attachments Project team / SSM → AO
6 TEMPEST Checklist TEMPEST Countermeasures Review (TCR) SSM → CTTA → AO
7 Design review Approved design; preliminary FFC A-E and SSM → AO
8 Construction Security Plan Approved CSP, before contract award SSM → AO
9 Construction with surveillance Inspection reports; CST logs; photo record SSM, CSTs, CAGs
10 Systems installation and testing UL 2050 certificate; IDS acceptance tests; acoustic data Integrator → SSM → AO
11 Final FFC Complete FFC, TEMPEST addendum, attachments SSO/SSM → AO
12 SOPs and emergency plan SOP; emergency plan; catastrophic failure plan (DoD) SSO/CSSO → AO
13 TSCM, as required TSCM report U.S. Government TSCM team → AO
14 Accreditation inspection Inspection report AO or designee
15 Interim accreditation, where used Interim letter AO
16 Accreditation issued Letter of accreditation; repository entry AO → SSO, CSA, NCSC repository
17 Operations and continuous monitoring Logs; self-inspections; posture change reports SSO/SSR/CSSO
18 Periodic re-evaluation Re-evaluation report; FFC page changes CSA/AO → repository
19 Re-accreditation New letter AO
20 De-accreditation or withdrawal Withdrawal request; closeout inspection; repository notice SSO → AO → repository

Steps 3 through 8 normally precede construction contract award. The Tech Spec ties CSP approval directly to award (3.B.1) and requires AO approval of the final design before SCIF construction starts (3.A).

Sources ICS 705-2 · IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2

03.02

Sponsorship, concept approval and early AO coordination

Sponsorship. "Security begins when the initial requirement for a SCIF is known" (Tech Spec 2.A). A SCIF exists to meet a government mission need, so every project needs a government sponsor and an identified AO before design starts.

Concept approval (DoD SCIFs). UFC 4-010-05 2-2.1: "The commander must submit a request for SCI to the Service Cognizant Security Authority (CSA), their designee, or DoD Component senior intelligence official (SIO)." The request certifies the need and that no existing SCIF can support it. "Proof of sponsorship in the form of a SCIF number or written documentation of Concept Approval … is required to establish a SCIF." DoDM 5105.21 Vol. 2 gives Service CSAs, their designees or DoD Component SIOs the authority to "validate the need for a SCIF and … grant concept approval."

Facility Concept approval
DoD SCIF Required; Service CSA, designee or SIO
SAPF (under the cancelled DoDM 5205.07 Vol. 3) Not required; "Sponsorship for most SAPFs is formalized at the program level" (UFC 4-010-05 2-2.2)
Navy SAPF Required under memo DONSAPCO/0779-22, through the PSO and Government Program Manager

Early AO coordination. The Tech Spec requires coordination with the AO "before construction design, material ordering, or contracts are finalized." In DoD, DIA's accreditation office assigns a SCIF identification number during preconstruction (DoDM 5105.21 Vol. 2). UFC 4-010-05 2-4 calls for an interdisciplinary planning team; a practitioner model lists the CSA/AO, CTTA, SSO, the construction agent, the SSM and the end user.

Decisions to settle at this stage: storage mode (closed, open or continuous operation), whether a SWA or TSWA meets the need, whether Security-in-Depth is available, discussion and amplified-audio rooms, and whether classified processing will occur (which triggers the TEMPEST Checklist).

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025) · SAME 2026, Concept to Clearance (practitioner) · Holland & Knight, Leasing SCIF Space (industry)

03.03

Site survey, risk assessment and the Pre-Construction Checklist

"Site survey" is a practitioner term. The documented outputs the AO actually reviews are the risk assessment, the Security-in-Depth documentation, and the Pre-Construction Checklist.

Risk assessment (Tech Spec Ch. 2). The AO and SSM assess "threats, vulnerabilities, and assets to determine the most efficient countermeasures." The analytical risk management process covers threat, vulnerability, probability and consequence. SID factors are documented; overseas, the State Department technical threat rating sets the construction Category. "Exceeding a standard, even when based upon risk, requires that a waiver be processed and approved in accordance with ICD 705."

Pre-Construction Checklist (added in Tech Spec v1.5). It "provides the AO with project information, points of contact and information required to assist in the determination of the security requirements for the project and final accreditation" (UFC 4-010-05 1-19.4).

Checklist section What it captures
General Project identity, points of contact
Construction Scope and type of work
Personnel Site Security SSM, CSTs, CAGs, cleared escorts, and their costs
Physical Site Security Fence, secure storage area, access control facility, IDS and CCTV; the "security in-depth starting point location"
Additional Comments Anything else the AO needs
Attachments Compartmented Area checklist and TEMPEST checklist where applicable

Practitioner due diligence (not Tech Spec text): whether walls can run true floor to true deck; windows and floor level; adjacency to public areas and other tenants; building utilities that would transit the space (Tech Spec 3.G restricts this); a location for the primary-entrance vestibule; telecom room location; and landlord approval for penetrations and IDS monitoring pathways.

Sources IC Tech Spec v1.5.1 · SCIF Pre-Construction Checklist v1.5 · UFC 4-010-05 (2023) · SCIF Fixed Facility Checklist v1.5 · DoDM 5105.21 Vol. 2

03.04

TEMPEST Checklist and CTTA review

When. The FFC (Section I) says a facility that electronically processes classified information completes the TEMPEST Checklist. "For an initial TCR, the addendum will be submitted to AO during the planning phase" (UFC 4-010-05 1-19.3).

What the checklist asks (public form):

Section Content
A. General Location and controlled space, including distance from the SCIF perimeter to the closest limit of the inspectable space, and foreign-national-occupied areas nearby
B. SCIF Equipment/Systems Signal lines and power lines that exit the SCIF and whether filters or isolation devices exist; HVAC and pipes; radios; telecom; existing countermeasures; construction materials; windows
C. Information Processing Equipment that processes unencrypted national security information and the classification levels processed

What happens next. The CTTA reviews and gives "documented results of review with recommendations" to the CSA and AO. Recommended countermeasures are to be incorporated "into design when practicable" (Tech Spec 3.A). ICS 705-1 adds that RF shielding "should be planned for installation during initial construction as costs are significantly higher to retrofit."

Related AO approvals. RF transmitters may not enter a SCIF unless the CTTA or another competent authority evaluates them as low risk and the AO approves (ICS 705-1 §G.2.a). Unclassified systems are evaluated for TEMPEST and TSCM concerns (§G.2.d).

Sources SCIF TEMPEST Checklist v1.5 · SCIF TEMPEST Checklist v1.4 · SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05 (2023) · ICS 705-1 · IC Tech Spec v1.5.1

03.05

Design approval and the Construction Security Plan

Two AO approvals gate construction: the design and the CSP. The Tech Spec requires the AO to "review and approve the design concept, Construction Security Plan (CSP), and final design for each construction project prior to the start of SCIF construction" (3.A).

Design review. The AO reviews the design concept and final design. Designers "validate planning requirements" (UFC 4-010-05 3-1), and the preliminary FFC is completed for pre-construction review ("Complete Sections as Required by A/O"). DoD documents are "completed and submitted initially around the end of the design phase" (DoDM 5105.21 Vol. 2).

Construction Security Plan. "Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO" (Tech Spec 3.B.1). UFC 4-010-05 1-15: "Do not award a construction contract without an approved CSP." The CSP template's baseline "may not be reduced without coordination and approval."

CSP template field (v1.5) What to address
SSM; statement of project; existing SCIF ID; CSA/AO; location; start and finish dates Project identity
Risk Assessment Completion; Security in Depth Documentation Outputs of Tech Spec Ch. 2
Adjacencies Neighboring spaces and tenants
Control of plans and documents Marking, distribution, storage and disposal of drawings
Control of operations (renovations) Barriers separating workers from operational areas
Procurement, shipping and storage AO-imposed material controls
Construction workers Citizenship or U.S.-person status, vetting, badging, escorts, CSTs
Site security Identity checks, searches, prohibited-item signage, barriers, vehicle inspections
Security administration Inspection schedule, violation reporting to the AO within 3 business days

Sources IC Tech Spec v1.5.1 · Construction Security Plan v1.5 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2 · SAME 2026, Concept to Clearance (practitioner)

03.06

Construction surveillance and the evidence trail

During construction, the job is to build correctly and to prove it. Inspectors at accreditation cannot see inside finished walls, so the evidence trail is created now or never.

Control Requirement Source
Document protection "Construction plans and all related documents shall be handled and protected in accordance with the CSP" Tech Spec 3.B.2
Renovation barriers Segregate workers from operational areas and limit observation Tech Spec 3.B.3
SSM inspections "Periodic security inspections shall be conducted by the SSM or designee for the duration of the project" Tech Spec 3.B.4
Violations SSM documents violations or deviations from the CSP and notifies the AO within 3 business days Tech Spec 3.A
Workforce U.S. companies using U.S. citizens preferred; U.S. persons permitted with AO-ensured mitigations Tech Spec 3.B.5
Site access Identity verification, random entry and exit searches, prohibited-items signage, barriers, vehicle inspections Tech Spec 3.B.6
CSTs "When required by the AO" inside the U.S.; per threat Category overseas, but not required under Chief of Mission authority when contractors are U.S. citizens with TOP SECRET clearances Tech Spec 3.A; 4.C; Ch. 5
Materials The AO may impose procurement, shipping, selection and secure storage procedures UFC 4-010-05 4-3
Photo record Photographic surveillance record of perimeter penetrations, door installations and wall assemblies UFC 4-010-05 4-7

Overseas additions. Secure procurement, transport and storage of materials (Tech Spec 4.E–4.G), including secure storage areas with "true floor to true ceiling, slab-to-slab construction" and an AO-approved lock, plus the Inspectable Materials Checklist.

See: Construction Security & Build Sequence.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · IC Tech Spec v1.5 · CenCore, SCIF construction Q&A (practitioner)

03.07

Systems installation, testing and certificates

Security systems produce the most test data in the package. Every item below ends up referenced on the FFC.

IDS (Tech Spec Ch. 7):

Item Requirement Source
Standard Install per the Tech Spec, UL 2050 and the manufacturer's specifications; Extent 3 installation 7.A.2.a–b; 7.D.2
Installers U.S. companies using U.S. citizens inside the U.S. 7.D.1; UFC 4-010-05 1-18.1
Acceptance testing Before operational use and before accreditation; the AO approves system plans 7.A.2.o; 7.D.3
Motion sensor test Alarm on "at least three out of every four consecutive trials made by moving progressively through the SCIF" 7.D.3
High-security switch test Alarm before the non-hinged side of the door opens beyond the thickness of the door 7.D.3
Tamper test Each equipment cover tested in secure and access modes 7.D.3
Backup power "Twenty-four hours of uninterruptible backup power is required" 7.B.5
Recurring testing Semi-annual 7.D.3
Certificate Contractor SCIFs maintain a current UL certificate of installation and service; renew after IDS changes ICS 705-1

FFC Section E asks: "Has the IDS configuration been approved by the AO?" and "Has the IDS passed AO or UL 2050 installation and acceptance tests?", along with emergency power hours and response time in minutes.

DoD package items (DoDM 5105.21 Vol. 2): IDS specification sheets, UL 2050 certificate, NIST 128-bit encryption certificate for IDS, and IDS test results.

Acoustics (Tech Spec Ch. 9). Acoustic verification is performed as the AO requires, either audio (non-instrumental) tests, which "must be approved by the AO," or instrumented tests. See: Acoustics & Sound Masking.

Other systems. ACS per Chapter 8 and telecom per Chapter 11 are documented on the FFC. TEMPEST or RF testing is performed if the CTTA and AO require it.

Sources IC Tech Spec v1.5.1 · ICS 705-1 · SCIF Fixed Facility Checklist v1.5 · DoDM 5105.21 Vol. 2 · UFC 4-010-05 (2023) · DCSA SAP Compliance Checklist (Jan 2026)

03.08

Final Fixed Facility Checklist and operating documents

The FFC is "a standardized form that documents the physical, technical, and procedural security information to obtain accreditation" (UFC 4-010-05 1-19.2).

FFC v1.5 attribute Options or sections
Approval type Pre-construction; Final FFC Accreditation; Update/Page Change
Location type Domestic; Overseas Not COM; Overseas COM
Sections A General Information; B Security-in-Depth; C SCIF Security; D SCIF Doors; E IDS; F Telecommunication Systems and Equipment Baseline; G Acoustical Protection; H Classified Destruction Methods; I INFOSEC/TEMPEST/Technical Security

Timing (DoD). "The fully complete FFC and TEMPEST Addendum, along with attachments, should be submitted prior to the completion of the SCIF for final accreditation" (DoDM 5105.21 Vol. 2). Resolve every "TBD" entry before submission.

Operating documents. ICS 705-2 §D.2.a lists accreditation documents that "shall include, but not be limited to: 1) Fixed Facility checklists; 2) Standard operating procedures; 3) Emergency plans; 4) Construction Security Plan; and 5) Waiver request packages."

Document What it must cover Source
SOP Day-to-day security procedures, including combination control, visitor access, maintenance and PED rules Tech Spec 12.D, 12.H, 12.J, 12.K
Emergency plan Emergency actions; "IDS failure shall be addressed in the SCIF emergency plan" Tech Spec 12.M; 7.A.1.e
Failed-sensor procedure In the SOP or emergency action plan Tech Spec 7.A.3.a
Catastrophic failure plan Required in the DoD package; FFC Section E asks whether the AO approved it DoDM 5105.21 Vol. 2; FFC v1.5
External response agreement Written support agreement with the response force Tech Spec 7.C.1; FFC Section E

Sources SCIF Fixed Facility Checklist v1.5 · UFC 4-010-05 (2023) · ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · CDSE Security Short, Fixed Facility Checklist

03.09

Final inspection, TSCM and interim accreditation

Inspection. ICS 705-2 provides for "inspections conducted by [the AO] or designee prior to final accreditation." UFC 4-010-05 1-19.1: "Inspections and evaluations are typically performed by the SSM, or designee, prior to initial accreditation. The accreditation process includes, site inspections and a review of documents relating to design, construction, and testing." For SAP areas, CDSE SA501 states the accrediting official "will physically inspect any SAP area before accreditation."

TSCM.

Situation Rule Source
New SCIFs or significant renovations TSCM "may be required" ICS 705-2
Overseas Category I Required "for new SCIF construction or for significant renovations (50% or more of SCIF replacement cost)" Tech Spec 4.H
Overseas Categories II and III At AO discretion Tech Spec 4.H
Who performs "Will only be conducted by USG TSCM teams" (as quoted from 12.G.8 by a practitioner summary) Tech Spec 12.G.8

Interim accreditation. The Tech Spec expressly provides interim accreditation for overseas SCIFs (Ch. 4.I and 5.K): "Upon completion of a successful inspection, the respective agency's AO may issue an Interim Accreditation pending receipt of required documentation," or "If documentation is complete, AOs may issue an Interim Accreditation pending the final inspection." A practitioner model also uses an interim phase for testing, IT fit-out, furniture and the final FFC.

The rule that does not bend (DoD): "SCI will not be discussed or introduced into the proposed SCIF until the facility is accredited" (DoDM 5105.21 Vol. 2).

See: Roles & Responsibilities for TSCM team rules.

Sources ICS 705-2 · UFC 4-010-05 (2023) · CDSE SA501 Student Guide · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · Armag summary of Tech Spec v1.5 updates (practitioner) · SAME 2026, Concept to Clearance (practitioner)

03.10

Accreditation issuance: what the letter says

The letter of accreditation (ICS 705-2 §D.1.a) includes:

Element Why it matters
SCIF identity Ties the accreditation to a specific, bounded space. Expanding or reducing the perimeter changes it
Type (for example open or closed storage) Sets what may be stored and drives alarm response requirements
Effective date Starts the re-evaluation clock
Statement of compliance with physical, TEMPEST and technical standards The formal finding the whole package supports
Approved waivers, "to include details of the standard(s) not met and when they are scheduled to be met, or standard(s) exceeded" Signals loss of mandatory reciprocal use and any compliance deadline

Who issues it. The AO; in DoD, "DAC will review the accreditation package … and will issue a formal written accreditation for the SCIF" (DoDM 5105.21 Vol. 2). SAPFs are accredited by the SAPF-AO under DoDM 5205.07.

Where it is recorded. Accreditation data goes to the IC SCIF Repository managed by NCSC (ICD 705; ICS 705-2). CSAs are responsible for timely data input (ICS 705-1).

What the letter enables.

  • SCI operations within the accredited type and perimeter.
  • Reciprocal acceptance by other IC elements, if there are no waivers.
  • Co-use by tenants through a signed Co-Use Agreement.

What it does not do.

  • It does not authorize SAP operations. A Co-Use Agreement is required before SAP is introduced (DoDM 5105.21 Vol. 2).
  • It does not authorize a different storage mode, a larger perimeter, or conversion from continuous operation. Each requires re-accreditation in DoD.
  • It does not freeze the facility. Accreditation is continuously monitored and periodically re-evaluated.

Sources ICS 705-2 · ICS 705-1 · ICD 705 · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025)

03.11

Continuous monitoring and periodic re-evaluation

Continuous monitoring is the day-to-day proof that the accredited conditions still exist.

Activity Requirement Source
End-of-day checks SF 701 for the SCIF; SF 702 for the SCIF door, vaults and containers DoDM 5105.21 Vol. 2
After-hours inspections Random, "at least monthly," by the SSO, SSR or SCI-indoctrinated designees DoDM 5105.21 Vol. 2
Emergency action plan Exercised annually DoDM 5105.21 Vol. 2
Posture changes Reported to DIA's accreditation office "within 24 hours" DoDM 5105.21 Vol. 2
IDS testing Semi-annual; records kept two years Tech Spec 7.D.3; 12.L.6
IDS failures to arm or disarm Reported; records kept two years Tech Spec 7.B.3
Visitor and maintenance control Per SOP Tech Spec 12.J, 12.K
Self-inspections By the SSR CDSE SCI101

Periodic re-evaluation (ICS 705-2 §D.3.a). The CSA "shall ensure that regular, periodic re-evaluations are conducted … based on the sensitivity of programs, threat, facility modifications, and past security performance, or at least every five years." Results are reported to NCSC via the SCIF Repository within 30 days. TSCM may be part of inspections and reviews (Tech Spec 12.G.8). System changes are documented through FFC "Update/Page Change" submissions.

SAPFs. The cancelled DoDM 5205.07 Vol. 3 required periodic re-inspections "no less frequently than every 3 years," and CDSE SA501 (November 2024) repeats "at least every 3 years for SAPFs."

Sources ICS 705-2 · DoDM 5105.21 Vol. 2 · IC Tech Spec v1.5.1 · CDSE SCI101 Student Guide · CDSE SA501 Student Guide · DoDM 5205.07 Vol. 3 (cancelled; mirror) · DCSA SAP Compliance Checklist (Jan 2026)

03.12

Modifications and re-accreditation triggers

IC rule (ICS 705-2 §D.4.b). Re-accreditation is required "when there are major modifications to the SCIF, changes to the sensitivity of programs, or to the threat." SCIFs with earlier waivers are re-accredited under current standards. Tech Spec 12.E, Changes in Security and Accreditation, is the governing management section.

DoD rule (DoDM 5105.21 Vol. 2). "An existing SCIF must be reaccredited when a change occurs" to:

  • the SCIF perimeter (expansion or reduction);
  • storage requirements (for example, closed to open storage);
  • operations, from continuous (24-hour) operation to open or closed storage.

Moving a compartment to another room within the same SCIF does not require re-accreditation.

Trigger category Examples Typical action
Physical Perimeter expansion or reduction; major modifications; new penetrations; door or hardware replacement Consult the AO before work; update FFC; re-accreditation for major changes
Operational Storage mode change; continuous-operation change; new program sensitivity; SAP entering a SCIF or SCI entering a SAPF Re-accreditation (DoD) or Co-Use Agreement
Threat Change in threat; overseas threat rating upgrade AO re-evaluation
Performance Inspection findings; security incidents; past performance Re-evaluation; possible suspension or revocation (DoD)
Documentation IDS, ACS or telecom configuration change FFC Update/Page Change; UL certificate renewal after IDS changes (ICS 705-1)
Waivers Waiver expiry (DoD waivers normally up to 1 year) Correct the deficiency or seek renewal; re-accreditation to current standards
Time At least every five years (IC); legacy three years (SAPF) Periodic re-evaluation

Security-in-Depth changes. If an AO-accepted SID layer changes (for example, building lobby access control is removed or a fence line changes), an open storage SCIF may need a 5-minute rather than 15-minute response. Report it to the AO.

Sources ICS 705-2 · ICS 705-1 · DoDM 5105.21 Vol. 2 · IC Tech Spec v1.5.1 · SAME 2026, Concept to Clearance (practitioner)

03.13

Waiver requests: package contents and consequences

When a waiver may be considered (ICS 705-1). Only in "exceptional circumstances (i.e., only when the standards cannot be met or mitigated), or when there is a documented risk-based mission need to exceed the standards."

Required package contents (ICS 705-1):

# Element What to put in it
1 Standard affected The specific ICS 705-1 or Tech Spec requirement
2 Mitigations considered What was evaluated to meet or mitigate the standard
3 Justification The mission need
4 Residual risk assessment Risk remaining after mitigation
5 Procedures to reduce risk Compensatory measures in place
6 Timeline for compliance When the standard will be met
7 Reciprocity statement Acceptance of loss of mandatory reciprocal use

DoDM 5105.21 Vol. 2 frames DoD requests similarly: the requirement that cannot be met, why, the mission impact, compensatory measures, and a timeline.

Decision and reporting.

  • The AO prepares the request (ICS 705-1; Tech Spec 3.A).
  • The IC element head, or a single named senior official who is not the AO, decides (ICD 705).
  • Approved waivers are reported to D/NCSC no later than 30 days after the decision, via the IC SCIF Repository.
  • Approved waivers appear in the letter of accreditation with the standard not met or exceeded and when it will be met (ICS 705-2).
  • DoD waivers are "normally granted for a period of up to 1 year or until such time as the waiver is no longer needed."

Consequences. A waiver removes the SCIF from mandatory reciprocal use (ICS 705-1). Tenants under DoD co-use must "accept current accreditation and any waivers." Waived SCIFs are re-accredited to current standards.

Sources ICS 705-1 · ICD 705 · ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2

03.14

De-accreditation, withdrawal and re-use

Definition (ICS 705-2 §E.5.a). "De-accreditation of a SCIF is a formal notification to the DNI (via the SCIF Repository) that the facility is no longer accredited." The AO ensures the facility is sanitized in accordance with Tech Spec Chapter 12.I, De-Accreditation Guidelines.

Path Who starts it What happens Source
Voluntary withdrawal (DoD) "When a SCIF is no longer required, the local SSO will initiate withdrawal of accreditation" Closeout inspection; repository notice DoDM 5105.21 Vol. 2
Suspension or revocation (DoD) DIA's accreditation office, when "security conditions in a SCIF are unsatisfactory" Accreditation suspended or revoked DoDM 5105.21 Vol. 2
De-accreditation (IC) AO Sanitization; formal notification via the SCIF Repository ICS 705-2 §E.5.a; Tech Spec 12.I
Co-use cancellation Host or tenant Cancellation of SCIF Co-Use/Joint-Use form Tech Spec 12.P
SAPF de-accreditation SAPF-AO Per DoDM 5205.07 DoDM 5205.07 (2025)

Re-use rule. A SCIF "de-accredited but controlled at the SECRET level … for less than one year may be re-accredited" (Tech Spec 1.B.1; ICS 705-1).

Practical close-out considerations (practitioner synthesis; the Chapter 12.I text was not reviewed for this knowledge base):

  • Remove or account for all classified material, equipment and media under SSO control.
  • Return or re-combine locks and containers under the SSO's direction; retired FF-L-2740 locks go to the DoD Lock Program rather than normal waste streams.
  • Keep the IDS operating and monitored until the SSO confirms closeout, especially if SECRET-level control will be maintained for possible re-accreditation.
  • Coordinate lease restoration obligations with the security office before demolition starts.

Sources ICS 705-2 · ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025) · DoD Lock Program

03.15

Co-Use Agreements: process and paperwork

A Co-Use Agreement (CUA) lets a tenant organization use a host's accredited SCIF under the host's accreditation. "CUA" means Co-Use (co-utilization) Agreement, not "controlled unclassified area."

Forms (Tech Spec Ch. 12.N–P; Ch. 14): SCIF Co-Use or Joint-Use Request and MOA; Co-Use/Joint-Use Request Users Guide; Cancellation of SCIF Co-Use/Joint-Use.

Rule Source
Required for reciprocal use; identifies host and tenant responsibilities ICS 705-2
Coordinated between, and signed by, both parties' AOs or designees ICS 705-2
Not required among components under the same IC element's cognizance ICS 705-2
Required for each contractor contracting effort; contractor requests include an end date ICS 705-2
The tenant accepts the host's accreditation; a tenant needing modifications pays for them ICS 705-2
Co-use begins when the host CSA concurs; host CSA keeps cognizance unless both CSAs agree to transfer ICS 705-2
DoD: elements accepting co-use "must accept current accreditation and any waivers" DoDM 5105.21 Vol. 2
DoD: Component CSAs coordinate CUAs with other DoD agencies (courtesy copy to DIA's accreditation office); DIA coordinates CUAs involving NRO, NGA and NSA DoDM 5105.21 Vol. 2
State Department SCIFs may be co-utilized by other agencies with an AO-approved agreement 12 FAM 715.9(b)

SAP and SCI co-location. "If only part of the SCIF will be used for the SAP, it will be treated as a compartmented area … a CUA must be established prior to the introduction of a SAP" (DoDM 5105.21 Vol. 2). Under the legacy SAP manual, a CUA was also required before SCI entered a SAPF or SAPCA. The 2025 DoDM 5205.07 addresses "Acceptance of Existing Accreditation" for SAP discussion in accredited SCIFs.

Exceptions that do not need a CUA (ICS 705-2):

  • Temporary storage of SCI on behalf of other organizations "for up to seven calendar days."
  • Occasional use of SCIF conference rooms by other organizations, allowed by the SSO.

See: Facility Types, Modes & Overseas Categories for co-use versus joint use.

Sources ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025) · DoDM 5205.07 Vol. 3 (cancelled; mirror) · 12 FAM 710

03.16

What to have ready at inspection

This list compiles items the public standards require in the package or ask about on the FFC. Your AO may require more, and the handling of each document follows the CSP.

Documents

Item Basis
Final FFC with no open "TBD" items, plus TEMPEST addendum and CA checklist if applicable DoDM 5105.21 Vol. 2; UFC 4-010-05 1-19
CTTA's TEMPEST Countermeasures Review and evidence the recommendations were built UFC 4-010-05 1-19.3; Tech Spec 3.A
Approved CSP, SSM inspection reports, CST logs, violation notices and resolutions Tech Spec 3.A–3.B
Photographic construction surveillance record UFC 4-010-05 4-7
As-built floor plans, site plan, door and hardware schedule, penetration log UFC 4-010-05 1-19, 4-6 (practitioner list)
IDS specification sheets, zone map, UL 2050 certificate (Extent 3), encryption certification, signed acceptance test results DoDM 5105.21 Vol. 2; Tech Spec 7.A.2, 7.D.3
Evidence of 24-hour backup power Tech Spec 7.B.5; FFC Section E
Written response force agreement and response time Tech Spec 7.C.1; FFC Section E
Acoustic test results or AO-approved audio test record Tech Spec Ch. 9
SOP, emergency plan and AO-approved catastrophic failure plan ICS 705-2 §D.2.a; FFC Section E
TSCM report if required; approved waivers; Co-Use Agreements ICS 705-2; DoDM 5105.21 Vol. 2

Physical readiness

  • All systems operational and monitored; IDS master and maintenance codes changed from factory defaults by the SCI-cleared administrator (Tech Spec 7.A.3.b).
  • Every perimeter door with its high-security switch and motion coverage; emergency egress doors alarmed 24/7 with a local annunciator (Tech Spec 7.A.3.a; 3.E.4).
  • SF 700, SF 701 and SF 702 in place for the SCIF door and containers (DoDM 5105.21 Vol. 2).
  • PED storage and signage at entry points, as the SOP requires.

Sources SCIF Fixed Facility Checklist v1.5 · DoDM 5105.21 Vol. 2 · UFC 4-010-05 (2023) · IC Tech Spec v1.5.1 · ICS 705-2