Module 14 · 16 sections

Construction Security & Build Sequence

Construction security roles, the CSP, CSTs and escorts, materials, overseas rules, a Phase 0–5 SCIF build sequence, and mistakes that delay accreditation.

On this page
  1. 14.01Construction security roles
  2. 14.02U.S. construction security requirements
  3. 14.03Who may design, build and install
  4. 14.04The Construction Security Plan: what it contains
  5. 14.05CSTs, cleared escorts and site access control
  6. 14.06Material procurement, shipping and secure storage
  7. 14.07Outside the U.S.: key construction differences
  8. 14.08The build sequence at a glance
  9. 14.09Phase 0: sponsorship and site due diligence
  10. 14.10Phase 1: planning and pre-design submittals
  11. 14.11Phase 2: design
  12. 14.12Phase 3: procurement and award
  13. 14.13Phase 4: construction
  14. 14.14Phase 5: testing, inspection and accreditation
  15. 14.15Coordinating the AO, CTTA and AHJ
  16. 14.16Most common construction mistakes
14.01

Construction security roles

A SCIF project has the normal design and construction team plus a security chain that approves, watches and documents the work. Know who holds each decision before the first drawing is issued.

Role Construction responsibilities Source
Accrediting Official (AO) "Review and approve the design concept, Construction Security Plan (CSP), and final design for each construction project prior to the start of SCIF construction"; determines whether Site Security Manager duties are full-time; accredits the finished facility Tech Spec 3.A; ICS 705-1
Site Security Manager (SSM) Single point of contact to the AO for SCIF security; "In consultation with the AO, develop a CSP"; conducts periodic security inspections for the length of the project; "Document security violations or deviations from the CSP and notify the AO within 3 business days"; assembles accreditation documents from designer and contractor input Tech Spec 3.A; ICS 705-1; UFC 1-19.1
Certified TEMPEST Technical Authority (CTTA) "Review SCIF construction or renovation plans to determine if TEMPEST countermeasures are required and recommend solutions"; gives the CSA and AO documented results with recommendations Tech Spec 3.A; ICS 705-1
Construction Surveillance Technician (CST) "Supplement site access controls, implement screening and inspection procedures, as well as monitor construction and personnel, when required by the AO" Tech Spec 3.A
Cleared escorts Monitor non-cleared workers; outside the U.S. the escort-to-worker ratio is "determined by the SSM on a case-by-case basis and documented in the CSP" Tech Spec 4.C
Special Security Officer (SSO), DoD Designates the SSM for each project, who must be SCI-indoctrinated; submits the Fixed Facility Checklist and TEMPEST addendum through channels DoDM 5105.21 Vol. 2; UFC 4-010-05
Designer of record (A-E) "Must provide the SSM the project information needed to develop these documents to support the accreditation process" UFC 1-19.1
IDS integrator "IDS installation and testing must be performed by U.S. companies using U.S. citizens"; installation to UL 2050 Extent 3 UFC 1-18.1; ICS 705-1
General contractor Builds to the approved construction documents under the CSP's site controls Tech Spec 3.B

See: Roles & Responsibilities

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 · DoDM 5105.21 Vol. 2

14.02

U.S. construction security requirements

Inside the United States, Tech Spec Chapter 2.A and Chapter 3.A–3.B set the construction security baseline. The central idea: security starts when the SCIF requirement is known, not when construction starts.

Timing (Tech Spec 2.A and 3.A).

  • "Security begins when the initial requirement for a SCIF is known."
  • Coordination with the AO must happen "before construction design, material ordering, or contracts are finalized."
  • The AO approves the design concept, the CSP and the final design before SCIF construction starts.

The Tech Spec 3.B requirements.

# Requirement Wording or detail
1 CSP before award "Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO." UFC 4-010-05: "Do not award a construction contract without an approved CSP."
2 Protect plans "Construction plans and all related documents shall be handled and protected in accordance with the CSP." UFC 4-010-05 §4-2: SCIF location and identity protected at minimum as CUI.
3 Renovations Barriers segregate construction workers from operational areas and limit unauthorized access and observation
4 Inspections "Periodic security inspections shall be conducted by the SSM or designee for the duration of the project."
5 Workforce U.S. companies using U.S. citizens preferred; U.S. persons permitted with AO-ensured mitigations
6 Site access controls Consider identity verification, random searches at entry and exit, signage listing prohibited and restricted items, physical barriers, and vehicle inspections

Supporting DoD criteria (UFC 4-010-05).

  • Materials (§4-3): "The AO may impose procedures for the procurement, shipping, selection, and secure storage of construction materials."
  • Photo record (§4-7): maintain a photographic construction surveillance record documenting construction at critical areas such as perimeter penetrations, door installations and wall assemblies.

Standards are a ceiling as well as a floor.

Tech Spec 2.A: "Exceeding a standard, even when based upon risk, requires that a waiver be processed and approved." ICS 705-1 adds that a waiver removes a SCIF from mandatory reciprocal use.

See: Accreditation Lifecycle

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 · ICS 705-1

14.03

Who may design, build and install

Citizenship rules differ by activity. Get them into the solicitation so bidders price the right workforce.

Activity Requirement Source
Design U.S. companies using U.S. citizens or U.S. persons UFC 4-010-05 §1-17
Construction "Construction and design of SCIFs should be performed by U.S. companies using U.S. citizens to reduce risk, but may be performed by U.S. companies using U.S. persons" Tech Spec 3.B.5
Mitigations "The AO shall ensure mitigations are implemented when using non-U.S. citizens." Tech Spec 3.B.5
Standard wording "U.S. companies using U.S. persons" ICS 705-1 §F
IDS installation and testing "IDS installation and testing must be performed by U.S. companies using U.S. citizens." UFC 4-010-05 §1-18.1, citing the Tech Spec
Finish work outside the U.S. SECRET-cleared or TOP SECRET-cleared U.S. personnel depending on threat Category Tech Spec Ch. 4; UFC 1-18

Definitions that matter.

  • U.S. citizen: citizenship only.
  • U.S. person: broader. The Tech Spec includes lawful permanent residents and protected individuals under 8 U.S.C.

Practical consequences.

  1. Subcontractor flow-down. The citizenship requirement applies to every trade working on the SCIF, not only the prime contractor.
  2. IDS is stricter. An alarm company whose technicians are U.S. persons but not U.S. citizens cannot install or test SCIF IDS under the DoD criteria.
  3. Mitigations are documented. If non-citizen U.S. persons work on the project, the CSP should describe the AO-approved mitigations, such as escorts or restricted tasks.
  4. Experience matters too. Practitioners consistently list hiring a GC or installer without SCIF experience as a leading cause of rework and failed inspections.

See: Intrusion Detection & UL 2050 / Extent 3

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 · Pete Milham: ICD 705 construction lessons (practitioner) · Vertex: SCIF construction challenges (practitioner)

14.04

The Construction Security Plan: what it contains

The CSP is the AO-approved rulebook for security during design and construction. The Tech Spec provides a CSP template among its Chapter 14 forms. The table below reflects Tech Spec 3.B, UFC 4-010-05 and practitioner guidance on what a CSP typically addresses.

CSP element What it documents Basis
Project identification Location, description, schedule, AO and SSM Practitioner
Adjacent spaces Neighboring tenants and public areas, and their risk Practitioner
Security-in-Depth SID documentation block on the CSP form Primary (CSP form v1.5)
Drawings and specifications Marking, distribution, storage and disposal of project documents Primary (Tech Spec 3.B.2; UFC 4-2)
IDS technical documentation How the AO requires IDS documents to be protected Primary (Tech Spec 7.A.2.k)
Personnel Citizenship and U.S. person status, clearance requirements, biographical data, badging, escort ratios, CST use Primary (Tech Spec 3.B.5, 4.C–4.D)
Site access controls ID checks, searches, prohibited-items signage, barriers, vehicle inspection Primary (Tech Spec 3.B.6)
Materials Procurement, shipping, receipt inspection and secure storage Primary (UFC 4-3) + practitioner
Inspections Schedule, hold points and photo documentation Primary (Tech Spec 3.B.4; UFC 4-7)
Violations Documentation and reporting to the AO within 3 business days Primary (Tech Spec 3.A)
Renovations Separation barriers between work and operational areas Primary (Tech Spec 3.B.3)

Protecting project documents.

  • UFC 4-010-05 requires a SCIF's location and identity to be protected at minimum as CUI.
  • UFC 4-010-05 §1-16.3 notes that TEMPEST vulnerabilities tied to a location are classified at minimum CONFIDENTIAL.
  • Completed Fixed Facility Checklists may be CUI or classified. Plan for secure file transfer rather than routine project-management platforms.

Sources Construction Security Plan form v1.5 · IC Tech Spec v1.5.1 · UFC 4-010-05 · PSC: crafting a CSP (practitioner) · SAME: concept to clearance (practitioner)

14.05

CSTs, cleared escorts and site access control

Construction surveillance keeps unauthorized people, devices and materials out of the SCIF while it is being built. How much surveillance a project needs depends on location and threat.

Construction Surveillance Technicians.

  • Role (Tech Spec 3.A): CSTs "supplement site access controls, implement screening and inspection procedures, as well as monitor construction and personnel, when required by the AO."
  • Inside the U.S.: CST use is threat-driven and AO-driven. The AO and SSM set coverage in the CSP.
  • Outside the U.S. (Tech Spec 4.C): CSTs hold U.S. TOP SECRET clearances and are "specially trained in surveillance and the construction trade to deter technical penetrations and thwart implanted technical collection devices."
  • Records: CSTs keep surveillance records and logs as required by the CSP.

Cleared escorts.

  • Escorts monitor non-cleared workers.
  • Outside the U.S., the escort-to-worker ratio is "determined by the SSM on a case-by-case basis and documented in the CSP" (Tech Spec 4.C).
  • On U.S. projects that use escorts, the CSP should state the ratio and the tasks escorted workers may perform.

Cleared American Guards (overseas).

Tech Spec 4.C describes Cleared American Guards who screen personnel and materials at the construction access control point and deny prohibited items.

Site access controls (Tech Spec 3.B.6).

Control Purpose
Identity verification Only listed, vetted workers enter
Random searches at entry and exit Deter introduction of devices and removal of materials or documents
Signage listing prohibited and restricted items Put workers on notice before entry
Physical barriers Separate the SCIF work area from other construction and occupied areas
Vehicle inspections Control deliveries and equipment

Sources IC Tech Spec v1.5.1 · IC Tech Spec v1.5 (DNI archive) · UFC 4-010-05

14.06

Material procurement, shipping and secure storage

Construction materials are a path for implanted technical collection devices. The rules scale with threat: light-touch in most U.S. projects, heavily controlled overseas.

Inside the U.S.

  • UFC 4-010-05 §4-3: "The AO may impose procedures for the procurement, shipping, selection, and secure storage of construction materials."
  • The Tech Spec's Chapter 14 forms include an Inspectable Materials Checklist.
  • Practitioner CSP guidance covers receipt inspection and secure storage of materials that will be concealed in the perimeter.
  • Restricted and long-lead items: FF-L-2740 locks are sales-restricted to the government and authorized contractors. STC-rated door assemblies, FF-L-2890 devices, acoustic duct silencers, RF shielding materials and UL 2050 monitoring commonly have long lead times. One engineering firm notes "Specialized materials may have long lead times and limited suppliers."

Outside the U.S. (Tech Spec Chapter 4, as extracted).

Control Requirement
Source restrictions Materials from critical-threat countries prohibited
Random selection Cleared U.S. citizens randomly select a portion of general construction materials from non-specific stock; the allowed portion depends on threat Category
Secure transport Non-inspectable materials move by secure transportation: 24-hour courier escort or approved tamper-detecting transit methods; U.S. military or flag carriers preferred
Secure Storage Area "true floor to true ceiling, slab-to-slab construction of some substantial material, and a solid wood-core or steel-clad door equipped with an AO-approved security lock"
Storage control Under the control of U.S. personnel holding at least SECRET clearances

Practical steps for any project.

  1. Identify which materials will be concealed in the perimeter (framing, board, insulation, electrical boxes, duct sections) and whether the AO wants them inspected.
  2. Set a receiving location and inspection routine in the CSP.
  3. Store perimeter materials where uncontrolled workers cannot access them unobserved, if the CSP requires it.
  4. Keep delivery and inspection records with the photo log.

See: Facility Types, Modes & Overseas Categories

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · FF-L-2740B · PSC: crafting a CSP (practitioner) · Vertex: SCIF construction challenges (practitioner)

14.07

Outside the U.S.: key construction differences

The Tech Spec has three construction regimes: Chapter 3 inside the U.S., Chapter 4 outside the U.S. and not under Chief of Mission (COM) authority, and Chapter 5 under COM authority. Overseas rules are keyed to threat Categories based on the Department of State Security Environment Threat List (SETL) technical threat rating.

Topic Inside the U.S. (Ch. 3) Outside the U.S. (Ch. 4 and 5, as extracted)
Authority IC element AO AO; under COM, Department of State OSPB standards (12 FAH-6) also apply, and the more stringent standard governs
Security-in-Depth Optional; affects response time and construction Mandatory
Threat Categories Not used Category I (critical or high technical threat, high vulnerability buildings), Category II, Category III (low and medium technical threat)
CSTs When required by the AO Required per threat Category (Ch. 4); under COM, not required when contractors are U.S. citizens with TOP SECRET clearances (Ch. 5). Category III: surveillance begins "at the start of SCIF construction or the installation of major utilities, whichever comes first." Categories I and II: earlier, beginning with construction of adjacent public access or administrative areas
Finish work Per CSP Category III: "SECRET-cleared, U.S. personnel"; Categories I and II: "TOP SECRET-cleared, U.S. personnel"
Non-cleared workers Per CSP and AO mitigations Limited tasks (for example major utility installation, demolition, debris removal) "monitored by CSTs or cleared escorts"
Workforce vetting Citizenship rules Foreign nationals from State Department prohibited-list countries excluded; biographical data and fingerprints before starting
Materials AO may impose controls Source restrictions, random selection, secure transport, Secure Storage Area
Open storage Permitted with matching walls and response Avoided in Category I (Ch. 4); avoided in Categories I and II under COM (Ch. 5)
Alarm response Closed 15 min; open 15 min with SID, 5 min without Closed 15 min; open 5 min
Interim accreditation Expressly provided (Ch. 4.I, 5.K)

Sources IC Tech Spec v1.5.1 · IC Tech Spec v1.5 (DNI archive) · UFC 4-010-05 · 12 FAM 710

14.08

The build sequence at a glance

A SCIF tenant improvement follows the normal design-bid-build path with security gates inserted at each step. The sequence below synthesizes primary requirements with practitioner practice. It is a planning aid, not a substitute for the AO-approved CSP and design.

Phase Name Goal Key outputs Security gate
0 Sponsorship and site due diligence Confirm the need, the sponsor, the AO and a buildable space Sponsor and AO identified; SSM appointed; site feasibility findings Requirement known: security begins (Tech Spec 2.A)
1 Planning and pre-design submittals Define the SCIF profile and get early documents to the AO and CTTA Concept approval; preliminary CSP; Fixed Facility Checklist; TEMPEST Addendum AO and CTTA engaged before design is finalized
2 Design Produce construction documents that meet the Tech Spec, the code and the CTTA's recommendations Drawings; door, hardware and penetration schedules; IDS design; AHJ life-safety review AO approves design concept, CSP and final design (Tech Spec 3.A)
3 Procurement and award Hire a qualified, properly vetted team and buy long-lead items Contract award; subcontractor citizenship compliance; long-lead orders No award without an approved CSP (Tech Spec 3.B.1)
4 Construction Build under CSP controls with documented inspections Site controls; photo record; pre-cover inspection; change log Periodic SSM inspections; violations to AO within 3 business days
5 Testing, inspection and accreditation Prove performance and deliver the accreditation package Acoustic, IDS and (if required) TEMPEST/RF and TSCM results; UL 2050 certificate; as-builts; final checklist AO inspection and accreditation

How to use the table.

  • Owners and sponsors should treat each security gate as a schedule milestone with float in front of it.
  • GCs should price the Phase 4 controls from the CSP, not from a generic SCIF assumption.
  • Integrators should be engaged in Phase 1 or 2, because IDS, access control, cable entry and power decisions shape the architecture.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 · ICS 705-2 · SAME: concept to clearance (practitioner)

14.09

Phase 0: sponsorship and site due diligence

A SCIF cannot be built on speculation. It needs a government sponsor, an AO, and a space that can physically meet the perimeter rules.

Primary steps.

  1. Confirm sponsorship and need. For DoD, a concept approval request goes to the Service Cognizant Security Authority or senior intelligence official, certifying the need and that no existing SCIF can support it (UFC 4-010-05 §2-2, 2-2.1). Practitioners note that commercial (contractor) SCIFs likewise need a government contract sponsor and an AO.
  2. Identify the AO and appoint the SSM as early as possible (Tech Spec 3.A; UFC 1-14).

Space and lease due diligence (practitioner).

Question Why it matters
Can walls reach the true deck? What is the deck height, and are there flutes? Slab-to-slab perimeter
Are there exterior windows, and on which floors? 18-ft rule; acoustics; visual protection
What is adjacent: public corridors, other tenants, loading docks? SID, stand-off, acoustic exposure
Do building utilities serving other areas cross the space? Tech Spec 3.G.3 prohibits transit without AO-approved mitigation
Is there room for a vestibule at the primary entrance? Recommended by the Tech Spec and UFC
Can the telecom room be inside or adjacent to the SCIF? Minimizes Protected Distribution System needs (UFC 3-3.3.2)
Will the landlord approve penetrations, roof or core work, and IDS monitoring pathways? Construction and alarm transmission feasibility
What are restoration obligations at lease end? Cost of removing SCIF construction

A real estate law firm notes that leases should address "responsibility for SCIF maintenance, lessor preapproval of any future upgrades required by a government contract."

GC and integrator tasks.

  • GC: walk the space above the ceiling and below the floor; map existing slab penetrations, deck conditions and shared utilities.
  • Integrator: identify the likely monitoring path, telecom room location and utility entry point.

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · Holland & Knight: leasing SCIF space (industry) · Pete Milham: ICD 705 construction lessons (practitioner)

14.10

Phase 1: planning and pre-design submittals

Phase 1 turns a sponsored requirement into a defined SCIF profile, and puts the first documents in front of the AO and CTTA.

Primary steps.

  1. Assemble the interdisciplinary team: planning, the supported command or customer, the SSM, communications, security and engineering (UFC 4-010-05 §2-4).
  2. Submit during planning: concept approval, a preliminary CSP, the Fixed Facility Checklist, and the TEMPEST Addendum, which requests the CTTA's TEMPEST Countermeasures Review (UFC 4-010-05 §2-5, 1-19.3).
  3. Decide the SCIF profile (Tech Spec 3.C, 3.H; UFC 3-4.3.2):
Decision What it drives
Closed storage, open storage, Secure Working Area or continuous operation Wall type, container count, alarm response
SID accepted by the AO or not Wall A vs. Wall B/C for open storage; 15-minute vs. 5-minute response
Discussion areas and amplified-audio rooms Sound Group 3 vs. Sound Group 4 zoning
Electronic processing of classified information TEMPEST Checklist; possible RF protection at CTTA direction

The Tech Spec's Pre-Construction Checklist asks where Security-in-Depth starts ("Security in-depth starting point location"). Answer it with the AO, not by assumption.

GC tasks.

  • Review the preliminary CSP for site controls that affect general conditions: escorts, badging, searches, secure storage, document handling.
  • Flag space conditions from Phase 0 that affect the profile, such as windows inside the 18-ft zone or utilities crossing the space.

Integrator tasks.

  • Confirm the alarm response time the profile requires and whether the monitoring and response arrangement can meet it.
  • Identify IDS, access control, telecom and PED-control needs early enough to be on the Fixed Facility Checklist.

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · SCIF Pre-Construction Checklist v1.5 · ICS 705-1

14.11

Phase 2: design

Design is where most accreditation problems are either prevented or baked in. Every perimeter element, penetration and door should be resolved on paper.

Architectural (Tech Spec 3.C–3.G; UFC 3-4).

  • Perimeter wall types and slab-to-slab details, including deck flute infill.
  • Door schedule with STC assembly ratings 5 points above the target and the FF-L-2890 type for each door; vestibule.
  • Window treatments; the 18-ft zone marked on elevations.
  • Penetration schedule listing every duct, pipe, conduit and sleeve with its treatment.
  • PED cabinet location; no recessed cabinets or boxes on perimeter walls.

MEP (UFC 2-10, 3-4.11–3-4.18).

  • Single utility entry point.
  • Z-ducts or silencers; man-bars with access ports.
  • Dielectric breaks and grounding per the TEMPEST Countermeasures Review.
  • Dedicated SCIF power, UPS and generator strategy; telecom room cooling.
  • Sprinkler and fire alarm penetration strategy coordinated with the AHJ and CTTA.

Low-voltage and security (integrator; UFC 3-4.17–3-4.20).

  • UL 2050 Extent 3 IDS design with the PCU and all sensor cabling inside the perimeter.
  • UL 634 Level II High Security Switches on every perimeter door, plus motion coverage and duress.
  • Access control readers and UL 1034 fail-secure strikes coordinated with FF-L-2890 electric-release types.
  • Sound masking only where the AO approves it.
  • Cable entry at a single point, color-coded by classification; separation per the CTTA's review.

Life safety and document control.

  • AHJ review early: egress-only doors, delayed egress, panic hardware, fire-rated acoustic doors, firestopping and notification appliances (Tech Spec 3.E.5; UFC 1-9).
  • Protect drawings as the CSP requires, at minimum CUI for location and identity (UFC 4-2).

The gate.

The AO approves the design concept, the CSP and the final design before construction starts (Tech Spec 3.A).

See: Perimeter Construction & Vaults · See: Penetrations, Utilities & Life Safety

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · DoD Lock Program: Pedestrian Door Deadbolt Devices

14.12

Phase 3: procurement and award

Phase 3 has one hard rule and several practical ones. The hard rule protects the whole project.

The hard rule.

No construction contract award without an approved CSP. Tech Spec 3.B.1: "Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO." UFC 4-010-05: "Do not award a construction contract without an approved CSP."

Workforce.

Team Requirement
Design U.S. companies using U.S. citizens or U.S. persons (UFC 1-17)
Construction U.S. companies using U.S. citizens preferred; U.S. persons permitted with AO-ensured mitigations (Tech Spec 3.B.5)
IDS installation and testing U.S. companies using U.S. citizens (UFC 1-18.1)

Flow the requirements down to every subcontractor and supplier who will work on the SCIF.

Long-lead buyout (practitioner).

Item Procurement note
STC-rated door assemblies The tested assembly must match the specified door, frame, seals and hardware prep
FF-L-2890 devices and FF-L-2740 locks QPL products; FF-L-2740 locks are sales-restricted to the government and authorized contractors
Acoustic duct silencers Coordinate with the HVAC design, because baffles add backpressure
RF shielding materials Only when the CTTA directs
UL 2050 installation and monitoring Installer must use U.S. citizens and deliver a UL 2050 certificate

One engineering firm notes "Specialized materials may have long lead times and limited suppliers."

Before you buy door hardware.

The DoD Lock Program tells buyers to "check with your local fire marshal (Authority Having Jurisdiction – AHJ) prior to procurement." Egress and fire-rating decisions can change the device type.

Material controls.

If the AO imposes procurement, shipping or storage procedures (UFC 4-3), bake them into purchase orders and delivery schedules.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 · DoD Lock Program: Pedestrian Door Deadbolt Devices · FF-L-2740B · Vertex: SCIF construction challenges (practitioner)

14.13

Phase 4: construction

Phase 4 is where the approved design becomes concealed work. The security controls exist so the AO can trust what it will never see.

Construction steps and trade tasks.

Step GC tasks Integrator tasks Basis
1. Mobilize site security Access control, ID checks, searches, prohibited-items signage, barriers, vehicle inspection; escorts or CSTs if required Badge and vet low-voltage crews per CSP Tech Spec 3.B.3, 3.B.6
2. Demo and deck prep Lay out walls to the true deck; install 16-gauge top and bottom track bedded in acoustic sealant Identify abandoned cabling and sleeves to remove Tech Spec Wall A
3. Framing and hardening Expanded metal or plywood (Walls B/C); sleeves, man-bars, access ports; dielectric breaks and grounding per TCR; set door frames plumb, level and square Confirm sleeve locations at the single entry point Tech Spec 3.C, 3.E.6, 3.G
4. Rough-in Single-point utility entry; spare conduits filled and capped IDS and access control conduit and cabling inside the perimeter; PCU location Tech Spec 3.G.4–3.G.6; UFC 3-4.17
5. Hold point: pre-cover inspection SSM (and AO or TSCM if requested) inspects in-wall and above-ceiling conditions; photograph every wall segment, penetration and top-of-wall seal Photograph cable routes and boxes before cover Tech Spec 3.B.4; UFC 4-7; practitioner
6. Close walls Fastened insulation; staggered board layers; sealant at top, bottom and all penetrations; finish true floor to true ceiling Tech Spec Wall A; UFC 3-4.4
7. Doors and hardware STC assemblies, seals, cam-lift hinges, closers, FF-L-2890 devices with FF-L-2740 locks, strikes High Security Switches; egress-only alarm with local annunciator Tech Spec 3.E; UFC 3-4.6
8. Systems Fire alarm devices and AHJ tests IDS and access control install and programming; 24-hour standby power verification; sound masking if approved UFC 3-4.17.3.7
9. Change control Log every field change and obtain SSM and AO concurrence Same for device moves and added penetrations Practitioner

Reporting.

The SSM documents security violations or deviations from the CSP and notifies the AO within 3 business days (Tech Spec 3.A). One accreditation consultant puts it plainly: "Any deviations from the approved design, no matter how minor, must be documented and approved."

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 · CenCore: SCIF construction Q&A (practitioner) · ASI: SCIF accreditation process (practitioner)

14.14

Phase 5: testing, inspection and accreditation

Phase 5 proves the SCIF performs and hands the AO a complete, consistent documentation package.

Testing (Tech Spec Ch. 7 and 9; UFC 4-4, 4-5).

Test What it proves Basis
Acoustic verification Sound Group 3 or 4 met at all perimeter walls and openings, by audio check or instrumented NIC test as the AO requires Tech Spec Ch. 9
IDS acceptance testing System meets Chapter 7; acceptance testing is required before accreditation Tech Spec 7.A.2.o
UL 2050 certificate Contractor SCIFs "shall maintain a current UL certificate of installation and service" ICS 705-1
TEMPEST or RF testing CTTA-directed countermeasures perform, if required Tech Spec 3.C.4; CTTA
TSCM evaluation Technical security of the completed space, as the AO directs UFC 4-4, 4-5

Documentation delivered to the SSM (UFC 1-19, 4-6; practitioner).

  • As-built floor plans and site plan.
  • IDS specifications and zone map.
  • Door and hardware schedule; penetration log.
  • Construction photo record.
  • Test reports.
  • Final Fixed Facility Checklist and TEMPEST addendum.

DoD accreditation packages also require IDS specification sheets, the UL 2050 certificate, the NIST encryption certificate, IDS test results and a catastrophic failure plan (DoDM 5105.21 Vol. 2). Unresolved "TBD" entries on the final Fixed Facility Checklist stall accreditation.

Accreditation.

The AO or SSM inspects, and the AO accredits (Tech Spec 3.A; ICS 705-2). Before SCI operations begin, SOPs, access rosters, alarm response arrangements and emergency procedures must be in place. ICS 705-2 describes accreditation as "the beginning of a life-cycle process of continuous monitoring and evaluation, periodic re-evaluations, and documentation reviews."

See: Accreditation Lifecycle · See: Intrusion Detection & UL 2050 / Extent 3

Sources UFC 4-010-05 · IC Tech Spec v1.5.1 · ICS 705-2 · DoDM 5105.21 Vol. 2

14.15

Coordinating the AO, CTTA and AHJ

Three authorities outside the construction team can each stop a SCIF project. They decide different things, and none of them can overrule the others in their own area.

Authority Decides Engage Bring them
Accrediting Official (AO) Design concept, CSP and final design approval; SID acceptance; CST and escort needs; testing method; accreditation When the SCIF requirement is known and before design, material ordering or contracts are finalized (Tech Spec 2.A) Concept approval request, preliminary CSP, Fixed Facility Checklist, design submittals, deviation requests
Certified TEMPEST Technical Authority (CTTA) Whether TEMPEST countermeasures are required and which ones: RF protection, dielectric breaks, grounding, filtering; evaluation of RF transmitters During planning, through the TEMPEST Addendum (UFC 1-19.3) TEMPEST Checklist information, equipment list, signal and power lines exiting the SCIF, construction details
Authority Having Jurisdiction (AHJ) Building code, egress, accessibility, fire ratings, firestopping, fire alarm and notification Schematic design, and before door hardware procurement Egress plan, door and hardware schedule, fire-rated assemblies, notification strategy

The SSM holds it together.

The SSM is the single point of contact to the AO. One design firm's guidance: "The SSM is the primary (and, many times, the only) contact for all things related to ICD 705 space." Keep the SSM in project meetings and route security-related RFIs through the SSM.

Waivers are not an AO shortcut.

  • ICD 705: the waiver authority is the IC element head or a single named senior official, and that official may not be the AO.
  • ICS 705-1: a waiver removes a SCIF from mandatory reciprocal use.
  • Tech Spec 2.A: exceeding a standard also requires a waiver.

Coordination rules of thumb.

  1. Get AHJ and AO positions in writing on every egress door.
  2. Do not self-specify TEMPEST countermeasures or skip the CTTA's recommendations.
  3. Build to the AO-approved construction documents, not to a general reading of ICD 705.

See: Roles & Responsibilities · See: RED/BLACK, TEMPEST & EMI Filters

Sources IC Tech Spec v1.5.1 · ICD 705 · ICS 705-1 · UFC 4-010-05 · SAME: concept to clearance (practitioner)

14.16

Most common construction mistakes

These mistakes recur across SCIF projects. The source type column shows whether each is grounded in a primary requirement, practitioner experience, or both.

# Mistake Why it fails or delays Source type
1 Engaging the AO after design, material orders or contracts Tech Spec 2.A requires coordination first Primary
2 Awarding the contract or starting work before the CSP is approved Violates Tech Spec 3.B.1 and 3.A Primary
3 Walls stop at the drop ceiling or leave deck gaps Not true floor to true ceiling; acoustic and visual-evidence failure Primary
4 Missing acoustic sealant; unfastened insulation Flanking paths Primary
5 Recessed boxes or cabinets in perimeter walls Violates Tech Spec 3.G.5 and UFC prohibitions Primary
6 Ducts meeting the size trigger without bars or access ports; no acoustic duct treatment Tech Spec 3.G.7 Primary + practitioner
7 Utilities for other areas crossing the SCIF; scattered utility entries Tech Spec 3.G.3, 3.G.4 Primary
8 Metallic penetrations without CTTA-required countermeasures Tech Spec 3.G.2 Primary
9 Untested door component mixes; racked frames; exposed hinge pins Tech Spec 3.E; poor installation Primary + practitioner
10 Wrong lock hardware or fail-safe strikes Tech Spec 3.E; UFC 3-4.6.5 Primary + practitioner
11 IDS cabling or PCU outside the perimeter; IDS not UL 2050 certificated; short standby power UFC 3-4.17.3 Primary + practitioner
12 VTC or amplified-audio rooms built to Sound Group 3 UFC 3-4.3.2 Primary + practitioner
13 No photo record; untracked field changes; missing test data UFC 4-7 Primary + practitioner
14 Late CTTA involvement; RF shielding damaged before cover ICS 705-1 Practitioner + primary
15 GC or installer without SCIF experience Rework and failed inspections Practitioner
16 Life-safety conflicts found at AHJ final Late hardware and door changes Practitioner + primary
17 SCIF documents handled like ordinary construction documents Tech Spec 3.B.2; UFC 4-2 Primary + practitioner
18 Exceeding a standard without a waiver Tech Spec 2.A; loss of reciprocity Primary

See: Traps & Common Failures

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 · ICS 705-1 · CenCore: SCIF construction Q&A (practitioner) · Vertex: SCIF construction challenges (practitioner) · Pete Milham: ICD 705 construction lessons (practitioner)