Module 01 · 16 sections

Governance & Document Hierarchy

ICD 705, ICS 705-1/-2, the IC Tech Spec, DoD and SAP manuals, NISPOM, UFC 4-010-05, who the CSAs are, and how reciprocity and waivers work.

On this page
  1. 01.01The document hierarchy at a glance
  2. 01.02ICD 705: what the directive requires
  3. 01.03ICS 705-1: physical and technical security standards
  4. 01.04ICS 705-2: accreditation and reciprocal use
  5. 01.05The IC Tech Spec: purpose and applicability
  6. 01.06Tech Spec v1.5.1 chapter map
  7. 01.07Tech Spec version history
  8. 01.08Tech Spec forms and plans (Chapter 14)
  9. 01.09Reported 2025–2026 changes to SCIF requirements
  10. 01.10DoDM 5105.21: DoD's SCI security manual
  11. 01.11DoDM 5205.07 (2025) and legacy SAP standards
  12. 01.1232 CFR Part 117 (NISPOM) and 32 CFR Part 2001
  13. 01.13DCSA's role, and what it does not do
  14. 01.14Cognizant Security Authorities for SCI at a glance
  15. 01.15UFC 4-010-05: DoD design criteria for SCIFs and SAPFs
  16. 01.16Reciprocity and waivers
01.01

The document hierarchy at a glance

Authority chain (ICD 705 §A; ICS 705-1 §A): National Security Act of 1947, as amended → EO 12333, as amended → EO 13526 → ICD 705ICS 705-1 and ICS 705-2IC Tech Spec.

Tier Document Current public version Role
Directive ICD 705, Sensitive Compartmented Information Facilities Signed 26 May 2010; posted copy carries later technical amendments naming the Director, NCSC (D/NCSC) Policy, accreditation and waiver authority, reciprocity, SCIF inventory
Standard ICS 705-1, Physical and Technical Security Standards for SCIFs 17 Sep 2010 (NCSC lists it as "ICS 705-01") Physical and technical standards; facility types; roles; waiver process
Standard ICS 705-2, Standards for the Accreditation and Reciprocal Use of SCIFs 22 Dec 2016 ("ICS 705-02") Accreditation criteria, re-evaluation, de-accreditation, reciprocity, co-use
Technical specification Technical Specifications for Construction and Management of SCIFs v1.5.1, 26 Jul 2021 Construction, IDS, ACS, acoustics, telecom and management details, plus the forms

Parallel and implementing documents:

Community Document Relationship
DoD SCI DoDM 5105.21 Vols. 1–3 DoD implementation of SCI administrative, physical and technical security
DoD SAP DoDM 5205.07 (17 Jan 2025) SAPF physical security, built to equivalent Tech Spec criteria
DoD design UFC 4-010-05 (26 May 2023) Planning, design and construction criteria for SCIFs and SAPFs
Collateral / industry 32 CFR Part 117 and Part 2001 Contractor safeguarding; SCI handled under IC directives via §117.23
State Department 12 FAM 710; OSPB standards (12 FAH-6) SCIFs under Chief of Mission authority

Related ODNI standards on the same NCSC page, for context only: ICS 706-01 (domestic facility security risk assessments, 18 Jun 2019) and ICS 706-02 (mission-critical facility-related control systems, 23 Dec 2019).

Sources NCSC Security Governance and Regulations · ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1

01.02

ICD 705: what the directive requires

ICD 705 is short, but every other document traces back to its Section D policy statements.

Policy point What ICD 705 says
SCI only in accredited SCIFs All SCI must be handled in accredited SCIFs, and facilities must be accredited before SCI operations begin.
Accreditation authority "The IC element head may accredit, re-accredit, and de-accredit SCIFs. This authority may be delegated by the IC element head to a single named official, who shall serve as the Accrediting Official." The AO may delegate decision authority for specific SCIFs "while retaining overall responsibility."
Waiver authority Granted "pursuant to a documented mission need." May be delegated to "a single named senior official" and "may not be further delegated." "In no case may this official be the same person as the Accrediting Official."
Waiver reporting "All approved waivers shall be reported to the D/NCSC immediately, but no later than 30 days after the IC element head's decision."
Reciprocity SCIFs are built for reciprocal use across IC elements unless waived. D/NCSC issues the reciprocity standards (now ICS 705-2).
Chief of Mission facilities "For SCIFs that fall under Chief of Mission authority, IC elements shall comply with Overseas Security Policy Board (OSPB) standards." Waivers to OSPB standards go to the State Department's Bureau of Diplomatic Security.
Inventory D/NCSC manages an inventory of all SCIFs, updated within 30 days of new or changed information. This is the IC SCIF Repository.
Rescissions DCID 6/9 (with its Manual and Annexes), ICPM 2005-700-1, ICPM 2006-700-7 and ICPM 2007-700-2.

Sources ICD 705 · ICS 705-1 · NCSC Security Governance and Regulations

01.03

ICS 705-1: physical and technical security standards

ICS 705-1 (17 Sep 2010) is where the "shall" statements for the space itself live. It also directs development of the Tech Spec as its implementation document.

What it covers:

  • Perimeter: walls, windows, doors, ceiling and floor.
  • Intrusion detection: "IDS shall detect attempted or actual unauthorized human entry into a SCIF." Installation, related components and monitoring stations "shall comply with Underwriters Laboratories (UL) 2050 Extent 3 standards." Response times follow 32 CFR Parts 2001 and 2004 for Top Secret. "Contractor SCIFs shall maintain a current UL certificate of installation and service."
  • Access control (§G.2.b): access limited to authorized personnel by AO-approved methods, including "automated access control systems using at least two technologies (badge, PIN, biometric, etc.)." These methods are not approved for securing SCIF entrances when the SCIF is unoccupied.
  • RF transmitters (§G.2.a): not introduced "unless evaluated and mitigated to be a low risk to classified information by a competent authority (e.g., CTTA) and approved by the AO."
  • Unclassified systems (§G.2.d): evaluated by the CTTA and AO for TSCM and TEMPEST concerns.
  • PEDs (§G.2.e): PEDs "pose a risk to SCI"; the Tech Spec provides the restrictions.
  • RF shielding: "should be planned for installation during initial construction as costs are significantly higher to retrofit."
  • Facility types and roles: open and closed storage, continuous operation, SWA, TSWA, T-SCIF; CSA, AO, SSM, CTTA, CST.
  • Waivers: package contents, and the rule that a waiver removes a SCIF from mandatory reciprocal use.

Grandfathering. SCIFs accredited as of ICD 705's effective date "shall continue to be operated in accordance with the physical and technical security requirements applicable at the time of the most recent accreditation or re-accreditation." On re-accreditation, the SCIF must meet current IDS standards unless a waiver is granted. ICS 705-1 and the Tech Spec also allow a SCIF de-accredited but controlled at the SECRET level for less than one year to be re-accredited.

Sources ICS 705-1 · IC Tech Spec v1.5.1 · SAME 2026, Concept to Clearance (practitioner)

01.04

ICS 705-2: accreditation and reciprocal use

ICS 705-2 (22 Dec 2016, signed by the Director, NCSC) governs what happens around the build: how a facility is accredited, kept accredited, shared and closed.

Topic ICS 705-2 requirement
Nature of accreditation "The beginning of a life-cycle process of continuous monitoring and evaluation, periodic re-evaluations, and documentation reviews."
Accreditation documents (§D.2.a) "Shall include, but not be limited to: 1) Fixed Facility checklists; 2) Standard operating procedures; 3) Emergency plans; 4) Construction Security Plan; and 5) Waiver request packages."
Letter of accreditation (§D.1.a) SCIF identity, type (e.g., open or closed storage), effective date, a statement of compliance with physical, TEMPEST and technical standards, and approved waivers "to include details of the standard(s) not met and when they are scheduled to be met, or standard(s) exceeded."
Inspections Conducted by the AO or designee before final accreditation.
TSCM "May be required for new SCIFs or significant renovations."
Periodic re-evaluation (§D.3.a) The CSA "shall ensure that regular, periodic re-evaluations are conducted … based on the sensitivity of programs, threat, facility modifications, and past security performance, or at least every five years." Results go to NCSC via the SCIF Repository within 30 days.
Re-accreditation (§D.4.b) Required "when there are major modifications to the SCIF, changes to the sensitivity of programs, or to the threat."
De-accreditation (§E.5.a) "A formal notification to the DNI (via the SCIF Repository) that the facility is no longer accredited."
Reciprocity A SCIF accredited by an IC element AO "shall be reciprocally accepted for use as accredited by all IC elements" when there are no waivers to ICS 705-01, ICS 705-02 or the Tech Spec.
Co-use Required for reciprocal use; not required among components under the same IC element's cognizance; required for each contractor contracting effort; the tenant accepts the host accreditation and pays for modifications it needs.
Short-term exceptions Temporary storage of SCI for other organizations up to seven calendar days; occasional conference-room use approved by the SSO without a Co-Use Agreement.

See: Accreditation Lifecycle for how these rules play out step by step.

Sources ICS 705-2 · ICS 705-1 · IC Tech Spec v1.5.1

01.05

The IC Tech Spec: purpose and applicability

Full title: IC Tech Spec for ICD/ICS 705: Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities. Current public version 1.5.1, 26 July 2021.

Purpose (Ch. 1.A). The Tech Spec "sets forth the physical and technical security specifications and best practices for meeting standards of" ICS 705-01. "IC Elements shall fully implement this standard within 180 days of its signature." The v1.5.1 transmittal memo, signed by the Acting Director, NCSC, was "effective upon signature."

Applicability to SAPFs (Ch. 1.B.2). SAP language was added in v1.4. When the specifications "have been applied to new construction, renovations, and operation of Special Access Program Facilities (SAPFs), those facilities shall satisfy the standards outlined in ICD 705 to enable uniform use across all IC elements." Accreditation of a SAPF as a SCIF "will be based upon a review of all required SCIF construction documentation." If documentation is incomplete or waivers exist, "the AO is not required to issue SCIF accreditation." A SAPF co-utilized as a SCIF is held to the highest applicable requirement.

Risk management (Ch. 2.A). Coordination with the AO must happen "before construction design, material ordering, or contracts are finalized." And: "Exceeding a standard, even when based upon risk, requires that a waiver be processed and approved in accordance with ICD 705."

Prefabricated products (note added in v1.3). "Advertised claims by manufactures that their product(s), to include mobile platforms, prefabricated structures, containers and modular structures are built to SCIF standards and can be accredited without modification may not be accurate."

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · IC Tech Spec v1.5.1 (NCSC) · SAME 2026, Concept to Clearance (practitioner)

01.06

Tech Spec v1.5.1 chapter map

Ch. Title Sections
1 Introduction A Purpose; B Applicability
2 Risk Management A Analytical Risk Management Process; B Security in Depth (SID); C Compartmented Area (CA)
3 Fixed Facility SCIF Construction A Personnel; B Construction Security; C Perimeter Wall Construction; D Floor and Ceiling; E SCIF Doors; F Windows; G Perimeter Penetrations; H Alarm Response Time (U.S.); I Secure Working Areas; J Temporary Secure Working Areas
4 SCIFs Outside the U.S. and NOT Under Chief of Mission Authority General; threat ratings; personnel; construction security; procurement, transport and storage of materials; technical security; interim accreditations
5 SCIFs Outside the U.S. and Under Chief of Mission Authority Applicability; threat Categories; construction; personnel; construction security; materials; technical security; interim accreditations
6 Temporary, Airborne, and Shipboard SCIFs Ground-based T-SCIFs; permanent and tactical SCIFs aboard aircraft; on surface or subsurface vessels
7 Intrusion Detection Systems Specifications; modes of operation; operations and maintenance; installation and testing
8 Access Control Systems SCIF access control; administration; physical protection; recordkeeping; CCTV to supplement ACS; non-automated access control
9 Acoustic Protection Overview; Sound Group ratings; acoustic testing; construction guidance; sound transmission mitigations
10 PEDs with Recording Capabilities and Embedded Technologies Approved use; prohibitions; risk levels; risk mitigation
11 Telecommunications Systems Unclassified telephones and information systems; CCTV at entry points; wireless; environmental infrastructure; emergency notification; system access; cable control; Protected Distribution Systems
12 Management and Operations SCIF Repository; management; SOP; changes in security and accreditation; inspections; combinations; de-accreditation; visitors; maintenance; IDS/ACS documentation; emergency plan; co-use and joint use (N–P)
13 Second Party Integree and Second Party Liaison Spaces within SCIFs Added in v1.5.1
14 Forms and Plans Checklists, plans and co-use forms (see next section)

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · IC Tech Spec v1.5.1 (NCSC)

01.07

Tech Spec version history

All entries in the v1.5.1 change history list the approver as "PTSEWG."

Version Change-history date Notable changes
1.2 23 Apr 2012 Wall drawings replaced; "Type X gypsum" became "wallboard"; FIPS/AES encryption language; TEMPEST checklist edits; Compartmented Area checklist replaced; joint-use statements added to co-use form
1.3 26 Mar 2015 D/NCSC memo appended; prefabricated modular SCIF note; vent and duct guidance; high-security switch (HSS) requirement; IDS "zones" became "IDE sensor points"; integrated IDS and remote access language; "access/secure" became "arm/disarm"; inspection responsibility moved from "IC element head" to the AO or designee; Co-Use Request and MOA form appended
1.4 27 Jun 2017 (NCSC lists a 28 Sep 2017 posting) SAPF language added; egress device language; UL 2050 requirement (60 minutes) added; Chapter 10 (PEDs) revised; CNSSI 5002 sub-bullets; Chapter 12.L/M edits
1.5 13 Nov 2019 change entries; cover dated 13 Mar 2020 Compartmented Area Types defined; Pre-Construction Checklist added; SCIF door criteria expanded; Inspectable Materials Checklist reference; "CSA" changed to "AO" where appropriate; Ch. 12.G.8 TSCM language; Ch. 12.N/O/P Co-Use Agreement instructions; FFC and CUA forms updated
1.5.1 26 Jul 2021 New Chapter 13 (Second Party integree and liaison spaces); former Chapter 13 (Forms and Plans) renumbered as Chapter 14

Status as of September 2026. No v1.6 or v2.0 was found on dni.gov. The NCSC regulations page still lists v1.5.1 and the v1.5 checklist set, and a March 2026 practitioner presentation still cites v1.5.1 as current. The v1.5 and v1.5.1 change histories list no Chapter 7 (IDS) changes.

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · IC Tech Spec v1.5 · NCSC Security Governance and Regulations · SAME 2026, Concept to Clearance (practitioner)

01.08

Tech Spec forms and plans (Chapter 14)

The forms are where the rules become evidence. NCSC also posts the v1.5 forms as stand-alone files.

Form or plan What it is for When it is used
Pre-Construction Checklist (added v1.5) Gives the AO project information, points of contact and what is needed to set security requirements Planning, before design is final
Construction Security Plan (CSP) The SSM's project security plan; the template baseline "may not be reduced without coordination and approval" Approved by the AO before contract award
Fixed Facility Checklist (FFC) Documents physical, technical and procedural security in Sections A–I Pre-construction, final accreditation, and page changes
Compartmented Area Checklist Documents a CA inside a SCIF When a CA is established
TEMPEST Checklist Collects facts the CTTA needs to decide countermeasures Planning phase, for the CTTA's review
Shipboard, Submarine and Aircraft/UAV Checklists Platform-specific equivalents of the FFC Tech Spec Chapter 6 facilities
SCIF Co-Use or Joint-Use Request and MOA, Users Guide, Cancellation Establishes, explains and ends co-use Before a tenant uses the host SCIF
Inspectable Materials Checklist Material control, principally for overseas construction Procurement and construction

Handling. The Pre-Construction Checklist says it "is not intended to contain any classified information," but the AO should be consulted before sending it over unclassified channels. A completed FFC "may be CUI or Classified depending on contents" (UFC 4-010-05, 1-19.2). DoDM 5105.21 Vol. 2 requires a SCIF's full address and identity as a SCIF to be protected (now handled as CUI).

Sources SCIF Fixed Facility Checklist v1.5 · Construction Security Plan v1.5 · SCIF Pre-Construction Checklist v1.5 · SCIF TEMPEST Checklist v1.5 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2

01.09

Reported 2025–2026 changes to SCIF requirements

What is verified:

  • The publicly available IC Tech Spec is v1.5.1 (26 Jul 2021). No successor was found on dni.gov, archive.dni.gov or the NAVFAC DoD Lock Program library as of September 2026.
  • A CDSE Fixed Facility Checklist short guide dated April 2025 still refers to the ICD 705 Tech Spec.

What is reported but not publicly verifiable:

Claim Reported by
An ODNI memorandum rescinds authorization to re-accredit SCIFs under previous standards, and requires reviews of existing SCIFs and planned upgrades AECOM presentation at a SAME conference (March 2026)
A "new" or "updated" ICD 705 emphasizing TEMPEST and RF protection, with compliance plans and a multi-year implementation window JLL, MGAC, Holland & Knight, LVT, DAVIS Construction, JK Moving
"The big story in 2025 was not a brand-new public ICD-705 release" PSC Consultant (March 2026)
A later memorandum removed the plan-of-action requirement and its timeline, stating v1.5.1 remains the governing baseline and a revision is forthcoming Cushman & Wakefield (2026)
The FY2025 Intelligence Authorization Act directs ODNI to plan updated SCIF technical specifications PSC Consultant

Sources SAME 2026, Concept to Clearance (practitioner) · Cushman & Wakefield, ICD 705 POA&M rescission (industry) · PSC Consultant, ICD/ICS 705 in 2026 (practitioner) · Holland & Knight, Leasing SCIF Space (industry) · LVT, ICD 705 construction security (industry) · CDSE FFC short guide · JLL, New era of SCIF construction (industry) · MGAC, New SCIF requirements under ICD 705 (industry)

01.10

DoDM 5105.21: DoD's SCI security manual

Title: Sensitive Compartmented Information (SCI) Administrative Security Manual. UFC 4-010-05 (1-6.2): "DoDM 5105.21 (Volumes 1-3) are the primary documents associated with SCIFs for the DoD."

Volume Subject Date
Vol. 1 Information and Information Systems Security 19 Oct 2012, Change 2 effective 6 Oct 2020
Vol. 2 Physical Security, Visitor Control, and Technical Security 19 Oct 2012, Change 2 effective 2 Nov 2020
Vol. 3 Personnel Security, Industrial Security, and Special Activities 19 Oct 2012, Change 2 effective 14 Sep 2020

Who it applies to. Vol. 1 "Does not apply to the National Security Agency/Central Security Service (NSA/CSS), National Geospatial-Intelligence Agency (NGA), and the National Reconnaissance Office (NRO)." Those agencies run SCI security under their own IC-element authority.

DIA's role. The Director, DIA shall "Provide centralized physical security and TEMPEST accreditation for the DoD Components and DoD contractors except those under the security cognizance of NSA/CSS, NGA, and NRO" (Vol. 1). Vol. 2: "DAC is the sole accrediting authority for physical and technical (TEMPEST) security for permanent SCI facilities."

What Vol. 2 adds in practice:

  • Service CSAs, their designees, or DoD Component Senior Intelligence Officials "validate the need for a SCIF and … grant concept approval."
  • An SCI-indoctrinated SSM is designated by the component SSO for each project and develops the CSP.
  • The accreditation package: final FFC, IDS specification sheets, UL 2050 certificate, NIST 128-bit certificate for IDS, IDS test results, SAP co-utilization agreement, TSCM reports if applicable, and a catastrophic failure plan.
  • The SSO reports all changes affecting a SCIF's security posture to DAC within 24 hours.
  • Re-accreditation is required for perimeter changes, storage-mode changes, and changes from continuous operation.
  • Waivers are "normally granted for a period of up to 1 year or until such time as the waiver is no longer needed."

Sources DoDM 5105.21 Vol. 1 · DoDM 5105.21 Vol. 2 · DoDM 5105.21 Vol. 3 · UFC 4-010-05 (2023) · CDSE SCI101 Student Guide

01.11

DoDM 5205.07 (2025) and legacy SAP standards

Current: DoDM 5205.07, Special Access Program Security Manual, effective 17 January 2025, a single consolidated manual (OPR: OUSD(I&S); cleared for public release).

What it cancels. It "incorporates and cancels" Vol. 1 (General Procedures, 18 Jun 2015), Vol. 2 (Personnel Vetting, 24 Nov 2015) and Vol. 3 (Physical Security, 23 Apr 2015). It also incorporates the USD(I&S) memo "SAP Discussion in Accredited SCIFs" (21 Nov 2023). Vol. 4 (Marking) is still posted separately.

Where physical security lives now. Section 15, Physical Security Procedures, with subsections including SAP discussion, handling and processing in an accredited SCIF; risk management; preconstruction review and approval; construction procedures; co-use and co-accreditation; and TEMPEST requirements.

Who accredits. "The CA SAPCO, or their designee in writing, will appoint in writing an individual to serve as SAPF-AO." The SAPF-AO "is responsible for reviewing and approving or disapproving physical security preconstruction plans for, and physically inspecting and accrediting, reaccrediting, and de-accrediting, a SAPF."

How SAPFs use the Tech Spec. The cancelled Vol. 3 said SAPFs, T-SAPFs, SAPCAs, SAPWAs and SAPTSWAs "will conform to the equivalent" SCIF, T-SCIF, CA, SWA and TSWA criteria in the Tech Spec. DCSA's January 2026 SAP compliance checklist cites Tech Spec Chapter 7 paragraphs throughout for SAPF IDS.

Sources DoDM 5205.07 (2025) · DoDM 5205.07 Vol. 3 (cancelled; mirror) · DoDM 5205.07 Vol. 4 · DCSA SAP Compliance Checklist (Jan 2026) · UFC 4-010-05 (2023) · CDSE SA501 Student Guide

01.12

32 CFR Part 117 (NISPOM) and 32 CFR Part 2001

32 CFR Part 117, the NISPOM rule, governs cleared contractors' protection of collateral classified information. It replaced DoD 5220.22-M on 24 Feb 2021. 32 CFR Part 2001 is the ISOO implementing directive that sets storage and supplemental controls.

Topic Rule
Storage (§117.15(c)) GSA-approved security containers, vaults built to FED-STD 832, or an open storage area constructed per 32 CFR 2001.53, with controls per 2001.43(b)
Terminology Part 117 "codified requirements for open storage areas and replaced 'closed areas' as an entity" (DCSA Form 147 guide)
IDS approval (§117.15(d)(1)) "CSA approval is required before installing an IDS." The basis may be ICD 705 and IC standards, UL 2050, or CSA written standards. Installation by an alarm services company certified by a Nationally Recognized Testing Laboratory (NRTL)
TS supplemental controls (2001.43(b)(1)) Container: inspection every 2 hours, or IDS with 15-minute response, or SID plus an FF-L-2740 lock. Open storage with SID: IDS with 15-minute response. Without SID: 5-minute response
Secret (2001.43(b)(2)) Inspection every 4 hours, or IDS with 30-minute response (not needed for GSA containers or FED-STD 832 vaults)
Response performance (§117.15(d)(3)) "The requirement for response is 80 percent within the time limits"
Security-in-depth (§117.3) "A determination made by the CSA that a contractor's security program consists of layered and complementary security controls sufficient to deter and detect unauthorized entry and movement within the facility"
SCI (§117.23) "National intelligence is under the jurisdiction and control of the DNI, who establishes security policy." Contractors follow IC directives for SCI

Sources 32 CFR Part 117 · 32 CFR 117.3 · 32 CFR 117.15 · 32 CFR 117.23 · 32 CFR 2001.43 · 32 CFR 2001.53 · DCSA Form 147 Guide

01.13

DCSA's role, and what it does not do

The Defense Counterintelligence and Security Agency (DCSA) is central to cleared industry, which is why project teams often assume it accredits SCIFs. It does not.

DCSA does DCSA does not
Administer the National Industrial Security Program (NISP) for DoD as the cognizant security office for collateral classified contracts Accredit SCIFs. Under DoDM 5105.21, DIA provides "centralized physical security and TEMPEST accreditation for the DoD Components and DoD contractors," except those under NSA/CSS, NGA or NRO cognizance
Approve contractor open storage areas and their IDS before installation (DCSA Form 147) Accredit SAPFs. That is the SAPF-AO appointed under DoDM 5205.07
Administer the NISP "for collateral classified requirements within the scope of contracts also involving SAPs" (DoDM 5205.07 §2.3) Replace the SCI AO's decision on co-use, waivers or re-accreditation
Oversee compliance with assigned industrial security requirements of contracts requiring SAP access, until the transfer noted below
Run the Center for Development of Security Excellence (CDSE), which publishes the SCI and SAP physical security student guides and short courses

Scheduled change. DoDM 5205.07 (2025) §2.3 states that DCSA's SAP industrial-security compliance oversight responsibility "No later than July 31, 2029 … will transfer to the CA responsible for the program."

Sources DoDM 5205.07 (2025) · DoDM 5105.21 Vol. 1 · DCSA NISP Oversight · DCSA Form 147 Guide · CDSE SA501 Student Guide

01.14

Cognizant Security Authorities for SCI at a glance

ICS 705-1 says CSAs "oversee construction and accreditation programs and ensure timely data input to the IC SCIF repository." Who fills that role depends on who sponsors the SCI.

Organization SCI accreditation role in public sources
DIA Accredits SCIFs (physical and TEMPEST) for DoD Components and DoD contractors not under NSA, NGA or NRO cognizance. The Director, DIA appoints CSAs, including one for OSD, the Joint Staff and the Combatant Commands (DoDM 5105.21 Vols. 1–2)
NSA/CSS, NGA, NRO Excluded from DoDM 5105.21. As IC elements, their heads accredit, or delegate AO authority for, SCIFs under their cognizance per ICD 705
Military Departments Department heads, through their Heads of Intelligence Community Elements (HICEs), appoint Service CSAs, who validate SCIF need, grant concept approval, and approve TSWAs and T-SCIFs
Department of State The Division Chief, DS/IS/SSO "is the Cognizant Security Authority (CSA) for SCI matters" (12 FAM 712.2(a)). The Department AO accredits State SCIFs. Chief of Mission SCIFs must comply with 12 FAH-6 H-626, other OSPB standards and ICD 705 (12 FAM 715.4-2)
Other IC elements Accredit under ICD 705 through their own AOs; not detailed in this knowledge base

Co-use coordination in DoD. DoD Component CSAs coordinate Co-Use Agreements with other DoD agencies, with a courtesy copy to DIA's accreditation office, which coordinates agreements involving NRO, NGA and NSA (DoDM 5105.21 Vol. 2).

Sources ICS 705-1 · DoDM 5105.21 Vol. 1 · DoDM 5105.21 Vol. 2 · 12 FAM 710 · ICD 705 · UFC 4-010-05 (2023)

01.15

UFC 4-010-05: DoD design criteria for SCIFs and SAPFs

Title: Sensitive Compartmented Information Facilities (SCIF) / Special Access Program Facilities (SAPF) Planning, Design, and Construction. Dated 26 May 2023, superseding the 2013 edition with Change 1.

What it contributes:

Paragraph Content
1-6.2 Identifies DoDM 5105.21 as the primary DoD SCIF documents and DoDM 5205.07 for SAPFs
1-12 "Security in Depth (SID) is desired for all SCIF or SAPF and required for locations outside the United States, its possessions or territories"
1-14 SSM "Responsible for the security aspects of project planning, design and construction"
1-15 "Do not award a construction contract without an approved CSP"
1-16.3 TEMPEST vulnerabilities associated with a physical location are classified at a minimum of CONFIDENTIAL
1-17 Design by U.S. companies using U.S. citizens or U.S. persons
1-18.1 "IDS installation and testing must be performed by U.S. companies using U.S. citizens"
1-19.1–1-19.4 Accreditation documents: FFC, TEMPEST addendum, Pre-Construction Checklist; A-E provides the SSM project information
2-2 Concept approval and proof of sponsorship
3-4 Architectural, mechanical, electrical and security design details
4-7 Photographic construction surveillance record

Relationship to the Tech Spec. UFC 4-010-05 implements, and does not override, the Tech Spec. UFC 3-4.1 requires Tech Spec details to be made to comply with the building code, and 1-9 invokes UFC 1-200-01, which brings in NFPA 101.

Sources UFC 4-010-05 (NAVFAC mirror) · UFC 4-010-05 (WBDG) · IC Tech Spec v1.5.1

01.16

Reciprocity and waivers

Reciprocity is the principle that a SCIF accredited by one IC element, with no waivers, is accepted as accredited by all IC elements (ICS 705-2). It is why ICD 705 insists on uniform standards: a compliant SCIF is an asset any agency can use through a Co-Use Agreement.

Waivers are the formal exception. ICS 705-1 limits them to "exceptional circumstances (i.e., only when the standards cannot be met or mitigated), or when there is a documented risk-based mission need to exceed the standards."

Waiver rule Source
Granted by the IC element head, or a single named senior official who may not be the AO ICD 705
Reported to D/NCSC no later than 30 days after the decision, via the IC SCIF Repository ICD 705; ICS 705-1
Removes the SCIF from mandatory reciprocal use ICS 705-1
Required even to exceed a standard based on risk Tech Spec 2.A
Listed in the letter of accreditation with the standard not met or exceeded and when it will be met ICS 705-2 §D.1.a
DoD waivers normally last up to 1 year or until no longer needed DoDM 5105.21 Vol. 2
A co-use tenant must accept the host's current accreditation and any waivers (DoD) DoDM 5105.21 Vol. 2
A waived SCIF is re-accredited under current standards ICS 705-2

Package contents (ICS 705-1): the standard affected; mitigations considered; justification; residual risk assessment; procedures to reduce risk; timeline for compliance; and a statement accepting loss of mandatory reciprocal use.

See: Accreditation Lifecycle for how waivers fit into the package.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2