Title and date only (per public listings); U//FOUO
23 Apr 2015
DoDM 5205.07 Vol 3, SAP physical security
Cancelled 17 Jan 2025
22 Dec 2016
ICS 705-2
Current IC standard
2012–2017
Tech Spec v1.2, v1.3, v1.4 (see the ICD 705 section below)
Superseded
13 Mar 2020
Tech Spec v1.5
Superseded by v1.5.1
26 Jul 2021
Tech Spec v1.5.1
Current published version
30 Mar 2023
IEEE 299-2006 listed Inactive-Reserved
Revision in development
26 May 2023
UFC 4-010-05
Current DoD design criteria
17 Jan 2025
DoDM 5205.07 consolidated SAP Security Manual
Current; cancels Vols 1–3
13 Feb 2025
IEEE P299 revision PAR approved
In development
7 Apr 2025
UL 2050 Edition 6
Current IDS standard edition
Reading the table:
Policy and facility countermeasures (CNSSP 300, CNSSI 7000) and installation guidance (CNSSAM TEMPEST/1-13) are controlled documents. The public construction documents (ICD 705, ICS 705-1, the Tech Spec) defer TEMPEST decisions to the CTTA instead of restating them.
The 2010 shift from DCID 6/9 to ICD 705 changed the IC's document structure. It didn't make TEMPEST requirements public.
The story is told in NSA's declassified article TEMPEST: A Signal Problem.
What happened. During WWII, the Bell Telephone 131-B2 mixer was in use for encrypted communications. A Bell engineer "noticed, quite by accident, that each time the machine stepped, a spike appeared on an oscilloscope." Those spikes could be read as the plain text being encrypted. The machine was leaking what it was supposed to protect.
The proof. Bell engineers set up across the street from a wartime cryptocenter, roughly 80 feet away, and "produced about 75% of the plain text" from the leaking signals.
The response. Bell Labs identified three families of fixes that still frame the field:
The Signal Corps also chose to control a zone around the cryptocenter. That's an early form of what is now called inspectable space. Distance and control of space later joined shielding and filtering as standard countermeasures.
The name. NSA's history records: "This problem of compromising radiation we have given the covername TEMPEST." TEMPEST is a covername, not an acronym. The expansions found on some vendor websites were invented after the fact.
What builders should take from it. The first compromise wasn't a spy planting a bug. It was ordinary equipment doing its job, with signals escaping through the air and along wires. Every filter, waveguide and RED/BLACK rule in a modern SCIF traces back to that discovery.
1951: the problem comes back. In 1951 the CIA rediscovered the effect and read "plain text about a quarter mile down the signal line." That detail matters for builders. The leak traveled along a wire, far past any wall. Conducted emanations became as important as radiated ones, which is why filters and fortuitous conductors matter today.
Control zones and their limits. Early responses defined zones of control around equipment. NSA's own history later described one such zone as "quite arbitrary." Fixed distances were a blunt instrument. Modern practice replaced them with a CTTA's facility-specific assessment of threat, equipment and inspectable space.
Standards take shape:
Date
Development
Significance
1956
NRL lower-voltage, lower-radiation mixer
Fixing the equipment, not only the room
1958
NAG-1 radiation standards
Early formal limits tied to a limit of control
1964
NSA 65-6 shielded-enclosure specification
Start of the NSA enclosure spec lineage
Dec 1964
DoD Directive 5200.19 (implemented by NSA June 1966)
Department-wide policy
1 Feb 1982
NACSIM 5000, TEMPEST Fundamentals
Formal RED/BLACK definitions
NACSIM 5000's contribution. It separated circuits handling "national security plain language information in electric signal form (RED)" from those handling "encrypted or non-national security information (BLACK)." It used the term "Controlled Space," a forerunner of inspectable space. It also explained why grounding matters: "appreciable impedances can and do exist between various points of the return paths." That is the physics behind today's rule that RED/BLACK grounding is engineered, not improvised.
The Moscow embassy. NSA's article notes that in 1964 "more than 40 microphones were discovered in the U.S. embassy in Moscow." That's a separate threat (audio bugging), but it shows why technical security grew into a discipline alongside TEMPEST.
For four decades TEMPEST was a government secret. In 1985 it became a public research topic.
Wim van Eck, 1985. "Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?" appeared in Computers & Security 4(4):269–286. Van Eck showed that the image on a video display could be reconstructed remotely "at a range of hundreds of metres, using just $15 worth of equipment plus a television set" (Wikipedia). The technique is still called van Eck phreaking.
Why it mattered.
It proved that compromising emanations weren't limited to cipher machines and teletypes. Ordinary office computers leaked too.
It moved the threat from nation-state labs to anyone with modest skill and cheap parts.
It explained to the public why government facilities cared about screens, cabling and room construction.
Later public work.
Period
Work
Takeaway
1985
van Eck, video display units
CRT emanations can be reconstructed at distance
2003–2004
Markus Kuhn, University of Cambridge technical report TR-577 and flat-panel research
Extended public research to flat-panel displays
1999–2000
FOIA requests and appeals publicized by Cryptome
Redacted NSA and NSTISS documents released
Equipment standards, briefly. NSTISSAM TEMPEST/1-92 (15 Dec 1992), Compromising Emanations Laboratory Test Requirements, Electromagnetics, set laboratory test levels for equipment. It superseded 1-91 (21 Mar 1991). Wikipedia maps its Levels I, II and III to NATO SDIP-27 Levels A, B and C. These are equipment evaluation standards. They explain why a CTTA asks what equipment will process classified information: evaluated equipment can reduce the facility countermeasures needed.
What it means for designers. Public research is why TEMPEST can't be treated as exotic. The threat is well documented and the tools are inexpensive. What stays controlled is the specific countermeasure criteria, which is why they come from your CTTA and not from the internet.
Many RF-shielding datasheets still cite "NSA 65-6" or "NSA 94-106." Here's where those names come from.
Document
Date
What the public record shows
NSA 65-6
30 Oct 1964
RF shielded enclosures for communications equipment, per the Cryptome timeline description. The formal title isn't confirmed. Vendors still cite it.
NSA 73-2A
15 Nov 1972
A later enclosure specification. The title isn't confirmed.
NSA 89-02
Undated ("TBD" / "[No date]")
"National Security Agency Specification for Shielded Enclosures." The FOIA copy is marked "Superceding Specification NSA No. 65-6, 30 October 1964," and "Specification NSA No. 73-2A, 15 November 1972." It appears to have been a draft.
NSA 94-106
24 Oct 1994
"National Security Agency Specification for Shielded Enclosures." The cover reads "SUPERSEDING SPECIFICATION NSA NO. 65-6." Marked FOUO; released 30 Dec 2000 on FOIA appeal.
IEEE 299-2006
Published 28 Feb 2007
The consensus test method now commonly cited for shielding effectiveness. Listed Inactive-Reserved in 2023; revision P299 in development.
The FOIA context. In 1999–2000, requests and appeals publicized by Cryptome produced redacted releases of several NSA and NSTISS documents, including 94-106. The mirrored copies are useful for understanding what kinds of things an enclosure specification addressed: structure, doors, vents, filters, grounding, testing and warranty. The public mirror doesn't include 94-106's Figure 1 performance values.
How vendors use the names today. ETS-Lindgren's DKE door datasheet lists testing per "MIL-STD-285, NSA 65-6/NSA 94-106, ITSG-02/IEEE 299 or EN 50147-1." Test labs still offer 94-106-style testing. A citation on a datasheet tells you what method a product was tested to. It doesn't tell you what your project requires.
Applicable Documents (including MIL-STD-220A for filter testing)
3
Requirements: 3.1 Performance (referencing Figure 1); 3.7 Enclosure Structure; 3.8 doors, HVAC, 3.8.3 power and line isolation, 3.8.4 grounding
4
Quality Assurance, including 4.3 Acceptance Tests
5
Delivery
6
Notes
Test frequencies listed (historical):
Field type
Frequencies
Magnetic
1 kHz, 10 kHz, 100 kHz, 1 MHz
Electric
1 kHz, 10 kHz, 100 kHz, 1 MHz, 10 MHz
Plane wave
100 MHz, 400 MHz, 1 GHz, 10 GHz
Topics it addressed, and the modern practice each one foreshadows:
94-106 topic (historical wording)
Where the idea lives today
"Isolation devices shall be provided for each line penetrating the shielded enclosure"
Power and signal filters at the penetration panel
Filters tested per MIL-STD-220A, with voltage-drop and temperature-rise checks
Filter submittals cite MIL-STD-220
Bolted seams "bolted from the inside only"
Modular panel assembly details
"Door hinges shall support the door's weight without sagging… positive closure"
RF door adjustment and maintenance
"noncorrosive material"; avoid dissimilar metals
Galvanic compatibility of gaskets and finger stock
"A single ground lug connected to the shield surface"
Single-point shield grounding
Tests at doors, ducts, filters and joints
Whole-room testing after all penetrations
Warranty to "meet and maintain the appropriate attenuation requirements for not less than five years"
Maintenance and retest planning
The lesson. Almost every item that fails a shield test today (filters, seams, doors, vents, grounding) was already a named requirement in 1994. The technology changed; the weak points didn't.
Three families of national TEMPEST documents run in parallel: policy, facility countermeasures and installation guidance. A fourth family covers equipment testing.
Family
Historical documents
Current successor (title and role only)
Policy
NTISSP 300 (1988)
CNSSP 300, National Policy on Control of Compromising Emanations (Apr 2004)
Facility countermeasures
NTISSI 7000 (17 Oct 1988) → NSTISSI 7000, TEMPEST Countermeasures for Facilities (29 Nov 1993)
CNSSI 7000 (May 2004)
RED/BLACK installation
NACSIM 5000 concepts (1982) → NACSIM 5203 (30 Jun 1982) → NSTISSAM TEMPEST/2-95, RED/BLACK Installation Guidance (12 Dec 1995)
CNSSAM TEMPEST/1-13, RED/BLACK Installation Guidance (17 Jan 2014; U//FOUO). Its succession to 2-95 is inferred from the shared title.
Equipment lab testing
NSTISSAM TEMPEST/1-91 (21 Mar 1991) → 1-92 (15 Dec 1992)
CTTA primacy: "There should be no commitment of funds without CTTA concurrence."
Dedicated RED and BLACK wireways and incompatible patch connectors
Optical fiber that doesn't "conduct or radiate radio frequency interference," but with "no metallic stiffeners or metallic sheath"
Filters and isolators "when separation requirements cannot be met"
Fortuitous conductors, and the warning that "a long slender ground wire is not an effective RF ground"
Facility countermeasure process (historical NSTISSI 7000). The CTTA conducts or validates a review and determines the inspectable space. Location, information volume and sensitivity, physical controls, equipment TEMPEST profiles and the threat environment drive the countermeasures. That risk-based model is still how the IC Tech Spec works: countermeasures come "when recommended by the CTTA."
Before 2010. IC SCIF physical and technical security lived in DCID 6/9 (with its Manual and Annexes), supplemented by Intelligence Community Policy Memoranda. The SAP world used the parallel JAFAN 6/9 manual, now a legacy standard.
26 May 2010. DNI Dennis C. Blair signed ICD 705, Sensitive Compartmented Information Facilities. It rescinded DCID 6/9 and ICPMs 2005-700-1, 2006-700-7 and 2007-700-2. It set a layered structure that remains in place:
Tier
Document
Date
Directive
ICD 705
26 May 2010
Standard (physical and technical)
ICS 705-1
17 Sep 2010
Standard (accreditation and reciprocity)
ICS 705-2
22 Dec 2016
Technical specification
IC Tech Spec for ICD/ICS 705
v1.5.1, 26 Jul 2021
How the Tech Spec evolved (from its change history):
Modular SCIF note; vent and duct guidance; high-security switch requirement
1.4
27 Jun 2017
SAPF language added; UL 2050 (60-minute) response language added to Chapter 7
1.5
13 Mar 2020
Pre-Construction Checklist; door criteria expanded; "CSA" changed to "AO" where appropriate
1.5.1
26 Jul 2021
New Chapter 13 (Second Party Integree/Liaison spaces); forms moved to Chapter 14
TEMPEST in the ICD 705 era. The public documents don't restate national TEMPEST criteria. They assign the decision to the CTTA (Tech Spec 3.A.3) and name the triggers: RF protection "at the direction of the CTTA" (3.C.4), and dielectric breaks or grounding "when recommended by the CTTA" (3.G.2). The TEMPEST Checklist is a standard Tech Spec form.
Parallel changes:
SAPFs: DoDM 5205.07 Vol 3 (23 Apr 2015) pointed SAPF construction to the IC Tech Spec. The consolidated DoDM 5205.07 (17 Jan 2025) cancelled Vols 1–3.
Grandfathering. ICS 705-1 lets SCIFs accredited before ICD 705 continue under the standards in effect at their most recent accreditation. On re-accreditation they must meet current IDS standards unless waived.
History isn't trivia on a SCIF project. It shows up on datasheets, legacy drawings, old facilities and the internet.
1. Legacy citations are everywhere. Datasheets cite "NSA 65-6," "NSA 94-106" and "MIL-STD-285." Old specifications reference DCID 6/9 or JAFAN 6/9. When you see an old citation, ask what the current contract, CTTA recommendation and AO require. A datasheet's test method isn't the project's acceptance criterion.
2. FOIA documents teach concepts, not requirements. 2-95 and 94-106 are publicly mirrored, well written and superseded. Use them to understand why filters, waveguides and single-point grounds exist. Never lift a number, distance or table from them into a design.
Use historical documents to…
Don't use them to…
Understand RED/BLACK, inspectable space and fortuitous conductors
Set separation distances
Recognize legacy citations on submittals
Set attenuation or test levels
Explain to trades why details matter
Claim a room is "TEMPEST compliant"
3. Existing SCIFs may predate current rules. Because of ICS 705-1 grandfathering, a renovation can land in a facility built to older standards. On re-accreditation, current IDS standards apply unless waived. Ask the AO before assuming old conditions carry forward.
4. The threat lessons are permanent. Signals travel along wires (1951), ordinary equipment leaks (1985), and fixed zones proved "quite arbitrary." That's why the modern system is risk-based and CTTA-driven, and why builders shouldn't substitute a rule of thumb for the TCR.
5. Requirements are still moving. The Tech Spec went through five versions in under a decade. UL 2050, DoDM 5205.07 and IEEE 299 all changed status in 2023–2025.
Documents marked Historical are FOIA-released or superseded. Read them for background only. Controlled documents (CNSSP 300, CNSSI 7000, CNSSAM TEMPEST/1-13) aren't listed because they aren't public. Get applicable requirements through your AO or CTTA.