Module 16 · 11 sections

History of TEMPEST & Shielding Specs

From the WWII Bell 131-B2 discovery to NSA shielding specs, the RED/BLACK document lineage, ICD 705 and today's standards, with historical labels.

On this page
  1. 16.01Timeline: discovery to the FOIA releases (WWII–2000)
  2. 16.02Timeline: the CNSS era to today (2004–2025)
  3. 16.03The discovery: Bell 131-B2 and the covername TEMPEST
  4. 16.04Rediscovery and the first control standards (1951–1982)
  5. 16.05Public research: van Eck and after
  6. 16.06The NSA shielded-enclosure specification lineage
  7. 16.07What NSA 94-106 covered
  8. 16.08The RED/BLACK and facility countermeasure guidance lineage
  9. 16.09The IC's move from DCID 6/9 to ICD 705
  10. 16.10Why history matters to today's designers
  11. 16.11Public reading list
16.01

Timeline: discovery to the FOIA releases (WWII–2000)

Everything in this table is historical. Superseded documents are listed so readers can recognize old citations, not so anyone designs to them.

Date Event or document Notes
WWII Bell Telephone 131-B2 mixer found to leak plain text Oscilloscope spikes matched each step of the machine (NSA, TEMPEST: A Signal Problem)
1951 CIA rediscovers the problem Plain text read "about a quarter mile down the signal line"
1954 MIL-STD-285 Attenuation measurement for shielding enclosures (public TEMPEST timelines)
1956 Naval Research Laboratory builds a lower-radiation mixer Wikipedia
1958 NAG-1 radiation standards Early control-distance standard (Wikipedia)
30 Oct 1964 NSA 65-6 NSA shielded-enclosure specification (formal title not confirmed)
Dec 1964 DoD Directive 5200.19 Signed by McNamara; NSA implementation June 1966 (Wikipedia)
1964 More than 40 microphones found in the U.S. embassy in Moscow Context for the era's technical-security concern (NSA article)
15 Nov 1972 NSA 73-2A Shielded-enclosure specification (title not confirmed)
1 Feb 1982 NACSIM 5000, TEMPEST Fundamentals Defines RED and BLACK; uses "Controlled Space"
30 Jun 1982 NACSIM 5203 RED/BLACK installation predecessor to 2-95
1985 Wim van Eck paper on video display eavesdropping Brought TEMPEST-style attacks into public research
17 Oct 1988 NTISSI 7000 Facility countermeasures; superseded 1993
Undated NSA 89-02 Draft marked as superseding 65-6 and 73-2A
15 Dec 1992 NSTISSAM TEMPEST/1-92 Compromising Emanations Laboratory Test Requirements, Electromagnetics
29 Nov 1993 NSTISSI 7000 TEMPEST Countermeasures for Facilities
24 Oct 1994 NSA 94-106 National Security Agency Specification for Shielded Enclosures
12 Dec 1995 NSTISSAM TEMPEST/2-95 RED/BLACK Installation Guidance
21 Oct 1999 Partial FOIA release of 1-92 Redacted
30 Dec 2000 NSA 94-106 released on FOIA appeal NACSIM 5000 redacted release, Dec 2000

Sources NSA, TEMPEST: A Signal Problem · Wikipedia: Tempest (codename) · NSA 94-106 (historical mirror)

16.02

Timeline: the CNSS era to today (2004–2025)

Date Event or document Status for a designer today
Apr 2004 CNSSP 300, National Policy on Control of Compromising Emanations National policy; not public
May 2004 CNSSI 7000, TEMPEST Countermeasures for Facilities Successor to NSTISSI 7000; not public
2007 IEEE 299-2006 published (28 Feb 2007) Shielding effectiveness test method
26 May 2010 ICD 705 signed; rescinds DCID 6/9 Current IC policy
17 Sep 2010 ICS 705-1 Current IC standard
17 Jan 2014 CNSSAM TEMPEST/1-13, RED/BLACK Installation Guidance Title and date only (per public listings); U//FOUO
23 Apr 2015 DoDM 5205.07 Vol 3, SAP physical security Cancelled 17 Jan 2025
22 Dec 2016 ICS 705-2 Current IC standard
2012–2017 Tech Spec v1.2, v1.3, v1.4 (see the ICD 705 section below) Superseded
13 Mar 2020 Tech Spec v1.5 Superseded by v1.5.1
26 Jul 2021 Tech Spec v1.5.1 Current published version
30 Mar 2023 IEEE 299-2006 listed Inactive-Reserved Revision in development
26 May 2023 UFC 4-010-05 Current DoD design criteria
17 Jan 2025 DoDM 5205.07 consolidated SAP Security Manual Current; cancels Vols 1–3
13 Feb 2025 IEEE P299 revision PAR approved In development
7 Apr 2025 UL 2050 Edition 6 Current IDS standard edition

Reading the table:

  • Policy and facility countermeasures (CNSSP 300, CNSSI 7000) and installation guidance (CNSSAM TEMPEST/1-13) are controlled documents. The public construction documents (ICD 705, ICS 705-1, the Tech Spec) defer TEMPEST decisions to the CTTA instead of restating them.
  • The 2010 shift from DCID 6/9 to ICD 705 changed the IC's document structure. It didn't make TEMPEST requirements public.

Sources DoDI 8523.01 · Wikipedia: Tempest (codename) · ICD 705 · IC Tech Spec v1.5.1 (NAVFAC mirror) · IEEE 299-2006 · DoDM 5205.07 (2025) · UL 2050 Ed. 6

16.03

The discovery: Bell 131-B2 and the covername TEMPEST

The story is told in NSA's declassified article TEMPEST: A Signal Problem.

What happened. During WWII, the Bell Telephone 131-B2 mixer was in use for encrypted communications. A Bell engineer "noticed, quite by accident, that each time the machine stepped, a spike appeared on an oscilloscope." Those spikes could be read as the plain text being encrypted. The machine was leaking what it was supposed to protect.

The proof. Bell engineers set up across the street from a wartime cryptocenter, roughly 80 feet away, and "produced about 75% of the plain text" from the leaking signals.

The response. Bell Labs identified three families of fixes that still frame the field:

Countermeasure Addresses Modern construction equivalent
Shielding Radiated and magnetic fields Shielded rooms, foil-backed drywall, shielded racks
Filtering Signals conducted along wires Power and signal filters at the boundary
Masking Hiding the signal among other signals Operational and equipment measures

The Signal Corps also chose to control a zone around the cryptocenter. That's an early form of what is now called inspectable space. Distance and control of space later joined shielding and filtering as standard countermeasures.

The name. NSA's history records: "This problem of compromising radiation we have given the covername TEMPEST." TEMPEST is a covername, not an acronym. The expansions found on some vendor websites were invented after the fact.

What builders should take from it. The first compromise wasn't a spy planting a bug. It was ordinary equipment doing its job, with signals escaping through the air and along wires. Every filter, waveguide and RED/BLACK rule in a modern SCIF traces back to that discovery.

Sources NSA, TEMPEST: A Signal Problem · Wikipedia: Tempest (codename)

16.04

Rediscovery and the first control standards (1951–1982)

1951: the problem comes back. In 1951 the CIA rediscovered the effect and read "plain text about a quarter mile down the signal line." That detail matters for builders. The leak traveled along a wire, far past any wall. Conducted emanations became as important as radiated ones, which is why filters and fortuitous conductors matter today.

Control zones and their limits. Early responses defined zones of control around equipment. NSA's own history later described one such zone as "quite arbitrary." Fixed distances were a blunt instrument. Modern practice replaced them with a CTTA's facility-specific assessment of threat, equipment and inspectable space.

Standards take shape:

Date Development Significance
1956 NRL lower-voltage, lower-radiation mixer Fixing the equipment, not only the room
1958 NAG-1 radiation standards Early formal limits tied to a limit of control
1964 NSA 65-6 shielded-enclosure specification Start of the NSA enclosure spec lineage
Dec 1964 DoD Directive 5200.19 (implemented by NSA June 1966) Department-wide policy
1 Feb 1982 NACSIM 5000, TEMPEST Fundamentals Formal RED/BLACK definitions

NACSIM 5000's contribution. It separated circuits handling "national security plain language information in electric signal form (RED)" from those handling "encrypted or non-national security information (BLACK)." It used the term "Controlled Space," a forerunner of inspectable space. It also explained why grounding matters: "appreciable impedances can and do exist between various points of the return paths." That is the physics behind today's rule that RED/BLACK grounding is engineered, not improvised.

The Moscow embassy. NSA's article notes that in 1964 "more than 40 microphones were discovered in the U.S. embassy in Moscow." That's a separate threat (audio bugging), but it shows why technical security grew into a discipline alongside TEMPEST.

Sources NSA, TEMPEST: A Signal Problem · NACSIM 5000 (historical mirror) · Wikipedia: Tempest (codename)

16.05

Public research: van Eck and after

For four decades TEMPEST was a government secret. In 1985 it became a public research topic.

Wim van Eck, 1985. "Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?" appeared in Computers & Security 4(4):269–286. Van Eck showed that the image on a video display could be reconstructed remotely "at a range of hundreds of metres, using just $15 worth of equipment plus a television set" (Wikipedia). The technique is still called van Eck phreaking.

Why it mattered.

  • It proved that compromising emanations weren't limited to cipher machines and teletypes. Ordinary office computers leaked too.
  • It moved the threat from nation-state labs to anyone with modest skill and cheap parts.
  • It explained to the public why government facilities cared about screens, cabling and room construction.

Later public work.

Period Work Takeaway
1985 van Eck, video display units CRT emanations can be reconstructed at distance
2003–2004 Markus Kuhn, University of Cambridge technical report TR-577 and flat-panel research Extended public research to flat-panel displays
1999–2000 FOIA requests and appeals publicized by Cryptome Redacted NSA and NSTISS documents released

Equipment standards, briefly. NSTISSAM TEMPEST/1-92 (15 Dec 1992), Compromising Emanations Laboratory Test Requirements, Electromagnetics, set laboratory test levels for equipment. It superseded 1-91 (21 Mar 1991). Wikipedia maps its Levels I, II and III to NATO SDIP-27 Levels A, B and C. These are equipment evaluation standards. They explain why a CTTA asks what equipment will process classified information: evaluated equipment can reduce the facility countermeasures needed.

What it means for designers. Public research is why TEMPEST can't be treated as exotic. The threat is well documented and the tools are inexpensive. What stays controlled is the specific countermeasure criteria, which is why they come from your CTTA and not from the internet.

Sources Wikipedia: Van Eck phreaking · Wikipedia: Tempest (codename) · NSTISSAM TEMPEST/1-92 (historical mirror)

16.06

The NSA shielded-enclosure specification lineage

Many RF-shielding datasheets still cite "NSA 65-6" or "NSA 94-106." Here's where those names come from.

Document Date What the public record shows
NSA 65-6 30 Oct 1964 RF shielded enclosures for communications equipment, per the Cryptome timeline description. The formal title isn't confirmed. Vendors still cite it.
NSA 73-2A 15 Nov 1972 A later enclosure specification. The title isn't confirmed.
NSA 89-02 Undated ("TBD" / "[No date]") "National Security Agency Specification for Shielded Enclosures." The FOIA copy is marked "Superceding Specification NSA No. 65-6, 30 October 1964," and "Specification NSA No. 73-2A, 15 November 1972." It appears to have been a draft.
NSA 94-106 24 Oct 1994 "National Security Agency Specification for Shielded Enclosures." The cover reads "SUPERSEDING SPECIFICATION NSA NO. 65-6." Marked FOUO; released 30 Dec 2000 on FOIA appeal.
IEEE 299-2006 Published 28 Feb 2007 The consensus test method now commonly cited for shielding effectiveness. Listed Inactive-Reserved in 2023; revision P299 in development.

The FOIA context. In 1999–2000, requests and appeals publicized by Cryptome produced redacted releases of several NSA and NSTISS documents, including 94-106. The mirrored copies are useful for understanding what kinds of things an enclosure specification addressed: structure, doors, vents, filters, grounding, testing and warranty. The public mirror doesn't include 94-106's Figure 1 performance values.

How vendors use the names today. ETS-Lindgren's DKE door datasheet lists testing per "MIL-STD-285, NSA 65-6/NSA 94-106, ITSG-02/IEEE 299 or EN 50147-1." Test labs still offer 94-106-style testing. A citation on a datasheet tells you what method a product was tested to. It doesn't tell you what your project requires.

See: RF Shielding, Penetrations & Installer Methods for current testing practice.

Sources NSA 94-106 (historical mirror) · Wikipedia: Tempest (codename) · IEEE 299-2006 · ETS-Lindgren DKE door datasheet · Keystone Compliance: NSA 94-106 testing

16.07

What NSA 94-106 covered

Document structure (per the public mirror):

Section Subject
1 Scope
2 Applicable Documents (including MIL-STD-220A for filter testing)
3 Requirements: 3.1 Performance (referencing Figure 1); 3.7 Enclosure Structure; 3.8 doors, HVAC, 3.8.3 power and line isolation, 3.8.4 grounding
4 Quality Assurance, including 4.3 Acceptance Tests
5 Delivery
6 Notes

Test frequencies listed (historical):

Field type Frequencies
Magnetic 1 kHz, 10 kHz, 100 kHz, 1 MHz
Electric 1 kHz, 10 kHz, 100 kHz, 1 MHz, 10 MHz
Plane wave 100 MHz, 400 MHz, 1 GHz, 10 GHz

Topics it addressed, and the modern practice each one foreshadows:

94-106 topic (historical wording) Where the idea lives today
"Isolation devices shall be provided for each line penetrating the shielded enclosure" Power and signal filters at the penetration panel
Filters tested per MIL-STD-220A, with voltage-drop and temperature-rise checks Filter submittals cite MIL-STD-220
Bolted seams "bolted from the inside only" Modular panel assembly details
"Door hinges shall support the door's weight without sagging… positive closure" RF door adjustment and maintenance
"noncorrosive material"; avoid dissimilar metals Galvanic compatibility of gaskets and finger stock
"A single ground lug connected to the shield surface" Single-point shield grounding
Tests at doors, ducts, filters and joints Whole-room testing after all penetrations
Warranty to "meet and maintain the appropriate attenuation requirements for not less than five years" Maintenance and retest planning

The lesson. Almost every item that fails a shield test today (filters, seams, doors, vents, grounding) was already a named requirement in 1994. The technology changed; the weak points didn't.

See: RF Shielding, Penetrations & Installer Methods.

Sources NSA 94-106 (historical mirror) · Wikipedia: Tempest (codename)

16.08

The RED/BLACK and facility countermeasure guidance lineage

Three families of national TEMPEST documents run in parallel: policy, facility countermeasures and installation guidance. A fourth family covers equipment testing.

Family Historical documents Current successor (title and role only)
Policy NTISSP 300 (1988) CNSSP 300, National Policy on Control of Compromising Emanations (Apr 2004)
Facility countermeasures NTISSI 7000 (17 Oct 1988) → NSTISSI 7000, TEMPEST Countermeasures for Facilities (29 Nov 1993) CNSSI 7000 (May 2004)
RED/BLACK installation NACSIM 5000 concepts (1982) → NACSIM 5203 (30 Jun 1982) → NSTISSAM TEMPEST/2-95, RED/BLACK Installation Guidance (12 Dec 1995) CNSSAM TEMPEST/1-13, RED/BLACK Installation Guidance (17 Jan 2014; U//FOUO). Its succession to 2-95 is inferred from the shared title.
Equipment lab testing NSTISSAM TEMPEST/1-91 (21 Mar 1991) → 1-92 (15 Dec 1992) Controlled; not reproduced

What 2-95 contained (structure only). Sections: 1 Introduction; 2 Definitions; 3 RED/BLACK Installation Recommendations; 4 TEMPEST Integrity; 5 Secure Voice; 6 SCI; 7 Tactical Transportable; 8 Aircraft; 9 Ships. It implemented NSTISSP 300, NSTISSI 7000 and 7001, and superseded NACSIM 5203 "except Appendix K."

Concepts from 2-95 that still teach well:

  • CTTA primacy: "There should be no commitment of funds without CTTA concurrence."
  • Dedicated RED and BLACK wireways and incompatible patch connectors
  • Optical fiber that doesn't "conduct or radiate radio frequency interference," but with "no metallic stiffeners or metallic sheath"
  • Filters and isolators "when separation requirements cannot be met"
  • Fortuitous conductors, and the warning that "a long slender ground wire is not an effective RF ground"

Facility countermeasure process (historical NSTISSI 7000). The CTTA conducts or validates a review and determines the inspectable space. Location, information volume and sensitivity, physical controls, equipment TEMPEST profiles and the threat environment drive the countermeasures. That risk-based model is still how the IC Tech Spec works: countermeasures come "when recommended by the CTTA."

Sources NSTISSAM TEMPEST/2-95 (historical mirror) · NSTISSI 7000 (historical mirror) · NACSIM 5000 (historical mirror) · DoDI 8523.01 · CNSS memoranda listing

16.09

The IC's move from DCID 6/9 to ICD 705

Before 2010. IC SCIF physical and technical security lived in DCID 6/9 (with its Manual and Annexes), supplemented by Intelligence Community Policy Memoranda. The SAP world used the parallel JAFAN 6/9 manual, now a legacy standard.

26 May 2010. DNI Dennis C. Blair signed ICD 705, Sensitive Compartmented Information Facilities. It rescinded DCID 6/9 and ICPMs 2005-700-1, 2006-700-7 and 2007-700-2. It set a layered structure that remains in place:

Tier Document Date
Directive ICD 705 26 May 2010
Standard (physical and technical) ICS 705-1 17 Sep 2010
Standard (accreditation and reciprocity) ICS 705-2 22 Dec 2016
Technical specification IC Tech Spec for ICD/ICS 705 v1.5.1, 26 Jul 2021

How the Tech Spec evolved (from its change history):

Version Date Notable changes
1.2 23 Apr 2012 Wall drawings replaced; FIPS/AES encryption language; TEMPEST checklist edits
1.3 26 Mar 2015 Modular SCIF note; vent and duct guidance; high-security switch requirement
1.4 27 Jun 2017 SAPF language added; UL 2050 (60-minute) response language added to Chapter 7
1.5 13 Mar 2020 Pre-Construction Checklist; door criteria expanded; "CSA" changed to "AO" where appropriate
1.5.1 26 Jul 2021 New Chapter 13 (Second Party Integree/Liaison spaces); forms moved to Chapter 14

TEMPEST in the ICD 705 era. The public documents don't restate national TEMPEST criteria. They assign the decision to the CTTA (Tech Spec 3.A.3) and name the triggers: RF protection "at the direction of the CTTA" (3.C.4), and dielectric breaks or grounding "when recommended by the CTTA" (3.G.2). The TEMPEST Checklist is a standard Tech Spec form.

Parallel changes:

  • SAPFs: DoDM 5205.07 Vol 3 (23 Apr 2015) pointed SAPF construction to the IC Tech Spec. The consolidated DoDM 5205.07 (17 Jan 2025) cancelled Vols 1–3.
  • Intrusion detection: UL 2050 Edition 6 (7 Apr 2025) replaced Edition 5 (5 Nov 2010). See: Intrusion Detection & UL 2050 / Extent 3.

Grandfathering. ICS 705-1 lets SCIFs accredited before ICD 705 continue under the standards in effect at their most recent accreditation. On re-accreditation they must meet current IDS standards unless waived.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1 (NAVFAC mirror) · DoDM 5205.07 (2025) · UL 2050 Ed. 6

16.10

Why history matters to today's designers

History isn't trivia on a SCIF project. It shows up on datasheets, legacy drawings, old facilities and the internet.

1. Legacy citations are everywhere. Datasheets cite "NSA 65-6," "NSA 94-106" and "MIL-STD-285." Old specifications reference DCID 6/9 or JAFAN 6/9. When you see an old citation, ask what the current contract, CTTA recommendation and AO require. A datasheet's test method isn't the project's acceptance criterion.

2. FOIA documents teach concepts, not requirements. 2-95 and 94-106 are publicly mirrored, well written and superseded. Use them to understand why filters, waveguides and single-point grounds exist. Never lift a number, distance or table from them into a design.

Use historical documents to… Don't use them to…
Understand RED/BLACK, inspectable space and fortuitous conductors Set separation distances
Recognize legacy citations on submittals Set attenuation or test levels
Explain to trades why details matter Claim a room is "TEMPEST compliant"

3. Existing SCIFs may predate current rules. Because of ICS 705-1 grandfathering, a renovation can land in a facility built to older standards. On re-accreditation, current IDS standards apply unless waived. Ask the AO before assuming old conditions carry forward.

4. The threat lessons are permanent. Signals travel along wires (1951), ordinary equipment leaks (1985), and fixed zones proved "quite arbitrary." That's why the modern system is risk-based and CTTA-driven, and why builders shouldn't substitute a rule of thumb for the TCR.

5. Requirements are still moving. The Tech Spec went through five versions in under a decade. UL 2050, DoDM 5205.07 and IEEE 299 all changed status in 2023–2025.

Sources IC Tech Spec v1.5.1 (NAVFAC mirror) · ICS 705-1 · NSTISSAM TEMPEST/2-95 (historical mirror) · NSA, TEMPEST: A Signal Problem · NCSC regulations page

16.11

Public reading list

Documents marked Historical are FOIA-released or superseded. Read them for background only. Controlled documents (CNSSP 300, CNSSI 7000, CNSSAM TEMPEST/1-13) aren't listed because they aren't public. Get applicable requirements through your AO or CTTA.

Document Status Why read it Link
NSA, TEMPEST: A Signal Problem Declassified article The discovery story and the covername nsa.gov
NACSIM 5000, TEMPEST Fundamentals (1982) Historical (FOIA, redacted) Original RED/BLACK definitions FOIA mirror
NSTISSAM TEMPEST/1-92 (1992) Historical (partial FOIA) Equipment test-level concepts FOIA mirror
NSTISSI 7000 (1993) Historical (FOIA) Facility countermeasure process and inspectable space FOIA mirror
NSA 94-106 (1994) Historical (FOIA) Enclosure specification structure FOIA mirror
NSTISSAM TEMPEST/2-95 (1995) Historical (FOIA) RED/BLACK installation concepts FOIA mirror
Cryptome TEMPEST index and timeline Index (historical) Document dates and release history Wikipedia: Tempest (codename) · Wikipedia: Tempest (codename)
Wikipedia: Tempest (codename); Van Eck phreaking Reference Accessible overviews Tempest · Van Eck
NIST CSRC Glossary: TEMPEST Current definition Official public definition csrc.nist.gov
IC Tech Spec v1.5.1 Current The CTTA's role and TEMPEST triggers (3.A.3, 3.C.4, 3.G.2) NAVFAC mirror
SCIF TEMPEST Checklist Public form What a CTTA asks archive.dni.gov
IEEE 299-2006 Inactive-Reserved; revision in development Shielding test method IEEE

See: Reference Library for the full current document list.

Sources NSA, TEMPEST: A Signal Problem · Wikipedia: Tempest (codename) · NIST CSRC Glossary: TEMPEST · IC Tech Spec v1.5.1 (NAVFAC mirror) · IEEE 299-2006