Step-by-step answers to the questions owners, GCs and installers actually ask: first steps, leases, ducts, filters, alarms, doors, re-evaluation and more.
Confirm sponsorship. Identify the government sponsor and how the need is documented. For DoD, "proof of sponsorship in the form of a SCIF number or written documentation of Concept Approval" is required (UFC 4-010-05 2-2.1).
Ask whether an existing SCIF will do. Co-use of an accredited SCIF under a Co-Use Agreement is usually faster than building.
Identify the AO and appoint a Site Security Manager (SSM). Coordinate with the AO "before construction design, material ordering, or contracts are finalized" (Tech Spec 2.A).
Define the operating profile: closed or open storage, SWA or continuous operation, available Security-in-Depth, and which rooms need discussion or amplified audio. These choices drive wall type, alarm response time and Sound Group.
Submit early paperwork: Pre-Construction Checklist, preliminary Fixed Facility Checklist and the TEMPEST Checklist so the CTTA can review during planning (UFC 1-19.3).
Get the Construction Security Plan (CSP) approved. "Do not award a construction contract without an approved CSP" (UFC 4-1).
Staff correctly. Design and construction by U.S. companies using U.S. citizens (U.S. persons permitted with AO mitigations); IDS installation and testing by U.S. companies using U.S. citizens.
Plan the schedule honestly. JLL (2025, practitioner) reports SCIFs "typically take 12-18 months to accredit," possibly longer.
Who decides
Sponsor / Service CSA (DoD): validates need and grants concept approval.
AO: approves design concept, CSP and final design, then accredits.
Walk the shell before signing. Can perimeter walls run true floor to true deck? Where are deck flutes? Are there windows within 18 feet of grade or an accessible platform? Where would a vestibule and a telecom room go?
Trace building utilities. "Utilities servicing areas other than the SCIF shall not transit the SCIF unless mitigated with AO approval" (Tech Spec 3.G.3). Other tenants' ducts, pipes and risers crossing the space are expensive to move.
Inventory Security-in-Depth. A controlled building with separate access control, alarms and elevator controls, or alarmed adjacent office areas, can support a 15-minute rather than 5-minute response for open storage. Document it for FFC Section B.
Check existing walls. Brick, concrete or block walls that meet the perimeter standard may be used, pending AO approval.
Expect TEMPEST questions. Shared buildings often leave little inspectable space. List nearby Wi-Fi access points, DAS antennas and boosters, since the TEMPEST Checklist asks about radios within three meters of the perimeter.
Write the lease for SCIF life. Holland & Knight (2025) recommends terms on "responsibility for SCIF maintenance, lessor preapproval of any future upgrades required by a government contract." Add landlord approval for penetrations, roof or core work, IDS communication paths and restoration.
Protect your SID. Require notice if the landlord changes lobby access control or tenant layout, because a lost SID layer can change the required response time.
Who decides
AO: accepts existing walls, SID and any utility mitigation.
CTTA: RF or TEMPEST countermeasures.
Landlord and AHJ: building alterations and life safety.
Raise it as a formal RFI to the SSM before rough-in. Do not let the fire protection contractor proceed on the original route.
Classify the pipe. Is it a branch serving only the SCIF, or a main transiting to other spaces? Tech Spec 3.G.3 bars transiting utilities "unless mitigated with AO approval," and UFC 3-3.3.2 says utilities and building support spaces "should remain outside of the secure areas."
Reroute the main around the perimeter where possible. If rerouting is impractical, request AO approval for a documented mitigation.
Minimize and consolidate entries. Utilities should enter at a single point (Tech Spec 3.G.4). Keep penetrations to a minimum.
Seal and firestop. "Seal both sides of perimeter penetrations with an acoustical foam or sealant finished to match adjacent wall"; a listed firestop system may be required in rated assemblies (UFC 3-4.11.3).
Apply only the TEMPEST treatment the CTTA calls for. Unless the TEMPEST Countermeasure Review directs otherwise, UFC 3-4.11.2 says to ground metallic sprinkler pipe within 6 inches of the penetration using No. 4 copper wire to the building grounding system.
In an RF-shielded room, use the shield vendor's engineered pipe waveguide. Water lowers a waveguide's cutoff frequency, so the design must account for a filled pipe.
Photograph the finished penetration before the ceiling closes and add it to the penetration schedule (UFC 4-7).
Who decides
AO: any transiting utility and its mitigation.
CTTA: grounding or dielectric treatment.
Fire protection engineer and AHJ: listed fittings, firestopping and system design.
Run the numbers. Bars or grilles are required when an opening "exceed[s] 96 square inches," unless "one dimension of the penetration measures less than six inches" (Tech Spec 3.G.7). A 12 × 10 inch duct (120 square inches) needs them; a 30 × 5 inch duct does not, because one side is under 6 inches.
Pick the barrier:
Option
Tech Spec requirement
Man-bars
Minimum ½-inch steel, welded vertically and horizontally 6 inches on center (½-inch spacing deviation allowed)
Expanded metal
¾-inch mesh, #9 (10 gauge), case-hardened
Welded wire fabric
4x4 W2.9xW2.9
Metal baffles or wave forms
Permanently installed, no more than 6 inches apart, in lieu of bars
Add an inspection port inside the perimeter so the barrier can be seen. A port outside the perimeter must be secured with an AO-approved high-security lock.
Treat the duct acoustically. Use silencers or a Z-duct and double-wall acoustic duct instead of lined duct (UFC 3-4.13). Finish the wall tight to the duct.
Bring in the mechanical engineer. Baffle backpressure "may significantly impact the HVAC system design," and Z-ducts need ceiling space.
Apply TEMPEST treatment if directed. When countermeasures apply, and unless the TEMPEST Countermeasure Review directs otherwise, UFC 3-4.11.2 details a nonconductive flex break in a short (2- to 6-inch) section of duct inside the perimeter; the TCR and stamped drawings govern. In an RF shield, the vent becomes a bonded honeycomb waveguide.
Complete the TEMPEST Checklist during planning. It asks for the distance from the SCIF to the limit of inspectable space, radios inside or within three meters of the perimeter, signal and power lines that exit, and equipment that processes classified information.
Route it through the AO to the CTTA and get the TEMPEST Countermeasure Review in writing before committing funds.
Read the trigger. "RF protection shall be installed at the direction of the CTTA when a SCIF utilizes electronic processing and does not provide adequate RF attenuation at the inspectable space boundary" (Tech Spec 3.C.4). Little inspectable space in a shared building is a common reason. Overseas SCIFs not under Chief of Mission authority have TEMPEST countermeasures "pre-engineered into the construction" (4.H.1).
If shielding is required, pin down scope: foil-backed wallboard or approved foil on certain walls, shielded racks, filtered power only, or a full enclosure. Get the attenuation target, test method and acceptance criteria.
Plan it into initial construction. ICS 705-1 says RF shielding "should be planned for installation during initial construction as costs are significantly higher to retrofit."
Freeze the penetration schedule with the shield vendor: filters, waveguides, vents and RF doors.
Get the details first: the CTTA's list of lines to filter, the shield vendor's penetration detail, and the engineer of record's filter sizing.
Mount at the entry point. Premier EMC: "as close as possible to the entry point of the input power wires."
Line side outside, load side inside. ETS-Lindgren calls these the "dirty side" and "clean side." The feeder conduit ends at the dirty compartment and never continues through the shield on its own.
Keep input and output wiring apart. Premier: "Maintain physical isolation and separation between filter input and output wires."
Bond the case metal to metal. Surfaces must be "void of paint or other insulating material." Use short flat braid, not a long round wire.
Keep the safety ground solid. ETS-Lindgren: "provide uninterruptible safety earth ground from the main power source to the product input wiring terminals."
Coordinate leakage and GFCI. Filters leak current to ground by design (Captor lists "5mA maximum @ 120 VAC"). Engineering sources caution that a GFCI upstream of a filter can nuisance-trip, so the EE of record and AHJ decide where ground-fault protection goes.
Flag generators and UPS. High-capacitance filters can create kVAR that may "Prevent generator startup altogether" (Premier). Low-kVAR designs exist.
Treat low-voltage lines too. Readers, contacts and IDS wiring need signal filters, or fiber through a waveguide.
Who decides
CTTA: which lines need filtering.
EE of record and AHJ: sizing, grounding, leakage and code compliance.
Confirm the device. UFC 3-4.17.3.3 requires "UL 634 HSS level 2," and every perimeter door needs an HSS and a motion sensor (Tech Spec 7.A.3.a(7)).
Get the door maker's and shield vendor's attachment points before rough-in. A historical Navy shielding handbook notes some door makers "refuse to guarantee performance" unless they control the door installation.
Prefer a surface switch on the protected side. Concealed models need a drilled frame; Magnasphere's L2C instructions say "installation must be in a metal frame" with a "deburred 1" hole." Never field-drill an RF or knife-edge frame.
Use the manufacturer's brackets and spacers. Z- and L-brackets, non-ferrous spacers and shims align the switch across deep acoustic frames and steel doors.
Keep removal tamper working. The tamper magnet is inserted into the mounting hole, so an adhesive-only mount defeats it. Wire tamper to a 24-hour circuit.
Keep hardware clear of drop seals, gaskets, finger stock and knife edges. A bracket that holds the door slightly open fails both acoustic and RF tests.
Route armored leads in surface raceway to the IDS panel inside. Only filtered or fiber-converted circuits cross the shield's penetration panel.
Install before the final shield test, and walk-test after seals take a set: the alarm must activate before the non-hinged side opens beyond the door's thickness (7.D.3).
Who decides
Door maker and shield vendor: where anything may attach.
Check the listing in UL Product iQ. Look for category CRZH (National Industrial Security Systems) for the installing company and CRZM for a national industrial monitoring station. Note the file number.
Ask for a redacted sample UL 2050 certificate and how the company handles the CS-ASD-NISS alarm system description form. Confirm Extent 3 SCIF or SAPF experience.
Confirm the monitoring model. Under the Edition 5 NISPPAC briefing, a Government Contractor Monitoring Station covers systems within 240 miles; beyond that needs a NIMS listing. Under the Tech Spec, monitoring operators must be trained U.S. citizens eligible for a SECRET clearance.
Confirm people. Installation and testing inside the U.S. by U.S. companies using U.S. citizens (7.D.1). Maintenance technicians hold TOP SECRET or are escorted (7.C.2).
Put service terms in the contract. Repairs start "within 4 hours" of a trouble signal (7.C.2).
Get approval before installing. The AO approves IDS plans before installation; for NISPOM areas, "CSA approval is required before installing an IDS."
Verify the certificate on delivery: National Industrial Security System certificate, CCN, issue and expiration dates, system type, Extent 3, approved response time and encrypted line security.
Plan renewals. Any IDS change after the certificate is issued requires renewing it (ICS 705-1).
Who decides
AO or CSA: approves the IDS plan and response arrangements.
UL: issues the certificate through the listed company and audits listed companies.
Sponsor: clearance sponsorship for cleared monitoring, which UL does not control.
Protect the SCIF now. If an IDS component fails, the SCIF must be occupied by SCI-indoctrinated personnel or covered by other AO-approved measures (7.A.1.d). Follow the emergency plan and notify the SSO.
Confirm the test was run correctly. Each trial is four consecutive steps at one step per second, about 30 inches (± 3 inches) per step, with 3–5 second pauses. The alarm must activate on at least three of every four trials "made by moving progressively through the SCIF" (7.D.3).
Map the miss. Plot the failed path against sensor coverage. Look for new tall cabinets, safes, cubicle walls or GSA containers creating dead zones.
Check the sensors. Dual-technology units must report each technology independently (7.A.3.a(4)). Confirm mounting and settings match the manufacturer's instructions.
For door switch failures, measure the gap and realign. The alarm must trip before the door opens beyond its own thickness.
Fix without creating false alarms. The limit is one false alarm per 30 days per partition (7.A.2.p). HVAC diffusers on PIRs and microwave sensors seeing through drywall are common causes.
Treat added or relocated sensors as an IDS change: AO concurrence, FFC Section E update and UL certificate renewal.
Retest and record test dates, testers, equipment, malfunctions and corrective action. Keep records two years.
Who decides
SSO or IDS administrator: compensatory measures and records.
AO: sensor count and IDS plan changes.
Alarm service company: repairs and certificate renewal.
Confirm the CA type for each compartment with the SSO and program manager:
Type
Use
Design impact
I
Viewing and processing; no storage or discussion
Keep monitors from facing the primary door or common areas
II
Discussion (secure VTC or phones); no storage
Meet STC requirements; acoustic door assembly
III
Processing, printing, storage in GSA containers
Everyone with unfettered access briefed into all compartments in the CA
Lay out high inside low. UFC 3-3.3.2: "Entry into a lower security area cannot be through a higher security area." Nobody should cross one compartment to reach another.
Choose CA door hardware. Access is by visual recognition or mechanical or electronic devices. "Spin-dial combination locks shall not be installed on CA doors" (Tech Spec 2.C.4).
Build explicit access levels. One level per CA door group, matched to the compartment read-in roster. Clearance alone is not access: E.O. 13526 requires eligibility, a nondisclosure agreement and need-to-know.
Do not add alarms. "Independent alarm systems shall not be installed in a CA." No CA partition, no CA keypad. CA door events are access control events.
Protect acoustics on Type II rooms. Reader and REX penetrations must not break the STC rating.
File the paperwork. CA Fixed Facility Checklist; the AO approves "with the concurrence of the CA Program Manager." SAP use of part of a SCIF is treated as a CA and needs a Co-Use Agreement first.
Who decides
AO with CA Program Manager concurrence: CA approval.
Know the policy driver. The Secretary of Defense's 30 June 2023 memo told DoD components to "program for appropriate electronic device detection systems and mitigation measures in all DoD SCIFs and SAPFs by September 30, 2024." That is planning language, not a mandate for a specific product.
Place PED lockers outside the primary entrance, not within 10 feet of equipment processing unencrypted classified information, and never recessed in the perimeter wall (UFC 3-4.7).
Pick a technology for the job. Fixed standalone RF detectors suit a vestibule; passive WIDS sensor networks cover rooms; ferrous screening finds devices whether or not they are on.
Design the workflow. Badge the outer door; the interlock holds the inner door; the person dwells in the detection zone; a detection inhibits the inner-door grant through a dry contact or relay into the access control system and alerts SCI-indoctrinated staff.
Keep priorities straight. Detector inputs are access control events and rank below IDS alarms (Tech Spec 7.A.2.i).
Get AO and CTTA review of any sensor inside the SCIF, its cabling and any network or web interface.
Get AHJ approval for the interlock. Allegion notes interlocks "are not currently addressed in the model codes, so each interlock application must be approved by the Authority Having Jurisdiction." Expect the AHJ to address release on fire alarm and power loss; egress is never blocked.
Handle logs as security records under the SSO.
Who decides
AO and CTTA: sensors, placement and network paths.
Meet early with the AHJ and bring cut sheets. The DoD Lock Program tells buyers to "check with your local fire marshal (Authority Having Jurisdiction – AHJ) prior to procurement."
Explain the security requirement. Electric strikes or electrified mortise locks used with access control "must have a positive engagement, fail secure, and approved under UL 1034" (UFC 3-4.6.5). Magnetic locks are fail-safe by nature and generally conflict with that rule.
Show how egress is solved mechanically. FF-L-2890C devices for occupied doors provide one-hand, single-motion egress (Types V and VI are for rooms not regularly occupied), and the specification requires compliance with the IBC, NFPA 80, NFPA 101 and ADA. Types II, IV, VII and VIII provide "fail secure, electric release capability" for access control.
Match hardware to occupancy. Types III, IV, VIII and X include fire-rated panic hardware where occupant load requires it.
Address the egress-only door. No exterior hardware, FF-L-2890 exit device, alarmed 24/7 with a local annunciator. UFC recommends delayed egress "with NFPA 101 compliance," only where the AHJ and code permit.
Clarify what locks an empty SCIF. The FF-L-2740 combination lock throws the FF-L-2890 deadbolt and the IDS is armed. Access control is not approved for securing an unoccupied SCIF (ICS 705-1).
Document the agreed solution in the door schedule and submit it to both the AHJ and the AO.
Who decides
AHJ: egress, panic hardware, delayed egress and fire ratings.
Practitioner advice: design discussion areas to Sound Group 4 now
Built correctly but a path still leaks (door, window, duct)
Masking on that path, with AO approval
Action plan
Set the target with the AO and zone rooms by Sound Group (UFC 3-4.3.2).
Buy tested assemblies. Door and wall components tested to ASTM E90 at STC 50 for an STC 45 perimeter, and STC 55 for STC 50.
Test as built. With doors closed, the perimeter and openings are tested at multiple points by audio or instrumented methods approved by the AO.
If a weakness remains, masking is a mitigation "when normal construction and baffling measures have been determined to be inadequate" (UFC 3-4.3.4). Alternatives include structural enhancement or a stand-off zone.
Design masking to the Tech Spec rules: generator permanently installed inside the SCIF with no AM/FM receiver and recording disabled; transducers on the leak paths; wires and transducers inside the perimeter "to the greatest extent possible."
Commission it. Listen outside, raise the level until conversations are unintelligible, then set and fix the volume. Expect TSCM inspection.
Who decides
AO: required Sound Group, test method and masking approval.
CTTA: any masking cable that crosses the perimeter.
Ask the AO in writing which standards apply. ICS 705-1 historically let accredited SCIFs keep prior standards, but required current IDS standards at re-accreditation unless waived. Practitioners report non-public 2025 ODNI direction rescinding re-accreditation under previous standards.
Know the clock. The CSA ensures re-evaluations based on program sensitivity, threat, modifications and past performance, "or at least every five years" (ICS 705-2). Legacy SAPF re-inspection was at least every three years.
Reconcile the building to the file. List every change since the last accreditation: penetrations, doors and hardware, IDS and ACS configuration, telecom and SID layers. Submit FFC page changes.
Pull IDS evidence: current UL 2050 certificate, acceptance and semi-annual test records, arm/disarm failure reports and battery maintenance records (two years each), and the backup power calculation.
Plan equipment refresh. Existing UL 634 Level I switches may stay only until major IDS modifications. Check communicator encryption validation status.
Check locks and containers. The DoD Lock Program recommends replacing X-07 and X-08 locks; black-label Class 5 and 6 containers are being phased out by 1 October 2028.
Refresh operating documents: SOP, emergency plan, access rosters, SF 701 and SF 702 practice, and any waivers (DoD waivers normally run up to one year).
Budget upgrades and settle lease responsibility before findings arrive.
Stop and submit. Describe the penetration to the SSO: location, size, material, purpose and what crosses it. The SSO takes it to the AO.
Let the AO classify the change. A minor change may need only an FFC page change. "Major modifications" trigger re-accreditation (ICS 705-2). In DoD, the SSO reports "all changes affecting the security posture" of a SCIF to DIA's accreditation office (DAC) within 24 hours.
Get CTTA input for any metallic penetration, which "may require TEMPEST countermeasures, to include dielectric breaks or grounding" (Tech Spec 3.G.2).
Plan construction security. DoD requires an SSM for each renovation, and the SSM develops a CSP. Renovations need barriers separating workers from operational areas (Tech Spec 3.B.3). Secure classified material and escort uncleared workers.
Build to the approved detail. Keep it small; seal both sides finished to match the wall; maintain acoustic performance; add bars if a duct opening exceeds 96 square inches; fill and cap spare conduit with acoustic fill.
Do not cut hardening layers (expanded metal or plywood in Wall B or C) without an AO-approved detail. An unexplained patch is exactly what inspectors look for.
Document and test. Photograph before closing, update as-builts, and retest what the change affects: acoustics, IDS and, in a shielded room, the shield. Any IDS change requires UL certificate renewal.
Co-Use Agreement; tenant accepts host accreditation and pays for changes
ICS 705-2
Temporary Secure Working Area (TSWA)
Less than 40 hours per month; accreditation 12 months or less; no storage
Tech Spec 3.J
Secure Working Area (SWA)
No storage; 15-minute alarm response; no DoD time limit
Tech Spec 3.I; DoDM 5105.21
Temporary SCIF (T-SCIF)
Tactical, emergency or immediate operational need; DoD approvals up to 1 year
ICS 705-1; DoDM 5105.21
Action plan
Ask the sponsor about co-use first. SCIFs may temporarily store SCI for other organizations for up to seven calendar days; longer needs a Co-Use Agreement.
Define the need: hours per month, storage, discussion, electronic processing and end date.
For a TSWA: secure it with a high-security, AO-approved key or combination lock when not in use; the AO may require an alarm; meet Chapter 9 acoustics if used for discussion. TSCM may be required if the space was not under continuous SECRET-level control.
For a T-SCIF: CDSE teaches one controlled entrance, at least one SCI-cleared person present at all times, perimeter guarded by U.S. SECRET-cleared guards, and TEMPEST countermeasures as the CTTA identifies.
Get the right approval. In DoD, Service CSAs approve TSWAs and T-SCIFs.
Plan the end. "Extension requests require a plan to accredit as a SCIF or SWA" (3.J).
DoDM 5205.07, Special Access Program Security Manual, effective 17 January 2025, "incorporates and cancels" Volumes 1, 2 and 3 (Vol. 3 was Physical Security, 23 April 2015). Volume 4 (Marking) is still posted separately.
It incorporates the USD(I&S) memo on "SAP Discussion in Accredited SCIFs" (21 November 2023).
A SAPF Accrediting Official, appointed in writing by the CA SAPCO or designee, reviews preconstruction plans, inspects and accredits SAPFs.
DCSA's oversight of SAP contract industrial security transfers to the program's Cognizant Authority no later than 31 July 2029.
Action plan
Update your specifications. Cite DoDM 5205.07 (2025), not Volume 3. Treat JAFAN 6/9 as legacy.
Identify the SAPF-AO through the Program Security Officer.
Submit preconstruction plans to the SAPF-AO. UFC 4-010-05 notes most SAPF sponsorship is formalized at the program level; the Navy requires concept approval.
Build to Tech Spec equivalents. Legacy Vol. 3 required SAPFs to "conform to the equivalent" SCIF standards, and DCSA's January 2026 checklist still cites Tech Spec Chapter 7 for IDS.
Design IDS to the checklist: UL 2050 certificate with Extent 3 (F-30), semi-annual testing (F-26), entry delay of 30 seconds or less (F-29), 24-hour backup power documented in the FFC (F-44).
Execute a Co-Use Agreement before SCI enters the SAPF or SAP enters a SCIF.
Who decides
SAPF-AO: plans, inspection and accreditation.
PSO, GSSO or CSSO: program security administration.
The Cryptographic Module Validation Program stopped accepting FIPS 140-2 submissions on 1 April 2022.
140-2 validations move to the Historical List on 21 September 2026 (the NIST schedule table also shows 22 September 2026).
"Even on the historical list, CMVP supports the purchase and use of these modules for existing systems."
What the Tech Spec says
A UL 1610 listed PCU needs FIPS 197 (AES) or FIPS 140-2 encryption; a UL 1076 listed PCU needs FIPS 140-2 (7.A.3.b(10)).
LAN/WAN transmission uses FIPS 140-2, VPN or closed and sealed conveyance; AES with AO approval.
Action plan
Inventory every module in the alarm path: panel, communicator, any add-on encryption module and the receiver. Get the CMVP certificate number for each, not just the word "AES." FIPS 197 is an algorithm; FIPS 140-2 and 140-3 validate modules.
Separate existing from new. For an installed, accredited system, ask the AO or CSA whether continued use is accepted.
For new installs or major changes, ask the AO in writing before specifying, and prefer FIPS 140-3 validated modules.
Treat a communicator swap as an IDS change: AO or CSA approval (data-network transmission needs prior CSA approval on the UL form), acceptance testing, FFC update and UL certificate renewal.
Check end to end. Encryption enabled at the panel and the receiver, receiver keys changed from defaults, and no unlisted IP converter in the path.
File the certificate numbers in the accreditation package.
Who decides
AO or CSA: acceptability for the facility.
NIST CMVP: only validation status, not facility approval.
Protected at no less than FOUO, now handled as CUI (DoDM 5105.21 Vol. 2; UFC 4-2)
Construction plans and related documents
"Handled and protected in accordance with the CSP" (Tech Spec 3.B)
IDS technical documentation
The AO decides protection; it goes in the CSP (7.A.2.k)
Filled-in Fixed Facility Checklist
"May be CUI or Classified depending on contents" (UFC 1-19.2)
TEMPEST findings tied to a location
Classified at a minimum of CONFIDENTIAL (UFC 1-16.3)
System variables, passwords, PINs, enrollment data
Restricted to SCI-indoctrinated personnel (7.A.2.j; FFC C.1)
Action plan
Read the CSP's document controls before the first email. Ask the SSM how files move and how the project is to be referred to.
Never pair the address and "SCIF" in email, bid portals, calendar invites, photo captions, marketing or social media.
Keep drawings, zone maps and penetration schedules off open cloud shares. In 2017 a misconfigured storage bucket exposed Army intelligence data; data about secure systems leaks too.
Do not keep codes. Hand master and maintenance codes to the SCI-cleared IDS administrator, who changes them from defaults.
Limit remote access to what the AO approves; non-SCI-cleared personnel may not modify the IDS or ACS, and remote sessions are logged.
Control photos. The construction photo record belongs to the SSM under the CSP.
Return or destroy project data at closeout as the CSP directs.
What Hirsch literature verifies (manufacturer claims)
Velocity 3.9 is the current release.
Mx controllers are UL 294 and UL 1076 listed and use "FIPS 140-3 certified cryptography, including TLS v1.3."
Mx supports two-person rule, occupancy counting, door interlocking and anti-passback; alarm line modules add 2% or 4% line supervision and alarm masking.
TS ScramblePad readers scramble keypad digits and include viewing restrictors.
Velocity 3.8 or later integrates DMP XR150 and XR550 intrusion panels.
Hirsch cites GSA FIPS 201 APL #10103; confirm on the GSA list.
Action plan: questions to settle with the AO
Head-end location. Must the Velocity server and Mx panels sit inside the SCIF or an alarmed area controlled at SECRET, or is a shared enterprise server acceptable?
Encryption evidence. What proof is required for lines leaving protected space? Hirsch datasheets do not publish CMVP certificate numbers, so request them from Hirsch.
Credential mode. Card and PIN at a TS ScramblePad SC, or card, PIN and fingerprint at a ScrambleFactor?
IDS role. Will a separate UL 2050 intrusion panel serve as the PCU, or would the AO consider Mx UL 1076 inputs? Hirsch documents do not say "SCIF IDS approved."
Integration rules. IDS alarms must outrank access notifications (7.A.2.i), and non-SCI-cleared operators cannot change IDS modes (7.B.1). How will operator roles enforce this?
Door schedules. Secondary-door access control must be deactivated when the SCIF is unoccupied (3.E.3).
Network authorization. On a U.S. Government network, the IDS host needs an Authority to Operate; which cyber documentation will be required?
Who decides
AO: architecture and IDS acceptance.
The AO's CIO and the network's authorization process: an ATO under the Risk Management Framework before connecting to a U.S. Government network (7.A.3.c(1)).
Start from the rule. "Cameras are not allowed within the perimeter or enable observation within the perimeter" (UFC 3-4.17.2). An exterior camera at the primary entrance is permitted for remote control of the door, and a video intercom may provide this.
Use CCTV as a supplement. The Tech Spec treats entrance CCTV as a way to support remote door control from inside the SCIF, with the camera giving a clear view of the entrance and monitored by SCI-indoctrinated personnel inside. It does not replace the combination lock, access control or IDS.
Aim carefully. Frame the approach and door face. Keep the keypad, the FF-L-2740 dial and the view through an open door out of frame. VMS privacy masking is a backup, not the primary control.
Keep controls inside. The monitor, intercom master and door release belong inside the SCIF.
No audio. Choose cameras and intercom stations without microphones, or with microphones physically disabled. IDS components with audio or video capability need AO approval.
Route cabling outside where possible. Any line that must enter is a perimeter conductor for CTTA review and tamper protection.
Keep recording off SCIF networks and restrict who can view entrance footage, since it shows who enters a SCIF.
Claim Security-in-Depth credit. List corridor and building cameras in FFC Section B with coverage maps.
Coordinate before design is final. The AHJ, fire protection engineer, AO and CTTA all have a stake. No specific Tech Spec or UFC text on fire alarm speakers inside SCIFs was found in public portions reviewed.
Apply the checklist rule. The Fixed Facility Checklist asks whether public address, music or emergency notification systems use "fiber isolation, self-amplified speakers, other method to ensure no audio back feed from the system." Systems originating outside the SCIF need special design and approval.
Choose an approach with the AO and AHJ. Practitioner options include listed isolation modules or amplifiers inside the SCIF with one-way isolation, or visual-only notification where the AHJ permits.
Keep panels outside. Utilities and building support spaces "should remain outside of the secure areas" (UFC 3-3.3.2); normally only field devices are inside.
Treat every circuit as a penetration. Enter at the single point, seal both sides, and follow the TEMPEST Countermeasure Review. In a shielded room, notification circuits pass through signal filters; Genisco notes one filter model "is commonly installed in most commercial fire alarm systems."
Keep IDS separate. "IDS's shall be separate from, and independent of, fire, smoke, radon, water, and other systems" (Tech Spec 7.A.2.h).
Mind the walls. Recessed fire extinguisher cabinets are prohibited on perimeter walls (UFC 3-4.4.8).
Tie in interlocks. If the entrance uses an interlocked vestibule, coordinate its fire alarm release with the AHJ.
Who decides
AHJ: required devices and coverage.
AO and CTTA: back-feed protection and penetrations.
"PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes" (Tech Spec 7.A.3.b(1)).
Changing arm or disarm status is limited to SCI-indoctrinated personnel, with no remote mode changes by non-SCI-cleared personnel (7.B.1).
Co-located SCIFs may use a partitioned PCU, with each partition acting as an independent control unit (7.A.2.f).
A monitoring station handling several systems needs distinct audible and visible annunciation for each (7.A.2.g).
The collateral area's IDS needs CSA approval before installation under 32 CFR 117.15(d).
Action plan
Map the boundaries and who is authorized at each: building, collateral area, SCIF, and any Compartmented Area.
Default to separate panels for the collateral area and the SCIF, each with its own UL 2050 certificate and approvals.
If adjacent SCIFs want to share, confirm they support the same IC element or have a Co-Use Agreement, place the PCU in the SCIF whose staff administer it, and document the other SCIF's arm and disarm authority in the SOP.
If someone proposes a collateral partition on the SCIF panel, take it to the AO and CSA in writing, since non-SCI users would operate SCI equipment.
Do not create a CA partition. "Independent alarm systems shall not be installed in a CA."
Issue codes per partition only to that space's authorized staff, and site keypads where they cannot be observed.