Module 02 · 16 sections

Roles & Responsibilities

Who decides, who writes, who signs. The AO, CSA, SSM, SSO, CTTA, CSTs, escorts, designers, GCs, integrators and the AHJ, and what each produces.

On this page
  1. 02.01Roles at a glance: who produces and signs what
  2. 02.02IC element head and the Director, NCSC
  3. 02.03Accrediting Official (AO)
  4. 02.04Cognizant Security Authority (CSA)
  5. 02.05SAPF Accrediting Official and SAP security roles
  6. 02.06Site Security Manager (SSM)
  7. 02.07SSO, SSR and CSSO: running the accredited space
  8. 02.08Certified TEMPEST Technical Authority (CTTA)
  9. 02.09Construction surveillance technicians, cleared guards and escorts
  10. 02.10TSCM teams
  11. 02.11Sponsors, program managers and co-use tenants
  12. 02.12Designer of record (architect-engineer)
  13. 02.13General contractor responsibilities
  14. 02.14Low-voltage and IDS integrator responsibilities
  15. 02.15Authority Having Jurisdiction (AHJ) and life safety
  16. 02.16Role separation rules and common confusions
02.01

Roles at a glance: who produces and signs what

Role Primary phase Produces Approves or signs
IC element head All Delegations Accreditation authority (original); waivers, or delegates them to a named senior official who is not the AO
Accrediting Official (AO) All Waiver requests; letters of accreditation Design concept, CSP, final design; accreditation, interim accreditation, re-accreditation, de-accreditation
Cognizant Security Authority (CSA) Oversight Repository data; re-evaluation schedule Concept approval (DoD Services); co-use concurrence; TSWAs and T-SCIFs (DoD)
SAPF-AO SAP facilities SAPF preconstruction plans; SAPF accreditation
Site Security Manager (SSM) Planning to accreditation CSP; inspection reports; violation notices; assembled accreditation documents — (advises the AO)
SSO / SSR / CSSO Operations SOP, emergency plans, SF 701/702 records, posture change reports, withdrawal requests Occasional conference-room use without a CUA (SSO)
CTTA Planning and design TEMPEST countermeasures review with recommendations Recommends; the AO approves
CST / CAG / escorts Construction Surveillance logs; screening records
TSCM team (U.S. Government) As required TSCM report
Designer of record (A-E) Design Drawings and project data for the SSM
General contractor Construction Work per approved drawings and CSP; photo record
IDS / low-voltage integrator Installation and testing UL 2050 certificate, specification sheets, acceptance test results
Authority Having Jurisdiction (AHJ) Design to occupancy Building code, fire and accessibility compliance

Each role is detailed in the sections below.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025) · UFC 4-010-05 (2023)

02.02

IC element head and the Director, NCSC

IC element head. The head of an Intelligence Community element holds the original authority over SCIFs under ICD 705.

Authority ICD 705 text Delegation limit
Accredit, re-accredit, de-accredit "The IC element head may accredit, re-accredit, and de-accredit SCIFs." May be delegated "to a single named official, who shall serve as the Accrediting Official." The AO may further delegate decision authority for specific SCIFs "while retaining overall responsibility."
Grant waivers Granted "pursuant to a documented mission need." May be delegated to "a single named senior official" and "may not be further delegated." "In no case may this official be the same person as the Accrediting Official."
Report waivers "All approved waivers shall be reported to the D/NCSC immediately, but no later than 30 days after the IC element head's decision."
Report inventory New or updated SCIF information to D/NCSC within 30 days

Director, National Counterintelligence and Security Center (D/NCSC). The ODNI official responsible for SCIF standards. The posted ICD 705 carries technical amendments naming the D/NCSC; ICS 705-1 names the former ADNI/SEC as the original developer of the Tech Spec.

The D/NCSC:

  • issues the ICS 705 series and the IC Tech Spec (ICS 705-2 is signed by the Director, NCSC; the v1.5.1 Tech Spec transmittal was signed by the Acting Director);
  • manages the IC SCIF Repository, the inventory of accreditations, waivers and de-accreditations;
  • receives waiver reports and periodic re-evaluation results, which are reported via the repository within 30 days.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · NCSC Security Governance and Regulations

02.03

Accrediting Official (AO)

The AO is the "single named official" to whom the IC element head delegates accreditation authority (ICD 705). In DoD, for most DoD Components and DoD contractors, that authority sits with DIA's accreditation office, which DoDM 5105.21 Vol. 2 calls "the sole accrediting authority for physical and technical (TEMPEST) security for permanent SCI facilities."

What the AO does (ICS 705-1; Tech Spec 3.A and related chapters):

Responsibility Source
Reviews and approves the design concept, CSP and final design "prior to the start of SCIF construction" Tech Spec 3.A; ICS 705-1
Determines whether SSM duties are full-time Tech Spec 3.A
Decides whether CSTs are required for U.S. projects Tech Spec 3.A
Considers and documents Security-in-Depth with the SSM Tech Spec 2.A–2.B
Ensures mitigations when non-U.S. citizens perform construction Tech Spec 3.B
Approves IDS system plans; requires acceptance testing before accreditation Tech Spec 7.A.2.o
Approves RF transmitters in a SCIF after CTTA evaluation ICS 705-1 §G.2.a
Approves Compartmented Areas, with concurrence of the CA Program Manager Tech Spec 2.C
Prepares waiver requests (but does not grant them) ICS 705-1
Issues interim accreditation where provided (overseas) Tech Spec 4.I, 5.K
Conducts, or designates, the inspection before final accreditation ICS 705-2
Signs the letter of accreditation; provides SCIF data to the repository ICS 705-2
Coordinates and signs Co-Use Agreements with the other party's AO ICS 705-2; Tech Spec 12.N–P
De-accredits and ensures sanitization ICS 705-2 §E.5

Version note. Tech Spec v1.3 moved inspection responsibility from the "IC element head" to "the AO or designee," and v1.5 changed many "CSA" references to "AO." Older submittals and training may still say "CSA" where current text says "AO."

Sources ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2

02.04

Cognizant Security Authority (CSA)

Definition. The official with "authority over and responsibility for all aspects of management and oversight of the security program" (DoDM 5105.21, as taught in CDSE SCI101). ICS 705-1 adds that CSAs "oversee construction and accreditation programs and ensure timely data input to the IC SCIF repository."

What the CSA produces or approves:

Responsibility Source
Ensures periodic re-evaluations occur "at least every five years," or sooner based on program sensitivity, threat, modifications and past performance ICS 705-2 §D.3.a
Concurs on co-use: "co-use begins when host CSA concurs" ICS 705-2
Keeps security cognizance of a co-used SCIF unless both CSAs agree to transfer it ICS 705-2
DoD Services: validates the need for a SCIF and grants concept approval DoDM 5105.21 Vol. 2; UFC 4-010-05 2-2.1
DoD Services: approves TSWAs and T-SCIFs DoDM 5105.21 Vol. 2; UFC 4-010-05
Receives the CTTA's documented TEMPEST review results with the AO Tech Spec 3.A
DoD Components: coordinate Co-Use Agreements with other DoD agencies DoDM 5105.21 Vol. 2

Who appoints CSAs in DoD. The Director, DIA appoints CSAs, including one for OSD, the Joint Staff and the Combatant Commands. Military Department heads, through their Heads of Intelligence Community Elements, appoint CSAs for their departments. At the State Department, the Division Chief, DS/IS/SSO "is the Cognizant Security Authority (CSA) for SCI matters" (12 FAM 712.2(a)).

Sources ICS 705-1 · ICS 705-2 · CDSE SCI101 Student Guide · DoDM 5105.21 Vol. 2 · UFC 4-010-05 (2023) · 12 FAM 710 · 32 CFR 117.3

02.05

SAPF Accrediting Official and SAP security roles

Special Access Program facilities use a parallel set of roles under DoDM 5205.07 (17 Jan 2025).

Role What it does
CA SAPCO (Cognizant Authority Special Access Program Central Office) "The CA SAPCO, or their designee in writing, will appoint in writing an individual to serve as SAPF-AO."
SAPF Accrediting Official (SAPF-AO) "Responsible for reviewing and approving or disapproving physical security preconstruction plans for, and physically inspecting and accrediting, reaccrediting, and de-accrediting, a SAPF." CDSE SA501 uses "SAO" for this role and notes the SAO "will physically inspect any SAP area before accreditation."
PSO (Program Security Officer) Program-level security official; the Navy routes SAPF concept approval requests through the PSO and Government Program Manager
PSM (Program Security Manager) Program-level security management
GSSO (Government SAP Security Officer) Facility-level government SAP security officer
CSSO (Contractor SAP Security Officer) Facility-level contractor SAP security officer; receives failure-to-arm reports for SAPF IDS (DCSA SAP checklist F-28)
CPSO (Contractor Program Security Officer) Contractor program security

Concept approval. UFC 4-010-05 (2-2.2): "DoDM 5205.07 Vol 3 does not require Concept Approval for SAPF. Sponsorship for most SAPFs is formalized at the program level." The Navy is the stated exception, under memo DONSAPCO/0779-22.

TEMPEST. CDSE guidance (2025) notes that the SAPF AO submits plans to a CTTA with the TEMPEST checklist.

Sources DoDM 5205.07 (2025) · CDSE SA501 Student Guide · UFC 4-010-05 (2023) · DCSA SAP Compliance Checklist (Jan 2026) · CDSE FFC short guide

02.06

Site Security Manager (SSM)

In ICS 705-1 and the Tech Spec, SSM means Site Security Manager: the single point of contact to the AO for the security of a construction or renovation project. UFC 4-010-05 (1-14): "Responsible for the security aspects of project planning, design and construction."

Who can serve. In DoD, "An SCI-indoctrinated site security manager (SSM) shall be designated by the component SSO for each new construction or renovation project" (DoDM 5105.21 Vol. 2). The AO determines whether the duties are full-time (Tech Spec 3.A).

What the SSM produces:

Output Requirement Source
Construction Security Plan Developed "in consultation with the AO" for each project; approved by the AO before contract award Tech Spec 3.A–3.B
Risk assessment and SID documentation With the AO, assesses "threats, vulnerabilities, and assets to determine the most efficient countermeasures" Tech Spec 2.A
Periodic security inspections "For the duration of the project" Tech Spec 3.B.4
Violation and deviation notices "Document security violations or deviations from the CSP and notify the AO within 3 business days" Tech Spec 3.A
Compliance advice "Ensure the requirements herein are implemented and advise the AO of compliance or variances" Tech Spec 3.A
Escort ratios (overseas) "Determined by the SSM on a case-by-case basis and documented in the CSP" Tech Spec 4.C
Accreditation documents Assembled from designer and contractor input; "Inspections and evaluations are typically performed by the SSM, or designee, prior to initial accreditation" UFC 4-010-05 1-19.1

DoDM 5105.21 Vol. 2 also calls for 24-hour unrestricted access for inspections.

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2 · SAME 2026, Concept to Clearance (practitioner)

02.07

SSO, SSR and CSSO: running the accredited space

Once a SCIF is accredited, the SSM's role ends and operational security officers take over.

Role Definition Core duties
Special Security Officer (SSO) "Manage the SCI security program and oversee SCI security functions for subordinate SCIFs" (CDSE SCI101, citing DoDM 5105.21) Designates the SSM for DoD projects; maintains SOPs and emergency plans; submits the FFC and TEMPEST addendum through channels; reports posture changes; initiates withdrawal of accreditation
Special Security Representative (SSR) "Under the direction of the SSO, is responsible for the day-to-day management and implementation of the facility's SCI security program" Daily operations; self-inspections
Contractor Special Security Officer (CSSO) Contractor counterpart to the SSO, coordinating through the contracting office and the government SSO (DoDM 5105.21 Vol. 1) SOPs, access rosters, visitor control, FFC and co-use inputs to the government sponsor and AO

Operational requirements (DoDM 5105.21 Vol. 2 unless noted):

  • End-of-day checks recorded on SF 701 (Activity Security Checklist) and SF 702 (Security Container Check Sheet, used for the SCIF door, vaults and containers).
  • "SSO, SSR, or properly SCI-indoctrinated designees will conduct random inspections at least monthly" after duty hours.
  • Emergency action plans exercised annually.
  • "Within 24 hours, the SSO will report to DAC … all changes affecting the security posture of any SCIF."
  • "When a SCIF is no longer required, the local SSO will initiate withdrawal of accreditation."
  • The SSO may allow occasional use of SCIF conference rooms by other organizations for SCI discussion without a Co-Use Agreement (ICS 705-2).

Training (CDSE SCI101). SSOs must attend the SCI Security Officials course within 120 days of appointment, and SSOs train SSRs within 30 days of assignment.

IDS responsibilities (Tech Spec Ch. 7). Only SCI-indoctrinated people change arm or disarm status; failures to arm or disarm are reported and kept two years; the SCI-cleared IDS administrator changes master and maintenance codes from factory defaults.

Sources CDSE SCI101 Student Guide · DoDM 5105.21 Vol. 1 · DoDM 5105.21 Vol. 2 · ICS 705-2 · IC Tech Spec v1.5.1 · ISOO security forms · UFC 4-010-05 (2023)

02.08

Certified TEMPEST Technical Authority (CTTA)

Definition and duty. CTTAs "review SCIF construction or renovation plans to determine if TEMPEST countermeasures are required and recommend solutions" (Tech Spec 3.A.3; ICS 705-1 §J.6). They give "the CSA and AO … documented results of review with recommendations." As far as practicable, TEMPEST mitigation is built into the SCIF design.

CTTA input or output Detail Source
TEMPEST Checklist (input) General information; SCIF equipment and systems (signal lines, power, HVAC and pipes, radios, telecom, existing countermeasures, materials, windows); information processing Tech Spec Ch. 14 form
TEMPEST Countermeasures Review (output) "For an initial TCR, the addendum will be submitted to AO during the planning phase" UFC 4-010-05 1-19.3
RF transmitters Not introduced unless "evaluated and mitigated to be a low risk … by a competent authority (e.g., CTTA) and approved by the AO" ICS 705-1 §G.2.a
Unclassified systems Evaluated by the CTTA and AO for TSCM and TEMPEST concerns ICS 705-1 §G.2.d
Metallic penetrations "May require TEMPEST countermeasures, to include dielectric breaks or grounding, when recommended by the CTTA" Tech Spec 3.G
Perimeter doors Meet TEMPEST requirements per CTTA guidance Tech Spec 3.E.5
Inspectable space Determined by the CTTA Tech Spec (delegated)

DoD. DoD Components coordinate with the CTTA (DIA's CTTA for DoD SCI) when facilities cannot meet compromising-emanations standards (DoDM 5105.21 Vol. 2).

Sources IC Tech Spec v1.5.1 · ICS 705-1 · SCIF TEMPEST Checklist v1.5 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2

02.09

Construction surveillance technicians, cleared guards and escorts

These roles keep uncleared workers, materials and access under control while the perimeter is being built.

Role Definition Clearance What they produce
Construction Surveillance Technician (CST) CSTs "supplement site access controls, implement screening and inspection procedures, as well as monitor construction and personnel, when required by the AO" (Tech Spec 3.A). Overseas they are "specially trained in surveillance and the construction trade to deter technical penetrations and thwart implanted technical collection devices" (Tech Spec 4.C) U.S. TOP SECRET outside the U.S. (Tech Spec 4.C) Surveillance records and logs as the CSP requires
Cleared American Guard (CAG) Screens personnel and materials at the construction access control point and denies prohibited items (Tech Spec 4.C) At least U.S. SECRET Access and screening records
Cleared escort Accompanies and monitors uncleared workers or visitors Appropriate clearance Escort logs

When CSTs are used.

  • Inside the U.S.: only "when required by the AO." CST use and escort ratios are set in the CSP.
  • Outside the U.S., not under Chief of Mission authority: start time depends on threat Category. For Category III, surveillance begins "at the start of SCIF construction or the installation of major utilities, whichever comes first." For Categories I and II it starts earlier, at construction of adjacent public-access or administrative areas.
  • Under Chief of Mission authority (Ch. 5): CSTs are not required when contractors are U.S. citizens with U.S. TOP SECRET clearances.

Escort ratio. "The ratio of escort personnel to construction personnel shall be determined by the SSM on a case-by-case basis and documented in the CSP" (Tech Spec 4.C). Inside an operating SCIF, uncleared visitors must be escorted and SCI secured (DoDM 5105.21 Vol. 2, Encl. 3).

Sources IC Tech Spec v1.5.1 · IC Tech Spec v1.5 · DoDM 5105.21 Vol. 2 · UFC 4-010-05 (2023)

02.10

TSCM teams

Technical Surveillance Countermeasures (TSCM) are inspections to detect technical surveillance devices. ICD 702 is the IC directive for TSCM (cited by 12 FAM 715.7).

Rule Source
TSCM "may be required for new SCIFs or significant renovations" ICS 705-2
Overseas Category I: "a TSCM inspection shall be required for new SCIF construction or for significant renovations (50% or more of SCIF replacement cost)" Tech Spec 4.H
Overseas Categories II and III: at AO discretion Tech Spec 4.H
TSCM may be part of inspections and reviews Tech Spec 12.G.8
TSCM reports, if applicable, are part of the DoD accreditation package DoDM 5105.21 Vol. 2
TSWAs: TSCM may be required if the space was not under continuous SECRET-level control Tech Spec 3.J
Unclassified systems in a SCIF are evaluated for TSCM concerns ICS 705-1 §G.2.d

Who performs TSCM. A practitioner summary of the v1.5 updates quotes Tech Spec 12.G.8 as requiring that TSCM "will only be conducted by USG TSCM teams."

Sources ICS 705-2 · ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · 12 FAM 710 · Armag summary of Tech Spec v1.5 updates (practitioner)

02.11

Sponsors, program managers and co-use tenants

These roles do not build or accredit, but they start projects, own compartments and share space.

Role What it does Source
Government sponsor / supported command Identifies the mission need. "Security begins when the initial requirement for a SCIF is known" Tech Spec 2.A
Commander (DoD) "The commander must submit a request for SCI to the Service Cognizant Security Authority (CSA), their designee, or DoD Component senior intelligence official (SIO)" UFC 4-010-05 2-2.1
Proof of sponsorship "Proof of sponsorship in the form of a SCIF number or written documentation of Concept Approval … is required to establish a SCIF" UFC 4-010-05 2-2.1
CA Program Manager Concurs with the AO's approval of a Compartmented Area Tech Spec 2.C
Host organization Holds the accreditation; the host CSA keeps cognizance unless both CSAs agree to transfer it ICS 705-2
Tenant organization Accepts the host's accreditation; "a tenant that needs modifications pays for them"; contractor requests include an end date ICS 705-2
End user (planning team) Part of the interdisciplinary planning team; a practitioner model lists the CSA/AO, CTTA, SSO, SSM, construction agency and end user UFC 4-010-05 2-4; SAME 2026 (practitioner)

Co-use signatures. The SCIF Co-Use or Joint-Use Request and MOA is coordinated between, and signed by, both parties' AOs or designees. It is not required among components under the same IC element's cognizance, but it is required for each contractor contracting effort (ICS 705-2). In DoD, "Elements accepting co-use must accept current accreditation and any waivers" (DoDM 5105.21 Vol. 2).

See: Accreditation Lifecycle for the Co-Use Agreement process.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · ICS 705-2 · DoDM 5105.21 Vol. 2 · SAME 2026, Concept to Clearance (practitioner)

02.12

Designer of record (architect-engineer)

Role. The A-E translates the AO's requirements into drawings and specifications. Under UFC 4-010-05, the A-E "must provide the SSM the project information needed to develop these documents to support the accreditation process" (1-19.1).

Responsibility Source
Design performed by U.S. companies using U.S. citizens or U.S. persons UFC 4-010-05 1-17
"Validate planning requirements" before design proceeds UFC 4-010-05 3-1
Protect drawings and specifications as the CSP requires; SCIF location and identity handled at minimum as CUI Tech Spec 3.B.2; UFC 4-010-05 4-2
Show perimeter wall types, slab-to-slab details, door schedules, penetration schedules and single-point utility entry Tech Spec 3.C–3.G; UFC 4-010-05 3-4
Make Tech Spec details comply with the building code UFC 4-010-05 3-4.1
Provide inputs to the FFC and TEMPEST addendum (planning and final) UFC 4-010-05 1-19.2–1-19.3
Incorporate CTTA recommendations "into design when practicable" Tech Spec 3.A

Deliverables the SSM will ask for at accreditation (practitioner synthesis of UFC 1-19 and 4-6): as-built floor plans, site plan, IDS specifications and zone map, door and hardware schedule, penetration log, photographs and test reports.

See: Perimeter Construction & Vaults and Penetrations, Utilities & Life Safety.

Sources UFC 4-010-05 (2023) · IC Tech Spec v1.5.1 · SAME 2026, Concept to Clearance (practitioner)

02.13

General contractor responsibilities

The GC does not appear as a named role in ICD 705, but most Tech Spec construction-security requirements land on the GC's jobsite.

Requirement GC implication Source
"Prior to awarding a construction contract, a CSP for each project shall be developed by the SSM and approved by the AO" No notice to proceed on SCIF work before the CSP is approved Tech Spec 3.B.1; UFC 4-010-05 1-15
"Construction plans and all related documents shall be handled and protected in accordance with the CSP" Controlled drawing distribution, marking and disposal Tech Spec 3.B.2
Renovations: barriers segregate workers from operational areas Temporary partitions and controlled routes Tech Spec 3.B.3
"Periodic security inspections shall be conducted by the SSM or designee" Give the SSM access and schedule hold points Tech Spec 3.B.4
Construction "should be performed by U.S. companies using U.S. citizens … but may be performed by U.S. companies using U.S. persons," with AO-ensured mitigations Workforce vetting and documentation Tech Spec 3.B.5
Site access controls: identity verification, random entry and exit searches, prohibited-items signage, barriers, vehicle inspections Jobsite logistics Tech Spec 3.B.6
The AO may impose procedures for procurement, shipping and secure storage of materials Material receiving and storage plan UFC 4-010-05 4-3
Photographic surveillance record of perimeter penetrations, door installations and wall assemblies Photo documentation before concealment UFC 4-010-05 4-7

Overseas. Finish work requires SECRET-cleared U.S. personnel in Category III and TOP SECRET-cleared U.S. personnel in Categories I and II. Non-cleared workers may perform limited tasks under CST or cleared-escort monitoring (Tech Spec Ch. 4).

See: Construction Security & Build Sequence.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · ICS 705-2 · ASI, SCIF accreditation process (practitioner)

02.14

Low-voltage and IDS integrator responsibilities

The integrator's work is some of the most heavily documented in the package, because the IDS is the SCIF's detection layer when nobody is inside.

Requirement Source
IDS installation, components and monitoring stations comply with UL 2050; installation is Extent 3 Tech Spec 7.A.2.a–b; ICS 705-1
Systems built and used by the U.S. Government need no UL certificate but must meet Extent 3 installation requirements Tech Spec 7.A.2.c
Contractor SCIFs maintain a current UL certificate of installation and service; changes after issuance require renewal ICS 705-1
"Installation and testing within the U.S. shall be performed by U.S. companies using U.S. citizens." Outside the U.S.: TOP SECRET-cleared personnel, or SECRET-cleared personnel escorted by SCIF staff Tech Spec 7.D.1; UFC 4-010-05 1-18.1
PCUs located within the SCIF; only SCIF personnel initiate mode changes Tech Spec 7.A.3.b
System variables and passwords restricted to SCI-indoctrinated U.S. personnel Tech Spec 7.A.2.j
Acceptance testing before accreditation; semi-annual testing thereafter Tech Spec 7.A.2.o; 7.D.3
Maintenance personnel TOP SECRET-cleared or escorted; repairs initiated within 4 hours of a trouble signal Tech Spec 7.C.2
DoD package: IDS specification sheets, UL 2050 certificate, NIST encryption certificate, IDS test results DoDM 5105.21 Vol. 2

Access control. Automated ACS uses at least two technologies, and ACS is not approved for securing an unoccupied SCIF (ICS 705-1 §G.2.b). Video inside the perimeter is not allowed under DoD design criteria (UFC 4-010-05 3-4.17.2).

See: Intrusion Detection & UL 2050 / Extent 3 and Access Control, Identity & Hirsch.

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2 · DCSA SAP Compliance Checklist (Jan 2026)

02.15

Authority Having Jurisdiction (AHJ) and life safety

Role. The AHJ (building official and fire marshal) enforces building, fire and accessibility codes. Security requirements do not exempt a SCIF from them.

Intersection Requirement Source
All SCIF doors Must "comply with applicable building code, safety, accessibility standards" as determined by the AHJ Tech Spec 3.E.5
Secondary and emergency egress doors Established per building code, safety and accessibility requirements, with AO approval Tech Spec 3.E.3–3.E.4
DoD projects Comply with UFC 1-200-01 (DoD Building Code), which brings in NFPA 101 UFC 4-010-05 1-9
Delayed egress "Delayed-egress is recommended with NFPA 101 compliance" UFC 4-010-05 3-4.6.10
Egress routing "Egress paths from the lower security areas must not pass through a higher security area" UFC 4-010-05 3-3.3.2
Fire-rated assemblies Fire stop systems may be required at penetrations of rated assemblies UFC 4-010-05 3-4.11.3
FF-L-2890 hardware Engineered to comply with IBC, NFPA 80, NFPA 101 and ADA; the DoD Lock Program says to "check with your local fire marshal (Authority Having Jurisdiction – AHJ) prior to procurement" FF-L-2890C; DoD Lock Program

Practitioner coordination points (not Tech Spec text; confirm with AHJ, AO and CTTA): fire alarm and mass-notification appliances inside the SCIF are life-safety devices whose circuits are also perimeter penetrations reviewed by the CTTA; panels normally stay outside the SCIF; emergency responder access and post-emergency security inspection belong in the SOP.

See: Penetrations, Utilities & Life Safety and Doors, Locks & Security Containers.

Sources IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · FF-L-2890C · DoD Lock Program, pedestrian door deadbolt devices

02.16

Role separation rules and common confusions

Several rules exist specifically to keep roles apart. Violating them invalidates approvals, not just paperwork.

Rule or confusion The accurate position Source
The AO grants waivers No. The waiver official is the IC element head or a single named senior official, and "In no case may this official be the same person as the Accrediting Official." ICD 705
The CTTA approves countermeasures The CTTA recommends; the AO approves and accredits. Tech Spec 3.A; ICS 705-1
The SSM runs the SCIF after accreditation The SSM covers planning, design and construction. Operations belong to the SSO/SSR or CSSO. Tech Spec 3.A; DoDM 5105.21 Vol. 2
DCSA accredits contractor SCIFs No. DIA accredits for DoD and most DoD contractors; NSA, NGA and NRO for their own cognizance. DoDM 5105.21 Vol. 1
"CSA" is one role SCI: Cognizant Security Authority. NISPOM: Cognizant Security Agency. ICS 705-1; 32 CFR 117.3
"CSSO" is one role SCI: Contractor Special Security Officer. SAP: Contractor SAP Security Officer. DoDM 5105.21; DoDM 5205.07
Anyone on the integrator team can program the IDS Mode changes, reset after alarms, and system variables and passwords are limited to SCI-indoctrinated personnel. Tech Spec 7.A.2.j; 7.B.1
The GC can approve minor perimeter changes in the field Deviations go through the SSM to the AO; the SSM notifies the AO of violations within 3 business days. Tech Spec 3.A
A commercial sweep satisfies TSCM Accreditation TSCM is conducted by U.S. Government teams. Tech Spec 12.G.8 (as quoted by a practitioner summary)
The AO can waive a fire code requirement Life-safety compliance is determined by the AHJ. Tech Spec 3.E.5

Sources ICD 705 · ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 1 · DoDM 5205.07 (2025) · 32 CFR 117.3 · Armag summary of Tech Spec v1.5 updates (practitioner)