Module 00 · 12 sections

Start Here: How SCIF Security Fits Together

The on-ramp. What a SCIF is, how accreditation works, the object model, the document stack, and the naming traps that trip up project teams.

On this page
  1. 00.01What a SCIF is (and what it is not)
  2. 00.02SCIF vs SAPF vs NISPOM open storage area vs GSA container
  3. 00.03The three things every accreditation proves
  4. 00.04The object model
  5. 00.05Object model reference table
  6. 00.06How the pieces flow from concept to re-evaluation
  7. 00.07Lifecycle states of a SCIF
  8. 00.08The document stack in one table
  9. 00.09Naming quirks: acronyms that mean two things
  10. 00.10Version and terminology traps
  11. 00.11Where a low-voltage integrator fits
  12. 00.12How to use this knowledge base
00.01

What a SCIF is (and what it is not)

The precise requirement. ICD 705 (26 May 2010) requires that SCI be handled only in accredited SCIFs, that SCIFs meet uniform Intelligence Community (IC) standards, and that they be built for reciprocal use across IC elements. Facilities must be accredited before SCI operations begin. In DoD terms: "SCI will not be discussed or introduced into the proposed SCIF until the facility is accredited" (DoDM 5105.21 Vol. 2).

What a SCIF is not:

Often confused with Why it is not a SCIF
A NISPOM open storage area (formerly "closed area") Protects collateral classified information under 32 CFR Part 117 and is approved by DCSA. SCI cannot be introduced without SCI accreditation.
A GSA-approved security container A container is storage equipment, not a facility. A closed storage SCIF uses GSA containers inside an accredited perimeter.
A vault A vault is a construction method (Tech Spec 3.C.5; FED-STD 832). A vault may sit inside or form part of a SCIF.
A "SCIF-ready" or "pre-accredited" modular product The Tech Spec warns that claims that products "can be accredited without modification may not be accurate."
An RF-shielded room Shielding is one possible TEMPEST countermeasure the CTTA may recommend. It does not accredit anything.

A SCIF also has a mode (closed storage, open storage, continuous operation) and possibly a lesser type (SWA, TSWA, T-SCIF). Those choices drive alarm response, construction and cost. See: Facility Types, Modes & Overseas Categories.

Sources ICD 705 · ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · 32 CFR 117.3

00.02

SCIF vs SAPF vs NISPOM open storage area vs GSA container

Four ways classified information is protected, side by side. Figures are the published baselines; many items are left to AO or CSA determination, and exceeding a published standard requires a waiver.

Attribute SCIF SAPF NISPOM open storage area GSA-approved container
Protects SCI Special Access Program (SAP) information Collateral classified (contractor) Collateral classified; SCI when inside a closed storage SCIF
Governing documents ICD 705, ICS 705-1/-2, IC Tech Spec; DoDM 5105.21 in DoD DoDM 5205.07 (17 Jan 2025), built to the equivalent Tech Spec criteria 32 CFR 117.15; construction per 32 CFR 2001.53; controls per 2001.43 32 CFR 2001.43; DoD Lock Program specs
Who approves IC element AO (DIA for most DoD and DoD contractors) SAPF Accrediting Official (SAPF-AO) DCSA approves the space and the IDS before installation Container must be GSA-approved; supplemental controls per 2001.43
IDS installation level UL 2050 Extent 3 (Tech Spec 7.A.2.b) UL 2050 Extent 3 (DCSA SAP checklist F-30) Extent 3 baseline; Extent 5 only with CSA approval No IDS sensors on the container itself (117.15(d)(4))
Alarm response (Top Secret / SCI) Closed storage 15 min; open storage 15 min with SID, 5 min without Same as SCIF TS open storage 15 min with SID, 5 min without TS: 2-hour checks, or IDS with 15-min response, or SID plus an FF-L-2740 lock
Reciprocity Mandatory across IC elements if no waivers May be accredited as a SCIF on review of complete SCIF construction documentation (Tech Spec 1.B.2); co-use needs a CUA Not applicable Not applicable

Sources 32 CFR 117.15 · 32 CFR 2001.43 · IC Tech Spec v1.5.1 · DoDM 5205.07 (2025) · DCSA SAP Compliance Checklist (Jan 2026) · DoDM 5105.21 Vol. 2

00.03

The three things every accreditation proves

The Fixed Facility Checklist (FFC) is "a standardized form that documents the physical, technical, and procedural security information to obtain accreditation" (UFC 4-010-05, 1-19.2). ICS 705-2 requires the letter of accreditation to state compliance with physical, TEMPEST and technical standards. Every SCIF package therefore proves three things.

Pillar What must be demonstrated Typical evidence FFC v1.5 sections
Physical The perimeter resists and shows evidence of penetration; doors, locks and penetrations meet the Tech Spec; speech does not leave the room As-built drawings, wall and penetration details, photographic construction record, door and hardware schedule, acoustic test data B Security-in-Depth; C SCIF Security; D SCIF Doors; G Acoustical Protection
Technical Intrusion detection, access control, telecom and emanations risks are controlled UL 2050 certificate, IDS specification sheets and acceptance test results, encryption certificate, telecom baseline, TEMPEST checklist and the CTTA's countermeasures review E IDS; F Telecommunication Systems and Equipment Baseline; I INFOSEC/TEMPEST/Technical Security
Procedural People run the space correctly every day SOP, emergency plan, Construction Security Plan, destruction methods, visitor and combination control, end-of-day checks (SF 701/702) A General Information; H Classified Destruction Methods; plus SOP and plans

In DoD, the package also includes a catastrophic failure plan and, where SAP is present, a SAP co-utilization agreement (DoDM 5105.21 Vol. 2).

Sources UFC 4-010-05 (2023) · ICS 705-2 · SCIF Fixed Facility Checklist v1.5 · DoDM 5105.21 Vol. 2

00.04

The object model

Every SCIF question in this knowledge base maps onto the same small set of objects. Learn the tree once and the regulations stop looking like a pile of acronyms.

Mission need (SCI access is required)
└── Sponsor / Government customer
    └── IC element head  (waiver official = a named senior official, never the AO)
        └── Accrediting Official (AO)  +  Cognizant Security Authority (CSA)
            └── Facility (SCIF, SAPF, SWA, TSWA, T-SCIF, Compartmented Area)
                ├── Profile: storage mode · location regime · threat Category · SID
                ├── Accreditation package
                │   ├── Pre-Construction Checklist
                │   ├── Construction Security Plan (CSP)
                │   ├── Fixed Facility Checklist (FFC, Sections A–I)
                │   ├── TEMPEST Checklist → CTTA countermeasures review
                │   ├── SOP · emergency plan · catastrophic failure plan (DoD)
                │   ├── Test results & certificates (IDS, UL 2050, acoustic)
                │   ├── Waiver packages (if any)
                │   └── Co-Use Agreement(s) (if any)
                ├── Security systems
                │   ├── Perimeter: walls, floor, ceiling, windows, vault
                │   ├── Doors & locks: FF-L-2890 hardware, FF-L-2740 lock
                │   ├── IDS: UL 2050 Extent 3, PCU, monitoring, response force
                │   ├── ACS: two or more technologies while occupied
                │   ├── Acoustics: Sound Group ratings, sound masking
                │   ├── TEMPEST / RED-BLACK / RF: as the CTTA determines
                │   ├── PED controls: storage, signage, detection
                │   └── Telecom: approved phones, cable control, PDS
                └── People / roles
                    ├── Construction: SSM · CST · CAG · escorts · A-E · GC · integrator
                    ├── Technical: CTTA · USG TSCM team
                    ├── Operations: SSO · SSR · CSSO
                    └── Life safety: AHJ

Two relationships matter most. First, authority flows down: the IC element head delegates accreditation to a single named AO, and waiver authority to a different official. Second, evidence flows up: the people and systems at the bottom produce the package that the AO accredits. The next section defines each object.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · IC Tech Spec v1.5.1

00.05

Object model reference table

Object What it is Who owns it Where it is defined
Sponsor / Government customer The organization with the mission need and contract. DoD SCIFs need proof of sponsorship: a SCIF number or written Concept Approval Government program office or command UFC 4-010-05 2-2.1
IC element head Holds original authority to accredit, re-accredit and de-accredit, and to grant waivers Agency head ICD 705 §D
Accrediting Official (AO) Single named official who approves the design concept, CSP and final design, and accredits the SCIF Delegated by the IC element head ICD 705; ICS 705-1; Tech Spec 3.A
CSA Oversees the security program, re-evaluations and co-use concurrence Agency or Service security office ICS 705-1; ICS 705-2
Facility The accredited space and its profile: type, storage mode, location regime, Security-in-Depth (SID) Host organization ICS 705-1; Tech Spec Ch. 2–6
Accreditation package The documents that prove physical, technical and procedural compliance SSM/SSO assembles; AO approves ICS 705-2 §D.2.a; DoDM 5105.21 Vol. 2
Security systems Perimeter, doors, IDS, ACS, acoustics, TEMPEST, PEDs, telecom Designers and installers build; AO approves Tech Spec Ch. 3 and 7–11
People / roles SSM for construction; SSO/SSR/CSSO for operations; CTTA for TEMPEST; CSTs for surveillance Various Tech Spec 3.A; DoDM 5105.21
IC SCIF Repository NCSC-managed inventory of accreditations, waivers and de-accreditations D/NCSC ICD 705; ICS 705-2

See: Roles & Responsibilities for what each role signs.

Sources ICD 705 · ICS 705-1 · ICS 705-2 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2

00.06

How the pieces flow from concept to re-evaluation

ICS 705-2 frames accreditation as "the beginning of a life-cycle process of continuous monitoring and evaluation, periodic re-evaluations, and documentation reviews." The Tech Spec is blunter: "Security begins when the initial requirement for a SCIF is known."

# Step Key output Produced by → approved by
1 Requirement and sponsorship Mission need; sponsorship evidence Government sponsor
2 Concept approval (DoD SCIF) Concept approval letter or SCIF number Command → Service CSA or senior intelligence official
3 Early AO coordination, before design, material orders or contracts are final Planning team; SSM designated AO; component SSO
4 Risk assessment and SID documentation Risk assessment; SID record AO and SSM
5 Pre-Construction Checklist Project data for the AO Project team / SSM → AO
6 TEMPEST Checklist CTTA countermeasures review SSM → CTTA → AO
7 Design review Approved design; preliminary FFC A-E and SSM → AO
8 Construction Security Plan Approved CSP before contract award SSM → AO
9 Construction under surveillance Inspection reports; photo record; CST logs SSM, CSTs
10 Systems installation and testing IDS acceptance tests; UL 2050 certificate; acoustic data Integrator → SSM → AO
11 Final FFC, SOP, emergency plan Complete package, no open "TBD" items SSO/SSM → AO
12 Inspection (and TSCM where required) Inspection report AO or designee
13 Accreditation Letter of accreditation; repository entry AO
14 Operations and continuous monitoring Logs, self-inspections, change reports SSO/SSR/CSSO
15 Periodic re-evaluation, at least every five years Re-evaluation report reported to NCSC within 30 days CSA/AO
16 Re-accreditation or de-accreditation New letter, or repository de-accreditation notice AO

See: Accreditation Lifecycle for each step in detail.

Sources ICS 705-2 · IC Tech Spec v1.5.1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2

00.07

Lifecycle states of a SCIF

A facility is always in exactly one of these states. Knowing the state tells you what is allowed inside it and what paperwork is live.

State SCI allowed? What defines the state Source
Proposed / concept No Sponsorship and, for DoD SCIFs, concept approval UFC 4-010-05 2-2.1
Under design and construction No Approved design and CSP; site controls in force Tech Spec 3.A–3.B
Interim accreditation (overseas provisions) As the AO's letter specifies AO may issue pending documentation or final inspection Tech Spec 4.I, 5.K
Accredited Yes Letter of accreditation; IC SCIF Repository entry ICS 705-2 §D.1
Accredited with waiver Yes Waiver approved and reported; SCIF loses mandatory reciprocal use ICD 705; ICS 705-1
Co-used Yes, for host and tenant Signed Co-Use Agreement; tenant accepts host accreditation ICS 705-2; Tech Spec 12.N–P
Under re-evaluation Yes Periodic review, at least every five years ICS 705-2 §D.3.a
Re-accreditation required Per AO direction Major modification, program sensitivity change or threat change ICS 705-2 §D.4.b
Suspended or revoked (DoD) No DIA's accreditation office finds security conditions unsatisfactory DoDM 5105.21 Vol. 2
De-accredited / withdrawn No Formal notice via the SCIF Repository; closeout inspection ICS 705-2 §E.5.a; DoDM 5105.21 Vol. 2
De-accredited but held at SECRET No Controlled at the SECRET level for less than one year; may be re-accredited Tech Spec 1.B.1; ICS 705-1

Sources ICS 705-2 · ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · SAME 2026, Concept to Clearance (practitioner)

00.08

The document stack in one table

Layer Document Current public version What it does
Directive ICD 705, Sensitive Compartmented Information Facilities 26 May 2010 Policy: SCI only in accredited SCIFs; AO and waiver authority; reciprocity
Standard ICS 705-1, Physical and Technical Security Standards for SCIFs 17 Sep 2010 The "shall" standards: perimeter, IDS, ACS, TEMPEST, PEDs, telecom; facility types; roles
Standard ICS 705-2, Standards for the Accreditation and Reciprocal Use of SCIFs 22 Dec 2016 Accreditation, re-evaluation, de-accreditation, reciprocity, co-use
Specification IC Tech Spec for ICD/ICS 705 v1.5.1, 26 Jul 2021 The build-to document and its forms: FFC, TEMPEST Checklist, CSP, Pre-Construction Checklist, co-use forms
DoD SCI manual DoDM 5105.21 Vol. 2 19 Oct 2012, Change 2 effective 2 Nov 2020 DoD SCIF physical security, visitor control, technical security
DoD SAP manual DoDM 5205.07, SAP Security Manual 17 Jan 2025 (consolidated; Vol. 3 cancelled) SAPF physical security in Section 15; SAPF-AO
DoD design criteria UFC 4-010-05, SCIF/SAPF Planning, Design, and Construction 26 May 2023 Design detail for A-E and GC teams on DoD projects
Collateral rule 32 CFR Part 117 (NISPOM) and 32 CFR Part 2001 Current eCFR Contractor safeguarding, open storage areas, IDS approval and response
Alarm standard UL 2050, National Industrial Security Systems Edition 6, 7 Apr 2025 Alarm company certification; the Extent 3 installation the Tech Spec requires
State Department 12 FAM 710 series; OSPB standards in 12 FAH-6 Current FAM SCIFs under Chief of Mission authority

See: Governance & Document Hierarchy and the Reference Library.

Sources NCSC Security Governance and Regulations · ICD 705 · ICS 705-2 · DoDM 5205.07 (2025) · UFC 4-010-05 (2023) · UL 2050 Ed. 6 · 12 FAM 710

00.09

Naming quirks: acronyms that mean two things

Secure-space documents reuse abbreviations across regimes. Misreading one can send a submittal to the wrong office.

Term Meaning in ICD 705 / IC documents Other meaning you will meet Why it matters
SSM Site Security Manager: owns security during planning, design and construction and writes the CSP Industry often uses "SSM" or "SCIF security manager" loosely for whoever runs day-to-day SCIF security. That is not a defined term in the ICD 705 set Day-to-day operations belong to the SSO/SSR (government) or CSSO (contractor)
CSA Cognizant Security Authority: the official over the SCI security program NISPOM's Cognizant Security Agency: DoD, DOE, NRC, ODNI, DHS Same letters, different level of organization
CSSO SCI: Contractor Special Security Officer SAP: Contractor SAP Security Officer Check which program's manual the title comes from
CUA Co-Use (co-utilization) Agreement, Tech Spec 12.N–P Sometimes misread as a "controlled unclassified area" A CUA is a signed agreement between AOs, not a space type
AO Accrediting Official for the facility Networked IDS on U.S. Government networks also needs an Authority to Operate (ATO) under the Risk Management Framework, a separate cybersecurity approval Facility accreditation does not grant an ATO, and an ATO does not accredit a SCIF
DAC DIA's SCI accreditation office, "sole accrediting authority" for DoD permanent SCIFs outside NSA, NGA and NRO cognizance The expansion is not given in the manual's glossary Refer to it as DIA's accreditation office
CA Compartmented Area inside a SCIF (Types I–III) In SAP usage, "CA" also appears in "CA SAPCO" (Cognizant Authority SAP Central Office) Read the surrounding program context

Sources ICS 705-1 · IC Tech Spec v1.5.1 · DoDM 5105.21 Vol. 2 · DoDM 5205.07 (2025) · CDSE SCI101 Student Guide · 32 CFR 117.15

00.10

Version and terminology traps

These are the mistakes that show up in specifications, proposals and marketing copy.

Trap The accurate version
"The 2020 Tech Spec" v1.5 carries a 13 Mar 2020 cover date. The current public version is v1.5.1 (26 Jul 2021), which added Chapter 13 (Second Party integree and liaison spaces) and moved Forms and Plans to Chapter 14. Chapter references to forms changed.
"NISPOM closed area" 32 CFR Part 117 "codified requirements for open storage areas and replaced 'closed areas' as an entity" (DCSA Form 147 guide). UL's alarm description form still says "closed area."
"Open storage" means the same thing everywhere In a SCIF, open storage is an accreditation mode: SCI may sit outside GSA containers inside the SCIF. In NISPOM, an open storage area is a DCSA-approved room for collateral material. Confusingly, the old NISPOM "closed area" was an open storage room.
"Closed storage" = "closed area" No. A closed storage SCIF keeps all SCI in GSA-approved containers. A legacy closed area stored material in the open.
"DoDM 5205.07 Volume 3 governs SAPFs" Volume 3 (23 Apr 2015) was cancelled by the consolidated DoDM 5205.07 effective 17 Jan 2025.
"Build to JAFAN 6/9" or "DCID 6/9" Both are legacy. ICD 705 rescinded DCID 6/9 in 2010. Current SAPF construction follows the Tech Spec through DoDM 5205.07.
"Extent 3 is in the Tech Spec" Extent 3 is a UL 2050 installation designation. Tech Spec 7.A.2.b requires installation to "comply with an Extent 3 installation as referenced in UL 2050." UL's own definition is in paid standards.
"DCSA will accredit our SCIF" DCSA does not accredit SCIFs. It administers the NISP for collateral work. DIA provides SCI physical and TEMPEST accreditation for DoD and most DoD contractors; NSA, NGA and NRO handle their own.
"Our site has SID, so response is 15 minutes" SID is an AO determination, documented in the FFC and CSP. Without accepted SID, open storage needs a 5-minute response.

Sources IC Tech Spec v1.5.1 · DCSA Form 147 Guide · DoDM 5205.07 (2025) · ICD 705 · UL CS-ASD-NISS instructions · DoDM 5105.21 Vol. 1

00.11

Where a low-voltage integrator fits

LA CCTV Supply supports the low-voltage scope of secure-space projects: intrusion detection, access control, video outside the perimeter, and the cabling that connects them. This knowledge base exists so owners, architects, general contractors, installers and security managers share one accurate vocabulary before the first submittal.

What the documents actually require of the low-voltage scope:

Requirement Source
IDS installation, components and monitoring stations comply with UL 2050; installation is Extent 3 Tech Spec 7.A.2.a–b; ICS 705-1
Contractor SCIFs maintain a current UL certificate of installation and service, renewed after IDS changes ICS 705-1
IDS installation and testing by U.S. companies using U.S. citizens UFC 4-010-05 1-18.1
DoD package includes IDS specification sheets, the UL 2050 certificate, the NIST encryption certificate and IDS test results DoDM 5105.21 Vol. 2
The A-E provides the SSM the project information needed to build the accreditation documents UFC 4-010-05 1-19.1
Cameras are not allowed within the perimeter or positioned to enable observation within it (DoD design criteria) UFC 4-010-05 3-4.17.2

What an integrator does not do: accredit the space, approve the design, decide TEMPEST countermeasures (the CTTA recommends them; the AO approves), or overrule life-safety requirements (the AHJ). An integrator also should not self-certify a room as "SCIF compliant."

See: Intrusion Detection & UL 2050 / Extent 3 and Access Control, Identity & Hirsch.

Sources IC Tech Spec v1.5.1 · ICS 705-1 · UFC 4-010-05 (2023) · DoDM 5105.21 Vol. 2 · UL National Industrial Security System certification

00.12

How to use this knowledge base

Reading order. New to secure spaces? Read this module, then Governance & Document Hierarchy, Roles & Responsibilities, Accreditation Lifecycle and Facility Types, Modes & Overseas Categories. Those five modules are the frame; the build modules hang on them.

If you are a… Start with
Facility owner or sponsor Accreditation Lifecycle; Facility Types; Traps & Common Failures
Architect / engineer Perimeter Construction & Vaults; Penetrations, Utilities & Life Safety; Acoustics & Sound Masking
General contractor Construction Security & Build Sequence; Doors, Locks & Security Containers
Low-voltage installer Intrusion Detection & UL 2050 / Extent 3; Access Control, Identity & Hirsch; PEDs, Wireless Detection, Telecom & CCTV
Security manager Roles & Responsibilities; DISA Traditional Security STIG & PDS; Playbooks: Real-World Scenarios

Callouts. Each label signals a different kind of statement:

Label Meaning
Trap A mistake that fails inspection or causes rework
Field note Practitioner tip for installers and GCs
Plain English Short explanation for non-specialists
Verify with your AO The requirement varies by AO or CSA, or is not publicly fixed
Historical Superseded or FOIA-released material, never a current requirement

Conventions.

  • Every section ends with Sources linking to the public document it relies on. Paragraph numbers (for example, Tech Spec 3.H) let you find the exact text.
  • Current versions used throughout: Tech Spec v1.5.1 (26 Jul 2021); ICD 705 (26 May 2010); ICS 705-1 (17 Sep 2010); ICS 705-2 (22 Dec 2016); DoDM 5205.07 consolidated (17 Jan 2025); UL 2050 Ed. 6 (7 Apr 2025); UFC 4-010-05 (26 May 2023).
  • This is a public-level reference. It names restricted TEMPEST documents but does not reproduce their content, publishes no facility addresses, and shows no filled-in checklists. A completed FFC "may be CUI or Classified depending on contents" (UFC 4-010-05, 1-19.2).

Sources NCSC Security Governance and Regulations · UFC 4-010-05 (2023) · IC Tech Spec v1.5.1