The precise requirement. ICD 705 (26 May 2010) requires that SCI be handled only in accredited SCIFs, that SCIFs meet uniform Intelligence Community (IC) standards, and that they be built for reciprocal use across IC elements. Facilities must be accredited before SCI operations begin. In DoD terms: "SCI will not be discussed or introduced into the proposed SCIF until the facility is accredited" (DoDM 5105.21 Vol. 2).
What a SCIF is not:
Often confused with
Why it is not a SCIF
A NISPOM open storage area (formerly "closed area")
Protects collateral classified information under 32 CFR Part 117 and is approved by DCSA. SCI cannot be introduced without SCI accreditation.
A GSA-approved security container
A container is storage equipment, not a facility. A closed storage SCIF uses GSA containers inside an accredited perimeter.
A vault
A vault is a construction method (Tech Spec 3.C.5; FED-STD 832). A vault may sit inside or form part of a SCIF.
A "SCIF-ready" or "pre-accredited" modular product
The Tech Spec warns that claims that products "can be accredited without modification may not be accurate."
An RF-shielded room
Shielding is one possible TEMPEST countermeasure the CTTA may recommend. It does not accredit anything.
A SCIF also has a mode (closed storage, open storage, continuous operation) and possibly a lesser type (SWA, TSWA, T-SCIF). Those choices drive alarm response, construction and cost. See: Facility Types, Modes & Overseas Categories.
Four ways classified information is protected, side by side. Figures are the published baselines; many items are left to AO or CSA determination, and exceeding a published standard requires a waiver.
Attribute
SCIF
SAPF
NISPOM open storage area
GSA-approved container
Protects
SCI
Special Access Program (SAP) information
Collateral classified (contractor)
Collateral classified; SCI when inside a closed storage SCIF
Governing documents
ICD 705, ICS 705-1/-2, IC Tech Spec; DoDM 5105.21 in DoD
DoDM 5205.07 (17 Jan 2025), built to the equivalent Tech Spec criteria
32 CFR 117.15; construction per 32 CFR 2001.53; controls per 2001.43
32 CFR 2001.43; DoD Lock Program specs
Who approves
IC element AO (DIA for most DoD and DoD contractors)
SAPF Accrediting Official (SAPF-AO)
DCSA approves the space and the IDS before installation
Container must be GSA-approved; supplemental controls per 2001.43
IDS installation level
UL 2050 Extent 3 (Tech Spec 7.A.2.b)
UL 2050 Extent 3 (DCSA SAP checklist F-30)
Extent 3 baseline; Extent 5 only with CSA approval
No IDS sensors on the container itself (117.15(d)(4))
Alarm response (Top Secret / SCI)
Closed storage 15 min; open storage 15 min with SID, 5 min without
Same as SCIF
TS open storage 15 min with SID, 5 min without
TS: 2-hour checks, or IDS with 15-min response, or SID plus an FF-L-2740 lock
Reciprocity
Mandatory across IC elements if no waivers
May be accredited as a SCIF on review of complete SCIF construction documentation (Tech Spec 1.B.2); co-use needs a CUA
The Fixed Facility Checklist (FFC) is "a standardized form that documents the physical, technical, and procedural security information to obtain accreditation" (UFC 4-010-05, 1-19.2). ICS 705-2 requires the letter of accreditation to state compliance with physical, TEMPEST and technical standards. Every SCIF package therefore proves three things.
Pillar
What must be demonstrated
Typical evidence
FFC v1.5 sections
Physical
The perimeter resists and shows evidence of penetration; doors, locks and penetrations meet the Tech Spec; speech does not leave the room
As-built drawings, wall and penetration details, photographic construction record, door and hardware schedule, acoustic test data
B Security-in-Depth; C SCIF Security; D SCIF Doors; G Acoustical Protection
Technical
Intrusion detection, access control, telecom and emanations risks are controlled
UL 2050 certificate, IDS specification sheets and acceptance test results, encryption certificate, telecom baseline, TEMPEST checklist and the CTTA's countermeasures review
E IDS; F Telecommunication Systems and Equipment Baseline; I INFOSEC/TEMPEST/Technical Security
Procedural
People run the space correctly every day
SOP, emergency plan, Construction Security Plan, destruction methods, visitor and combination control, end-of-day checks (SF 701/702)
A General Information; H Classified Destruction Methods; plus SOP and plans
In DoD, the package also includes a catastrophic failure plan and, where SAP is present, a SAP co-utilization agreement (DoDM 5105.21 Vol. 2).
Every SCIF question in this knowledge base maps onto the same small set of objects. Learn the tree once and the regulations stop looking like a pile of acronyms.
Mission need (SCI access is required)
└── Sponsor / Government customer
└── IC element head (waiver official = a named senior official, never the AO)
└── Accrediting Official (AO) + Cognizant Security Authority (CSA)
└── Facility (SCIF, SAPF, SWA, TSWA, T-SCIF, Compartmented Area)
├── Profile: storage mode · location regime · threat Category · SID
├── Accreditation package
│ ├── Pre-Construction Checklist
│ ├── Construction Security Plan (CSP)
│ ├── Fixed Facility Checklist (FFC, Sections A–I)
│ ├── TEMPEST Checklist → CTTA countermeasures review
│ ├── SOP · emergency plan · catastrophic failure plan (DoD)
│ ├── Test results & certificates (IDS, UL 2050, acoustic)
│ ├── Waiver packages (if any)
│ └── Co-Use Agreement(s) (if any)
├── Security systems
│ ├── Perimeter: walls, floor, ceiling, windows, vault
│ ├── Doors & locks: FF-L-2890 hardware, FF-L-2740 lock
│ ├── IDS: UL 2050 Extent 3, PCU, monitoring, response force
│ ├── ACS: two or more technologies while occupied
│ ├── Acoustics: Sound Group ratings, sound masking
│ ├── TEMPEST / RED-BLACK / RF: as the CTTA determines
│ ├── PED controls: storage, signage, detection
│ └── Telecom: approved phones, cable control, PDS
└── People / roles
├── Construction: SSM · CST · CAG · escorts · A-E · GC · integrator
├── Technical: CTTA · USG TSCM team
├── Operations: SSO · SSR · CSSO
└── Life safety: AHJ
Two relationships matter most. First, authority flows down: the IC element head delegates accreditation to a single named AO, and waiver authority to a different official. Second, evidence flows up: the people and systems at the bottom produce the package that the AO accredits. The next section defines each object.
ICS 705-2 frames accreditation as "the beginning of a life-cycle process of continuous monitoring and evaluation, periodic re-evaluations, and documentation reviews." The Tech Spec is blunter: "Security begins when the initial requirement for a SCIF is known."
#
Step
Key output
Produced by → approved by
1
Requirement and sponsorship
Mission need; sponsorship evidence
Government sponsor
2
Concept approval (DoD SCIF)
Concept approval letter or SCIF number
Command → Service CSA or senior intelligence official
3
Early AO coordination, before design, material orders or contracts are final
Planning team; SSM designated
AO; component SSO
4
Risk assessment and SID documentation
Risk assessment; SID record
AO and SSM
5
Pre-Construction Checklist
Project data for the AO
Project team / SSM → AO
6
TEMPEST Checklist
CTTA countermeasures review
SSM → CTTA → AO
7
Design review
Approved design; preliminary FFC
A-E and SSM → AO
8
Construction Security Plan
Approved CSP before contract award
SSM → AO
9
Construction under surveillance
Inspection reports; photo record; CST logs
SSM, CSTs
10
Systems installation and testing
IDS acceptance tests; UL 2050 certificate; acoustic data
Integrator → SSM → AO
11
Final FFC, SOP, emergency plan
Complete package, no open "TBD" items
SSO/SSM → AO
12
Inspection (and TSCM where required)
Inspection report
AO or designee
13
Accreditation
Letter of accreditation; repository entry
AO
14
Operations and continuous monitoring
Logs, self-inspections, change reports
SSO/SSR/CSSO
15
Periodic re-evaluation, at least every five years
Re-evaluation report reported to NCSC within 30 days
Sometimes misread as a "controlled unclassified area"
A CUA is a signed agreement between AOs, not a space type
AO
Accrediting Official for the facility
Networked IDS on U.S. Government networks also needs an Authority to Operate (ATO) under the Risk Management Framework, a separate cybersecurity approval
Facility accreditation does not grant an ATO, and an ATO does not accredit a SCIF
DAC
DIA's SCI accreditation office, "sole accrediting authority" for DoD permanent SCIFs outside NSA, NGA and NRO cognizance
The expansion is not given in the manual's glossary
Refer to it as DIA's accreditation office
CA
Compartmented Area inside a SCIF (Types I–III)
In SAP usage, "CA" also appears in "CA SAPCO" (Cognizant Authority SAP Central Office)
These are the mistakes that show up in specifications, proposals and marketing copy.
Trap
The accurate version
"The 2020 Tech Spec"
v1.5 carries a 13 Mar 2020 cover date. The current public version is v1.5.1 (26 Jul 2021), which added Chapter 13 (Second Party integree and liaison spaces) and moved Forms and Plans to Chapter 14. Chapter references to forms changed.
"NISPOM closed area"
32 CFR Part 117 "codified requirements for open storage areas and replaced 'closed areas' as an entity" (DCSA Form 147 guide). UL's alarm description form still says "closed area."
"Open storage" means the same thing everywhere
In a SCIF, open storage is an accreditation mode: SCI may sit outside GSA containers inside the SCIF. In NISPOM, an open storage area is a DCSA-approved room for collateral material. Confusingly, the old NISPOM "closed area" was an open storage room.
"Closed storage" = "closed area"
No. A closed storage SCIF keeps all SCI in GSA-approved containers. A legacy closed area stored material in the open.
"DoDM 5205.07 Volume 3 governs SAPFs"
Volume 3 (23 Apr 2015) was cancelled by the consolidated DoDM 5205.07 effective 17 Jan 2025.
"Build to JAFAN 6/9" or "DCID 6/9"
Both are legacy. ICD 705 rescinded DCID 6/9 in 2010. Current SAPF construction follows the Tech Spec through DoDM 5205.07.
"Extent 3 is in the Tech Spec"
Extent 3 is a UL 2050 installation designation. Tech Spec 7.A.2.b requires installation to "comply with an Extent 3 installation as referenced in UL 2050." UL's own definition is in paid standards.
"DCSA will accredit our SCIF"
DCSA does not accredit SCIFs. It administers the NISP for collateral work. DIA provides SCI physical and TEMPEST accreditation for DoD and most DoD contractors; NSA, NGA and NRO handle their own.
"Our site has SID, so response is 15 minutes"
SID is an AO determination, documented in the FFC and CSP. Without accepted SID, open storage needs a 5-minute response.
LA CCTV Supply supports the low-voltage scope of secure-space projects: intrusion detection, access control, video outside the perimeter, and the cabling that connects them. This knowledge base exists so owners, architects, general contractors, installers and security managers share one accurate vocabulary before the first submittal.
What the documents actually require of the low-voltage scope:
Requirement
Source
IDS installation, components and monitoring stations comply with UL 2050; installation is Extent 3
Tech Spec 7.A.2.a–b; ICS 705-1
Contractor SCIFs maintain a current UL certificate of installation and service, renewed after IDS changes
ICS 705-1
IDS installation and testing by U.S. companies using U.S. citizens
UFC 4-010-05 1-18.1
DoD package includes IDS specification sheets, the UL 2050 certificate, the NIST encryption certificate and IDS test results
DoDM 5105.21 Vol. 2
The A-E provides the SSM the project information needed to build the accreditation documents
UFC 4-010-05 1-19.1
Cameras are not allowed within the perimeter or positioned to enable observation within it (DoD design criteria)
UFC 4-010-05 3-4.17.2
What an integrator does not do: accredit the space, approve the design, decide TEMPEST countermeasures (the CTTA recommends them; the AO approves), or overrule life-safety requirements (the AHJ). An integrator also should not self-certify a room as "SCIF compliant."
Reading order. New to secure spaces? Read this module, then Governance & Document Hierarchy, Roles & Responsibilities, Accreditation Lifecycle and Facility Types, Modes & Overseas Categories. Those five modules are the frame; the build modules hang on them.
If you are a…
Start with
Facility owner or sponsor
Accreditation Lifecycle; Facility Types; Traps & Common Failures
Architect / engineer
Perimeter Construction & Vaults; Penetrations, Utilities & Life Safety; Acoustics & Sound Masking
General contractor
Construction Security & Build Sequence; Doors, Locks & Security Containers
Roles & Responsibilities; DISA Traditional Security STIG & PDS; Playbooks: Real-World Scenarios
Callouts. Each label signals a different kind of statement:
Label
Meaning
Trap
A mistake that fails inspection or causes rework
Field note
Practitioner tip for installers and GCs
Plain English
Short explanation for non-specialists
Verify with your AO
The requirement varies by AO or CSA, or is not publicly fixed
Historical
Superseded or FOIA-released material, never a current requirement
Conventions.
Every section ends with Sources linking to the public document it relies on. Paragraph numbers (for example, Tech Spec 3.H) let you find the exact text.
Current versions used throughout: Tech Spec v1.5.1 (26 Jul 2021); ICD 705 (26 May 2010); ICS 705-1 (17 Sep 2010); ICS 705-2 (22 Dec 2016); DoDM 5205.07 consolidated (17 Jan 2025); UL 2050 Ed. 6 (7 Apr 2025); UFC 4-010-05 (26 May 2023).
This is a public-level reference. It names restricted TEMPEST documents but does not reproduce their content, publishes no facility addresses, and shows no filled-in checklists. A completed FFC "may be CUI or Classified depending on contents" (UFC 4-010-05, 1-19.2).