Physical
The perimeter resists and shows evidence of penetration; doors, locks and penetrations meet the Tech Spec; speech does not leave the room.
Evidence As-builts, penetration details, photo record, door schedule, acoustic test data
Solutions
Resources
Commercial
SCIF & SAPF
Free documents
Company
LA CCTV Supply · SCIF & SAPF security
Layered protection — from perimeter construction and RF control to intrusion detection and access — explained the way accrediting officials, inspectors and installers see it.
01 The basics
A Sensitive Compartmented Information Facility is an area an Accrediting Official has accredited for Sensitive Compartmented Information. Walls, doors, alarms, access control, acoustics and procedures are all evidence — and nothing is “ICD 705 certified” until the facility itself is accredited against its approved design.
The perimeter resists and shows evidence of penetration; doors, locks and penetrations meet the Tech Spec; speech does not leave the room.
Evidence As-builts, penetration details, photo record, door schedule, acoustic test data
Intrusion detection, access control, telecommunications and emanations risks are controlled — and proven by test.
Evidence UL 2050 certificate, IDS acceptance tests, encryption certificates, telecom baseline, CTTA review
People run the space correctly every day — entry, visitors, combinations, end-of-day checks and emergencies.
Evidence SOP, emergency plan, Construction Security Plan, SF 701/702 checks
| Attribute | SCIF | SAPF | NISPOM open storage area | GSA-approved container |
|---|---|---|---|---|
| Protects | SCI | Special Access Program information | Collateral classified (contractor) | Collateral classified; SCI when inside a closed-storage SCIF |
| Governing documents | ICD 705, ICS 705-1/-2, IC Tech Spec; DoDM 5105.21 in DoD | DoDM 5205.07 (17 Jan 2025), built to equivalent Tech Spec criteria | 32 CFR 117.15; 32 CFR 2001.53 & 2001.43 | 32 CFR 2001.43; DoD Lock Program specs |
| Who approves | IC element Accrediting Official (DIA for most DoD & DoD contractors) | SAPF Accrediting Official (SAPF-AO) | DCSA approves the space and the IDS before installation | Container must be GSA-approved; supplemental controls per 2001.43 |
| IDS installation | UL 2050 Extent 3 (Tech Spec 7.A.2.b) | UL 2050 Extent 3 (DCSA SAP checklist) | Extent 3 baseline; Extent 5 only with CSA approval | No IDS sensors on the container itself |
| Alarm response (TS/SCI) | Closed storage 15 min; open storage 15 min with SID, 5 min without | Same as SCIF | TS open storage 15 min with SID, 5 min without | TS: 2-hour checks, or IDS with 15-min response, or SID + FF-L-2740 lock |
Published baselines; many items are left to AO or CSA determination, and exceeding a standard requires a waiver. A DCSA-approved open storage area is not a SCIF, and moving SAP into a SCIF (or SCI into a SAPF) requires a co-use agreement first.
02 Interactive SCIF Explorer
Select any numbered point to see what it is, the numbers that matter and a common mistake that fails inspections. Turn on X-ray to see wall layers and hidden cabling, or press Tour.
03 Security-in-Depth & nested access
Security-in-Depth (SID) is the credit a SCIF earns for the protection around it. The IC Tech Spec lists primary means such as these — and SID is mandatory outside the U.S. It can change alarm response times and construction, but only when the AO documents it.
The one-way rule. Higher access may pass into lower areas; lower never passes into higher. Clearance is not access — need-to-know is decided separately — and UFC 4-010-05 adds that entry into a lower security area cannot be through a higher one.
Lab 01 Access control
Every boundary is controlled on its own. A credential that opens an outer door never opens an inner one, peer compartments don’t open each other, and a clearance is not the same thing as access.
2 Try a door
You are: on the street
Pick a credential, then try a door.
Start outside on the street. Doors must be passed in order, one boundary at a time.
The collateral open storage area and the SCIF are alarmed separately. Only people authorized for an area can change its alarm state, and only SCI-indoctrinated personnel change SCIF modes. Compartments A and B have no alarm system of their own: Tech Spec 2.C.4 says independent alarm systems shall not be installed in a compartmented area, so the SCIF IDS covers them and their doors are access-control boundaries.
Clearance ≠ access
Getting through a door takes the right clearance, formal access to that program, and a need-to-know. IDS and access control codes go only to SCI-indoctrinated people with a need to know.
Two technologies at the SCIF
An automated access control system must use at least two technologies (badge, PIN, biometric). It isn’t approved for securing an unoccupied SCIF: that’s the combination lock plus an armed IDS.
Compartmented areas
A compartmented area separates compartments or programs inside a SCIF. The AO approves it with the CA Program Manager’s concurrence. No spin-dial combination locks go on CA doors, and no independent alarm system is installed in a CA (Tech Spec 2.C.4).
Conceptual model
Anti-passback and separate alarm areas for the open storage area and the SCIF are shown to illustrate layered control. They’re site-configured features, not quoted requirements (whether both areas share one panel is an AO/CSA decision); your AO-approved design and SOP set the real rules.
04 Accreditation roadmap
SCIF projects commonly stumble on sequence: contracts awarded before the Construction Security Plan is approved, penetrations added after the TEMPEST review, walls closed before the photo record. Step through who produces — and who approves — each deliverable.
Lab 02 Accreditation
Six phases, who produces what, who signs, and where projects usually go wrong. Use the arrow keys to move between phases.
Phase 1 of 6
“Security begins when the initial requirement for a SCIF is known.” Confirm there is a sponsor and a need, then find out whether the space can physically become a SCIF.
Phase 2 of 6
Decide what kind of SCIF this is and document the risk. Those choices drive wall type, alarm response, acoustics and TEMPEST review.
Phase 3 of 6
Turn the profile into drawings, a Construction Security Plan and a Fixed Facility Checklist, with the CTTA’s countermeasure recommendations built in.
Phase 4 of 6
No contract award without an approved CSP. Then build with site security, surveillance as the AO requires, and a photo record of everything that gets covered.
Phase 5 of 6
Prove it works, then prove it on paper. Inspectors can’t see inside a finished wall, so the test data and documents carry the case.
Phase 6 of 6
“Accreditation is the beginning of a life-cycle process”: continuous monitoring, periodic re-evaluation and documentation reviews.
05 Perimeter, penetrations & acoustics
The perimeter has two jobs: resist forced entry to the degree the storage mode requires, and show visual evidence of any surreptitious penetration. Every duct, pipe and conduit that crosses it is a designed exception.
Lab 03 Perimeter construction
The IC Tech Spec (Chapter 3.C, Figures 1–3) gives three perimeter wall details. Wall A is the standard; Walls B and C add a forced-entry layer for open storage without Security-in-Depth.
Serves
Designed for Sound Group 3 (STC 45).
Every wall: finished and painted from true floor to true ceiling, so any cut or patch is visible on inspection.
⅝″ gypsum wallboard, 1 layer
Uncontrolled side. The wall uses three layers of ⅝″ GWB in total: one outside, two on the controlled side.
Studs and track
3⅝″-wide 16-gauge metal studs or wood 2×4s on a 16″ o.c. layout (the figure note reads “no less than 16″ on center”). 16-gauge continuous track top and bottom, anchors at 32″ o.c. maximum, bedded in a continuous bead of acoustical sealant.
Acoustic fill
3½″ (89 mm) sound attenuation material, fastened to prevent sliding.
⅝″ GWB, 2 layers
Controlled (SCIF) side, mounted so seams don’t align. Top and bottom sealed with acoustic sealant where the wall meets the slab.
Serves
Same GWB, stud, track, fill and sealant details as Wall A, plus a forced-entry layer.
Every wall: finished and painted from true floor to true ceiling, so any cut or patch is visible on inspection.
⅝″ gypsum wallboard, 1 layer
Uncontrolled side.
Studs, track and acoustic fill
Same as Wall A: 16-gauge studs, 16-gauge continuous track with anchors at 32″ o.c. maximum in acoustical sealant, 3½″ fastened acoustic fill.
Expanded metal
¾″ mesh, #9 (10-gauge) expanded metal affixed to the interior side of all SCIF perimeter wall studs. Spot-welded every 6″ along each vertical stud and at ceiling and floor; hardened screws with 1″ washers or hardened clips may be used instead of welding.
⅝″ GWB, 2 layers
Controlled side, staggered joints, finished and painted true floor to true ceiling.
Serves
Still three layers of GWB, but two go on the uncontrolled side and one covers the plywood.
Every wall: finished and painted from true floor to true ceiling, so any cut or patch is visible on inspection.
⅝″ gypsum wallboard, 2 layers
Uncontrolled side.
Studs, track and acoustic fill
16-gauge studs (the plywood fastens to them), 16-gauge continuous track with anchors at 32″ o.c. maximum in acoustical sealant, 3½″ fastened acoustic fill.
½″ plywood (minimum)
Affixed 8′ vertical by 4′ horizontal to 16-gauge studs with glue and #10 steel tapping screws at 12″ o.c. Must be fire-retardant treated in buildings required to be noncombustible (UFC 3-4.1).
⅝″ GWB, 1 layer
Controlled side, over the plywood. Finished and painted true floor to true ceiling.
Existing masonry
An existing brick, concrete or block wall equal to the perimeter standard may be used, pending AO approval.
Going to STC 50
UFC 4-010-05 associates STC 50 with four GWB layers (two each side) and allows one layer of factory-laminated GWB meeting ASTM C1766 to enhance attenuation.
Security detail, not a fire assembly
The Tech Spec figures aren’t rated assemblies. UFC tells designers to make them comply with the building code. RF foil or foil-backed GWB goes in only when the CTTA recommends it.
Openings over 96 sq in that penetrate the perimeter get permanently fixed ½-in steel bars 6 in on center (or approved baffles) — not required if one dimension is under 6 in — plus an inspection port.
Utilities should enter at one designed location. Other areas’ utilities do not transit the SCIF unless mitigated with AO approval.
Unused conduit is acoustically filled and capped. An open pipe is an open microphone.
Dielectric breaks, grounding and filtering are built exactly as the CTTA’s review and the drawings specify.
Lab 04 Acoustics
SCIF acoustic protection keeps classified conversations from being overheard outside. The Tech Spec expresses it as Sound Groups tied to a wall’s Sound Transmission Class (STC). Slide the rating and watch what reaches the hallway.
Meets the Sound Group 3 target for a discussion room.
Sound Group 3
STC 45 or better · field: NIC 40
Meets
“Loud speech from within the SCIF can be faintly heard but not understood outside the SCIF. Normal speech is unintelligible with the unaided human ear.”
Default for the SCIF perimeter.
Sound Group 4
STC 50 or better · field: NIC 45
Below
“Very loud sounds within the SCIF, such as loud singing, brass music, or a radio at full volume, can be heard with the human ear faintly or not at all outside the SCIF.”
Conference rooms, VTC and other rooms with amplified audio.
Plain English At STC 45 the wall meets Sound Group 3: loud speech may be faintly heard outside but not understood. It isn’t rated for amplified audio.
The lab number isn’t the field result
STC comes from lab tests (ASTM E90). At accreditation, walls and openings are checked in place, by audio test or instrumented test to NIC 40 (Sound Group 3) or NIC 45 (Sound Group 4) per ASTM E336. The AO decides which.
Buy 5 points of margin
Flanking paths (ducts, door gaps, back boxes, deck flutes, unsealed track) pull field performance below component ratings. UFC 4-010-05 asks for lab-tested assemblies of no less than STC 50 for Sound Group 3 and STC 55 for Sound Group 4.
Rooms change use
A room built to Sound Group 3 that later gets VTC needs Sound Group 4. Some practitioners design every discussion area to Sound Group 4 to avoid a retrofit.
Perimeter & vaultsPenetrations & life safetyAcoustics & sound masking
06 Intrusion detection & UL 2050
Most confusion around SCIF alarms comes from mixing up mercantile burglar-alarm certificates with the UL 2050 National Industrial Security Systems program. A SCIF needs the latter.
“Installation shall comply with an Extent 3 installation as referenced in UL 2050.”
IC Tech Spec, paragraph 7.A.2.b
IC Tech Spec Ch. 7 and 3.H. Some items allow an AO-approved alternative — get it in writing.
Lab 05 Alarm response
How fast someone must respond depends on how the SCIF stores material and whether Security-in-Depth covers it. Press play to run a scaled simulation of every clock from the same moment.
Response force
Response force on site within 15 minutes of the alarm.
Ready
Tech Spec 3.H(a)
Within 15 minutes of alarm annunciation when the area is covered by AO-accepted SID.
Ready
Tech Spec 3.H(b)
A five-minute alarm response when there’s no Security-in-Depth.
Ready
Tech Spec 3.H(b)
Follow-up
Arrives within 60 minutes per UL 2050, or the AO-approved time, then inspects, finds the cause and resets the IDS before the response force leaves.
Ready
Tech Spec 7.C.1
Within 4 hours of a trouble signal or service request. Until it’s fixed, SCI-indoctrinated staff occupy the SCIF around the clock unless the AO approves alternate procedures.
Ready
Tech Spec 7.C.2
An alarm is an intrusion until resolved
The response force protects the SCIF under a written support agreement until SCI-indoctrinated personnel arrive.
SID is documented, not assumed
The 15-minute open-storage clock depends on the AO accepting SID. If that layer changes (lobby access control removed, a new tenant mix, a moved fence line), the SCIF may need a 5-minute response. Take it to the AO.
Continuous operation
Tech Spec 3.H doesn’t state a separate IDS response time for continuous-operation SCIFs. Get the AO’s determination in writing.
Intrusion Detection & UL 2050 moduleVetting a UL 2050 alarm company
07 Access control & door hardware
Access control manages who enters during duty hours. When the room is empty, the FF-L-2740B combination lock and the armed IDS protect it. Design the door as one stack, not a pile of parts.
Automated entry uses at least two technologies; DoD design criteria call for a card reader with keypad at the primary entrance. Readers outside the SCIF are tamper-protected.
ACS head-end in the SCIF or in an alarmed area controlled at the SECRET level; no cloud or building-wide server in unsecured space without AO approval.
Reader and panel lines that leave the SCIF are encrypted (FIPS 140 validated) or protected by an AO-approved method.
ACS is not approved to secure an unoccupied SCIF. When empty: FF-L-2740B lock closed and IDS armed; secondary-door ACS shut off.
Electric strikes are UL 1034, fail-secure, and coordinated with the FF-L-2890 hardware the combination lock mounts on.
Entrance cameras supplement access control only; no cameras inside or viewing into the perimeter, and never aimed at keypads or displays.
Platform spotlight
Hirsch (Hirsch Group, formerly Vitaprotech; previously part of Identiv) describes itself as a long-time provider of high-security access control to the U.S. federal government, and its Velocity platform is the one we lead with for secure entrances. What the Hirsch datasheets state, and what the public record shows when you check them:
Hirsch's security management software — from single high-secure rooms to multi-building campuses; Alarm Viewer and Who's Inside views; PIV/CAC/TWIC validation via VCCS. Hirsch ships 3.9, but GSA APL #10103 approves Velocity 3.8.6 with VCCS 3.8.5, CCM/CCMx 8.3.00.73 and SNIB3 4.02.1554 — and Hirsch's own 3.9 release notes point federal customers to that same stack. An APL update is in GSA's test queue. Specify the APL build on federal work, and confirm the build and part numbers at quote.
UL 294 and UL 1076 listed; two-person rule, occupancy counting, door interlocking, anti-passback. On cryptography, ask for a certificate number: the Mx datasheet claims FIPS 140-3 with TLS v1.3, other current Hirsch datasheets describe the same SNIB3 as FIPS 140-2, and NIST's CMVP list shows no validated module for Hirsch or Identiv.
High-security line supervision and alarm masking; supervision measured 100 times per second; SBMS-L2HSS contact meets UL 634 Level 2.
Keypad digits re-scramble on every use with viewing restrictors — protects the PIN that SCIF entrances depend on. UL 294; GSA APL per Hirsch.
Manufacturer claims, not accreditation approvals. No product is “ICD 705 certified.” Final system design, IDS/ACS integration and door hardware are subject to approval by the Accrediting Official / Cognizant Security Authority, and the CTTA where TEMPEST applies. Read the full Hirsch sections.
08 RED/BLACK, EMI filters & shield penetrations
Many SCIFs are not RF-shielded — shielding and other TEMPEST countermeasures are required only when the Certified TEMPEST Technical Authority (CTTA) says so. But any project that processes classified information needs RED/BLACK discipline, and every installer needs to understand how a penetration is made without creating a leak.
Equipment, wiring and signals that carry classified information in the clear. Controlled by the CTTA’s countermeasures — separation, filtering, fiber and inspectable space.
Signals that are encrypted or never classified — the unclassified LAN, building systems, telephones. Kept from coupling with RED.
Why no distances here? Current RED/BLACK installation guidance (CNSSAM TEMPEST/1-13) is a controlled document. Separation and treatment for any facility are set by its CTTA — this site teaches the concepts, never the numbers.
Lab 06 Penetrations & filters
Short answer: at the penetration, and either face. MIL-HDBK-1195 §2.8 puts filters “at the conductor penetration locations, either inside or out, depending usually on available access or space.” Nothing in that section prefers one face over the other for a filter mounted at the penetration. What is not a free choice is everything else. Any wire crossing an RF shield carries RF straight through it, so the filter only works if its case is bonded into the shield and the unfiltered conductors stop there: dirty conductors terminate on the unprotected side, and only filtered conductors carry on into the room. That part is a rule about conductors, not boxes. Both faces are drawn below — switch between them and watch what does and does not change. A filter that cannot sit at the penetration is a different case with its own rules — see “If it can’t go at the penetration” below.
Fails: unbonded case, unfiltered conductors carried inside
Here the feeder runs straight past the filter and on into the room. Any wire through a shield carries RF straight through it, so that unfiltered length re-radiates noise inside the room like an antenna, and it can carry signals out the same way. Note what has not changed: the case is still on the same face. Which way the housing projects was never the fault.
The case is no longer bonded at the shield either. The filter’s capacitors dump RF to the case, so an unbonded case never reaches its rated attenuation — and the dashed envelope in the figure stops dead at the wall instead of closing on the barrier plate, because an unbonded case is not part of the shield.
Fix: unfiltered LINE conductors terminate on the unprotected side, case bonded metal-to-metal (paint-free surfaces, short flat braid) into the shield at the power entry point, and only filtered LOAD conductors continue — through the penetration detail the project specification calls for.
If it can’t go at the penetration: remote mounting
Everything above assumes the filter sits at the penetration. When access, space or gear size forces it away from the shielding surface, MIL-HDBK-1195 §2.8 adds four requirements that do not apply to a filter at the penetration:
MIL-HDBK-1195 is a 1988 handbook scoped to RF shielded enclosures, quoted here to explain the reasoning. Build the detail the shield designer and the project specification call for.
What the manufacturer’s drawing will call these
The figure uses the specification’s names. The submittal on your desk will use the manufacturer’s. ETS-Lindgren’s filter manual has the source conductors brought “through an opening made in the field on the dirty side wiring compartment” and the output conductors brought “into the clean side wiring compartment,” with the filter elements “enclosed in a filter can.” Those are UFGS’s input compartment and load terminal compartment, and the filter can sealed to the barrier plate between them.
Premier’s installation guidance adds the practice points, and they line up with every rule above: “bulkhead mount the filter to the host cabinet,” bonded “via metal-metal connection” with “all surfaces… conductive and void of paint or other insulating material”; “maintain physical isolation and separation between filter input and output wires”; and “make sure that the ground connections are as short as possible.”
Read these as product practice, not as the requirement. Neither manual says which face of a shielded wall the filter goes on — that comes from MIL-HDBK-1195 §2.8 — and neither replaces the project specification. What they are good for is confirming that the arrangement drawn above is the one the industry actually ships, and giving you the words the submittal will use.
Field note Filters store charge. Before touching one: lock out and tag out, wait the discharge time, verify with a meter, and use a shorting stick.
Continuous metal is a fortuitous conductor
Conduit, pipe, duct and cable armor weren’t meant to carry signals, but they can. Unbroken, this pipe is a conductive path across the perimeter.
What it is
A short, listed non-metallic section in a metal pipe, conduit, duct or tray: a dielectric union, insulating flange kit or non-conductive duct connector.
When it’s used
At a non-shielded SCIF perimeter, when the CTTA recommends it. Tech Spec 3.G.2: “Metallic penetrations may require TEMPEST countermeasures, to include dielectric breaks or grounding, when recommended by the CTTA.”
How long, and where
Per the drawings and your AO / CTTA. Don’t take a length from a blog or an old job. At an RF shield the logic flips: every metal penetration is bonded to become part of the shield.
Code Non-metallic sections in sprinkler, gas or rated assemblies must be listed and firestopped. Coordinate with the fire protection engineer and AHJ.
Why it works
Each hexagonal cell is a tiny metal tube. Below its cutoff frequency, RF can’t propagate and decays exponentially along the cell, while air flows straight through. Try the numbers in Lab 02 →
Install
Bond the vent to the shield by solder, braze, weld, or RF gaskets (for example Monel or tin-coated). A gap around the frame undoes the cells.
Coordinate
The mechanical engineer must account for pressure drop. Low-frequency magnetic fields are the hardest to stop, and steel beats brass there.
Never put a conductor through a waveguide
A wire, metallic cable, or fiber with a steel strength member turns the tube into a coaxial line, which has no cutoff. RF passes straight through. PoE copper never goes through the wall.
Why fiber
Light in glass doesn’t conduct or radiate RF, so a fiber link can pass through a waveguide tube without making it a conductor.
No metal in the cable
Use all-dielectric cable: no armor, metal strength member or tracer wire, or have metal elements stripped back outside per the vendor and CTTA.
Power the inside converter
Feed the inside media converter from filtered circuits. Whether a filtered copper data path is acceptable instead is a CTTA call. This solves RF, not security: CNSSI 7003 covers “wire line and optical fiber distribution systems,” so fiber is no exemption from protected distribution. A classified circuit crossing the perimeter still needs a PDS, NSA-approved (Type 1) encryption or an approved CSfC solution, and equipment handling unencrypted classified information belongs inside the accredited space.
Lab 07 RF physics
A bonded metal tube passes air, water or fiber, yet RF well below the tube’s cutoff frequency dies away exponentially along its length. The opening size sets the cutoff; the length sets how much attenuation you get below it.
Educational estimate — your CTTA/shielding engineer sets requirements. This is ideal-tube theory; the shield vendor’s tested design governs.
below cutoff: attenuatesat or above cutoff: propagatesfrequency of concern
Circular, TE11 fc = 1.841·c / (π·D) = c / (1.706·D)
Rectangular, TE10 fc = c / (2·a) a = widest inside dimension
Filled with a dielectric fc ÷ √εr water, εr ≈ 80 → about 9× lower
Attenuation below cutoff α = (2π/λc)·√(1 − (f/fc)²) Np per unit length; A = 8.686·α·L dB
For f ≪ fc A ≈ 32 × L/D (circular) · A ≈ 27.3 × L/a (rectangular)
Never put a conductor through a waveguide
A wire, metallic cable or fiber with a steel strength member turns the tube into a coaxial line. A coax has no cutoff, so this math stops applying.
Theory vs. the real thing
Real limits come from the weld or bond, not the math. Measured honeycomb panels come in far lower than ideal-cell theory: Tech-Etch reports 40–75 dB for ⅛″ cells ½″ deep (chem film), 60–105 dB cross-cell, 100 kHz–10 GHz.
Water is simplified here
The water setting treats εr as a constant 80 and ignores the water’s own losses. Sprinkler and water waveguides must be engineered for the fluid.
Presets Pipe and conduit sizes are nominal; use the measured inside diameter. Hexagonal cells are modeled as circles of the cell size. Preset lengths are example geometry, not requirements.
For installers
A single drywall screw through foil or steel shielding is a hidden leak. Mounting a door contact above a shielded door, running cable to a device or hanging a raceway all have a method that leaves the shield intact.
Mount the high-security switch to the door frame or header on the protected side with the switch maker’s bracket and spacers — never field-drill a shielded frame for a concealed switch.
Unistrut-type standoffs fastened where the shield designer allows keep device weight off the shield.
A furred or secondary stud wall inside the shield becomes the device and cable chase; fasteners go into the furring, not the shield.
Route surface conduit or raceway to the penetration panel. Build each penetration exactly as the shield designer details it.
Stop. Report it. The shielding vendor repairs it and the enclosure is retested as the vendor and CTTA direct — any later penetration means review, then retest.
RED/BLACK, TEMPEST & EMI filtersRF shielding & installer methods
09 PEDs, wireless detection & telecom
A vestibule gives detection its best chance: a known person, a closed space and a few seconds of dwell before the inner door opens. Detection feeds the access control interlock — and egress is never blocked.
Devices stored in lockers outside the primary entrance; signage lists prohibited items.
Credential grants entry; the interlock keeps the inner door locked while the outer door is open.
RF detector evaluates the zone; optional ferrous or metal screening.
Clean: inner reader enabled — card plus PIN still required. Detected: inner grant inhibited, local alert, event to the SCI-indoctrinated monitor.
Sensor network (if fielded) keeps listening; approved medical devices per AO approval.
10 History
From a wartime cipher machine that leaked plain text to today’s ICD 705 Tech Spec. Older documents are listed so you can recognize legacy citations — not so anyone designs to them.
The Bell Telephone 131-B2 cipher mixer is found to leak plain text as electrical spikes — the problem later code-named TEMPEST.
Plain text recovered "about a quarter mile down the signal line."
Early NSA shielded-enclosure specification.
NSA specification later listed as superseded on the undated NSA 89-02 draft shielded-enclosure specification.
"TEMPEST Fundamentals" defines RED and BLACK.
Public paper on video-display eavesdropping brings emanations into open research.
"Specification for Shielded Enclosures" — released on FOIA appeal in December 2000. Historical.
"RED/BLACK Installation Guidance." Historical \u2014 superseded, with its Feb 2000 addendum, by CNSSAM TEMPEST/1-13 (17 Jan 2014).
TEMPEST Countermeasures for Facilities (successor to NSTISSI 7000). Not public.
Signed; rescinds DCID 6/9 and restructures IC facility standards.
Current RED/BLACK installation guidance (date per public listings) — controlled; your CTTA applies it.
Current published IC Technical Specifications for SCIF construction.
Consolidated SAP Security Manual; Volume 3 (physical security) cancelled.
Current edition of the National Industrial Security Systems standard.
11 Inspection killers
Tap a card to see the fix. The full list — 25 killers plus traps by system — is in the knowledge base.
SCIF Answers
345 cited answers across 19 modules, a 218-term glossary and a reference library of official documents. Every section ends with its sources.
12 Free downloads
Public-level primers, a field guide for GCs and installers, an editable readiness questionnaire and a briefing deck. No sign-up.
Educational material. Do not add classified information, CUI or facility addresses to these documents, and share completed questionnaires only through channels your security officer approves.
Technician training portal
LA CCTV Supply technicians and authorized project staff sign in with their existing CRM credentials for requirement-by-requirement design training, submittal workbooks and knowledge checks.
Chapter-by-chapter Tech Spec requirements mapped to IDS, ACS, CCTV, cabling and door hardware submittals.
How the integrator's drawings, battery calculations and test records feed the Fixed Facility Checklist.
Applying CTTA countermeasures in cable plant, power and equipment layouts.
Mounting, routing and hold-point procedures with photo checklists.
Acceptance testing, walk tests, records and certificate coordination.
Scenario quizzes with per-answer explanations and sources.
FAQ
Short versions. Each links into the knowledge base for the cited detail.
Open SCIF AnswersA Sensitive Compartmented Information Facility is an accredited area where Sensitive Compartmented Information (SCI) is stored, used, discussed or processed. It is a combination of construction, security systems and procedures that an Accrediting Official has accredited against ICD 705 and the IC Technical Specifications — not a product you can buy.
A SCIF protects SCI and is accredited under ICD 705 by an Intelligence Community element's Accrediting Official. A SAPF protects Special Access Program information and is accredited by a SAPF Accrediting Official under DoDM 5205.07 (consolidated 17 January 2025), using construction criteria equivalent to the IC Tech Spec. Using one for the other's information requires a co-use agreement.
The IC Tech Spec (7.A.2.b) requires the intrusion detection installation to "comply with an Extent 3 installation as referenced in UL 2050." An extent describes how much alarm protection is installed for an area; UL's form allows Extent 3 for closed areas, and Extent 5 only with prior government approval. The full extent definitions are in the licensed UL standards.
Inside the U.S., within 15 minutes for closed storage. For open storage, 15 minutes when AO-accepted Security-in-Depth exists and 5 minutes without it (Tech Spec 3.H). Overseas SCIFs and continuous-operation SCIFs have different or AO-set times, so confirm with your AO.
No. Shielding and other TEMPEST countermeasures are required only when the Certified TEMPEST Technical Authority (CTTA) determines they are needed after a TEMPEST countermeasure review. SCIFs that process classified information still need RED/BLACK installation discipline.
At the penetration, and either face. MIL-HDBK-1195 §2.8 puts filters “at the conductor penetration locations, either inside or out, depending usually on available access or space,” with no TEMPEST preference between the two faces. What is not a free choice is the conductors and the bond: the case is bonded metal-to-metal into the shield plane so it closes the hole it occupies; the unfiltered LINE conductors terminate on the unprotected side and never cross, and only the filtered LOAD conductors continue into the room. So it is a rule about conductors, not boxes. The sentences that follow in §2.8 open a different case — a filter mounted remotely from the shield — and it is that case that requires continuous metal conduit, puts TEMPEST conduit runs inside the enclosure, and requires a controlled access area when the remote filter sits outside. The clean-side penetration detail follows the project specification — welded pipe on most government work, a compressed RF gasket on many commercial rooms. And all of this is the shielded-enclosure case: at a non-shielded SCIF perimeter there is no shield plane to bond into, and the grounding and bonding detail comes from the CTTA, the engineer of record and the drawings.
No. When the SCIF is unoccupied it is secured by the FF-L-2740B combination lock and the armed intrusion detection system. Access control manages entry during duty hours, and access control on secondary doors is shut off when the SCIF is empty.
No. Products may carry listings such as UL 294, UL 634 or UL 639, or appear on the GSA FIPS 201 APL, but the facility is what gets accredited — by the AO, against the approved design.
Bring your drawings and your AO’s requirements. We’ll help you plan the low-voltage scope — intrusion detection, access control, cabling and door hardware coordination — before the walls go up.
Please don’t send classified information, CUI or facility addresses through web forms or unencrypted email.