SAP vs SCI is a comparison between two different security frameworks that both sit on top of a Top Secret clearance. Sensitive Compartmented Information (SCI) controls access to intelligence based on the sources and methods used to collect it, and it is run by the Director of National Intelligence. A Special Access Program (SAP) wraps additional protections around a specific project, technology, or operation, and it is run by the Secretary of Defense or the head of the sponsoring agency. Neither is a clearance level in its own right. Both add restrictions that limit who can see what, even among people who already hold high-level access.
What SCI Protects
SCI is a subset of classified national intelligence that protects the sources and methods behind the information. NIST defines it as classified information “concerning or derived from intelligence sources, methods, or analytical processes, which is required to be handled within formal access control systems established by the Director of National Intelligence.”1National Institute of Standards and Technology. Computer Security Resource Center Glossary – Sensitive Compartmented Information The DNI’s authority to set uniform standards for SCI access across the intelligence community comes from 50 U.S.C. § 3024.2Office of the Law Revision Counsel. 50 U.S. Code 3024 – Responsibilities and Authorities of the Director of National Intelligence
The organizing idea is compartmentation. Information is sorted into compartments, each representing a different source, collection method, or analytical process. Being cleared for one compartment gives you nothing in another. Two analysts sitting at neighboring desks may be authorized for entirely different compartments depending on their work, and a breach in one compartment does not automatically expose material in others.
Eligibility requires U.S. citizenship, a favorably adjudicated background investigation (historically a Tier 5 using Standard Form 86), and a formal indoctrination before any SCI material is handled. That indoctrination includes a pre-screening interview, a briefing on protection responsibilities, and signing both the standard Classified Information Nondisclosure Agreement (SF-312) and a separate SCI Nondisclosure Statement (DD Form 1847-1), executed before a witness and retained by the government for at least 70 years.3Center for Development of Security Excellence. Student Guide Course – Sensitive Compartmented Information
What a SAP Protects
A SAP builds an additional layer of security around a specific program that needs more protection than a standard Top Secret classification provides. Where SCI organizes intelligence by source and method, a SAP wraps restrictions around a defined thing: a weapons system in development, a clandestine military operation, or a sensitive intelligence activity. Each program runs under its own tailored rules on access, storage, and discussion, and vetting for personnel frequently exceeds the requirements for standard clearances.
SAPs fall into three categories:
- Acquisition (AQ-SAP), which protects sensitive research, development, testing, and procurement, often involving weapons systems or military technology. These make up roughly 75–80 percent of all SAPs.4Center for Development of Security Excellence. Student Guide – Special Access Program Types and Categories
- Intelligence (IN-SAP), which protects the planning and execution of especially sensitive intelligence or counterintelligence operations.
- Operations and Support (OS-SAP), which protects the planning, execution, and support of especially sensitive military operations.
Visibility inside the government also varies by program. Acknowledged SAPs are known to exist and appear in certain budget documents, though their details stay classified. Unacknowledged SAPs are hidden from public view, and the government may decline to confirm they exist. Waived SAPs receive a partial exemption from standard congressional reporting under 10 U.S.C. § 119, with information going only to the chairman and ranking minority member of each defense committee rather than the full committee.5Office of the Law Revision Counsel. 10 U.S. Code 119 – Special Access Programs: Congressional Oversight
The Core Differences
The two frameworks are easiest to keep straight if you separate them along four lines: what they protect, who runs them, how they are organized, and who oversees them.
What they protect. SCI protects the way intelligence was gathered — the satellite capability, the human source, the signals intercept. A SAP protects the thing being built or the operation being conducted. An engineer working on a classified aircraft might hold SAP access for that acquisition program without any SCI access to the intelligence reporting that identified the threat the aircraft was designed to counter. That separation is intentional: a breach on one side stays contained.
Who runs them. SCI access standards are set by the Director of National Intelligence under 50 U.S.C. § 3024, which produces relatively consistent rules across the intelligence community.2Office of the Law Revision Counsel. 50 U.S. Code 3024 – Responsibilities and Authorities of the Director of National Intelligence SAPs run under the authority of the Secretary of Defense and individual agency heads. Within DoD, SAP policy is governed by DoD Directive 5205.07. Because that authority is decentralized, the rules governing one department’s SAPs can differ significantly from another’s.
How they are organized. SCI is organized into compartments defined by source or method; a person cleared for one compartment sees only that compartment. A SAP is organized around a single program; being read into one SAP gives you no access to any other SAP. Both frameworks are strictly need-to-know, but they slice the pie differently.
Who oversees them. SAP oversight runs through the armed services and appropriations committees under 10 U.S.C. § 119, with the waiver mechanism above for the most sensitive programs.5Office of the Law Revision Counsel. 10 U.S. Code 119 – Special Access Programs: Congressional Oversight Covert action oversight, which people frequently confuse with SAP oversight, runs through the intelligence committees under 50 U.S.C. § 3093 and uses the “Gang of Eight” notification structure.6Office of the Law Revision Counsel. 50 U.S. Code 3093 – Presidential Approval and Reporting of Covert Actions SAPs are not covert actions, and the two statutes do not overlap. The broader uniform system for classifying and safeguarding national security information sits under Executive Order 13526.7National Archives. Executive Order 13526 – Classified National Security Information
Where the Two Overlap
SCI and SAP are not mutually exclusive. Many programs exist as a SAP within the SCI system, using the intelligence community’s compartmented structure while adding SAP-level restrictions on top. Holding a Top Secret clearance with SCI access still does not get you into such a program; you also have to be read into the SAP itself. Other programs operate entirely outside the intelligence framework as non-SCI SAPs, answering directly to departmental leadership rather than the DNI.
Day to day, that layering means a single contractor might hold SCI access for one compartment and SAP access for a separate program at the same time, each governed by its own rules, nondisclosure agreements, and chain of authority. Security officers track these overlapping authorizations in specialized databases so no one holds more information than the role requires.
Getting Read In
Both SCI and SAP access start from a Top Secret clearance built on a Tier 5 background investigation covering financial records, criminal history, foreign contacts, employment history, and interviews with associates. The investigation alone does not grant either. Each requires a separate authorization step, and the two paths differ.
For SCI, the indoctrination follows a defined sequence. A security officer reviews the individual’s records, conducts a pre-screening interview, briefs the person on their protection responsibilities, and has them read Executive Order 13526 and the SCI Nondisclosure Statement before signing it in front of a witness. The individual then watches indoctrination videos specific to the compartments being granted and signs an indoctrination memorandum.3Center for Development of Security Excellence. Student Guide Course – Sensitive Compartmented Information
SAP read-in follows a similar concept, but each program tailors its own requirements. The program security officer controls the process, and whether a polygraph is required depends on the program and the sponsoring agency. Some SAPs require a counterintelligence-scope polygraph; others demand a full-scope examination covering both counterintelligence and lifestyle topics. Being read into one SAP grants zero access to any other SAP. Each program is its own island with its own approval chain.
Facilities and Handling
SCI can only be accessed inside a Sensitive Compartmented Information Facility (SCIF). Intelligence Community Directive 705 establishes the uniform physical and technical security requirements for any facility where SCI is processed, stored, used, or discussed.8Office of the Director of National Intelligence. ICD 705 – Sensitive Compartmented Information Facilities The companion technical specification adds measures such as TEMPEST countermeasures on perimeter doors and metallic penetrations, RF-protective window treatments where recommended, and routing all incoming wiring through a single breach point in the SCIF perimeter.9Office of the Director of National Intelligence. Technical Specifications for Construction and Management of SCIFs Personal electronics, cameras, audio recorders, and removable storage media are prohibited inside; policies on where you leave them vary by agency.
SAP-related work may take place in a SCIF or in a separately accredited SAP facility, depending on whether the program falls under SCI. The physical security standards for SAP facilities are at least as stringent, and some programs impose additional requirements on top of what a standard SCIF mandates.
The Short Version
SCI is the intelligence community’s system for compartmenting information by source and method, run by the DNI under a uniform set of standards. A SAP is a program-specific bubble of extra protection run by the Secretary of Defense or an agency head, with rules that vary from program to program. A given project can sit under one, the other, or both. What they share is that each is layered on top of a Top Secret clearance, each requires a separate read-in, and access to one never implies access to the other.