A SCIF, short for Sensitive Compartmented Information Facility and pronounced “skiff,” is an accredited secure room, suite, or building where the U.S. government stores, discusses, and processes its most sensitive intelligence. Every SCIF, whoever operates it, has to meet the same baseline physical and technical security requirements set by Intelligence Community Directive 705.1Intelligence.gov. Intelligence Community Directive 705 – Sensitive Compartmented Information Facilities The purpose is simple to state and hard to engineer: keep anyone without the right clearance and a legitimate reason from seeing, hearing, or intercepting what happens inside.
The Information a SCIF Is Built Around
A SCIF exists to protect Sensitive Compartmented Information, or SCI. SCI is classified intelligence tied to specific sources and methods, and it carries handling controls that go beyond ordinary Secret or even Top Secret markings. A Top Secret clearance by itself does not grant access. You also need formal indoctrination into the particular compartment and a documented need to see the material to do your job.2Department of State Foreign Affairs Manual. 12 FAM 710 Security Policy for Sensitive Compartmented Information
Not every secure space is a SCIF. A vault is built to the highest physical-penetration standard and is designed primarily for storage. A Special Access Program Facility, or SAPF, protects information tied to specific programs rather than intelligence compartments and answers to a different accreditation track. The construction rules overlap heavily, but the categories of information and the approving authorities are different.3Whole Building Design Guide. UFC 4-010-05 SCIF SAPF Planning Design and Construction
Fixed, Temporary, Mobile, and Portable
SCIFs are not always permanent rooms in permanent buildings. They come in four broad forms:
- Fixed SCIFs are permanent installations inside government buildings, military bases, or embassies, supporting day-to-day intelligence work.
- Temporary SCIFs are stood up for a limited period, often for a specific mission or event where a permanent facility is unavailable.
- Mobile SCIFs are built into vehicles, aircraft, or ships and allow secure intelligence work during transit or in the field.
- Portable SCIFs are modular units that can be assembled and torn down quickly for emergencies or short-notice deployments.
The form changes; the standards do not. A temporary SCIF in a hotel conference room has to satisfy the same core ICD 705 requirements as a permanent facility at the Pentagon.1Intelligence.gov. Intelligence Community Directive 705 – Sensitive Compartmented Information Facilities
What Makes a Room a SCIF
ICD 705 and its implementing technical specification (currently Version 1.5, updated in March 2020) spell out how a SCIF has to be built and equipped.4Director of National Intelligence. Technical Specifications for Construction and Management of SCIFs Version 1.5 The rules cover walls, doors, ceilings, sound, locking hardware, alarms, and electromagnetic shielding.
Walls That Stop Sound
SCIF perimeter walls are designed to resist both physical entry and sound leakage. Sound Transmission Class ratings measure how much speech gets through. Standard SCIF walls must reach at least STC 45, at which loud speech inside can be faintly heard but not understood outside. Conference rooms and spaces used for amplified audio or video teleconferencing require STC 50 or better, at which very loud sounds inside are faint or inaudible outside. Sound masking systems can supplement wall construction when the structure alone cannot meet the required rating.5Director of National Intelligence. Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities
TEMPEST Shielding
Electronic equipment emits unintentional signals that, with the right tools, an adversary could intercept and reconstruct into readable data. TEMPEST is the program that addresses this threat through shielding, filtering, grounding, and physical separation of classified and unclassified systems. The specific countermeasures depend on the facility’s threat assessment, but the goal is constant: no usable electromagnetic signal leaves the perimeter.
Locks and Alarms
Entry doors use GSA-approved locking hardware that meets federal specification FF-L-2890, covering electromechanical locks for high-security pedestrian doors.6Center for Development of Security Excellence. DOD-Approved Locks Job Aid Every SCIF also needs an intrusion detection system monitored around the clock, with an immediate response to any alarm.
Devices and Networks Inside
The rule that surprises most first-time visitors: your phone stays outside. Personal cell phones, smartwatches, fitness trackers, wireless earbuds, tablets, and anything else that can record, store, or transmit data is banned from the facility, even powered off or in airplane mode. Implanted medical devices like pacemakers and hearing aids are generally exempt, but anything wireless, Bluetooth-enabled, or microphone-equipped on your person cannot enter without explicit approval from the responsible security officer.
Inside, classified and unclassified computer systems cannot connect to each other. Hard drives, USB sticks, and other storage media cannot be brought in or carried out without being logged and approved by the information systems security officer.7Center for Development of Security Excellence. Sensitive Compartmented Information Refresher Student Guide Even copiers have to be vetted to confirm they do not retain latent images or phone home for diagnostics. Classified material rarely leaves a secure facility through a wall. It leaves on a device someone carried through the door.
SCIFs typically connect to the Joint Worldwide Intelligence Communications System (JWICS), the Top Secret/SCI network that operates continuously for secure multimedia intelligence communication worldwide.7Center for Development of Security Excellence. Sensitive Compartmented Information Refresher Student Guide Some also carry SIPRNet for Secret-level work. No classified system inside touches the public internet, and no unclassified system connects to a classified one. The air gap is absolute.
Who Gets to Go In
Three things are required for SCIF access: a final Top Secret clearance, formal SCI indoctrination into the relevant compartment, and a legitimate need to know the specific information being handled inside.2Department of State Foreign Affairs Manual. 12 FAM 710 Security Policy for Sensitive Compartmented Information SCI access is a separate approval from a Top Secret clearance and depends on a determination that you actually need the information to do your job.8General Services Administration. Sensitive Compartmented Information Facility Use SCIF Policy Everyone with SCI access receives an initial security indoctrination covering handling procedures, physical security, and the criminal penalties for unauthorized disclosure, followed by annual refresher training.
Uncleared personnel, including maintenance workers, cleaning crews, and repair technicians, can enter only after the space is sanitized. Classified discussions stop, SCI documents are covered or locked away, and everyone inside is notified before uncleared people come in. Uncleared visitors must be escorted continuously, at no more than two uncleared people per cleared escort, and classified work stays paused until they leave.2Department of State Foreign Affairs Manual. 12 FAM 710 Security Policy for Sensitive Compartmented Information
Accreditation
No facility operates as a SCIF until it has been formally accredited by an Authorizing Official. Accreditation starts before construction begins. A Site Security Manager is designated as the single security point of contact and develops a Construction Security Plan with the Authorizing Official, spelling out how the project will meet ICD 705 from start to finish. The SSM controls access to the construction site, inspects the work as it progresses, and has to notify the Authorizing Official of any security violation within three business days.9Director of National Intelligence. ICS 705-1 Physical and Technical Security Standards for SCIFs
After construction, the Authorizing Official inspects the facility, may issue interim accreditation while final documentation is completed, and grants full accreditation once everything is in place. The AO also approves the SCIF’s Standard Operating Procedure, which governs day-to-day access, material handling, and alarm response. Re-inspections happen at least every five years.4Director of National Intelligence. Technical Specifications for Construction and Management of SCIFs Version 1.5 Defense contractors can build and operate SCIFs on classified contracts, but the company must first hold a final Top Secret Facility Clearance; an interim clearance is not enough for SCI operations.10Department of Defense. DoDM 5105.21 Volume 3 – SCI Administrative Security Manual
What Happens When Rules Are Broken
Security incidents fall into two categories. A violation involves an actual or likely compromise of classified information, or a serious rule failure. An infraction is a lesser deviation unlikely to cause compromise on its own but still requiring correction.10Department of Defense. DoDM 5105.21 Volume 3 – SCI Administrative Security Manual Consequences are recorded in the individual’s security file and can range from additional training to suspension or revocation of SCI access. Someone whose access is suspended or revoked cannot enter any SCIF without explicit approval from the head of the relevant intelligence community element. If the revocation was “for cause,” re-indoctrination requires a fresh favorable adjudication by the Central Adjudication Facility.
Federal criminal law goes further. Knowingly disclosing certain classified intelligence, such as communication intercepts or details about cryptographic systems, to an unauthorized person carries up to 10 years in federal prison.11Office of the Law Revision Counsel. 18 US Code 798 – Disclosure of Classified Information Removing classified documents from an authorized location and keeping them somewhere unauthorized, even without sharing them, carries up to five years.12Office of the Law Revision Counsel. 18 US Code 1924 – Unauthorized Removal and Retention of Classified Documents or Material A person with authorized access who intentionally reveals the identity of a covert intelligence officer faces up to 15 years, and that sentence runs consecutive to any other, stacking rather than running concurrently.13Office of the Law Revision Counsel. 50 US Code 3121 – Protection of Identities of Certain United States Undercover Intelligence Officers, Agents, Informants, and Sources