TL;DR
TEMPEST controls address the risk of sensitive information leaking through unintentional electromagnetic emissions from electronic equipment inside secure facilities. Not every SCIF requires full TEMPEST implementation, but when they do, those requirements must be designed in from the start — retrofitting is significantly more complex and costly. Recent updates to ICD 705 have elevated TEMPEST requirements significantly, making coordination with experienced security providers more critical than ever.
When it comes to SCIF security, a lion’s share of discussions focus on what can be seen: reinforced walls, controlled access points, intrusion detection systems, and surveillance. Critical components, all. But some of the most significant vulnerabilities in a classified environment are invisible.
Electronic equipment generates electromagnetic emissions as a byproduct of normal operation. Under certain, precise conditions, those emissions can carry sensitive information beyond the boundaries of a secure facility — intercepted by adversaries without ever triggering a physical breach. TEMPEST controls exist specifically to address that risk.
For organizations developing or operating SCIFs, understanding when TEMPEST controls are required — and what they actually involve — is essential to building a facility that can achieve and maintain accreditation.
Defining TEMPEST Controls
TEMPEST is the U.S. government’s program for evaluating and controlling the risk posed by compromising electromagnetic emanations. The acronym originally stood for Telecommunications Electronics Materials Protected from Emanating Spurious Transmissions — but in practice, it refers to the full suite of measures designed to prevent electronic equipment inside a secure facility from broadcasting sensitive data outward.
This is a distinct concern from acoustic protection, which addresses the risk of conversations being overheard. TEMPEST focuses on the signals emitted by electronics themselves — computers, displays, communications equipment, and cabling — and the potential for those signals to be intercepted and reconstructed by a sophisticated adversary outside the facility.
Controls often include:
- RF shielding integrated into walls, ceilings, floors, and doors
- Shielded cabling and conduits throughout the facility
- Power line filtering to prevent signal leakage through electrical systems
- Conductive enclosures and honeycomb steel panels
- Equipment placement and spacing protocols within the facility
- Personnel training and operational procedures
The scope of what’s required for a specific facility is not standardized across all SCIFs — it depends on a formal evaluation by a Certified TEMPEST Technical Authority (CTTA).
When Are TEMPEST Controls Required?
This is the question most organizations ask first. The honest answer? It depends.
Not every SCIF requires full TEMPEST implementation. The requirement is determined through a risk assessment that evaluates the threat environment, the classification level and operational context of the work performed inside the facility, and the physical location and surroundings of the SCIF.
A SCIF located on a secure government campus with significant standoff distance from potential adversary positions carries a different risk profile than one situated in a leased commercial building in a dense urban environment. The latter may require significantly boosted safeguards.
A Certified TEMPEST Technical Authority (CTTA) conducts the evaluation and determines what controls, if any, are required. That determination drives the technical specifications for the facility. Once made, those specifications need to be built in from the start.
The Cost of Getting TEMPEST Wrong
When RF shielding and related controls are treated as something that can be layered in after construction is underway — or worse, after it’s complete — the remediation costs can be substantial.
Regulations are explicit on this point: RF shielding required by CTTA evaluation should be planned for installation during initial construction because costs are significantly higher to retrofit afterward. In practice, retrofitting can mean tearing into finished walls, replacing cabling throughout the facility, and revisiting every penetration point for HVAC, electrical, and communications systems.
The operational consequences compound the financial ones. A facility that can’t achieve accreditation is a facility where classified work can’t happen. Missions pause. Teams languish. Timelines extend in ways that ripple across an entire program.
How the 2025 ICD 705 Updates Elevated TEMPEST Requirements
For organizations operating under legacy SCIF standards, the 2025 updates to ICD 705 represent the most significant shift in roughly 15 years. The Office of the Director of National Intelligence has substantially elevated TEMPEST and RF shielding requirements — making this an active compliance challenge for many existing facilities, not just new construction.
Key changes include:
- Significantly increased RF attenuation requirements, with many facilities now needing to achieve 60dB of RF attenuation
- New TEMPEST specifications integrated directly into ICD 705 rather than referenced separately
- Tightened acoustic protection requirements working alongside TEMPEST controls
- Faster required response times for security incidents involving RF and TEMPEST systems
While the National Counterintelligence and Security Center rescinded the formal POAM (Plan of Action and Milestones) compliance planning requirement in May 2026, the underlying ICD 705 standards — including the elevated TEMPEST and RF attenuation requirements — remain in effect. The rescission removes the planning mechanism, not the compliance obligation. The case for involving a qualified UL 2050 security provider from the outset remains as strong as ever.
TEMPEST Controls Within the Broader SCIF Security Picture
TEMPEST controls don’t operate in isolation. They’re one layer within a comprehensive physical and technical security framework that governs how SCIFs are built and operated. Understanding how TEMPEST fits alongside the other components helps clarify why early coordination across all security disciplines matters.
A fully compliant SCIF typically integrates:
- Physical security — reinforced perimeter construction meeting ICD 705-1 standards
- Access control — badge systems, biometrics, and surveillance supporting controlled entry
- Intrusion detection — UL 2050-certified systems with verified response protocols
- Acoustic protection — sound masking and structural design achieving STC 50+ ratings
- TEMPEST controls — RF shielding, filtered penetrations, and emission security measures
These systems are interdependent. Acoustic protection and TEMPEST controls both influence how HVAC, electrical, and communications systems are designed. Access control and intrusion detection share infrastructure with perimeter construction. Decisions in one area create constraints in another — which is why treating any of these components as a later-phase concern tends to generate problems.
The Role of the CTTA and Accrediting Official
Two roles are particularly important in determining TEMPEST requirements for a specific SCIF: the Certified TEMPEST Technical Authority (CTTA) and the Accrediting Official (AO).
The CTTA conducts a technical evaluation determining whether TEMPEST controls are required and at what level. That evaluation drives the specifications construction and security teams must meet.
An AO reviews the completed facility against all ICD 705 requirements — including TEMPEST — before granting accreditation.
Neither role is optional, and both need to be engaged early in the project. Organizations that bring security providers into the design process after the CTTA has completed its evaluation — without having accounted for those findings in the initial design — often discover that significant rework is required before the AO will begin the accreditation review.
How Secom Supports TEMPEST-Aware SCIF Security
Secom does not build SCIFs or conduct CTTA evaluations. Our role is to secure the facilities that organizations build — and to do it with the expertise that TEMPEST-sensitive environments require.
As one of a select number of providers nationwide authorized to support UL 2050 environments, Secom regularly works within SCIFs, SAPFs, secure containers, and closed areas. Our team understands how TEMPEST requirements interact with the security systems we install and monitor — and we coordinate with the broader project team to ensure our systems support, rather than compromise, the facility’s technical security posture.
That includes:
- UL 2050-certified intrusion detection designed for classified environments
- Access control systems coordinated with facility construction standards
- Surveillance integration that aligns with ICD 705 compliance expectations
- Sound masking systems supporting acoustic protection requirements
- Ongoing DoD and UL 2050 monitoring for long-term operational compliance
Involving Secom early in a SCIF project — before construction documents are finalized — allows our team to identify coordination requirements that could otherwise surface as costly conflicts later. That’s especially important in projects where TEMPEST requirements are driving significant changes to infrastructure design.
Moving Forward
TEMPEST controls are one of the more technically complex areas of SCIF compliance — and one of the most consequential to get wrong. As ICD 705 requirements continue to evolve and updates create new compliance obligations for both new construction and existing facilities, understanding when and where these controls apply has never been more important.
If your organization is planning a new SCIF, evaluating an existing facility for compliance, or navigating the 2025 ICD 705 updates, Secom can help ensure your security systems support every requirement the facility demands.
Reach out to our team today to learn how Secom supports TEMPEST-aware SCIF environments nationwide.
***
FAQs
What does TEMPEST mean in the context of SCIF security?
TEMPEST refers to the U.S. government’s program for evaluating and controlling electromagnetic emissions from electronic equipment inside secure facilities. The goal is to prevent sensitive information from leaking beyond the facility’s boundaries through unintentional signals that could be intercepted externally.
Does every SCIF require TEMPEST controls?
No. TEMPEST requirements are determined through a formal evaluation by a Certified TEMPEST Technical Authority (CTTA) based on the facility’s threat environment, classification level, operational context, and physical location. Some SCIFs require extensive TEMPEST mitigation; others require none beyond standard ICD 705 construction.
Does Secom conduct CTTA evaluations or build SCIFs?
No. Secom secures SCIFs through UL 2050-certified intrusion detection, access control, surveillance, sound masking, and monitoring services. Our team works alongside construction and security teams to ensure our systems support the facility’s full compliance requirements, including those driven by TEMPEST evaluations.