Shielding guide

TEMPEST vs ICD 705: What Each One Actually Governs

ICD 705 makes every SCIF meet uniform physical and technical security requirements. TEMPEST is a separate emissions-security discipline, applied per project only when a Certified TEMPEST Technical Authority determines countermeasures are needed.

Reviewed as of August 2026Primary topic: tempest vs icd 705
Illustration of a technician operating a heavy shielded vault door in a secure corridor with copper wall panels

TEMPEST is a discipline, not a sticker

NIST defines TEMPEST as the investigation, study, and control of unintentional compromising emanations from telecommunications and information systems equipment. The emanations in question are signals that, if intercepted and analyzed, would disclose the information the equipment was handling. [3]

That definition matters because it describes an analytical practice, not a product rating. Emissions security is the countermeasure side of that practice, and what any given room needs is an output of analysis rather than a fixed specification you can order. [3]

What ICD 705 actually governs

ICD 705 is the Intelligence Community directive requiring that all SCIFs comply with uniform physical and technical security requirements, so that SCI is protected and facilities can be used reciprocally across the community. All SCI must be processed, stored, used, or discussed in an accredited SCIF. [1]

The four-page directive itself contains construction detail at the policy level only; the implementing document is the IC Technical Specifications for the construction and management of SCIFs. Among the Tech Spec's stated purposes is protecting SCI against compromising emanations, which is where the directive and the discipline meet. [1][2]

The CTTA makes the TEMPEST call

Under the IC Tech Spec, a Certified TEMPEST Technical Authority reviews SCIF construction or renovation plans, determines whether TEMPEST countermeasures are required, and recommends solutions, providing the accrediting officials documented results of that review. To the maximum extent practicable, mitigation is incorporated into the SCIF design itself. [2]

The determination is risk-based and per facility. The same directive-compliant room can require extensive countermeasures on one site and none on another, because the threat environment, location, and equipment differ even when the floor plan does not. [2]

Where RF shielding enters on each side

The Tech Spec's own TEMPEST checklist asks whether the CTTA required any countermeasures, and lists radio frequency shielding as one option among non-conductive sections, power and signal line filters, and window film. A SCIF can be fully accredited under ICD 705 with no RF shielding at all, because the checklist explicitly allows a no-countermeasures outcome. [2]

So the two drive shielding differently. ICD 705 and the Tech Spec set the baseline physical build every SCIF must meet, while an RF enclosure is a conditional layer that exists on a project only when the emanations analysis calls for it. [1][2]

Illustration of a copper-lined shielded enclosure inside a secure facility hall, with a radome visible outside

What this means for a project team

Specifying a generic TEMPEST-certified room is asking for something the governing documents do not define. The buildable question is which authority owns the emanations determination for this project, what that authority requires, and how the required countermeasures integrate with the SCIF design before walls close. [2][3]

The determination comes out of a review of the construction or renovation plans, and the Tech Spec directs that mitigation be built into the SCIF design to the maximum extent practicable, so countermeasures belong in preconstruction planning rather than after the base scope is set. The honest position early on is that the project implies a SCIF build, with RF performance still to be determined by the authority that owns it. [2]

The Longlead connection

How Longlead AI helps

Longlead AI reads dated public records and surfaces projects that may create demand for a specialist's scope — typically 9–18 months before the GC buys out that scope on major federal projects, depending on the signal and project. Every opportunity carries its source, and where the record supports one, an estimated lead-time window. Longlead prepares a cited qualification brief that names the likely counterparty where the record identifies one; the customer makes the call from its own channels, and nothing leaves the system.

Official sources

  1. [1]Intelligence Community Directive 705 — Sensitive Compartmented Information FacilitiesOffice of the Director of National Intelligence
  2. [2]Technical Specifications for Construction and Management of SCIFs, Version 1.5National Counterintelligence and Security Center
  3. [3]Computer Security Resource Center glossary — TEMPESTNational Institute of Standards and Technology

FAQ

What is TEMPEST?
TEMPEST is the investigation, study, and control of unintentional compromising emanations from telecommunications and information systems equipment, per the NIST glossary definition. It is an emissions-security discipline, not a product certification.
Is every SCIF TEMPEST shielded?
Not every SCIF carries TEMPEST countermeasures. A Certified TEMPEST Technical Authority reviews each SCIF project and determines whether countermeasures are required, and the IC Tech Spec's checklist explicitly allows an outcome where none are.
What is a CTTA?
A CTTA is a Certified TEMPEST Technical Authority, the official who reviews SCIF construction or renovation plans, determines whether TEMPEST countermeasures are required, and recommends solutions to the accrediting officials.
Is TEMPEST part of ICD 705?
TEMPEST is a separate discipline that SCIF projects encounter through ICD 705's implementing technical specifications. The directive governs uniform physical and technical SCIF security, while TEMPEST countermeasures are a distinct risk-based determination made per facility.

Keep learning

Find the demand behind the public record.

Tell us what you sell and see the dated signals Longlead is watching for your scope.