Facility planners routinely conflate TEMPEST and SCIF requirements, and the mistake is expensive. A team that assumes every SCIF needs full RF shielding can over-build a space by hundreds of thousands of dollars; a team that assumes a SCIF accreditation automatically covers emanation security can fail a TEMPEST review late in the project. The two are related but distinct disciplines, governed by different authorities, answering different questions.
The short version: a SCIF is an accredited physical space for handling sensitive compartmented information, while TEMPEST is a set of countermeasures for controlling compromising electromagnetic emanations. You can have one without the other, you sometimes need both, and the overlap between them is exactly where RF shielding lives. This guide draws the line between TEMPEST shielding and SCIF shielding so planners can scope a secure facility correctly the first time.
What a SCIF Is
A SCIF — Sensitive Compartmented Information Facility — is an accredited, access-controlled space built and approved to handle and discuss SCI, with its construction and accreditation governed by Intelligence Community Directive (ICD) 705 and its Technical Specifications. A SCIF's defining requirements are physical: controlled access, intrusion detection, and acoustic protection so conversations cannot be overheard. RF shielding is included only when the facility's threat determination calls for it, which means many accredited SCIFs are not fully RF-shielded.
The accrediting authority for a SCIF is the Accrediting Official (AO), working within the cognizant security authority's framework. The AO signs off that the space meets ICD 705 and is approved for SCI. National Shielding builds to this framework as part of its SCIF and ICD 705 secure-facility shielding practice, and our SCIF construction and ICD 705 shielding requirements guide details what the accreditation actually demands.
What TEMPEST Is
TEMPEST is the codename and discipline covering the study and control of compromising emanations — the unintentional electromagnetic, acoustic, or other signals that electronic equipment radiates and that could be intercepted to reconstruct the information being processed. TEMPEST countermeasures are governed by national-level guidance such as the NSTISSAM and CNSSAM documents, and they aim to ensure that classified information cannot leak through equipment emanations, regardless of the room's physical security.
TEMPEST is fundamentally about emanation security, not access control. Its countermeasures can include equipment selection, RED/BLACK installation separation, zoning to establish inspectable space, and — where required — RF shielding of the space to contain emanations. Crucially, a TEMPEST determination does not always mandate full RF shielding; the required countermeasures depend on the threat and the controlled space around the facility. The authority for TEMPEST is the Certified TEMPEST Technical Authority (CTTA), who performs the analysis and prescribes the countermeasures. Our guide to TEMPEST shielding standards, requirements, and certification covers this in depth, and our TEMPEST shielding page describes how the countermeasures are built.
TEMPEST vs. SCIF: Side-by-Side Comparison
The clearest way to separate the two is to compare them across the dimensions that matter to a facility planner: what each is for, what governs it, who approves it, what it physically contains, and when it is required. The table below does exactly that.
| Dimension | SCIF | TEMPEST |
|---|---|---|
| Purpose | Accredited physical space to handle and discuss SCI | Control compromising electromagnetic emanations from equipment |
| Governing standard | ICD 705 and its Technical Specifications | NSTISSAM / CNSSAM TEMPEST guidance |
| Approval authority | Accrediting Official (AO) / cognizant security authority | Certified TEMPEST Technical Authority (CTTA) |
| Primary focus | Access control, intrusion detection, acoustic protection | Emanation security, zoning, RED/BLACK separation |
| RF shielding | Included only when the threat determination requires it | Required only when the TEMPEST analysis calls for it |
| When required | When SCI will be processed, stored, or discussed in the space | When compromising emanations are a credible interception risk |
The overlap is RF shielding
The two disciplines meet at RF shielding. When a CTTA's TEMPEST analysis for a SCIF determines that emanations cannot be adequately controlled by zoning and separation alone, the countermeasure is to RF-shield the space — and that shielded SCIF now satisfies both a SCIF accreditation requirement and a TEMPEST countermeasure with the same construction. This is why the question "does my SCIF need shielding?" is really a TEMPEST question answered by the CTTA, not a generic SCIF requirement.
When You Need One, Both, or Neither
Because the two requirements are independent, a facility can fall into any of four situations. Knowing which one applies prevents both over-building and dangerous gaps.
- SCIF only (no TEMPEST shielding) — SCI is handled in the space, but the TEMPEST determination finds that zoning and separation control emanations without full RF shielding. Common where the inspectable space around the facility is large.
- TEMPEST only (not a SCIF) — A space processes classified information with an emanation-security requirement but is not an accredited SCIF. TEMPEST countermeasures apply without the full ICD 705 physical-security regime.
- Both — A SCIF whose TEMPEST analysis requires RF shielding. The space carries the full ICD 705 accreditation and an RF shield that doubles as the TEMPEST countermeasure. This is the highest-spec and most expensive case.
- Neither — A secure or shielded room driven by a non-classified requirement (EMC testing, equipment protection, commercial confidentiality) that needs neither SCIF accreditation nor TEMPEST treatment.
The decision is made by the right authorities in the right order: the AO establishes the SCIF requirement, and the CTTA establishes the TEMPEST countermeasures, including whether RF shielding is needed. A planner who engages both early avoids the two classic failures — paying for shielding a SCIF does not need, or discovering a shielding requirement after the room is built. For a broader comparison of secure enclosure types, see our guide to Faraday room vs. SCIF vs. shielded enclosure.
What This Means for Facility Planning
For a planner, the practical takeaway is to treat SCIF accreditation and TEMPEST as two separate scoping questions with two separate authorities, then look for where they converge on RF shielding. Budget and schedule should reflect both determinations, and the design should be built against the actual TEMPEST analysis rather than a blanket assumption that every SCIF is fully shielded. Getting this right early is the difference between a defensible budget and a mid-project surprise.
A contractor experienced in both disciplines can coordinate with the AO and CTTA, build a space that satisfies whichever combination applies, and deliver the acceptance testing that proves it. National Shielding's TEMPEST shielding and SCIF secure-facility shielding practices are built to do exactly that — aligning the construction with the determinations that govern it.
Frequently Asked Questions About TEMPEST vs. SCIF Shielding
What is the difference between TEMPEST and SCIF?
A SCIF is an accredited physical space for handling sensitive compartmented information, governed by ICD 705 and focused on access control, intrusion detection, and acoustic protection. TEMPEST is a set of countermeasures for controlling compromising electromagnetic emanations from equipment, governed by NSTISSAM/CNSSAM guidance. They are distinct disciplines that overlap when a SCIF's TEMPEST analysis requires RF shielding.
Does every SCIF require TEMPEST shielding?
No. A SCIF requires RF shielding only when its TEMPEST countermeasures determination, made by a Certified TEMPEST Technical Authority, calls for it. Many accredited SCIFs rely on zoning, RED/BLACK separation, and inspectable space to control emanations without full RF shielding, which is why assuming every SCIF needs shielding can lead to significant over-building.
Who approves a SCIF versus a TEMPEST requirement?
A SCIF is approved by the Accrediting Official (AO) within the cognizant security authority's framework, confirming the space meets ICD 705 for handling SCI. TEMPEST countermeasures are prescribed by a Certified TEMPEST Technical Authority (CTTA), who analyzes the emanation-security threat and determines the required measures, including whether RF shielding is needed.
Can you have TEMPEST shielding without a SCIF?
Yes. A space can have a TEMPEST emanation-security requirement without being an accredited SCIF, where classified information is processed but the full ICD 705 physical-security regime does not apply. Conversely, a SCIF can be accredited without full RF shielding when its TEMPEST analysis does not require it. The two requirements are independent.
Where do TEMPEST and SCIF requirements overlap?
They overlap at RF shielding. When a CTTA determines that a SCIF's compromising emanations cannot be controlled by zoning and separation alone, the countermeasure is to RF-shield the space. That single shielded construction then satisfies both a SCIF requirement and a TEMPEST countermeasure, which is why the question of whether a SCIF needs shielding is really a TEMPEST determination.
What governs TEMPEST versus SCIF construction?
SCIF construction is governed by Intelligence Community Directive (ICD) 705 and its Technical Specifications. TEMPEST countermeasures are governed by national-level guidance such as the NSTISSAM and CNSSAM documents. A facility that is both a SCIF and TEMPEST-shielded must satisfy both frameworks, with the RF shield meeting the performance the TEMPEST analysis specifies.
How should a facility planner scope a secure space?
Treat SCIF accreditation and TEMPEST as two separate scoping questions with two separate authorities — the AO for the SCIF and the CTTA for TEMPEST — and engage both early. Determine whether the space needs to be a SCIF, whether it has a TEMPEST requirement, and whether the TEMPEST analysis mandates RF shielding. Budget and design against those determinations rather than assuming every secure space needs full shielding.
