Skip to content
Capability/Classified & Special Access

SAP & SCI Programs

Special Access Program and Sensitive Compartmented Information

01 / Overview

Special Access Programs and Sensitive Compartmented Information require enhanced security controls beyond standard classified handling. Thalorin supports SAP/SCI programs with specialized compliance workflows addressing compartmentalization, access control, and the unique documentation requirements of these programs.

Enhanced security for Special Access Programs and Sensitive Compartmented Information reaches a cleared contractor through 32 CFR 117.23, the supplement to the NISPOM rule. The wording is the part that matters: the requirements prescribed in that section exceed baseline standards for the rule and must be applied, as applicable, through specific contract requirements. None of it is inherited from a facility clearance — it arrives attached to an award. DoD Manual 5205.07, the Special Access Program Security Manual, was reissued in January 2025 and governs the government side; what binds industry is whichever of those requirements the contract actually names.

Two accrediting authorities then sit over one construction standard. A SCIF is accredited under ICD 705, which implements ICS 705-1, ICS 705-2 and the IC Tech Specs for the construction and management of SCIFs. A SAP facility is accredited in writing by the cognizant Program Security Officer under Department of Defense SAP policy, which adopts the same technical specifications. ICS 705-2 then requires an accredited SCIF to be accepted reciprocally without re-inspection — but only where it carries no waivers to those standards. Reciprocity therefore rests on a construction record, and most programmes never index one.

What gets underestimated is that the evidence inherits the compartment. A control implemented once may satisfy three programs, but the artifact proving it lives inside whichever program produced it, visible to that authorizing official and no other. The same control is therefore built, assessed and closed three times, and nobody is positioned to see the duplication. The recurring cost is not the control; it is the reconstruction, and it returns at every accreditation and every annual review.

Holding one control state and projecting it per compartment is the part of this a platform can honestly do. Thalorin records where an implementation is common across programs and where a compartment genuinely diverges, binds each artifact to the asset and the accreditation that consumed it, and carries facility waivers as first-class objects — because under ICS 705-2 a waiver is what decides whether a neighbouring element must inspect the facility for itself.

02 / Challenges

Classified environments require extraordinary controls

A waiver ends reciprocal use

ICS 705-2 requires an accredited SCIF to be accepted without re-inspection only where it carries no waivers to ICS 705-1, ICS 705-2 or the IC Tech Specs. One recorded deviation restores the inspection.

The SAP baseline still sits on Revision 4

The Joint SAP Implementation Guide in public circulation is dated 11 April 2016 and written against NIST SP 800-53 Revision 4. A contractor whose collateral estate runs Revision 5 keeps two catalogues for one control.

Evidence inherits the compartment

An artifact produced inside one program is visible to that program's authorizing official and to nobody else. The same control is implemented, assessed and evidenced repeatedly, and the duplication is structurally invisible.

Eligibility is not program access

SCI eligibility, or a Top Secret clearance, establishes only that a person may be considered. Access to a named compartment or Special Access Program is a separate determination with its own indoctrination and debriefing record.

03 / Capabilities

How Thalorin helps

DoD SAP policyICD 705DCID 6/3

SAP security control overlays

Derive the baseline from the CNSSI 1253 categorisation and apply the overlay the SAP authorizing official expects, keeping the mapping back to NIST SP 800-53 identifiers explicit.

SCI compliance documentation

Assemble the body of evidence an ICD 503 security authorization expects — categorisation, control implementation, assessment results, residual risk — from live state rather than by hand for each authorizing official.

Compartment-specific controls

Record which implementations are common across programs and which genuinely diverge by compartment, so one program's extra requirement does not become a separate control set for all.

Access determination support

Track eligibility, program access and the determination joining them as distinct facts, since a Top Secret clearance with SCI eligibility is a precondition for access, not a grant.

Indoctrination tracking

Hold the indoctrination, nondisclosure and debriefing record per person per compartment — SF 312 for collateral, IC Form 4414 for SCI, the program instrument for a SAP.

SAP facility compliance

Carry each SCIF and SAP facility accreditation with its construction documentation, the IC Tech Spec version it was built against, and any waivers that govern reciprocal use.

Questions

SAP & SCI Programs: common questions

Does a SCIF accredited by one agency transfer to another?

Yes, with one condition. ICS 705-2 provides that a SCIF accredited by an Intelligence Community element authorizing official is reciprocally accepted without re-inspection, provided there are no waivers to ICS 705-1, ICS 705-2 or the IC Tech Specs. Shared use is then arranged through a co-utilization agreement rather than a fresh accreditation. In practice the waiver clause is what breaks reciprocity: a deviation accepted during construction leaves every other element free to inspect for itself.

Is DCID 6/3 still the standard for SCI information systems?

No. ICD 503 rescinded and replaced DCID 6/3 and its associated manual, effective 15 September 2008, moving Intelligence Community systems onto risk management and, by later technical amendment, onto security control assessment and security authorization terminology in place of certification and accreditation. DCID 6/3 nonetheless survives in contract language, inherited requirements documents and legacy system security plans. Where the reference appears, the useful question is which current requirement the drafter was standing in for.

Which control baseline applies to a DoD SAP information system?

Categorisation comes from CNSSI 1253 and implementation guidance from the Joint SAP Implementation Guide, applied under a SAP authorizing official rather than the DCSA process that governs collateral contractor systems. The JSIG edition in public circulation is dated 11 April 2016 and is written against NIST SP 800-53 Revision 4, which NIST superseded with Revision 5 in September 2020. Confirm the edition your authorizing official assesses against before mapping anything, because control identifiers moved between revisions.

Does SCI eligibility give access to a specific compartment?

No. Eligibility is a determination that a person may be granted access. Access to a named compartment or Special Access Program is a separate decision made by the office that owns the material, on need to know, and it does not travel between programs. Each access carries its own indoctrination, nondisclosure instrument — SF 312 for collateral, IC Form 4414 for SCI — and debriefing. Treating a clearance record as an access roster produces the stale list found at inspection.

What is the difference between a SCIF and a SAP facility?

The construction standard is largely shared; the authority is not. Both are built against the IC Tech Spec for ICD/ICS 705, and planning and design guidance sits in Unified Facilities Criteria 4-010-05. A SCIF is accredited under ICD 705 by an Intelligence Community authorizing official. A SAP facility is accredited in writing by the cognizant Program Security Officer under Department of Defense SAP policy, and adds program-specific access control and compartmentation on top of the physical standard.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about SAP & SCI Programs.

See how one evidence artifact satisfies SAP & SCI Programs requirements alongside every other framework you carry.