ICD 705 is undergoing its first major technical overhaul since 2010, and the changes reach further than most facility teams expect. RF and TEMPEST attenuation rules are tightening, acoustic protection standards are stricter, and legacy SCIFs face real compliance gaps that may require architectural rebuilds.
Craig Reifsteck, former Chief of Special Security Programs at ODNI, and Dr. Brett Walkenhorst, CTO of Bastille, walk through the history and intent of the standard, what is actually changing in the 2025 overhaul, and where continuous wireless monitoring fits alongside shielding. The session closes with an extended Q&A covering release timing, the three meter perimeter guideline, O.MG cables, temporary secure working areas, smart glasses, and how to phase a rebuild while staying operational.
Video Summary
ICD 705 sets the physical and technical standards for SCIFs: construction, shielding, TEMPEST, and RF attenuation requirements meant to prevent signal leakage. Its lineage runs from DCID 1/21 in 1994 through DCID 6/9 in 2002, both of which still left each IC element accrediting facilities differently. ODNI issued ICD 705 in May 2010 to put everyone on one standard and enable reciprocity, and DoD came on board in 2016. The modernization that began in 2025 is the first substantial overhaul of that baseline.
What changes: RF and TEMPEST attenuation move from compliance support to mandatory, and acoustic standards tighten around STC compliance and sound masking to block acoustic and vibration harvesting. Many existing SCIFs face a real compliance gap, and some will be looking at full architectural rebuilds. Three drivers explain the timing. Adversaries now have far more capable remote sensing, low power RF probes, and signal capture tools than existed in 2010; those tools have dropped in cost to the point of being bought online for a fraction of what they used to cost; and classified workloads keep spreading into defense contractor and federal facilities that never saw themselves as part of the IC footprint.
Shielding attenuates signal, but it does not tell you what is emitting inside the space, and devices carried through the door operate on the wrong side of the shielding. Bastille addresses that with a physical layer approach: passive software defined radio sensor arrays that scan from 25 MHz to above 6 GHz, covering Wi-Fi including 6E up to 7.125 GHz, Bluetooth Classic and BLE, cellular, Zigbee and other IoT protocols. The sensors decode packet headers into metadata, then localize every emitter to within one to three meters indoors. They are plenum rated, have no moving parts, fail gracefully, and are FCC certified as passive, meaning they add no transmissions of their own to a space where that matters.
Both speakers are direct about the limits: continuous monitoring is not a substitute for shielding and does not by itself satisfy ICD 705. Craig frames it as a mitigation rather than a remediation, something to negotiate with your AO and CTTA when a facility cannot yet fund a retrofit. The value sits above compliance: knowing where a violation is, being able to adjudicate it, and holding an auditable record rather than relying on a passive deterrent.
Key Takeaways
- ICD 705 is in its first major technical overhaul since May 2010, begun in 2025, with release expected to slip into 2026
- RF and TEMPEST attenuation shift from compliance support to mandatory, and acoustic protection tightens around STC compliance and sound masking
- Many legacy SCIFs face a genuine compliance gap and may require full architectural rebuilds rather than incremental upgrades
- The trigger for the standard is not who owns the building, it is who accredits the facility and whether SCI is processed, stored, used, or discussed there
- Classified workloads are spreading into defense contractor sites that never considered themselves part of the IC footprint, and accreditation requirements follow the information
- Shielding reduces signal leaving the space but says nothing about what is emitting inside it, and devices carried through the door sit on the wrong side of that shielding
- Customers are consistently surprised by how much the system finds immediately on deployment in facilities they believed were clean
- Sensor arrays cover 25 MHz to above 6 GHz, including Wi-Fi 6E to 7.125 GHz, Bluetooth Classic and BLE, cellular including LTE and 5G, and 802.15.4 based protocols
- Monitoring in a SCIF or SAPF must be RF passive; Bastille sensors are FCC certified as passive and introduce no transmissions of their own
- Indoor localization to within one to three meters is what turns a detection into an actionable alert, often narrowing it to the desk rather than just the room
- Continuous monitoring is a mitigation, not a remediation, and not a replacement for the shielding requirements in ICD 705
- Detection data doubles as a supply chain control, immediately flagging equipment that arrived carrying Wi-Fi or Bluetooth it was not supposed to have
- Smart glasses are the hardest case: visually innocuous, recording LEDs can be defeated, and the transmission is the only reliable tell
- A three meter guideline from SCIF perimeter walls remains in play, with AOs and CTTAs collaborating on how it applies to a given project
Featured Speakers
Craig Reifsteck
Craig Reifsteck is with Eagle Ray Services and spent three decades in the Intelligence Community, DHS, and Treasury, with deep expertise in SCI program development, TSCM/TEMPEST operations, and classified facility accreditation.
Brett Walkenhorst, Ph.D.
Dr. Walkenhorst is the CTO of Bastille with over 20 years of experience in RF systems and signal processing, previously leading R&D at Lucent Bell Labs, GTRI, NSI-MI Technologies, Silvus Technologies, and Raytheon.
Transcript
Welcome and Introductions
Justin: Thank you for joining our webinar today, The Wireless Blindspot: The Evolution of ICD 705 and Top Security Measures. My name is Justin Fry, I’m the CMO here at Bastille. Before we start the event, some housekeeping. We’ll have a Q&A session at the end of the webinar, but you can ask questions at any time using the Q&A button at the bottom of the Zoom interface. If you should have any technical issues with the webinar, please use the chat button to let me know. As always, a recording of the webinar will be made available later this week.
And now on to our speakers, Craig Reifsteck and Brett Walkenhorst. Craig is a former Chief of Special Security Programs at ODNI. Craig is an expert in SCI program development, TSCM and TEMPEST operations, and the integration of emerging security technologies to safeguard sensitive environments. Dr. Brett Walkenhorst is the Bastille CTO. Brett is the former director of the Software Defined Radio Lab at Georgia Tech and works closely with all our government and enterprise customers. Today Craig and Brett will guide you through the history of the ICD 705 standards, examine how today’s risks are different, and summarize best practices for protecting sensitive environments. Thank you both. Craig, over to you.
Roadmap for the Session
Craig: Thank you, Justin. Let me give you a quick roadmap of where we’re heading today. We’ll be moving through three parts. Part one is a fast introduction to ICD 705. What is it? How did it come about? Who does it apply to? Part two will be Brett walking through why wireless has become such a pressing blind spot for facilities, around the old assumptions of building a SCIF. Part three is the overhaul of ICD 705, what changes are actually happening, and what it means for your compliance timeline. Then we’ll close with a summary and open it up to your questions.
What ICD 705 Is and Where It Came From
Craig: ICD 705 is focused on Sensitive Compartmented Information Facilities, SCIFs, and their physical and technical standards, which define the construction, shielding, TEMPEST, and RF attenuation requirements to prevent signal leakage. The key here is integrating systems and processes to manage a secure environment, a happy balance. When was the last time someone looked at an alarm log or identified an anomaly? Our adversaries are always playing against those types of weaknesses, and it is important to understand the story for your security and your facility.
The lineage goes back to DCID 1/21 in 1994, the first IC wide physical security standard for SCIFs, managed by CIA. That was succeeded by DCID 6/9 in 2002. Even with those directives, each IC element still accredited SCIFs somewhat differently, so as a facility builder, one agency often couldn’t reuse another’s without rebuilding. ODNI rescinded DCID 6/9 and issued ICD 705 in May of 2010, putting everyone on the same standard, which then enabled reciprocity across the community. The DoD came on board in 2016. What we’re really talking about today is the next chapter, the first major technical overhaul of the baseline since 2010, which started in 2025 and should be out by 2026.
Who the Standard Applies To
Craig: At its core, ICD 705 applies to the intelligence community as defined by the National Security Act, and any facility where SCI is processed, stored, used, or discussed. That’s the trigger. It’s not who owns the building, it’s who is accrediting the facility. DOE is a good example. It is one of the formal IC elements through its Office of Intelligence and Counterintelligence, so the SCIFs at DOE headquarters and its national labs fall under the same direction as CIA or NSA. That also applies to DoD SCIFs and SAPFs under the equivalent standard, and we’re increasingly seeing it show up in defense contractor facilities that have never seen themselves as part of the IC footprint. Classified workloads are spreading beyond the traditional intelligence environment and its agencies, and the accreditation requirements for that information are following suit.
Why Wireless Is the Blind Spot
Craig: Understanding the rules is half the story. The other half is understanding the threat, and one of the common wireless vulnerabilities is one of the major threats of today. We’re seeing all kinds of wireless devices: Bluetooth, Wi-Fi, smart glasses, smart rings, medical devices. They all have these communication platforms. You have cell phones that are operational and tactical. You have HVAC systems that are now talking remotely over wireless or through an integrated system. In SCIFs and other secure facilities like data centers, wireless devices pose a unique risk to classified information and to the confidentiality of that information. We have facilities in close proximity, with multiple equities that may not have the best intentions.
Brett: Craig, let me chime in. In secure spaces we’ve long recognized the risk associated with wireless devices. What has been changing over the last ten, twenty years is the proliferation of wireless everywhere. These devices are all around us, some with the capacity to collect audio and video information, and they pose a unique risk in very secure facilities like SCIFs and SAPFs. At Bastille, this is what we do as a company. We partner with government and defense organizations and help them understand the risks associated with wireless device presence. Obviously it’s against policy in these facilities to have wireless devices without prior approval, and that approval is typically for necessary medical devices. We work with these organizations to implement the controls needed to maintain visibility, to find, identify, and localize emissions so they can properly adjudicate and enforce policy about wireless devices being introduced into these spaces.
What Changes in the 2025 Overhaul
Craig: A major modernization and rollout of ICD 705 began in 2025, the first substantial overhaul of the SCIF standards since May of 2010. On RF and TEMPEST, we have shifted from compliance support to mandatory, now a requirement for rigorous RF attenuation and advanced signal containment to prevent electromagnetic espionage. On the acoustic side, increased STC compliance and sound masking to block acoustic and vibration harvesting.
For grandfathered and legacy facilities, and honestly this is a lot of the existing SCIFs out there, they are facing a real compliance gap. They’re likely going to be looking at full architectural rebuilds to meet these new specifications. On the enforcement and planning side, we’re heading toward early and aggressive POA&Ms and a shift away from a more pragmatic NCSC oversight approach. The technical mandates are still there for all the new buildings, and the challenge is figuring out how to meet the requirements without undercutting the ability to perform and meet mission requirements.
Why Now
Craig: There are three drivers. Adversaries are using far more capable remote sensing, low power RF probes, and complex signal capturing tools that did not exist when the 2010 baselines were written. There’s a real growing need to neutralize compromising emanations: subtle acoustic leakage, structural vibrations, electromagnetic data leakage from secure electronic components. And classified workloads keep proliferating into the wider defense contractor and federal agency networks outside the traditional intelligence footprint. Part of this is also cost. These devices used to be very, very expensive. They are now readily available, accessible, and purchased on the internet for pennies on the dollar.
Let me pull this together from a practical side. ICD 705 sets the physical and technical baselines for every SCIF across the IC and DoD. Wireless devices can potentially create blind spots that shielding alone cannot fully close. In 2025 the requirements tightened RF and TEMPEST rules, which means continuous monitoring has become a more practical way to demonstrate some forms of compliance while still working on physical security upgrades. What that means is that the security operation can actually help define who were bad actors versus individuals making poor decisions.
What Deployments Actually Find
Brett: Thank you, Craig. As Craig said, there is value in being able to actively identify devices that are in violation of policy, shoring up our security posture not just by shielding, which is an important mechanism, but also by identifying when something has come into the space that shouldn’t be there and could act as a mechanism for exfiltrating classified data.
We work with a large number of government organizations and have for many years. In that time, what we find is that when we deploy a system in a secure facility, the customers are always amazed how much they find right away. As soon as you turn the system on, it lights up. I won’t say it lights up like a Christmas tree, but it lights up with more lights than people would like to see. It’s always eye opening to have that experience with a customer for the first time and to watch them realize, this facility we thought was clean, it turns out it’s not. Once you start looking, you’re amazed at what you find. That highlights the necessity of this kind of solution. Shield the facility all you want, that’s useful, that’s important, but things are getting inside that you don’t realize until you actually pay attention.
How Detection and Localization Work
Brett: The Bastille solution takes a physical layer approach to detecting and localizing emissions using a set of sensor arrays. Each is a sophisticated software defined radio with a large bandwidth. We synchronize the schedule of scanning all relevant frequencies across all of the sensor arrays in a facility, and deploy those sensors so they can localize emissions using an algorithm optimized for indoor localization. The sensors scan the spectrum looking for packets of interest, then demodulate and decode the headers of those packets so we can extract the fields as metadata. That gives us a sense of what the device is and how it’s behaving. So we have detection, metadata extraction, then coordinated localization of every individual emitter, which allows us to do analytics and automate response depending on what the customer wants and what other systems we can integrate with.
One way to visualize the outcome is our DVR interface, where you see icons overlaying a floor plan. You can see where things are in your facility at any given time. You can go back in time, replay it, freeze it, or watch in real time, and see how devices are moving and evolving. If you have a geofence for a specific part of a facility, maybe a SCIF within a building that isn’t a full SCIF building, anything detected inside raises a red flag. You can create alerts and detection filters that zero in on exactly the policy you’re trying to enforce, and when that policy is violated you get an alert through a third party system or whatever you want to do. With that time and spatial information you can very quickly identify when something is happening that shouldn’t be, adjudicate, then investigate and remediate.
The metadata we extract is varied, and there’s a lot of rich information that tells us about the identity of the device, its physical layer characteristics, and contextual information such as behavior, connectivity, capability, sometimes even form factor. So with some level of precision we can say this is a specific kind of smart glasses, or this appears to be a smartphone or a laptop. That’s useful for physical security going and investigating, and can quickly identify the culprit. By that I mean the device, not the person. We’re not going to assume guilt. We just know the device shouldn’t be there.
Sensor Coverage and Passive Operation
Brett: The sensor arrays are broadband. They cover very low frequencies down to the 25 MHz range and north of 6 GHz, covering the Wi-Fi 6E band up to 7.125 GHz. They are rated to operate in a plenum space above ceiling tiles, so they can operate without being in your face, and hopefully people intending to do bad things won’t even know such a monitoring system is in place. Most incidents you’ll see are people who simply forgot, in their innocence. But if there are malicious actors, having a covert system is useful as well.
The most important thing for a SCIF or SAPF use case is that these are one hundred percent RF passive devices. The sensors have no active transmissions. They don’t send Bluetooth in order to hear Bluetooth. They just listen. They don’t send any packets. They are FCC certified as passive, which means their unintended emissions are so low that they’ve passed a very rigorous test. They simply don’t emit. That’s another aspect of covertness, but it’s also important for certification: these aren’t going to violate the policy of your SCIF by being introduced. They’re intended to be an overlay security mechanism, not to introduce more noise into the environment. There are other nice features, like no moving parts and health monitoring. When they do fail, they fail gracefully. If a sensor fails we may lose some accuracy in localization near that sensor, but detection still occurs, localization still occurs, and we know a sensor has gone bad and needs replacing. That’s covered under the subscription.
On protocols, the broad spectrum coverage lets us see Wi-Fi, Bluetooth, Zigbee, cellular emissions including LTE and 5G, and IEEE 802.15.4 based specifications, Bluetooth Classic and Bluetooth Low Energy. There are a lot of protocols we can detect, the most common terrestrial commercial ones, and there are also mechanisms for looking at less standard protocols.
Localization, Audit, and Compliance
Brett: Here’s something that struck me when I joined Bastille. I have a background in signal processing and I’m very familiar with localization concepts and algorithms. What I found was that for indoor environments our algorithm pinpoints location to within one to three meters, which is pretty remarkable from an RF perspective. That gives you high confidence, especially over a brief period as you watch those localizations move around, about where the device actually is. Not just the room, but possibly the desk. That accuracy really shortens the time from detection to remediation.
Then there’s the ability to be compliant with requirements associated with ICD 705 and many other compliance frameworks. Part of what feeds that compliance is the ability to audit and perform forensic investigations. For that we have a database that houses all of your data. Anything that can be displayed on that floor plan view is available for querying at any time, and your retention policy is whatever you want it to be. We have customers who have been retaining data for many years and still haven’t deleted it. All of that ties together to provide a capability that augments protection of classified information in these facilities.
Q&A: Release Date for the New ICD 705
Justin: What is the release date for the new ICD 705?
Craig: That is unfortunately in the hands of the government and they are still working through the process of getting those documents out. I am surmising sometime in the summer of 2026. They will have submitted the paperwork later this summer for approval, and we may see something later this fall. If not, it will slide to the next year.
Q&A: The Three Meter Perimeter Guideline
Justin: I’ve heard that three meters from SCIF perimeter walls is going to be a standard for permanent wireless emanations, to include cell phones. Is this still going to be a new addition?
Craig: There will still be a strong three meter guideline in play. The AOs and your CTTAs for your particular projects will be collaborating with the builder or the manager of the facility to manage those requirements.
Q&A: How an O.MG Cable Evades Inspection
Justin: How does something like an O.MG cable evade standard security inspection, and what does it take to catch one?
Brett: Just to baseline everyone, an O.MG cable is a readily available hacker tool. It’s really meant for pen testing, but of course you can use it for bad things. It’s a cable that looks like any charging cable, but when you plug it into a device it fires up a Wi-Fi access point that allows an attacker to connect wirelessly and conduct flexible attacks, because through that cable they have HID access to the target system. This often evades standard detection. Cables are lying around, people just grab one and use it, and it looks no different from a benign charging cable. There’s nothing physically to see.
The only way to see it is to observe the Wi-Fi access point firing up. We can observe the beacons, the associations, and all the packets flying back and forth between the attacker and the tool plugged into the victim’s device. That’s what it takes to catch one. If you get devices inside a facility, shielding can help prevent that connection if the attacker is outside. But if shielding degrades and you don’t have visibility into that, this is a mechanism that can allow an attacker to inject keystrokes into a target machine and possibly do other things like data exfiltration. The key is to be monitoring actively for those emissions.
Q&A: When a Contractor Site Qualifies
Justin: Now that classified workloads are showing up in defense contractor facilities, how does a contractor know if their site qualifies as a SCIF or SAPF under this directive?
Craig: Basically the government is asking that vendor to do work. There has to be a DD Form 254 that authorizes them to have this information and to build a facility to support the processing of that information.
Q&A: Temporary Secure Working Areas and Smart Glasses
Justin: Since a temporary secure working area doesn’t require special construction and is meant for limited or temporary use, does that lighter footprint make it more or less exposed to something like smart glasses, which can record and transmit without much visual indication?
Craig: Let me first speak to what it is. A TSWA is a temporary secure working area processing at a set level. It could be a tent in the desert with physical security. The intent is that you are so far away from everything else that you cannot be detected. But there are still countermeasures that can be put in to protect the facility. For the issue of smart glasses and things of that nature, it’s still a pretty high risk.
Brett: Thanks, Craig. Smart glasses are an interesting use case we’ve been getting more and more questions about. Some customers are concerned about their ability to be used as surveillance devices to exfiltrate sensitive information. In a TSWA without shielding, those smart glasses have an easier mechanism for exfiltrating data. Without some kind of active detection mechanism there’s no way to know whether they’re smart glasses, or whether they’ve been modified. With physical inspection you can see that something looks like a pair of smart glasses, but it’s much more innocuous looking than, say, a smartphone someone pulls out of their pocket. The ability to have that reach back makes them a very real threat in all kinds of domains, but especially here, with a temporary SCIF set up without shielding. This is a very real risk area.
Q&A: Why Smart Glasses Are Hard to Distinguish
Justin: Smart glasses look like ordinary eyewear and often connect over Bluetooth or Wi-Fi rather than cellular. Does that make them harder for existing detection approaches to distinguish from a routine consumer device versus an actual threat?
Brett: The answer is yes, they are harder to detect. If you’ve been paying attention to the backlash against smart glasses in the social sphere, there are people very concerned about being surreptitiously recorded and having those videos uploaded without their permission or consent. That points to the fact that they are more difficult to identify. They do look different from typical glasses. If they have a camera you may be able to see it, and ideally they have an LED that lights up when the camera is working. There are ways to disable that. There’s been pushback and a cat and mouse game with the vendors trying to make it impossible to modify, but people still find ways to modify them so the LED doesn’t turn on.
What I think about from this perspective is the cases we have seen of insider threats capturing information with smartphones inside secure facilities, just by photographing their screen. There have been multiple incidents that have gone to court with convictions, and those were built on physical inspection or video camera footage. In the case of smart glasses that’s much less obvious. If someone taps the frame of their glasses or invokes recording in a way that isn’t physically obvious, how are you going to detect that? They represent an interesting and new class of threat. The one thing we can say is that they are always transmitting wireless packets. Having the ability to detect those packets is the only fail safe mechanism for identifying when smart glasses are present or nearby, and in secure facilities that is the most robust way of ensuring those glasses don’t make their way inside.
Q&A: Phasing an Architectural Rebuild
Justin: For a facility facing a full architectural gut rebuild, is there any way to phase that work while still staying operational?
Craig: It’s an interesting question. The challenge is going to be what their mission support is and what their customer is asking them to do in that facility. They may get shut down because they are not compliant, but they also might be able to negotiate with the technical team, the CTTA and the AO, to do some partial processing and move some of their elements into a segregated environment so they can do the update. That is a collaboration exercise they need to do with their accrediting organization.
Q&A: Monitoring as a Stopgap or a Complement
Justin: Can continuous monitoring close the compliance gap for facilities that can’t yet afford the physical retrofit, or is it meant as a complement to TEMPEST shielding rather than a direct substitute?
Craig: If the facility has a cost problem and they have a large facility they can’t shield, then a solution like Bastille could help provide a mitigation solution, but not necessarily a remediation solution. This would be a narrative between the AO, the CTTA, and potentially the technical security team, to identify if this is a good answer to help them continue their mission operations. A sidebar to that conversation is also supply chain. When items are brought into a facility that was specifically told not to have Wi-Fi or Bluetooth in them, this type of solution would immediately identify that the equipment had those devices in it, and then they would conduct a supply chain review.
Brett: I don’t have a lot to add, but let me foot stomp that last piece. It isn’t a replacement for the requirements of ICD 705. The requirement to do detection like this is found in many other requirements documents, and many of our customers are subject to those, which is why they need it. But the value of a detection mechanism like this, over and above passive shielding, is knowledge of where the problems are and the ability to adjudicate actual policy violations rather than relying on a passive deterrent. And continuous monitoring can be a stopgap. As Craig said, a mitigation, not a remediation. If budget is an issue, we can walk through that and help you through the process of getting that approval.
Q&A: What Craig Wishes He Had Known
Justin: When you first started your career in this area, what do you wish you’d known?
Craig: When I started building SCIFs, what I really wanted to understand was what the mission was, what the customer in that particular case was trying to accomplish. I can build a six sided box and that’s okay, and I can check all the requirements. But if I don’t understand what their mission is and what they’re trying to support, I can’t build the correct mitigation and protection schema for that mission activity. I would have loved to have learned a lot more about that when I first started out, because all I initially started out doing was building a six sided box. As I grew in my years I quickly learned that it’s a collaboration of all the different parties, bringing all of these issues together to solve the problem.
Closing
Justin: Thank you, Craig. Thank you, Brett. Thank you to all the registrants, the people who showed up for the event, and everyone who sent in questions. Much appreciated.
Brett: Thanks, Justin. Thanks, Craig. We’ll make a recording of this available later in the week. To learn more about Bastille, please visit bastille.net. Take care, and see you on the next webinar.