DCSA SPeD Physical Security Certification (PSC) Actual
Exam– Defense Counterintelligence and Security Agency
(DCSA) SPeD Physical Security – 2026/2027 Edition –
Verified Questions and Answers
Guidelines for controlling access to a SAP facility?
- SCIFs shall be controlled by SCI-indoctrinated personnel or by an AO- approved ACS to
ensure access is restricted to authorized personnel.
- Personnel access control shall be utilized at all SCIFs.
- Visual recognition of persons entering the SCIF by an SCI-indoctrinated person at the entrance
to a SCIF is the ideal access control.
- Entrances where visitor control is conducted shall be under continuous visual observation
unless the SCIF is properly secured.
- When the SCIF is an entire building, access control shall occur at the building perimeter.
SAPF Two-Person Integrity (TPI) Security Measures?
TPI mandates the minimum of two indoctrinated persons at all times in a SAPF, T-SAPF,
SAPCA, SAPWA, and SAPTSWA. This security protection can only be authorized by the
Director, CA SAPCO or designee, and reflected in the SOP.
SAPF Physical Protection Measures?
- Card readers, keypads, communication interface devices, and other access control equipment
located outside the SCIF shall be tamper-protected and be securely fastened to a wall or other
fixed structure.
- Electrical components, associated wiring, or mechanical links shall be accessible only from
inside the SCIF.
- System data that is carried on transmission lines (e.g., access authorizations, personal
identification, or verification data) to and from equipment located outside the SCIF shall be
, protected using FIPS AES certified encrypted lines. If this communication technology is not
feasible, transmission lines shall be installed as approved by the AO.
- Equipment containing access-control software programs shall be located in the SCIF or a
SECRET controlled area.
- Electric door strikes installed in conjunction with a personnel ACS shall have a positive
engagement and be approved under UL 1034 for burglar resistance.
SAPF Physical Security Criteria?
Physical security criteria are governed by whether or not the SAPF or SAPCA is located in the
United States and according to the operational criteria of closed storage, open storage, or
continuous operations. The IC Tech Spec details the specific construction, physical controls, and
alarm systems for each situation.
SAPF Establishment, Accreditation, and Withdrawal of Accreditation
1. SAP FFC and supporting documentation.
2. Any accreditation documents (e.g., physical, TEMPEST, and information systems) and copies
of any waivers granted by the CA SAPCO.
3. SAPF accreditation approval documentation (including mitigations and waivers).
4. TSCM reports, for the entire period of SAPF, T-SAPF, SAPCA, SAPWA, and SAPTSWA
accreditation.
5. Operating procedures and any security documentation (including information system security
authorization package, Co-Utilization Agreements (CUAs), appointment letters, Memorandums
of Agreement (MOA), and emergency action plans).
SAPF Co-Utilization Requirements?
• DoD Components that want to co-utilize a SAPF, T-SAPF, SAPCA, SAPWA, and SAPTSWA
will accept the current accreditation of the responsible agency if accredited without waiver to the
standards in this volume. Prospective tenant activities will be informed of all mitigations and
Exam– Defense Counterintelligence and Security Agency
(DCSA) SPeD Physical Security – 2026/2027 Edition –
Verified Questions and Answers
Guidelines for controlling access to a SAP facility?
- SCIFs shall be controlled by SCI-indoctrinated personnel or by an AO- approved ACS to
ensure access is restricted to authorized personnel.
- Personnel access control shall be utilized at all SCIFs.
- Visual recognition of persons entering the SCIF by an SCI-indoctrinated person at the entrance
to a SCIF is the ideal access control.
- Entrances where visitor control is conducted shall be under continuous visual observation
unless the SCIF is properly secured.
- When the SCIF is an entire building, access control shall occur at the building perimeter.
SAPF Two-Person Integrity (TPI) Security Measures?
TPI mandates the minimum of two indoctrinated persons at all times in a SAPF, T-SAPF,
SAPCA, SAPWA, and SAPTSWA. This security protection can only be authorized by the
Director, CA SAPCO or designee, and reflected in the SOP.
SAPF Physical Protection Measures?
- Card readers, keypads, communication interface devices, and other access control equipment
located outside the SCIF shall be tamper-protected and be securely fastened to a wall or other
fixed structure.
- Electrical components, associated wiring, or mechanical links shall be accessible only from
inside the SCIF.
- System data that is carried on transmission lines (e.g., access authorizations, personal
identification, or verification data) to and from equipment located outside the SCIF shall be
, protected using FIPS AES certified encrypted lines. If this communication technology is not
feasible, transmission lines shall be installed as approved by the AO.
- Equipment containing access-control software programs shall be located in the SCIF or a
SECRET controlled area.
- Electric door strikes installed in conjunction with a personnel ACS shall have a positive
engagement and be approved under UL 1034 for burglar resistance.
SAPF Physical Security Criteria?
Physical security criteria are governed by whether or not the SAPF or SAPCA is located in the
United States and according to the operational criteria of closed storage, open storage, or
continuous operations. The IC Tech Spec details the specific construction, physical controls, and
alarm systems for each situation.
SAPF Establishment, Accreditation, and Withdrawal of Accreditation
1. SAP FFC and supporting documentation.
2. Any accreditation documents (e.g., physical, TEMPEST, and information systems) and copies
of any waivers granted by the CA SAPCO.
3. SAPF accreditation approval documentation (including mitigations and waivers).
4. TSCM reports, for the entire period of SAPF, T-SAPF, SAPCA, SAPWA, and SAPTSWA
accreditation.
5. Operating procedures and any security documentation (including information system security
authorization package, Co-Utilization Agreements (CUAs), appointment letters, Memorandums
of Agreement (MOA), and emergency action plans).
SAPF Co-Utilization Requirements?
• DoD Components that want to co-utilize a SAPF, T-SAPF, SAPCA, SAPWA, and SAPTSWA
will accept the current accreditation of the responsible agency if accredited without waiver to the
standards in this volume. Prospective tenant activities will be informed of all mitigations and