The 30 Percent Design Milestone That Decides Whether Your CSP Works
- Phillip Chance
- Jul 14
- 4 min read
There is a specific moment on every SCIF project where the Construction Security Plan stops being theoretical and starts driving cost, schedule, and accreditation outcomes. That moment is the 30 percent design milestone. Miss it and the project pays.

The Construction Security Plan (CSP) is the document that governs how a SCIF or SAPF is protected during design, construction, and accreditation. ICD 705 requires it. The AO has to approve it before construction begins. The Site Security Manager owns it, in collaboration with the AO. The IC Tech Spec spells out the structure. None of that is new.
What changed recently is the timing. In February 2025, the Defense Intelligence Agency issued a memorandum reinforcing the 30 percent design milestone for CSP submission on SCIFs accredited by DIA or co-utilized by DIA-accredited programs. The memorandum did not invent a new standard. It put a hard line under one that had been treated as guidance.
The reason for the line is straightforward. By 30 percent design, the basic layout is set. The floor plan, the perimeter, the major utility routes, and the rough placement of doors and openings are known. That is enough information to write a meaningful CSP. It is also early enough that adjustments are still affordable. A CSP submitted at 60 or 90 percent design has to be rewritten every time the AO asks for a change, because the design is already too far along to absorb the change cleanly. A CSP submitted at 30 percent gives the AO the chance to drive issues to resolution before they become expensive.
The pre-ICD 705 era ran differently. The standards that preceded ICD 705, DCID 6/9 and its predecessors, varied by agency, and CSP timing was treated as a project-by-project negotiation. Some projects got it right. Many did not. The result was a steady drumbeat of accreditation problems that the post-2010 framework was designed to prevent. The 30 percent milestone is part of that prevention.
The reality on most projects: the SSM is new to the role. The CSP is one of the most demanding documents the project produces, and writing one for the first time without help is brutal. The standard accommodates that. Many SSMs lean on ICD 705 consultants or experienced general contractors to develop the early drafts, especially the first one at 30 percent. The work product still belongs to the SSM and is still submitted under the SSM's signature. The early help is about getting the right structure and the right depth in the first version, not about transferring responsibility.
The CSP itself follows a structure that the ODNI template defines. It identifies the SSM. It describes the project, including location, size, mission category, and scope. It names the CSA and the AO. It lays out the construction schedule. The bulk of the document is the security protective measures: the construction security controls, the document handling protocols, the personnel control measures, the material procurement controls, the tamper detection approach, the badge and escort regime, and the reporting obligations.
The structure is straightforward. The depth is where the work is. A CSP that lists "tamper detection seals will be used" is not actually a CSP. A CSP that names the type of seal, the placement, the inspection cadence, the chain of custody, and the response to a failed inspection is starting to do the job. The AO is reading for that depth.
A piece of mechanics worth knowing: the CSP is a living document. Revision history is part of the structure. When project conditions change, when the site changes, when the schedule changes, when a stakeholder changes, when the construction method changes, the CSP gets revised. Some revisions require AO re-approval before they take effect. Others can proceed with notice. The CSP itself usually defines which is which for that project, with the AO's input. Treating the CSP as a one-and-done deliverable that gets filed and forgotten is one of the more reliable ways to land an accreditation problem at the end of the job.
The worst-case scenario is the one to keep visible. A project that starts construction without an approved CSP is a project that may never be accredited. Construction security depends on having documented measures in place from day one. Without an approved CSP, the controls that were in effect during construction are unverifiable. The AO has no record of what was done, no basis to accept the residual risk, and no way to certify that the construction phase was protected. The space might be physically complete and procedurally clean, but the accreditation package is missing its spine.
Practical advice for project teams. Build the CSP development into the design schedule explicitly. Name an owner, the SSM, and a backup writer, a consultant or an experienced contractor if the SSM is new. Aim for a first complete draft at 30 percent design. Submit to the AO with enough time to absorb feedback before the design freezes. Treat the document as a project deliverable on the same footing as the architectural and structural drawing sets. The CSP is what makes those drawing sets accreditable.
The 30 percent milestone is not arbitrary. It is the point where the project knows enough to commit and still has time to adjust. The teams that hit it cleanly do not run accreditation surprises. The teams that miss it do.
This material is taught at greater depth in Module 7 of the ICD 705 Foundations Series. The full Series is available at psc-consultant.com/on-demand-education.