A vendor with cleared staff says: our engineers hold TS clearances, so we are covered for this work.
Sometimes that is true. Often it is not, and the reason is the single most commonly missed idea in this whole subject. Classification level is not the only thing controlling who may see something. There is a second axis, it is independent of the first, and a clearance at the highest level on axis one does not, by itself, grant access on axis two.
Two axes, not one ladder
Almost everyone arriving from outside builds the same mental model: a ladder from Unclassified up through Confidential, Secret, Top Secret, and then — because they have heard the phrase — something above Top Secret. The ladder part is right. The thing above it is not.
| Axis | What it answers | Values |
|---|---|---|
| Classification level | How much damage would disclosure cause? | Confidential, Secret, Top Secret |
| Compartmentation | Who may be granted access, and by whom? | Collateral (none), SCI, other SAPs |
These are orthogonal. A piece of information has a level and a compartmentation status, and you need both to know who can handle it. Getting one and assuming the other is where vendors lose months.
Collateral, and a word you will hear that is not official
Collateral is the word for classified information that is not inside a compartmented control system, and it has a formal definition. CNSSI 4009, the national glossary of security terms, published through NIST, defines it as "National security information (including intelligence information) classified Top Secret, Secret, or Confidential that is not in the Sensitive Compartmented Information (SCI) or other Special Access Program (SAP) category."
You will also hear GENSER, short for general service, used loosely to mean the same thing. Treat it as jargon rather than terminology. It is not in that national glossary, and it does not appear in DISA's current cloud security requirements guide. DISA's connection process guide uses it exactly once, in passing, without defining it. If a document you are relying on turns on the word GENSER, find the word collateral and anchor to that instead.
The consequence people miss: collateral Top Secret exists. The definition above includes Top Secret, so Top Secret information that is not in any SCI or other special access program is collateral. When a requirement says "Top Secret," that does not tell you that SCI is involved, and it does not tell you that the TS/SCI network is where the work happens. Level and compartment have to be stated separately, because neither implies the other.
SCI is not a level
Here is the fact that resolves most of the confusion, and it surprises nearly everyone.
Sensitive Compartmented Information is not a classification level. The governing directive, ICD 703, defines it in one sentence: "A subset of CNI concerning or derived from intelligence sources, methods or analytical processes that is required to be protected within formal access control systems established by the DNI."
Read that slowly, because both halves matter. SCI is a subset of classified national intelligence — so it is already classified, under the same executive order and the same Confidential, Secret and Top Secret levels as everything else. What makes it SCI is the second half: it must also be protected within a formal access control system established by the Director of National Intelligence. The classification is one thing. The control system is a separate layer on top of it.
This is why "above Top Secret" is a misnomer, however widely it is used. There is nothing above Top Secret on the level axis. SCI does not add a rung. It adds a separate set of controls over who may see information that already has a level.
That executive order says exactly this about special access programs — the wider family SCI belongs to, as the next section shows. Executive Order 13526 defines one as "a program established for a specific class of classified information that imposes safeguarding and access requirements that exceed those normally required for information at the same classification level." Extra controls. Same level.
So "TS/SCI" is two facts joined by a slash: Top Secret on the level axis, inside an SCI control system on the compartmentation axis. People read it as one thing. It is two.
SCI and SAP: one family, run as separate regimes
The vocabulary here is genuinely inconsistent, and it is worth seeing why rather than picking a side.
By definition, SCI is a kind of special access program. The national glossary's definition of collateral, quoted above, excludes SCI or other special access program information — and other is doing the work. And the nondisclosure agreement signed for SCI access, Form 4414, describes SCI as "information or material protected within Special Access Programs."
In practice, they are run as separate regimes. When people say SAP they almost always mean the non-SCI kind, and DoD administers the two separately. DoD's SAP security manual requires authorization before SCI is used inside a SAP facility or a SAP inside an SCI facility, and applies SAP security rules "in addition to all collateral and SCI requirements." Different facilities, different security officers.
The authorities differ, and that is the part that matters to you. SCI runs under the Director of National Intelligence: ICD 704 says the DNI establishes eligibility standards and "delegates, to heads of IC elements, the authority to grant access," and those heads may delegate it further to a Cognizant Security Authority. Other special access programs are created under Executive Order 13526, which allows only the Secretaries of State, Defense, Energy and Homeland Security, the Attorney General, and the Director of National Intelligence, or their principal deputies, to create one — and only where a statute requires it, or on a specific finding that the threat to the information is exceptional and the normal access criteria for its classification level are not sufficient to protect it.
That difference in authority determines who you have to ask. A program office cannot read your staff into an SCI control system, and an intelligence element cannot read them into someone else's SAP.
Why this shows up as cost and schedule
This is the part that belongs in a capture plan rather than a training slide.
A clearance is eligibility. Access is a separate grant. You can hold a Top Secret clearance and have no SCI access at all. SCI access is tied to a Tier 5 background investigation under the Federal Investigative Standards — ICPG 704.1 requires one to be initiated even before temporary SCI access is approved — and that investigation is necessary but not sufficient. The gap between eligibility and access is a government decision you do not control, and ICD 704 is blunt about its nature: access determinations "are discretionary and based on IC mission requirements, and do not create any rights, substantive or procedural."
Eligibility travels. Access may not. ICD 704 requires IC elements to accept each other's in-scope eligibility determinations that carry no conditions, deviations or waivers, so the investigation and adjudication are reciprocal — that part genuinely does move with a person. Access into a particular control system is a separate grant, made by whoever holds that authority, and it comes with a formal security indoctrination and a signed nondisclosure agreement. That agreement is explicit about the point that matters here: the signer acknowledges they "may be required to sign subsequent agreements upon being granted access to different categories of SCI." A team read in for one program should not assume it is read in for the next.
Need to know still applies on top. Executive Order 13526 defines it as a determination "that a prospective recipient requires access to specific classified information in order to perform or assist in a lawful and authorized governmental function." Eligibility plus access plus a demonstrated need. All three.
Therefore "we have cleared staff" does not answer the question. The question is whether your specific people hold the specific accesses this specific work requires, and if not, who grants them and how long that takes. That is a schedule dependency owned by the government, and vendors routinely put it on a Gantt chart as though it were theirs.
And it changes where the work physically happens. ICD 703 is categorical: "all SCI must be processed, stored, used, or discussed in accordance with ICD 705, Sensitive Compartmented Information Facilities." That requirement belongs to SCI specifically, and a qualifying facility is a lease, a build, or a partner — not a configuration setting.
Back to the networks
This also sharpens the question that opened part one: do we need SIPR or JWICS?
Look at the two classified services' names again. One is named for a classification level: Secret. The other is named for a level and a control system: Top Secret/SCI. The second name joins the two axes this post has pulled apart. So "SIPR or JWICS" is really two questions asked as one — what level, and is it compartmented — and a requirement that answers only the first has not told you which network it needs. That is the same reason what may sit alongside what is a harder question than the classification markings suggest.
What to ask
When a requirement mentions a classification, get both axes on the record before estimating anything.
- What level, and is it collateral or compartmented? Two questions, always. An answer to one is not an answer to both.
- If compartmented: SCI or SAP, and which control system? This determines who grants access.
- Which of my people already hold that access? Not their clearance level. The specific access.
- Who is the Cognizant Security Authority, and what is the current timeline? That is the role holding delegated authority to grant the access. Find out who, early.
- What facility does the work require? Ask before assuming your existing space qualifies.
None of these is expensive to ask. All of them are expensive to discover after a schedule has been committed, and the gap between working software and fielded software is largely made of questions like these going unasked.
Next in this series: where the software is allowed to run, and the impact-level vocabulary that governs it.
Robert Burckner is the founder of Millabs Corporation, a Service-Disabled Veteran-Owned Small Business. He has served as ISSM and ISSE for legacy weapon systems at the Air Force Lifecycle Management Center and as Division Chief at the Space Warfighting Analysis Center (USSF/NRO). Millabs has deployed commercial software to IL-4 and TOP SECRET environments operational on JWICS.
If you have government demand and are working out what deploying into a classified environment actually requires, an enclave fit study answers the hosting, inheritance and authorization questions before you commit to a schedule. Contact Millabs.