Orbital FederalFederal

Physical Security

Do we need a Construction Surveillance Technician?

The question usually arrives late — after the drawings are frozen, sometimes after the trades are on site. Here is how to answer it properly, and what it costs to get it wrong.

The short answer

If uncleared workers will be inside a space being built or modified to a secure standard, and the accreditation of that space depends on what ends up inside the walls, you need construction surveillance. Whether that means continuous coverage, shift coverage, or milestone inspections is a scoping question for your cognizant security authority — and it belongs in your Construction Security Plan before anyone breaks ground.

The failure this prevents is specific: a space that fails inspection because of something now sealed behind finished surfaces. That is not a punch list item. That is demolition.

What a CST actually does

A Construction Surveillance Technician is a cleared security specialist whose only job is the integrity of the build. They are not a quality-control function for the architect and not an inspector working for the general contractor. They report to security.

Day to day, that looks like:

  • Access control and escort of uncleared workers inside the secure perimeter — knowing who is in the space, and that they are accompanied
  • Material inspection and control — verifying what comes onto the site is what was specified, and that nothing arrives or leaves unexamined
  • Continuous observation of the installations the standard cares about — wall and slab penetrations, conduit runs, acoustic and RF treatments, deck-to-deck construction, door and hardware sets
  • Contemporaneous documentation — daily logs, deviation reports, and a photographic record built as the work happens rather than reconstructed afterwards

That last point is the one owners underestimate. The purpose is not only to catch problems but to produce a defensible record that the construction was witnessed. When an accrediting official asks how you know a penetration was sleeved and sealed correctly, "our GC says so" is a materially weaker answer than a dated log and photograph from someone whose job was to watch.

Why the construction phase is the vulnerable one

A finished secure facility is, by design, hard to attack. A facility under construction is the opposite. The walls are open. The trades are numerous, rotating, and mostly uncleared. Deliveries arrive daily from suppliers nobody vetted. And the drawings — which describe exactly where the sensitive spaces are, how they are protected, and where the weaknesses sit — exist in more hands during construction than at any other point in the building's life.

An adversary who wants persistent access to a secure space has no better opportunity than the eighteen months when it is being built. They do not need to defeat the finished protection; they need to be present, or to have a cooperative person present, while it is being installed.

This is why the standard treats construction as a security phase in its own right, with its own plan, rather than as a period to get through before security starts.

How the requirement actually reaches you

There is no statute that says "hire a CST." The obligation arrives through the accreditation path, and it arrives in a specific order:

  1. ICD 705 and the IC Tech Spec establish how a SCIF or secure space must be designed, built, and managed — including construction security expectations
  2. Your cognizant security authority — the government office that will ultimately accredit the space — determines what construction security measures your particular project requires, based on location, threat, classification level, and who will be doing the work
  3. The Construction Security Plan documents those measures, including what surveillance coverage will be provided and by whom
  4. The accreditation inspection tests whether what the CSP promised is what happened

Which means the decision is not really yours to make in isolation, and the most expensive version of this mistake is assuming the answer is no. Ask the accrediting authority early. The conversation is free; the remediation is not.

Where owners get caught

Four patterns recur:

The CSP was written by someone who had never run one

A Construction Security Plan assembled from a template will describe surveillance in terms nobody can execute — vague coverage, undefined escalation, no clarity on who has authority to stop work. It passes review and fails in practice.

Coverage was scoped to the budget rather than the risk

Milestone inspections are appropriate for some projects. They are not appropriate when uncleared trades have unsupervised access to open assemblies between milestones. The gaps between visits are exactly where the record goes blank.

The reporting line ran through construction

If the surveillance function answers to the party being surveilled, the incentive is wrong at precisely the moment it matters — when a deviation would cost schedule. This is the single most common structural flaw we see.

Nobody reviewed the drawings for surveillance priorities

A CST who arrives on day one of construction with no design context is watching a building they do not understand. The penetrations that matter, the assemblies with acoustic performance requirements, the adjacencies that create risk — those are knowable in advance, and should shape the coverage plan.

What to do next

If you are early in a secure build, in this order:

  • Ask your cognizant security authority what construction security they will expect. Do it in writing, and do it before design freezes.
  • Get the CSP written by someone who has executed one, not adapted from a template.
  • Fix the reporting line first. Whoever provides surveillance answers to security, not to the builder or the schedule.
  • Have the drawings reviewed for surveillance priorities before coverage is scoped, so the plan reflects the actual building.

If you are already under construction without coverage, the useful move is triage rather than panic: establish what has been closed up, what record exists for it, and what can still be verified without destructive investigation. That assessment is worth doing before the accrediting authority arrives rather than after.

On authority Accreditation decisions rest with the cognizant government office. Nothing here substitutes for their determination on your specific project, and the requirements vary by program, location, and classification level. This is a guide to asking the right questions early — not a ruling on what your project needs.

Questions

Asked on almost every secure build

Is a CST legally required?
There is no single statute that says "hire a CST." The requirement reaches you through the accreditation path: ICD 705 and the IC Tech Spec govern how a SCIF or secure space must be built, the cognizant security authority decides what construction security measures your specific project needs, and for most projects involving uncleared workers inside the secure perimeter that determination includes continuous or periodic surveillance by cleared personnel. Your Construction Security Plan is where that gets written down. So the honest answer is that it is required when the accrediting authority says it is — and asking them early is far cheaper than assuming.
Can our general contractor provide the CST?
They can provide a person, but not the independence. A CST's value comes from reporting to security rather than to the construction schedule. When the same organisation that is being watched also employs the watcher, the deviation that costs a week gets resolved in favour of the week. Some programs explicitly prohibit the arrangement. Where it is permitted, expect the accrediting authority to scrutinise the reporting line.
When in the project should we engage one?
Before the Construction Security Plan is written, which is before construction starts. The CSP defines what surveillance coverage the project will have, and a CST engaged after it is approved inherits whatever someone else guessed. Engaging during design also means someone reviews the drawings for the details that later become surveillance priorities — penetrations, conduit routing, acoustic assemblies.
What does a CST cost compared with the risk?
CST coverage is priced as labour — a function of shift pattern, clearance level, duration, and site location. The comparison that matters is not CST cost against project budget but CST cost against remediation. If an accrediting authority finds a non-conforming penetration behind finished drywall, the correction is demolition, rebuild, re-inspection, and schedule. On a secure space of any size that is a six-figure event, and on a program with a delivery date attached it can be worse than the money.

Next Step

Building or planning a secure space?

Ten minutes before the drawings freeze is worth more than any report written afterwards.

Prefer to talk? 866.960.7475 · info@orbitalfederal.com