SDIP-27 is the NATO standard that sets out how much electromagnetic emission a device may produce and still be considered safe for classified processing. It defines three protection levels – A, B and C – and the test procedures used to verify them. Sweden’s RÖS levels U1, U2 and U3 correspond directly.
The standard itself is classified. What is public, and what matters when you specify or buy equipment, is which level applies where and what a certificate at that level actually guarantees.
The three levels
| SDIP-27 | Sweden | Assumed adversary distance | Typical environment |
|---|---|---|---|
| Level A | RÖS U1 | Immediately adjacent | Embassies, city-centre offices, shared buildings, vehicles |
| Level B | RÖS U2 | Roughly 20 metres | Facilities with a controlled perimeter |
| Level C | RÖS U3 | Roughly 100 metres | Military installations with a large controlled zone |
The essential idea is that the level is a statement about the environment, not about the classification of the information. The same secret document processed in an embassy on a public street and in the middle of a guarded military area calls for different equipment – because in one case the adversary can stand three metres from the wall and in the other they cannot get within a hundred.
This is why “we handle classified information, so we need Level A” is not automatically right, and why “our facility is secure, so Level C is enough” is not automatically right either. The question is how close a capable adversary can get, and stay, without being noticed.
What a certificate covers
A TEMPEST certificate is issued for one product in one configuration, tested by an accredited laboratory against the emission limits for that level. It says: this unit, built this way, with these components, keeps its emissions below the threshold.
Four things follow from that, and each of them causes problems in real projects:
Change a graphics card, a power supply or an enclosure panel and the tested configuration no longer exists. The certificate does not follow the modification.
Commercial equipment cannot be tested after purchase and declared certified. Shielding, filtering and internal layout are design decisions; they are not accessories.
Certified equipment installed with unfiltered mains, with red and black cables run together, or with an unprotected cable leaving the zone, does not deliver the level it was certified to. The device is only one part of the system.
A Level A workplace consists of a Level A computer, monitor, keyboard, mouse, phone, printer and camera. An uncertified USB headset in the middle of it is a working transmitter next to a protected screen.
Level A and Level B in practice
Most of the difference a buyer notices is cost, availability and physical design. Level A equipment carries more shielding, more filtering and tighter constraints on what components may be used, which means fewer models, longer lead times and a higher price. Level B has more room to work with commercially available parts.
That difference is worth understanding before a requirement is written. Specifying Level A across an entire estate when only two rooms face the street is expensive without being safer; specifying Level B for a facility on a public square may be cheap in the wrong way.
The practical approach is to zone: establish where an adversary can get close, protect those areas to Level A, and use Level B where the perimeter already does part of the work.
Writing the requirement
A common failure in procurement is a specification that describes the function but not the approval. “Interception-proof monitor” is not a requirement – it is a hope. It lets an uncertified product qualify on paper, and the gap is discovered after delivery.
A requirement that holds looks like this:
Equipment shall be certified to TEMPEST Level A in accordance with SDIP-27, corresponding to Swedish RÖS U1. Certification shall be issued by an accredited laboratory and the certificate shall be presented with the tender.
Two clauses, and together they remove the ambiguity: the level is named against the standard, and the evidence has to arrive with the offer rather than being promised later. Procurement support covers this in more detail, including the other clauses worth including.
Where M-numbers fit
For deliveries to the Swedish Armed Forces there is a further step. An M-number is the Armed Forces’ own approval identifier for a specific piece of equipment, granted after their own assessment. A TEMPEST certificate and an M-number are not the same thing and do not replace each other: the certificate is the laboratory’s verdict on emissions, the M-number is the customer’s decision that the item may be used in their systems. M-numbers are explained separately.
Getting the documentation
Certificates for a specific product, and the test reports behind them, are not published openly – both because of what they reveal about the equipment and because they are issued into a specific context. They are available on request, and are a normal part of a tender response.
Fibersystem is a NATO-certified TEMPEST supplier and builds equipment certified to Level A and Level B, corresponding to RÖS U1 and U2. If you are drafting a requirement specification, send it to us before you publish it – it is considerably cheaper to correct a clause than a delivery.






