Certified Site Security Manager (SSM) Certification Program by Tonex

The Certified Site Security Manager (SSM) program is an intensive certification course designed to develop security professionals capable of managing and overseeing security operations for high-risk sites, including:
- Government facilities
- SCIF/SAPF environments
- Defense industrial construction sites
- Corporate R&D labs
- Critical infrastructure
- High-value commercial properties
An SSM is responsible for:
- Designing and enforcing security procedures
- Supervising Construction Surveillance Technicians (CSTs) and escorts
- Managing physical, personnel, technical, and cybersecurity elements
- Ensuring compliance with ICD 705, DoD, DHS, NISPOM, and organization-specific policies
- Conducting incident response, reporting, documentation, and audits
This certification prepares participants to lead a site security program with confidence, technical competence, and regulatory compliance.
Learning Objectives
After completing the SSM certification, participants will be able to:
Security Leadership & Operations
- Lead a site security program and manage security personnel
- Develop and enforce standard operating procedures (SOPs)
- Conduct threat, vulnerability, and risk assessments
Regulatory Compliance
- Interpret and implement ICD 705, NISPOM, DoDM 5105.21, DoD SAPF manuals
- Conduct SCIF/SAPF inspections, accreditation readiness, and mitigation plans
Workforce Management
- Train and supervise CSTs, uniformed escorts, and contract security personnel
- Implement screening, onboarding, evaluation, and corrective action processes
Technical & Physical Security Integration
- Oversee CCTV, access control, intrusion detection, and sensor systems
- Ensure technical compliance in construction and operations phases
Incident Management
- Lead investigations, document findings, escalate properly
- Communicate and coordinate with government security officials (SSO, CSSO, PSO, FSO)
Professional Reporting
- Prepare daily, weekly, and incident reports
- Present findings to government agencies, contractors, and leadership
Target Audience
- Site Security Managers
- Facility Security Officers (FSOs)
- Construction Security Managers
- Senior CSTs aspiring to management roles
- Defense contractors, integrators, and program security professionals
- Corporate security leaders
Prerequisites
- Background in physical, personnel, or construction security (recommended)
- Basic knowledge of access control, CCTV, and physical security
- Ability to pass federal background checks (for real-world employment)
Program Modules
Day 1 — Security Program Leadership & Regulatory Compliance
Module 1: Role of the Site Security Manager (SSM)
- Key duties and responsibilities
- Relationship to CSTs, FSOs, CSSO/CSO, PSO, SSM/SSO structure
- Managing multi-phase construction and operational security programs
Module 2: Regulatory Framework for Secure Sites
- ICD 705 requirements & compliance enforcement
- NISPOM & DoD special access program (SAPF) security
- DoDM 5105.21 Vol 1–3 (SCI security)
- SCIF accreditation workflow and documentation
Module 3: Risk Management & Threat Assessment
- Risk analysis models for secure facilities
- Identifying vulnerabilities in construction, operations, and maintenance phases
- Insider threats and countermeasures
- Coordination with counterintelligence (CI) personnel
Module 4: Managing Security Staff & Escorts
- Supervising CSTs, uniformed escorts, and subcontractor personnel
- Conducting shift briefings, scheduling, roles & responsibilities
- Skill validation, performance issues, corrective actions
- Maintaining professionalism and TS/SCI-level standards
Module 5: Site Access Control & Personnel Security
- Visitor processing, badges, logs, verification procedures
- Unescorted vs escorted access
- Response to unauthorized personnel or anomalies
- High-risk personnel scenarios
Hands-On Exercise A:
Simulated management scenario — directing multiple CSTs, identifying breakdowns, producing corrective instructions.
Day 2 — Technical Security, Incident Response & Documentation
Module 6: Physical Security Systems & Technical Oversight
- CCTV, access control, alarms, environmental sensors
- Working with integrators and IT/OT personnel
- Security design review for construction phases
- Red/Black separation basics, TEMPEST considerations (manager level)
Module 7: Construction Security Oversight
- Enforcement of secure construction protocols
- Material inspections and approval workflows
- Ensuring daily operations adhere to ICD 705
- Oversight of foreign materials, tools, and equipment
(Integrated with CST supervision responsibilities.)
Module 8: Incident Response & Investigations
- Initial response, preservation of evidence
- Taking witness statements
- When to escalate to PSO, SSO, CI, law enforcement
- Managing insider threat indicators
- Root cause analysis
Module 9: Documentation, Reporting & Communication
- Daily logs, SSM reports, incident reports
- Weekly summaries for government counterparts
- Preparing accreditation readiness documents
- Briefing stakeholders and agencies
Module 10: Audits, Continuous Monitoring & Post-Construction Security
- Periodic inspections
- Mitigating contractor deviations
- Security assurance after completion
- Maintaining accreditation & lifecycle security
Certification Exam Domains (SSM)
| Domain | Description |
| Domain 1 – Security Program Leadership & Workforce Management | Managing personnel, schedules, CSTs/escorts, professionalism, leadership. |
| Domain 2 – Regulatory Compliance (ICD 705, NISPOM, DoDM, SAPF) | In-depth understanding of secure facility requirements and compliance. |
| Domain 3 – Risk, Threat & Vulnerability Management | Threat detection, CI coordination, insider threats, risk analysis. |
| Domain 4 – Physical & Technical Security Systems | CCTV, access control, alarm systems, red/black separation concepts. |
| Domain 5 – Secure Construction & Material Oversight | Enforcing secure construction methods, inspections, adherence to ICD 705. |
| Domain 6 – Incident Response & Investigations | Responding to events, escalation, documentation, corrective action. |
| Domain 7 – Reporting, Documentation & Communication | Logs, incident reports, accreditation docs, briefings to agencies. |