What is a security classification guide? A Security Classification Guide (SCG) is an official set of instructions that tells authorized U.S. government personnel which information must be classified, what classification level applies, and how long that information should remain protected.
Under Executive Order 13526, classification guides are issued under the authority of an Original Classification Authority (OCA). Instead of leaving employees and contractors to make individual judgments about sensitive information, an SCG records established classification decisions that derivative classifiers can apply consistently.
This matters because classification involves much more than placing a Secret or Top Secret marking on a document. A well-designed SCG identifies specific information elements, assigns the appropriate classification level, provides declassification instructions, and helps prevent both under-classification and unnecessary over-classification.
Understanding what is a security classification guide also makes the broader U.S. classification system easier to follow. In practice, an SCG acts as the rulebook connecting an original classification decision to the analysts, military personnel, engineers, program managers, and authorized contractors who must correctly apply that decision when creating or handling government information.
Key Takeaways
- A Security Classification Guide (SCG) records classification decisions and gives authorized users clear instructions for applying them consistently.
- Original classification decisions must come from an authorized Original Classification Authority (OCA); derivative classifiers apply those existing decisions.
- SCGs identify specific information elements, their classification level, the reason for classification, and applicable declassification instructions.
- The three standard U.S. national-security classification levels are Confidential, Secret, and Top Secret.
- Understanding what is a security classification guide also means recognizing its limits: an SCG does not grant a security clearance, authorize public release, or make CUI classified.
- Classification guidance must be reviewed periodically and can be revised, superseded, consolidated, or cancelled as circumstances change.
- One reason what is a security classification guide remains relevant in 2026 is that established classification rules still apply as agencies use newer technologies, including AI systems.
What Is a Security Classification Guide?
A Security Classification Guide (SCG) turns authorized classification decisions into practical instructions that government personnel and derivative classifiers can follow. Under Executive Order 13526, it identifies specific information that requires classification and establishes the appropriate level and duration.
A typical SCG identifies:
- Information element — the specific information covered by the guide.
- Classification level — Confidential, Secret, Top Secret, or unclassified.
- Classification reason — why protection is required.
- Duration — when or under what conditions classification ends.
- Additional guidance — special controls or instructions that may apply.
For anyone researching what is a security classification guide, the key point is that an SCG does not create new classification authority for its users. It records established decisions so they can be applied accurately and consistently. This distinction is essential to understanding what is a security classification guide in practice.
Why Do Security Classification Guides Exist?
A Security Classification Guide exists to keep classification decisions consistent across a program, system, project, or activity. Without common guidance, the same information could be treated as Secret by one person, Confidential by another, or unclassified by someone else. This consistency is an important part of understanding what is a security classification guide and why agencies use one.
SCGs help agencies:
- Prevent under-classification — ensuring sensitive information receives the level of protection required.
- Reduce over-classification — avoiding unnecessary restrictions on information that does not warrant a higher classification level.
- Apply decisions consistently — giving derivative classifiers a common source instead of relying on individual judgment.
- Support information sharing — helping prevent unnecessary classification from restricting legitimate access and collaboration.
- Maintain clear guidance — connecting specific information elements with the appropriate classification level and duration.
Executive Order 13526 states that significant doubt about whether information should be classified should generally be resolved against classification, while significant doubt about the appropriate level should be resolved in favor of the lower level. In practice, what is a security classification guide is closely tied to this balance: protecting information that genuinely requires protection without classifying more than necessary.
What a Security Classification Guide Can and Cannot Do
A Security Classification Guide provides specific instructions for applying established classification decisions, but its authority has clear limits. Knowing those limits is essential when explaining what is a security classification guide in practice.
| An SCG Can Help | An SCG Does Not Automatically |
|---|---|
| Apply classification consistently | Make information unclassified |
| Identify the appropriate classification level | Authorize information for public release |
| Guide derivative classification | Give a user Original Classification Authority |
| Establish classification duration | Allow derivative classifiers to create new classification decisions |
| Reduce unnecessary classification | Classify another agency’s information |
| Direct users to the proper authority | Replace required security or release-review procedures |
One of the most important distinctions is that unclassified does not necessarily mean publicly releasable. Information may still be protected by CUI requirements, privacy rules, export controls, contractual restrictions, or other release procedures.
This distinction helps clarify what is a security classification guide: an SCG manages how classification decisions are applied; it is not permission to disclose or publicly release information.
How Does a Security Classification Guide Work?
The best way to understand what is a security classification guide in practice is to follow how a classification decision moves from an authorized official into guidance used by derivative classifiers.
Step 1: An OCA Makes the Classification Decision
An Original Classification Authority (OCA) determines that specific government information requires classification. The information must meet the requirements of Executive Order 13526, including falling within an authorized category and presenting an identifiable risk of damage to national security if disclosed without authorization.
Step 2: Classification Instructions Are Established
The OCA determines the key elements of the decision, including:
- What specific information requires protection;
- Why it qualifies for classification;
- Whether it is Confidential, Secret, or Top Secret;
- How long it should remain classified; and
- Whether additional controls apply.
Step 3: The Decision Is Incorporated Into the SCG
Agencies incorporate applicable original classification decisions into classification guides. This creates a consistent source of instructions for personnel working with the covered information.
Step 4: Derivative Classifiers Apply the Guidance
Derivative classifiers use the SCG when creating new material involving covered information. They apply the existing classification instructions rather than making a new original classification decision.
Step 5: The Material Is Marked Accordingly
The resulting material receives the appropriate classification markings and applicable declassification instructions based on the authorized classification source.
The process can be summarized as:
OCA → Classification decision → SCG → Derivative classifier → Properly marked material
This workflow is central to what is a security classification guide: the SCG connects an original classification decision with the people responsible for applying that decision consistently.
What Information Does a Security Classification Guide Contain?
Under 32 CFR § 2001.15, classification guides must provide enough detail for users to identify the information covered and apply the correct classification instructions. This required structure is an important part of understanding what is a security classification guide.
A typical SCG includes:
| SCG Component | Purpose |
|---|---|
| Subject | Identifies the program, system, project, operation, or topic covered |
| Original Classification Authority | Identifies the authority responsible for the classification decisions |
| Point of contact | Provides a source for questions or clarification |
| Issue or review date | Shows when the guidance was issued or reviewed |
| Information element | Specifies exactly what information the instruction covers |
| Classification level | Identifies whether the information is Confidential, Secret, Top Secret, or unclassified |
| Classification reason | Connects the decision to an authorized classification category |
| Duration | Provides the applicable declassification instruction |
| Additional controls | Identifies other controls or qualifying instructions when applicable |
Precision is important. Instead of broadly stating that all “technical information” about a program is Secret, an effective SCG separates specific capabilities, vulnerabilities, technical characteristics, and other information elements so each can receive the appropriate treatment.
That level of detail is central to what is a security classification guide: the goal is to provide precise instructions rather than encourage users to classify an entire subject more broadly than necessary.
What Does a Security Classification Guide Format Look Like?

Security Classification Guides do not all use an identical layout, but the format should make it easy to connect each information element with its classification instructions. Seeing this structure also helps explain what is a security classification guide in practical terms.
A simplified SCG format might look like this:
| Information Element | Level | Reason | Declassify On | Controls |
|---|---|---|---|---|
| Information Element A | U/C/S/TS | Applicable category | Date or event | If applicable |
| Information Element B | U/C/S/TS | Applicable category | Date or event | If applicable |
ISOO guidance also encourages clear distinctions between why information has value, what national-security damage unauthorized disclosure could cause, and what can be stated without revealing the classified element.
These details are important to what is a security classification guide because a well-structured SCG should help users protect specific sensitive information without unnecessarily classifying everything associated with the subject.
Security Classification Levels Explained
Executive Order 13526 establishes three standard levels of classified national-security information based on the potential damage caused by unauthorized disclosure.
| Level | Expected Damage From Unauthorized Disclosure |
|---|---|
| Confidential | Damage to national security |
| Secret | Serious damage to national security |
| Top Secret | Exceptionally grave damage to national security |
- Confidential: Applies when unauthorized disclosure could reasonably be expected to cause damage to national security.
- Secret: Applies when unauthorized disclosure could reasonably be expected to cause serious damage to national security.
- Top Secret: Applies when unauthorized disclosure could reasonably be expected to cause exceptionally grave damage to national security.
The classification level must match the expected harm from disclosure. Information should not receive a higher classification level simply because it provides greater protection.
What Types of Information Can Be Classified?
Executive Order 13526 limits original classification to specific categories of national-security information. A security classification guide helps authorized personnel identify which types of information require protection and apply the correct classification standards.
Eligible information may concern:
- Military plans, weapons systems, or operations
- Foreign-government information
- Intelligence activities, sources, methods, or cryptology
- U.S. foreign relations or foreign activities
- Scientific, technological, or economic matters related to national security
- U.S. programs for safeguarding nuclear materials or facilities
- Vulnerabilities or capabilities of systems, installations, infrastructure, projects, plans, or protection services
- Development, production, or use of weapons of mass destruction
However, information does not automatically become classified simply because it falls within one of these categories. Classification requirements must still be met, including a determination that unauthorized disclosure could reasonably be expected to damage national security.
Understanding what is a security classification guide helps explain how these classification decisions are applied consistently across organizations handling sensitive information.
What Cannot Be Classified?
What is a security classification guide? It is a tool used to apply legitimate classification standards, not a method for hiding information that is embarrassing, inconvenient, or politically sensitive.
Executive Order 13526 prohibits classifying, continuing classification, or delaying declassification for purposes such as:
- Concealing violations of law
- Hiding government inefficiency or administrative mistakes
- Preventing embarrassment to individuals, organizations, or agencies
- Restricting competition
- Delaying the release of information that does not require national-security protection
The Order also limits the classification of basic scientific research information that is not clearly connected to national security.
Understanding what is a security classification guide is important because an SCG must support justified classification decisions based on national-security concerns. It should provide clear protection requirements without becoming a blanket secrecy tool for avoiding disclosure.
Original Classification vs. Derivative Classification
Understanding the difference between original and derivative classification is essential when learning what is a security classification guide and how classification decisions are applied.
| Original Classification | Derivative Classification |
|---|---|
| Creates an initial classification decision | Applies an existing classification decision |
| Requires Original Classification Authority (OCA) | Does not require OCA authority |
| Determines why information requires protection | Uses the original classification rationale |
| Establishes classification level and duration | Carries existing instructions forward |
| Can provide the basis for an SCG | Commonly relies on an SCG |
Original Classification
Original classification is the initial decision that information requires protection because unauthorized disclosure could harm national security.
Only an Original Classification Authority (OCA) with proper authority can make an original classification decision.
Derivative Classification
Derivative classification involves using existing classified information or approved classification guidance to mark newly created material. This may include incorporating, paraphrasing, summarizing, or restating classified information.
A derivative classifier does not create a new classification decision. Instead, they apply existing classification instructions, often provided through a security classification guide.
Knowing what is a security classification guide helps explain how derivative classifiers apply consistent markings and protection requirements based on established classification decisions.
How Is an SCG Used for Derivative Classification?
What is a security classification guide? It is a reference used by authorized personnel to apply existing classification decisions when creating new documents or materials. During derivative classification, a classifier follows the instructions in an SCG rather than creating a new classification decision.
The basic process includes:
- Identify information covered by the SCG
- Apply the required classification markings
- Mark portions according to their classification level
- Determine the overall classification of the document
- Include the classification source and declassification instructions
Under 32 CFR § 2001.22, derivative classifiers must identify the classification source on the “Derived From” line. When an SCG is used, the citation should include enough details to identify the guide, such as the issuing agency and date when available.
Common portion markings include:
- (U) — Unclassified
- (C) — Confidential
- (S) — Secret
- (TS) — Top Secret
The overall classification of a document is generally based on the highest classification level of information contained within it. A derivative classifier applies the decisions already established in the SCG rather than making a new original classification determination.
Understanding what is a security classification guide helps explain why derivative classifiers rely on approved guidance to ensure consistent classification and marking practices.
What Happens When Multiple Classification Sources Apply?
A derivative document may sometimes rely on more than one classification source. This can include multiple Security Classification Guides (SCGs), classified source documents, or a combination of both.
When several sources are used, the classifier must identify all applicable sources and apply the correct classification instructions.
Under 32 CFR § 2001.22, documents based on multiple classification sources use:
Derived From: Multiple Sources
The supporting source materials must also be listed on or attached to the derivative document. The classifier then applies the appropriate declassification instruction, generally following the source with the longest classification duration according to applicable rules.
This process helps maintain accountability and ensures that classification decisions remain traceable when multiple sources contribute to a single document.
Who Creates and Approves a Security Classification Guide?
A security classification guide is created under the authority of an Original Classification Authority (OCA). Executive Order 13526 requires agencies with original classification authority to prepare classification guides to support consistent and accurate derivative classification.
An SCG must be approved in writing by an official who:
- Has program or supervisory responsibility for the information, or is the senior agency official; and
- Holds original classification authority at a level equal to or higher than the highest classification level included in the guide.
Although the OCA approves the guide, development often involves input from:
- Subject-matter experts
- Security specialists
- Guide users
- Foreign-disclosure specialists, when applicable
Coordination may also be necessary when information involves multiple agencies or shared interests. However, an SCG should only address information within the issuing authority’s jurisdiction and should not create classification decisions for another agency.
Who Uses Security Classification Guides?
Security Classification Guides are used by authorized personnel who create, review, or handle information covered by classification guidance. This may include government employees, military personnel, intelligence staff, security specialists, and authorized contractors involved in derivative classification.
Access to an SCG does not grant Original Classification Authority. It only provides instructions for applying existing classification decisions.
Does an SCG Give Someone Access to Classified Information?
What is a security classification guide? It is a document that provides classification instructions; it does not grant permission to view classified information.
Classification authority and access authority are separate. A person generally needs:
- A favorable security eligibility determination
- A signed approved nondisclosure agreement
- A legitimate need to know the specific information
| Concept | What It Addresses |
|---|---|
| Security eligibility/clearance | Whether someone is approved for classified access |
| Need-to-know | Whether someone requires specific information for an authorized purpose |
| Security Classification Guide | How specific information should be classified and protected |
Having access to an SCG does not provide unrestricted access to all classified information connected to a program.
Do Derivative Classifiers Need Special Training?

Yes. Personnel who apply derivative classification markings must receive training on proper classification practices and avoiding unnecessary classification.
Under Executive Order 13526, derivative classifiers must complete required training at least once every two years. Failure to complete required training may suspend their authority to apply derivative markings, subject to limited exceptions.
Security education is important because what is a security classification guide only provides the classification instructions. Properly trained personnel are required to interpret and apply those instructions correctly.
Security Classification Guide Example
What is a security classification guide? It is a document that identifies specific information elements requiring protection and explains the appropriate classification handling for each element. Because real SCGs may contain sensitive or classified details, public examples should use fictional and simplified scenarios.
Fictional Program: Project Northstar
| Information Element | Classification Guidance |
|---|---|
| Public project name | Unclassified |
| Publicly announced purpose | Unclassified |
| Protected technical capability | Apply approved classification guidance |
| Sensitive operational details | Apply approved classification guidance |
| Combined information revealing sensitive relationships | Review compilation guidance |
The key feature of an effective SCG is specificity. Instead of classifying an entire program broadly, a well-written guide identifies individual information elements and explains which details require protection.
This approach helps organizations protect sensitive information while still allowing appropriate access to information that does not require classification.
SCG vs. DD Form 254 vs. CUI vs. Other Guidance
Understanding what is a security classification guide becomes easier when comparing it with other security-related documents and concepts that are often confused.
| Item | Primary Purpose | Classified? |
|---|---|---|
| Security Classification Guide (SCG) | Provides instructions for classifying and protecting specific information | Depends on contents |
| Classified Source Document | Contains already classified information | Yes |
| DD Form 254 | Communicates security requirements for classified government contracts | Not necessarily |
| CUI Guidance | Controls safeguarding and sharing of unclassified sensitive information | No |
| Declassification Guide | Provides instructions for reviewing and removing classification | Depends on contents |
SCG vs. DD Form 254
A Security Classification Guide provides classification instructions, while DD Form 254 (Contract Security Classification Specification) communicates security requirements for contractors handling classified information.
The two documents may work together, but they serve different purposes.
SCG vs. CUI
Controlled Unclassified Information (CUI) is protected information that requires safeguarding but is not classified under Executive Order 13526 or the Atomic Energy Act.
Therefore:
CUI ≠ Confidential
Confidential is a national-security classification level, while CUI remains unclassified.
SCG vs. Declassification Guide
An SCG explains how information should be classified. A declassification guide explains when classified information may be reviewed for possible declassification.
How Long Does Information Stay Classified?
What is a security classification guide? It is a document that helps determine not only how information is classified but also how long protection requirements should apply.
Classification is not permanent. An Original Classification Authority (OCA) sets a declassification date or event based on how long the information is expected to remain sensitive.
Key points:
- Classification duration depends on the expected national-security risk.
- Derivative classifiers generally follow the declassification instructions provided in the applicable classification guide.
- Most classification should not continue longer than necessary and is subject to Executive Order 13526 rules.
- Certain sensitive information may qualify for extended protection under approved exemptions.
Understanding what is a security classification guide also helps explain why classification periods are established in advance rather than allowing information to remain protected indefinitely.
What Changed for SCG Declassification Guidance in 2025?
What is a security classification guide? It is a document that must remain accurate as classification rules, technology, and national-security needs change.
In 2025, ISOO issued Notice 2025-01, clarifying how agencies may include approved automatic-declassification exemptions in Security Classification Guides. The update emphasized that extended classification must follow proper Executive Order and ISCAP requirements.
How Are Security Classification Guides Reviewed?
Security Classification Guides are reviewed periodically because information can lose sensitivity over time.
Reviews consider whether:
- classification decisions remain necessary;
- technology or circumstances have changed;
- classification levels and durations are still appropriate;
- guidance can be reduced or removed.
Under 32 CFR § 2001.16, agencies must conduct Fundamental Classification Guidance Reviews (FCGRs) at least once every five years.
Understanding what is a security classification guide also includes knowing that these guides are updated to maintain accurate protection while reducing unnecessary classification.
SCG Updates, Challenges, and Declassification
What is a security classification guide? It is a document that can be updated, replaced, or cancelled as classification requirements change. Agencies revise SCGs when information becomes outdated, programs change, or protection requirements no longer apply.
Key points:
- SCGs may be updated, superseded, consolidated, or cancelled when necessary.
- Classification decisions can be challenged through authorized agency procedures.
- The public may request review of classified information through the Mandatory Declassification Review (MDR) process.
- Information does not automatically become declassified because it appears in leaks, media reports, or public discussions.
- Official classification status changes only through approved government processes.
Understanding what is a security classification guide also means recognizing that SCGs provide classification instructions while allowing for review, correction, and declassification when appropriate.
Common Security Classification Guide Mistakes
What is a security classification guide? It is a tool that helps apply consistent classification decisions, but mistakes in using one can lead to over-classification, improper handling, or outdated protection requirements.
Common mistakes include:
- Classifying broad topics instead of specific information elements.
- Confusing security clearance with Original Classification Authority.
- Choosing higher classification levels without considering actual national-security impact.
- Ignoring classification by compilation, where combined facts may reveal sensitive information.
- Failing to include declassification instructions or update outdated guidance.
- Confusing CUI with classified information.
- Creating new original classification decisions without proper authority.
- Assuming public disclosure automatically removes classification.
Understanding what is a security classification guide helps users apply classification rules correctly and avoid unnecessary secrecy or improper protection.
Why Security Classification Guides Matter in 2026
What is a security classification guide? It is a document that helps organizations apply consistent protection rules as classified information is created, shared, and processed.
Security Classification Guides remain important under Executive Order 13526 because modern environments now involve:
- Cloud systems and digital platforms
- Artificial intelligence tools
- Automated data analysis
- Contractor and partner networks
Recent policy developments, including guidance on AI use with classified information and CUI, highlight the need for accurate classification decisions. These changes do not replace SCGs but reinforce the importance of clear classification instructions.
Understanding what is a security classification guide is especially important in 2026 because information is moving through more complex technology environments while still requiring proper protection and handling.
Why Over-Classification Matters as Much as Under-Classification
Protecting classified information is important, but unnecessary classification can also create problems.
Over-classification may:
- Limit appropriate information sharing
- Increase security and management costs
- Reduce operational efficiency
- Make oversight and accountability more difficult
- Hide truly sensitive information among too much protected material
The classification system is designed to protect information that requires protection while avoiding unnecessary restrictions.
A well-designed Security Classification Guide supports this balance by helping organizations:
- Protect information that genuinely requires security controls
- Avoid classifying information that does not meet classification standards
Conclusion: Why Security Classification Guides Matter
What is a security classification guide? It is a structured document that helps authorized personnel apply consistent classification decisions by identifying what information requires protection, the appropriate classification level, and the required handling procedures.
A well-developed Security Classification Guide helps protect sensitive national-security information while also preventing unnecessary classification. It creates a clear process for applying, reviewing, and updating classification decisions as requirements change.
What is a security classification guide matters because accurate classification supports both security and responsible information management. A strong SCG ensures that information receives the right level of protection without creating unnecessary restrictions.
What Is A Security Classification Guide FAQs
1. Why do agencies need a Security Classification Guide?
A Security Classification Guide helps agencies apply the same classification rules across different teams and prevents inconsistent decisions about sensitive information.
2. What information does a Security Classification Guide identify?
A Security Classification Guide identifies specific information elements, their classification level, classification reason, protection duration, and any additional handling instructions.
3. Can a Security Classification Guide reduce over-classification?
Yes. A properly written SCG helps prevent unnecessary classification by showing exactly what information requires protection instead of broadly classifying an entire subject.
4. What happens if a Security Classification Guide becomes outdated?
An outdated SCG may be reviewed, revised, replaced, consolidated, or cancelled when classification requirements change or information no longer requires the same level of protection.
5. How does a Security Classification Guide support contractors?
Authorized contractors can use applicable SCGs when handling government information to apply existing classification decisions consistently during contract work.
6. Can a Security Classification Guide classify information from another agency?
No. An SCG should only address information within the issuing authority’s jurisdiction and cannot independently create classification decisions for another agency.
7. Why is precision important in a Security Classification Guide?
Precision prevents unnecessary secrecy by separating specific sensitive information elements from information that can remain unclassified.
8. How does artificial intelligence affect Security Classification Guides?
AI systems create new information-handling challenges, making accurate classification guidance more important when classified information is processed through modern technologies.