What Is a Security Classification Guide? A Complete Beginner’s Guide
If you searched what is a security classification guide, you may have found a one-line quiz answer: it is a primary source for derivative classification. That is correct, but incomplete. A Security Classification Guide, or SCG, records original classification decisions and tells authorized users which information elements are classified, at what level, for what reason, and for how long.
The guide does not give an employee power to classify information from scratch. It converts an Original Classification Authority’s decisions into instructions that trained derivative classifiers apply to new material. The purpose is consistency, so two people using the same protected facts reach the same answer.
While reviewing the public rules and training materials for this article, I noticed that many online explanations conflate a federal SCG with a company data classification policy. That is a big difference. A private business may label files Public, Internal, Confidential, or Restricted, but those labels do not automatically make the information classified national-security information.
This guide clears up that confusion. It explains who makes the original decision, how the levels work, what an SCG contains, how derivative classifiers use it, and what to check before buying classification-management support.
The Short Answer: What Is a Security Classification Guide?
A Security Classification Guide is an authoritative set of written classification instructions for a specific system, plan, program, project, mission, operation, or subject. It records decisions made by an Original Classification Authority and lets derivative classifiers identify protected information and apply the correct markings without making a new original classification decision.
The official implementing rule for classification guides requires an SCG to identify its subject, approving authority, point of contact, issue or review date, protected information elements, applicable classification level, reason, special handling caveats when needed, and declassification instructions. It also says guides must be distributed as needed to support proper and uniform derivative classification.
The easiest way to remember the purpose is this: the authority decides, the guide records, and the derivative classifier applies. The guide is therefore a decision tool, not a cover sheet, a security clearance, a storage manual, or a person.

What an SCG Is, and What It Is Not
An SCG is a record of classification decisions about individual pieces or elements of information. An element might concern a capability, location, technical specification, vulnerability, schedule, method, relationship, or combination of facts. A well-written guide describes each element narrowly enough that a trained user can recognize it and select one clear result.
An SCG can also identify information that is unclassified or controlled but unclassified when that adds clarity. This matters because a guide should protect what genuinely needs protection without forcing every related fact into the same category. The current DoD manual on original classification and writing SCGs says that timely, precise guidance helps ensure that security resources are used only for information that truly warrants national security protection.
Here is what an SCG is not:
- It is not a person who decides whether information is classified.
- It is not a security clearance or permission to access classified information.
- It is not a classified-document cover sheet.
- It is not a general physical-security plan for rooms, locks, alarms, or guards.
- It is not permission to release information to the public.
- It is not a substitute for required training, access eligibility, need-to-know, or safeguarding rules.
- It does not turn an ordinary private company label into a federal classification level.
The last point is often missed. A corporate data policy may be valuable for privacy, contracts, and cybersecurity, but it is not the same system as an SCG issued under the national-security classification framework.
| Document or concept | Main purpose | Typical labels | Creates federal classified status? |
|---|---|---|---|
| Security Classification Guide | Records original classification decisions and guides derivative classification | Top Secret, Secret, Confidential, Unclassified, and sometimes CUI references | No new decision by the user; it communicates approved decisions |
| Corporate data-classification policy | Sets internal handling rules based on business risk | Public, Internal, Confidential, Restricted | No |
| Security clearance | Establishes an individual’s eligibility for access at a level | Confidential, Secret, Top Secret eligibility | No, and access still requires need to know |
| Properly marked source document | Serves as an authorized source for derivative classification | Markings carried from the source | No new original decision |
I use a simple test when a term sounds vague: ask whether the document records a government OCA’s decision regarding national security information. If the answer is no, you are probably dealing with a business data policy, a handling procedure, or another security document rather than a federal SCG.

Who Designates Whether Information Is Classified?
The direct answer to who designates whether information is classified is the Original Classification Authority (OCA). Under Executive Order 13526, original classification authority may be exercised by the President and Vice President, agency heads and officials designated by the President, and officials who receive a valid written delegation.
That authority is deliberately limited. Delegations must be written and identify the authorized official by name or position. A derivative classifier does not become an OCA simply by using an SCG.
For information to be originally classified under the order, all of the following conditions must be met:
- An authorized OCA makes the determination.
- The information is owned by, produced by or for, or under the control of the government.
- The information falls within at least one permitted classification category.
- Unauthorized disclosure could reasonably be expected to damage national security.
- The OCA can identify or describe that expected damage.
Eligible categories include military plans, foreign government information, intelligence sources or methods, foreign relations, certain national-security scientific or economic matters, nuclear material protection, national-security vulnerabilities, and weapons of mass destruction. A fact does not qualify merely because an organization would prefer to keep it private.
The order expressly prohibits classification to hide violations of law, inefficiency, or administrative error; to prevent embarrassment; to restrain competition; or to delay release when national-security protection is not required. It also says that significant doubt about whether information needs classification should be resolved against classification, while significant doubt about the level should be resolved at the lower level.
If a person without OCA encounters newly created information that appears to require classification, that person should not make the original decision. The information should be protected and referred promptly through the authorized exceptional-case process.

The Three Classification Levels Explained
The national-security system uses three classification levels: Top Secret, Secret, and Confidential. These are based on the reasonably expected damage from unauthorized disclosure, not on how dramatic a document looks, the seniority of its author, or how long it will remain protected.
The official public FAQ on classified national-security information confirms that classified material can take many forms, including paper, photographs, maps, databases, and hard drives. Changing the file format does not remove the protection requirement.
| Classification level | Damage standard if disclosed without authorization | Plain-language meaning |
| Top Secret | Exceptionally grave damage to national security | The highest of the three levels |
| Secret | Serious damage to national security | The middle level |
| Confidential | Damage to national security | The lowest classified level |
“Unclassified” is not a fourth classified level. It means the information is not classified under this three-level system, though it may still be subject to other controls, including Controlled Unclassified Information rules, privacy requirements, export controls, contracts, or agency policy.
“Restricted” is not a current general level in this system. It may appear in private schemes, foreign systems, or the separate statutory term Restricted Data for certain nuclear information, but those uses are not interchangeable.
Classification level and duration answer different questions. The level measures expected damage, while duration states how long protection is required. Users must carry forward the approved declassification instruction rather than guessing at the level.

What the Security Classification Guide States
When a training question says the security classification guide states that a certain fact is Confidential, Secret, Top Secret, Unclassified, or classified only when combined with another fact, that instruction is the starting point for the derivative decision. The user identifies what the new material actually says, matches it to the applicable information element, and carries forward the required level and other markings.
Federal regulations set minimum content requirements for a guide. In practical terms, a usable SCG should answer nine questions:
- What does the guide cover? It should clearly name the system, plan, program, project, mission, operation, or other subject.
- Who made or approved the original decisions? It should identify the OCA by name, position, or personal identifier.
- Who can answer questions? It should provide an agency point of contact.
- How current is it? It should show the issue date or last review date.
- What exact information is protected? It should describe each element of information precisely.
- What level applies? It should assign a clear level to each element and identify unclassified elements when useful.
- Are there extra controls? It should state any applicable special handling caveats or dissemination controls.
- Why is it classified? It should cite a valid category under the governing order and provide a concise reason.
- When does classification end or change? It should give approved declassification or downgrading instructions.
A strong guide is specific. “Technical information: Unclassified to Top Secret” forces the reader to make an original decision and is therefore poor guidance unless the exact conditions for each result are defined. A better entry separates the circumstances into distinct rows, so the reader can find a single answer without inventing a standard.
The guide may itself be classified if its contents or compilation reveal protected information. An unclassified guide may still require controlled handling, so users must follow its markings and distribution rules.
A simplified, fictional SCG row
The following example is invented only to explain the structure. It contains no operational or protected information and is not a substitute for an authorized guide.
| Element of information | Level | Reason | Declassify on | Remarks |
| Public project name | Unclassified | Not applicable | Not applicable | Approved public name only |
| Exact date of a fictional evaluation | Secret | Training example only | Fictional date | Use only as a format example |
| General duration of the fictional evaluation | Confidential | Training example only | Fictional date | Use only as a format example |
| Date and location in the same document | Secret | Fictional compilation example | Fictional date | Combination changes the result |
The value of the table is not the sample label. It is the separation of the element, level, reason, duration, and remarks. In real work, only the current authorized SCG and other approved sources control the answer.
How a Security Classification Guide Works in Practice
Original and derivative classification are related but different. Original classification is the initial government decision that information requires national-security protection. Derivative classification is the process of incorporating, paraphrasing, restating, or generating information in a new form from already classified information, then marking the new material consistently with the authorized source.
The derivative classification training job aid identifies an SCG as the primary source of classification guidance and a properly marked source document as another authorized source. It also explains that if an SCG and a source document appear to conflict about a specific information element, the derivative classifier follows the SCG and seeks guidance as required.
A practical six-step reading method
I translated the official guidance into six beginner-friendly questions. This learning framework does not replace agency procedures or training.
- Identify the new content. Read the exact words, figures, images, metadata, title, subject line, attachments, and context that will appear in the new product.
- Find the authorized source. Use the current applicable SCG or properly marked source document, not memory, an old study guide, or a web answer.
- Match each information element. Determine which specific SCG rows apply to each portion of the new content.
- Check combinations and context. Ask whether multiple facts together reveal something protected or raise the overall level.
- Carry forward the markings. Apply portion markings, overall classification, source information, declassification instructions, and controls as required by current policy.
- Stop when the answer is unclear. Contact the guide’s point of contact or security office rather than making an original classification judgment.
Always use the current guide. Programs, threats, public releases, and classification decisions change, so a superseded guide can produce the wrong result.
This risk-first habit appears in other forms of safety planning too. In our guide to safe backyard archery range planning, the useful question is not only where the target is, but where a realistic miss could go. In classification work, the parallel question is not only what each sentence says alone, but what the document reveals as a whole.

Contained In, Revealed By, and Classification by Compilation
Derivative classification is not limited to copying a sentence word for word. The current public derivative-classification course description highlights three important concepts: contained in, revealed by, and compilation. Understanding them explains why paraphrasing or combining facts can still carry classification.
Contained in
“Contained in” applies when the new material directly includes classified information from an authorized source. The wording may be copied, extracted, or restated with little or no additional analysis. If the protected fact remains present, changing the font, format, or sentence structure does not make it unclassified.
Revealed by
“Revealed by” applies when the new material allows a trained reader to deduce or infer classified information through analysis. The exact classified words may not appear, but the meaning is still disclosed. This is why a derivative classifier must assess substance and context rather than running a simple keyword search.
Classification by compilation
Compilation occurs when unclassified or lower-classified items produce classified information or a higher classification when combined. The SCG should identify foreseeable compilation situations so the derivative classifier is not forced to invent the decision. The public SCG handbook illustrates that two facts can have one result when considered separately and a different result when combined in the same product.
Overall classification is not always found by reading each line alone. Titles, charts, attachments, metadata, and relationships between facts can change what the finished product reveals.

How SCGs Are Created, Approved, Distributed, and Reviewed
An SCG should begin early in the life of a classified system, plan, program, project, or mission. The responsible OCA and supporting experts first determine whether the information meets the requirements for original classification, research-related guidance, identify precise information elements, assign levels, document reasons, set duration, and address handling or dissemination requirements.
The regulation encourages originators to consult with users, subject-matter experts, and agencies that are developing related guidance. Coordination reduces conflict and makes the final instructions easier to apply.
Approval is not a routine administrative signature. Executive Order 13526 requires that each guide be approved personally and in writing by an official who has program or supervisory responsibility for the information, or is the senior agency official, and who can classify originally at the highest level prescribed in the guide.
After approval, the guide must be distributed to the people who need it to ensure proper and uniform derivative classification. Distribution does not mean unrestricted publication. The guide’s own classification, controlled status, dissemination markings, access requirements, and need-to-know rules still apply.
Review is part of the lifecycle, not an optional cleanup task. Agencies must promptly incorporate original decisions into their guides, and the governing framework requires periodic reviews of fundamental classification guidance. The current eCFR provisions on classification guidance review require a review at least once every five years, while an agency may review more often based on its guides and the information they cover.
A meaningful review checks current conditions, classification standards, likely damage, availability, and actual use. The 2025 DoD manual also calls for earlier review when significant changes affect policy, a program, or a mission.
The lifecycle can be summarized as follows:
- Confirm the subject, authority, and original-classification criteria.
- Research existing guidance and coordinate with users and experts.
- Define precise elements, including useful unclassified boundaries.
- Assign one level, valid reason, duration, and applicable controls to each protected element.
- Obtain written approval from an OCA with sufficient authority.
- Distribute through approved channels, update promptly, and review periodically.
- Supersede or cancel obsolete guidance through the proper records process.

Common SCG Mistakes and Why They Matter
The costliest mistakes often begin with vague language. If a row says “program information” without defining what part of the program is protected, users must guess. Some will overclassify to be safe, while others will underclassify because they interpret the phrase narrowly.
Common problems include:
- Using classification ranges without criteria. A range such as Unclassified to Secret is not actionable unless the guide states exactly when each level applies.
- Describing elements too broadly. Broad categories transfer original decision-making to people who do not hold that authority.
- Ignoring unclassified boundaries. Showing what is not classified can prevent unnecessary protection and improve information sharing.
- Confusing level with duration. A higher classification does not automatically mean a longer period, and a lower level does not automatically mean an earlier expiration.
- Missing compilation rules. Separate harmless-looking facts may disclose a protected capability, location, method, or relationship when combined.
- Relying on memory. Derivative classifiers must use an authorized source, especially when the program or guide has changed.
- Using an outdated edition. Old guidance may omit later decisions, new threats, public releases, or changed declassification instructions.
- Treating declassification as public-release approval. Declassified information may still require an authorized release review or remain under another rule’s control.
- Assuming internet disclosure changes status. Unauthorized public appearance does not automatically declassify the information.
- Ignoring the point of contact. When a row does not fit the facts, asking is safer than making an unauthorized original judgment.
The best corrective principle is precision. The seven-step public job aid for writing classification guides warns that vague guidance can lead to overclassification or underclassification, thereby blocking sharing or weakening protection.
Expert Tips for Reading and Managing an SCG
You do not need to memorize every rule to build good habits. You do need a disciplined method that makes uncertainty visible before the document is sent, stored, briefed, or uploaded.
1. Start with the information element, not the desired outcome
Do not begin by deciding what level feels safe and then search for a row that supports it. Identify exactly what the new product reveals, then match that content to the current guide. This keeps the decision tied to the authorized source.
2. Read the remarks and definitions
The short label in the first column may not carry all the conditions. Definitions, notes, exceptions, compilation rules, and remarks can change how a row applies. Read the guide as an integrated instruction, not as a single-cell lookup table.
3. Test titles, metadata, and attachments separately
A safe body paragraph does not guarantee a safe subject line, filename, chart title, embedded image, speaker note, or attachment. Review each component and then assess the product as a whole. This is especially important when multiple sources are used.
4. Treat uncertainty as a workflow event
An unclear row is not an invitation to improvise. Pause the release, protect the material at the appropriate interim level under your procedures, and ask the office of primary responsibility or security contact. A well-managed question can also reveal where the guide needs revision.
5. Write for the next trained user
If you help draft or review guidance, test whether another trained person can reach the same answer without calling the author. Plain language, defined acronyms, one clear outcome per condition, and practical examples make the guide more reliable. This is the same reason I value practical step-by-step guides in any technical subject: clarity reduces avoidable mistakes.
Pros and Cons of a Security Classification Guide
An SCG is a powerful control, but it works only when it is accurate, up to date, available to authorized users, and supported by training. Its strengths and limitations should be evaluated together.
| Advantages | Limitations and risks |
| Creates consistent derivative decisions across users and locations | Vague wording can create inconsistent interpretation |
| Records the OCA’s decision, level, reason, and duration | An outdated guide can spread outdated decisions at scale |
| Reduces reliance on memory and informal advice | It cannot anticipate every new technology, context, or compilation |
| Helps avoid both overclassification and underclassification | Access and distribution controls may make the right guide harder to find |
| Identifies unclassified boundaries that support sharing | Users may mistake the guide for public-release authority |
| Provides a point of contact and review structure | Software cannot replace OCA judgment, policy, or trained human review |
The key is not to treat the guide as a static PDF that disappears into a shared folder. It is a controlled decision product with an owner, a version, an audience, a review cycle, and a feedback path.
When Software or Professional Support Can Help
This topic has commercial intent because organizations involved in classified contracts or programs may need secure document control, workflow, training, records, and review support. The important boundary is that no software vendor or consultant can grant original classification authority or replace the authorized OCA’s decision.
Software can support version control, permissions, source citations, review reminders, change history, and approved templates. It should never invent a level from a generic risk score or rewrite an OCA-approved row.
Before buying an SCG management, governance, document-control, or training solution, ask these questions:
- Can it operate in the approved environment to process the highest volume of information?
- Does it enforce least privilege, need-to-know, and distribution controls?
- Does it protect approval history and show the current effective version?
- Can users trace a decision to the exact approved guide and row?
- Does it track reviews without exposing sensitive metadata?
- Does it support required records retention and preserve markings during export?
- Have security, legal, contracting, records, and system-authorization staff approved it?
For consulting or training support, look for demonstrated experience with the governing framework, your agency or contract environment, derivative classification practices, records management, and secure systems. Ask for a clearly defined scope that distinguishes drafting support, administrative workflow, technical configuration, formal approval, and legal authority.
Red flags include promises to “automatically classify everything,” generic corporate sensitivity labels presented as federal classification levels, cloud storage proposed without an approved environment, and templates that omit authority, reason, duration, or review information. A polished interface cannot repair an invalid source or unauthorized decision.
Frequently Asked Questions
1. What is a security classification guide used for?
A security classification guide is used to communicate approved original classification decisions, enabling trained derivative classifiers to protect and mark new material consistently. It identifies the information elements covered, their level, the reason for classification, duration or declassification instruction, and relevant controls.
2. Is a Security Classification Guide a primary source for derivative classification?
Yes. An SCG is the primary source of guidance for derivative classification, while a properly marked source document is another authorized source. The derivative classifier must use the current applicable source and carry forward the required markings.
3. Who designates whether information is classified and its classification level?
An authorized Original Classification Authority determines whether information is originally classified and selects the appropriate level based on the expected national-security damage from unauthorized disclosure. A derivative classifier applies that existing decision through an SCG or another authorized source but does not create a new original decision.
4. What are the classification levels in a Security Classification Guide?
The three classified levels are Confidential, Secret, and Top Secret. They correspond to damage, serious damage, and exceptionally grave damage to national security, respectively, while Unclassified is not a classified level and CUI is a separate control framework.
5. Does an SCG tell you how to store or share classified information?
An SCG may include special handling caveats and dissemination controls, but it is not the only source for safeguarding rules. Storage, transmission, access, destruction, public release, and incident response must also follow the applicable executive order, regulations, agency policy, contract requirements, system rules, and security procedures.
Final Thoughts
The clearest answer to what is a security classification guide is that it is the written bridge between original and derivative classification. An authorized OCA decides what requires protection, and the SCG records the precise elements, levels, reasons, duration, and controls that trained users must apply.
If you remember only one workflow, remember this: identify the exact content, use the current authorized guide, check the context and compilation, carry forward all required markings, and ask when the guidance does not fit. That disciplined approach protects national-security information while also reducing unnecessary classification and avoidable barriers to sharing.
Before using this article for real work, compare it with your current agency, component, contract, and security-office requirements. Then bookmark the official sources linked throughout this guide and make the authorized point of contact your next stop whenever a classification decision is unclear.
Also Read: How Long Does a Speeding Ticket Stay on Your Record?
Does Georgia Law Require You to Stop Before Turning Right on a Red Light?

