Last updated: September 2026
If you work with classified national security information, you may encounter the term Security Classification Guide (SCG) frequently. But what is a security classification guide, who creates one, what does it contain, and how is it used?
A Security Classification Guide (SCG) is a documentary form of classification guidance that identifies specific information relating to a subject that must be classified and establishes the applicable classification level and duration, along with other instructions for applying the classification decision.
In simple terms, an SCG acts like a classification rulebook for a particular program, project, system, mission, plan, or subject. It helps authorized personnel consistently determine how specific information should be classified, marked, protected, and eventually declassified.
This guide explains what a security classification guide is, how it works, what information it contains, how it differs from related concepts such as security clearances and Controlled Unclassified Information (CUI), and what to do when an SCG does not clearly address a particular piece of information.
Quick Answer: What Is a Security Classification Guide?
A Security Classification Guide (SCG) is an official document that records classification decisions made under the authority of an Original Classification Authority (OCA) for information related to a program, project, system, mission, or other subject.
Its main purpose is to help derivative classifiers correctly identify, mark, and protect classified information when creating new documents or materials.
An SCG typically identifies:
- The subject covered
- Information requiring protection
- Classification levels
- Reasons for classification
- Declassification instructions and duration
- Handling or dissemination requirements
- The responsible classification authority
- The Office of Primary Responsibility or contact
- The issue or review date
Federal rules establish minimum requirements for classification guides, while individual agencies may add their own requirements.
What Does SCG Stand For?
SCG stands for Security Classification Guide.
You may also encounter related terms such as:
- Security Classification Guidance
- Classification Guide
- Classification Guidance
- SCG
These terms can overlap, but they are not always interchangeable.
A security classification guide is a specific documentary method for recording and communicating original classification decisions. More broadly, security classification guidance can refer to the instructions or information used to determine classification.
The distinction matters because classification guidance can exist in more than one form. An SCG is a formal documentary method for communicating classification guidance and is specifically designed to support consistent derivative classification. A properly marked source document can also provide classification information that may be used in derivative classification when applicable.
What Is the Purpose of a Security Classification Guide?

The main purpose of an SCG is consistency.
Without detailed classification guidance, different people working on the same program could reach different conclusions about the classification of similar information.
An SCG helps prevent that problem by documenting original classification decisions so authorized personnel can apply those decisions consistently.
An SCG Helps Users
- Determine the correct classification level
- Identify information that does not require classification
- Apply appropriate markings
- Determine applicable declassification instructions
- Identify special handling requirements
- Apply dissemination controls
- Create derivative documents consistently
- Know where to ask classification questions
- Avoid unnecessarily classifying information
The goal is not simply to classify more information. The classification system is designed to protect information that meets applicable national-security criteria while supporting appropriate information sharing and eventual declassification.
Who Creates a Security Classification Guide?
A Security Classification Guide is prepared by or under the authority of an Original Classification Authority (OCA) and must be approved in accordance with applicable classification requirements.
An Original Classification Authority (OCA) is an official authorized to make original classification determinations under the applicable classification system.
The classification authority determines which specific information elements require classification and establishes the appropriate classification level, duration, and other applicable guidance.
The SCG then records and communicates those decisions so authorized personnel can apply them later.
Simple Example
Imagine a government program involving a new defense system.
The applicable classification authority may determine that:
- The system’s general name is Unclassified.
- Certain performance specifications are Confidential.
- A particular vulnerability is Secret.
- A specific operational capability is Top Secret.
The SCG records those decisions.
People subsequently working with information about the system can consult the guide rather than independently making a new original classification decision.
How Does a Security Classification Guide Work?
The basic process can be understood in five stages.
Step 1: An Original Classification Decision Is Made
An authorized OCA determines that specific information requires protection because its unauthorized disclosure could damage national security.
Step 2: The Decision Is Documented
The classification decision is incorporated into an SCG or another authorized form of classification guidance.
Step 3: The SCG Identifies Specific Information Elements
The guide explains exactly what information requires protection, what classification level applies, and how long the classification should remain in effect.
Step 4: Authorized Personnel Apply the Guidance
When someone creates a report, briefing, email, presentation, technical document, or other product containing the information, they use the applicable classification guidance.
This is generally known as derivative classification.
Step 5: The Resulting Information Is Marked and Protected
The new product receives the appropriate classification markings and handling requirements.
This creates a chain from the original classification decision to later documents containing the same classified information.
What Information Does a Security Classification Guide Contain?
Federal requirements establish minimum elements that classification guides should contain.
A properly constructed SCG generally identifies the following:
| SCG Element | What It Tells the User |
|---|---|
| Subject matter | What program, project, system, mission, or topic the guide covers |
| Classification authority | The authority responsible for the original classification decisions |
| Office of Primary Responsibility (OPR) / point of contact | Who is responsible for questions regarding the SCG |
| Issue or review date | When the guide was issued or last reviewed |
| Information elements | The specific information that requires protection |
| Classification level | Whether each element is Unclassified, Confidential, Secret, or Top Secret |
| Classification basis or reason | The applicable classification category, basis, and justification |
| Duration | How long the classification applies when specified |
| Declassification instructions | When or how the information may be declassified |
| Special handling | Additional restrictions or caveats when applicable |
| Dissemination controls | Restrictions governing distribution when applicable |
| CUI information | Controlled Unclassified Information requirements when applicable |
The exact format varies by agency or organization, but the underlying objective is to make classification decisions precise enough for consistent application.
An SCG is not simply a table saying that a particular item is Secret or Top Secret. The guidance should provide enough information for authorized users to understand what information is covered, why the classification applies, how long it applies, and what procedures must be followed.
The Three U.S. National Security Classification Levels
The U.S. national security classification system currently has three classification levels:
- Confidential
- Secret
- Top Secret
The levels correspond to the degree of damage that unauthorized disclosure could reasonably be expected to cause to national security.
| Classification Level | General Meaning |
|---|---|
| Confidential | Unauthorized disclosure could reasonably be expected to cause damage to national security |
| Secret | Unauthorized disclosure could reasonably be expected to cause serious damage to national security |
| Top Secret | Unauthorized disclosure could reasonably be expected to cause exceptionally grave damage to national security |
The classification level is determined by the applicable original classification rules and documented guidance.
What About Unclassified Information?
Not every piece of information covered by an SCG is necessarily classified.
A guide can identify information that should remain Unclassified.
This is important because a good classification guide should distinguish between information that requires protection and information that does not.
However, Unclassified does not automatically mean publicly releasable.
Other laws, regulations, contractual requirements, privacy protections, CUI requirements, export controls, or agency policies may restrict disclosure.
Security Classification Guidance vs. Security Classification Guide
These terms are closely related but should not automatically be treated as identical.
Security Classification Guidance
This is the broader concept of instructions or information used to determine how information should be classified and handled.
Security Classification Guide
An SCG is a specific documentary method for recording original classification decisions and communicating detailed classification instructions.
Think of it this way:
Classification guidance = the broader instructions
SCG = a formal document used to record and communicate those decisions
This distinction is useful when reading government policies, training materials, or security documentation.
Original Classification vs. Derivative Classification
One of the most important concepts to understand is the difference between original classification and derivative classification.
Original Classification
Original classification occurs when an authorized OCA makes the initial determination that information requires national-security classification.
The OCA determines:
- Whether information requires classification
- What classification level applies
- Why the information is classified
- How long classification should remain in effect
Derivative Classification
Derivative classification occurs when someone creates a new document or product based on information that has already been classified.
This can include:
- Incorporating classified information
- Paraphrasing classified information
- Restating classified information
- Generating a new product containing classified information
Why the Distinction Matters
A person performing derivative classification is generally applying an existing classification decision, not creating a new original classification decision.
The SCG provides the guidance needed to apply that decision consistently.
How Does an SCG Support Derivative Classification?
Suppose an SCG says:
Information about a particular operational capability is classified Secret.
An authorized employee later prepares a briefing containing that capability.
Instead of independently deciding that the information is Secret, the employee applies the existing classification guidance.
The employee must still correctly identify the relevant information, apply required markings, and follow applicable procedures.
Simplified Workflow
OCA → Original classification decision → SCG → Derivative classifier → New classified product
This is one of the most important reasons SCGs exist.
What Does a Security Classification Guide NOT Do?
Understanding what an SCG does not do is just as important as understanding what it does.
An SCG does not:
- Automatically make information classified
- Automatically make information unclassified
- Give someone original classification authority
- Automatically authorize public release
- Replace all security procedures
- Allow users to ignore other applicable classification guidance
- Automatically authorize disclosure to foreign governments
- Grant a person access to classified information
- Grant a security clearance
- Establish need-to-know
A classification guide provides and communicates classification guidance. It does not, by itself, give someone authority to access or disclose classified information.
What If the SCG Does Not Cover the Information?
This is a critical question that basic explanations often overlook.
An SCG may not address every possible piece of information.
If the information you are handling is not clearly covered:
- Do not assume it is automatically unclassified.
- Do not invent a classification decision.
- Check whether another applicable classification guide or source document exists.
- Consult the designated security, classification, or program point of contact.
- If necessary, refer the question to the appropriate classification authority.
The purpose of this process is to prevent inconsistent or unauthorized classification decisions.
Important Warning
Never treat an SCG as a complete substitute for all other applicable classification guidance.
Programs can involve multiple equities, systems, authorities, or sources of classified information.
Classification by Compilation: Why Combining Information Matters
A common question is whether information that is individually unclassified can become classified when combined with other information.
The answer can depend on the applicable classification guidance.
An SCG may identify situations where a combination or compilation of otherwise separate pieces of information requires protection.
For example:
- Fact A is Unclassified.
- Fact B is Unclassified.
- Fact C is Unclassified.
But an existing classification guide determines that a particular combination of A, B, and C reveals a sensitive capability.
The combination may therefore require classification if the applicable guidance covers what the combined information reveals.
Why This Matters
Looking at each fact separately is not always enough.
When reviewing information for classification, users should consider whether the overall combination or compilation reveals information covered by existing classification guidance.
However, users should not assume that any combination of public or unclassified information automatically becomes classified. The applicable classification guidance and classification rules control.
What If the Compilation Is Not Covered by Existing Guidance?
If an existing classification guide specifically covers the compilation, applying that guidance is a derivative classification action.
If the combination reveals a genuinely new aspect that meets classification criteria but is not covered by existing classification guidance, the issue should be referred through the appropriate process to an OCA for an original classification decision.
This distinction helps prevent users from creating unauthorized original classification decisions.
SCG vs. Source Document
An SCG is not the only way classification guidance can be communicated.
A properly marked source document may also provide classified information and markings that can be used in derivative classification when applicable.
| Feature | Security Classification Guide | Source Document |
|---|---|---|
| Primary purpose | Communicates detailed classification decisions for a subject | Contains classified source information and markings that may be used in derivative classification |
| Created from | Original classification decisions | An existing classified information product |
| Used for derivative classification | Yes | Yes, when applicable |
| Focus | Classification guidance | The classified information and its markings |
| Typical use | Program, project, system, mission, or subject guidance | Reports, documents, technical materials, or other classified products |
People sometimes assume that every classification decision must be found in a document titled “Security Classification Guide.”
That is not necessarily the case.
SCG vs. Security Clearance vs. Need-to-Know
These concepts are frequently confused because they address different questions.
| Concept | Main Question |
|---|---|
| Security Classification Guide | How should this information be classified? |
| Security clearance | Has the person been determined eligible for access to classified information at an appropriate level? |
| Need-to-know | Does the person have a legitimate requirement to access this particular information? |
| CUI requirements | What controls apply to specified sensitive unclassified information? |
A security clearance does not automatically mean someone may access every piece of information at that classification level.
A security clearance reflects an individual’s eligibility for access to classified information at a particular level; it does not by itself establish access to every item at that level.
Access also depends on applicable authorization and need-to-know requirements.
Example
Someone with a Secret eligibility determination does not automatically have access to every Secret document.
A classification guide determines the classification of information.
Applicable access controls, authorization requirements, and need-to-know rules determine whether an individual may access it.
SCG vs. CUI
Controlled Unclassified Information (CUI) is another concept that is often confused with classified information.
CUI is sensitive information that requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy but does not meet the requirements for national-security classification.
| Security Classification | CUI |
|---|---|
| Classified for national-security reasons | Controlled but not classified for national-security reasons |
| Confidential, Secret, or Top Secret | Uses applicable CUI categories and controls |
| Governed by the national-security classification framework | Governed by the CUI framework and applicable authorities |
| Unauthorized disclosure is evaluated under classification standards | Handling restrictions come from applicable CUI authorities |
CUI therefore should not simply be treated as a fourth classification level.
Can an SCG Address CUI?
Yes, when applicable.
For example, current DoD classification-guide guidance provides for CUI information to be addressed within applicable classification guidance.
However, CUI requirements can vary by agency, program, contract, and applicable authority. Do not assume that every SCG must contain CUI information.
Can an SCG Contain Both Classified and Unclassified Information?
Yes.
A classification guide can identify both information that requires classification and information that should remain unclassified.
For example:
| Information Element | Possible Treatment |
|---|---|
| Program name | Unclassified |
| General mission | Unclassified |
| Technical specification | Confidential |
| Vulnerability information | Secret |
| Highly sensitive operational capability | Top Secret |
The exact treatment depends on the applicable classification guidance rather than the type of document alone.
Can an SCG Be Classified?
An SCG is not automatically classified merely because it is a classification guide.
Its own classification depends on the information it contains and the applicable classification decisions.
An SCG may include sensitive details about a program, system, capability, or intelligence matter. If the guide itself contains information that requires classification, it must be handled accordingly.
But the title “Security Classification Guide” does not by itself determine its classification level.
Don’t Classify Based Only on the Document Title
A document titled “Security Classification Guide” is not automatically classified, and a document without the word “classified” in its title is not automatically unclassified.
Classification depends on the information, applicable classification decisions, and required markings.
How to Read a Security Classification Guide
If you are given an SCG, start by identifying the following:
1. What Subject Does It Cover?
Determine whether the guide applies to your program, project, system, mission, or information.
2. Who Issued or Approved It?
Identify the responsible classification authority and applicable approving authority.
3. Who Is Responsible for Questions?
Look for the Office of Primary Responsibility (OPR) or designated point of contact.
4. Is the Guide Current?
Check its issue or last-review information and determine whether newer guidance exists.
5. What Exact Information Elements Are Listed?
Do not classify information simply because it relates generally to a classified program.
Look for the specific information element or circumstance addressed by the guide.
6. What Classification Level Applies?
Identify whether the relevant element is:
- Unclassified
- Confidential
- Secret
- Top Secret
7. What Is the Basis for Classification?
Review the stated classification category, basis, and justification.
8. How Long Does Classification Apply?
Check the applicable duration and declassification instructions.
9. Are There Special Controls?
Check dissemination controls, handling caveats, or other restrictions.
10. Is CUI Involved?
If applicable, identify the relevant CUI category and controls.
11. Who Should Answer Questions?
Use the designated point of contact, OPR, security office, or classification authority when the guidance is unclear.
A Simple Security Classification Guide Example
Consider a fictional project called Project Northstar.
An SCG could contain guidance like this:
| Information | Classification | Example Guidance |
|---|---|---|
| Project name | Unclassified | May be used publicly if no other restriction applies |
| General project purpose | Unclassified | General description does not reveal protected information |
| Specific technical capability | Confidential | Protect according to applicable guidance |
| Operational vulnerability | Secret | Unauthorized disclosure could cause serious damage |
| Highly sensitive operational capability | Top Secret | Unauthorized disclosure could cause exceptionally grave damage |
This example is fictional and simplified.
A real SCG would contain much more precise information, including the applicable classification basis, duration or declassification instructions, handling requirements, responsible authority, and other applicable controls.
What Happens When Classification Guidance Changes?
Classification guidance is not intended to remain frozen forever.
Programs evolve, technologies change, threats change, and information may no longer require the same level of protection.
Classification guidance therefore needs to be reviewed and maintained.
The federal classification framework includes the Fundamental Classification Guidance Review (FCGR) process, which is designed to help agencies maintain accurate classification guidance and reduce unnecessary classification.
Important Clarification
A common misconception is:
“Every SCG automatically expires after five years.”
That is not the correct way to understand the five-year review requirement.
The five-year requirement concerns the review of classification guidance. It is not an automatic five-year expiration date for every individual SCG.
Always check the current agency or organizational requirements for the specific guide.
Why Must Security Classification Guides Be Reviewed?
Regular review helps determine whether:
- Information still requires classification
- The classification level remains appropriate
- Declassification instructions remain accurate
- New information needs to be added
- Old information can be removed
- Technology or mission changes affect classification
- Existing guidance creates unnecessary classification
- Different guides conflict with one another
Accurate and current classification guides help support standardized classification and reduce unnecessary classification.
What Is the Fundamental Classification Guidance Review?
The Fundamental Classification Guidance Review (FCGR) is a government-wide review process associated with Executive Order 13526.
Its purpose includes examining classification guidance to help ensure that information is appropriately classified and that unnecessary classification is reduced.
The process is important because classification should not continue indefinitely when information no longer requires protection.
The National Archives identifies FCGR as part of the federal classification oversight framework.
Security Classification Guide and Declassification
An SCG does more than tell people how to classify information.
It can also tell them when classification should end.
A guide should provide applicable declassification instructions, such as:
- A specific date
- A specific event
- An authorized exemption
The purpose is to avoid keeping information classified longer than necessary.
Declassification does not necessarily mean immediate public release. Other legal or regulatory restrictions can still apply to the information.
Security Classification Guide vs. Declassification Guide
A Security Classification Guide and a declassification guide address related but different functions.
| Document | Primary Purpose |
|---|---|
| Security Classification Guide | Identifies information requiring classification and provides classification guidance |
| Declassification guide | Provides guidance for determining when and how information can be declassified |
An SCG may contain declassification instructions because classification guidance can establish how long information should remain classified.
However, a declassification guide or related declassification guidance may provide more detailed instructions for reviewing information for declassification.
Terminology and document structures can vary by agency and program.
What Is a Classification Challenge?
A classification challenge is a formal mechanism through which an authorized holder can question whether information is properly classified.
This is an important part of the classification system because classification decisions are subject to review.
A person who believes information may be improperly classified can use the applicable agency challenge process.
Agencies maintain procedures for processing, tracking, and recording formal classification challenges.
Important Point
A challenge does not automatically make information unclassified.
Until the applicable review process reaches a final determination, the information continues to be handled according to the existing classification requirements.
What If You Believe an SCG Is Wrong?
If you believe an SCG:
- Incorrectly classifies information
- Fails to identify information that requires protection
- Contains conflicting guidance
- Uses outdated information
- Provides unclear declassification instructions
you should not simply ignore the guide.
Instead, follow the applicable classification challenge, review, or security-management process.
The appropriate process may involve the designated security office, classification authority, program office, OPR, or agency review mechanism.
Security Classification Guide and Public Release
One of the biggest misunderstandings about classification guidance is assuming that anything marked Unclassified can automatically be published.
That is not necessarily true.
Unclassified ≠ automatically public.
Information can be unclassified while still being subject to other restrictions.
Examples can include:
- CUI
- Privacy restrictions
- Export-control requirements
- Procurement restrictions
- Contractual restrictions
- Law-enforcement restrictions
- Agency-specific disclosure rules
An SCG may provide classification guidance, but it does not by itself authorize public release.
Security Classification Guide and Foreign Disclosure
Another important distinction is between classification and foreign disclosure.
A person should not assume that an individual who is authorized to access classified information can automatically disclose it to a foreign person, foreign government, international organization, or foreign contractor.
Foreign disclosure is governed by additional rules and authorization processes.
Therefore:
Classification guidance tells you how information is classified.
Foreign-disclosure rules determine whether and under what authority information may be shared outside the authorized U.S. context.
Security Classification Guides for Defense Contractors
SCGs are particularly important in defense and national-security contracting.
Contractors handling classified information may need to apply government classification guidance when preparing:
- Technical reports
- Engineering documents
- Program plans
- Presentations
- Test results
- Proposals
- Briefings
- Other deliverables
Federal contractor requirements can require derivative classification based on applicable source documents or current security classification guidance.
Defense-specific requirements may also impose additional procedures.
DoD Security Classification Guide Requirements
For Department of Defense personnel and contractors, DoDM 5200.45 is an important reference.
The DoD manual is titled:
DoDM 5200.45 — Original Classification Authority and Writing a Security Classification Guide
The current DoD Manuals listing identifies the manual with a date of January 17, 2025.
The manual addresses topics such as:
- Original Classification Authority responsibilities
- Developing classification guidance
- Security Classification Guides
- Interim classification guidance
- Coordination
- Classification decisions
- Declassification instructions
- Dissemination controls
- CUI information within applicable guidance
- Office of Primary Responsibility requirements
- Classification challenges
DoD-specific requirements should not automatically be treated as universal requirements for every federal agency.
Security Classification Guide Training
Training requirements depend on the individual’s responsibilities and the applicable agency or organizational rules.
| Role or Responsibility | Training Context |
|---|---|
| Personnel who work with classified information | Generally receive required security and classification training, including refresher training |
| Original Classification Authorities (OCAs) | Receive specialized training covering original classification responsibilities |
| Personnel who apply derivative classification markings | Receive derivative-classification training according to applicable requirements |
| Personnel with specialized classification responsibilities | May receive additional role-specific training |
Federal classification training can address:
- Original classification
- Derivative classification
- Classification levels
- Classification markings
- Classification authority
- Declassification
- Classification challenges
- Security Classification Guides
- Handling requirements
- Prohibited practices
- Consequences of mishandling classified information
For example, applicable federal requirements provide for annual refresher training for personnel who work with classified information, while derivative-classification training requirements may apply at least once every two years to personnel who perform derivative classification.
Training requirements can vary according to role and applicable agency requirements, so personnel should follow the requirements established by their organization.
Security Classification Guide Decision Tree
When you encounter information that may be classified, a simplified decision process can help.
Step 1: Is There an Applicable SCG?
- Yes: Continue to Step 2.
- No: Look for other applicable classification guidance and consult the responsible authority.
Step 2: Does the Information Match a Specific Information Element or Circumstance?
- Yes: Continue to Step 3.
- No: Do not invent a classification decision.
Step 3: What Classification Level Does the Guidance Specify?
Identify the applicable level.
Step 4: Are There Special Controls?
Check dissemination restrictions, caveats, CUI requirements, or other applicable instructions.
Step 5: What Are the Duration and Declassification Instructions?
Identify the applicable date, event, duration, or exemption.
Step 6: Apply the Required Markings and Handling Procedures
Use the applicable marking and handling rules.
Step 7: If Uncertain, Ask the Responsible Authority
Do not guess.
Common Security Classification Guide Mistakes
Common mistakes when using or interpreting a Security Classification Guide include:
- Treating the entire document as classified when different sections may have different classification levels.
- Assuming everything connected to a classified program is automatically classified.
- Confusing a security clearance with the classification level of information.
- Assuming unclassified information is always available to the public.
- Ignoring how separate pieces of information may become sensitive when combined.
- Using an outdated Security Classification Guide instead of the latest version.
- Guessing the classification level when the SCG is unclear.
- Assuming the five-year review requirement means the SCG automatically expires.
- Believing an SCG gives someone permission to access classified information.
- Assuming an SCG automatically authorizes disclosure to foreign governments or individuals.
Why Accurate SCGs Matter
A well-written SCG can improve several parts of information security.
Consistency
Different users can apply the same classification decisions.
Accuracy
Specific information elements are identified instead of relying on vague descriptions.
Accountability
The responsible classification authority and contacts are documented.
Declassification
Users can identify when information should be reviewed or declassified.
Information Sharing
Clear guidance can help users distinguish information that requires protection from information that does not.
Compliance
Agencies and organizations can demonstrate that classification decisions are documented and managed according to applicable requirements.
Security Classification Guide vs. Security Classification Markings
Another useful distinction is between the guide and the marking.
The SCG tells an authorized user how information should be classified.
The marking communicates the classification and applicable controls on the resulting document or information product.
For example:
SCG: Specifies that a particular technical capability is Secret.
New report: Contains that capability.
Marking: The resulting report receives the appropriate Secret classification markings under applicable marking requirements.
Therefore:
SCG = guidance
Marking = communication of the classification applied to the product
Security Classification Guide vs. Security Policy
An SCG should also not be confused with a broad security policy.
| Document | Primary Purpose |
|---|---|
| Security Classification Guide | Provides specific classification decisions and guidance |
| Security policy | Establishes broader organizational security requirements |
| Security clearance process | Determines eligibility for access |
| CUI policy | Establishes controls for applicable controlled unclassified information |
| Marking guidance | Explains how classification markings should be applied |
| Handling procedures | Explain how information must be stored, transmitted, protected, or destroyed |
Each serves a different function.
The Classification Lifecycle
A useful way to understand an SCG is to view it as part of the entire classification lifecycle.
- Identify: Information is identified as potentially requiring protection.
- Decide: An authorized OCA makes the original classification determination.
- Document: The decision is recorded in an SCG or other authorized classification guidance.
- Apply: Authorized users apply the guidance through derivative classification.
- Mark: The resulting product receives appropriate markings.
- Safeguard: The information is protected according to its classification and applicable controls.
- Review: Classification guidance and information are periodically reviewed.
- Declassify: Information is declassified when applicable requirements are met.
- Dispose or Release Appropriately: Once classification ends, information is handled according to applicable records, disclosure, and disposition requirements.
The classification system therefore extends beyond the initial decision. It involves classification, marking, safeguarding, review, declassification, and appropriate subsequent handling.
Is a Security Classification Guide the Same as a Classification Decision?

No.
An SCG records and communicates original classification decisions.
The original decision is made by an authorized OCA.
A derivative classifier then applies the existing guidance to information incorporated into a new product.
This distinction prevents a common misunderstanding: simply reading an SCG does not give a person the authority to create new original classifications.
Is Every Classified Document Based on an SCG?
Not necessarily.
Classification guidance can come from an applicable SCG or an appropriately marked source document, depending on the circumstances and applicable rules.
However, SCGs are specifically designed to provide detailed guidance for derivative classification and to communicate classification decisions for program-specific information.
Can an SCG Be Used to Classify New Information?
It depends on whether the new information falls within the existing classification guidance.
If the information is covered by the SCG, an authorized user may be able to apply the existing guidance through derivative classification.
If the information represents a genuinely new classification issue that is not addressed by existing guidance, the user should not simply create a new original classification decision unless authorized to do so.
Instead, the issue should be referred through the appropriate classification process.
Why SCGs Are Important for Consistency
Imagine that 100 people are working on the same program.
Without detailed guidance, one employee might mark a technical specification Confidential while another marks the same information Secret. A third might treat it as Unclassified.
An SCG provides a common reference point.
Instead of relying on personal judgment alone, authorized users can apply the same documented classification decision.
That consistency is one of the central functions of an SCG.
Frequently Asked Questions
1. What Does SCG Stand For?
SCG stands for Security Classification Guide.
2. Who Creates a Security Classification Guide?
An SCG is created under the authority of an Original Classification Authority (OCA) and approved according to applicable classification requirements.
3. What Are the Three U.S. Classification Levels?
The three national-security classification levels are Confidential, Secret, and Top Secret.
4. Does an SCG Classify Everything Related to a Program?
No. An SCG identifies specific information that requires protection. Not everything associated with a classified program is automatically classified.
5. Does Unclassified Mean Public?
No. Unclassified information may still be restricted by CUI rules, privacy requirements, export controls, contracts, or other policies.
6. Does an SCG Give Someone Classification Authority?
No. Using an SCG does not make someone an Original Classification Authority.
7. Is Every Security Classification Guide Classified?
No. Whether an SCG is classified depends on the information contained within the guide.
8. What Should I Do If an SCG Is Unclear?
Do not guess. Contact the designated OPR, security office, point of contact, or appropriate classification authority for guidance.
Final Thoughts
A Security Classification Guide plays an important role in making sure classification decisions are applied consistently and correctly. It translates decisions made by an Original Classification Authority into practical guidance that authorized users can follow when creating, handling, reviewing, and protecting sensitive information.
A well-prepared SCG explains which information requires classification, the appropriate classification level, why protection is necessary, how long the classification applies, and whether any additional handling or dissemination controls are required. Just as importantly, it helps distinguish genuinely classified information from information that is simply connected to a classified program.
Users should remember that an SCG does not grant security clearance, establish need-to-know, or automatically authorize public or foreign disclosure. It also does not replace applicable rules for CUI, declassification, or classification challenges.
When classification guidance is unclear or does not address a specific situation, the safest and most appropriate approach is to consult the responsible classification, security, or program authority rather than make an assumption.
Ultimately, the purpose of a Security Classification Guide is consistency, accuracy, and protection. By providing clear classification instructions, an SCG helps organizations safeguard national-security information while avoiding unnecessary or inconsistent classification.

