Skip to main content
Category: Classified Information Management

Classified National Security Information

Also known as: CNSI, National Security Information, NSI, Classified Information
Simply put

Classified National Security Information is government information that officials have formally determined must be protected from unauthorized disclosure in the interest of national security. Access is restricted to individuals who are cleared and have a need to know. It is commonly referred to simply as classified information.

Formal definition

Classified National Security Information (CNSI) is information that has been determined, pursuant to Executive Order 13526 or a predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status. Per CNSSI 4009-2015, the term is treated as synonymous with 'national security information (NSI)' and 'classified information.' Governmentwide policy oversight for the handling of CNSI is provided by the Information Security Oversight Office (ISOO), which also issues guidance on the distinct category of Controlled Unclassified Information (CUI); note that CUI is not classified information and is governed under a separate framework. This entry addresses the definition and scope of the term and does not cover classification level assignment (e.g., Confidential, Secret, Top Secret), specific marking, handling, or safeguarding requirements, or agency-specific implementation, which readers should verify against the current text of the governing executive order and applicable agency guidance.

Why it matters

Classified National Security Information represents the government's most consequential category of protected information, where unauthorized disclosure is formally determined to risk damage to national security. For compliance officers and security managers, the distinction between CNSI and other protected categories is not academic: the frameworks, marking requirements, and access controls that apply to classified information differ fundamentally from those governing unclassified but sensitive data. Misclassifying the two, or assuming that safeguards designed for one apply to the other, can result in either over-restriction or, more seriously, inadequate protection of genuinely sensitive material.

A frequent and consequential error is conflating CNSI with Controlled Unclassified Information (CUI). Although the Information Security Oversight Office (ISOO) provides governmentwide oversight for both categories, CUI is not classified information and is governed under a separate framework. Treating CUI as though it were classified, or vice versa, undermines the credibility of an organization's information protection program and can lead to handling failures. Practitioners should recognize that the governing authority for CNSI is Executive Order 13526 (or a predecessor order), which is distinct from the statutory and regulatory basis for CUI.

Because classification determinations, marking conventions, and safeguarding requirements are established by executive order and implemented through agency-specific guidance, compliance programs cannot rely on generalized assumptions. The authority to classify, the assignment of classification levels, and the handling rules all trace to specific policy that may be revised over time, making it essential to work from current authoritative text rather than institutional memory or secondhand summaries.

Who it's relevant to

Information System Security Managers and Security Officers
Personnel responsible for safeguarding sensitive government information must correctly distinguish CNSI from CUI and ensure that access, marking, and handling controls align with the classified status of the material. Because the specific safeguarding requirements derive from the governing executive order and agency implementation rather than from this definition alone, these practitioners should confirm current requirements against authoritative sources.
Compliance Officers and Auditors
Those assessing an organization's information protection posture need to verify that classified and unclassified sensitive categories are treated under their respective frameworks. A common finding an auditor should flag is the conflation of CNSI with CUI, given that CUI is not classified information and is governed under a separate framework despite both falling within ISOO's oversight.
Government Contractors Handling Classified Material
Contractors who may access or store classified information must ensure their personnel are appropriately cleared and operate on a need-to-know basis. They should confirm the applicable classification, marking, and handling obligations against the current governing executive order and agency-specific guidance rather than assuming that controls for other protected categories are sufficient.
Authorizing Officials and Program Managers
Officials accountable for systems that process national security information rely on a clear understanding of what constitutes CNSI and where governmentwide oversight originates. Because classification determinations and safeguarding rules are subject to the terms of the governing executive order and may be revised over time, these decision-makers should base authorization decisions on current authoritative policy.

Inside CNSI

Classification Levels
CNSI is generally categorized into three levels based on the degree of damage to national security that unauthorized disclosure could reasonably be expected to cause: Confidential, Secret, and Top Secret. Practitioners should verify the current definitions against the governing executive order and its implementing directives.
Original Classification Authority (OCA)
Classification originates with officials specifically delegated the authority to make an initial determination that information requires protection. This authority is limited to designated positions and is distinct from derivative classification, which applies existing determinations to newly created material.
Derivative Classification
The incorporation, paraphrasing, restating, or generation of information that is already classified, carrying forward the markings and handling requirements from source documents or a security classification guide.
Marking and Handling Requirements
CNSI must be marked to indicate its classification level and associated caveats, and handled, stored, transmitted, and destroyed according to prescribed safeguarding standards for its level. Specific marking conventions should be confirmed against current authoritative guidance.
Declassification and Downgrading
CNSI is subject to processes for reducing its classification level or removing classification entirely, including duration-based, event-based, and automatic declassification mechanisms as defined in governing policy.
Governing Authority
CNSI is defined and governed primarily by the applicable executive order on national security information and its implementing regulations, rather than by FISMA-based civilian frameworks. Readers should confirm the currently effective executive order and directives.

Common questions

Answers to the questions practitioners most commonly ask about CNSI.

Does compliance with the Risk Management Framework (RMF) or FISMA mean a system is authorized to process Classified National Security Information (CNSI)?
No. Meeting general RMF or FISMA obligations does not by itself authorize a system to handle CNSI. Classified national security systems are subject to separate governing authorities and additional safeguarding requirements beyond baseline federal information security controls. Compliance with a control framework is not the same as authorization to process classified information, and the two should not be conflated. Confirm the specific classification-handling authorities and authorization conditions applicable to your system against current official sources.
Is Classified National Security Information the same thing as Controlled Unclassified Information (CUI)?
No. CNSI and CUI are distinct categories with different governing authorities and safeguarding regimes. Treating them as interchangeable is a common and consequential error. CUI is unclassified information requiring safeguarding or dissemination controls, while CNSI has been formally classified under the applicable national security classification authority. The protections, marking, and handling requirements differ, and applying one regime's rules to the other can result in mishandling. Verify the correct category and its requirements against current authoritative guidance.
How should CNSI be marked so that its classification level is clear to those handling it?
CNSI generally must carry markings that identify its classification level and the associated handling requirements consistent with the governing classification authority. Marking practices are prescribed by official guidance rather than left to individual discretion. Because specific marking conventions and any agency-specific interpretations can vary, this entry does not cover exact marking formats; confirm the required markings against the current authoritative implementing guidance applicable to your organization.
Who is authorized to make classification decisions about information that may qualify as CNSI?
Classification decisions are made by officials acting under the applicable national security classification authority, and derivative classification may occur when handling information based on existing classified sources. This entry does not detail the specific roles, delegations, or procedures, which may have agency-specific interpretations. Verify who holds classification authority in your organization and the governing procedures against current official sources before making or relying on a classification determination.
What should personnel do if they encounter a possible spillage of CNSI onto an unauthorized system?
A suspected spillage of CNSI onto a system not authorized for that classification level is generally treated as a reportable incident requiring prompt handling under established procedures. This entry does not cover the specific reporting channels, containment steps, or remediation requirements, which are governed by applicable policy and may differ by agency and system type. Confirm the exact incident-handling and reporting obligations against your organization's current authoritative guidance.
How does authorization to process CNSI relate to continuous monitoring, and is such authorization permanent?
Authorization to process classified information should not be assumed to be permanent. In most implementations, authorizations are time-bound and remain subject to ongoing oversight and continuous monitoring conditions rather than being granted indefinitely. Treating an authorization as a one-time, permanent status is a common mistake. Verify the specific authorization terms, expiration, and continuous monitoring requirements applicable to your system against the current governing authorities.

Common misconceptions

Classified National Security Information and Controlled Unclassified Information (CUI) are essentially the same and can be handled under the same framework.
CNSI and CUI are distinct categories with different governing authorities and safeguarding regimes. CNSI is national security information classified at Confidential, Secret, or Top Secret under the applicable executive order, while CUI is unclassified information requiring protection under separate policy. Handling one framework's requirements does not satisfy the other's.
Any authorized official can classify information as CNSI.
Original classification may only be performed by officials with delegated Original Classification Authority. Most personnel who work with classified material perform derivative classification, carrying forward existing determinations rather than making original ones.
Once information is classified, it remains classified permanently.
CNSI is subject to declassification and downgrading processes, including duration-based, event-based, and automatic declassification. Classification is intended to be time-bound and reviewable rather than perpetual, as defined in governing policy.

Best practices

Confirm classification determinations against an authoritative security classification guide and the current governing executive order rather than relying on assumptions or informal precedent.
Distinguish clearly between original and derivative classification, and ensure only officials with delegated Original Classification Authority make initial classification decisions.
Apply markings, caveats, and safeguarding measures appropriate to the specific classification level (Confidential, Secret, or Top Secret), verifying conventions against current official guidance.
Do not treat CNSI and CUI as interchangeable; apply the correct governing framework and handling requirements for each category.
Track declassification, downgrading, and review requirements so that classification durations and events are managed rather than allowing information to remain classified indefinitely by default.
Periodically verify handling, storage, transmission, and destruction procedures against the most current implementing directives, since specific requirements may change across revisions.