Classified National Security Information
Classified National Security Information is government information that officials have formally determined must be protected from unauthorized disclosure in the interest of national security. Access is restricted to individuals who are cleared and have a need to know. It is commonly referred to simply as classified information.
Classified National Security Information (CNSI) is information that has been determined, pursuant to Executive Order 13526 or a predecessor order, to require protection against unauthorized disclosure and is marked to indicate its classified status. Per CNSSI 4009-2015, the term is treated as synonymous with 'national security information (NSI)' and 'classified information.' Governmentwide policy oversight for the handling of CNSI is provided by the Information Security Oversight Office (ISOO), which also issues guidance on the distinct category of Controlled Unclassified Information (CUI); note that CUI is not classified information and is governed under a separate framework. This entry addresses the definition and scope of the term and does not cover classification level assignment (e.g., Confidential, Secret, Top Secret), specific marking, handling, or safeguarding requirements, or agency-specific implementation, which readers should verify against the current text of the governing executive order and applicable agency guidance.
Why it matters
Classified National Security Information represents the government's most consequential category of protected information, where unauthorized disclosure is formally determined to risk damage to national security. For compliance officers and security managers, the distinction between CNSI and other protected categories is not academic: the frameworks, marking requirements, and access controls that apply to classified information differ fundamentally from those governing unclassified but sensitive data. Misclassifying the two, or assuming that safeguards designed for one apply to the other, can result in either over-restriction or, more seriously, inadequate protection of genuinely sensitive material.
A frequent and consequential error is conflating CNSI with Controlled Unclassified Information (CUI). Although the Information Security Oversight Office (ISOO) provides governmentwide oversight for both categories, CUI is not classified information and is governed under a separate framework. Treating CUI as though it were classified, or vice versa, undermines the credibility of an organization's information protection program and can lead to handling failures. Practitioners should recognize that the governing authority for CNSI is Executive Order 13526 (or a predecessor order), which is distinct from the statutory and regulatory basis for CUI.
Because classification determinations, marking conventions, and safeguarding requirements are established by executive order and implemented through agency-specific guidance, compliance programs cannot rely on generalized assumptions. The authority to classify, the assignment of classification levels, and the handling rules all trace to specific policy that may be revised over time, making it essential to work from current authoritative text rather than institutional memory or secondhand summaries.
Who it's relevant to
Inside CNSI
Common questions
Answers to the questions practitioners most commonly ask about CNSI.