Skip to main content
Category: Classified Information Management

Derivative Classification

Simply put

Derivative classification is the process of creating new documents or materials from information that is already classified, and marking the new product with the appropriate classification. Rather than making an original decision that information needs protection, the person doing derivative classification carries forward the classification decisions already made by others. This applies to national security information within the classified environment.

Formal definition

Derivative classification is generally defined as the incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the newly created material consistent with the classification markings that apply to the source information. It relies on existing classified source documents and/or applicable classification guidance rather than an original classification determination, and is performed from a classification management perspective for national security information. Note that this concept is specific to the national security classification system and is distinct from the marking and handling of Controlled Unclassified Information (CUI) or the control-based regimes such as the RMF; readers should verify current governing authorities and marking requirements against official sources, as the evidence provided here describes the concept but does not establish the controlling regulation or its current revision.

Why it matters

Derivative classification is the mechanism through which the vast majority of classified material in day-to-day government and contractor work is created. Very few people make original classification decisions; instead, most cleared personnel who handle national security information generate new products, reports, briefings, emails, memoranda, that draw on already-classified source documents or classification guidance. Because these individuals carry forward existing classification decisions rather than making new ones, the accuracy of their marking directly determines whether sensitive information is properly protected or improperly exposed or over-restricted.

Errors in derivative classification can have consequences in both directions. Under-marking or failing to carry forward a classification can result in the unauthorized disclosure of national security information, while over-marking can impede legitimate information sharing and burden systems with unnecessary handling requirements. Because the derivative classifier is accountable for applying markings consistent with the source material or guidance, mistakes reflect a breakdown in the chain of classification decisions that originated with an original classification authority.

It is important to keep this concept within its proper scope. Derivative classification applies to the national security classification system and is distinct from the marking and handling of Controlled Unclassified Information (CUI) and from control-based regimes such as the RMF. Personnel should not assume the practices, training, or markings of one regime satisfy the requirements of another, and should verify current governing authorities and marking requirements against official sources.

Who it's relevant to

Cleared personnel creating classified products
Anyone who incorporates, paraphrases, restates, or generates classified information in new form is acting as a derivative classifier and is responsible for marking the resulting material consistent with the source. This includes analysts, program staff, and contractor personnel who routinely produce reports, briefings, and correspondence from existing classified sources.
Security managers and classification management staff
Those responsible for classification management oversee the correct application of derivative markings, ensure personnel complete required training, and address errors in carrying forward source classifications. The concept is taught explicitly from a classification management perspective through courses such as those offered by DCSA/CDSE.
Training and compliance officers
Personnel responsible for workforce readiness must ensure that cleared staff receive derivative classification training that explains the processes and methods derivative classifiers use, and should confirm the specific governing authorities and marking requirements against current official sources rather than assuming they mirror CUI or RMF requirements.

Inside Derivative Classification

Definition of Derivative Classification
The process of incorporating, paraphrasing, restating, or generating in new form information that is already classified, and marking the newly developed material consistent with the classification markings that apply to the source information. It is distinct from original classification, which is the initial determination that information requires protection.
Source of Classification Guidance
Derivative classifiers rely on authorized sources such as a properly marked source document, a Security Classification Guide (SCG), or a DD Form 254 (Contract Security Classification Specification) rather than making an independent original determination. The applicable guidance is issued through the governing classification authority for the program or contract.
Governing Authority
Derivative classification of national security information is generally governed by the executive order on classified national security information and its implementing directive, along with agency-specific and DoD implementing guidance such as the NISPOM for cleared contractors. Readers should verify the current effective versions of these authorities against official sources.
Markings and Carry-Forward Requirements
Derivatively classified material generally must carry forward the classification level, applicable dissemination controls, a citation of the source(s) or classification guide used, the classified-by/derived-from line, and declassification instructions taken from the source. Specific marking formats should be confirmed against current agency and DoD guidance.
Scope Boundary
Derivative classification applies to classified national security information, including material handled by cleared contractors under the NISPOM. It is distinct from the handling and marking of Controlled Unclassified Information (CUI), which follows separate authorities, and this entry does not address CUI, contractual, or legal specifics that a reader must confirm independently.

Common questions

Answers to the questions practitioners most commonly ask about Derivative Classification.

Is derivative classification the same as original classification?
No. These are distinct activities with different authorities. Original classification is the initial determination that information requires protection in the interest of national security, and it may only be performed by officials with delegated original classification authority (OCA). Derivative classification, by contrast, is the act of incorporating, paraphrasing, restating, or generating in new form information that is already classified, and then marking the new material consistent with the classification of the source. Derivative classifiers do not make the underlying determination that information warrants protection; they carry forward determinations already made by an OCA or reflected in a classification guide.
Does someone need to hold original classification authority to perform derivative classification?
No. Performing derivative classification does not require OCA. Cleared personnel who reproduce, extract, paraphrase, or generate new material from existing classified sources are acting as derivative classifiers, generally without needing a special delegation of authority. However, derivative classifiers are typically expected to be trained on proper derivative classification procedures and marking requirements before performing this function. This is a common point of confusion: OCA is required to originally classify information, while derivative classification is a broader responsibility that many cleared individuals may carry out. Confirm the specific training and eligibility requirements against your organization's security policy and current governing guidance.
What sources may a derivative classifier rely on to determine classification?
Derivative classifiers generally rely on authorized classification sources, which typically include a security classification guide and properly marked source documents. When information is drawn from a source document, the derivative classifier carries forward the classification level and associated markings applied to that source. When a classification guide applies, the classifier follows the guidance it provides. Where multiple sources are used, the resulting product generally reflects the most restrictive markings applicable. Consult your applicable classification guide and organizational procedures for the authoritative list of usable sources.
How should a derivatively classified document be marked?
A derivatively classified document generally requires markings that indicate the classification level, the source or sources of the classification, and declassification information. In most implementations this includes portion markings, overall banner markings, and a classification authority block that identifies the source of the derivative classification (such as the applicable source document or classification guide) and reflects declassification instructions carried forward from that source. Exact marking formats and required elements are prescribed by governing marking guidance and may vary by agency; verify the current authoritative marking standard before finalizing any document.
What should a derivative classifier do when sources appear to conflict or seem improperly classified?
When sources conflict, general practice is to apply the most restrictive applicable classification while the discrepancy is resolved. If a derivative classifier believes information may be improperly classified, either over-classified or under-classified, the appropriate step is generally to raise the concern through the established channel rather than unilaterally changing the classification. Many organizations maintain a process for questioning or challenging classification. Follow your organization's specific procedures and escalate to the responsible security office or classification management authority as directed by current guidance.
What training or recordkeeping obligations are typically associated with derivative classification?
Personnel who perform derivative classification are generally expected to receive training on derivative classification principles and marking requirements, often on a recurring basis, before performing the function. Organizations also commonly maintain records reflecting who is authorized or trained to perform derivative classification. The specific frequency of training, the content required, and the recordkeeping expectations are set by governing policy and may differ by agency and by whether the work involves classified national security information under the applicable directives. Confirm the precise training cycle and documentation requirements against your organization's security policy and current authoritative sources.

Common misconceptions

Derivative classification is the same as original classification.
They are distinct. Original classification is the initial determination that information requires protection and may only be performed by designated original classification authorities. Derivative classification applies existing classification determinations to newly created material based on authorized sources, and most personnel who classify are acting as derivative classifiers, not original classification authorities.
A derivative classifier can decide the classification level based on their own judgment of sensitivity.
Derivative classifiers must classify consistent with the source document, Security Classification Guide, or other authorized guidance. They do not independently determine that information warrants protection; they carry forward the determinations already made in the authorized source.
Compliance with derivative classification marking rules means the information is adequately secured.
Correct classification and marking is a labeling and compliance function; it does not by itself provide physical, personnel, or information system security. Protection also depends on separate safeguarding, access control, and handling requirements applicable to the classification level.

Best practices

Classify only from authorized and current sources, such as a properly marked source document, an applicable Security Classification Guide, or a DD Form 254, rather than personal judgment about sensitivity.
Verify that you are relying on the most current classification guidance, since source documents and guides can be revised, superseded, or reclassified over time.
Carry forward all applicable markings from the source, including classification level, dissemination controls, source citation, and declassification instructions, and confirm the required format against current agency and DoD guidance.
Complete and maintain any required derivative classification training on the schedule mandated by your agency or the governing directive before performing derivative classification.
When multiple sources are used, cite each source and apply the most restrictive markings and the latest declassification date indicated by the combined guidance.
Escalate to a designated original classification authority or security officer when the source guidance is ambiguous, conflicting, or absent, rather than making an independent classification determination.