Skip to main content
Category: Laws & Executive Orders

Executive Order 13526

Also known as: EO 13526, Classified National Security Information (Executive Order)
Simply put

Executive Order 13526 is a presidential directive that governs how the U.S. government classifies, safeguards, and eventually declassifies national security information. It sets out the rules for what may be treated as classified and the levels of classification used to protect it. Because it is a policy for national security information, it is generally distinct from the frameworks that govern Controlled Unclassified Information (CUI) or unclassified federal and defense systems.

Formal definition

Executive Order 13526 is an executive order establishing the policy framework for classifying, protecting, and declassifying national security information within the executive branch. It generally addresses classification authority, classification levels, standards and criteria for original and derivative classification, safeguarding requirements, and declassification and downgrading processes for classified national security information. Its scope is national security information and should not be conflated with the security and privacy control frameworks applicable to unclassified federal civilian systems (for example those addressed under FISMA and NIST SP 800-53) or CUI protection requirements (for example NIST SP 800-171); classified systems and facilities are also subject to additional governing authorities. Because specific provisions, definitions, and any amendments or superseding directives may change, and because agency-specific implementing guidance exists, practitioners should verify the current authoritative text and applicable agency policy before relying on particular requirements. This entry does not cover implementation procedures, marking specifics, or the interaction with related regulations, which must be confirmed against current official sources.

Why it matters

Executive Order 13526 establishes the baseline policy that determines what information the executive branch may treat as classified national security information and how it must be handled across its lifecycle. For compliance officers, security managers, and authorizing officials, this matters because classification decisions carry legal and operational consequences: information determined to be classified is subject to safeguarding, access, and handling requirements that differ substantially from those governing unclassified systems. Misunderstanding the boundary between classified national security information and other categories of protected information can lead to over-classification, improper marking, or inadequate protection.

A frequent and consequential mistake is conflating the framework EO 13526 provides for classified national security information with the frameworks that govern Controlled Unclassified Information (CUI) or unclassified federal and defense systems. CUI protection requirements and the security control frameworks applicable to unclassified federal civilian and defense systems are distinct from classification policy, and treating them as interchangeable can result in applying the wrong safeguarding regime. Practitioners should recognize that classified systems and facilities are subject to additional governing authorities beyond this order.

Because specific provisions, definitions, and any amendments or superseding directives may change over time, and because individual agencies issue their own implementing guidance, reliance on EO 13526 in practice requires consulting the current authoritative text and applicable agency policy. Assuming that a general understanding of the order is sufficient for a specific classification, marking, or declassification action can introduce compliance risk.

Who it's relevant to

Original and Derivative Classifiers
Individuals who make or apply classification decisions rely on the standards and criteria that EO 13526 establishes for original and derivative classification. They should verify the current authoritative text and their agency's implementing guidance before making classification determinations, since specific criteria and procedures are set out in policy that may be amended.
Security Managers and Compliance Officers
Personnel responsible for safeguarding national security information use this order as a reference point for classification levels and safeguarding requirements. They should be careful to distinguish these requirements from those governing CUI or unclassified federal and defense systems, which fall under separate frameworks, and should confirm that classified systems and facilities meet the additional governing authorities that apply to them.
Records and Declassification Staff
Those managing declassification and downgrading of classified information reference the processes addressed by the order. Because procedural specifics reside in agency implementing guidance and provisions may change, these practitioners should consult current official sources rather than relying on a general understanding of the order alone.
Auditors and Authorizing Officials
Reviewers assessing whether classified national security information is handled appropriately should understand that EO 13526 sets policy for national security information and is distinct from the security and privacy control frameworks used for unclassified systems. They should avoid conflating classification policy compliance with the assessment and authorization activities that apply to unclassified federal or defense information systems.

Inside Executive Order 13526

Classification Authority
Executive Order 13526 establishes the framework under which information may be classified in the interest of national security, identifying original classification authorities (OCAs) who are designated officials permitted to make initial classification determinations. Readers should verify the current text of the order and any implementing directives for the precise designation and delegation requirements.
Classification Levels
The order provides for the classification of national security information at levels generally described as Top Secret, Secret, and Confidential, each tied to the degree of expected damage to national security if disclosed. Consult the governing text for the exact damage standards associated with each level.
Classification Categories
The order identifies the categories of information that may be considered for classification, such as information concerning national defense and foreign relations. The specific enumerated categories should be confirmed against the current authoritative text.
Declassification and Downgrading
The order addresses processes for declassification, including automatic, systematic, and mandatory declassification review, and for downgrading information as sensitivity diminishes over time. The applicable timeframes and procedures should be verified against the order and its implementing guidance.
Safeguarding of Classified Information
The order contemplates requirements for protecting classified national security information from unauthorized disclosure, with implementation details generally elaborated in subordinate directives and agency policy rather than in the order alone.
Scope: National Security Information
Executive Order 13526 governs classified national security information and is distinct from frameworks addressing Controlled Unclassified Information (CUI) or unclassified federal information systems under FISMA. Its subject matter concerns classification of information, not the risk management or authorization of information systems.

Common questions

Answers to the questions practitioners most commonly ask about Executive Order 13526.

Does Executive Order 13526 govern the protection of Controlled Unclassified Information (CUI)?
No. Executive Order 13526 addresses classified national security information (information classified as Confidential, Secret, or Top Secret). CUI is a separate category governed under a distinct authority and is not classified information. Conflating the two is a common error; the marking, handling, and safeguarding regimes differ, and readers should confirm the applicable authority for each information type against current official sources.
Once information is classified under Executive Order 13526, does it stay classified permanently?
Generally, no. Classification under Executive Order 13526 is intended to be time-bound rather than perpetual. The order contemplates declassification processes and durations for classification, and information is not meant to remain classified indefinitely without justification. Treating a classification decision as permanent overlooks the declassification and review mechanisms the order establishes. Consult the current text of the order and implementing guidance for the specifics that apply to a given case.
Who has the authority to make original classification decisions under Executive Order 13526?
The order limits original classification authority to specifically designated officials, and this authority is not held by every government employee or contractor. Personnel who handle classified information more commonly apply derivative classification based on existing guidance rather than making original classification decisions. Organizations should verify the designation of original classification authorities and applicable delegations against current official guidance.
How does Executive Order 13526 relate to the RMF-based safeguarding of classified systems?
Executive Order 13526 addresses the classification, marking, and declassification of national security information itself, while the safeguarding of the information systems that process, store, or transmit that information is generally handled through separate security frameworks and, for national security systems, agency- and community-specific requirements. Compliance with classification requirements under the order does not by itself establish that a system is authorized to operate; assessment and authorization are governed by other authorities that readers should confirm.
What is the practical difference between original and derivative classification under this order?
Original classification is the initial determination that information requires protection, made by a designated original classification authority. Derivative classification, which is far more common in day-to-day practice, involves incorporating, paraphrasing, restating, or generating classified information based on existing source documents or classification guidance. Personnel performing derivative classification should carry forward markings and durations accurately from the source and follow applicable derivative classification guidance.
How should personnel handle uncertainty about the classification level of a document?
When the appropriate classification level is unclear, personnel should generally not guess or default to a level, and should instead consult applicable classification guides, the security manager, or the relevant original classification authority for a determination. Handling procedures and marking obligations follow from the correct classification level, so resolving uncertainty through the proper channels rather than assuming a level is the sound practice. Confirm your organization's specific procedures against current official guidance.

Common misconceptions

Executive Order 13526 governs the same information as CUI and FISMA-based controls like NIST SP 800-171 and SP 800-53.
The order addresses classified national security information and its classification, declassification, and safeguarding. Controlled Unclassified Information is a separate category handled under different authorities, and system-level security control baselines are maintained by NIST. These regimes should not be treated as interchangeable, and readers should confirm which body of guidance applies to their information and systems.
Once information is classified under the order, it remains classified indefinitely.
The order provides for declassification and downgrading, including systematic and mandatory review processes, so classification is generally time-bound and subject to reevaluation rather than permanent. The specific timeframes and review mechanisms should be verified against the current authoritative text.
Complying with Executive Order 13526 means an organization's information systems are secure.
The order addresses the classification and safeguarding of national security information, which is distinct from demonstrating that a given information system is secure or authorized to operate. Compliance with classification requirements does not by itself establish system security, and readers should not conflate the two.

Best practices

Confirm the current authoritative text of Executive Order 13526 and its implementing directives before relying on any specific classification level definitions, categories, or declassification timeframes, since details should be verified against official sources.
Verify that individuals making original classification decisions are properly designated original classification authorities and are operating within the scope of their delegated authority.
Distinguish classified national security information handled under the order from Controlled Unclassified Information and from system-level obligations under FISMA and NIST publications, and apply the correct authority to each type of information.
Track declassification, downgrading, and review obligations rather than treating a classification determination as permanent, and document the basis and duration for each classification decision.
Coordinate classification and safeguarding practices with your agency's security office to ensure alignment with agency-specific implementing policy, which may impose additional or more detailed requirements.
Do not equate compliance with classification requirements with overall information system security or authorization; assess and address system security separately under the applicable framework.