Executive Order 13526
Executive Order 13526 is a presidential directive that governs how the U.S. government classifies, safeguards, and eventually declassifies national security information. It sets out the rules for what may be treated as classified and the levels of classification used to protect it. Because it is a policy for national security information, it is generally distinct from the frameworks that govern Controlled Unclassified Information (CUI) or unclassified federal and defense systems.
Executive Order 13526 is an executive order establishing the policy framework for classifying, protecting, and declassifying national security information within the executive branch. It generally addresses classification authority, classification levels, standards and criteria for original and derivative classification, safeguarding requirements, and declassification and downgrading processes for classified national security information. Its scope is national security information and should not be conflated with the security and privacy control frameworks applicable to unclassified federal civilian systems (for example those addressed under FISMA and NIST SP 800-53) or CUI protection requirements (for example NIST SP 800-171); classified systems and facilities are also subject to additional governing authorities. Because specific provisions, definitions, and any amendments or superseding directives may change, and because agency-specific implementing guidance exists, practitioners should verify the current authoritative text and applicable agency policy before relying on particular requirements. This entry does not cover implementation procedures, marking specifics, or the interaction with related regulations, which must be confirmed against current official sources.
Why it matters
Executive Order 13526 establishes the baseline policy that determines what information the executive branch may treat as classified national security information and how it must be handled across its lifecycle. For compliance officers, security managers, and authorizing officials, this matters because classification decisions carry legal and operational consequences: information determined to be classified is subject to safeguarding, access, and handling requirements that differ substantially from those governing unclassified systems. Misunderstanding the boundary between classified national security information and other categories of protected information can lead to over-classification, improper marking, or inadequate protection.
A frequent and consequential mistake is conflating the framework EO 13526 provides for classified national security information with the frameworks that govern Controlled Unclassified Information (CUI) or unclassified federal and defense systems. CUI protection requirements and the security control frameworks applicable to unclassified federal civilian and defense systems are distinct from classification policy, and treating them as interchangeable can result in applying the wrong safeguarding regime. Practitioners should recognize that classified systems and facilities are subject to additional governing authorities beyond this order.
Because specific provisions, definitions, and any amendments or superseding directives may change over time, and because individual agencies issue their own implementing guidance, reliance on EO 13526 in practice requires consulting the current authoritative text and applicable agency policy. Assuming that a general understanding of the order is sufficient for a specific classification, marking, or declassification action can introduce compliance risk.
Who it's relevant to
Inside Executive Order 13526
Common questions
Answers to the questions practitioners most commonly ask about Executive Order 13526.