Original Classification Authority
An Original Classification Authority (OCA) is an individual who has been officially authorized to decide, for the first time, that certain information must be classified to protect national security. This authority is generally held by designated senior government officials and must be properly delegated rather than assumed. The OCA determines that information is owned by, produced by or for, or under the control of the government before classifying it.
An Original Classification Authority is an individual authorized in writing to perform original classification of national security information, meaning the initial determination that information requires protection and the assignment of a classification level. Eligibility is contingent on proper delegation of authority consistent with the governing executive order, and OCAs are expected to complete required training on original classification policies, procedures, and the prescribed decision steps. Original classification is distinct from derivative classification; this entry addresses the OCA role generally and does not cover agency-specific delegation chains, quantitative thresholds, or the full procedural requirements, which the reader should verify against the current governing Order and their agency's implementing guidance.
Why it matters
The OCA role is the point of origin for the entire classified information lifecycle. Because original classification is the first-time determination that information requires protection in the interest of national security, the decisions an OCA makes cascade downstream into countless derivative classification actions, marking practices, safeguarding requirements, and eventual declassification. An improper or unauthorized original classification decision can therefore propagate errors across a large body of documents and systems, while a failure to classify information that genuinely warrants protection can expose national security information. This is why the governing framework treats OCA status as a formal, delegated authority rather than something an official may simply assume.
A recurring compliance concern is verifying that the person who made an original classification decision was in fact an OCA and was properly delegated that authority. Guidance from the Information Security Oversight Office frames these as threshold questions for evaluating whether classification was appropriate: was the individual an OCA, and was the authority properly delegated consistent with the governing Order. When these prerequisites are not met, the resulting classification decision is open to challenge, and organizations may need to review and correct affected holdings.
Because eligibility depends on written delegation and completion of required training, OCA compliance is also a training and recordkeeping matter. An official who holds a senior position does not automatically become an OCA; the authority must be delegated in accordance with the applicable executive order and agency implementing guidance, and OCAs are expected to complete training on original classification policies, procedures, and the prescribed decision steps before exercising the authority.
Who it's relevant to
Inside OCA
Common questions
Answers to the questions practitioners most commonly ask about OCA.