Skip to main content
Category: Classified Information Management

Original Classification Authority

Also known as:
Simply put

An Original Classification Authority (OCA) is an individual who has been officially authorized to decide, for the first time, that certain information must be classified to protect national security. This authority is generally held by designated senior government officials and must be properly delegated rather than assumed. The OCA determines that information is owned by, produced by or for, or under the control of the government before classifying it.

Formal definition

An Original Classification Authority is an individual authorized in writing to perform original classification of national security information, meaning the initial determination that information requires protection and the assignment of a classification level. Eligibility is contingent on proper delegation of authority consistent with the governing executive order, and OCAs are expected to complete required training on original classification policies, procedures, and the prescribed decision steps. Original classification is distinct from derivative classification; this entry addresses the OCA role generally and does not cover agency-specific delegation chains, quantitative thresholds, or the full procedural requirements, which the reader should verify against the current governing Order and their agency's implementing guidance.

Why it matters

The OCA role is the point of origin for the entire classified information lifecycle. Because original classification is the first-time determination that information requires protection in the interest of national security, the decisions an OCA makes cascade downstream into countless derivative classification actions, marking practices, safeguarding requirements, and eventual declassification. An improper or unauthorized original classification decision can therefore propagate errors across a large body of documents and systems, while a failure to classify information that genuinely warrants protection can expose national security information. This is why the governing framework treats OCA status as a formal, delegated authority rather than something an official may simply assume.

A recurring compliance concern is verifying that the person who made an original classification decision was in fact an OCA and was properly delegated that authority. Guidance from the Information Security Oversight Office frames these as threshold questions for evaluating whether classification was appropriate: was the individual an OCA, and was the authority properly delegated consistent with the governing Order. When these prerequisites are not met, the resulting classification decision is open to challenge, and organizations may need to review and correct affected holdings.

Because eligibility depends on written delegation and completion of required training, OCA compliance is also a training and recordkeeping matter. An official who holds a senior position does not automatically become an OCA; the authority must be delegated in accordance with the applicable executive order and agency implementing guidance, and OCAs are expected to complete training on original classification policies, procedures, and the prescribed decision steps before exercising the authority.

Who it's relevant to

Designated Senior Officials Serving as OCAs
Senior government officials who have been delegated original classification authority in writing must understand that the role carries specific obligations, including establishing government ownership or control of the information and completing required training on original classification policies, procedures, and the prescribed decision steps. Holding a senior position does not by itself confer OCA status; the authority must be properly delegated consistent with the governing Order.
Agency Security Managers and Classification Management Staff
Personnel responsible for classification management need to track which officials hold delegated OCA authority, maintain delegation records, and ensure OCAs complete the required training before exercising the authority. They should verify delegation chains and procedural requirements against the current governing executive order and their agency's implementing guidance rather than relying on general descriptions.
Derivative Classifiers
Individuals who apply or carry forward existing classification decisions should clearly distinguish their role from original classification. Derivative classification relies on decisions already made by an OCA, and understanding this boundary helps ensure classification actions are properly attributed and sourced.
Oversight Reviewers and Auditors
Those evaluating whether classification was appropriate use threshold questions drawn from Information Security Oversight Office guidance, including whether the classifying individual was an OCA and whether the authority was properly delegated. These reviewers should reference the current governing Order when assessing the validity of original classification decisions.

Inside OCA

Designated Authority Position
An OCA is an individual, occupying a specific position, who is authorized in writing to make an initial classification determination that information requires protection in the interest of national security. The authority attaches to the position and its written delegation, not to the person independent of that role.
Classification Level Delegation
OCA authority is delegated at a specific level (Top Secret, Secret, or Confidential) and generally permits classification only at or below the level for which the authority was granted. Practitioners should verify the specific level of any given OCA's delegation against the governing appointment documentation.
Original Classification Decision
The OCA determines that information is owned by, produced by or for, or under the control of the U.S. Government and that its unauthorized disclosure could reasonably be expected to cause identifiable or describable damage to national security. This original decision is distinct from derivative classification, which applies markings based on existing guidance rather than making a new determination.
Duration and Declassification Instructions
As part of an original classification decision, the OCA generally establishes a duration for classification and associated declassification instructions. Specific timeframes and rules should be confirmed against the current governing executive order and implementing directives rather than assumed.
Security Classification Guidance
OCAs are typically responsible for issuing or approving security classification guides (SCGs) that document classification decisions so that others can apply derivative classification consistently. The SCG operationalizes the OCA's original decisions for downstream users.

Common questions

Answers to the questions practitioners most commonly ask about OCA.

Can any cleared employee who handles classified information make an original classification decision?
No. Original classification is a distinct authority that must be delegated in writing, and only individuals designated as Original Classification Authorities (OCAs) may make original classification decisions. Holding a security clearance and having access to classified information does not confer OCA status. Personnel who apply classification markings based on existing guidance, such as a security classification guide or a properly classified source document, are performing derivative classification, not original classification. The distinction between original and derivative classification is fundamental, and readers should confirm the specific designation and delegation requirements against current governing authority.
Does an OCA designation give someone unlimited authority to classify information at any level?
No. An OCA's authority is bounded in several ways. The designation typically specifies the highest classification level the OCA may apply, and authority to classify at a given level does not automatically include higher levels. OCA authority is also generally tied to the subject matter within the official's area of responsibility rather than a blanket power to classify any information. Because these limits and the specific delegation terms can vary, readers should verify the scope of a given OCA designation against the applicable delegation instrument and current governing policy.
How is OCA authority delegated within an organization?
OCA authority is generally delegated in writing through a formal designation that flows from an established chain of authority, and it is typically limited to the minimum number of officials necessary. The delegation ordinarily identifies the position or individual and the highest classification level authorized. Because delegation procedures, documentation requirements, and any restrictions on further redelegation are governed by applicable policy and can differ by organization, confirm the specific process against the current authoritative text before relying on it.
What must an OCA document when making an original classification decision?
When making an original classification decision, an OCA is generally expected to document the basis for the decision, including the reason the information warrants protection and the applicable declassification determination or duration. In most implementations this information is captured so that it can support derivative classification, subsequent markings, and later declassification review. The precise documentation elements and formats are set by governing policy, so verify the current requirements rather than assuming a fixed template.
What is the relationship between an OCA and a security classification guide (SCG)?
A security classification guide typically records the original classification decisions of an OCA in a reusable form so that others can apply consistent markings through derivative classification. In most implementations the OCA is responsible for the accuracy and currency of the guidance attributed to that authority. Personnel using an SCG are generally performing derivative classification rather than original classification. Confirm the specific responsibilities for issuing, approving, and maintaining an SCG against the applicable governing policy.
How should an organization handle situations where no OCA has classified certain information but protection appears warranted?
If information appears to require protection but no applicable original classification decision or guidance exists, the general practice is to safeguard the information pending a determination and to refer the matter to an appropriate OCA, since derivative classifiers cannot make original classification decisions on their own. The specific interim handling, referral procedures, and timelines are governed by applicable policy and may vary by organization, so verify the required process against the current authoritative text.

Common misconceptions

Anyone with a security clearance or access to classified information can make original classification decisions.
Original classification authority is limited to positions specifically and formally delegated that authority in writing under the governing executive order framework. A clearance grants access, not the authority to originally classify. Most personnel who handle classified material perform derivative classification, not original classification.
Original classification and derivative classification are the same activity.
Original classification is the initial determination by an OCA that information requires protection, including setting the level, duration, and declassification instructions. Derivative classification applies markings that flow from existing source documents or classification guides and does not require OCA authority. Conflating the two obscures who is actually accountable for a classification decision.
OCA authority is unlimited once granted.
The authority is bounded by the classification level delegated, the position held, and the requirements of the governing executive order and implementing policy. An OCA generally cannot classify above the delegated level and must be able to identify or describe the damage to national security expected from disclosure.

Best practices

Verify the written delegation and the specific classification level for any OCA position against current appointment documentation before relying on an original classification decision, since authority attaches to the position and its written delegation.
Maintain clear separation between original and derivative classification in policy, training, and records so that accountability for each classification decision is traceable to the correct authority.
Ensure OCAs document original classification decisions in a security classification guide or equivalent so that derivative classifiers can apply consistent markings without re-deriving the underlying determination.
Confirm that classification duration and declassification instructions are established at the time of the original decision and reviewed against the current governing executive order and implementing directives.
Provide role-specific training that clarifies the limits of OCA authority, including that an OCA generally cannot classify above the delegated level and must be able to identify or describe the expected damage to national security.
Confirm all specific requirements, timeframes, and delegation rules against the current authoritative executive order and agency implementing policy, as these details are subject to revision and agency-specific interpretation.