Skip to main content
Category: Classified Information Management

Security Classification Guide

Also known as: SCG, Security Classification Guidance
Simply put

A Security Classification Guide (SCG) is an official document that tells people what specific information about a system, plan, program, or mission is classified and at what level. It is issued by an authorized official so that everyone working with the information applies the same classification decisions consistently. It does not itself classify information on the reader's behalf; rather, it communicates classification decisions that an authorized official has already made.

Formal definition

A Security Classification Guide (SCG) is an instruction or source, issued by an Original Classification Authority (OCA), that documents and distributes the OCA's original classification decisions regarding a specific system, plan, program, mission, or project. It identifies elements of information, states whether each is classified and at what level, and thereby enables derivative classifiers and other organizations or activities to apply consistent classification (and, where applicable, declassification) guidance. As reflected in the evidence, an SCG is a document that conveys classification determinations rather than a person who makes those determinations, and it should be distinguished from the OCA who authors it. This entry does not cover the detailed procedural requirements for developing, approving, or maintaining an SCG, nor agency-specific implementation, markings, or declassification timelines; readers should verify those against the current authoritative governing directives and training guidance.

Why it matters

Consistent classification depends on shared, authoritative decisions rather than individual judgment. A Security Classification Guide (SCG) matters because it captures an Original Classification Authority's (OCA's) classification decisions in a single reference so that everyone working with a system, plan, program, mission, or project applies the same level of protection to the same elements of information. Without an SCG, derivative classifiers would be left to interpret classification levels on their own, which generally increases the risk of both over-classification and, more dangerously, under-classification or inadvertent disclosure.

The SCG also enables consistency across multiple organizations and activities that touch the same information. Because it distributes the OCA's guidance broadly, an SCG helps ensure that contractors, program offices, and supporting activities mark and handle information the same way, which is essential when information moves between organizations. This shared baseline supports accountability, because classification determinations can be traced back to an authorized decision documented in the guide rather than to ad hoc interpretation.

A common and consequential mistake is treating the SCG as though it classifies information on the reader's behalf, or confusing the guide with the person who makes classification decisions. The SCG is a document that conveys determinations already made by an OCA; it is not itself the OCA. Misunderstanding this distinction can lead personnel to apply guidance incorrectly or to assume authority they do not have. Readers should confirm specific procedural, marking, and declassification requirements against the current authoritative governing directives, as those details are outside the scope of this entry.

Who it's relevant to

Original Classification Authorities (OCAs)
OCAs make the original classification decisions that an SCG documents and distributes. They are responsible for the accuracy of the guidance conveyed in the guide, and they should understand that the SCG communicates their determinations to others rather than substituting for their authority.
Derivative Classifiers
Derivative classifiers rely on SCGs to apply classification consistently to information they generate or handle. Rather than making original determinations, they apply the OCA's decisions as reflected in the guide, which underscores why understanding the SCG correctly is essential to avoiding misclassification.
Program and Security Managers Across Organizations and Activities
Because an SCG is used to distribute an OCA's guidance to all relevant organizations and activities, program offices, supporting contractors, and their security personnel depend on it to align how the same information is marked and protected when it moves between organizations.
Classification Management Trainers and Personnel in Training
Training resources on security classification and declassification guidance address how classifiers use SCGs within the classification determination process. Personnel learning these roles benefit from understanding what an SCG is, and just as importantly, what it is not, to apply it correctly on the job.

Inside SCG

Classification Determinations by Element of Information
A Security Classification Guide (SCG) itemizes specific elements of information associated with a system, program, project, plan, or mission and states the classification level (for example, Confidential, Secret, or Top Secret) assigned to each. This element-by-element structure is the core function of an SCG and is generally issued by the original classification authority (OCA) responsible for the information.
Reason for Classification
For each classified element, an SCG typically identifies the basis for classification consistent with the categories authorized under governing executive branch policy on classified national security information. Practitioners should confirm the applicable categories and citations against the current governing directive rather than assuming a fixed list.
Downgrading and Declassification Instructions
An SCG generally specifies duration of classification and any downgrading or declassification instructions or events for the covered information. These instructions are what enable derivative classifiers to apply consistent markings over time.
Derivative Classification Guidance
The SCG serves as an authoritative source for derivative classification, allowing personnel who incorporate, paraphrase, or restate classified information to apply markings based on the guide rather than making independent original classification decisions. This distinguishes derivative classification (applying existing determinations) from original classification (making new determinations by an OCA).
Identifying and Approval Information
An SCG customarily identifies the issuing authority, points of contact, and dates or revision identifiers so users can confirm they are working from the current, approved version. Because guides are revised, the specific approval details and effective dates should be verified against the controlling document.
Scope and Applicability Statement
An SCG defines the program, system, or subject matter it covers and its intended user population. This is central to respecting scope boundaries, because an SCG addresses classified national security information under the applicable classification regime and does not, by itself, govern Controlled Unclassified Information (CUI) handling or unclassified system authorization requirements.

Common questions

Answers to the questions practitioners most commonly ask about SCG.

Does a Security Classification Guide (SCG) classify information under the same authority as a control catalog like NIST SP 800-53?
No. These serve fundamentally different purposes and derive from different authorities. An SCG is a classification management tool that records original classification decisions, identifying what specific elements of information are classified, at what level, and for how long, under the national security classification system. NIST SP 800-53, maintained by NIST, is a catalog of security and privacy controls used to protect information systems. An SCG tells you whether and how information is classified; a control catalog tells you how to protect a system. Confusing the two conflates a classification-of-information function with an information-system-protection function. Readers should confirm the specific classification authority and control obligations against current official sources.
If a program already has an SCG, does that mean all its Controlled Unclassified Information (CUI) marking questions are answered?
Not necessarily. An SCG generally addresses classified national security information, while CUI is unclassified information that carries safeguarding or dissemination controls under a separate framework. The two categories are governed by distinct policy regimes, and an SCG is not, on its own, the authoritative source for how to identify, mark, or handle CUI. Programs handling both classified information and CUI typically rely on separate guidance for each. Because agency-specific interpretations and marking practices vary, readers should verify CUI obligations against the applicable current authoritative guidance rather than assuming an SCG covers them.
Who is responsible for developing and issuing an SCG for a program?
In most implementations, an SCG is developed under the direction of an official with original classification authority for the program or subject matter, working with security and program personnel. The SCG documents the classification decisions that this authority makes. Because roles, delegations, and organizational structures differ across agencies and defense components, the specific responsible official and approval process should be confirmed against the governing program security policy and applicable current guidance.
How should a contractor use an SCG when performing on a classified contract?
Contractors generally use the SCG, along with the contract's security requirements, to determine how to classify and mark information they generate or handle in performance of the contract. The SCG serves as the reference for what is classified, at what level, and any applicable declassification or downgrading instructions. This entry does not address specific contractual clauses, facility clearance requirements, or the interplay with a program's overall security guidance, all of which the contractor should confirm against the current contract documents and applicable official policy.
Should an SCG be treated as a static document once issued?
No. Classification decisions can change as information sensitivity evolves, as guidance is updated, or as declassification and downgrading events occur. In most implementations an SCG is reviewed and revised on a recurring basis, and users are generally expected to work from the current, approved version. Relying on a superseded SCG can result in incorrect classification or marking. The specific review cadence and update procedures should be verified against the applicable current program security policy.
How does an SCG relate to a program's system security and authorization activities?
An SCG informs system security work by establishing what information is classified and at what level, which in turn influences protection requirements and the categorization used in system authorization processes such as the Risk Management Framework. However, an SCG is not itself an assessment, an authorization, or a control implementation, it is a classification reference. Determining the resulting protection requirements, control baselines, and authorization outcomes involves separate processes and authorities that the reader should confirm against current official sources.

Common misconceptions

An SCG classifies information the same way an information system security authorization (such as an ATO) secures a system, so having one addresses the other.
These are distinct functions. An SCG communicates classification determinations for elements of information to support consistent marking and derivative classification. It does not assess, authorize, or continuously monitor an information system, and it does not substitute for the security authorization processes that govern operating a system. Compliance with an SCG is not equivalent to system security.
An SCG grants authority to make classification decisions, so anyone using it is acting as a classifier of first instance.
An SCG is a tool for derivative classification. Original classification determinations are made by an original classification authority (OCA); users of the guide apply those existing determinations derivatively. Making a new classification decision not covered by the guide is not the same as following the guide.
An SCG is a permanent, static reference that can be used indefinitely once issued.
SCGs are revised and reissued, and classification, downgrading, and declassification instructions can change. Users should confirm they are working from the current approved version and verify effective dates and revision identifiers against the controlling official document rather than treating any single copy as authoritative in perpetuity.

Best practices

Confirm you are using the current, approved revision of the SCG by checking issuing authority, revision identifiers, and dates against the controlling official source before applying any classification markings.
Use the SCG as your basis for derivative classification and cite it accordingly; escalate to the appropriate original classification authority when you encounter information not addressed by the guide rather than making an independent classification decision.
Apply the SCG's downgrading and declassification instructions precisely for each element, tracking any duration or event-based conditions specified for the covered information.
Respect the SCG's stated scope and applicability, and do not assume it governs Controlled Unclassified Information handling or system security authorization matters, which are addressed under separate authorities.
Keep the SCG distinct from system security authorization activities; do not treat adherence to the guide as satisfying assessment, authorization, or continuous monitoring obligations for an information system.
Route questions about ambiguous or conflicting element determinations to the identified SCG point of contact or issuing authority, and verify any specific citations or reasons for classification against the current governing directive.