You've probably seen the stamps. CONFIDENTIAL. Someone — a specific person with a specific title — decided that information needed protection. But here's the thing most people miss: those markings don't appear by magic. So sECRET. They show up in movies, in news leaks, in FOIA requests with thick black bars eating entire paragraphs. TOP SECRET. And that decision carries real weight.
So who actually makes that call? And how do they decide between "Secret" and "Top Secret" anyway?
What Is Classification Authority
Classification authority isn't one person sitting in a room stamping documents. It's a structured system built on executive orders, agency policies, and a chain of delegation that starts at the very top And it works..
The current framework comes from Executive Order 13526, signed by President Obama in 2009 and still in effect. It establishes two distinct types of classification authority: original and derivative. The difference matters more than most people realize.
Original Classification Authority (OCA)
Original classification is the act of classifying information for the first time. Also, not copying a marking from another document. Not applying a classification guide. Deciding that this specific information, right now, meets the standards for protection — and at what level.
Only designated Original Classification Authorities can do this. And the list of who qualifies is surprisingly short.
About the Pr —esident holds original classification authority inherently. But they can't just hand it out like business cards. After that, it gets delegated. Agency heads — the Secretary of Defense, the Director of National Intelligence, the Secretary of State — can designate OCAs within their organizations. So does the Vice President. The order requires that OCAs be "senior agency officials" whose positions require them to make classification decisions regularly.
In practice? That means a few dozen people across the entire federal government. On the flip side, maybe a hundred at most. Not thousands. Not even hundreds And that's really what it comes down to..
Each OCA gets a written delegation letter specifying their authority. Some can classify at all three levels. Others are limited to Secret and Confidential. The delegation spells it out explicitly. And every OCA has to receive training before they exercise that authority — not optional, required.
Derivative Classification
Here's where the volume lives. The vast majority of classified documents — we're talking 95% plus — aren't originally classified. They're derivatively classified Small thing, real impact..
Derivative classification happens when someone takes already-classified information and incorporates it into a new document, or paraphrases it, or summarizes it. The classifier isn't making a new judgment about whether the information should be classified. They're carrying forward an existing determination.
But — and this is critical — derivative classifiers still need authorization. And they're personally responsible for getting it right. Not your boss. They need access to classification guides. Practically speaking, not the OCA who wrote the guide. Consider this: if you derivatively classify something at the wrong level, or mark something classified that shouldn't be, that's on you. On the flip side, they need to be trained. You.
Why It Matters
Overclassification is a real problem. Practically speaking, it clogs systems, hides mistakes, wastes money, and erodes public trust. But underclassification gets people killed. Sources exposed. So operations compromised. Technical advantages lost.
The classification level isn't arbitrary. Each level maps to a specific damage standard:
- Top Secret — exceptionally grave damage to national security
- Secret — serious damage
- Confidential — damage (measurable, identifiable damage)
Those phrases — "exceptionally grave," "serious," "damage" — aren't decorative. And they're legal standards. An OCA has to be able to articulate what the damage would be, how it would happen, and why it meets that threshold. If they can't, they're not supposed to classify it at that level The details matter here. Simple as that..
And the system has checks. At least in theory.
The Classification Guide System
OCAs don't classify every document personally. They write classification guides — detailed documents that tell derivative classifiers what's classified, at what level, and for how long. A good guide might say: "The specific frequency range of Radar System X is SECRET. On the flip side, the fact that Radar System X exists is UNCLASSIFIED. The general capability of radar systems is UNCLASSIFIED Turns out it matters..
Guides are supposed to be reviewed regularly. Some guides sit untouched for years. In practice? Consider this: updated when programs change. Some classify things that haven't been sensitive in decades. Cancelled when they're obsolete. That's how you get FOIA responses where the only unclassified words are "the" and "and And that's really what it comes down to..
How It Works
Let's walk through the actual mechanics. Because the process matters more than the org chart Most people skip this — try not to..
Step 1: The Information Exists
Someone creates information. At this moment, it's unclassified. An email. A technical drawing. A conversation captured in notes. In real terms, a report. Classification isn't a default state — it's an affirmative action.
Step 2: The OCA Evaluates
An Original Classification Authority reviews the information (or more likely, reviews a program and issues a guide covering categories of information). O. They apply the standards from E.13526 Section 1.
- The information is owned by, produced by or for, or under the control of the U.S. government
- Unauthorized disclosure could reasonably be expected to cause damage to national security
- The damage is identifiable and describable
- The classification level matches the degree of damage
All four must be met. Not three. Four.
Step 3: The Determination Is Documented
The OCA doesn't just think it. In real terms, they write it down. The classification decision gets recorded — what information, what level, why, how long it stays classified, any special handling requirements (like SCI, SAP, or NOFORN). This creates the paper trail that derivative classifiers rely on No workaround needed..
Step 4: Derivative Classifiers Apply the Guidance
A cleared employee writing a briefing pulls from a classified source. Now, they check the classification guide. And they mark their new document accordingly. They carry forward the classification markings, the duration instructions, the "classified by" line (which cites the guide, not the person) Took long enough..
Step 5: Review and Challenge
Here's the part most people don't know exists. Also, the system requires mechanisms for challenging classification. If you're a derivative classifier and you think the guide is wrong — overclassifying, underclassifying, classifying something that shouldn't be — you're supposed to raise it. Your security office reviews. If they agree, they go back to the OCA. The OCA can change the guide.
Does this happen often? In practice, not as often as it should. But the mechanism exists. And mandatory declassification review — where anyone can request review of classified records after 25 years — provides another pressure valve Not complicated — just consistent. Less friction, more output..
Common Mistakes / What Most People Get Wrong
"The President Classifies Everything"
No. The President can classify anything. But in practice, the President almost never personally classifies individual documents. The authority is delegated. The system runs on OCAs and derivative classifiers making thousands of decisions daily without White House involvement.
"Classification Level = Sensitivity"
Not exactly. Classification level = damage potential from unauthorized disclosure. Something can be incredibly sensitive — personally embarrassing
Step 5: Review and Challenge (Continued)
Something can be incredibly sensitive — personally embarrassing, politically damaging, or strategically important — yet still not qualify for classification. A memo detailing a diplomatic gaffe might be embarrassing, but unless its disclosure could compromise intelligence sources or military operations, it doesn’t meet the criteria. Here's the thing — the bar is specifically about demonstrable harm to national security, not general secrecy or discomfort. This distinction is critical because overclassification dilutes the system’s effectiveness and undermines public trust Worth knowing..
It sounds simple, but the gap is usually here.
Common Mistakes / What Most People Get Wrong (Continued)
"Automatic Classification Without Evaluation"
Many assume that certain topics — like nuclear weapons or intelligence operations — are automatically classified. In reality, even within these domains, each piece of information must be evaluated individually. A discussion of historical nuclear testing might be unclassified, while specifics about current warhead designs are not. The OCA’s role is to ensure nuanced, context-driven decisions rather than blanket categorizations.
"Derivative Classifiers Ignore the Guide"
Derivative classifiers sometimes misapply guidance, either over-marking documents due to caution or under-marking due to oversight. To give you an idea, a briefing might inherit a "Confidential" label from a source, but if the content only discusses general policy without revealing sensitive details, it could be downgraded to "For Official Use Only." Training and accountability are essential to prevent such errors.
"Classification Overrides Other Legal Obligations"
Classified information isn’t exempt from other laws. Whistleblower protections, Freedom of Information Act (FOIA) requests, and congressional oversight still apply, albeit with procedural safeguards. Take this case: a contractor might lawfully report waste, fraud, or abuse through proper channels without violating classification rules, provided they follow protocols for handling sensitive data The details matter here..
The Bigger Picture: Accountability and Evolution
The classification system is a living framework, not a static bureaucracy. It must adapt to evolving threats, technological advances, and shifting geopolitical landscapes. To give you an idea, cyber warfare and space-based assets have introduced new categories of information that earlier frameworks didn’t address. Similarly, the rise of digital communications has complicated how classification is applied to emails, cloud storage, and collaborative platforms Easy to understand, harder to ignore..
Still, the system’s integrity depends on human judgment. When done correctly, classification protects legitimate interests. But oCAs and derivative classifiers are not just following rules — they’re making decisions that balance security with transparency. When done poorly, it either fails to safeguard critical information or suppresses truths that deserve public scrutiny Surprisingly effective..
This tension is why continuous education and oversight are vital. Security offices regularly audit classification practices, and agencies like the Information Security Oversight Office (ISOO) under the National Archives provide guidance to ensure consistency. Yet, as seen in scandals involving mishandled documents or unauthorized disclosures, lapses still occur, often due to inadequate training or complacency.
Easier said than done, but still worth knowing Not complicated — just consistent..
Conclusion
The classification process is a meticulous, multi-step endeavor designed to protect national security while maintaining accountability. From the OCA’s initial evaluation to the derivative classifier’s application of guidance, each stage requires careful judgment and adherence to strict standards. The system’s strength lies in its checks and balances — including mechanisms for challenge and review — which allow for corrections and adaptations over time Not complicated — just consistent..