You've seen the stamp. That said, rEDACTED. But here's the thing most people never ask: who actually decides? TOP SECRET. CLASSIFIED. In practice, it shows up in movies, in news leaks, in that one documentary your uncle won't stop talking about. Who sits down, looks at a document, and says "this stays secret" — and how do they pick the level?
People argue about this. Here's where I land on it.
It's not a mysterious cabal. Still, it's not an algorithm. Consider this: it's a specific person with a specific title, operating under a specific executive order. And the rules are more bureaucratic than you'd think Most people skip this — try not to. Worth knowing..
What Is Classification Authority
Classification authority in the U.S. Consider this: government isn't one person. On top of that, it's a hierarchy defined by Executive Order 13526, signed by President Obama in 2009 and still in force today. The order lays out exactly who can classify information, at what level, and under what conditions.
At the top sits the President. These are Original Classification Authorities — OCAs in the jargon. Because of that, agency heads. Senior officials designated by the President. Worth adding: the Vice President. They're the only people who can look at brand-new information and say "this is classified, and here's why It's one of those things that adds up..
Everyone else? They're doing derivative classification. Big difference.
Original vs. Derivative Classification
Original classification is the act of classifying information for the first time. Now, you're creating the classification. You're deciding: this didn't exist before, or it existed but nobody marked it, and now I'm saying it's Secret Took long enough..
Derivative classification is what happens when you take already-classified information and incorporate it into something new. A report. A briefing slide. An email. Even so, you're not making a new judgment about sensitivity — you're carrying forward the existing markings. The source document tells you what level to use.
Here's where it gets practical: the vast majority of classified markings you see are derivative. Some analyst reads a Top Secret cable, writes a summary, and marks the summary Top Secret because the source was. They didn't decide the cable was Top Secret. Someone else did that years ago.
Who Actually Holds OCA Authority
The list is shorter than you'd think. By statute and executive order, OCAs include:
- The President and Vice President
- Cabinet secretaries and agency heads (Secretary of Defense, Director of CIA, etc.)
- Senior officials specifically designated in writing by the President or agency heads
That last category is where the numbers grow. A department secretary can designate deputies, under secretaries, and certain senior executives as OCAs. In real terms, they have to specify the classification level each person can assign — Top Secret, Secret, or Confidential. But they have to do it in writing. And they have to report those designations to the Information Security Oversight Office (ISOO) at the National Archives.
Most government employees never meet an OCA. They work with classification guides instead.
Why It Matters / Why People Care
Classification isn't academic. Over-classification wastes billions. Under-classification gets people killed. So it determines who can see what, where information can be stored, how it's transmitted, and what happens if it's mishandled. The balance matters.
The Cost of Getting It Wrong
Over-classification is the quieter scandal. That said, a 2012 report from the Public Interest Declassification Board estimated that up to 50% of classified material could be safely declassified. Some estimates go higher.
- More secure storage space needed
- More cleared personnel required
- More expensive handling procedures
- Slower information sharing between agencies
- FOIA requests denied for no real reason
Under-classification is louder when it fails. The 9/11 Commission cited information sharing failures rooted partly in classification barriers. The WikiLeaks and Snowden disclosures revealed both over-classification (embarrassing but harmless cables marked Secret) and genuine sensitivity (actual intelligence sources and methods).
Who Cares Besides the Government
Journalists care — classification determines what they can publish without legal risk. S. Contractors care — their facility clearances and personnel clearances depend on what level of work they do. Historians care — the 25-year automatic declassification review clock starts at the original classification decision. Even foreign governments care — they track U.classification patterns to infer capabilities and priorities.
It sounds simple, but the gap is usually here Not complicated — just consistent..
How It Works (or How to Do It)
The mechanics of classification are surprisingly structured. And it's not "this feels secret. " It's a checklist Simple as that..
The Three Levels — And What They Actually Mean
Top Secret — Unauthorized disclosure could cause "exceptionally grave damage" to national security. This is the highest level. Think: nuclear weapon designs, identities of deep-cover agents, ongoing sensitive operations, certain cryptographic capabilities.
Secret — Unauthorized disclosure could cause "serious damage." This covers a huge range: military operational plans, intelligence collection details, diplomatic negotiating positions, many weapons systems specifications.
Confidential — Unauthorized disclosure could cause "damage." The lowest level, but still protected. Routine diplomatic cables, some personnel security files, certain logistics data.
The definitions sound similar. The difference is in the degree of damage — and that judgment call is where OCAs earn their authority.
The Six Categories — Information Must Fit One
Executive Order 13526, Section 1.Now, 4, lists exactly six categories of information that can be classified. If it doesn't fit, it cannot be classified. Period The details matter here..
- Military plans, weapons systems, or operations
- Foreign government information
- Intelligence activities, sources, or methods
- Foreign relations or foreign activities of the U.S.
- Scientific, technological, or economic matters relating to national security
- Vulnerabilities or capabilities of systems, installations, infrastructures, projects, or plans relating to national security
That's it. Not classifiable. A politician's tax returns? Which means the menu at the White House mess? Practically speaking, your embarrassing email to a coworker? Think about it: not classifiable. Not classifiable — unless it reveals a vulnerability in food supply chains (category 6).
The Classification Decision Process
When an OCA classifies originally, they have to document:
- What information is being classified (specific, not "this whole program")
- Why it fits one of the six categories
- Which level applies and the reasoning for that level
- How long it should stay classified — a specific date or event, not "forever"
- Who the OCA is (name, title, agency)
This gets recorded in a classification guide — a document that tells derivative classifiers how to handle related information going forward. Guides are living documents. On top of that, they expire. They get updated. They're supposed to be reviewed every five years And that's really what it comes down to..
Marking Requirements — Not Optional
Every classified document must show:
- Overall classification banner (top and bottom of every page)
- Portion markings on each paragraph, section, figure, table — showing the level for that specific part
- Classification authority block: who classified it, by what authority (EO 13526), reason category, declassification instruction
- Downgrading instructions if applicable
- Declassification date or event
Missing markings don't make it unclassified. But they're a security violation — and they make derivative classification harder for everyone downstream Simple as that..
The classification guide itself is more than a static reference; it is the linchpin of the derivative classification system. When a new document is generated, the guide tells the author which portions inherit the original markings, which can be downgraded, and which must be treated as “unclassified” because they no longer meet the original justification. Because the guide is reviewed on a five‑year schedule, any change — whether a re‑assessment of the threat environment, a shift in policy, or a technical advance that renders a previously sensitive capability non‑critical — must be reflected in an updated edition. Failure to keep the guide current creates a cascade of errors: derivative classifiers may over‑protect information, inflating classification levels and impeding information sharing, or they may under‑protect material, leaving it exposed to unauthorized access.
Oversight of the classification process is coordinated across several entities. Within each department, the Office of the Chief Records Officer (or its equivalent) ensures that classified records are stored in compliance with the prescribed handling controls, while the agency’s security officer monitors adherence to downgrading instructions and declassification schedules. The Information Security Oversight Authority (ISOA) conducts periodic audits of classification logs, verifies that marking requirements are met, and reports deficiencies to the appropriate agency heads. The Office of the Director of National Intelligence (ODNI) has instituted a cross‑agency classification dashboard that aggregates real‑time data on the number of documents at each level, the age of classifications, and any pending declassification actions, providing senior leadership with a holistic view of the information‑security posture.
This changes depending on context. Keep that in mind.
Training remains a constant imperative. New officers receive a condensed version of the classification decision process, while seasoned personnel undergo refresher courses whenever the regulatory framework changes — such as the introduction of the “Science and Technology” category in EO 13526 or the addition of “critical infrastructure” language in recent amendments. Day to day, simulated classification exercises, often involving redacted excerpts of real‑world documents, help reinforce the importance of precise marking and the consequences of shortcuts. These programs are now increasingly delivered through interactive e‑learning platforms that track completion, quiz performance, and on‑the‑job application, creating a measurable baseline for competency.
Looking ahead, the classification ecosystem is gradually embracing automation. Machine‑learning models are being trained to scan documents for keywords, classification‑relevant phrasing, and the presence of system‑specific identifiers, thereby suggesting appropriate categories and marking levels. While these tools promise faster, more consistent decisions, they also introduce new risks: algorithmic bias, false positives that over‑classify, or false negatives that under‑classify. Because of that, the human oversight role is evolving from a purely procedural check to a supervisory function that validates algorithmic recommendations, especially for high‑impact or novel content.
In sum, the integrity of the classification system rests on a disciplined blend of clear policy, rigorous documentation, continuous oversight, and ongoing education. When each element — from the initial authority’s justification to the final declassification date — is meticulously applied and regularly reviewed, the system preserves both national security and the openness required for effective governance. A failure in any one of these pillars reverberates through the chain of custody, undermining trust, compromising sensitive information, and ultimately weakening the nation’s ability to protect itself.