Ever tried to write a report and then got stuck wondering, “Do I even need to classify this?On the flip side, ”
You’re not alone. Most people think classification is a one‑click thing—pick a label, slap it on, and you’re done. In reality, derivative classification is a tiny, meticulous process that can feel like threading a needle in the dark. Miss a step, and you could be exposing something you shouldn’t, or you could be over‑classifying and slowing down the whole workflow.
Let’s walk through the exact steps you need to follow, why each one matters, and what most people get wrong. By the end you’ll be able to take a raw document, apply the right markings, and feel confident you’re staying on the right side of the rules.
What Is Derivative Classification
Derivative classification is the act of taking existing classified material and using it to create a new document, while preserving the original classification level. In plain English: you’re borrowing the “secret sauce” from a source that’s already marked, and you have to make sure the new dish carries the same flavor.
You don’t get to guess the level; you inherit it. Think about it: if the source says Secret, your new memo can’t be Confidential—it has to be at least Secret, and possibly higher if you add new sensitive content. The whole point is to keep the chain of custody intact, so no one can slip a lower‑level label onto something that was originally higher Still holds up..
Where It Lives in the Bigger Picture
Derivative classification sits between two worlds: the original classification authority (the person who first decided the info is Secret, Top Secret, etc.) and the end user who needs the info for a specific task. It’s the bridge that makes sure the bridge isn’t built on shaky ground.
In practice, the process is governed by Executive Order 13526, the National Industrial Security Program (NISPOM), and agency‑specific manuals. Those documents spell out the steps, but they read like legalese. Below is the human‑friendly version that actually works on the job floor.
Why It Matters / Why People Care
If you mishandle derivative classification, the fallout can be severe. Think about a contractor who accidentally de‑classifies a Top Secret design for a new radar system. The consequences range from a simple reprimand to a criminal charge under the Espionage Act Practical, not theoretical..
On the flip side, over‑classifying can be just as damaging. Imagine a team that has to file a Top Secret request for a routine maintenance report. The extra paperwork, longer clearance times, and unnecessary restrictions can stall a project for weeks.
This is where a lot of people lose the thread.
Real‑talk: the short version is that correct derivative classification keeps the right people in the loop, the wrong people out, and the project moving at a reasonable pace. Miss a step, and you either leak something you shouldn’t or you lock yourself out of your own work.
How It Works (or How to Do It)
Below is the step‑by‑step checklist most agencies use. Treat it like a recipe—skip a step and the dish is ruined.
1. Identify the Source Material
Before you write anything, locate every piece of classified source you’ll be using. That includes:
- Classified documents (handbooks, memos, emails)
- Classified briefings (slides, recordings)
- Classified databases (metadata, spreadsheets)
If you can’t find a clear classification marking on the source, you must treat it as unclassified until you get clarification. Never assume a “soft‑copy” is safe just because it’s on a shared drive.
2. Determine the Highest Classification Level
Once you have all sources, look for the highest level among them. If one source is Secret and another is Confidential, the derivative work must be at least Secret That's the whole idea..
Why? Because the most sensitive piece dictates the floor. Adding a lower‑level label would be a straight violation of the “no downgrading” rule And that's really what it comes down to..
3. Assess New Information
Did you add anything that wasn’t in the source material? Maybe a new analysis, a risk assessment, or a recommendation. If that addition introduces a higher level of sensitivity, you must bump the classification up Less friction, more output..
A quick way to test this: ask yourself, “If an adversary got this new paragraph, would it cause more damage than the original sources?” If yes, raise the level Took long enough..
4. Apply the Proper Markings
Now you actually mark the document. The markings depend on the agency’s style guide, but the core elements are:
- Banner (top and bottom of each page) – e.g., TOP SECRET//NOFORN
- Portion markings (if only part of the document is classified) – e.g., [Secret] This paragraph…
- Control markings (e.g., REL TO USA, AUS, CAN)
Don’t forget the Date and Originating Agency if required. And always double‑check that the markings match the classification level you determined in step 2.
5. Document the Classification Decision
Most agencies require a short justification note. Something like:
“Derived from DOE‑DOC‑2023‑001 (Secret) and DOE‑BRF‑2022‑045 (Confidential). In practice, no new classified content added. Classification: Secret Turns out it matters..
Keep this note in the document’s metadata or on a separate cover sheet. It’s the audit trail that shows you followed the process.
6. Review and Approve
If you’re not the original classification authority (most of the time you aren’t), you need a designated Derivative Classification Reviewer to sign off. This could be a security manager, a program office, or a senior engineer with clearance.
The reviewer checks:
- All source material identified?
- Highest classification correctly applied?
- No new higher‑level content introduced?
Only after the reviewer signs off can the document be released Small thing, real impact..
7. Distribute According to Markings
Finally, send the document through the proper channels. But if it’s Secret, use the Secret distribution system; if it’s Top Secret, use the TS system. And never, ever, email a Top Secret file to a personal address—those rules are there for a reason.
Easier said than done, but still worth knowing.
Common Mistakes / What Most People Get Wrong
Even seasoned professionals slip up. Here are the pitfalls that show up again and again.
-
Assuming “Unmarked = Unclassified”
In reality, an unmarked document could be Classified but missing its banner due to a clerical error. Always verify. -
Skipping the “New Information” test
People often think, “I just copied the source, so I’m fine.” But even a tiny comment can raise the classification. -
Using the wrong banner format
A misplaced slash or missing double slash can render the marking non‑compliant. It’s a small typo with big consequences. -
Failing to document the decision
Auditors love to ask, “Why was this marked Secret?” If you have no note, you’re on the spot Worth keeping that in mind. That alone is useful.. -
Over‑classifying for safety
“Better safe than sorry” sounds good until a project stalls because everyone needs a Top Secret clearance Worth knowing.. -
Relying on memory for source list
Human memory is flaky. Keep a written list of every source you used; it’s your safety net.
Practical Tips / What Actually Works
- Create a source log template – a simple table with columns for Document ID, Classification, Date, and Notes. Fill it out as you go.
- Use a classification checklist – print the seven steps above and keep it on your desk. Tick each box before you hit “Send.”
- use automated tools – many secure collaboration platforms have built‑in classification prompts that remind you to add markings.
- Ask early – if you’re unsure about a source’s level, ask the original author or your security office before you start writing.
- Do a “quick‑look” peer review – a fresh set of eyes often catches a missing banner or an unintended higher‑level statement.
- Keep a “no‑new‑sensitive‑content” rule – unless you’re specifically tasked to add analysis, try to stay within the original material. That reduces the risk of accidentally raising the classification.
FAQ
Q: Can I downgrade a document if I only use a portion of a higher‑level source?
A: No. Even if you excerpt a Top Secret paragraph, the derivative work must retain the Top Secret level for that portion. You can use portion markings to indicate the lower‑level sections, but the overall document can’t be lower than the highest source used.
Q: What if the source material is missing a classification banner?
A: Treat it as unclassified only after you’ve verified with the originating office. If you can’t get clarification, do not use the material for a classified product.
Q: Do I need to re‑classify if I translate a classified document into another language?
A: Yes. Translation is considered a derivative work. The new document inherits the original classification and must be marked accordingly Most people skip this — try not to..
Q: How long should I keep the classification decision record?
A: At least as long as the document’s retention period, typically 10 years for most classified material, unless agency policy says otherwise.
Q: Is it okay to use “CONFIDENTIAL” on a document that contains both Confidential and Secret sections?
A: No. The banner must reflect the highest level—Secret in this case. Use portion markings for the Confidential parts Took long enough..
Wrapping It Up
Derivative classification isn’t a mystery you have to live with forever. It’s a set of clear, repeatable steps that, once internalized, become second nature. Practically speaking, identify your sources, lock in the highest level, watch for new sensitive content, mark it right, document the why, get the proper sign‑off, and then ship it through the correct channel. Avoid the common traps, use the practical tips, and you’ll keep your information secure without grinding the project to a halt.
No fluff here — just what actually works.
Now go ahead—take that draft, run through the checklist, and feel good knowing you’ve done it by the book. Your future self (and the security office) will thank you.