eSourcingData - Source-to-Contract Procurement Software
Buyers11 August 2026 · 8 min read · The eSourcing Data team

Security classification is a contract management problem, not a filing problem

Ask a commercial team who owns security classification and the answer is usually the security team, or information assurance, or someone in a different building. PPN 012 makes that answer inadequate. The Government Security Classifications Policy applies to any information or data created, processed, stored or managed as part of an HMG contract, which puts it squarely inside the commercial lifecycle: specified at procurement, agreed at award, monitored in delivery.

Why this lands on commercial teams

The PPN's action is not directed at security staff. It tells in-scope organisations, meaning central government departments, their executive agencies, non-departmental public bodies and NHS bodies, to ensure appropriate protective security controls are in place for new and existing contracts. New and existing is the phrase that matters. Anything already live is in scope.

It then asks organisations to notify existing suppliers that the policy has been updated and to set out any changes needed to the contract. That is a commercial communication, sent by people who hold the supplier relationship, and it needs to be consistent across a portfolio rather than left to individual judgement.

There is a helpful piece of proportionality built in. The PPN says most updates are minor and will not require a contract variation, while accepting some specific contracts may need review. The skill is deciding which ones, and that decision needs contract knowledge, not just security knowledge.

The mistake everyone makes

OFFICIAL-SENSITIVE is not a classification tier. The PPN says so directly, and it says so because the misconception is widespread enough to need correcting in a policy note. There are three tiers: OFFICIAL, SECRET and TOP SECRET. SENSITIVE is an additional marking applied to OFFICIAL information.

The consequence of getting this wrong is not pedantic. Treating OFFICIAL-SENSITIVE as its own tier leads to either over-protection, which slows delivery and inflates supplier cost, or under-protection, because the specific additional controls that accompany the marking are never applied. The test in the policy is clear enough to use: information not intended for public release, of at least some interest to threat actors, activists or the media, where compromise is likely to cause moderate damage to the organisation's or HMG's work or reputation.

The second common error is marking combinations. Not every additional marking can be used at every tier. FOR PUBLIC RELEASE sits at OFFICIAL and nowhere higher. Descriptors like PERSONAL DATA and HR MANAGEMENT work at OFFICIAL, including with the SENSITIVE marking, but not at SECRET or TOP SECRET. Local markings can be defined on top of the standard list, which is useful and also a source of confusion if nobody writes them down.

What to do about it

Build the map first. You cannot apply proportionate controls across a portfolio you have not classified. Work out which contracts involve HMG information, at what tier, and whether remote working or aggregation issues are in play, because the 2023 policy added guidance on both.

Use the training assets rather than writing your own. The Mark My Words materials, held through the Security Education and Awareness Centre within the Department for Work and Pensions, include a video that can be sent to suppliers. The Government Campus hosts a Security Classifications e-learning module. Both are cheaper and more consistent than local briefings.

Then decide who answers what. Enquiries about the PPN and requests for standard templates go to the Crown Commercial Service Helpdesk. Questions about applying the policy itself go to the Government Security Function. Knowing which queue a question belongs in saves a surprising amount of time when a live procurement hits a classification question.

Do not forget aggregation. The 2023 policy added updated guidance on it, and it is the issue least likely to surface in a contract review, because it is not about any single document. A supplier holding modest volumes of OFFICIAL information may hold something rather more sensitive once that information accumulates, and the right time to think about it is when the data flows are being designed rather than after the contract is signed.

The February 2025 update is a good moment to do this, precisely because it is not a policy change. There is no new obligation to race against, which makes it a rare opportunity to fix the underlying practice rather than scramble to meet a deadline.

The takeaways

  • The classifications policy applies to information handled under any HMG contract, so it belongs in the commercial lifecycle.
  • There are three tiers. OFFICIAL-SENSITIVE is a marking, not a fourth tier.
  • Most contracts will not need varying, but you need criteria for deciding which ones do.
  • Supplier notification is an explicit action in the PPN, not an optional courtesy.
  • The February 2025 update aligns terminology with the Procurement Act 2023 rather than changing policy.

Want the full breakdown?

The complete explainer covers the key facts, the requirements in detail and a practical action list, free and printable in the Procurement Library.

Browse the Procurement Library →All articles