eSourcingData - Source-to-Contract Procurement Software
Buyers11 August 2026 · 8 min read · The eSourcing Data team

The 12 month window that quietly closed: revisiting PPN 07/23 on security classifications

PPN 07/23 did something Procurement Policy Notes rarely do: it gave organisations a year. The contents were to be implemented by June 2024, explicitly so that the updated Government Security Classifications Policy could be worked into commercial activity properly rather than in a rush. Long runways sound generous. In practice they are the deadlines most likely to slip, because nothing forces the work to start.

Why the note still matters after being updated

PPN 07/23 has been superseded in the sense that PPN 012, issued in February 2025, restates the same requirements using Procurement Act 2023 terminology. But it has not been rendered irrelevant. It remains the correct reference for procurements commenced before 24 February 2025 and for contracts awarded before that date, including through frameworks and dynamic purchasing systems set up under the previous legislation.

For most organisations that is not a small residual population. Multi-year service contracts signed in 2023 and 2024 will be running well into the second half of this decade, and every one of them that touches HMG information sits under this note.

The reassuring part is that the substance did not move. The later update was described as not being a change in policy or a new call for action. Tiers, markings, baseline behaviours and the contractual obligation are identical. Only the surrounding vocabulary changed.

What was supposed to happen by June 2024

Three things. Protective security controls appropriate to the updated policy in place across new and existing contracts. Existing suppliers notified that the policy had been updated, with any contract changes set out. And the small number of contracts genuinely needing review identified and dealt with, on the understanding that most updates were minor and would not require a variation.

That last point deserves emphasis because it is the one that stops this becoming an unmanageable exercise. The note did not ask for a portfolio-wide contract renegotiation. It asked for judgement about where the updated requirements actually change what a supplier must do.

Alongside that sat a familiarisation task covering six areas, including remote working guidance and updated guidance on aggregation. Aggregation in particular tends to get overlooked: individually innocuous OFFICIAL information can warrant more protection in bulk, and that is a design question for how supplier systems hold data, not a filing question.

How to check whether you actually did it

Pick five contracts that involve HMG information and were awarded before February 2025. For each one, can you show the classification tier that applies, the notification sent to the supplier about the 2023 policy update, and either the review decision or the reason no review was needed. If you can do that for five, you can probably do it for the portfolio. If you cannot, the gap is not academic.

The answer will often be uncomfortable, and that is useful information rather than a reason to stop. A generous implementation window means the work was scheduled for later, and later has a habit of never arriving in a commercial team with live procurements to run. Nothing about the requirement has expired because the date passed.

Then look at markings discipline in the live relationship. Is OFFICIAL-SENSITIVE being used as though it were a tier? Are additional markings being applied in combinations the policy does not permit at that tier? Are locally defined markings written down anywhere a supplier could find them? These are the practical failures, and none of them show up in a contract review.

Look hard at remote working too. The 2023 policy added new guidance on handling HMG information remotely, and that is the area where the 2013 policy was furthest from current reality. Contracts written before hybrid working became normal often assume a supplier office and a supplier network, and the controls that were adequate under that assumption may not describe how the work is actually done today.

Finally, use the material that already exists. Guidance 1.6 speaks directly to contractors and contracting authorities. The Mark My Words package includes a video specifically intended to be sent to suppliers. Directing people to the authoritative source beats a locally written summary that will be out of date the next time the policy moves.

The takeaways

  • PPN 07/23 still governs procurements commenced and contracts awarded before 24 February 2025.
  • The February 2025 update changed terminology, not the security substance.
  • The June 2024 implementation deadline covered controls, supplier notification and targeted contract review.
  • Most contracts needed no variation, which makes identifying the exceptions the real skill.
  • Marking discipline, especially around OFFICIAL-SENSITIVE, is where practice most often drifts from policy.

Want the full breakdown?

The complete explainer covers the key facts, the requirements in detail and a practical action list, free and printable in the Procurement Library.

Browse the Procurement Library →All articles