eSourcingData - Source-to-Contract Procurement Software

Procurement Policy Note · explained by eSourcing Data

PPN 012 and the Government Security Classifications Policy 2023: the official guidance, explained

How PPN 012 applies the Government Security Classifications Policy to contracts, what changed in the 2023 policy, and what commercial teams must do about it.

Central government commercial and contract management teamsNHS bodies handling HMG information under contractInformation assurance and data protection leadsSuppliers holding or processing government information8 min read

Source document: Procurement Policy Note: Government Security Classifications Policy 2023 (Action Note 012)

The key facts

  • PPN 012 was previously issued in June 2023 and updated in February 2025 to reflect terminology from the Procurement Act 2023 and the Procurement Regulations 2024.
  • It applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies.
  • In-scope organisations should note its provisions from 24 February 2025. For procurements commenced and contracts awarded before that date, PPN 07/23 applies.
  • The update is not a change in policy or a new call for action, but ongoing obligations continue to apply.
  • The Government Security Classifications Policy applies to any information or data created, processed, stored or managed as part of an HMG contract.
  • HMG uses three classification tiers: OFFICIAL, SECRET and TOP SECRET. OFFICIAL-SENSITIVE is an additional marking, not a fourth tier.
  • Most updates are minor and will not require a contract variation, though some specific contracts may need review, and existing suppliers should be notified.
  • Specific guidance for commercial teams and suppliers is set out in Guidance 1.6: Contractors and Contracting Authorities.

What this PPN is and who it applies to

PPN 012 is the procurement route into the Government Security Classifications Policy 2023, the administrative system HM Government uses to protect information and data assets against prevalent threats through classification tiers. The policy was updated to address gaps in the previous version and to reflect how government working practices have changed since the last major update in 2013.

The PPN applies to all central government departments, their executive agencies and non-departmental public bodies, and to NHS bodies. Other public sector contracting authorities that create, process, store or manage data or information as part of an HMG contract may wish to apply the same approach. The PPN asks organisations to circulate it to commercial, procurement and contract management staff, and to share the policy itself with information assurance and data protection leads.

This version was issued in February 2025 and updates the earlier note, PPN 07/23, to reflect the terminology introduced by the Procurement Act 2023 and the Procurement Regulations 2024. Those apply to procurements commenced on or after 24 February 2025, and in-scope organisations should note the provisions of PPN 012 from that date. Where a procurement commenced or a contract was awarded before 24 February 2025, including under frameworks, dynamic purchasing systems or qualification systems established under the previous legislation, PPN 07/23 remains the reference. The update does not constitute a change in policy or a new call for action.

What the PPN requires

The core obligation is that in-scope organisations must ensure appropriate protective security controls are in place for new and existing contracts, in line with the updated policy. A full suite of guidance documents sits on GOV.UK, with the material aimed specifically at commercial teams and suppliers set out in Guidance 1.6: Contractors and Contracting Authorities.

In practical terms, most of the updates are minor and will not require a contract variation to existing contracts, though the PPN accepts there may be instances where specific contracts need to be reviewed. It also asks organisations to notify existing suppliers that the policy has been updated and to set out any changes needed to the contract, which makes supplier communication an explicit action rather than an optional courtesy.

The PPN then lists six aspects of the updated policy that in-scope organisations should familiarise themselves with: updated definitions for the three classification tiers; baseline security behaviours for each tier plus further controls where the SENSITIVE marking is applied to OFFICIAL information; an updated list of principles for anyone handling HMG information; standardised additional markings covering handling instructions, descriptors, prefixes and national caveats; new guidance for remote working when handling HMG information; and updated guidance on aggregation and further considerations.

Finally, all HMG information should, where possible, be clearly marked with a classification tier. That sounds administrative but it is the mechanism on which everything else depends, because the tier determines which baseline behaviours and protective controls apply.

The three tiers and the additional markings

The updated definitions are set out in the PPN. OFFICIAL covers the majority of information created, processed, sent or received in the public sector and by partner organisations, which could cause no more than moderate damage if compromised and must be defended against a broad range of threat actors with differing capabilities using nuanced protective controls. SECRET covers very sensitive information requiring enhanced protective controls, including secure networks on secured dedicated physical infrastructure and defined boundary controls, suitable to defend against highly capable and determined threat actors, where a compromise could threaten life, seriously damage the UK's security, international relations or financial stability, or impede the investigation of serious and organised crime. TOP SECRET covers exceptionally sensitive assets that directly support or inform the national security of the UK or its allies and require an extremely high assurance of protection from all threats.

Each tier carries a set of recommended baseline behaviours and protective controls proportionate both to the threat profile for that tier and to the potential impact of compromise, accidental loss or incorrect disclosure. Those behaviours cover the handling of information in electronic, hard copy and verbal formats, including sharing, storage, transport and destruction, and are set out in Guidance 1.1: Working at OFFICIAL, Guidance 1.2: Working at SECRET and Guidance 1.3: Working at TOP SECRET.

The point people most often get wrong is OFFICIAL-SENSITIVE. It is not a separate classification tier. It is an additional marking applied to OFFICIAL information that is not intended for public release and is of at least some interest to threat actors, activists or the media, where a compromise is likely to cause moderate damage to the work or reputation of the organisation or of HMG. Information meeting that description must carry the marking and must be handled with the additional controls that come with it.

The 2023 policy also introduces a non-exhaustive standard list of additional markings, covering handling instructions, descriptors, prefixes and national caveats. Organisations may define further markings locally, and users need to be familiar with those too. Not every marking works with every tier. The PPN includes a table showing, for example, that FOR PUBLIC RELEASE applies at OFFICIAL but not at SECRET or TOP SECRET, and that descriptors such as HR MANAGEMENT and PERSONAL DATA apply at OFFICIAL, including with the SENSITIVE marking, but not at SECRET or TOP SECRET.

What it changes and why it matters

For commercial teams the practical shift is that classification is a contractual matter, not just an internal information management one. The policy applies to any information or data created, processed, stored or managed as part of an HMG contract, which means a supplier's handling of that information falls within scope from the moment the contract is live.

The February 2025 update does not add obligations. Its value is alignment: it puts the policy into the vocabulary of the Procurement Act 2023 so that teams running procurements under the new regime are not translating between two sets of terminology. The substantive change was the 2023 policy update itself, which closed gaps in the previous version and addressed working practices, including remote working, that the 2013 policy never anticipated.

Training is treated as part of implementation. Departmental Security Advisors receive education and awareness materials called Mark My Words, obtained through the Security Education and Awareness Centre hosted within the Department for Work and Pensions, which include an information video that can be sent to suppliers. A separate e-learning module called Security Classifications is available on the Government Campus.

Applying it in practice

Start by identifying which contracts involve HMG information at all, and at what tier. That mapping is the foundation for everything else, because it tells you which suppliers need notifying, which contracts might need reviewing and where the SENSITIVE marking and its additional controls will bite.

Then handle the supplier communication deliberately. The PPN asks in-scope organisations to notify existing suppliers of the update and set out any changes needed to the contract. A single, clear notification that points suppliers at Guidance 1.6 and includes the awareness materials is more effective than piecemeal contact from individual contract managers.

Treat variations as the exception. The PPN is explicit that most updates are minor and will not require a contract variation, so the disciplined approach is to define the criteria that would trigger a review, for example contracts operating at SECRET or above, contracts involving significant volumes of OFFICIAL-SENSITIVE material, or contracts with remote working arrangements, and to review only those.

Get the marking discipline right at source. All HMG information should, where possible, be clearly marked with a classification tier, and additional markings should only be used in combinations the policy permits. Where markings are defined locally, they need documenting so that suppliers and new staff can apply them consistently. Route policy application questions to the Government Security Function, and enquiries about the PPN and standard templates to the Crown Commercial Service Helpdesk.

How eSourcing Data helps

The first task this PPN creates is a data task: knowing which contracts touch HMG information and at which tier. eSourcing Data lets you hold classification and security attributes against contract and supplier records, so identifying the affected population is a query rather than a manual trawl, and so a new contract manager inherits the security context along with the contract.

The PPN also asks for supplier notification and, in some cases, contract review. The platform supports structured supplier communications and records that they were sent, and tracks any resulting contract review or variation through to completion. That gives assurance leads a defensible answer to the question of whether every affected supplier was told and what happened next.

For new procurements, eSourcing Data can carry security requirements through from specification into evaluation and into contract management, so classification requirements set at the outset are the ones assessed at bid stage and monitored in delivery. Combined with the platform's audit trail and reporting, that keeps the security position visible across the contract lifecycle rather than only at the point of award.

What to do about it

  1. 1Identify every contract under which HMG information is created, processed, stored or managed, and record the classification tier that applies.
  2. 2Notify existing suppliers that the Government Security Classifications Policy has been updated, and set out any changes needed to their contract.
  3. 3Review the six listed aspects of the updated policy with commercial, contract management, information assurance and data protection colleagues.
  4. 4Define the criteria that would trigger a contract review or variation, and review only those contracts rather than the whole portfolio.
  5. 5Make sure teams understand that OFFICIAL-SENSITIVE is an additional marking, not a fourth classification tier, and apply the SENSITIVE marking to the material that meets the test.
  6. 6Document any locally defined additional markings and check that marking combinations are permitted at the relevant tier.
  7. 7Circulate the Mark My Words awareness materials and the Government Campus Security Classifications e-learning module to relevant staff and suppliers.

Put this into practice on the platform

eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.

Read our take on the blog →Back to the Procurement Library

This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.

All documents