eSourcingData - Source-to-Contract Procurement Software

Procurement Policy Note · explained by eSourcing Data

PPN 07/23 on the Government Security Classifications Policy: the original guidance, explained

PPN 07/23 brought the 2023 classifications policy into public contracts, with a 12 month window. Here is what it required and where it still applies.

Commercial teams managing contracts awarded before 24 February 2025NHS bodies handling HMG information under contractContract managers and information assurance leadsSuppliers processing government information8 min read

Source document: Procurement Policy Note: Government Security Classifications Policy 2023 (Action Note 07/23)

The key facts

  • PPN 07/23 was issued in June 2023 and is the original procurement note applying the Government Security Classifications Policy 2023.
  • It applies to all central government departments, their executive agencies, non-departmental public bodies and NHS bodies.
  • Its contents were to be implemented by June 2024, a 12 month window intended to allow the updated policy to be integrated into commercial activity.
  • It remains the reference point for procurements commenced and contracts awarded before 24 February 2025, after which the updated note, PPN 012, applies.
  • The policy applies to any information or data created, processed, stored or managed as part of an HMG contract.
  • HMG uses three classification tiers: OFFICIAL, SECRET and TOP SECRET. OFFICIAL-SENSITIVE was not introduced as a new tier.
  • Most updates were minor and would not require a contract variation, though some contracts might need review and suppliers should be notified.
  • Guidance 1.6: Contractors and Contracting Authorities holds the specific material for commercial teams and suppliers.

What this PPN is and who it applied to

PPN 07/23 is the original Procurement Policy Note that brought the Government Security Classifications Policy 2023 into public contracting. The policy had been updated to address gaps in the previous version and changes in government working practices since the last major update in 2013, and this note is how that update reached commercial and contract management teams.

Its contents applied to all central government departments, their executive agencies, non-departmental public bodies and NHS bodies. Other public sector contracting authorities creating, processing, storing or managing data or information as part of an HMG contract were invited to apply the same approach. The note asked organisations to circulate it particularly to those with a commercial, procurement or contract management role, and to share the policy itself with information assurance and data protection leads.

Unusually for a PPN, it came with a long runway. The contents were to be implemented by June 2024, a 12 month implementation window explicitly designed to give organisations enough time to integrate the requirements of the updated classifications policy into commercial activity.

What the PPN required

In-scope organisations had to ensure appropriate protective security controls were in place for new and existing contracts, in line with the updated policy. A full suite of guidance documents was published on GOV.UK, with the material for commercial teams and suppliers set out in Guidance 1.6: Contractors and Contracting Authorities.

The note took a proportionate line on contractual change. The majority of the updates were minor and would not require a contract variation to existing contracts, though there might be instances where specific contracts needed to be reviewed. Organisations were asked to notify existing suppliers that the policy had been updated and to set out any changes needed to the contract.

Six aspects of the updated policy were flagged for familiarisation: updated definitions of the three classification tiers; baseline security behaviours for each tier plus further controls where the SENSITIVE marking is applied to OFFICIAL information; an updated list of principles for anyone handling HMG information; standardised additional markings covering handling instructions, descriptors, prefixes and national caveats; new guidance for remote working when handling HMG information; and updated guidance on aggregation and further considerations.

Underpinning all of it was a simple instruction: all HMG information should, where possible, be clearly marked with a classification tier. The tier is what determines which baseline behaviours and protective controls apply, so unmarked information is information without a defined standard of protection.

The classification tiers and additional markings

HMG uses three classification tiers, each with a set of recommended baseline behaviours and protective controls proportionate to the threat profile for that tier and the potential impact of a compromise, accidental loss or incorrect disclosure. OFFICIAL covers the majority of information created, processed, sent or received in the public sector and by partner organisations, which could cause no more than moderate damage if compromised. SECRET covers very sensitive information requiring enhanced protective controls including secure networks on secured dedicated physical infrastructure, where compromise could threaten life, seriously damage the UK's security, international relations or financial stability, or impede investigation of serious and organised crime. TOP SECRET covers exceptionally sensitive assets that directly support or inform national security and require an extremely high assurance of protection from all threats.

The baseline behaviours cover handling in electronic, hard copy and verbal formats, including sharing, storage, transport and destruction. They are set out tier by tier in Guidance 1.1: Working at OFFICIAL, Guidance 1.2: Working at SECRET and Guidance 1.3: Working at TOP SECRET. Users are expected to be familiar with both the policy and local security guidance before handling classified information.

The 2023 policy introduced a non-exhaustive standard list of additional markings covering handling instructions, descriptors, prefixes and national caveats, with organisations free to define further markings locally. Additional markings are applied alongside a classification to indicate the nature or source of information, to limit access to specific user groups, and to signal that additional protective controls are needed. Not all markings can be used at every tier: FOR PUBLIC RELEASE, for example, applies at OFFICIAL but not at SECRET or TOP SECRET, and descriptors such as HR MANAGEMENT and PERSONAL DATA apply at OFFICIAL, including with the SENSITIVE marking, but not above it.

The note is explicit that OFFICIAL-SENSITIVE was not introduced as a new classification tier. The SENSITIVE marking should be applied to OFFICIAL information that is not intended for public release and is of at least some interest to threat actors, activists or the media, where compromise is likely to cause moderate damage to the work or reputation of the organisation or of HMG. Such information must carry the marking and be handled with the additional controls that follow from it.

Where PPN 07/23 still applies

This note has since been updated. PPN 012, issued in February 2025, carries the same substance but uses the terminology introduced by the Procurement Act 2023 and the Procurement Regulations 2024. Those apply to procurements commenced on or after 24 February 2025.

That leaves PPN 07/23 with a continuing role. It remains the reference point for procurements commenced before 24 February 2025 and for contracts awarded before that date, including those awarded through frameworks, dynamic purchasing systems or qualification systems established under the previous legislation. Given typical public sector contract lengths, a substantial part of most live portfolios still sits in that population.

Nothing of substance changed between the two notes. The later update was described as not constituting a change in policy or a new call for action. The security requirements, tiers, markings and baseline behaviours are the same in both. What differs is the legislative vocabulary wrapped around them, which is why the correct note to cite depends on when the procurement commenced rather than on which is newer.

Applying it in practice

For contracts in the pre February 2025 population, the practical questions are the same ones the note posed in 2023. Was the implementation work completed within the window to June 2024? Were suppliers notified? Were the contracts that genuinely needed reviewing identified and dealt with? If those answers are not evidenced anywhere, the gap is worth closing regardless of which note applies.

Use the guidance structure rather than inventing local documentation. Guidance 1.6 is written for contractors and contracting authorities, and the tier specific documents at 1.1, 1.2 and 1.3 tell users exactly what behaviours apply to them. Pointing suppliers at the authoritative source reduces the risk of local paraphrase drifting from the policy.

Take the training seriously. Departmental Security Advisors receive education and awareness materials called Mark My Words, obtained through the Security Education and Awareness Centre hosted within the Department for Work and Pensions, and those materials include an information video that can be sent to suppliers. A Security Classifications e-learning module is available on the Government Campus.

Know the routes for questions. Enquiries about the PPN itself go to the Crown Commercial Service Helpdesk. Enquiries about applying the policy go to the Government Security Function. Separating the two saves time when a live contract raises a classification question that is really a policy interpretation issue.

How eSourcing Data helps

Legacy contracts are where classification obligations quietly go missing, because the requirement was agreed once at award and then lives in a document nobody opens. eSourcing Data holds classification and security attributes as structured fields on the contract and supplier record, so the security position of a contract awarded in 2023 is as visible today as the one signed last week, and so a successor contract manager inherits it automatically.

The platform also makes the implementation evidence retrievable. Supplier notifications, contract review decisions and any resulting variations can be recorded against the contract with dates and owners, which answers the awkward question of whether the June 2024 implementation work was actually completed and for which suppliers.

Because the applicable note depends on when a procurement commenced, the commencement date matters operationally, not just historically. eSourcing Data records procurement timelines alongside contract records, so teams can segment their portfolio between contracts governed by the earlier note and those under the current regime, and apply the right reference and the right notices to each.

What to do about it

  1. 1Identify which of your live contracts were commenced or awarded before 24 February 2025, since PPN 07/23 remains the reference point for those.
  2. 2Confirm and evidence whether the implementation work required by June 2024 was completed, including supplier notification.
  3. 3Check that contracts involving HMG information carry a recorded classification tier and any applicable additional markings.
  4. 4Review the small number of contracts where the updated policy genuinely requires a variation, rather than reopening the whole portfolio.
  5. 5Direct suppliers to Guidance 1.6: Contractors and Contracting Authorities and the tier specific guidance at 1.1, 1.2 and 1.3.
  6. 6Reinforce that OFFICIAL-SENSITIVE is a marking on OFFICIAL information, not a separate classification tier.
  7. 7Use the Mark My Words materials and the Government Campus Security Classifications module rather than writing local training from scratch.

Put this into practice on the platform

eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.

Read our take on the blog →Back to the Procurement Library

This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.

All documents