Federal agencies classify information according to how sensitive it is and the potential harm its disclosure could cause. Information that meets the criteria for national security classification is marked at the appropriate level; other sensitive government information may be handled under separate protections without being classified.
Those distinctions matter: a classification label affects who may access information and how it must be protected, but it does not mean every confidential or restricted government record is classified. Understanding how federal agencies classify information means looking at the standards for national security classification—and at the separate rules that govern other sensitive records.
| Term or rule | What the supplied material establishes | What it does not establish |
|---|---|---|
| Classified information | Sensitive information is designated for restricted access under legal and regulatory criteria | Complete decision test or specific access qualifications |
| CUI | Non-public information that requires safeguarding | That it is a classification level |
| Sensitive, restricted, confidential | Terms listed in the current summary | An official federal hierarchy or precise handling rules |
| Paperwork Reduction Act | OMB approval for covered agency information collections | A classification marking or access decision |
- 1995 Year of the Paperwork Reduction Act cited in the Federal Register material
- 44 U.S.C. 3501 et seq. Statutory reference given for the Paperwork Reduction Act
- July 15, 2016 Publication date of the supplied Federal Register item
- 80–90% Estimate for government information in documents, emails, presentations and reports, attributed to Collibra in the supplied NHI forum summary; not presented there as a federal measurement
How does information get classified in federal agencies?
Federal agencies classify information by applying criteria in laws and regulations to decide whether its sensitive nature warrants restricting access. The purpose is to protect national security, privacy and other vital interests; the decision turns on the information’s sensitivity, not whether it appears in a record, email, presentation or report.
What the available material establishes—and leaves open
A Federal Register item dated July 15, 2016, addresses classification, declassification, access and authority to classify information. It also discusses the Paperwork Reduction Act of 1995 and agency collections of information, but the supplied material does not set out the full legal test for classifying information.
The material likewise does not identify who may make each classification decision or prescribe a review timetable. It mentions labels including unclassified, sensitive, restricted and confidential, but does not provide their legal definitions or handling rules; those details cannot be inferred from this general description.
What do classification markings tell readers?
Classification markings tell readers that information has a handling status and should not be treated as unrestricted public material. They signal a need to consider access and handling before sharing a document; the marking alone does not establish what legal rules apply.
Do the listed terms form a federal classification scale?
No. The current summary lists “unclassified,” “sensitive,” “restricted” and “confidential,” but the provided material does not establish these as official federal national-security levels or define their legal meaning, rank or required document markings. Readers should not infer that the four terms form one federal scale.
The 2019 New Zealand government guidance concerns New Zealand’s government classification system, not a U.S. federal rule. It therefore cannot fill gaps in the supplied American information or establish which markings U.S. federal documents must carry. The Federal Register item provided concerns classification and access authority, but its cited excerpt addresses the Paperwork Reduction Act of 1995 and agency approval for information collection; it does not specify a marking scheme.
Who may access classified or controlled information?
Access to classified information is restricted to prevent unauthorized disclosure, but classification alone does not establish that every employee—or every recipient inside an agency—may see it. The available material does not specify clearance categories, eligibility tests or a need-to-know rule, so it cannot support a more detailed account of who qualifies for access.
Classified information and CUI are not the same label
Controlled unclassified information (CUI) is identified in the current summary as non-public information that must be safeguarded; that description does not make CUI classified information. The distinction matters because the supplied material connects classification and access but does not set out particular access permissions for either category.
The Federal Register notice titled “Classified Information: Classification/Declassification/Access; Authority To Classify Information (RRR)” names access and authority to classify in its title. But the supplied excerpt contains only a Paperwork Reduction Act discussion: it says federal agencies must obtain Office of Management and Budget approval for each information collection they conduct, sponsor or require through regulations. That passage does not explain who may access classified material.
How is classification different from ordinary withholding?
Classification differs from ordinary withholding because classification assigns a security designation to information and governs how it must be handled, while a record can be kept from public access for another reason without being classified. The US Legal Forms explanation describes classified information broadly as restricted from public access because of its sensitive nature; that description does not mean every unavailable record carries a classification designation.
What to check first
For a particular record, first look for an explicit classification designation; if none appears, check whether it is described as non-public information or controlled unclassified information (CUI). Those labels are not interchangeable: “classified” identifies a classification status, while non-public and CUI describe other handling or access categories in the supplied material.
- Classified information: Look for a classification designation tied to the information and its handling.
- Non-public or CUI: These descriptions may indicate restricted access or special handling, but do not by themselves establish that the record is classified.
The available sources do not identify particular disclosure exemptions, privacy statutes, or records-request procedures. They therefore cannot support a complete account of why an agency might withhold a record; the safe distinction is between a stated classification designation and a record described only as non-public or CUI.
Where do classification and handling systems fall short?
Classification and handling systems fall short when they cannot reliably identify what unstructured records contain or when users treat different labels as equivalent. A summary from the NHI Support Guidance Forum, attributing its estimate to Collibra, says documents, emails, presentations and reports account for 80–90% of government information; it does not establish that range as a federal measurement.
Unstructured records make consistent classification a practical challenge: a label must reflect a record’s contents, not merely its file type or location. Automated classification and sensitive-data tagging may help flag material for review, but neither proves that a record has been classified correctly or that a person is legally entitled to access it.
Labels are not interchangeable
“Sensitive,” “restricted,” “confidential” and “CUI” should not be treated as synonyms. The supplied material lists these terms but does not establish that they carry the same meaning or handling rules. That distinction matters because a mistaken label can lead to the wrong access decision or safeguard; applying a tag is not a substitute for determining the rules that govern the information.
What approval rule applies to federal information collection?
Federal agencies must obtain Office of Management and Budget (OMB) approval for each information collection they conduct, sponsor, or require through regulations. The requirement appears in the Paperwork Reduction Act section of a Federal Register item dated July 15, 2016, and cites the Paperwork Reduction Act of 1995, 44 U.S.C. 3501 et seq.
Approval is separate from classification
The OMB rule addresses agencies’ collection of information; it does not assign a classification level or decide whether information may be made public. Those are separate questions: the approval requirement concerns the collection, while classification concerns how information is designated and handled.
The cited excerpt does not specify how long an approval lasts, identify forms, or set processing deadlines. Those details therefore cannot be inferred from this passage; its stated rule is limited to requiring OMB approval for each covered collection.
Questions readers ask
How information gets classified in a federal agency?
Is CUI the same as classified information?
Does every withheld federal record have a classification marking?
What does the Paperwork Reduction Act require?
Key takeaways
- Federal classification rests on criteria established by laws and regulations.
- The July 15, 2016 Federal Register item addresses classification, declassification, access and authority to classify.
- CUI is identified as safeguarded non-public information, not as a synonym for classified information.
- The Paperwork Reduction Act of 1995 requires OMB approval for covered agency information collections.
Sources
- federalregister.gov — “Federal Register :: Classified Information: Classification/Declassification/Access; Authority To Classify Information (RRR)”
- US Legal Forms — “Classification of Information: Legal Definition Explained”
- nhimg.org — “Document classification and tagging: what federal agencies need now”
- Version: 2019 — “Classify Information”
- cybersheath.com — “How to Classify Non-Public Information and CUI – CyberSheath”
