PPN 012: Security Classifications Policy · first published 17 February 2025
This Procurement Policy Note (PPN 012) tells central government buyers and their suppliers about an update to the Government Security Classifications Policy (GSCP) — the rules covering how government information must be labelled and protected. The GSCP was originally updated in June 2023; this February 2025 version refreshes the wording to align with the new Procurement Act 2023 (which applies to procurements started on or after 24 February 2025). The policy applies to any information created, processed, stored or managed as part of a government contract — so if your business works on such a contract, these rules apply to you. The three classification tiers remain OFFICIAL, SECRET and TOP SECRET, but definitions, baseline security behaviours, additional markings and guidance on remote working have all been updated. Most changes are minor and unlikely to require a formal contract variation, but your buyer must notify you of any changes that do affect your contract.
WHO THIS APPLIES TO
THE ENKII VIEW
If your business holds or handles government information under a public contract — even at the basic OFFICIAL level — you must be aware of the updated GSCP rules, particularly the refreshed definitions, the correct use of the OFFICIAL-SENSITIVE marking, and the new remote working guidance. The risk for SMEs is non-compliance: failing to apply the right security controls or markings could put a contract at risk or result in a required variation. The opportunity is modest but real: suppliers who proactively update their internal security practices and complete the new 'Security Classifications' e-learning before their buyer asks will be better placed to demonstrate compliance and avoid delays.
1. Review Guidance 1.6: Contractors and Contracting Authorities on GOV.UK to understand what the updated GSCP requires of you specifically as a supplier, and check whether your existing security controls and information-handling practices still meet the updated standards.
All SMEs with an active central government, NHS or NDPB contract — The PPN states that 'in-scope organisations must ensure that appropriate protective security controls are in place for new and existing contracts in line with the updated GSCP' and that specific guidance for suppliers is in Guidance 1.6.
2. Audit how your team currently marks and handles OFFICIAL information. Ensure the OFFICIAL-SENSITIVE marking (not a new tier, but an additional marking) is being applied correctly — only to information not intended for public release that could cause moderate damage if disclosed — and that additional controls are in place when this marking is used.
All SMEs handling OFFICIAL-level government information — The updated GSCP clarifies that 'the -SENSITIVE marking should be applied to OFFICIAL information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media', and that such information 'must be handled using the additional marking and with other additional controls'.
3. Complete the new 'Security Classifications' e-learning module on the Government Campus, and ask your buyer's Security Advisor for the 'Mark My Words' information video to share with your team — particularly staff who work remotely with government information.
All SMEs with staff handling HMG information, including remote workers — PPN 012 notes new remote working guidance within the updated GSCP and states that 'an information video...can be sent to suppliers' and that 'A new E-Learning module is also available on the Government Campus entitled 'Security Classifications''.
4. Do not assume your contract is unaffected. Wait for your buyer to notify you of any changes required, but proactively check whether any contract variation is needed by asking your contract manager — the PPN confirms that 'there might be some instances where specific contracts need to be reviewed'.
SMEs on contracts commenced before 24 February 2025 — The PPN states that 'in-scope organisations should notify existing suppliers that the GSCP has been updated and set out any changes needed to the contract', and that while most changes are minor, some contracts may need review.
5. When preparing bids, ensure your security management approach references the updated GSCP three-tier framework (OFFICIAL, SECRET, TOP SECRET) and demonstrate familiarity with classification, marking and handling requirements — buyers will expect compliance from day one.
SMEs bidding for new central government contracts from 24 February 2025 onwards — The PPN applies to 'any information or data that is created, processed, stored or managed as part of an HMG contract' and in-scope organisations 'must ensure that appropriate protective security controls are in place for new and existing contracts'.
Every rule below quotes the official document verbatim.
The PPN applies to all central government departments, executive agencies, non-departmental public bodies (NDPBs) and NHS bodies ('in-scope organisations'), and the GSCP applies to any information or data created, processed, stored or managed as part of an HMG contract. (All central government departments, executive agencies, NDPBs, NHS bodies and their suppliers)
“This Procurement Policy Note (PPN) applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies.”
In-scope organisations (and therefore their suppliers) must note the provisions of this PPN from 24 February 2025. (All in-scope organisations and their suppliers)
“In-scope organisations should note the provisions of this PPN from 24 February 2025.”
The Procurement Act 2023 and associated Procurement Regulations 2024 apply only to procurements commenced on or after 24 February 2025; contracts awarded before this date remain under previous legislation and should refer to PPN 07/23. (All procurements; contracts commenced before 24 February 2025 refer to PPN 07/23)
“The Procurement Act 2023 and the Procurement Regulations 2024 apply to procurements commenced on or after 24 February 2025.”
This update does not constitute a new policy change or a new call for action — it reflects updated terminology from the Procurement Act 2023. (All in-scope organisations)
“This update does not constitute a change in policy or a new call for action but in-scope organisations should continue to apply any ongoing obligations set out in the provisions of this PPN.”
HMG uses three classification tiers: OFFICIAL, SECRET and TOP SECRET, each with baseline security behaviours and protective controls proportionate to threat level and potential impact of compromise. (All suppliers handling HMG information under a government contract)
“HMG uses three classification tiers; OFFICIAL, SECRET and TOP SECRET. Each tier provides a set of recommended baseline behaviours and a set of protective controls, which are proportionate to the threat profile for that tier AND the potential impact of a compromise, accidental loss or incorrect disclosure.”
OFFICIAL covers the majority of public sector information that could cause no more than moderate damage if compromised. (All suppliers handling government information)
“OFFICIAL: 'The majority of information that is created, processed, sent or received in the public sector and by partner organisations, which could cause no more than moderate damage if compromised.'”
OFFICIAL-SENSITIVE is not a separate classification tier; it is an additional marking applied to OFFICIAL information not intended for public release and of at least some interest to threat actors, activists or the media, where compromise is likely to cause moderate damage. (All suppliers handling OFFICIAL-level government information)
“OFFICIAL-SENSITIVE has not been introduced as a new classification tier.”
The OFFICIAL-SENSITIVE marking should be applied to OFFICIAL information not intended for public release and of at least some interest to threat actors, activists or the media, where a compromise is likely to cause moderate damage to the organisation and/or HMG. (All suppliers handling OFFICIAL information)
“the -SENSITIVE marking should be applied to OFFICIAL information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media.”
The majority of GSCP updates are minor and will not require a contract variation to existing contracts, but some specific contracts may need to be reviewed. (All existing government contracts)
“The majority of these updates are minor changes which will not require a contract variation to existing contracts. However, there might be some instances where specific contracts need to be reviewed.”
In-scope buying organisations must notify existing suppliers that the GSCP has been updated and set out any changes needed to the contract. (In-scope organisations and their existing suppliers)
“In-scope organisations should notify existing suppliers that the GSCP has been updated and set out any changes needed to the contract.”
A new e-learning module called 'Security Classifications' is available on the Government Campus, and an information video ('Mark My Words') can be sent to suppliers by departmental Security Advisors. (All suppliers and in-scope organisation staff)
“A new E-Learning module is also available on the Government Campus entitled 'Security Classifications'.”
Specific guidance for commercial teams and suppliers is set out in Guidance 1.6: Contractors and Contracting Authorities, available on GOV.UK. (All suppliers on HMG contracts)
“A full suite of guidance documents is available on GOV.UK, with specific guidance for commercial teams and suppliers set out in Guidance 1.6: Contractors and Contracting Authorities.”
Other public sector contracting authorities outside the mandatory in-scope group may wish to apply the approach set out in this PPN. (Wider public sector contracting authorities (encouraged, not mandated))
“Other public sector contracting authorities creating, processing, storing or managing data or information as part of an HMG contract may wish to apply the approach set out in this PPN.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.