LIVE · UK MARKET INDEXED
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
PPN 07/23 · UPDATED 30 JUNE 2023

The Government Security Classifications Policy has been updated and all central-government suppliers must handle official information under new classification rules by June 2024.

PPN 07/23: Security Classifications Policy · first published 30 June 2023

What it says, in plain English

This Procurement Policy Note (PPN 07/23) tells central government buyers to update how they classify and protect information on contracts — and requires them to notify their suppliers of any changes. The Government Security Classifications Policy (GSCP) was last overhauled in 2013; this 2023 update refreshes the three classification tiers (OFFICIAL, SECRET, TOP SECRET), tightens rules around the OFFICIAL-SENSITIVE marking, and introduces standardised additional markings such as handling instructions and descriptors. If you hold or handle government information under a contract, you may receive a notification from your buyer about changed security requirements. Most updates are minor and will not require a formal contract variation, but some contracts may need to be reviewed. You have until June 2024 to be compliant.

WHO THIS APPLIES TO

Who it binds
Central government buyers
Contract values
any value
Applies from
30 June 2024
Sectors
All sectors where suppliers create, process, store or manage information or data as part of a central-government contract.

THE ENKII VIEW

For SMEs already working on government contracts that involve handling official data, this is a compliance checkpoint: your buyer is obliged to tell you what has changed, but you should proactively familiarise yourself with the updated classification tiers and OFFICIAL-SENSITIVE rules before they ask. SMEs bidding for new contracts should expect updated security requirements baked into tender documents from now on — buyers must implement by June 2024, so new procurements launched after that date will reflect the full updated GSCP. The availability of free training materials (including a supplier-facing video and a new e-learning module) means there is no cost barrier to getting compliant.

What a small business should do about it

1. Wait for your buyer's notification about changes to your contract's security requirements — but don't wait passively: read Guidance 1.6 (Contractors and Contracting Authorities) on GOV.UK now so you are ready to respond quickly.

All SMEs with existing central-government contracts involving HMG informationThe PPN requires in-scope buyers to notify existing suppliers of changes; most will not need a contract variation, but some contracts will require review — knowing the guidance in advance speeds up your response.

2. Check whether any information you hold under contract should now carry the OFFICIAL-SENSITIVE marking and apply the required additional controls if so.

All SMEs handling OFFICIAL-tier government informationThe updated GSCP clarifies that OFFICIAL-SENSITIVE is an additional marking (not a new tier) and specifies that it must be applied to OFFICIAL information not intended for public release that could cause moderate damage if compromised.

3. Complete the free 'Security Classifications' e-learning module on the Government Campus and request the 'Mark My Words' awareness video from your buyer's Security Advisor before the June 2024 deadline.

All SMEs handling HMG information at any classification tierThe PPN explicitly states these training materials are available to suppliers at no cost; completing them demonstrates compliance readiness and reduces the risk of handling errors under the updated policy.

4. Familiarise yourself with the updated definitions of the three tiers (OFFICIAL, SECRET, TOP SECRET) and the standardised additional markings table, so you can accurately describe your security controls in tender responses.

SMEs bidding for new central-government contracts that will involve handling government dataBuyers must implement the updated GSCP by June 2024; new tenders launched after that date will reflect the updated classification requirements, and bidders will be expected to demonstrate they understand and can comply with them.

5. Review the specific baseline security behaviours in Guidance 1.2 (Working at SECRET) and Guidance 1.3 (Working at TOP SECRET) on GOV.UK to confirm your physical infrastructure and network controls still meet the updated requirements.

SMEs handling SECRET or TOP SECRET information under contractThe updated GSCP sets enhanced protective controls for SECRET and TOP SECRET tiers, including requirements for secure networks on secured dedicated physical infrastructure — gaps here could trigger a contract review.

The rules, anchored to the text

Every rule below quotes the official document verbatim.

The PPN applies to all Central Government Departments, their Executive Agencies, Non-Departmental Public Bodies (NDPBs) and NHS bodies, collectively called 'In-Scope Organisations'. (All in-scope central government organisations, all contract values)

The contents of this Procurement Policy Note (PPN) apply to all Central Government Departments, their Executive Agencies, Non-Departmental Public Bodies and NHS bodies.

The GSCP applies to any information or data created, processed, stored or managed as part of an HMG contract — including by suppliers. (All suppliers holding or handling HMG information under contract)

The Policy applies to any information or data that is created, processed, stored or managed as part of an HMG contract.

In-Scope Organisations must implement the updated GSCP by June 2024. (All in-scope organisations, all contract values)

The contents of this PPN should be implemented by June 2024. This 12-month implementation window is to allow sufficient time for the requirements of the updated classifications policy to be integrated into commercial activity.

Other public sector contracting authorities (outside central government) may choose to apply this PPN but are not required to. (Public sector bodies outside central government — voluntary adoption only)

Other public sector contracting authorities creating, processing, storing or managing data or information as part of an HMG contract may wish to apply the approach set out in this PPN.

HMG uses three classification tiers: OFFICIAL, SECRET and TOP SECRET, each with defined baseline security behaviours proportionate to threat and impact. (All suppliers handling HMG information, all contract values)

HMG uses three classification tiers; OFFICIAL, SECRET and TOP SECRET. Each tier provides a set of recommended baseline behaviours and a set of protective controls, which are proportionate to the threat profile for that tier AND the potential impact of a compromise, accidental loss or incorrect disclosure.

OFFICIAL covers the majority of public-sector information and must be defended against a broad range of threat actors; a compromise could cause no more than moderate damage. (All suppliers handling OFFICIAL-tier HMG information)

The majority of information that is created, processed, sent or received in the public sector and by partner organisations, which could cause no more than moderate damage if compromised and must be defended against a broad range of threat actors with differing capabilities using nuanced protective controls.

OFFICIAL-SENSITIVE is NOT a separate classification tier; it is an additional marking applied to OFFICIAL information that is sensitive enough to require extra controls. (All suppliers handling OFFICIAL-tier HMG information)

OFFICIAL-SENSITIVE has not been introduced as a new classification tier.

The OFFICIAL-SENSITIVE marking must be applied to OFFICIAL information not intended for public release that is of at least some interest to threat actors, activists or the media, and where compromise is likely to cause moderate damage. (All suppliers handling OFFICIAL-SENSITIVE information under contract)

The -SENSITIVE marking should be applied to OFFICIAL information that is not intended for public release and that is of at least some interest to threat actors (internal or external), activists or the media. A compromise of OFFICIAL information or material marked -SENSITIVE is likely to cause moderate damage to the work or reputation of the organisation and/or HMG.

The 2023 update introduces a standardised (non-exhaustive) list of additional markings — handling instructions, descriptors, prefixes and national caveats — which can be applied alongside classification tiers. (All suppliers handling HMG information, all contract values)

The GSCP 2023 introduces a non-exhaustive standard list of additional markings (handling instructions, descriptors, prefixes and national caveats).

Buyers must notify existing suppliers of the updated GSCP and set out any changes needed to the contract; most updates will not require a formal contract variation. (All existing suppliers on central-government contracts involving HMG information)

In-Scope Organisations should notify existing suppliers that the GSCP has been updated and set out any changes needed to the contract... The majority of these updates are minor changes which will not require a contract variation to existing contracts.

Training materials for suppliers include an information video ('Mark My Words') available via departmental Security Advisors, and a new e-learning module on the Government Campus called 'Security Classifications'. (All suppliers and in-scope organisations)

This includes an information video which can be sent to suppliers... A new E-Learning module is also available on the Government Campus entitled 'Security Classifications'.

Specific guidance for commercial teams and suppliers is set out in Guidance 1.6: Contractors and Contracting Authorities, available on GOV.UK. (All suppliers handling HMG information under contract)

A full suite of guidance documents is available on GOV.UK, with specific guidance for commercial teams and suppliers set out in Guidance 1.6: Contractors and Contracting Authorities.

This briefing is enkii's interpretation of the official document — the official text always governs.

Official document on GOV.UK

Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.