Understanding Derivative Classification
Derivative classification is when you take existing classified information and incorporate it, paraphrase it, or generate new material based on it. You aren't creating original classification decisions. You're following guidance that someone more senior already made. The process sounds simple on paper, but it trips people up constantly because the line between derivative and original classification isn't always obvious in practice. I learned this the hard way on a project involving intelligence estimates pulled from multiple originating agencies. The document in question had three different classification markings across its sections, and one paragraph referenced another document I hadn't actually read in full. My instinct was to classify the whole thing at the highest level mentioned anywhere. That would have been wrong. Instead, I had to go back to the source documents, verify the original markings, and apply the Derivative Classification Guidance (DCG) line by line. Took me about forty-five minutes longer than it should have, but it caught a mistake that would have resulted in over-classification.
What the Derivative Classification Exam Answers Actually Cover
The exam itself tests whether you understand the four main sources you're allowed to draw from when classifying derived material: Classification Guides, Original Classification Decisions, the Classification of National Security Information Executive Order (currently EO 13526), and classified information from other government documents. It also covers duration, marking requirements, and declassification rules. Most people study the executive order cover to cover and then wing it on the exam. That approach works for some questions but misses the nuance on others. The trick is understanding that the Classification Guide is your primary tool. If a guide exists for your organization or system, it overrides everything else when there's a conflict. People forget that part. Another thing the exam doesn't make clear but that matters in real work: you need to know how to handle situations where the Classification Guide is missing or outdated. I once had to classify a technical manual with no DCG on file and a superseded version in the archive. The workaround was contacting the originating activity directly to get a current guide or a written classification determination. Going forward with an old guide would have been a violation.
How Derivative Classification Actually Works
Start with the source document. Identify exactly what information it contains and what markings are already applied. Then match that information to your Classification Guide or the applicable Original Classification Decision. If the guide says the material is Secret but the source shows Top Secret, you need to figure out why before you proceed. That discrepancy might mean the source was over-classified or the guide needs updating. Mark your derived document using the proper formats. A derivative classification entry needs to show where the information came from, what the original classification level was, and who originally classified it. The marking goes in the lower portion of each page that contains the classified content, usually at the bottom center or bottom right depending on the document type. Don't skip this step. It's the most common error I see on audits. When you're compiling information from multiple sources, the general rule is you classify based on the highest level of any individual piece of information, not on the aggregate. Aggregate classification only applies under specific conditions outlined in the governing directives. Most people mix those two up and end up classifying containers or compilations unnecessarily.
Get the Full Details

Common Pitfalls
The biggest issue is treating derivative classification as a mechanical task rather than a decision-making process. You're supposed to be evaluating the information against guidance, not just copying markings from one document to another. I've seen people photoclassify entire files because they didn't want to spend time reading through the source material. That's not derivative classification. That's negligence. Another frequent mistake is getting confused about when declassification applies. Derivative classification doesn't reset the clock. If the source information was originally classified for five years and that period has expired, the information may already be eligible for automatic declassification even if it still appears in a source document you're working from. Check the declassification schedule and the date of the original classification decision before you assume the info is still protected. There's also the problem of handling Sensitive Compartmented Information, or SCI. SCI has its own compartment controls that go beyond the standard classification levels. You can't derive SCI-marked information into a document that only has a traditional classification marking. The SCI controls have to appear explicitly. This comes up constantly in joint operations where different agencies with different clearance levels are working together.
What I Wish I Knew Before Taking the Exam
The exam questions often present scenarios where multiple answers seem partially correct. The right answer is usually the one that most closely follows the Classification Guide as the controlling authority. When no guide exists, the Original Classification Decision governs. When neither is available, you reference EO 13526 and its implementing directives. The questions also love to test your knowledge of marking requirements. Know the exact formatting rules for class marks, security classification banners, and derivative classification entries. These details show up more often than you'd expect. Don't skim over them in your study materials. One counter-intuitive point that helped me: the exam frequently asks about situation where you are classifying something at a lower level than the source. This is allowed and sometimes necessary. If your Classification Guide specifically states that certain data elements should be classified at Confidential even though a source document marks them at Secret, the Guide controls. This happens more often in technical fields where classification decisions get tightened over time without the guides being updated. The exam expects you to know this hierarchy.