Template

Data Classification Matrix

Define your data levels and the handling rules that follow from each one.

Intended audience
Program owners and managers
Difficulty
Intermediate
Estimated time
30 minutes
Access
Premium plans
NIST SP 800-171
ISO 27001
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Define data classification levels appropriate to the organization, from public to regulated.
  • Assign approved storage locations and sharing rules to each classification level.
  • Set encryption, retention, and disposal requirements per level.

Suggested levels

  • Public: intended for release.
  • Internal: routine business information.
  • Confidential: customer, employee, or financial records.
  • Regulated: CUI, health, card, or other legally controlled data.

For each level, define

  • Approved storage locations.
  • Sharing and transmission rules.
  • Encryption requirements.
  • Retention and disposal.

Key takeaways

  • A data classification matrix should define levels from public to regulated, including a level for CUI and other legally controlled data.
  • Each level needs its own approved storage locations, since not all data should live in the same systems.
  • Sharing and transmission rules should differ by level, with regulated data facing the strictest restrictions.
  • Encryption requirements should scale with sensitivity, applying most strictly to confidential and regulated data.
  • Retention and disposal rules per level prevent sensitive data from being kept, or destroyed, inconsistently.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.

Matched on shared frameworks, topics, and program packs.

Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intermediate
15 min
Free
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Checklist

Internal Audit Preparation Checklist

Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.

Intermediate
35 min
Free
SOC 2
ISO 27001

Published · v1.0.0 · 2026-08-01

Guide

Preparing for a Security Assessment

The six weeks before an assessment, sequenced: documentation, evidence, owner rehearsal, and gap honesty.

Advanced
15 min
Premium
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.