# 32 C.F.R. § 2004.38 (2026): Safeguarding and marking

> Federal · Regulations · In force

URL: https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_38

## Section

- **Citation:** 32 C.F.R. § 2004.38 (2026)
- **Heading:** Safeguarding and marking
- **Jurisdiction:** Federal
- **Kind:** Regulations
- **Status:** In force
- **Text as of:** August 14, 2026
- **Source:** Compiled text
- **Location:** Title 32 CFR: National Defense / Chapter XX: INFORMATION SECURITY OVERSIGHT OFFICE, NATIONAL ARCHIVES AND RECORDS ADMINISTRATION / Part 2004: NATIONAL INDUSTRIAL SECURITY PROGRAM (NISP) / Subpart C: Operations / § 2004.38: § 2004.38   Safeguarding and marking.

## Text

(a)
Safeguarding approval.
(1) The CSA determines whether an entity's safeguarding capability meets requirements established in 32 CFR part 2001, and other applicable national level policy (
e.g.,
Atomic Energy Act for RD). If the CSA makes a favorable determination, the entity may store classified information at that level or below. If the determination is not favorable, the CSA must ensure that the entity does not possess classified information or does not possess information at the classification level denied or a higher level.
(2) The CSA maintains records of its safeguarding capability determinations and, upon request from GCAs or entities, and as appropriate and to the extent authorized by law, verifies that it has made a favorable safeguarding determination for a given entity and at what level.
(b)
Marking.
The GCA provides guidance to entities that meets requirements in 32 CFR 2001.22, 2001.23, 2001.24, and 2001.25, Derivative classification, Classification marking in the electronic environment, Additional requirements, and Declassification markings; ISOO's marking guide,
Marking Classified National Security Information;
and other applicable national level policy (
e.g.,
Atomic Energy Act for RD) for marking classified information and material.

## Nearby sections

- [32 C.F.R. § 2004.30 (2026) § 2004.30   Security classification requirements and guidance.](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_30.md)
- [32 C.F.R. § 2004.32 (2026) § 2004.32   Determining entity eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_32.md)
- [32 C.F.R. § 2004.34 (2026) § 2004.34   Foreign ownership, control, or influence (FOCI).](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_34.md)
- [32 C.F.R. § 2004.36 (2026) § 2004.36   Determining entity employee eligibility for access to classified information.](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_36.md)
- [32 C.F.R. § 2004.38 (2026) § 2004.38   Safeguarding and marking.](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_38.md)
- [32 C.F.R. § 2004.40 (2026) § 2004.40   Information system security.](https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_40.md)

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/statutes/CFR_T32_P2004_S2004_38. Check the current official text before relying on it. Not legal advice.
