GSA Approved Security Containers: A Practical Guide
Learn what GSA approved security containers are, which federal standards apply, and how GovCons can select, verify, and manage them for classified work.

Your first classified award lands, the program manager wants a start date, and the facility security officer is still answering basic questions. The facility clearance is pending, there is no approved container on site, and someone is already asking why this was not handled earlier.
That pressure is familiar to small and mid-sized GovCons. A security container is not a routine furniture purchase. It can become a gating item for DD-254 acceptance, security plan approval, and cleared-personnel onboarding. The right decision has three parts: choose the correct container, verify that the asset is approved, and operate it in a way that will hold up under agency scrutiny.
A Contractor's First Classified Win and the Container Question
Start with the material, not the catalog. Before anyone requests a quote, the FSO should read the DD-254, identify the highest classification involved, confirm the storage requirement, and match that requirement to the facility's approved security plan. If the solicitation involves classified information, storage cannot be treated as a later facilities task. GSA states that classified national security information must be stored in GSA-Approved Security Containers and Vault Doors, and material still held in non-approved containers must be relocated immediately.
The practical sequence is straightforward:
- Confirm the security trigger. Determine whether the contract involves Confidential, Secret, or Top Secret information, and separately identify any CUI, CDI, or SBU handling language.
- Select the container class. Do not let terms such as "government-grade safe" substitute for the applicable Federal Specification and class.
- Verify before delivery. Require the manufacturer, model, label details, lock configuration, and procurement records before the unit enters the controlled space.
- Prepare the operating controls. Combination custody, access records, inspections, supplemental Top Secret controls, and contingency access belong in the implementation plan.
A 45-day period of performance start can disappear quickly when facility clearance coordination, delivery access, installation, documentation, and inspection all compete for the same calendar. The FSO should own the container workstream, but the program manager, facilities lead, contracts manager, and IT security lead should each have assigned actions.
Practical rule: Treat the container as a readiness gate, not a warehouse item.
GovCon Reviews' company information
The strongest small-business workflow is to document the decision in the security plan, preserve the procurement trail, and schedule an inspection before classified material arrives.
What Makes a Container GSA Approved
A contractor can buy a heavy cabinet and still fail a security review. GSA approved identifies a security container that meets the applicable federal specification, approved construction requirements, and permitted lock configuration. The framework includes Federal Specification AA-F-358 for Class 5 and Class 6 filing cabinets and map files, AA-F-357 for Class 5 and Class 6 drawer containers, and FF-L-2740 for approved combination locks.
Approval depends on tested construction, resistance characteristics, locking hardware, and configuration. The approval label identifies the evaluated unit. Weight, a commercial burglary rating, or a salesperson's description does not establish compliance.
GSA documentation describes classified-storage containers as typically uninsulated cabinets covered by AA-F-358. It also connects approval to specific lock standards. Style 1 and Style 2 locks compliant with FF-L-2740 are permitted, while mechanical FF-L-2937 locks are allowed for field safes only, according to GSA's security-container guidance.

Read the specification, not the sales copy
A manufacturer may call a cabinet secure, reinforced, or suitable for government use without proving GSA approval. Require the exact Federal Specification reference, container class, approved lock type, label information, and any applicable National Stock Number. If the seller cannot provide those details, pause the purchase until the documentation is complete.
Class identifies the tested security category, but the cabinet must also remain in an approved configuration. A compliant cabinet with an unapproved replacement lock is not automatically compliant because its body still carries an approval plate. Verify the hardware in the field, not only in the quote.
Approval belongs to the unit
GSA approval belongs to the approved unit and its configuration. It is not a subscription, annual certification, or vendor status that renews automatically. The organization must preserve the unit's identity, inspect its condition, verify its label, and confirm that repairs or hardware changes have not altered the approved configuration.
That becomes especially important during ownership changes, facility moves, black-label phase-out work, and surplus purchases. A used cabinet can reduce procurement friction, but only after its provenance, label, construction, and lock configuration are established. Keep those records with the facility security documentation before classified storage begins.
Classified Material, CUI, and Where Each Container Fits
Choose the container for the highest classification the facility will store. GSA identifies approved containers for Confidential, Secret, and Top Secret information, while the required class and supplemental controls depend on the classification and the facility's security plan. GSA's container-type guidance also identifies a field cue for relevant Class 5 and Class 6 containers manufactured after October 1990: a silver label with red lettering, or red with silver lettering.
Use this decision table during facility planning:
| Material Type | Minimum Container Class | Supplemental Controls | Authority |
|---|---|---|---|
| Confidential | Class 5 as a practical floor | Follow approved facility procedures and contract direction | DD-254, agency security requirements, GSA container guidance |
| Secret | Class 5 or Class 6, selected for the mission and facility plan | Apply the controls in the approved security procedures | DD-254 and applicable federal security requirements |
| Top Secret | Class 6 | Apply one supplemental control required by 32 CFR 2001.43 | 32 CFR 2001.43 |
| CUI or CDI | No universal classified-container class solely because the material is CUI | Apply contract, agency, and system-security requirements | DFARS 252.204-7012, 32 CFR Part 2002, and contract terms |
| SBU | Depends on the issuing agency and handling instruction | Follow the specific agency direction | Agency policy and contract language |
Top Secret changes the installation plan
A Class 6 container does not complete the Top Secret storage requirement. Under 32 CFR 2001.43, a contractor may store Top Secret information in a GSA-approved security container only with one of three supplemental controls: inspection every two hours by an employee cleared at least to Secret, an intrusion detection system with responders arriving within 15 minutes, or security-in-depth coverage with a lock meeting FF-L-2740.
That selection drives staffing, alarm design, response procedures, and the security plan. Choose the control path with the container. Confirm that the facility can operate it before procurement.
Keep CUI in its own lane
CUI and CDI do not automatically receive the same treatment as classified information. A contractor may use a GSA container for CUI because of customer direction, internal policy, or risk reduction, but the container alone does not satisfy the CUI requirement. The governing requirements may come from DFARS 252.204-7012, 32 CFR Part 2002, the contract, and the organization's system-security documentation.
Read the DD-254 and the applicable CUI category together. A classified-storage clause calls for the classified-container decision. A CUI requirement calls for a physical-storage decision mapped to the contract, agency instructions, and system-security controls.
Verifying GSA Approval and Reading the Labels
Field verification often fails for ordinary reasons. Plates fade, cabinets get repainted, hardware gets replaced, and a facilities team may install a retrofit without realizing the lock is part of the approved configuration. A cabinet that looks right can still create a finding when the FSO cannot establish what it is.
Use a repeatable inspection routine
Begin with the exterior label or approval plate. Record the manufacturer, model or identifying information, Federal Specification reference, class, label color, and serial number where available. Then inspect the interior for matching labels or markings, because the transition guidance for legacy containers requires attention to both exterior and interior labels.
The silver-label cue is associated with current-standard identification for relevant Class 5 and Class 6 containers manufactured after October 1990. Black-label units are legacy approved containers, not automatically worthless, but they do require active phase-out management. The Defense Counterintelligence and Security Agency explains the transition and label-removal requirements.
| Feature | Silver-Label Current Standard | Black-Label Legacy Approved |
|---|---|---|
| Field cue | Silver label with red lettering, or red with silver lettering | Black approval label |
| Procurement meaning | Supports current identification and inspection | Requires phase-out tracking for classified storage |
| Verification focus | Confirm specification, class, manufacturer, and lock | Confirm legacy identity, disposition status, and transition action |
| Documentation action | Record serial and approval details | Record location, planned transition, and label-removal action |
Next, cross-reference the asset with the GSA Global Supply catalog and applicable NSN. Confirm that the model or product family appears in the relevant qualified-products information, then preserve the procurement record with the security plan. A serial-number inventory is more useful than a vague entry such as "one government safe."
Inspection standard: If the FSO cannot explain what the label says, which specification applies, and whether the lock remains approved, the container is not ready for classified storage.
Treat missing plates, welded repairs, third-party retrofit kits, overpainted faces, and swapped locks as stop signs. Do not relabel a unit from memory. Escalate the evidence to the manufacturer, procurement authority, or cognizant security authority before using it.
Procurement Routes for GovCons
Small and mid-sized contractors have three realistic buying routes. The right route depends on the required specification, delivery window, facility constraints, and the strength of the documentation trail.
GSA Global Supply requisition is the cleanest compliance path. GSA says federal agencies are required to buy approved security containers and vault doors through brand-name NSNs in GSA Global Supply via requisition. That route reduces ambiguity, but inventory, lead times, delivery restrictions, and standard dimensions may not fit every facility.
GSA Schedule purchasing through an approved reseller can offer broader product selection, installation support, delivery coordination, and field service. It can work well when the contractor needs a specific footprint or help moving a heavy cabinet into a controlled area. The tradeoff is more vendor comparison, possible minimum-order friction, and price variance that the buyer should document.
Open-market purchase should be the fallback, not the default. It may solve a time or configuration problem, but the contractor must establish why the purchase is permitted, identify contract language authorizing a non-GSA container if applicable, and preserve the technical evidence supporting the exception.

The practical default
For a 50-person GovCon, default to the cleanest approved channel that meets the schedule. Start with GSA Global Supply when the required NSN and standard configuration fit the facility. Use a Schedule reseller when installation, layout, or delivery support makes the additional administration worthwhile. Choose open market only after the FSO and contracts lead document the authority and approval basis.
Do not separate purchasing from security review. Put the FSO in the purchase approval chain before the purchase order is issued, and require the vendor to identify the exact model, class, Federal Specification, lock configuration, label format, and delivery conditions.
Selection and Compliance Checklist for Small and Mid GovCons
Most container findings do not begin with an absent safe. They begin with a safe that was selected without checking the classification, installed without documenting the location, or operated without controlling combinations. A working checklist catches those failures before a DCSA review turns them into corrective actions.

Selection and physical installation
Container selection: Record the material category, required class, internal capacity, exterior dimensions, weight, lock type, label status, and replacement outlook. Check floor loading and delivery access before ordering. If Top Secret work is plausible, evaluate the supplemental-control path now.
Physical installation: Confirm anchoring requirements, clear working space, access restrictions, environmental conditions, and separation from unauthorized personnel traffic. For Top Secret operations, reserve the space and infrastructure needed for the chosen supplemental control, including any alarm, response, inspection, or security-in-depth procedure.
Documentation and lifecycle
Update the Fixed Facility Checklist entries, the relevant SF-702 and SF-703 records, the container inventory, and the lock-combination custody log. The documentation should identify the asset, location, responsible personnel, operating procedure, and evidence used to verify approval.
Combination management deserves its own procedure. Define changeover after personnel departures, emergency access during lockouts, custody of combination records, and coordination with the cognizant security authority before re-keying or changing approved lock hardware. Storing a combination card inside the container defeats the purpose of access control and creates an avoidable inspection problem.
Lifecycle review: Re-verify labels, reconcile the inventory, inspect the lock and body, document repairs, and track legacy black-label units through disposition or approved unclassified reuse. Assign an owner and a review date.
What DCSA sees: The container, the records, the people who can open it, and the evidence that those elements still match.
Use the following video as a supplemental visual reference while building your internal checklist, then validate every operational decision against the contract and security authority.
Tradeoffs and Operational Risks Most Plans Miss
A sealed, heavy cabinet does not equal finished compliance. It only solves the physical-storage question if the unit is approved, correctly configured, properly installed, and operated under the controls required for the material inside.
A major operational issue today is the black-label transition. GSA-approved containers date back to 1954, when the first approved containers and vault doors entered federal service, and the Information Security Oversight Office noted in 2021 that they had been in service for 67 years in the federal specification record. GSA announced a four-year phase-out beginning October 1, 2024, covering pre-1989 black-label containers and Class 1, 2, 3, and 4 cabinets produced under the specified AA-F-357 and AA-F-358 revisions. DCSA later extended the deadline to October 1, 2027, so contractors need an inventory and replacement plan.

Convert each risk into an action
- Assumed benefit, sealed container: The unmanaged risk is ignoring label transition, maintenance debt, and changing storage authority. Corrective action: inventory every black-label unit, identify its classified use, and assign replacement or disposition.
- Assumed benefit, purchase complete: The unmanaged risk is losing the evidence needed to prove provenance and configuration. Corrective action: retain the NSN, model, label photographs, serial number, invoice, lock details, and installation record together.
- Assumed benefit, standard lock: The unmanaged risk is missing a required supplemental control or operating an unapproved replacement. Corrective action: compare the installed lock to the permitted specification before storing classified material.
- Assumed benefit, combination known to the FSO: The unmanaged risk is uncontrolled access after turnover or emergency lockout. Corrective action: document custody, changeover, emergency access, and authority coordination.
Top Secret storage adds another layer. The selected supplemental control must work in practice, whether the facility relies on recurring inspections, an intrusion detection system with the required response capability, or security-in-depth with the required lock standard. A plan that lists the control but does not name the responsible person, record, response process, and review cadence is incomplete.
DCSA reviews also expose basic field failures: illegible or missing labels, locks swapped without approval evidence, combination cards left inside containers, and undocumented combination changes after personnel turnover. Fix those items this quarter.
Pulling It Together Into a Decision Flow
Run the process as a reusable operating procedure.
- Start with the trigger. Use a classified award, DD-254 change, CUI requirement shift, facility move, or legacy-container review as the initiation event.
- Identify the material. Separate Confidential, Secret, Top Secret, CUI, CDI, and SBU requirements instead of treating them as one storage category.
- Determine the specification and class. Select the container against the actual contract and facility requirement, then identify any Top Secret supplemental control.
- Verify the asset. Check the label, specification, lock, serial number, procurement record, and applicable GSA Global Supply NSN before use.
- Choose the channel. Match GSA requisition, Schedule purchase, or documented open-market procurement to the timeline, configuration, and approval basis.
- Close the operating loop. Update the security plan and records, control combinations, complete installation checks, and track the asset through recurring reviews and black-label disposition.
This flow handles new classified work, CUI boundary changes, facility moves, and replacement planning without rebuilding the process each time. The FSO should be able to show not only what container is present, but why it was selected, how it was verified, who controls it, and what happens when the asset or personnel changes.
FAQ
What is a GSA approved security container?
A GSA approved security container is a storage unit that meets the applicable federal specification and approved lock requirements for classified storage. Approval depends on the specific unit and its configuration, not on marketing language or vendor claims.
Can I use a commercial safe for classified storage?
Not by default. A heavy commercial safe, burglary rating, or "government-grade" description does not establish approval for classified storage. The unit must match the required federal specification and approved lock configuration.
How do I verify that a container is approved?
Check the approval label, manufacturer details, class, applicable specification, and installed lock. Then match the unit to procurement records and any relevant NSN information before placing classified material inside.
What container class is used for Top Secret storage?
Top Secret storage generally requires a Class 6 container, plus one supplemental control under 32 CFR 2001.43. The container alone is not the full requirement.
Is a GSA approved container required for CUI?
Not in every case. CUI is governed by contract terms, agency instructions, and applicable security requirements. A contractor may choose to use a GSA container for CUI, but the container itself does not automatically satisfy all CUI handling obligations.
Can I buy a used GSA approved container?
Yes, but only after verifying the unit's provenance, approval label, condition, and lock configuration. Used containers should be treated as a documentation exercise, not just a cost-saving purchase.
What is the difference between silver-label and black-label containers?
Silver-label containers are the current field cue for relevant Class 5 and Class 6 containers manufactured after October 1990. Black-label containers are legacy approved units that may require transition planning, tracking, and eventual replacement depending on their status and use.
What records should the FSO keep?
Keep the procurement record, model details, serial number, label photos, lock information, installation record, inventory entry, and combination custody documentation. Those records should stay aligned with the facility security documentation.
GovCon Reviews helps contractors evaluate the software and services that support capture, compliance, and operational readiness, with practical comparisons for teams that cannot afford a poor buying decision. Visit GovCon Reviews to assess tools and services that can strengthen the procurement record, inventory process, and inspection readiness behind your security program.
Related analysis

What Is FedRAMP and Why It Matters in 2026
Learn what is FedRAMP, how it works, who needs authorization in 2026, and how the modernization push changes the path for cloud providers and GovCon buyers.

10 Proposal Writing AI Tools for GovCon Teams
Compare 10 proposal writing AI tools for GovCon teams, with features, pricing, strengths, limitations, use cases, and a clear top pick.

Time and Materials Contracts for Federal Contractors
Learn how time and materials contracts work for federal contractors, including FAR rules, pricing, invoicing, audit controls, and how T&M compares to FFP.