CTI Academy
Login Get Started

Traffic Light Protocol (TLP 2.0), Explained

What each TLP label really means, how to mark reports correctly, and the mistakes analysts make.

The fastest way to get quietly cut out of an information sharing community is not leaking something. It is mislabeling it.

Mark a report TLP:RED when it should have been TLP:GREEN and you have just made your intelligence useless to everyone who needed it. Mark it TLP:GREEN when the source meant TLP:AMBER and you have burned a trust relationship that took years to build, and possibly exposed a victim organization in the process. Neither mistake looks dramatic at the time. Both are the kind of thing that ends an analyst's invitation to the good channels.

The Traffic Light Protocol exists to prevent exactly this. It is four short labels that tell a recipient how far they are allowed to pass something on, and it is the closest thing threat intelligence has to a universal handling language. It works identically in an email, a PDF, a Slack message, a slide, or a sentence spoken out loud at a conference.

It is also, as of 2026, one of the most consistently misexplained topics in CTI. Plenty of published guides still describe TLP:WHITE, which was retired in 2022. Plenty describe five labels when the standard defines four. And almost none mention the machine-readable gap that will break your STIX export the first time you try to use the newest marking.

Here is the accurate version.

What the Traffic Light Protocol Actually Is

The Traffic Light Protocol (TLP) is a set of four labels that an information source attaches to what it shares, telling recipients how widely they may pass it on. The four labels are TLP:RED, TLP:AMBER, TLP:GREEN, and TLP:CLEAR, and they run from no onward sharing at all to unrestricted public release. The current version is TLP 2.0, standardized by FIRST and authoritative since August 2022.

The design goal is worth understanding, because it explains why TLP is so minimal. FIRST's own framing is that TLP was created to facilitate greater sharing, not less. It is not a lock. It is a permission slip. Before TLP existed, the safe default when you held sensitive information was to say nothing, because you had no reliable way to tell a recipient what they could do with it. A label that travels with the data removes that excuse.

That origin story goes back further than most people realize. TLP was created in the early 2000s by the UK government's National Infrastructure Security Co-ordination Centre, and it circulated informally in incident response circles for well over a decade before FIRST formed a Special Interest Group to standardize it. Version 1.0 was published on 31 August 2016. Version 2.0 followed on 5 August 2022, and CISA officially adopted it on 1 November 2022.

One framing to keep straight from the start: TLP is not a classification scheme. FIRST is explicit that it is not a formal classification system, was never designed to carry licensing terms or encryption rules, and has no effect on freedom of information or sunshine laws in any jurisdiction. CISA states plainly that, unlike formal classification systems, TLP is not legally binding. It runs on community trust and reciprocity, which is precisely why breaking it costs you access rather than a court date.

TLP 2.0 sharing ladder from most restrictive TLP:RED to least restrictive

Note: this graphic labels the least-restrictive tier "TLP:WHITE" and includes a "TLP:BLUE" tier. Under TLP 2.0 there are only four labels: TLP:RED, TLP:AMBER (with the optional AMBER+STRICT restriction), TLP:GREEN, and TLP:CLEAR. TLP:WHITE was retired in August 2022 and TLP:BLUE was never part of the FIRST standard at any version. Read the label definitions in the section above, not this graphic.

The Four Labels, Precisely

Here is what each label permits, in the terms the standard actually uses.

Label Recipient may share with Typical use
TLP:RED No one. Named individual recipients only Victim-identifying detail, live operational sensitivity
TLP:AMBER+STRICT Their organization only Sensitive detail where downstream clients must be excluded
TLP:AMBER Their organization and its clients, need-to-know Actionable intelligence that requires support to act on
TLP:GREEN Their community, but not publicly Awareness-raising across a sector or trust group
TLP:CLEAR Anyone, without restriction Publishable research, public advisories

TLP:RED means, in FIRST's phrasing, for the eyes and ears of individual recipients only, with no further disclosure. Not your team. Not your manager, unless your manager was in the room. In the context of a meeting, TLP:RED covers only the people present. Sources reach for it when information cannot be acted on without significant risk to the privacy, reputation, or operations of the organizations involved.

TLP:AMBER allows limited disclosure inside the recipient's organization and its clients, strictly on a need-to-know basis. That inclusion of clients is deliberate and is the detail people most often get wrong in the other direction: under TLP 2.0, clients are in scope by default, precisely so that a managed service provider or a national team can warn the people who need to protect themselves.

TLP:AMBER+STRICT is the answer when the source does not want that downstream hop. It restricts sharing to the organization only. Critically, FIRST does not treat this as a fifth label. The standard says the four TLP labels are RED, AMBER, GREEN, and CLEAR, and describes AMBER+STRICT as a restriction the source specifies on AMBER. In everyday practice analysts talk about five levels and everyone understands what is meant. But if you are writing policy, building a tool, or answering an exam question, the formal position is four labels with one modifier.

TLP:GREEN permits sharing across the recipient's community, defined as peers and partner organizations, but never through publicly accessible channels. Posting TLP:GREEN material to a public blog or an open social account is a violation, even though it feels harmless. FIRST adds a useful default: when "community" has not been defined, assume the cybersecurity and defense community.

TLP:CLEAR means the recipient can share it with the world. Standard copyright rules still apply, which is worth remembering before you paste someone's report wholesale into your own.

The Three Words That Cause Most Arguments

TLP disputes almost always come down to scope words, so the standard defines them.

A community is a group sharing common goals, practices, and informal trust relationships. It can be as broad as all cybersecurity practitioners in a country, sector, or region. Informal is the key word; membership is not administered.

An organization is a group sharing a common affiliation through formal membership and bound by common policies. It can stretch as far as all members of an information sharing organization, but FIRST notes it is rarely broader than that.

Clients are people or entities that receive cybersecurity services from an organization. For teams with a national responsibility, this definition also covers their stakeholders and constituents.

If you take one thing from this section: the difference between GREEN and AMBER is not sensitivity, it is structure. GREEN travels along informal trust relationships. AMBER travels along formal ones.

What Changed in TLP 2.0

If you learned TLP before 2022, three things moved.

TLP:WHITE became TLP:CLEAR. CISA explained the reasoning as improving both inclusivity and connotation, noting that most English speakers already understand the phrase "cleared for publication." The meaning did not change. The word did, and TLP:WHITE is now deprecated. Seeing it in a 2026 document is a reliable sign that either the document or its author's training is stale.

TLP:AMBER+STRICT arrived. Under TLP 1.0 there was no clean way to say "your organization but not your customers," so sources improvised with free-text caveats that recipients interpreted inconsistently. AMBER+STRICT closed that gap.

The definitions got sharper. TLP:RED in particular moved from the vaguer "restricted to participants only" to the much more pointed "for the eyes and ears of individual recipients only."

Adoption was not instant, and that is a useful lesson in itself. Even after CISA switched on 1 November 2022, its Automated Indicator Sharing capability did not move to TLP 2.0 until March 2023. Standards change on a date; ecosystems change over quarters.

How to Mark Things Correctly

The handling rules are short, and following them is most of what separates a professional product from an amateur one.

In email and chat, the label must appear directly before the information it applies to, and it should also be in the email subject line. Where it is not obvious where the marked content stops, say so explicitly.

In documents, the label must appear in the header and footer of every page. It should be 12-point type or larger, for readers with low vision, and FIRST recommends right-justifying it to avoid confusion with other control markings.

In writing generally, labels must not contain spaces and should be in capitals. "TLP: Amber" and "tlp amber" are both malformed; the correct form is TLP:AMBER. Labels must also stay in their original form in translated documents. You may translate the content of a report into Turkish, German, or Japanese, but the label itself stays TLP:AMBER.

In color, FIRST specifies exact values, and the reason is accessibility rather than branding. Each label is defined as colored text on a black background so that low-vision readers get sufficient contrast: TLP:RED is #FF2B2B, TLP:AMBER is #FFC000, TLP:GREEN is #33FF00, and TLP:CLEAR is #FFFFFF, each on #000000.

An email with TLP:AMBER in both the subject line and at the top of the message body

Figure 2: TLP in messaging. The label belongs in the subject line and again directly above the information it covers, so a forwarded fragment still carries its handling instruction.

The Machine-Readable Problem Nobody Warns You About

This is the section that will save you a debugging session, and it is missing from almost every other TLP explainer.

TLP was designed for humans. FIRST says so directly: TLP usage in automated information exchanges is not defined by the standard and is left to the designers of those exchanges. That handoff created a real and ongoing gap between TLP 2.0 on paper and TLP as implemented in tooling.

In STIX 2.1, TLP markings are represented as marking-definition objects, and the specification predefines them with fixed identifiers, stating that other instances of TLP marking definitions must not be used. The catch is that those predefined objects are the TLP 1.0 set: WHITE, GREEN, AMBER, and RED. TLP:CLEAR and TLP:AMBER+STRICT are not part of the core specification. OASIS addressed this with a separate TLP 2.0 extension definition rather than by changing the core objects.

The practical consequences are exactly what you would expect. MISP users have hit import failures where a bundle carrying TLP:CLEAR was rejected outright, and changing the label back to WHITE let the same bundle through. On the OpenCTI side, a connector issue opened in February 2026 documents STIX 2.1 export validation failing on entities marked TLP:AMBER+STRICT, with the root cause identified as exactly this: AMBER+STRICT is not in the STIX 2.1 core specification and has to be implemented through the extension mechanism instead. A request to update the Python STIX2 library's built-in markings to match current CISA guidance has been open since January 2024.

Two working rules follow from this. First, when you exchange machine-readable intelligence, confirm what your counterpart's platform actually supports before you rely on the newest labels, because a marking that silently fails to import is worse than no marking. Second, remember the precedence rule that STIX inherited and platforms implement: when an object carries multiple TLP markings, treat it as the most restrictive one. An item marked both GREEN and AMBER is AMBER.

The MISP tagging interface showing the TLP taxonomy dropdown with tlp:amber selected

Figure 3: TLP inside a sharing platform. This MISP instance's taxonomy dropdown still lists the TLP 1.0 tag set (white, green, amber, red) rather than TLP 2.0's clear and amber+strict, a live example of the machine-readable gap described above.

The Mistakes Analysts Actually Make

Seven failure modes account for nearly all real-world TLP problems.

Over-marking is the big one. Defaulting everything to AMBER or RED feels prudent and is actively harmful, because it defeats the entire purpose of a protocol built to increase sharing. Intelligence that nobody is allowed to act on protects nobody. Before you reach for a restrictive label, ask what specific harm the wider label would cause. If you cannot name one, mark it lower.

Inventing labels. TLP:BLACK, TLP:ORANGE, and TLP:PURPLE do not exist. FIRST is unambiguous that only the labels in the standard are valid. If you need something the standard does not express, the correct move is to add an explicit written restriction alongside a valid label, which the standard permits and which recipients are obliged to follow.

Still using TLP:WHITE. It was deprecated in August 2022.

Malformed labels. Spaces, lowercase, and translated labels all break machine parsing and signal carelessness to human readers.

Marking only the cover page. The standard says header and footer of each page, and there is a good operational reason: pages get screenshotted, printed, and pasted into other documents, and a page that has drifted from its cover needs to carry its own instruction.

Relabeling on the way through. If you need to share more widely than your label allows, you must obtain explicit permission from the source. You do not get to promote TLP:AMBER to TLP:GREEN because you judged it harmless. The source, not the recipient, owns the restriction.

Using TLP:GREEN without a defined community. If your audience does not know where the boundary is, they will draw it themselves, usually generously.

Where TLP Fits in the Intelligence Cycle

TLP is a dissemination control, and that is the most useful way to hold it in your head. Everything upstream in the threat intelligence lifecycle, the requirements, the collection, the analysis, produces a finished report. TLP is the decision you make at the moment that product leaves your hands about how far it is allowed to travel.

Getting that decision right is a genuine analyst skill, not an administrative afterthought. Every choice sits between two failure modes: mark too tightly and the intelligence dies in an inbox, mark too loosely and you damage a source, a victim, or your own team's standing. It is also one of the first things a receiving organization notices about your work. A cleanly and correctly marked product signals that you understand the community you are operating in. A sloppily marked one signals the opposite before anyone has read your analysis.

This is exactly the kind of judgment CTI Academy's Hunter track builds through practice rather than memorization. In the SOC Simulator you sit on the receiving end of intelligence products and see firsthand how handling instructions shape what a defender can actually do with what they are given, which is the perspective that makes marking decisions obvious rather than arbitrary. If you want to build that instinct alongside the rest of the analyst toolkit, start with the Hunter track.

Frequently Asked Questions

What is the Traffic Light Protocol in cyber security?

The Traffic Light Protocol (TLP) is a set of four labels that tell recipients how widely they may share information they have received. The labels are TLP:RED, TLP:AMBER, TLP:GREEN, and TLP:CLEAR, ranging from no onward sharing to unrestricted public release. It is maintained by FIRST and used across incident response, threat intelligence, and vulnerability disclosure.

How many TLP labels are there, four or five?

FIRST's TLP 2.0 standard defines four labels: TLP:RED, TLP:AMBER, TLP:GREEN, and TLP:CLEAR. TLP:AMBER+STRICT is a restriction that a source applies to TLP:AMBER to limit sharing to the recipient's organization only, not a separate fifth label. In everyday conversation analysts often describe five levels, which is understood but not formally correct.

What replaced TLP:WHITE?

TLP:CLEAR replaced TLP:WHITE in TLP 2.0, published in August 2022. The meaning is unchanged, meaning unlimited disclosure subject to standard copyright. CISA described the change as improving inclusivity and connotation, since "cleared for publication" is widely understood. TLP:WHITE is deprecated and should not appear in current documents.

What is the difference between TLP:AMBER and TLP:AMBER+STRICT?

TLP:AMBER lets recipients share within their own organization and with its clients, on a need-to-know basis. TLP:AMBER+STRICT removes the clients, restricting sharing to the organization only. If a source wants that tighter boundary, the standard requires them to specify TLP:AMBER+STRICT explicitly.

Is the Traffic Light Protocol legally binding?

No. CISA states that, unlike formal classification systems, TLP is not legally binding, and FIRST notes that TLP is not a formal classification scheme and has no effect on freedom of information laws. It works on community trust and reciprocity, so the practical penalty for violating it is losing access to sharing relationships.

How should TLP labels be formatted in documents and email?

In documents, the label goes in the header and footer of every page, in 12-point type or larger, ideally right-justified. In email and chat, it goes in the subject line and directly before the information it covers. Labels must not contain spaces, should be capitalized, and must stay in their original English form even when the content is translated.

Can I share TLP:AMBER information with my clients?

Yes, on a need-to-know basis, unless the source marked it TLP:AMBER+STRICT. Under TLP 2.0 clients are included in TLP:AMBER by default, specifically so recipients can pass warnings downstream to the people who need to protect themselves. For teams with national responsibility, this also covers stakeholders and constituents.

Does TLP work in automated systems like MISP and STIX?

Partly. FIRST leaves automated exchange to the designers of those systems. STIX 2.1's built-in TLP marking definitions still reflect the older label set, so TLP:CLEAR and TLP:AMBER+STRICT require an OASIS extension and can fail validation in some tooling. Confirm what your counterpart's platform supports before relying on the newer labels.

Sources

Read more at CTI Academy Blog