It applies to projects where the information itself could be a security risk if it leaked - critical infrastructure, defense sites, high-profile buildings - requiring a documented sensitivity assessment before deciding how openly a CDE can actually be shared.