DoD 5015.02 Records Management for Federal Contractors
DoD 5015.02-STD was the Defense Department's design-criteria standard for electronic records management software, but it was cancelled on July 2, 2025 and superseded by DoD Manual 8180.01, with the JITC certification program terminated. Federal contractors' binding obligations now flow from NARA federal-records rules, CUI safeguarding under NIST SP 800-171's 110 controls, and CMMC.
DoD 5015.02-STD — the Department of Defense's Design Criteria Standard for Electronic Records Management Software Applications — spent more than two decades as the de facto benchmark for records management software across the federal government. For federal contractors, "DoD 5015.02 compliance" became shorthand for a records system rigorous enough to survive a government review. The most important fact a compliance officer needs in 2026, however, is that the standard itself has changed status: as of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, and the Joint Interoperability Test Command (JITC) program that certified products against it was terminated.
The cancellation does not mean records-management obligations have eased. It means the locus of compliance has shifted from a single software certification to the broader regulatory stack that governs how contractors create, protect, retain, and dispose of federal information. Three regimes now do the work the 5015.02 label once signaled: the Federal Records Act and NARA's records rules, which require that every federal record — including those a contractor maintains for the government — be covered by a NARA-approved disposition authority; the Controlled Unclassified Information program and its security baseline, NIST SP 800-171, with 110 security requirements enforced through DFARS clause 252.204-7012; and the Cybersecurity Maturity Model Certification (CMMC) program, which verifies that those safeguards are actually in place.
This guide explains what DoD 5015.02-STD required and why it mattered, what its 2025 cancellation changes, and how the CUI, NIST SP 800-171, and CMMC requirements fit together for a defense contractor. It then walks through building a contractor records-management program, a worked compliance scenario, retention and disposition of federal records, audit and enforcement, and the failures that most often trip organizations up. Reynolds Business Systems, a records and document-management firm based in Emmaus, Pennsylvania, works with these requirements across the Lehigh Valley and the Mid-Atlantic, and the Pennsylvania context appears throughout.
What DoD 5015.02-STD is — and what changed in July 2025
DoD 5015.02-STD is a design-criteria standard: a set of minimum functional requirements that records management software must meet, rather than a procedure for running a records program. The Department of Defense first released it as DOD 5015.2-STD in November 1997, establishing baseline criteria that records management applications had to satisfy to be considered fit for federal use. DoD revised the standard in June 2002 to add requirements for classified records — including classified markings, access control, declassification, and downgrading — reflecting the realities of managing national-security information.
The version most organizations still reference, DoD 5015.02-STD, was signed on April 25, 2007. Policy and responsibilities for the broader DoD records program sit in a companion document, DoD Instruction 5015.02, "DoD Records Management Program," issued February 24, 2015 (Incorporating Change 1) — the instruction sets policy, while the standard set the software design criteria. Critically, the standard defines minimum functional requirements specifying the design criteria needed to identify, mark, store, and dispose of electronic records; it does not dictate how a given product delivers those capabilities or how an agency operates its records program. That distinction is why two very different products could both be called "5015.02 compliant."
What changed in 2025 is decisive. As of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, "Information Technology Planning for Electronic Records Management." In the same move, the JITC Records Management test program — the body that certified records management applications against 5015.02-STD — was terminated, a step that invalidated current support agreements with JITC's records-management customers. Contractors that built procurement language or marketing around "JITC-certified, 5015.02-compliant" software now reference a standard DoD has retired.
| Date | Milestone | What it established |
|---|---|---|
| November 1997 | DOD 5015.2-STD released | First design-criteria standard for electronic records management software |
| June 2002 | Standard revised | Added classified-records requirements: markings, access control, declassification, downgrading |
| April 25, 2007 | DoD 5015.02-STD signed | The version most organizations still cite as the design criteria |
| February 24, 2015 | DoD Instruction 5015.02 issued (Change 1) | DoD Records Management Program policy and responsibilities |
| July 2, 2025 | 5015.02-STD cancelled; JITC RM program terminated | Superseded by DoD Manual 8180.01; certification testing ends |
What the standard required: the design criteria in depth
At its core, DoD 5015.02-STD answered a single question: can this software manage an electronic record through its full lifecycle in a way the government can trust? The standard expressed that as four functional capabilities — the ability to identify, mark, store, and dispose of electronic records — and built its requirements around them. "Identify" covers capturing a document as a record and binding it to metadata; "mark" covers categorizing and labeling it, including security and access markings; "store" covers keeping the record and its metadata intact and retrievable; and "dispose" covers executing retention and destruction or transfer under an approved schedule.
The standard was layered. A baseline set of requirements applied to any records management application, establishing the file-plan structure, record categorization, metadata capture, and disposition processing that every compliant product had to support. Above that baseline sat additional requirement sets for specialized contexts — most notably the management of classified national-security information added in the 2002 revision, which required records software to handle classified markings, enforce access control, and support declassification and downgrading. Further requirements addressed Freedom of Information Act and Privacy Act material and the transfer of permanent records to the National Archives — the points where a records system meets the public and the permanent archive.
Because the standard set design criteria rather than operating procedures, certification confirmed that a product could do these things — not that a contractor was doing them correctly. A 5015.02-compliant repository configured with the wrong file plan, incomplete metadata, or no approved retention schedule was still non-compliant in practice. This gap between certified capability and disciplined operation is the most important thing to understand about the standard, and it explains why its 2025 cancellation changes less than it first appears: the operational obligations never lived in the certification.
| Capability | What the software had to do | Records-program equivalent |
|---|---|---|
| Identify | Capture a document as an official record and bind it to descriptive metadata | Declaring a record and filing it to a category |
| Mark | Categorize and label records, including security and access markings | Applying the file plan and access controls |
| Store | Keep records and their metadata authentic, intact, and retrievable for the full retention period | Maintaining the recordkeeping system |
| Dispose | Execute retention, then destroy or transfer records under an approved schedule | Defensible disposition and archival transfer |
Cyber-maturity for contractors
CMMC requirements by level
JITC certification: what it meant and why it ended
For most of the standard's life, compliance with DoD 5015.02-STD was demonstrated through testing by the Joint Interoperability Test Command (JITC), a component of the Defense Information Systems Agency (DISA). JITC's Records Management Application test program evaluated commercial records software against the standard's functional requirements and maintained a register of products that passed. For a contractor or agency buying records software, that register was a procurement shortcut: choosing a JITC-certified product was a defensible way to satisfy a "5015.02-compliant" requirement without independently testing the software.
That mechanism no longer exists. With the cancellation of DoD 5015.02-STD on July 2, 2025, the JITC Records Management test program was terminated, and JITC's notice made clear the move invalidated current support agreements with its records-management customers. There is no active DoD program issuing new 5015.02 certifications, and the existing register reflects a standard DoD has retired. Going forward, electronic records management planning falls under DoD Manual 8180.01, and the burden of evaluating records software shifts back to the buyer.
Stop treating "JITC-certified" as a current, dispositive credential. A product's prior 5015.02 certification remains useful evidence that it was built to handle records-lifecycle functions rigorously, but as of July 2, 2025 it is no longer a substitute for demonstrating compliance with the regimes that still bind contractors — federal-records retention, CUI protection, and the security controls verified under CMMC.
The compliance stack that still binds federal contractors
With the single-certification model retired, a defense contractor's records obligations are best understood as a stack of three overlapping regimes. Each governs a different dimension of the same records, and a compliant program has to satisfy all three at once.
| Regime | What it governs | Key authority | Core obligation |
|---|---|---|---|
| Federal records (NARA / FRA) | Retention and disposition of federal records | 36 CFR Part 1225; Federal Records Act | Every federal record covered by a NARA-approved disposition authority |
| CUI protection (NIST SP 800-171) | Safeguarding Controlled Unclassified Information | EO 13556; 32 CFR Part 2002; DFARS 252.204-7012 | Implement the 110 NIST SP 800-171 security requirements |
| CMMC | Verifying that safeguards are in place | 32 CFR Part 170 | Achieve the CMMC level the contract requires |
The regimes interlock. NARA rules decide how long a contractor must keep a federal record and when it may be destroyed; the CUI and NIST SP 800-171 rules decide how that record must be protected while it is kept; and CMMC decides how the contractor proves the protection is real. A records-management program that addresses retention but ignores CUI safeguarding — or implements security controls but never establishes disposition authority — is incomplete regardless of what software it runs on.
CUI and NIST SP 800-171: the 110 controls
Controlled Unclassified Information is the category of unclassified information that nonetheless requires safeguarding — covering everything from technical drawings and specifications to certain personnel and procurement data. The CUI Program was established by Executive Order 13556 to standardize how the executive branch handles such information, replacing a patchwork of agency-specific markings, and it is codified at 32 CFR Part 2002, which sets policy for designating, handling, and decontrolling CUI. For a defense contractor, the moment a contract involves CUI, a specific security baseline attaches.
That baseline is NIST Special Publication 800-171. Defense contractors handling CUI must implement the 110 security requirements in NIST SP 800-171 Revision 2, an obligation imposed through DFARS clause 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting." The 110 requirements are organized into 14 control families that span the practical surface of information security — from access control and audit and accountability to incident response and system and information integrity.
DFARS 252.204-7012 adds operational duties beyond the controls themselves. A contractor must rapidly report cyber incidents to DoD within 72 hours of discovery, and must preserve and protect images of all known affected information systems for at least 90 days from submission of the incident report, so the government can investigate. The clause also flows down: it must be included in subcontracts for operationally critical support or that involve covered defense information, extending the same CUI-safeguarding and incident-reporting obligations to subcontractors. A prime contractor cannot satisfy DFARS 7012 while its subcontractors handle the same CUI unprotected.
One point causes recurring confusion. NIST withdrew SP 800-171 Revision 2 on May 14, 2024 and replaced it with Revision 3, yet DoD's CMMC program and DFARS 252.204-7012 continue to reference the 110 requirements of Revision 2. For now, contractors meet their DoD obligations against Revision 2's 110 requirements even though Revision 3 is the current NIST publication — a transition contractors should track but not get ahead of.
| Control family | What it covers |
|---|---|
| Access Control | Limiting system access to authorized users and processes |
| Awareness and Training | Ensuring staff understand security risks and their duties |
| Audit and Accountability | Creating and protecting logs to trace user actions |
| Configuration Management | Establishing and maintaining secure baseline configurations |
| Identification and Authentication | Verifying the identity of users and devices |
| Incident Response | Detecting, reporting, and responding to incidents |
| Maintenance | Performing system maintenance securely |
| Media Protection | Protecting and sanitizing media that holds CUI |
| Personnel Security | Screening personnel and protecting CUI during personnel actions |
| Physical Protection | Limiting physical access to systems and facilities |
| Risk Assessment | Assessing and managing risk to operations and assets |
| Security Assessment | Evaluating and improving the effectiveness of controls |
| System and Communications Protection | Protecting information in transit and at system boundaries |
| System and Information Integrity | Identifying and correcting flaws and guarding against malicious code |
CMMC: the three certification levels
Implementing the 110 controls is one thing; proving it is another. That is the role of the Cybersecurity Maturity Model Certification (CMMC) Program, governed by 32 CFR Part 170, whose final rule was published October 15, 2024. CMMC verifies that a contractor's safeguards match the sensitivity of the information it handles, and it provides assessments at three progressive levels keyed to whether the contract involves Federal Contract Information (FCI) or CUI.
Level 1, Basic Safeguarding of FCI, requires an annual self-assessment and affirmation against the 15 security requirements in FAR clause 52.204-21. Level 2, Broad Protection of CUI, requires compliance with the 110 NIST SP 800-171 Revision 2 requirements, verified either by self-assessment or by an independent assessment from a CMMC Third-Party Assessment Organization (C3PAO) every three years. Level 3, aimed at protection against advanced persistent threats, adds 24 requirements drawn from NIST SP 800-172 and requires an assessment by the Defense Contract Management Agency's DIBCAC every three years. The level a contractor must hold is set by the contract, not chosen by the contractor.
Two timing rules matter. First, a CMMC status is valid for three years from the CMMC Status Date, making Level 2 and Level 3 assessments a triennial obligation. Second, Plans of Action and Milestones (POA&Ms) — used to close limited, lower-weight gaps after an assessment — are permitted only for certain requirements and must be closed out within 180 days of the Conditional CMMC Status Date. The program is rolling out in phases: Phase 1 began November 10, 2025, initially emphasizing Level 1 and Level 2 self-assessments, with full implementation phased in over three years.
| Level | Protects | Requirements | Assessment | Cadence |
|---|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements (FAR 52.204-21) | Self-assessment and affirmation | Annual |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements (NIST SP 800-171 Rev 2) | Self-assessment or C3PAO assessment | Every 3 years |
| Level 3 | CUI against advanced persistent threats | Level 2 plus 24 requirements (NIST SP 800-172) | DCMA DIBCAC assessment | Every 3 years |
Building a contractor records-management compliance program
With the certification shortcut gone, a defensible contractor records program is built deliberately, step by step. The sequence below moves from inventory to operations and folds the three regimes together so that retention, protection, and proof reinforce one another.
- Inventory the records and data flows. Identify every category of federal record and every system that creates, receives, or stores Controlled Unclassified Information, and map where CUI enters from contracts and where it flows to subcontractors.
- Determine the CMMC level the contract requires. Confirm whether the work involves FCI (pointing to Level 1) or CUI (Level 2, or Level 3 for the most sensitive programs), since the level dictates the controls and the assessment path.
- Establish NARA-approved disposition authority. Ensure every federal record the contractor creates or maintains for the government is covered by a NARA-approved retention authority, as 36 CFR Part 1225 requires — without it, the records have no lawful disposition path.
- Implement the 110 NIST SP 800-171 controls. Work through all 14 control families, close gaps, and document each control's implementation in a System Security Plan (SSP) — the SSP is the backbone an assessor reads first.
- Stand up incident response to the DFARS clock. Build the capability to detect, report to DoD within 72 hours of discovery, and preserve affected system images for at least 90 days, and rehearse it before an incident occurs.
- Flow obligations down to subcontractors. Include DFARS 252.204-7012 in subcontracts involving covered defense information or operationally critical support, and verify subcontractor compliance rather than assuming it.
- Move permanent and long-term records to compliant electronic formats. Align with the federal direction set by OMB Memorandum M-23-07, which required agencies to manage permanent records electronically with appropriate metadata by June 30, 2024 — a standard that reaches contractors creating federal records.
- Document, self-assess, and prepare for CMMC. Score the implementation, record eligible gaps in POA&Ms (closeable within 180 days), and schedule the self-assessment or C3PAO assessment the contract's level requires.
- Operate on a calendar, not from memory. Run retention and disposition on schedule, refresh the assessment every three years, and keep evidence current so the program is continuously, not episodically, compliant.
Worked example: a Lehigh Valley defense subcontractor
Consider a hypothetical machine shop in the Lehigh Valley that wins a subcontract to manufacture parts from DoD technical drawings. The drawings are CUI. The figures below combine the cited requirements with clearly illustrative inputs to show how the obligations stack up in practice.
Because the subcontract involves CUI, the shop needs CMMC Level 2 — compliance with all 110 NIST SP 800-171 Revision 2 requirements across 14 control families, verified by self-assessment or a C3PAO every three years. Suppose a self-assessment finds 102 of 110 requirements fully met (an illustrative figure); the eight remaining eligible gaps go into a POA&M that must be closed within 180 days of the Conditional CMMC Status Date. The prime flowed DFARS 252.204-7012 down, so the shop must also be able to report a cyber incident to DoD within 72 hours and preserve affected system images for at least 90 days. Separately, any drawings that qualify as federal records must fall under a NARA-approved disposition authority. None of this depends on a 5015.02 certification — the standard's cancellation on July 2, 2025 leaves every one of these duties intact.
The example illustrates the central shift: the contractor's compliance is now measured by the controls it implements, the records authority it establishes, and the assessment it passes — not by a logo on its software.
Retention and disposition of federal records
Records management for a contractor is not only about security; it is about lawful retention and disposition. Under 36 CFR Part 1225, all federal records — including those created or maintained for the government by a contractor — must be covered by a NARA-approved agency disposition (retention) authority. A records schedule is the legal instrument that authorizes how long each record is kept and what happens at the end of its life, whether destruction or transfer to the National Archives. A contractor holding federal records without a corresponding approved authority has no lawful basis to destroy them and no defensible basis to keep them indefinitely.
Format obligations are tightening in parallel. Under OMB Memorandum M-23-07, federal agencies were required to manage all permanent records in an electronic format with appropriate metadata by June 30, 2024 — and that expectation flows to contractors who create federal records on the government's behalf. The practical implication is that paper-based recordkeeping for permanent or long-lived federal records is increasingly untenable: the government partner needs electronic records with sound metadata, captured and maintained to a standard that supports eventual archival transfer.
Defensible disposition is the discipline that ties this together. A contractor should destroy a federal record only when its approved schedule allows, no litigation or investigation hold applies, and the disposition is documented. The ability to show — after the fact — that every disposition followed an approved authority is what separates a defensible program from an exposed one.
A litigation, audit, or investigation hold suspends the retention schedule. Once a federal record becomes relevant to a pending or anticipated matter, its scheduled destruction date is paused until the hold is released — even if the retention period has otherwise expired.
Audit, assessment, and enforcement
Compliance in this domain is actively assessed, not merely asserted. Through DFARS clause 252.204-7020, contractors must provide DoD access to their facilities, systems, and personnel for NIST SP 800-171 assessments and must maintain a current assessment of their implementation in the government's Supplier Performance Risk System. CMMC formalizes that scrutiny: Level 1 relies on annual self-assessment and affirmation against 15 requirements, while Level 2 and Level 3 require verification — by a C3PAO at Level 2 or DCMA's DIBCAC at Level 3 — every three years.
The consequences of getting it wrong are real even where this guide cites no dollar figures. A contractor that cannot demonstrate compliance can lose the ability to bid or continue on contracts requiring a given CMMC level, since the level becomes a condition of award. Misrepresenting compliance carries additional exposure: false statements about the implementation of required controls have drawn enforcement attention under federal false-claims authorities. The affirmations a senior official signs for CMMC are therefore not a formality — they are attestations the government can act on.
The cancellation of DoD 5015.02-STD and the end of JITC certification do nothing to soften this enforcement posture. If anything, they concentrate attention on the regimes that are actively assessed — NIST SP 800-171, CMMC, and NARA disposition — rather than on a one-time software certification. A contractor preparing for an assessment should assume its System Security Plan, its POA&M closure within 180 days, its incident-response evidence, and its disposition authorities will all be examined.
Where organizations get this wrong
The failures in this area are predictable, and most stem from treating records management as a software question rather than a program question.
- Assuming a 5015.02 certification still settles the matter. The standard was cancelled on July 2, 2025 and JITC's certification program was terminated; relying on that credential as current compliance is the most common 2026 mistake.
- Confusing NIST SP 800-171 revisions. DoD still requires the 110 requirements of Revision 2 even though NIST withdrew Revision 2 on May 14, 2024 in favor of Revision 3 — implementing the wrong revision wastes effort and can create gaps.
- Missing the 72-hour incident-reporting clock. DFARS 252.204-7012 requires reporting within 72 hours of discovery; organizations without a rehearsed process routinely blow the deadline during a real incident.
- Letting POA&Ms lapse. At CMMC Levels 2 and 3, eligible gaps must be closed within 180 days of the Conditional CMMC Status Date; an unclosed POA&M can cost the certification.
- Skipping flowdown. Failing to include DFARS 252.204-7012 in subcontracts involving covered defense information leaves CUI unprotected downstream and the prime exposed.
- Holding federal records without disposition authority. Under 36 CFR Part 1225, every federal record needs a NARA-approved retention authority; contractors that never establish one cannot dispose of records defensibly.
- Treating compliance as a one-time event. A CMMC status lasts three years and records run on continuous schedules; programs that lapse between assessments drift out of compliance.
Choosing records software after JITC — and the Lehigh Valley context
With no active program issuing 5015.02 certifications, contractors evaluate records software on its own merits against the obligations that remain. The useful questions are functional and operational: does the system manage records through identify, mark, store, and dispose with reliable metadata; does it support NARA-approved retention schedules and defensible, documented disposition; does it run inside an environment that can meet the relevant NIST SP 800-171 controls and the CMMC level the contract demands; and can it produce the evidence an assessor will ask for? A product's prior 5015.02 lineage is a reasonable signal of records-management rigor, but it is the answers to those questions — not a retired certification — that determine fitness.
Reynolds Business Systems is a family-owned records and document-management firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the broader Mid-Atlantic for more than 55 years. Defense contractors and their suppliers across the region face the same shift this guide describes: a long-relied-upon certification has been retired, while the underlying duties to retain, protect, and dispose of federal information have not. The operational work — digitizing records to compliant electronic formats with sound metadata, organizing retention so disposition is defensible, and structuring records so a CMMC or NARA review goes smoothly — is exactly where a records partner adds value. The regulations are set by NARA, NIST, and the Department of Defense; the role of a records partner is to make meeting them dependable and auditable.
Frequently asked questions
Is DoD 5015.02-STD still active?
No. As of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, "Information Technology Planning for Electronic Records Management." The JITC program that certified products against the standard was terminated at the same time, invalidating existing JITC records-management support agreements.
What replaced DoD 5015.02-STD?
DoD Manual 8180.01, "Information Technology Planning for Electronic Records Management," superseded the standard when it was cancelled on July 2, 2025. For contractors, the practical successors are the regimes that were always doing the underlying work: NARA's federal-records rules, NIST SP 800-171 for CUI, and CMMC.
What is JITC certification for records management?
JITC — the Joint Interoperability Test Command, part of DISA — ran the test program that evaluated records management software against DoD 5015.02-STD and maintained a register of compliant products. That test program was terminated when the standard was cancelled on July 2, 2025, so no active DoD program currently issues 5015.02 certifications.
How many controls are in NIST SP 800-171?
NIST SP 800-171 Revision 2 contains 110 security requirements, organized into 14 control families. Defense contractors handling Controlled Unclassified Information must implement all 110 under DFARS clause 252.204-7012. NIST withdrew Revision 2 on May 14, 2024 in favor of Revision 3, but DoD continues to reference Revision 2's 110 requirements.
What are the CMMC levels for defense contractors?
CMMC has three levels. Level 1 requires a self-assessment against 15 FAR 52.204-21 requirements for Federal Contract Information. Level 2 requires the 110 NIST SP 800-171 Revision 2 requirements for CUI, verified by self-assessment or a C3PAO every three years. Level 3 adds 24 NIST SP 800-172 requirements, assessed by DCMA's DIBCAC.
What is the federal law for records management?
The Federal Records Act (codified across 44 U.S.C. Chapters 21, 29, 31, and 33) is the foundational federal records-management law. It works alongside NARA's implementing regulations — for retention and disposition, 36 CFR Part 1225 requires that every federal record, including records a contractor maintains for the government, be covered by a NARA-approved disposition authority.
What is the DoD records management strategy?
DoD sets records-management policy and responsibilities through DoD Instruction 5015.02, "DoD Records Management Program" (issued February 24, 2015, Incorporating Change 1), and, since July 2025, governs electronic-records IT planning through DoD Manual 8180.01. The thrust is consistent with the federal-wide move toward electronic recordkeeping with sound metadata and approved retention schedules.
What are the four types of record management?
There is no single official "four types" under DoD policy. Records management is usually described by the lifecycle stages a record passes through — creation or capture, maintenance and use, storage, and disposition (destruction or archival transfer). DoD 5015.02-STD framed software requirements around four functional capabilities that mirror this lifecycle: identify, mark, store, and dispose of electronic records.
What are the 8 principles of records management?
The most widely cited set is ARMA International's Generally Accepted Recordkeeping Principles: accountability, transparency, integrity, protection, compliance, availability, retention, and disposition. These are an industry framework rather than a DoD or NARA mandate, but they map cleanly onto the federal obligations a contractor must meet — particularly protection, retention, and disposition.
What are the 5 S's of records management?
The "5 S's" — Sort, Set in order, Shine, Standardize, and Sustain — come from the Lean workplace-organization method and are sometimes applied to physical recordkeeping to reduce clutter and standardize filing. They are an operational housekeeping practice, not a compliance standard; for federal records, the controlling requirements are NARA retention schedules, CUI safeguarding under NIST SP 800-171, and CMMC.
Do federal contractors have to follow the Federal Records Act and NARA rules?
Yes, for federal records they create or maintain on the government's behalf. Under 36 CFR Part 1225, those records must be covered by a NARA-approved disposition authority, and under OMB Memorandum M-23-07 the federal expectation — managing permanent records electronically with appropriate metadata by June 30, 2024 — flows to contractors creating such records.
What is Controlled Unclassified Information (CUI)?
CUI is unclassified information that still requires safeguarding, such as technical drawings, specifications, and certain personnel or procurement data. The CUI Program was established by Executive Order 13556 and is codified at 32 CFR Part 2002. When a defense contract involves CUI, the NIST SP 800-171 security baseline and DFARS clause 252.204-7012 attach.
Sources Cited
24 REFS- U.S. DoD Joint Interoperability Test Command (JITC), DISA
- U.S. National Archives and Records Administration (NARA)
- U.S. Department of Defense, Office of the CIO / Washington Headquarters Services Executive Services Directorate
- U.S. Department of Defense (DoD 5015.02-STD, hosted copy via IRMS)
- U.S. Department of Defense, Office of the Chief Information Officer (DoD CIO)
- U.S. Department of Defense via Federal Register
- Electronic Code of Federal Regulations (U.S. DoD)
- U.S. Defense Federal Acquisition Regulation Supplement (Acquisition.gov)
- U.S. Defense Federal Acquisition Regulation Supplement (Acquisition.gov)
- U.S. National Institute of Standards and Technology (NIST)
- U.S. National Institute of Standards and Technology (NIST)
- Holland & Knight LLP
- U.S. National Archives and Records Administration (NARA)
- Electronic Code of Federal Regulations (NARA)
- U.S. Center for Development of Security Excellence (CDSE), DCSA
- Electronic Code of Federal Regulations (NARA)
- U.S. National Archives and Records Administration (NARA)
- Congressional Research Service (Congress.gov)
- U.S. Office of Management and Budget & National Archives and Records Administration
- ZL Technologies (ZL Tech)




