
A definitive guide to DoD 5015.02-STD records management for federal contractors: the standard's design criteria, its July 2025 cancellation and the end of JITC certification, and the regimes that now bind contractors — NARA federal records, CUI under NIST SP 800-171's 110 controls, and CMMC.
Guide briefing
DoD 5015.02-STD was the Defense Department's design-criteria standard for electronic records management software, but it was cancelled on July 2, 2025 and superseded by DoD Manual 8180.01, with the JITC certification program terminated. Federal contractors' binding obligations now flow from NARA federal-records rules, CUI safeguarding under NIST SP 800-171's 110 controls, and CMMC.
More from the Records Management category.
Next step
Share the framework, records condition, workflow, capacity issue, or implementation risk. Reynolds routes it to the discipline that owns the work — from Emmaus, with same-day response.
Need help applying this guide?
Talk to a specialistDoD 5015.02-STD — the Department of Defense's Design Criteria Standard for Electronic Records Management Software Applications — spent more than two decades as the de facto benchmark for records management software across the federal government. For federal contractors, "DoD 5015.02 compliance" became shorthand for a records system rigorous enough to survive a government review. The most important fact a compliance officer needs in 2026, however, is that the standard itself has changed status: as of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, and the Joint Interoperability Test Command (JITC) program that certified products against it was terminated.
The cancellation does not mean records-management obligations have eased. It means the locus of compliance has shifted from a single software certification to the broader regulatory stack that governs how contractors create, protect, retain, and dispose of federal information. Three regimes now do the work the 5015.02 label once signaled: the Federal Records Act and NARA's records rules, which require that every federal record — including those a contractor maintains for the government — be covered by a NARA-approved disposition authority; the Controlled Unclassified Information program and its security baseline, NIST SP 800-171, with 110 security requirements enforced through DFARS clause 252.204-7012; and the Cybersecurity Maturity Model Certification (CMMC) program, which verifies that those safeguards are actually in place.
This guide explains what DoD 5015.02-STD required and why it mattered, what its 2025 cancellation changes, and how the CUI, NIST SP 800-171, and CMMC requirements fit together for a defense contractor. It then walks through building a contractor records-management program, a worked compliance scenario, retention and disposition of federal records, audit and enforcement, and the failures that most often trip organizations up. Reynolds Business Systems, a records and document-management firm based in Emmaus, Pennsylvania, works with these requirements across the Lehigh Valley and the Mid-Atlantic, and the Pennsylvania context appears throughout.
DoD 5015.02-STD is a design-criteria standard: a set of minimum functional requirements that records management software must meet, rather than a procedure for running a records program. The Department of Defense first released it as DOD 5015.2-STD in November 1997, establishing baseline criteria that records management applications had to satisfy to be considered fit for federal use. DoD revised the standard in June 2002 to add requirements for classified records — including classified markings, access control, declassification, and downgrading — reflecting the realities of managing national-security information.
The version most organizations still reference, DoD 5015.02-STD, was signed on April 25, 2007. Policy and responsibilities for the broader DoD records program sit in a companion document, DoD Instruction 5015.02, "DoD Records Management Program," issued February 24, 2015 (Incorporating Change 1) — the instruction sets policy, while the standard set the software design criteria. Critically, the standard defines minimum functional requirements specifying the design criteria needed to identify, mark, store, and dispose of electronic records; it does not dictate how a given product delivers those capabilities or how an agency operates its records program. That distinction is why two very different products could both be called "5015.02 compliant."
What changed in 2025 is decisive. As of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, "Information Technology Planning for Electronic Records Management." In the same move, the JITC Records Management test program — the body that certified records management applications against 5015.02-STD — was terminated, a step that invalidated current support agreements with JITC's records-management customers. Contractors that built procurement language or marketing around "JITC-certified, 5015.02-compliant" software now reference a standard DoD has retired.
| Date | Milestone | What it established |
|---|---|---|
| November 1997 | DOD 5015.2-STD released | First design-criteria standard for electronic records management software |
| June 2002 | Standard revised | Added classified-records requirements: markings, access control, declassification, downgrading |
| April 25, 2007 | DoD 5015.02-STD signed | The version most organizations still cite as the design criteria |
| February 24, 2015 | DoD Instruction 5015.02 issued (Change 1) | DoD Records Management Program policy and responsibilities |
| July 2, 2025 | 5015.02-STD cancelled; JITC RM program terminated | Superseded by DoD Manual 8180.01; certification testing ends |
At its core, DoD 5015.02-STD answered a single question: can this software manage an electronic record through its full lifecycle in a way the government can trust? The standard expressed that as four functional capabilities — the ability to identify, mark, store, and dispose of electronic records — and built its requirements around them. "Identify" covers capturing a document as a record and binding it to metadata; "mark" covers categorizing and labeling it, including security and access markings; "store" covers keeping the record and its metadata intact and retrievable; and "dispose" covers executing retention and destruction or transfer under an approved schedule.
The standard was layered. A baseline set of requirements applied to any records management application, establishing the file-plan structure, record categorization, metadata capture, and disposition processing that every compliant product had to support. Above that baseline sat additional requirement sets for specialized contexts — most notably the management of classified national-security information added in the 2002 revision, which required records software to handle classified markings, enforce access control, and support declassification and downgrading. Further requirements addressed Freedom of Information Act and Privacy Act material and the transfer of permanent records to the National Archives — the points where a records system meets the public and the permanent archive.
Because the standard set design criteria rather than operating procedures, certification confirmed that a product could do these things — not that a contractor was doing them correctly. A 5015.02-compliant repository configured with the wrong file plan, incomplete metadata, or no approved retention schedule was still non-compliant in practice. This gap between certified capability and disciplined operation is the most important thing to understand about the standard, and it explains why its 2025 cancellation changes less than it first appears: the operational obligations never lived in the certification.
| Capability | What the software had to do | Records-program equivalent |
|---|---|---|
| Identify | Capture a document as an official record and bind it to descriptive metadata | Declaring a record and filing it to a category |
| Mark | Categorize and label records, including security and access markings | Applying the file plan and access controls |
| Store | Keep records and their metadata authentic, intact, and retrievable for the full retention period | Maintaining the recordkeeping system |
| Dispose | Execute retention, then destroy or transfer records under an approved schedule | Defensible disposition and archival transfer |
Cyber-maturity for contractors
| Category | Value |
|---|---|
| Level 1 | 15 |
| Level 2 | 110 |
| Level 3 (added) | 24 |
For most of the standard's life, compliance with DoD 5015.02-STD was demonstrated through testing by the Joint Interoperability Test Command (JITC), a component of the Defense Information Systems Agency (DISA). JITC's Records Management Application test program evaluated commercial records software against the standard's functional requirements and maintained a register of products that passed. For a contractor or agency buying records software, that register was a procurement shortcut: choosing a JITC-certified product was a defensible way to satisfy a "5015.02-compliant" requirement without independently testing the software.
That mechanism no longer exists. With the cancellation of DoD 5015.02-STD on July 2, 2025, the JITC Records Management test program ended, and JITC's notice said the move invalidated existing support agreements with its records-management customers. The register is now a historical product-test record, not an active DoD endorsement. Electronic records-management planning now falls under DoD Manual 8180.01, and buyers must evaluate the configured software against current requirements.
Stop treating a former JITC test result as a current, dispositive credential. A product's appearance in the historical 5015.02 register remains evidence of past product testing, but it is not a substitute for demonstrating compliance with the regimes that still bind contractors — federal-records retention, CUI protection, and the security controls assessed under CMMC.
With the single-certification model retired, a defense contractor's records obligations are best understood as a stack of three overlapping regimes. Each governs a different dimension of the same records, and a compliant program has to satisfy all three at once.
| Regime | What it governs | Key authority | Core obligation |
|---|---|---|---|
| Federal records (NARA / FRA) | Retention and disposition of federal records | 36 CFR Part 1225; Federal Records Act | Every federal record covered by a NARA-approved disposition authority |
| CUI protection (NIST SP 800-171) | Safeguarding Controlled Unclassified Information | EO 13556; 32 CFR Part 2002; DFARS 252.204-7012 | Implement the 110 NIST SP 800-171 security requirements |
| CMMC | Verifying that safeguards are in place | 32 CFR Part 170 | Achieve the CMMC level the contract requires |
The regimes interlock. NARA rules decide how long a contractor must keep a federal record and when it may be destroyed; the CUI and NIST SP 800-171 rules decide how that record must be protected while it is kept; and CMMC decides how the contractor proves the protection is real. A records-management program that addresses retention but ignores CUI safeguarding — or implements security controls but never establishes disposition authority — is incomplete regardless of what software it runs on.
Controlled Unclassified Information is the category of unclassified information that nonetheless requires safeguarding — covering everything from technical drawings and specifications to certain personnel and procurement data. The CUI Program was established by Executive Order 13556 to standardize how the executive branch handles such information, replacing a patchwork of agency-specific markings, and it is codified at 32 CFR Part 2002, which sets policy for designating, handling, and decontrolling CUI. For a defense contractor, the moment a contract involves CUI, a specific security baseline attaches.
That baseline is NIST Special Publication 800-171. Defense contractors handling CUI must implement the 110 security requirements in NIST SP 800-171 Revision 2, an obligation imposed through DFARS clause 252.204-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting." The 110 requirements are organized into 14 control families that span the practical surface of information security — from access control and audit and accountability to incident response and system and information integrity.
DFARS 252.204-7012 adds operational duties beyond the controls themselves. A contractor must rapidly report cyber incidents to DoD within 72 hours of discovery, and must preserve and protect images of all known affected information systems for at least 90 days from submission of the incident report, so the government can investigate. The clause also flows down: it must be included in subcontracts for operationally critical support or that involve covered defense information, extending the same CUI-safeguarding and incident-reporting obligations to subcontractors. A prime contractor cannot satisfy DFARS 7012 while its subcontractors handle the same CUI unprotected.
One point causes recurring confusion. NIST withdrew SP 800-171 Revision 2 on May 14, 2024 and replaced it with Revision 3, yet DoD's CMMC program and DFARS 252.204-7012 continue to reference the 110 requirements of Revision 2. For now, contractors meet their DoD obligations against Revision 2's 110 requirements even though Revision 3 is the current NIST publication — a transition contractors should track but not get ahead of.
| Control family | What it covers |
|---|---|
| Access Control | Limiting system access to authorized users and processes |
| Awareness and Training | Ensuring staff understand security risks and their duties |
| Audit and Accountability | Creating and protecting logs to trace user actions |
| Configuration Management | Establishing and maintaining secure baseline configurations |
| Identification and Authentication | Verifying the identity of users and devices |
| Incident Response | Detecting, reporting, and responding to incidents |
| Maintenance | Performing system maintenance securely |
| Media Protection | Protecting and sanitizing media that holds CUI |
| Personnel Security | Screening personnel and protecting CUI during personnel actions |
| Physical Protection | Limiting physical access to systems and facilities |
| Risk Assessment | Assessing and managing risk to operations and assets |
| Security Assessment | Evaluating and improving the effectiveness of controls |
| System and Communications Protection | Protecting information in transit and at system boundaries |
| System and Information Integrity | Identifying and correcting flaws and guarding against malicious code |
Implementing the 110 controls is one thing; proving it is another. That is the role of the Cybersecurity Maturity Model Certification (CMMC) Program, governed by 32 CFR Part 170, whose final rule was published October 15, 2024. CMMC verifies that a contractor's safeguards match the sensitivity of the information it handles, and it provides assessments at three progressive levels keyed to whether the contract involves Federal Contract Information (FCI) or CUI.
Level 1, Basic Safeguarding of FCI, requires an annual self-assessment and affirmation against the 15 security requirements in FAR clause 52.204-21. Level 2, Broad Protection of CUI, requires compliance with the 110 NIST SP 800-171 Revision 2 requirements, verified either by self-assessment or by an independent assessment from a CMMC Third-Party Assessment Organization (C3PAO) every three years. Level 3, aimed at protection against advanced persistent threats, adds 24 requirements drawn from NIST SP 800-172 and requires an assessment by the Defense Contract Management Agency's DIBCAC every three years. The level a contractor must hold is set by the contract, not chosen by the contractor.
Two timing rules matter. First, a CMMC status is valid for three years from the CMMC Status Date, making Level 2 and Level 3 assessments a triennial obligation. Second, Plans of Action and Milestones (POA&Ms) — used to close limited, lower-weight gaps after an assessment — are permitted only for certain requirements and must be closed out within 180 days of the Conditional CMMC Status Date. The program is rolling out in phases: Phase 1 began November 10, 2025, initially emphasizing Level 1 and Level 2 self-assessments, with full implementation phased in over three years.
| Level | Protects | Requirements | Assessment | Cadence |
|---|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements (FAR 52.204-21) | Self-assessment and affirmation | Annual |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements (NIST SP 800-171 Rev 2) | Self-assessment or C3PAO assessment | Every 3 years |
| Level 3 | CUI against advanced persistent threats | Level 2 plus 24 requirements (NIST SP 800-172) | DCMA DIBCAC assessment | Every 3 years |
With the certification shortcut gone, a defensible contractor records program is built deliberately, step by step. The sequence below moves from inventory to operations and folds the three regimes together so that retention, protection, and proof reinforce one another.
Consider a hypothetical machine shop in the Lehigh Valley that wins a subcontract to manufacture parts from DoD technical drawings. The drawings are CUI. The figures below combine the cited requirements with clearly illustrative inputs to show how the obligations stack up in practice.
Because the subcontract involves CUI, the shop needs CMMC Level 2 — compliance with all 110 NIST SP 800-171 Revision 2 requirements across 14 control families, verified by self-assessment or a C3PAO every three years. Suppose a self-assessment finds 102 of 110 requirements fully met (an illustrative figure); the eight remaining eligible gaps go into a POA&M that must be closed within 180 days of the Conditional CMMC Status Date. The prime flowed DFARS 252.204-7012 down, so the shop must also be able to report a cyber incident to DoD within 72 hours and preserve affected system images for at least 90 days. Separately, any drawings that qualify as federal records must fall under a NARA-approved disposition authority. None of this depends on the former 5015.02 product-test program; cancellation of the test standard left these duties intact.
The example illustrates the central shift: the contractor's compliance is now measured by the controls it implements, the records authority it establishes, and the assessment it passes — not by a logo on its software.
Records management for a contractor is not only about security; it is about lawful retention and disposition. Under 36 CFR Part 1225, all federal records — including those created or maintained for the government by a contractor — must be covered by a NARA-approved agency disposition (retention) authority. A records schedule is the legal instrument that authorizes how long each record is kept and what happens at the end of its life, whether destruction or transfer to the National Archives. A contractor holding federal records without a corresponding approved authority has no lawful basis to destroy them and no defensible basis to keep them indefinitely.
Format obligations are tightening in parallel. Under OMB Memorandum M-23-07, federal agencies were required to manage all permanent records in an electronic format with appropriate metadata by June 30, 2024 — and that expectation flows to contractors who create federal records on the government's behalf. The practical implication is that paper-based recordkeeping for permanent or long-lived federal records is increasingly untenable: the government partner needs electronic records with sound metadata, captured and maintained to a standard that supports eventual archival transfer.
Defensible disposition is the discipline that ties this together. A contractor should destroy a federal record only when its approved schedule allows, no litigation or investigation hold applies, and the disposition is documented. The ability to show — after the fact — that every disposition followed an approved authority is what separates a defensible program from an exposed one.
A litigation, audit, or investigation hold suspends the retention schedule. Once a federal record becomes relevant to a pending or anticipated matter, its scheduled destruction date is paused until the hold is released — even if the retention period has otherwise expired.
Compliance in this domain is actively assessed, not merely asserted. Through DFARS clause 252.204-7020, contractors must provide DoD access to their facilities, systems, and personnel for NIST SP 800-171 assessments and must maintain a current assessment of their implementation in the government's Supplier Performance Risk System. CMMC formalizes that scrutiny: Level 1 relies on annual self-assessment and affirmation against 15 requirements, while Level 2 and Level 3 require verification — by a C3PAO at Level 2 or DCMA's DIBCAC at Level 3 — every three years.
The consequences of getting it wrong are real even where this guide cites no dollar figures. A contractor that cannot demonstrate compliance can lose the ability to bid or continue on contracts requiring a given CMMC level, since the level becomes a condition of award. Misrepresenting compliance carries additional exposure: false statements about the implementation of required controls have drawn enforcement attention under federal false-claims authorities. The affirmations a senior official signs for CMMC are therefore not a formality — they are attestations the government can act on.
The cancellation of DoD 5015.02-STD and the end of JITC certification do nothing to soften this enforcement posture. If anything, they concentrate attention on the regimes that are actively assessed — NIST SP 800-171, CMMC, and NARA disposition — rather than on a one-time software certification. A contractor preparing for an assessment should assume its System Security Plan, its POA&M closure within 180 days, its incident-response evidence, and its disposition authorities will all be examined.
The failures in this area are predictable, and most stem from treating records management as a software question rather than a program question.
With no active program testing products under 5015.02-STD, contractors evaluate records software on its own merits against the obligations that remain. The useful questions are functional and operational: does the system manage records through identify, mark, store, and dispose with reliable metadata; does it support NARA-approved retention schedules and defensible, documented disposition; does it run inside an environment that can meet the relevant NIST SP 800-171 controls and the CMMC level the contract demands; and can it produce the evidence an assessor will ask for? A product's prior test history is one data point, but the configured capabilities and current evidence determine fitness.
Reynolds Business Systems is a family-owned records and document-management firm based in Emmaus, Pennsylvania, serving the Lehigh Valley — Allentown, Bethlehem, and Easton — and the broader Mid-Atlantic for more than 55 years. Defense contractors and their suppliers across the region face the same shift this guide describes: a long-relied-upon certification has been retired, while the underlying duties to retain, protect, and dispose of federal information have not. The operational work — digitizing records to compliant electronic formats with sound metadata, organizing retention so disposition is defensible, and structuring records so a CMMC or NARA review goes smoothly — is exactly where a records partner adds value. The regulations are set by NARA, NIST, and the Department of Defense; the role of a records partner is to make meeting them dependable and auditable.
No. As of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, "Information Technology Planning for Electronic Records Management." The JITC program that certified products against the standard was terminated at the same time, invalidating existing JITC records-management support agreements.
DoD Manual 8180.01, "Information Technology Planning for Electronic Records Management," superseded the standard when it was cancelled on July 2, 2025. For contractors, the practical successors are the regimes that were always doing the underlying work: NARA's federal-records rules, NIST SP 800-171 for CUI, and CMMC.
JITC — the Joint Interoperability Test Command, part of DISA — ran the program that tested records-management software against DoD 5015.02-STD and maintained a register of products that passed. The standard was cancelled and the program ended on July 2, 2025; no active DoD program now tests products under that standard. Current evaluation uses DoDI 5015.02 and DoDM 8180.01.
NIST SP 800-171 Revision 2 contains 110 security requirements, organized into 14 control families. Defense contractors handling Controlled Unclassified Information must implement all 110 under DFARS clause 252.204-7012. NIST withdrew Revision 2 on May 14, 2024 in favor of Revision 3, but DoD continues to reference Revision 2's 110 requirements.
CMMC has three levels. Level 1 requires a self-assessment against 15 FAR 52.204-21 requirements for Federal Contract Information. Level 2 requires the 110 NIST SP 800-171 Revision 2 requirements for CUI, verified by self-assessment or a C3PAO every three years. Level 3 adds 24 NIST SP 800-172 requirements, assessed by DCMA's DIBCAC.
The Federal Records Act (codified across 44 U.S.C. Chapters 21, 29, 31, and 33) is the foundational federal records-management law. It works alongside NARA's implementing regulations — for retention and disposition, 36 CFR Part 1225 requires that every federal record, including records a contractor maintains for the government, be covered by a NARA-approved disposition authority.
DoD sets records-management policy and responsibilities through DoD Instruction 5015.02, "DoD Records Management Program" (issued February 24, 2015, Incorporating Change 1), and, since July 2025, governs electronic-records IT planning through DoD Manual 8180.01. The thrust is consistent with the federal-wide move toward electronic recordkeeping with sound metadata and approved retention schedules.
There is no single official "four types" under DoD policy. Records management is usually described by the lifecycle stages a record passes through — creation or capture, maintenance and use, storage, and disposition (destruction or archival transfer). DoD 5015.02-STD framed software requirements around four functional capabilities that mirror this lifecycle: identify, mark, store, and dispose of electronic records.
The most widely cited set is ARMA International's Generally Accepted Recordkeeping Principles: accountability, transparency, integrity, protection, compliance, availability, retention, and disposition. These are an industry framework rather than a DoD or NARA mandate, but they map cleanly onto the federal obligations a contractor must meet — particularly protection, retention, and disposition.
The "5 S's" — Sort, Set in order, Shine, Standardize, and Sustain — come from the Lean workplace-organization method and are sometimes applied to physical recordkeeping to reduce clutter and standardize filing. They are an operational housekeeping practice, not a compliance standard; for federal records, the controlling requirements are NARA retention schedules, CUI safeguarding under NIST SP 800-171, and CMMC.
Yes, for federal records they create or maintain on the government's behalf. Under 36 CFR Part 1225, those records must be covered by a NARA-approved disposition authority, and under OMB Memorandum M-23-07 the federal expectation — managing permanent records electronically with appropriate metadata by June 30, 2024 — flows to contractors creating such records.
CUI is unclassified information that still requires safeguarding, such as technical drawings, specifications, and certain personnel or procurement data. The CUI Program was established by Executive Order 13556 and is codified at 32 CFR Part 2002. When a defense contract involves CUI, the NIST SP 800-171 security baseline and DFARS clause 252.204-7012 attach.
No. As of July 2, 2025, DoD 5015.02-STD was cancelled and superseded by DoD Manual (DoDM) 8180.01, "Information Technology Planning for Electronic Records Management." The JITC program that certified products against the standard was terminated at the same time, invalidating existing JITC records-management support agreements.
DoD Manual 8180.01, "Information Technology Planning for Electronic Records Management," superseded the standard when it was cancelled on July 2, 2025. For contractors, the practical successors are the regimes that were always doing the underlying work: NARA's federal-records rules, NIST SP 800-171 for CUI, and CMMC.
JITC — the Joint Interoperability Test Command, part of DISA — ran the program that tested records-management software against DoD 5015.02-STD and maintained a register of products that passed. The standard was cancelled and the program ended on July 2, 2025; no active DoD program now tests products under that standard. Current evaluation uses DoDI 5015.02 and DoDM 8180.01.
NIST SP 800-171 Revision 2 contains 110 security requirements, organized into 14 control families. Defense contractors handling Controlled Unclassified Information must implement all 110 under DFARS clause 252.204-7012. NIST withdrew Revision 2 on May 14, 2024 in favor of Revision 3, but DoD continues to reference Revision 2's 110 requirements.
CMMC has three levels. Level 1 requires a self-assessment against 15 FAR 52.204-21 requirements for Federal Contract Information. Level 2 requires the 110 NIST SP 800-171 Revision 2 requirements for CUI, verified by self-assessment or a C3PAO every three years. Level 3 adds 24 NIST SP 800-172 requirements, assessed by DCMA's DIBCAC.
The Federal Records Act (codified across 44 U.S.C. Chapters 21, 29, 31, and 33) is the foundational federal records-management law. It works alongside NARA's implementing regulations — for retention and disposition, 36 CFR Part 1225 requires that every federal record, including records a contractor maintains for the government, be covered by a NARA-approved disposition authority.
DoD sets records-management policy and responsibilities through DoD Instruction 5015.02, "DoD Records Management Program" (issued February 24, 2015, Incorporating Change 1), and, since July 2025, governs electronic-records IT planning through DoD Manual 8180.01. The thrust is consistent with the federal-wide move toward electronic recordkeeping with sound metadata and approved retention schedules.
There is no single official "four types" under DoD policy. Records management is usually described by the lifecycle stages a record passes through — creation or capture, maintenance and use, storage, and disposition (destruction or archival transfer). DoD 5015.02-STD framed software requirements around four functional capabilities that mirror this lifecycle: identify, mark, store, and dispose of electronic records.
The most widely cited set is ARMA International's Generally Accepted Recordkeeping Principles: accountability, transparency, integrity, protection, compliance, availability, retention, and disposition. These are an industry framework rather than a DoD or NARA mandate, but they map cleanly onto the federal obligations a contractor must meet — particularly protection, retention, and disposition.
The "5 S's" — Sort, Set in order, Shine, Standardize, and Sustain — come from the Lean workplace-organization method and are sometimes applied to physical recordkeeping to reduce clutter and standardize filing. They are an operational housekeeping practice, not a compliance standard; for federal records, the controlling requirements are NARA retention schedules, CUI safeguarding under NIST SP 800-171, and CMMC.
Yes, for federal records they create or maintain on the government's behalf. Under 36 CFR Part 1225, those records must be covered by a NARA-approved disposition authority, and under OMB Memorandum M-23-07 the federal expectation — managing permanent records electronically with appropriate metadata by June 30, 2024 — flows to contractors creating such records.
CUI is unclassified information that still requires safeguarding, such as technical drawings, specifications, and certain personnel or procurement data. The CUI Program was established by Executive Order 13556 and is codified at 32 CFR Part 2002. When a defense contract involves CUI, the NIST SP 800-171 security baseline and DFARS clause 252.204-7012 attach.