DoD 5015.02 was the Department of Defense’s design criteria standard for electronic records management software, telling vendors what their applications had to do before the military would buy them. It was cancelled on August 4, 2023, and replaced by DoD Manual 8180.01, “Information Technology Planning for Electronic Records Management.”1Department of Defense. DoDM 8180.01 – Information Technology Planning for Electronic Records Management If your agency, contract, or product documentation still points to 5015.02, those references are out of date.
The standard shaped federal recordkeeping for roughly two decades and its influence continues, because most of its core concepts carried into the replacement manual and into the guidance civilian agencies now follow.
What DoD 5015.02 Required
Federal law requires every agency head to create and preserve records that adequately document the organization’s activities, decisions, and transactions.2Office of the Law Revision Counsel. 44 USC 3101 – Records Management by Agency Heads; General Duties DoD 5015.02 translated that duty into concrete software requirements covering two categories of product: standalone records management applications built to oversee the lifecycle of a record, and integrated systems that embedded records management features into tools like email or document collaboration platforms.3Department of Defense. DoDI 5015.02 – DoD Records Management Program
The companion instruction, DoDI 5015.02, required DoD components to deploy compliant software within five years of the instruction’s change date and mandated annual records management training for all personnel, including contractors who create or maintain records.3Department of Defense. DoDI 5015.02 – DoD Records Management Program
Functionally, a compliant system had to capture metadata on every record, organize records into file plans, link each record to a NARA-approved retention schedule, protect finalized records from unauthorized change, support legal holds, log significant actions in an audit trail, control access by role, and either transfer permanent records to NARA or irrevocably destroy temporary ones at the end of their retention period. Records could not be removed from government custody or stored in personal files under any circumstances.3Department of Defense. DoDI 5015.02 – DoD Records Management Program
The standard also became a de facto government-wide benchmark. NARA Bulletin 2003-03 recommended version 2 for use by all federal agencies, advising that certified products complied with the Federal Records Act.4National Archives. NARA Bulletin 2003-03 NARA Bulletin 2008-07 extended that endorsement to version 3.5National Archives. NARA Bulletin 2008-07 The endorsements were recommendations, never mandates for civilian agencies.
Why the Standard Was Cancelled
The opening page of DoDM 8180.01 states plainly that it reissues and cancels DoD 5015.02-STD.1Department of Defense. DoDM 8180.01 – Information Technology Planning for Electronic Records Management The shift reflects a change in approach. Where 5015.02 focused on certifying purpose-built records management applications, the new manual addresses records management capabilities within any IT system or service. The Department is no longer assuming that agencies will buy a single dedicated records product and funnel everything through it. Records management functionality can be provided by the IT system itself or through an interface to another capability.
DoDM 8180.01 organizes its requirements around lifecycle stages: planning, creation, capture, storage, maintenance, disposition, and access, with specific outcomes defined for each. Records must remain findable, human readable, and trustworthy despite changes to technology, policy, or organizational strategy.1Department of Defense. DoDM 8180.01 – Information Technology Planning for Electronic Records Management Temporary records that outlive an IT system must be transferred to successor systems without losing content, metadata, or state, which is the requirement most likely to bite agencies during migrations.
The core recordkeeping concepts from 5015.02 carried across. Metadata capture, file plans, NARA-approved schedules, protection of finalized records, legal holds, audit trails covering schedule changes and search and retrieval and disposal and hold actions and transfers, role-based access, and the transfer-or-destroy endpoint are all present.1Department of Defense. DoDM 8180.01 – Information Technology Planning for Electronic Records Management Permanent records require storage planning for at least 25 years before eventual transfer to NARA.
DTM 22-001 and Default Disposition
Running alongside the manual is Directive-type Memorandum 22-001, which fills a practical gap: what happens to data that no one has formally classified as a record. DTM 22-001 sets a 30-day safe harbor after a user deletes data, giving the system a recovery window, after which the data must be irrevocably destroyed.6Department of Defense. DTM 22-001 – DoD Standards for Records Management Capabilities in Programs Including Information Technology
For unscheduled data, the memorandum sets two default timelines:
- Data with no business or legal value and low likelihood of qualifying as a record is deleted no more than six months from the date last modified.
- Data with no business or legal value but some likelihood of qualifying as a record is deleted no more than seven years from the date last modified.
These defaults are overridden whenever data is formally identified as a record and assigned a disposition authority. Systems must also support position-based retention in accordance with NARA General Records Schedule 6.1. DTM 22-001 incorporates changes through March 2026 and expires in March 2027.6Department of Defense. DTM 22-001 – DoD Standards for Records Management Capabilities in Programs Including Information Technology
What Civilian Agencies Use Instead
With 5015.02-STD cancelled, civilian agencies looking for software guidance turn to NARA’s Universal Electronic Records Management Requirements, currently at version 3 (released June 2023). The requirements are organized around six lifecycle stages: capture, maintenance and use, disposal, transfer, metadata, and reporting.7National Archives. Universal Electronic Records Management (ERM) Requirements
Each requirement is designated either “Must Have” or “Should Have,” giving vendors and procurement staff a clear picture of what is non-negotiable versus preferred. The requirements address both born-digital and digitized analog records, and split into program requirements (how an agency designs its policies) and system requirements (what the software must do).7National Archives. Universal Electronic Records Management (ERM) Requirements For vendors selling to civilian federal agencies, this is now the document that matters.
JITC Certification Is Terminated
Under the old framework, vendors selling records management software to the Department of Defense had to pass certification testing administered by the Joint Interoperability Test Command. JITC evaluated whether software met every functional requirement in the standard, and products that passed were listed on a public register that procurement officers used to verify compliance.
That program is over. JITC’s records management page states that the test program is terminated, effective immediately, because “the DoD 5015.02-STD has been cancelled and superseded by the release of DoD Manual (DoDM) 8180.01, invalidating current support agreements with JITC RM customers.”8Joint Interoperability Test Command. Records Management There is no direct replacement certification. DoDM 8180.01 embeds records management requirements into broader IT governance processes such as portfolio management, risk management, and enterprise architecture, rather than certifying individual products.1Department of Defense. DoDM 8180.01 – Information Technology Planning for Electronic Records Management
If Your Policies Still Reference DoD 5015.02
The standard is cancelled, the certification program is terminated, and the approved products list is no longer maintained. Procurement documents and internal policies should reference DoDM 8180.01 for DoD systems, or NARA’s Universal ERM Requirements for civilian systems.
Vendors with legacy DoD 5015.02 certifications cannot rely on them for new contracts. The underlying standard no longer exists, so the certification has nothing to validate against. Previously certified products may still meet recordkeeping requirements in practice, but the certification itself carries no current authority.
The operational requirements have not softened. Records must still be linked to approved schedules, protected by audit trails, managed across their full lifecycle, and either transferred to NARA or irrevocably destroyed when their retention period ends. What changed is the structure of compliance: less about certifying individual products, more about ensuring that any IT system touching records has the right capabilities built in or connected to it.