How Defense Contractors Use ERP for DCAA Audits and CMMC
A 140-employee avionics subcontractor in Huntsville won its first cost-plus contract with the Missile Defense Agency in early 2024, then failed its DCAA pre-award survey six weeks later. The problem wasn't the technical proposal — it was QuickBooks Enterprise. The system had no way to segregate direct costs by contract line item number (CLIN) or split indirect costs into separate overhead, fringe, and G&A pools. The company spent four months and roughly $90,000 migrating to an ERP system built for government contract accounting before DCAA would let the contract proceed.
That story repeats constantly in the defense supply chain. A commercial accounting package can run a healthy business for years and still be structurally incapable of supporting a government contract, because DCAA isn't grading profitability — it's grading whether the accounting system can prove, line by line, that costs billed to the government are the costs actually incurred on that specific contract.
What a DCAA pre-award survey actually checks
The Standard Form 1408 audit that determines whether your accounting system is "adequate" for a cost-reimbursable contract comes down to six requirements:
- Proper segregation of direct costs from indirect costs
- Identification and accumulation of direct costs by individual contract
- A logical, consistent method for allocating indirect costs to intermediate and final cost objectives
- Accumulation of costs under general ledger control
- A timekeeping system that supports total time accounting — every hour an employee works, including unpaid overtime and non-billable time, not just hours billed to a contract
- Exclusion of unallowable costs under FAR 31.205, such as alcohol, lobbying, and entertainment, from any billing to the government
Generic accounting software handles the first and fourth reasonably well. It almost never handles the second, third, and fifth without heavy customization, and by the time a company has bolted together spreadsheets to cover the gaps, it usually costs more than an ERP system built for government contractors would have in the first place.
Contract type changes what the ERP has to track
Defense contractors rarely work under a single contract type, and the accounting burden is different for each:
| Contract type | What the ERP must track | Risk if it can't |
|---|---|---|
| Firm fixed price (FFP) | Actual cost vs. bid, by CLIN, for internal profitability | Bidding blind on future contracts |
| Cost-plus-fixed-fee | Real-time work-in-progress cost by CLIN, tied to an annual incurred cost submission | Disallowed costs, delayed payment, contract termination |
| Time and materials | Timesheets tied directly to invoiced labor categories and rates | Billing disputes, questioned costs |
A contractor juggling all three needs an ERP that can hold multiple billing methodologies inside the same chart of accounts without forcing every project into a single revenue-recognition model.
Indirect cost pools and rate calculation
Every dollar that isn't direct labor or direct material on a specific contract has to land in an indirect pool — usually overhead, fringe, and general and administrative (G&A), and each pool needs its own allocation base. A mid-size contractor might run a $2.3 million G&A pool against a $15.4 million total cost input base, producing a provisional G&A rate of about 14.9%, which then gets trued up against actual costs at year-end through the incurred cost submission. Get the pool structure wrong and every invoice built on top of it is wrong too, which is exactly what DCAA auditors are trained to unwind.
CMMC 2.0 is now an ERP procurement decision, not just an IT one
Any contractor handling Controlled Unclassified Information (CUI) — technical drawings, bills of material, test data — needs CMMC Level 2 certification, which maps to the 110 controls in NIST SP 800-171. That has direct consequences for which ERP system you can run and how you host it:
- Data at rest and in transit inside the ERP needs FIPS-validated encryption
- Access to CUI-tagged records needs multi-factor authentication and full audit logging, not just a login password
- Cloud-hosted ERP needs to sit in an environment that meets FedRAMP Moderate equivalency — for Microsoft-based systems that usually means GCC High rather than standard commercial cloud
Contractors who assume their existing commercial-cloud ERP deployment "counts" for CMMC frequently find out otherwise during a C3PAO assessment, at which point re-platforming under contract deadline pressure is far more expensive than planning for it upfront.
ITAR and EAR: restricting who can see what, at the record level
Export control adds a second access layer on top of CMMC. An engineer working under an H-1B visa or a pending green card may need to see purchase order status and inventory counts but legally cannot view certain technical drawings classified as ITAR technical data. That requires role-based permissions operating below the module level — restricting individual record types and fields, not just locking someone out of an entire engineering module. Few commercial ERP systems ship with this granularity out of the box; it's usually a configuration project during implementation, and it's worth confirming a vendor has done it before, not building it for the first time on your account.
Restricting CUI and ITAR-controlled access to a smaller named-user group also affects licensing cost, since most ERP vendors price by seat rather than by company size. Before assuming every employee needs a full license, it's worth running the numbers through a cost-per-user calculator — a 200-person contractor might only need 40 licensed seats with access to controlled data, with the rest on lighter self-service licenses for time entry and expense reports.
Segregation of duties and the audit trail
DCAA and CMMC both expect segregation of duties: the person who approves a purchase order shouldn't be the same person who receives the goods and reconciles the invoice, and the person entering time shouldn't be the one approving their own timesheet without a second signoff. ERP workflow engines enforce this automatically through approval chains, and the system logs every change to a labor category, billing rate, or cost pool assignment with a timestamp and user ID. During an audit, being able to pull that change log in minutes — instead of asking three people to remember what happened six months ago — is often the difference between a clean finding and a follow-up request for more documentation.
Flowing requirements down to subcontractors
Prime contractors are contractually obligated to flow CMMC and DFARS 252.204-7012 cybersecurity clauses down to their own subcontractors, and to verify compliance rather than just take a subcontractor's word for it. An ERP vendor management module that tracks certification status, expiration dates, and required flow-down clauses per subcontractor turns that from an annual scramble into a standing report. It also means subcontractor invoices can be checked against the same cost-segregation rules before they're rolled into the prime's own incurred cost submission, instead of surfacing as a surprise during the prime's own audit.
Questions to ask an ERP vendor before signing for defense work
- Has this system passed a DCAA pre-award survey at another customer, and can we talk to that customer?
- Can it maintain three or more indirect cost pools with different allocation bases simultaneously?
- Does timekeeping enforce total time accounting, including uncompensated overtime?
- Is the hosting environment GCC High or an equivalent that meets CMMC Level 2 cloud requirements?
- Can access controls restrict individual technical-data records by user, not just by module?
- What's the incurred cost submission process — a built-in report, or a manual spreadsheet exercise?
None of this shows up in a standard product demo unless you ask for it directly. The Huntsville subcontractor now runs its incurred cost submission as a scheduled report instead of a six-week spreadsheet reconciliation — the kind of difference that only becomes obvious after the first audit goes badly.