How Deltek Costpoint Supports Government Compliance Requirements

Transcription

CostpointGuide toGovernmentComplianceHow Deltek Costpoint SupportsGovernment Compliance Requirements

Table of Contents03What is Government Contracting Compliance?04How Costpoint Supports Compliance05FAR & CAS Compliance Costpoint06DCAA Audit Readiness Costpoint07CMMC Compliance Costpoint09Consequences of Noncompliance2021 Small Business Checklist2

What is Government ContractingCompliance?Navigating government compliance regulations can be difficult for even the most seasoned ofcontractors. Deltek’s Costpoint Project Accounting and Enterprise Resource Planning (ERP)solution is trusted by both small businesses and multi-national corporations to provide theguardrails to keep their businesses compliant with the FAR. This guide will outline the basics of USGovernment compliance as it relates to financial accounting and the safeguarding of governmentinformation, and will provide a path to compliance utilizing Costpoint.Let’s begin with the Federal Acquisition Regulation (FAR)*,which is the overarching set of uniform policies and proceduresthat contractors doing business with the government mustcomply with. The US Government uses agencies like theDefense Contract Audit Agency (DCAA) and DefenseContract Management Agency (DCMA) to conduct auditsand assessments to assure the government that your businessis operating in compliance with the FAR. The DCAA audits abusiness’s financial and accounting system whereas the DCMAis involved on a contract level and may review pricing estimatespre-award or even be on-site to witness qualification testingprior to contract deliveries being made to the government.Contract Information (FCI). The risks of data breaches causedby cyber vulnerabilities has necessitated the requirement toensure firms doing business with the US Government have goodcyber hygiene. To this end the Government has added additionalrequirements to many DoD contracts for CybersecurityMaturity Model Certification (CMMC).As your business grows, it is essential to reduce the risk of noncompliance by establishing consistent business processesthat keep your business on the compliant side of the FAR.Keep reading to learn more specifics about the requirementsyour business is likely to have and how to gain and maintaincompliance with Costpoint as your ERP.Another aspect of US Government compliance that is becomingincreasingly more critical is the safeguarding of Federal*Additional guidance and standards referenced as part of the FAR include: Cost Accounting Standards (CAS), International Traffic and Arms Regulations(ITAR) and supplements like the Defense Federal Acquisition Regulations (DFAR). The specific FAR (or DFAR) requirements for a particular contract will becalled out as clauses in contract documents including Requests for Information (RFIs) and Requests for Proposals (RFPs).ASCFARCASComplianceDCAADCMA“When contractorsenter into agreementsto provide goodsand services to theGovernment, they mustfollow governmentacquisition guidanceand regulations. DCAAassesses contractorcompliance with theseregulations based on thetype of contract with theGovernment.”FromDCA A .mil3

Save on the cost and schedule of integrating additionalcapabilities to your ERP with Costpoint’s built in integrations.PLANNINGTIME &EXPENSE Easily comply withDCAA controls andgain support for FAR,CAS, DCMA and ASCcompliance needs.CONTRACTS &SUBCONTRACTSMANAGEMENTMANUFACTURINGPROCUREMENT Costpoint Cloudofferings implementNIST 800-171 controls,and CMMC Level 2certification is on theroadmap. Costpoint GovConCloud Moderate alsoaligns with FedRAMPModerate and supportsITAR controls.How Costpoint SupportsComplianceBuilt on 30 years of experience, Costpoint is theindustry’s leading project based ERP solution forgovernment contractors that need to comply with bothgovernment accounting and cybersecurity regulations.Costpoint provides the accounting infrastructure to enable businesses toimplement FAR-compliant processes for segregating and allocating projectcosts. It connects the dots between your pursuits, project delivery, and financeactivities, resulting in reduced data entry, better recording of indirect costs,and more efficient project handoffs and kickoffs. Costpoint can scale for firmsof any size, and supports government compliance in ways that homegrownor disparate systems simply can’t provide. Additionally, Deltek’s modern,integrated cloud offering enables the secure storage of your data and isconsistently enhanced to meet the most up-to-date governmental and agencycybersecurity compliance standards.4

FAR & CAS Compliance CostpointThe Federal Acquisition Regulation (FAR) and CostAccounting Standards (CAS) outline the rules thatdrive every DCAA audit. Since the primary method oftracking where government money goes is by accountingprocesses, it is particularly important that contractorsperform scrupulous accounting.FARThe FAR specifies what is allowable to chargeto the government through a governmentcontract—and what you cannot. According toGSA.gov, FAR is “the primary regulation for use byall Federal Executive agencies in their acquisitionof supplies and services with appropriatedfunds.” The purpose of FAR is to provide a setof consistent, uniform policies and procedureswithin the federal acquisition process. Itdefines when, and to what extent, costs can berecovered under a government contract.Addressing FAR & CAS with CostpointA government contracting firm’s business processes plays a pivotal role inmeeting FAR and CAS compliance requirements and standards. Successfullymanaging those processes from beginning to end are innately part of the DNAof the Deltek Costpoint solution. Designed with FAR and CAS in mind, keyfunctionalities of Costpoint allow for:CASThe CAS contains sets of standards and rulesestablished by the federal government to helpachieve uniformity and consistency in the costaccounting principles within federal contracting.CAS also contain detailed regulations thatrequire contractors to disclose their costaccounting practices, to follow the disclosedpractices consistently, and to comply withspecified standards. It says how you charge tocontracts, what gets charged to which contracts,dictates how you maintain your accountingsystems, and tells you how the costs have to flowfrom incursion to the final costs. It also instructscontractors on how to account for certain typesof costs. Integrated project financial modules that provide the controls andframework to implement the contractor-defined processes and workflowsfor providing reliable and accurate accounting and financial data. Exclusion from costs charged to government contracts of amountswhich are not allowable in terms of FAR 31, Contract Cost Principles andProcedures, or other contract provisions. The ability to identify, segregate and track direct and indirect costs atthe project, contract line item, part or unit level based on the contract’srequirements. Automated flow-downs of contract requirements both internally and toexternal vendors and subcontractors. A logical and consistent method for the allocation of indirect costs tointermediate and final cost objectives.Pre-configured dashboards and reports specifically for governmentcontractors to enable access to project/contract information for reportingpurposes as well as the ability to create custom reports and dashboards.5

DCAA Audit Readiness CostpointThe DCAA performs contract audits for the DoD andmany other agencies, and the scope of their influence issignificant. That’s because the DCAA provides definitiverecommendations to contracting officers that affectnegotiations with thousands of contractors each year.Audit TypesForward pricingForward pricing audits are generally completed before contract award. The DCAAevaluates a contractor’s estimate of how much it will cost the contractor toprovide goods or services to the government.Special auditsSpecial audits can be conducted before or after contract award. Most of thereports in this category are issued in response to requests from contractingofficers. In these instances, the contracting officers need an independentfinancial opinion on specific elements of a contract or on a contractor’saccounting business system in order for the contract work to proceed—makingspecial audits a high priority.Incurred costIncurred cost audits determine the accuracy of a contractor’s annual allowablecost representations. When a contract price is not fixed, the DCAA conducts anincurred cost audit after contract award to determine the accuracy of contractorcost representations.Pre-award surveysMany small businesses are affected by DCAA Standard Form (SF) 1408 pre-awardsurveys. The major objectives of this audit are to gain an understanding of thecontractor’s accounting system, complete the SF 1408 form, Preaward Survey ofProspective Contractor Accounting System, and form an opinion as to whetherthe contractor’s system design is acceptable for the award of a governmentcontract. Contractors that are audited must be able to demonstrate theiraccounting system to the auditor and implement it before incurring any costs ona contract. For a breakdown of the areas that the SF-1408 focuses on, read thewhite paper Accounting Systems, Compliance & the Government Contractor.Business system auditThe DCAA typically initiates these type of audits when there is high risk, such aswhere the contractor has inadequate business systems.Other AuditsOther audits primarily consist of audits performed after contract award, and canbe requested by a contracting officer or initiated by the DCAA.Costpoint establishes a foundation from which many audit requirements canbe met and by which good business practices can be monitored. Tools andfunctionality within Costpoint to aid in DCAA or DCMA audit readiness include: Approval workflows that require items to pass through the workflows setupby the contractor. Audit trails and traceability on every transaction at all project levels,including inventory and information on price paid. Tracking of purchasing data and all communications between buyers andsellers. Creation of a digital thread where all information is within one system,enabling timely analysis of cost and price.6

CMMC Compliance CostpointWhat is Cybersecurity Maturity Model Certification(CMMC)?Every year cybersecurity attacks against the USGovernment’s Defense Industrial Base (DIB) increase infrequency and sophistication. To combat these attacks,the DoD developed the CMMC program in order toenhance cybersecurity standards for its contractors andsubcontractors. CMMC assesses how well contractorscreating or possessing Controlled Unclassified Information(CUI) are adhering to data handling requirements defined inNIST SP 800-171.Gain Compliance Faster with Costpoint GovCon CloudRegulatory Compliance. Deltek has invested heavilyin cybersecurity and compliance requirementsfor the government contracting industry and, byleveraging Costpoint GCC’s CMMC compliantfoundation, regulatory compliance can be achievedfaster than if you were to handle it on your own.Scalability. Costpoint GCC supports businessesof all sizes from small firms to large, multi-nationalorganizations; its scalability features ensure yourneeds continue to be met as your organization grows,while maintaining reliable performance and secure,24/7 system accessibility.Preparation for the Future. You also get thepeace of mind of ensuring compliance with futuregovernment standards thanks to Deltek’s team ofcybersecurity and government compliance expertswho continually monitor the shifting regulations andact on them swiftly.Customer Support. Further ensuring your business’success is Deltek’s best-in-class customer supportand streamlined delivery system for enhancements,ensuring your software stays current while providingnew capabilities to your end users faster.Examples of CUI Data US Government-provided financial information Personally identifiable information (PII) Bills of materials Blueprints SchematicsPrime contractors and sub-contractors for the DoD maysee CMMC requirements in requests for information (RFIs),requests for proposal (RFPs), and as contract flow-downs;failing to meet these requirements could cause them tomiss out on new contract awards.7

Deltek RemainsCommitted to CMMCFor contractors that want to take advantage of the security, scalability andaccessibility of a cloud-based ERP deployment, Deltek has two CostpointCloud offerings that meet the unique cybersecurity needs of governmentcontractors. Costpoint GovCon Cloud (GCC) offers support for handling FederalContract Information (FCI) and most CUI. Costpoint GovCon Cloud Moderate (GCCM) is enhanced with supportfor International Traffic in Arms Regulation (ITAR) and FedRAMP Moderateequivalent controls to effectively handle more sensitive CUI data typeslike export-controlled, Covered Defense Information (CDI) and ControlledTechnical Information (CTI).Both Costpoint GCC solutions formally incorporate NIST SP 800-171 controlsinto their infrastructure, which serves as the basis for assessing CMMCcompliance. In addition, Deltek will continue to pursue CMMC 2.0 certificationat Maturity Level (ML) 2 for GCCM, which is the equivalent of CMMC ML 3 fromthe CMMC 1.0 framework.How Costpoint Keeps You“As CMMC requirements progress, we wanted toComplianthave peaceof mind knowing that our next solutionhad FedRAMPModerateequivalentor higherBuilt on 30 years of experience,Costpointis orization.willsolutionnot bethatstoringCUIrightaway,and greater intelligence through an all-in-one systembut it’s acrossimportantthatlifecyclewe havethe securitylevels inthe projectfor governmentcontractors.place tyour projects, people and finances, it canscale for firms of any size, and supports government compliance in ways thathomegrown or disparate systems simply can’t provide. Additionally, Deltek’s– LEE egrated cloudofferingenables the securestorage of your dataand is consistently enhanced to meet the most up-to-date governmental andagency cybersecurity compliance standards.8

Consequences of NoncomplianceEvery contractor is responsible for remaining compliant with all the government rules and regulations that apply. Misconduct couldbe exposed by a whistleblower, audit, investigation, Freedom of Information Act (FOIA) request or other means. Consequences ofnoncompliance include: Civil and Criminal Penalties: Civil penalties for noncompliance are determinedper violation, per invoice. The government can recoup thousands of dollars, and thecontractor runs the risk of paying the government up to three times the damage.Criminal penalties are much more serious—up to several years imprisonment forwhoever signed the certificate of cost and pricing data.Debarment: This is one of the most serious punishments the federal governmentcan impose on a contractor. A contractor can be debarred for committing fraudin obtaining or performing a contract, violating antitrust laws or a number of otheroffenses. A debarment from one agency has government-wide effects. Solicitationbids and proposals from debarred contractors cannot be considered, unless theagency head determines a compelling reason to do so in writing. Voided or Terminated Contracts: The FAR gives agencies the ability to void andrescind contracts for which there has been:» Final conviction for bribery, conflict of interest, disclosure or receipt of contractorbid or proposal information» Final conviction of source selection information in exchange for either a thing ofvalue or to give anyone competitive advantage» Agency head determination of any of the above.2021 Small Business Checklist9

Is it time to level upyour business withCostpoint?Accounting solutions that are not already built for government compliancecan become more and more limited in terms of capability and processmanagement. It is possible to continue some business functions with genericsolutions like QuickBooks , but when the DCAA performs a contract audit,having a solution that is purpose-built for compliance is essential.Designed specifically for government contractors, Costpoint supportscompliance requirements like DFARS 252.242-7005, NIST 800-171 and CMMC,while enabling improvement of operational efficiency and gaining real-timeinsights that impact your business. Additionally, Costpoint GovCon Cloudenables the secure storage of your data and is consistently enhanced to meetthe most up-to-date governmental and agency cybersecurity compliancestandards.Don’t settle for anything less than the gold standard of compliance!Get a quote today at Deltek.com/Costpoint »How Costpoint Keeps You“If the DCAA were to audit you tomorrow, wouldCompliantyou pass?How much of your time and resourceswould bespentfor theCostpointaudit? WhenBuilton 30 preparingyears of experience,is theindustry’sleadingsolutionthat deliversmore innovationit comesto auditsandcompliance,Deltekisand greater intelligence through an all-in-one systemthe industrythatwill saveyou timecontractors.andacross expertthe projectlifecyclefor governmentaggravation,andmovingoftois finances,the bestCentralizingthe managementyourCostpointprojects, people andit canscale for firms of any size, and supports government compliance in ways thatdecisionour smallbusinesshasevermade!”homegrownor disparatesystems simplycan’tprovide.Additionally, Deltek’smodern, integrated cloud offering enables the secure storage of your dataand is consistently enhanced to meet the most up-to-date governmental and– yVICE PRESIDENTCORPORATECONTROLLER, APPLIED INSIGHT10

Browse more content at deltek.com/resources »Better software means better projects. Deltek is the leading global provider of enterprise software and information solutions for project-based businesses. More than 30,000 organizations and millions of users in over 80 countriesaround the world rely on Deltek for superior levels of project intelligence, management and collaboration. Our industry-focused expertise powers project success by helping firms achieve performance that maximizes productivityand revenue. deltek.com Deltek, Inc. All Rights Reserved All referenced trademarks are the property of their respective owners. REV-021622 166682021 Small Business Checklist10

Costpoint Cloud offerings implement NIST 800-171 controls, and CMMC Level 2 certification is on the roadmap. Costpoint GovCon Cloud Moderate also aligns with FedRAMP Moderate and supports ITAR controls. Save on the cost and schedule of integrating additional capabilities to your ERP with Costpoint's built in integrations.