Business Operations
The GovCon Back Office: What Breaks and How to Fix It
Accounting, HR, contracts, and security operations behind every federal contractor - what fails as firms scale and how to rebuild it.
The Four Pillars
Project-based cost accounting: DCAA timekeeping, indirect rate calculation, WAWF/PIEE invoicing, FAR Part 31 unallowable segregation.
HR and payroll: SCA wage determinations, H&W fringe, OFCCP affirmative action, DISS clearance crossovers tied to start dates.
Contracts and subcontracts: FAR/DFARS clause review, NDA/TA negotiation, modification tracking, flow-down enforcement.
Industrial security and cybersecurity: FSO managing DISS and NISPOM, ISSM owning NIST 800-171/CMMC and the SSP.
Why It Breaks
The spreadsheet squeeze: rate calcs and SCA tracking outgrow Excel; one broken formula creates billing errors or False Claims exposure.
Silos: HR hires without telling Security, contracts negotiates without telling payroll. Employees show up Day 1 and can't badge in.
Reactive compliance: SSPs get updated only when CMMC assessments are announced. Floor-check failures become a recurring event.
The do-it-all executive: CEO is also FSO, Contracts Manager, and Head of HR. Growth stalls at the bottleneck.
How to Fix It
Move off spreadsheets to a GovCon ERP (Unanet, Deltek Costpoint, JAMIS) that natively enforces DCAA timekeeping and indirect rate application.
Integrate the workflows. Offer-letter signed should automatically trigger HR onboarding, FSO DISS crossover, IT provisioning, and accounting charge-code setup.
Outsource deep expertise. You don't need a $200K-a-year ISSM for one enclave or a senior GovCon controller to run ICS prep. Buy those capabilities by the hour.
Drive compliance culture from the top. DCAA timekeeping and NISPOM procedures aren't suggestions - they're conditions of employment.
Want help putting this into practice?
Desra Group operates the back office for growing defense contractors so leadership can focus on winning and executing the mission.
Need the people to execute?
Desra Group places cleared cybersecurity, RMF/GRC, IT, and mission support professionals on defense and federal programs.
Related guides
This guide is provided for general informational purposes only and does not constitute legal or compliance advice. Specific obligations depend on your contracts and the data you handle.