What a Manufacturer Actually Has to Do Before Bidding on a Defense Contract
You run a precision shop. Maybe a prime called and asked whether you take defense work. Maybe you watched reshoring pull aerospace demand back onshore and figured your capabilities fit. Either way, you are looking at a wall of acronyms and wondering what it would actually take to bid.
Here is the reassuring part. The path is structured and learnable. The requirements sort into three buckets, and you can work them in order. The first bucket lets you bid at all. The second is the cost and accounting discipline the government will hold you to. The third is about what information you handle and how you protect it. Most manufacturers clear the first bucket in a few weeks. The other two are where the real operational discipline lives, and where firms that prepare early pull ahead of firms that scramble after an award.
Bucket one: get eligible to bid
Before you can submit a single offer, your business needs to be registered in SAM.gov, the System for Award Management. This is the federal government’s contractor registry, and it is the true front door. Without an active registration, you are legally ineligible to receive a federal award.
A few things to know so you get it right the first time:
- Registration is free. You do this directly at SAM.gov. No third party is required, and you never need to pay a fee to register.
- You must be active at two points. Under current FAR rules, you need an active registration when you submit your offer and again at the time of award.
- Registration assigns your identifiers. When you register, the system issues your Unique Entity Identifier, the UEI, which replaced the old DUNS number. You also receive a CAGE code.
- You pick NAICS codes. These industry codes determine which Small Business Administration size standards apply to you and which set-aside opportunities you qualify for. Choose the ones that match what you build.
- Your details have to match. The single most common reason registrations get rejected is a mismatch between your SAM.gov legal name or address and what the IRS and your bank have on file. Reconcile those before you start.
- You renew every year. Registration lapses after 12 months. An expired registration means you cannot bid or get paid until you renew.
Plan for roughly 10 to 15 business days of government validation once you submit. If you want to pursue set-aside work as a small, HUBZone, woman-owned, or service-disabled veteran-owned business, those are separate certifications with their own eligibility rules. They are worth pursuing, but they sit on top of the base registration rather than replacing it.
Bucket two: understand your compliance burden by contract
This is the bucket most manufacturers underestimate, and it is broader than the contract type alone. Three things drive how closely the government examines your costs: the type of contract you win, whether your pricing crosses the certified cost or pricing data threshold, and which cost accounting requirements flow down to you. Work them in that order.
Start with contract type. It determines whether the government examines your accounting system before it hands you the work. The dividing line is simple. If a contract reimburses your actual costs, the government wants proof your books can track those costs accurately before it commits.
For cost-reimbursement and time-and-materials contracts, that proof comes through the SF 1408, formally the Pre-Award Survey of Prospective Contractor Accounting System. The Defense Contract Audit Agency, DCAA, usually runs it. The survey checks whether your system can separate direct costs from indirect costs, accumulate costs by individual contract, and tie labor hours to specific cost objectives.
Clear up one myth right away. There is no such thing as a “DCAA approved” accounting system, and DCAA does not certify software. DCAA reviews whether your system’s design is adequate and reports its findings to the contracting officer, who makes the actual determination. What matters is how your system is built and whether you have written policies and procedures backing it up, not the logo on your software.
One requirement runs through the entire SF 1408 and catches commercial manufacturers off guard: timekeeping. Your system has to track every employee’s hours and connect them to the right cost objective, separating direct project work from research and development and from indirect labor. This is called Total Time Accounting, and the word total is the point. It covers every hour a person works, not just the hours you bill to a customer. A punch clock or a shared spreadsheet almost never survives this requirement. The habits you build here are the ones a pre-award survey is designed to test.
Next comes price, and this one applies regardless of contract type. When a negotiated contract crosses the certified cost or pricing data threshold and no exception applies, you have to submit certified cost or pricing data under what most people still call TINA, the Truth in Negotiations Act. For defense contracts and subcontracts entered into after June 30, 2026, that threshold is $10 million, raised from $2.5 million by the 2026 National Defense Authorization Act. Fewer contracts cross the line now, which is the point of the increase.
The part that catches contractors off guard is what crossing that line opens up. Certified cost or pricing data does more than add a form. It puts your cost estimates, and the estimating system that produces them, under audit and review. Once you are certifying that the numbers behind your price are accurate, current, and complete, the government can go back and examine how you built them. Inaccurate certified data carries real weight, including a downward price adjustment, penalties, and False Claims Act exposure. For a first-time bidder the lesson is the same as with timekeeping: the estimating and accounting discipline you build early is what carries you through that scrutiny when a bid finally clears the threshold.
The third driver is Cost Accounting Standards, or CAS. For most manufacturers taking early government work, CAS is a horizon concern rather than a starting-line one. Small businesses are exempt, and the coverage thresholds sit well above where a first-time bidder operates. The 2026 NDAA raised the CAS coverage threshold to $35 million, part of the same effort to pull smaller and nontraditional companies into the defense base.
Where CAS reaches you sooner is through flowdown. When you subcontract to a prime whose contract is CAS-covered, CAS clauses can pass down into your subcontract, and the requirements attach as your business grows past small-business size and your contract values climb. You do not need full CAS machinery to bid your first job. You do need to recognize a CAS clause when it shows up in a subcontract and understand what it signals: a higher tier of cost-accounting consistency the government will expect as you scale.
Bucket three: protect the information you handle
The third bucket is defense-specific, and it is the one manufacturers most often get wrong by either overreacting or ignoring it.
The organizing question is what kind of information you touch. Two categories matter. Federal Contract Information, FCI, is information generated for or provided under a contract that is not meant for public release. Controlled Unclassified Information, CUI, is more sensitive government information that requires safeguarding. What you handle determines what you have to do.
If your defense work involves CUI, the baseline is DFARS clause 252.204-7012. It requires you to implement the 110 security controls in NIST Special Publication 800-171 and to report cyber incidents. That obligation has been in place for years and did not go anywhere.
Layered on top is the Cybersecurity Maturity Model Certification, CMMC. The DFARS rule implementing it took effect on November 10, 2025, which makes your CMMC status a condition of award for covered contracts. The structure is worth knowing:
- CMMC Level 1 applies to FCI. It is always a self-assessment. There is no third-party requirement.
- CMMC Level 2 applies to CUI. It is built on the same 110 NIST 800-171 controls and has two paths, a self-assessment and a third-party certification performed by a certified assessor.
There has been movement here, which is exactly why you should verify current status rather than trust an old article. On July 13, 2026, the Department of Defense suspended CMMC Phase 2, the phase that would have broadly expanded third-party certification requirements at award. This is a pause on that expansion, not the end of CMMC. The DFARS rule, the NIST 800-171 obligations, the Level 1 and Level 2 self-assessment requirements, and your exposure under the False Claims Act for misrepresenting your security posture all remain in effect. If you are preparing, keep preparing. The underlying security expectations have not softened.

The rest of the alphabet
A few other requirements exist that you will hear about. Name them, file them, and move on for now:
- FAR and DFARS are the master rulebooks for federal and defense procurement. Nearly everything above traces back to them.
- Cost Accounting Standards apply at higher contract-dollar thresholds and are not a first-bid concern for most small manufacturers.
- AS9100 is the quality management standard common in aerospace and defense, and many primes will expect it.
- ITAR and export controls come into play if your work touches controlled technical data.
- Most first awards arrive as a subcontract to a prime, which brings flow-down clauses that pass the prime’s obligations down to you.
What to do in the next 30 days
If you are serious about bidding, here is a realistic first month:
- Reconcile your legal name and address across IRS, bank, and business records, then start your SAM.gov registration.
- Identify your NAICS codes and check whether you qualify for any small-business set-asides.
- Take an honest look at your timekeeping. If you cannot tie every employee hour to a cost objective today, that is the gap to close first, because it underpins both the accounting survey and everyday floor-check readiness.
- Map what kind of government information your likely work would touch, so you know whether you are looking at FCI, CUI, or neither, and size your cybersecurity effort accordingly.
None of this requires you to become a compliance expert overnight. It requires you to work the buckets in order and build the operational habits before an award forces the issue.
The manufacturers who move into government work smoothly are the ones who treated timekeeping and cost tracking as a discipline before their first cost-type bid, not a fire drill after it. When you reach the point of making timekeeping audit-ready, purpose-built systems exist for exactly this. AutoTime is a DCAA-compliant timekeeping and labor-tracking platform built for aerospace, defense, and government contractors, and it is designed around the Total Time Accounting and floor-check readiness that a pre-award survey looks for. If that is the gap on your list, it is a good place to start.