Partial CUI Compliance

1 NIST 800-171 gaps detected. Not FedRAMP authorized. Popular among very small GovCon firms.

Accounting

PROCAS Accounting

by PROCAS

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

Accounting

Overview

PROCAS is a cloud-based project cost accounting system designed specifically for small government contractors. It offers DCAA-compliant timekeeping, indirect rate calculations, and project cost tracking at an accessible price point. Not FedRAMP authorized.

CUI Risk Assessment

Not FedRAMP authorized. Popular among very small GovCon firms.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

PROCAS Accounting has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO must remove PROCAS Accounting from the CUI authorization boundary in the System Security Plan within 30 days of migration decision per DFARS 252.204-7012 requirements.
  2. 2Contracts officer shall review all active contracts to identify DCAA audit requirements and coordinate migration timeline with government contracting officers.
  3. 3Sysadmin must export all project cost data from PROCAS including 7+ years of historical records required for DCAA compliance before account termination.
  4. 4ISSO shall evaluate FedRAMP authorized alternatives including Unanet GovCon Cloud and Deltek Costpoint Cloud based on contract CUI requirements and budget constraints.
  5. 5Legal counsel must review PROCAS data processing agreement to ensure secure data deletion post-migration and compliance with CUI handling requirements.
  6. 6ISSO must update POA&M to include migration milestones and target completion dates for NIST 800-171 control 3.13.8 remediation.
  7. 7Sysadmin shall configure new FedRAMP authorized system with equivalent DCAA-compliant features including indirect rate calculations and project cost tracking.
  8. 8ISSO must conduct user access reviews in new system to ensure least privilege principles per NIST 800-171 AC-6 requirements.
  9. 9Accounting manager shall validate data integrity post-migration by reconciling project costs and indirect rates against DCAA audit trails.
  10. 10ISSO must update authorization boundary diagram to reflect new FedRAMP authorized accounting system and submit revised SSP to authorizing official.

NIST 800-171 Violations

Using PROCAS Accounting for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

PROCAS Accounting has 1 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is PROCAS DCAA compliant?

PROCAS provides DCAA-compliant timekeeping and cost accounting features. However, it is not FedRAMP authorized, so if financial data includes CUI, document this as a risk acceptance.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This PROCAS Accounting CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures