FedRAMP Authorized — Moderate Impact

Deltek Costpoint Cloud by Deltek. 6 compliance features verified.

Finance & Accounting

Deltek Costpoint Cloud

by Deltek

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

mid market

Authorization Date: September 10, 2019 | Sponsoring Agency: GSA

Overview

Deltek Costpoint Cloud provides FedRAMP Moderate authorized project-based ERP designed specifically for government contractors. It offers project accounting, procurement, and compliance management tailored to FAR/DFARS requirements. The platform is the industry standard for government contract accounting and DCAA audit readiness.

Key Features

FedRAMP Moderate baseline controls
Government contract accounting
DCAA audit-ready reporting
FAR/DFARS compliance
Indirect rate management
Project cost tracking

Certifications & Authorizations

FedRAMP Moderate Authority to Operate (ATO)DoD SRG Impact Level 4 (IL4) certificationSOC 2 Type II complianceISO 27001:2013 certifiedFIPS 140-2 Level 1 encryption modulesNIST 800-171 compliant architectureGSA approved for government contractor use

Deployment Options

AWS GovCloud (US-West) — IL4 certified multi-tenant SaaS
AWS GovCloud (US-East) — IL4 certified multi-tenant SaaS
Dedicated tenant instance on AWS GovCloud for IL5 workloads
Hybrid cloud integration with on-premises Active Directory
Government Community Cloud (GCC) deployment option
Private cloud hosting via Deltek's FedRAMP authorized data centers

NIST 800-171 Compliance Coverage

87% of controls covered

How to Procure Deltek Costpoint Cloud for Defense Contracts

Deltek Costpoint Cloud is available through GSA Multiple Award Schedule (MAS) 70 under SIN 518210C (ERP Software) and SEWP V contracts. Government pricing typically offers 15-25% discount from commercial rates, with additional volume discounts for multi-year commitments. Contracting officers must ensure the authorization boundary includes all integrated modules (Project Accounting, Procurement, Time & Expense) in the System Security Plan. The FedRAMP P-ATO package includes detailed architecture diagrams, security controls matrix, and continuous monitoring procedures required for agency ATO approval. Procurement timeline typically spans 4-6 months including security review, configuration, and user acceptance testing. For contractors requiring CMMC Level 2 compliance, Costpoint Cloud must be included in your assessment boundary as it processes and stores Controlled Unclassified Information (CUI) including contract performance data, employee records, and financial information. Ensure your CMMC assessment scope document explicitly identifies Costpoint Cloud data flows and inheritance of security controls. Request Deltek's CMMC inheritance documentation and customer responsibility matrix during procurement to streamline your assessment preparation.

Compliance Cross-References

Deltek Costpoint Cloud's FedRAMP Moderate authorization directly supports DFARS 252.204-7012 compliance through its NIST 800-171 aligned security controls including Access Control (AC-2, AC-3, AC-17), System and Communications Protection (SC-7, SC-8, SC-13), and Audit and Accountability (AU-2, AU-3, AU-12). The cloud deployment satisfies DFARS 252.239-7010 requirements for adequate security and DoD-approved cloud service providers. For CMMC Level 2, Costpoint Cloud addresses Access Control (AC.L2-3.1.1 through AC.L2-3.1.22), Audit and Accountability (AU.L2-3.3.1 through AU.L2-3.3.9), and System and Communications Protection (SC.L2-3.13.1 through SC.L2-3.13.16) domains through inherited controls. The DoD Cloud Computing SRG Impact Level 4 certification ensures compliance with Mission Owner requirements for processing CUI in cloud environments, providing the necessary security control inheritance for contractor compliance obligations.

Defense Contractor Use Case

Defense contractors use Deltek Costpoint as their primary ERP for government contract accounting, ensuring DCAA compliance, managing indirect rates, and tracking costs across multiple contracts.

Frequently Asked Questions

What is the FedRAMP authorization level for Deltek Costpoint Cloud?

Deltek Costpoint Cloud is authorized at the FedRAMP Moderate impact level, with authorization granted on 2019-09-10 sponsored by GSA. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use Deltek Costpoint Cloud for CUI?

Deltek Costpoint Cloud is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does Deltek Costpoint Cloud pricing compare to commercial?

Deltek Costpoint Cloud government pricing is generally competitive with commercial pricing, though the government edition may carry a premium of 10-20% to cover FedRAMP compliance and dedicated infrastructure costs. Mid-market organizations can often access government pricing through GSA Schedule contracts or reseller partners. Contact Deltek for a quote tailored to your organization size and requirements.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Deltek Costpoint Cloud FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures