Back to Blog

How to Make QuickBooks Online DCAA-Compliant: A Step-by-Step Guide

You already run on QuickBooks Online and just landed — or are chasing — a cost-type government contract. Here's how to make QBO DCAA-compliant step by step, without ripping out your books for an ERP.

You already run your books on QuickBooks Online. Now you've won, or you're pursuing, a cost-type government contract, and someone has told you your accounting system needs to be "DCAA-compliant." The question that follows is almost always the same: do I have to abandon QuickBooks and migrate to Deltek or Unanet?

The short answer is no. QuickBooks Online is not DCAA-compliant out of the box, but it can become the foundation of a system that is, with the right structure and a compliance layer on top. This guide walks through exactly how to get there, step by step, whether you're setting up in advance or closing gaps under time pressure.

First, What "DCAA-Compliant" Actually Means

There's a persistent myth to correct before you change a single setting: there is no such thing as DCAA-approved accounting software. The Defense Contract Audit Agency does not certify or bless any product — it evaluates whether your system can produce reliable, supportable contract cost information.

This point came up directly in our first compliance webinar, when Sarah Sun, CPA, of Wendroff & Associates described asking a DCAA auditor whether the agency prefers a particular platform:

What we've seen in practice "We asked the exact question to a DCAA auditor — does DCAA have a preferred accounting software? The answer was no. They evaluate the system's capability and compliance, not the software brand."

Sarah Sun, CPA — Wendroff & Associates, CPA

"Making QuickBooks DCAA-compliant" isn't about a checkbox inside QBO. It's about building a system — software plus process — that can answer an auditor's core questions: can you separate direct costs from indirect, track costs by contract, support your labor charges, and preserve documentation for all of it?

What we've seen in practice "An adequate accounting system is much more than accounting software. It's a combination of the accounting platform, your company's policies, your timekeeping practices, and your internal controls — all working together."

Sarah Sun, CPA — Wendroff & Associates, CPA

The steps below are part software configuration, part process discipline — and neither works alone.

What QuickBooks Online Already Gives You

Before listing the gaps, here's what QuickBooks already does well.

It runs on accrual-basis, double-entry bookkeeping with a full general ledger, which satisfies the first thing an auditor checks: GAAP compliance. You can produce a balance sheet, a profit-and-loss statement, and a trial balance at any time.

Its chart of accounts is flexible enough to separate costs into the pools government contracting requires. Its class tracking maps naturally onto contracts, giving you the subsidiary job-cost ledger DCAA expects. And it posts journal entries — the mechanism you'll use to record labor distribution.

In other words, QuickBooks handles the money. What it lacks is the government-contracting layer that sits on top of the money: who worked on what, for how long, approved by whom, and posted where. That's the gap you're closing.

Where QuickBooks Online Falls Short

There are four gaps, and everything in this guide is aimed at closing them.

Compliant timekeeping. QBO's built-in time feature doesn't enforce daily recording, doesn't capture an immutable record of who entered or changed an entry, doesn't support a supervisor approval workflow, and doesn't require employees to account for all their hours — only the billable ones.

A labor distribution engine. There's no native way in QBO to take approved timesheets, calculate each employee's actual hourly rate, allocate their wages across contracts and indirect pools with penny precision, and generate the resulting journal entry.

An immutable audit trail for time. QBO logs financial transactions, but it doesn't preserve the granular, tamper-proof timekeeping trail an auditor wants to see.

Approval and correction controls. DCAA expects timesheets to be submitted, reviewed, approved, and locked — and corrections to be handled by reversing posted entries, never deleting them. QBO allows deletion, which is a compliance risk.

The steps below close all four.

Step 1 — Structure Your Chart of Accounts by Cost Pool

Everything downstream depends on this. Your chart of accounts needs to cleanly separate five categories of cost:

Direct — labor, materials, subcontracts, and travel that benefit a single contract. Fringe — benefits tied to labor (payroll taxes, health insurance, retirement, PTO). Overhead — costs that support your billable work broadly but not one contract (overhead labor, technical supervision, recruiting, equipment). G&A — the cost of running the company (executives, accounting, legal, business insurance, bid & proposal). Unallowable — costs that can never be billed to the government under FAR Part 31 (entertainment, alcohol, lobbying, fines), segregated into their own accounts so they never flow into a rate applied to a contract.

Depending on your size and contract mix, you may also break out Facilities — rent, utilities, network, depreciation — as its own indirect pool instead of folding it into Overhead, which gives you a cleaner Overhead rate. Whether to keep it separate depends on your indirect rate structure, so confirm it with your CPA.

If your current chart of accounts is a flat list of expenses, restructuring it now — before you have cost-type transactions — is far easier than reclassifying a year of history later. For the account-by-account breakdown of each pool — plus a ready-to-import template — see our guide to the right chart of accounts for GovCon in QuickBooks Online. And for how these categories work in practice, see direct vs. indirect costs in government contracting.

Step 2 — Turn On Class Tracking and Map Classes to Contracts

In QuickBooks Online, classes are how you identify direct costs by contract. Enable class tracking, then create one class per contract (using the contract number or a readable abbreviation) plus classes for your indirect pools.

Once that's in place, running a Profit & Loss by Class report shows revenue and costs broken out contract by contract. That report is the subsidiary job-cost ledger DCAA looks for, and it's the same view that later tells you which contracts are actually profitable. Consistency is everything here: everyone on the team has to use the same identifiers, every time.

Step 3 — Add Compliant Timekeeping (the Biggest Gap)

This is where bare QuickBooks can't take you the rest of the way, and it's the single most scrutinized area in a DCAA audit. A compliant timekeeping process has to do four things QBO's time feature doesn't enforce:

Record daily. Time is entered the day the work happens, not reconstructed on Friday afternoon. Auditors check timestamps for exactly this.

Account for all hours. Every hour of the workday is recorded — direct and indirect — not just the billable ones. This is the failure Sarah flagged as one of the most common she sees:

What we've seen in practice "One common issue is that the employee will only record the billable hours. Without the time entry for all direct and indirect hours, the indirect cost pools won't have the correct information, and then the allocation of indirect costs won't be correct either."

Sarah Sun, CPA — Wendroff & Associates, CPA

Route through approval. The employee submits; a supervisor with direct knowledge of the work approves or returns it; the period locks.

Stay attributable. Every entry and every edit is stamped with who did it and when.

Because QBO doesn't do this natively, you close the gap with a timekeeping layer that connects to QuickBooks rather than replacing it, which is the whole idea behind running a compliance layer on top of the books you already use.

Step 4 — Run Labor Distribution and Post the Journal Entry

This is the step that turns approved hours into contract costs, and where "tracking labor costs for a government contract in QuickBooks" actually happens. The mechanics matter, and one detail trips up almost everyone.

Calculate each employee's hourly rate by dividing their pay for the period by the hours they actually recorded, not by a flat 40. In our webinar series, WiseCost co-founder Alfonso Aguilera stressed this point:

What we've seen in practice "For the DCAA it's really important that you divide the wage and the salary by the effective hours, not by the total hours. If your employee works 40 hours a week, you shouldn't just divide by 40, you divide by every hour the employee registered in the time tracker."

Alfonso Aguilera — Co-founder, WiseCost

From there: multiply each employee's hours per class by their rate, split the result into direct labor (by contract) and indirect labor (Fringe, Overhead, and G&A), add a single balancing credit line, and reconcile so the total distributed equals payroll for the period to the penny. The result is posted to QuickBooks as a journal entry.

That penny-precise math and the rounding methodology behind it are worth understanding in full — we cover them in labor distribution for government contractors.

Step 5 — Preserve an Immutable Audit Trail (Reverse, Never Delete)

DCAA expects to see what changed, when, and who changed it, and it expects the original record to survive. That means corrections are never made by deleting. If an approved timesheet needs a fix, the period is formally reopened, the correction goes back through approval, and if a journal entry was already posted, you create a reversing entry and then a new one. The original is never removed.

This is exactly where the common do-it-yourself stack falls apart. Alfonso described the pattern we see repeatedly:

What we've seen in practice "We saw contractors tracking time in Clockify with the correct approvals, then exporting that information and running the labor distribution in a Google Sheet, and in that process, when the auditor asks you for the trail, you don't have every movement registered in an immutable way."

Alfonso Aguilera — Co-founder, WiseCost

The lesson isn't "Clockify is bad." It's that the moment your compliant records leave a controlled system for a spreadsheet, the audit trail breaks. Whatever you use, the trail from time entry to posted journal entry has to stay intact and tamper-proof.

Step 6 — Run One Full Cycle and Self-Walk-Through

Before an auditor ever asks, prove the system to yourself. Run a complete pay period end to end — employees record time, supervisors approve, you run labor distribution, journal entries post — then trace a single entry all the way through: time entry → approved timesheet → labor distribution → journal entry → general ledger → Profit & Loss by Class.

If you can follow that trail without a gap, so can the auditor. You can also pressure-test your setup against the DCAA's own Pre-award Accounting System Adequacy Checklist (SF-1408) before anyone else does. If you hit a dead end, fix it now, while there's no contracting officer waiting on the result.

What We've Seen in Practice

The contractors who struggle aren't usually the ones with a badly designed system — they're the ones whose day-to-day process doesn't hold together. And the root of it is often a misunderstanding of what QuickBooks can and can't do on its own.

What we've seen in practice "More than 90% of government contractors, especially small and mid-size ones, are using QuickBooks, and QuickBooks is a great, friendly tool. But QuickBooks doesn't have the tools and the capability to give you a compliant accounting system. So instead of forcing everyone onto a heavy ERP, we designed a fourth way: a layer that works on top of QuickBooks Online, so you don't need to migrate your whole system."

Alfonso Aguilera — Co-founder, WiseCost

Do You Need a Tool, or Just Discipline?

It depends on your size. For one or two people on a single contract, you can run labor distribution by hand in a spreadsheet — it's a handful of line items. Past that, the manual approach starts to break, not on the math but on the two things auditors care about most: an unbroken audit trail and penny-precise reconciliation every period.

From there you have two legitimate paths. Replace QuickBooks with an enterprise ERP like Deltek or Unanet — comprehensive, but expensive, slow to implement, and a full migration away from the books your team and CPA already know. Or keep QuickBooks and add a compliance layer that handles timekeeping, approvals, labor distribution, and DCAA-safe journal entries on top of it.

We walk through that decision in detail in QuickBooks Online for government contractors: can you stay DCAA-compliant without an ERP?, and the complete set of requirements behind all of this in our guide to DCAA-compliant accounting systems.

The Bottom Line

QuickBooks Online won't pass a DCAA audit on its own, but you almost certainly don't need to abandon it. Structure your chart of accounts by pool, map classes to contracts, add compliant timekeeping, run labor distribution the right way, and preserve an immutable trail from time entry to general ledger. Do that, and QuickBooks becomes the foundation of a system that stands up to scrutiny.

It costs far less to build this before a contract award than to reconstruct it once a contracting officer is asking.


Setting up for your first cost-type contract? Start with our step-by-step accounting system setup guide, then see how the pieces fit together in the complete DCAA-compliant accounting system guide.