Compliance After Award: CMMC, ITAR, EVMS, Reporting
Winning a NASA contract creates a set of standing obligations that begin at kickoff and continue for the life of the contract.
Award is frequently treated as the finish line. In federal contracting it is closer to a starting gun. A contract that has been won carries obligations in cybersecurity, export control, cost and schedule reporting, performance documentation, and audit readiness that begin at kickoff and continue for the full period of performance.
Post-award kickoff
A post-award kickoff meeting, usually convened by the contracting officer and the program or technical lead, establishes the working relationship between the contractor and the government team: points of contact, reporting cadence, invoicing procedures, and any contract-specific administrative requirements. It is also the point at which a contractor should confirm its understanding of every compliance obligation flowed down through the contract's clauses, because those obligations do not wait for a formal notice to begin — they are effective on the contract's start date. For how those clauses got into the contract in the first place, see FAR and DFARS: What Actually Applies to You.
CMMC and NIST SP 800-171 for controlled unclassified information
Contracts that involve controlled unclassified information, or CUI, generally require safeguarding practices aligned with NIST Special Publication 800-171, a catalog of security controls covering access control, incident response, system monitoring, and related domains. The Cybersecurity Maturity Model Certification, or CMMC, is a framework built to verify that those controls are actually in place, at a level of rigor tied to the sensitivity of the information involved.
An organization does not claim to "have" CMMC in the way it might hold an ISO certification that never expires. It aligns its information systems, policies, and system security plan with the applicable NIST SP 800-171 controls on an ongoing basis, and undergoes whatever self-assessment or third-party assessment a specific contract's CMMC level actually requires. Treating this as a continuous posture rather than a one-time credential is the more accurate — and more defensible — way to describe it.
ITAR and EAR export control
Many NASA technical programs touch hardware, software, or technical data subject to export control. The International Traffic in Arms Regulations, administered by the State Department, govern defense articles and services identified on the U.S. Munitions List. The Export Administration Regulations, administered by the Commerce Department, govern a broader set of dual-use and less sensitive commercial items through the Commerce Control List.
Practical export control compliance includes correctly classifying technical data and hardware at the outset of a program, controlling access to that data by citizenship and need-to-know, screening foreign national employees and visitors, and obtaining any required licenses before information or items cross a controlled boundary — including, in many cases, disclosure to a foreign national employee working inside the United States, which can itself constitute a controlled "deemed export." Export control violations carry both civil and criminal exposure, and the obligation exists independent of contract size.
Earned value management and reporting thresholds
Earned value management, or EVM, is a method for measuring program performance by comparing planned work, completed work, and actual cost, producing schedule and cost variance metrics that flag problems earlier than a simple spend-to-date comparison would. NASA and other federal agencies require formal EVM reporting, generally aligned with the ANSI/EIA-748 standard, above defined dollar thresholds set by agency and Office of Management and Budget policy; contracts below those thresholds typically carry lighter cost and schedule reporting obligations instead of a full EVMS.
Where EVM applies, the contractor is expected to maintain an integrated baseline, submit periodic performance reports in the required format, and support integrated baseline reviews with the government program office. An EVM system that produces numbers the government does not trust is, in practice, worse than no system at all, because it invites deeper scrutiny of everything else the contractor reports.
CPARS
The Contractor Performance Assessment Reporting System is where government personnel record formal, periodic evaluations of a contractor's performance during and after contract execution. Ratings typically cover quality, schedule, cost control, management, and small business subcontracting where applicable. These records feed directly into the past performance evaluations used in future competitions, discussed in Past Performance: Building It When You Have None. A contractor generally has the opportunity to review and comment on a CPARS rating before it becomes final, and disputing an inaccurate rating through that process — promptly and in writing — matters more than disputing it after the fact in a future proposal.
Property and subcontract management
Contracts that provide government-furnished property, or that fund the acquisition of contractor-acquired property that becomes government property, carry specific accountability requirements: tagging, tracking, periodic inventory, maintenance, and proper disposition at contract closeout. Contracts with an approved purchasing system and significant subcontracted effort similarly carry obligations to manage subcontractors' performance, flow down required clauses, and, above defined thresholds, maintain and report against a small business subcontracting plan. See Subcontracting and Prime Teaming Agreements for how those flow-down obligations are structured going into the relationship.
Audits
Contract performance can trigger several kinds of government audit, most commonly through the Defense Contract Audit Agency, or DCAA, which examines incurred cost, billing systems, and accounting practices, and the Defense Contract Management Agency, or DCMA, which oversees contract administration and, on larger programs, EVM system compliance. An organization that maintains an adequate accounting system, timekeeping discipline, and clean supporting documentation from day one experiences an audit as a review of existing records. An organization that does not treats every audit as an emergency reconstruction project.
Common questions
Is CMMC a certification a company can already hold?
CMMC is a Department of Defense assessment framework built on NIST SP 800-171, and its applicability and rollout to civilian agencies including NASA has evolved over time. Rather than describing a company as "CMMC certified," the accurate framing is that an organization aligns its practices with the NIST SP 800-171 control set that CMMC is built around, and pursues whatever assessment level a given contract actually requires.
What is the difference between ITAR and EAR?
ITAR, the International Traffic in Arms Regulations, controls defense articles and services on the U.S. Munitions List and is administered by the State Department. EAR, the Export Administration Regulations, controls dual-use and less sensitive commercial items and is administered by the Commerce Department. Many aerospace technologies are ITAR-controlled, and misclassifying an item between the two regimes is a common and serious compliance failure.
Does every contract require a full earned value management system?
No. EVMS reporting requirements typically apply above defined dollar thresholds set by agency policy and the FAR/DFARS, and the specific reporting format and rigor scale with contract size and risk. Smaller contracts may have lighter cost and schedule reporting requirements without a full ANSI/EIA-748-compliant system.
What is CPARS and why does it matter beyond the current contract?
CPARS, the Contractor Performance Assessment Reporting System, is where government program and contracting personnel record formal ratings of a contractor's performance. Those ratings become the past performance record evaluators pull for future competitions, which is why performance on the current contract has direct consequences for winning the next one.
All Chapters
This guide is published as a public reference on federal acquisition practice. It is educational in nature, reflects publicly available regulation and agency guidance, and is not legal advice. Regulations change; verify current requirements against the FAR, the NASA FAR Supplement, and the governing solicitation. Monarch Space Systems makes no representation regarding any specific procurement.
Last Updated: August 19, 2026
Author: Business Development Division, Monarch Space Systems