EVMS data integrity: the system controls behind a compliant EVMS.
EVMS data integrity refers to the practices, records, and system capabilities, distinct from the EVM calculations themselves, that support trustworthy earned value management: how the performance measurement baseline is changed, how cost and schedule data are maintained, and whether rate changes and reprogramming actions leave a complete, reviewable record. A DCMA EVMS Compliance Review evaluates the system description, processes, tools, implementation, and data, so this evidence is part of readiness work rather than a prescribed checklist of IT controls.
This guide is general information, not accounting, legal, or contracting advice. Confirm current DCMA review criteria and ANSI/EIA-748 guideline text against the official sources.
A compliance review tests the system, not only the math.
The companion guide on earned value management covers the EVM methodology itself: planned value, earned value, actual cost, and the CPI and SPI indices those three values produce. That methodology can be applied correctly and the underlying system can still need attention in a DCMA EVMS Compliance Review, because a review also considers the system description, processes, tools, implementation, and data supporting those calculations. This makes baseline-change documentation, cost and schedule data governance, and traceable records for rate changes and reprogramming important readiness topics, while the specific controls depend on the contractor's system and procedures.
This guide covers that system-controls side specifically: baseline change control, access practices for cost and schedule data, and traceable evidence for rate changes and reprogramming actions, and how each connects to ANSI/EIA-748 guidance on controlled, documented, and reconcilable changes and auditable data.
Baseline change control decides whether the PMB can be trusted.
The performance measurement baseline is the yardstick earned value is measured against. If it can be changed casually, the metrics derived from it, including CPI, SPI, and the EAC, lose meaning. A contractor's system should document how changes are authorized, incorporated, and recorded.
Documented baseline ownership and change paths
A contractor may designate a system of record and define which roles can propose, review, approve, and implement performance measurement baseline (PMB) changes. The specific roles and workflow depend on the system description and program; the objective is a controlled, documented, and reconcilable process, not a universal CAM, program-manager, or change-control-board configuration.
Formal change request and approval
A baseline change may be supported by a documented request, an impact assessment on cost and schedule, and recorded authorization before it is incorporated, as appropriate to the contractor's process. Verbal or spreadsheet-only changes can make the record harder to reconcile, but EIA-748 does not prescribe one approval workflow.
Timely incorporation
SAE EIA-748E (2026) Guideline 24 calls for authorized customer-directed changes to be incorporated into the PMB in a timely manner. Guideline 25 separately requires internal replanning changes to be documented and reconciled. A change that sits unincorporated or unreconciled for months leaves performance measured against a baseline that no longer reflects the authorized scope.
Controlled treatment of changes to reported periods
SAE EIA-748E (2026) Guideline 26 requires retroactive changes to be controlled; it does not make every reported period untouchable. The guideline permits corrections of errors, routine accounting adjustments, customer-directed changes, management-directed changes, and single-point adjustments when controlled and documented. A contractor's process should document and reconcile any permitted adjustment to the current data.
Access controls keep cost and schedule data from being self-serving.
A correct calculation depends on reliable source data. Contractors should assess who can change the PMB, actual-cost, and schedule data and document the safeguards in the system description and procedures. The standard does not prescribe a universal access-control model.
Approval separation as an implementation option
A contractor may separate the person proposing a budget or baseline change from the person who reviews, approves, or implements it. This can make responsibility visible, but EIA-748 does not universally require requester, approver, and poster roles or a particular segregation-of-duties model.
Role-based access as an implementation option
A contractor may use separate or overlapping permissions for actual-cost, schedule, and PMB data. The appropriate profile depends on the architecture and procedures; EIA-748 does not require three distinct access profiles.
Least privilege where appropriate
Least-privilege permissions can be a sensible safeguard when a contractor designs access to cost, schedule, and baseline data. A contractor may limit a control account manager's write access to assigned control accounts, but this is a design choice rather than a universal EIA-748 or DCMA requirement.
Access review and role changes
A contractor may review access when roles change or on a cadence selected for its environment, and revoke permissions that no longer match the person's work. The frequency and method are implementation decisions, not a prescribed EVMS requirement.
Rate changes and reprogramming need a trail, not a memory.
Two categories of action can affect reported values without changing the underlying work: a rate change and a formal reprogramming of the baseline. Both can be legitimate. The records used to support each action should provide enough context for the contractor to explain, authorize, apply, and reconcile it; EIA-748 does not mandate one system-generated log format.
Indirect and labor rate changes
For an indirect or labor rate change, a contractor can assemble evidence showing when the new rate took effect, why it changed, how it was applied, and any relevant authorization or reconciliation. The supporting evidence may include system logs, change documentation, management reports, or other work products; EIA-748 does not mandate an immutable, system-generated log containing a particular set of fields. Because CPI is earned value divided by actual cost, a rate change that changes actual cost has a genuine cost-performance effect, commonly analyzed as a rate or indirect-cost variance.
Reprogramming actions (OTB/OTS)
An over-target baseline (OTB) occurs when the total allocated budget exceeds the contract budget base. The contractor formally rebaselines because the current budget is insufficient. An over-target schedule (OTS) occurs when the performance schedule extends beyond contractual milestones or delivery dates. Neither action changes the contract value or contractual schedule obligations. An OTB can also affect above-target budget and management reserve, and a reprogramming can be partial: DFARS 252.234-7002(h) requires the approval request to state whether existing cost and schedule variances will be retained or reset. The applicable authority depends on the contract: SAE EIA-748E (2026) Guideline 27 requires advance customer notification before implementation, while DFARS 252.234-7002(h), when included in the contract, requires a request for approval to initiate an OTB/OTS. The contractor should retain the applicable notification or approval and supporting change records; neither authority universally prescribes an identical business-case, approval, and effective-date audit trail.
Management reserve transactions
Movement of management reserve into a control account should be documented and reconciled under the contractor's baseline-change process. The form of evidence and review path depends on the system description, contract, and program procedures; the standard does not designate one universal request-and-approval trail.
Audit evidence can come from more than one source
A useful audit trail can combine system history with change documentation, management reports, reconciliations, or other work products. The objective is to make the change traceable and the data reliable and auditable; EIA-748 and DCMA guidance do not universally require an immutable system-generated log or prohibit all human-authored documentation.
Where ANSI/EIA-748 addresses revisions and data maintenance.
As the earned value management guide explains, ANSI/EIA-748 has historically grouped its guidelines into five categories, the last of which is revisions and data maintenance. The standard calls for timely incorporation of authorized customer-directed changes to the PMB under Guideline 24, documented and reconciled internal replanning changes under Guideline 25, and reconciling budget records whenever a change is made. Guideline 26 requires retroactive changes to be controlled, but it permits corrections of errors, routine accounting adjustments, customer-directed changes, management-directed changes, and single-point adjustments when controlled and documented; it does not categorically prohibit changes to already-reported periods. Access control and segregation of duties may help a contractor demonstrate these practices, but EIA-748 and DCMA do not prescribe a single IT-control design. A DCMA EVMS Compliance Review considers the contractor's system description, processes, tools, implementation, and data.
Confirm the current guideline count and structure against SAE EIA-748E (2026). Revision E reorganized the historical 32 guidelines into a smaller set. The underlying intent around baseline discipline and data integrity carries forward.
How Lightbridge ERP helps with EVMS readiness.
Lightbridge ERP is an independent, vendor-neutral readiness advisor with deep in-house expertise in government contract accounting. It can independently assess EVMS and ERP data-integrity readiness, help document options for access governance, segregation of duties, and audit evidence, and support implementation decisions whether the EVMS runs inside the ERP or in a specialized scheduling and cost tool layered on top of it. The Cognizant Federal Agency and Contracting Officer remain the acceptance authorities. Because Lightbridge accepts no vendor kickbacks, no reseller quotas, and no partner-tier incentives, its recommendations on where those practices should live are driven by fit rather than commission.
For the accounting foundation these controls sit on top of, see GovCon project accounting and DCAA-compliant accounting. For the EVM methodology these controls protect, see earned value management.
EVMS data integrity: frequently asked questions
- What does a DCMA EVMS Compliance Review actually check?
- A DCMA EVMS Compliance Review is a comprehensive assessment of the contractor's system description, processes, tools, implementation, and data against applicable EVMS criteria. It can consider how the contractor controls and reconciles the performance measurement baseline, cost and schedule inputs, and supporting records, alongside the EVM methodology. The review does not prescribe a single access matrix, segregation-of-duties model, or log design; the contractor should be able to explain how its documented processes produce reliable, auditable data.
- Who should be authorized to change the performance measurement baseline?
- The contractor's system description and procedures should identify how performance measurement baseline (PMB) changes are proposed, authorized, implemented, and reconciled. Some programs assign these steps to a control account manager, program manager, or change control board, but EIA-748 does not require those exact roles or a single system of record. The important point is a controlled, documented process that fits the program and supports reliable, auditable data.
- Why does DCMA care about access controls, not just the EVM calculations?
- Because reliable EVMS data depends on controlled processes, a review may examine how the contractor limits and documents changes to actual costs, schedule logic, and the PMB. The standard does not prescribe a particular access-control or segregation-of-duties implementation. SOX internal-control obligations and DCAA accounting-system reviews are separate contexts; neither creates a universal EVMS access-control requirement, and DCAA does not certify an accounting system as ‘DCAA compliant’: the contracting authority determines acceptability under applicable contractual, FAR, and DFARS criteria.
- What counts as an acceptable audit trail for a rate change?
- A review record for an indirect or labor rate change can include the old and new rates, effective date, reason, authorization, and application method when those details are relevant to the contractor's process. It may be supported by system logs, change documentation, management reports, reconciliations, or other work products; EIA-748 does not require an immutable, system-generated log with that exact field set. The contractor should be able to explain and reconcile the effect on reported cost data, including any rate or indirect-cost variance.
- What is an over-target baseline (OTB) and why does it need special controls?
- An over-target baseline (OTB) occurs when the total allocated budget exceeds the contract budget base. The contractor formally rebaselines because the current budget is insufficient. An over-target schedule (OTS) occurs when the performance schedule extends beyond contractual milestones or delivery dates. Neither action changes the contract value or contractual schedule obligations. An OTB can also affect above-target budget and management reserve, and a reprogramming can be partial: DFARS 252.234-7002(h) requires the approval request to state whether existing cost and schedule variances will be retained or reset. Under SAE EIA-748E (2026) Guideline 27, the contractor provides advance customer notification before implementation. DFARS 252.234-7002(h), when included in the contract, requires a request for approval to initiate an OTB/OTS. The applicable contract and process determine what supporting records are maintained; neither rule universally requires an identical business case, approval, and effective-date audit trail.
- How does EVMS data integrity connect to the ANSI/EIA-748 guidelines?
- SAE EIA-748E (2026) includes revisions and data maintenance guidance concerning authorized changes, timely incorporation, controlled treatment of retroactive changes, and reconciliation of budget records. Guideline 26 does not categorically prohibit retroactive changes; it allows controlled corrections and adjustments including errors, routine accounting adjustments, customer-directed changes, management-directed changes, and single-point adjustments. Access controls and segregation of duties can be implementation choices that help a contractor demonstrate its process, but they are not a single prescribed EIA-748 control. The companion earned value management guide covers the full ANSI/EIA-748 guideline structure and the metrics it governs.
- Does the ERP or the EVMS engine enforce these controls?
- It depends on the system architecture, and documenting that architecture is part of readiness. Some contractors run cost collection and control-account budgeting inside the ERP, with a specialized scheduling or EVMS tool layered on top for the schedule network and performance calculations; others run a dedicated EVMS engine that pulls actuals from the ERP. Wherever the line falls, the contractor should document how data moves across systems, how changes are governed, and how records are reconciled. Access controls, segregation of duties, and audit trails may be configured differently across architectures; DCMA does not prescribe one implementation.
- How does Lightbridge ERP help with EVMS data integrity?
- Lightbridge ERP is an independent, vendor-neutral readiness advisor with deep in-house expertise in government contract accounting. It can independently assess EVMS and ERP data-integrity readiness, identify gaps between a contractor's documented processes and applicable contract or review criteria, and support implementation decisions whether the EVMS runs inside the ERP or in a specialized tool that draws on it. The Cognizant Federal Agency and Contracting Officer remain the acceptance authorities. Because Lightbridge accepts no vendor kickbacks, no reseller quotas, and no partner-tier incentives, its recommendations on where practices should live are driven by fit rather than commission. This guide is general information, not accounting, legal, or contracting advice; confirm current DCMA review criteria and ANSI/EIA-748 guideline text against the official sources.
Prepare for an EVMS review.
Lightbridge ERP can independently assess EVMS data-integrity readiness and support vendor-neutral implementation decisions around baseline change control, access governance, and traceable evidence for rate changes and reprogramming.