Custom Software for Aerospace & Defense
Secure, flexible, and compliant architecture tailored for the unique challenges of the Aerospace & Defense sector.
Vivek Mishra — Founder & Lead Architect, ERPStack
Quick Answer
In short: an aerospace and defense ERP is traceability with export control on top. ERPStack builds custom software that produces AS9102C First Article Forms 1, 2 and 3, holds heat-lot traceability back to the mill certificate, enforces ITAR deemed-export rules through RBAC, and carries CMMC Level 2 controls under 32 CFR 170.
Why Custom ERP for Aerospace & Defense?
Operating in the Aerospace & Defense sector requires a systems architecture designed for high scalability, operational flexibility, and strict regulatory compliance. Standard off-the-shelf software forces your teams to reshape their workflows to fit rigid software packages. A custom ERP for the Aerospace & Defense industry maps directly to your exact business logic. Deployed to your secure cloud infrastructure (AWS or Azure), the system isolates database schemas, automates redundant reporting tasks, and scales without user seat licensing fees. This ensures your corporate data remains under your absolute control, eliminates vendor lock-in, and lowers long-term operational technology costs by up to 70% over a 3-year period.
Industry Pain Points
- AS9102C First Article Forms 1, 2 and 3 rebuilt in Excel at every drawing revision
- Heat lot and mill certificate in a scan folder, not a PostgreSQL row against the serial
- Teamcenter holds the as-designed BOM while the ERP holds a conflicting as-built one
- ITAR technical data reachable by a foreign national on the domestic network — a deemed export
- DO-178C requirement-to-test traceability maintained by hand, outside any database
- Per-seat pricing on SAP S/4HANA or Epicor keeping inspectors off the aerospace system
Engineering Blueprint
Aerospace has a traceability floor no other vertical shares: a serialised part must resolve back to the raw-material heat lot and the mill certificate that shipped with it. ERPStack makes that lineage the spine of the aerospace ERP schema in PostgreSQL, not a PDF attached afterwards.
Four configurations, one revision table
Siemens Teamcenter and Dassault ENOVIA own the as-designed bill of materials; the ERP owns as-planned and as-built; the maintenance record owns as-maintained. In aerospace that disagreement is the audit finding. ERPStack resolves all four from one effectivity-dated table in Drizzle ORM on PostgreSQL, so a serial built in 2021 still explains itself against the drawing revision in force that day. SAP S/4HANA, Epicor and Infor each model one or two of the four convincingly, so the honest route off them is the Strangler Fig Migration Pattern — aerospace quality records first, MRP last.
AS9102C first articles, generated not typed
AS9102C (SAE, revised June 2023) is not a principle, it is three filled-in forms: Form 1 part number accountability, Form 2 materials and special processes, Form 3 characteristic accountability. Most aerospace suppliers rebuild them in Excel every revision. ERPStack emits them from PostgreSQL — each ballooned characteristic a row, each Nadcap-accredited special process a dated supplier approval validated by Zod, each AS5553E counterfeit-parts check hanging off the same part record under the AS9100 aerospace standard.
// Drizzle ORM on PostgreSQL — AS9102C Form 3 characteristic accountability
export const faiCharacteristics = pgTable('fai_characteristics', {
serialNumber: text('serial_number').notNull(),
balloonNumber: integer('balloon_number').notNull(),
drawingRev: text('drawing_rev').notNull(),
heatLot: text('heat_lot').notNull(), // mill certificate key
nadcapProcessCode: text('nadcap_process_code'),
measured: numeric('measured', { precision: 12, scale: 5 }),
usmlCategory: text('usml_category'), // ITAR access predicate
recordedAt: timestamp('recorded_at').defaultNow().notNull(),
});Certification evidence is a database join
RTCA DO-178C for airborne software, DO-254 for airborne electronic hardware, ARP4754B (revised December 2023), ARP4761A for safety assessment and DO-326A for airworthiness security all demand one artefact: bidirectional traceability from requirement to test to result. FAA AC 20-115D recognises DO-178C dated 13 December 2011; AC 20-152A, of 7 October 2022, covers DO-254 hardware at design assurance levels A to D. An aerospace ERP is ground support, so DO-178C never applies to it — but holding that traceability as a PostgreSQL join makes the pack regenerable rather than reconciled by hand.
Terminals, not seats
Inspection benches, bond rooms and aerospace line stations all need a screen. ERPStack ships them as Next.js and TypeScript terminals against a REST and GraphQL API, so adding a goods-receiving station is a deployment rather than a Software License Audit conversation — the structural difference from NetSuite, Odoo or Microsoft Dynamics 365 per-seat pricing.
Our Solutions
- AS9102C Form 1/2/3 generated from the PostgreSQL characteristic table, never re-typed
- Serialised lot genealogy in Drizzle ORM down to heat lot and mill certificate
- As-designed, as-planned, as-built and as-maintained from one effectivity table
- Row-Level Security and RBAC by nationality and USML category for ITAR deemed exports
- Requirements-to-test traceability as a PostgreSQL join, exported as DO-178C evidence
- Next.js and TypeScript inspection terminals on an AWS GovCloud enclave, no per-seat licence
Compliance & Security
In aerospace there is never one audit. Export control, cyber certification, government cost accounting and continued airworthiness each interrogate the same PostgreSQL database and each wants a different answer out of it.
ITAR deemed exports are an RBAC problem
22 CFR 120.50 makes releasing technical data to a foreign person inside the United States an export, and 120.50(b) deems it an export to every country of that person’s citizenship; the EAR repeats it at 15 CFR 734.13(a)(2). ERPStack attaches nationality and programme to the row, not the folder: Row-Level Security in Postgres, RBAC by USML category, SSO with short-lived JWT claims, and an aerospace enclave in AWS GovCloud — us-gov-west-1 or us-gov-east-1, provisioned with Terraform — not a shared multi-tenant estate.CMMC suspended the gate, not the duty
32 CFR part 170 took effect 16 December 2024 and the DFARS acquisition rule at 90 FR 43560 on 10 November 2025, starting Phase 1. A Department of War memorandum of 10 July 2026 then suspended the Phase 2 rollout due 10 November 2026, referring it to a CMMC Reform Task Force with 60 days to report. Read that precisely: DFARS 252.204-7012 and NIST SP 800-171 still bind, Level 2 is still the 110 Revision 2 requirements though Revision 3 landed in May 2024, and Phase 1 self-assessment stands — only third-party verification paused, so an aerospace supplier treating it as a reprieve keeps full False Claims Act exposure. ERPStack builds the system producing that evidence, the SPRS score and the SOC 2 and ISO 27001 artefacts primes ask for; the certification is yours to hold, not ours.Defence cost accounting is a schema, not a report
DFARS 252.242-7006 lists 18 accounting-system criteria: direct segregated from indirect, costs accumulated by contract under general ledger control, a timekeeping system that identifies labour by cost objective, and exclusion of FAR part 31 unallowables. ERPStack implements Certified Timesheet Tracking against those cost objectives in PostgreSQL, so earned value under SAE EIA-748E — revised 17 February 2026 — comes from the same postings that bill the government contract, not a parallel model.The aftermarket half generic ERPs skip
14 CFR 91.417(a)(2) reads like a schema: total time in service for airframe, each engine, propeller and rotor; life-limited part status; time since last overhaul; and airworthiness directive status with the method of compliance, the AD number and revision date, and when recurring action next falls due. 14 CFR 43.10 makes life status in cycles or hours travel with the part when sold. ERPStack ingests service bulletins with Idempotency in API Design keyed on the AD number and holds the result as an Immutable Audit Trail in Postgres — those aerospace records move with the aircraft, and a missing one costs more than the part.
Standards we engineer to
- AS9100D
- AS9102C
- AS5553E
- RTCA DO-178C
- ITAR 22 CFR 120-130
- CMMC Level 2 (32 CFR 170)
- NIST SP 800-171
Get the Blueprint
Download our comprehensive Systems Architecture Blueprint to see how we architect compliant solutions.
Download BlueprintMetrics & Integrations
Illustrative engineering targets for this sector — the SLAs and capacities we design and build toward, not a live service dashboard.
AS9102C Form 1/2/3 export from PostgreSQL
Serialised lot genealogy depth
ITAR deemed-export RBAC decision
DO-178C trace matrix rebuild
Integration: Siemens Teamcenter
Integration: Dassault ENOVIA
Integration: SAP S/4HANA
Integration: IFS Cloud
Integration: SPRS
Integration: AWS GovCloud (US)
Implementation Process
Characteristic accountability map
Every drawing balloon becomes a PostgreSQL row in the AS9102C Form 3 table.
Export-control data model
Nationality, programme and USML category on every row, enforced by RBAC.
Configuration baselines
Four aerospace configurations resolved from one Drizzle ORM effectivity table.
Certification evidence join
Requirements, tests and results linked bidirectionally for DO-178C and DO-254 packs.
Government accounting ledger
The 18 DFARS criteria and EIA-748E earned value from one PostgreSQL ledger.
Strangler Fig cutover
Aerospace quality records migrate first; legacy MRP stays authoritative until variance clears.
Frequently Asked Questions
Three completed forms, generated from live data. AS9102C, revised by SAE in June 2023, defines Form 1 for part number accountability, Form 2 for materials and special processes, and Form 3 for characteristic accountability. An aerospace ERP that holds every ballooned characteristic, heat lot and Nadcap-accredited process as a PostgreSQL row emits all three on demand, instead of rebuilding them in Excel at each revision.
By putting nationality into the access predicate. Under 22 CFR 120.50 releasing technical data to a foreign person inside the United States is itself an export — a deemed export — and 120.50(b) extends it to every country of that person's citizenship. ERPStack builds aerospace systems where Row-Level Security in PostgreSQL and RBAC by USML category decide row visibility, so the control is structural, not a training slide.
Often yes, and it is worth saying plainly. IFS carries real aerospace MRO depth — line maintenance, rotable pools, component histories — and SAP S/4HANA carries programme and cost structures that Epicor or NetSuite will not match. A custom aerospace ERP earns its place only where the differentiating process will not bend: back-to-birth reconstruction, a customer-specific first article dialect, an export-control model the package cannot express.
Down to the heat lot and the mill certificate. The defensible aerospace claim is that a serialised assembly resolves to the specific melt of raw material and the certificate that came with it, through every lot split and special process. ERPStack models that genealogy as an append-only graph in PostgreSQL with Drizzle ORM, so a recall walks upward from tail number to heat lot as a single query.
Phase 1 has applied since 10 November 2025, the effective date of the DFARS acquisition rule at 90 FR 43560; the CMMC Program rule at 32 CFR part 170 took effect on 16 December 2024. Phase 2, which was due on 10 November 2026, was suspended by a Department of War memorandum dated 10 July 2026 pending a CMMC Reform Task Force review. Phase 1 self-assessment obligations on aerospace and defense suppliers are unchanged.
No. The suspension paused the audit, not the obligation. The Department of War memorandum of 10 July 2026 halted the Phase 2 rollout and the third-party verification it would have required, but DFARS 252.204-7012 and NIST SP 800-171 still apply to every aerospace and defense contract carrying covered defense information, and Phase 1 self-assessment stands. A supplier that stops work now keeps its full False Claims Act exposure and only loses the head start.
Yes, because bidirectional traceability is a join, not a document. DO-178C for airborne software and DO-254 for airborne electronic hardware both require every requirement to reach a test and every result to reach a requirement. Modelled as foreign keys in PostgreSQL, an aerospace certification pack regenerates in seconds and orphan requirements surface as a query, not as a finding during FAA or EASA review.
Both, for different configurations — that is the real aerospace answer. Teamcenter or ENOVIA holds as-designed, the ERP holds as-planned and as-built, the maintenance record holds as-maintained. Instead of forcing one master, ERPStack keeps a single effectivity-dated revision table in Drizzle ORM on PostgreSQL from which all four views resolve, so the disagreement becomes a reportable delta rather than an audit finding.
As first-class records, because 14 CFR 91.417(a)(2) already names the fields: time in service for airframe, engine, propeller and rotor; life-limited part status; time since overhaul; and airworthiness directive status with method of compliance, AD number, revision date and next due point. 14 CFR 43.10 makes life status travel with the part on sale, so an aerospace ERP holds it as an Immutable Audit Trail.
Inside, provided the postings agree. SAE EIA-748E, revised 17 February 2026, expects the performance measurement baseline to reconcile to actual costs recorded in the accounting system, and DFARS 252.242-7006 imposes 18 criteria on that system. A separate aerospace EVMS means two truths and a monthly reconciliation; one PostgreSQL ledger carrying cost objectives and Certified Timesheet Tracking means one.