Government Contracting

Federal Award Timekeeping

What our system does to support your labor-charging obligations under 2 CFR Part 200 and 2 CFR Part 910 Subpart F — daily entry, signatures, record locking and audit trail, mapped provision by provision.

Need a signed, dated statement for your auditor? Request one.

Start here: what a vendor can and cannot tell you

Customers routinely ask us for "written confirmation that the system is compliant with 2 CFR 200," or for third-party certification saying so. We will not provide either, because neither can be given honestly — by us or by anyone else.

  1. Compliance attaches to you, not to the software. The obligations in 2 CFR Part 200 and Part 910 run to the non-Federal entity expending Federal funds. A product cannot hold or discharge them. What it can do is produce the records against which your compliance is tested.
  2. Nobody certifies timekeeping software against these regulations. In particular, DCAA does not approve, certify or endorse commercial timekeeping products, and keeps no approved-products list. DCAA audits contractors.

So what follows is the artifact that is both honest and more useful to your auditor: a precise description of what the system does and what evidence it produces, mapped to the specific provisions. The capability claims below were checked against the Hour Timesheet source rather than written from marketing copy.

System capabilities

The four areas auditors ask about most often.

Daily entry

Time is recorded against a specific calendar work date and a specific authorized charge code, per employee, per day.

  • Hours are captured per employee, per day, per charge code — so total hours worked each day are recorded as a matter of course, the record § 200.430(g)(3) requires for nonexempt employees.
  • All compensated time sits on one timesheet — direct charges to Federal awards, other direct charges, indirect activity and leave alike. That is what lets the records reflect total activity on an integrated basis without exceeding 100%.
  • Automated reminders prompt employees to enter time, and separately alert supervisors to employees whose timesheets are missing.
  • Contemporaneous daily recording is ultimately a matter of employee practice and your own policy. The system prompts it and makes any departure from it visible in the audit trail — it cannot guarantee it.

Signatures

Employee submission and supervisor approval are each recorded as a discrete, attributed, timestamped event — each written as a new record rather than overwriting a prior one.

  • Every event records the action taken, the identity of the authenticated individual who took it, the date and time, an optional note (a rejection reason, for example), and the specific timesheet revision it applies to.
  • The signature is an attributed act, not a drawn image. Evidentiary value rests on authentication and role-based permissions rather than on a graphic that can be copied.
  • A signature is bound to the revision it signed. A later edit does not silently inherit an earlier approval — the timesheet shows as requiring approval again. This is the property that prevents an approval appearing to cover data altered after the fact.
  • Multi-level approval is supported where a recipient’s policy requires more than one reviewer; each approval is independently attributed.

Lock records

Records are restricted from modification once they progress through the approval workflow, and every locking event is recorded.

  • A timesheet in a submitted, approved or payroll-processed state cannot be edited in place. Correcting it means moving it back through the approval flow — itself an attributed, timestamped, recorded action requiring re-approval.
  • Time entries consumed by a payroll export are locked. Voiding that export unlocks them and routes the correction back through approval. Expense records lock on the same principle.
  • Locking, unlocking, marking processed and reverting a processed lock each generate their own audit event. An auditor sees not just that a record is locked, but who locked or unlocked it and when.
  • A reason is required to change historical time. Creating or editing a past-dated entry is rejected unless a written reason is supplied — enforced by default via a company setting, and on an edit the reason is retained with the entry itself as a durable note. Deletion is covered separately: a reason is a required field on every deletion request regardless of the entry’s date, recorded in the audit trail with the deletion event.

Audit trail

A comprehensive log records who did what, to which record, from where, and when — and the customer can export it without involving us.

  • Each entry records the authenticated user, the typed action, the resource acted upon, a human-readable description, the originating IP address where the request presents one, the device type, and a UTC timestamp.
  • Coverage extends past labor data to the controls governing it: user accounts and permission groups, account settings, charge codes, contracts and line items, indirect cost pools and rates, payroll exports, labor distribution postings, and billing vouchers.
  • Records are removed logically, not physically. Time entries, timesheets, expense records and audit-log entries are marked deleted rather than erased, so history stays intact and the trail is not truncated by ordinary user activity.
  • The audit trail exports to Excel and CSV, filtered as needed — so evidence reaches an auditor on the customer’s timetable, with no vendor request in the critical path.

Mapped to the regulation

The operative timekeeping provision is 2 CFR § 200.430(g), Standards for Documentation of Personnel Expenses, which requires that charges to Federal awards for salaries and wages be based on records that accurately reflect the work performed.

ProvisionRequirement (abbreviated)Supporting capability
§ 200.430(g)(1)(i)Supported by a system of internal control giving reasonable assurance charges are accurate, allowable and properly allocatedRole-based permissions; approval workflow with attributed signatures; record locking; enforced reason-for-change on historical time; audit trail covering data, configuration and access changes
§ 200.430(g)(1)(ii)Incorporated into the official records of the entityRecords held in the system of record and exportable in durable formats
§ 200.430(g)(1)(iii)Reasonably reflect total activity compensated, not exceeding 100%All compensated time — direct, indirect and leave — recorded on a single timesheet
§ 200.430(g)(1)(iv)Encompass federally-assisted and all other activities on an integrated basis (subsidiary records permitted where defined in the recipient's written policy)Federal and non-Federal activity captured together, not in separate subsystems
§ 200.430(g)(1)(v)Comply with the established accounting policies and procedures of the recipientConfigurable pay periods, charge code structure, approval levels, and indirect cost pools and rates
§ 200.430(g)(1)(vi)Support distribution of salary or wages among specific cost objectivesPer-entry charge code assignment; labor distribution reporting
§ 200.430(g)(1)(vii)Budget estimates alone do not qualify as support for charges to Federal awardsEntries record actual time worked against a specific date, entered by the employee — not a planned allocation
§ 200.430(g)(3)For nonexempt employees, records indicating total hours worked each dayEntries recorded against a specific work date, yielding total hours per day
§ 200.334Record retention requirementsLogical deletion preserving history; customer-controlled export
2 CFR 910 Subpart FRecipient’s compliance audit (GAGAS), with documentation available to DOE, the cognizant agency or GAOAuditable, exportable records of labor charging, approval and change history, available to the recipient’s auditor on request

A note on 2 CFR Part 910 Subpart F

Subpart F governs audits of the recipient. Under § 910.501, a for-profit entity expending Department of Energy funds at or above the applicable threshold must obtain a compliance audit conducted in accordance with GAGAS (§ 910.514), with audit documentation retained and made available to DOE, the cognizant agency for indirect cost, or GAO (§ 910.517), and the reporting package submitted to DOE and retained for three years (§ 910.512).

The codified threshold in § 910.501 is $750,000. DOE Policy Flash 2025-02 issued a class deviation raising it to $1,000,000 for recipient fiscal years beginning on or after 1 October 2024, aligning with OMB's change to 2 CFR Part 200 Subpart F. Confirm the currently applicable figure with your contracting officer.

Subpart F imposes no requirement on a software vendor. Its practical bearing here is that your auditor will test labor charges against the records described above — and you can export those records and hand them over directly, on your timetable, without a vendor request in the critical path.

What we do not claim

Stated plainly, because a compliance statement that overstates is worse than none.

We do not certify your compliance

Obligations under 2 CFR Part 200 and Part 910 attach to the recipient of the Federal award. They depend on your written policies, your configuration choices and your personnel’s day-to-day practice — none of which is within a vendor’s knowledge or control.

No third-party certification of timekeeping software exists

DCAA does not approve, certify or endorse commercial timekeeping software, and maintains no approved-products list. No vendor can supply such a certificate. Any vendor claiming a "DCAA certification" is misrepresenting — if you have been told otherwise, we are glad to discuss it directly.

The determination you may actually need is different

Where a government customer requires assurance about an accounting system, the determination is ordinarily made by the cognizant government agency about the contractor’s system as a whole — for example a pre-award accounting system survey (SF 1408) performed by DCAA at a contracting officer’s request. Timekeeping is one element of that review. This statement is intended as evidence within such a review, not a substitute for one.

We hold no SOC 2, ISO 27001 or FedRAMP authorization for the application

The application is hosted on Amazon Web Services, which maintains its own certifications for the infrastructure layer. We do not represent AWS’s certifications as our own.

Configuration matters

Capabilities such as multi-level approval, reminder cadence and the reason-for-change requirement are configurable. Whether they are enabled, and how, is your decision. We are glad to review your configuration against your own policy on request.

This statement describes Hour Timesheet

The capabilities described here were verified against the Hour Timesheet platform. LMNTL sells more than one timekeeping product, and this statement should not be relied on for any other — if you are evaluating or running something else, ask us and we will confirm what applies to it in writing.

Need this signed for an auditor?

We issue a dated statement of system capability addressed to your legal entity, signed by our CEO, suitable for inclusion in an audit file. We will also review your configuration against your own timekeeping policy.

Content last reviewed August 2026. This page describes system capability; it is not legal advice and does not certify any recipient's compliance.