Industry guide · ERP

Aerospace Manufacturing Software for AS9100 Suppliers: Problems, Solutions, and What It Costs to Build

The short answer

If your first articles, mill certs, and special process records live outside your ERP (Enterprise Resource Planning) and get retyped into Excel, you are already paying for custom software in labor, you are just not getting an asset for it. Build when your quality headcount is growing faster than your revenue, when a prime's portal drives your part numbering, or when an escape takes more than a day to trace. Digital Heroes has delivered 2,000+ projects, and in this category a focused first release (characteristic-level FAI engine plus traceability spine) typically runs $60k to $130k and ships in 12 to 16 weeks, with a full quality and shop platform at $150k to $400k phased over 6 to 12 months. Keep E2 or Kinetic for jobs and inventory. Build the layer they were never designed to hold.

Why aerospace supplier software makes or breaks an AS9100 supplier

It is 6:40 on a Monday and your quality engineer is on hour three of a first article. The part is a machined bracket for a nacelle assembly: 212 characteristics on the ballooned print. The balloons came out of InspectionXpert. The CMM data came out of PC-DMIS as a text report. The AS9102 Rev C Form 3 is an Excel template somebody built in 2016, and she is alt-tabbing between three windows typing measured values into cells, because your ERP has no concept of a characteristic. At 9:15 the prime pushes a drawing revision through Exostar. Two of the 212 characteristics moved. You now owe a partial FAI, and there is no button anywhere in your stack that tells you which two.

This is the normal operating model for suppliers between roughly $8M and $80M in revenue. The stack looks like this: E2 Shop System or JobBOSS2 or Global Shop Solutions or Epicor Kinetic for jobs, routers, and inventory. A SharePoint or Dropbox tree named by job number for mill certs and C of Cs. Net-Inspect because Boeing or Honeywell told you to use it. High QA or InspectionXpert for ballooning. Excel for gage calibration and shelf-life on sealants. A whiteboard for MRB. Email for supplier corrective action requests. Not one of those systems agrees with the others on what a part number, a revision, or a lot is, so a human is the integration layer.

Across our aerospace and precision manufacturing engagements, the consistent pattern Digital Heroes sees is that quality headcount grows faster than revenue. A $30M shop with nine people in quality, and when we shadow them, 30 to 40 percent of the quality engineer's week is transcription: moving numbers from one screen to another screen so a document exists. That is the leak. Not scrap, not machine hours. Typing. And it is worse than the labor cost, because the same gap is what turns an escape into a two-week investigation and what turns a Nadcap audit into a fire drill.

Problem: the first article takes 14 hours of typing, and the print changes anyway

In the shops we have walked, an AS9102 package on a 200-plus characteristic part takes a QE 10 to 14 hours the first time. Forms 1, 2, and 3 all restate the same identity data. Form 2 wants every material and special process with its certification source. Form 3 wants every characteristic, its design tolerance, its measured result, and the method. Then engineering releases Rev G, and because AS9102 requires a partial FAI on affected characteristics only, somebody sits with two PDFs side by side and eyeballs the delta.

Net-Inspect, High QA, and InspectionXpert each solve one slice: ballooning, or the prime's submission format, or a characteristic library. None of them know your router, your lot, your operator, or your gage. So the characteristic data lives in a quality island while the production data lives in E2, and the join happens in a person's head. E2 and JobBOSS2 were architected around jobs and operations. There is no first-class object called "characteristic" in them, and there never will be, because the addressable market for that object is aerospace and medical, not the general job shop they sell to.

What a custom build does differently: model the characteristic as a real entity, keyed to part number plus revision plus balloon number, with design nominal, tolerance, classification (key characteristic or not), inspection method, required gage type, and frequency. Import CMM output directly by parsing the Zeiss Calypso or PC-DMIS report and matching by balloon number, so measured values land without a keystroke. Generate Forms 1, 2, and 3 as output, not as input. Then, on a revision, diff the characteristic set programmatically and open a partial FAI containing exactly the affected balloons. AI earns its place here in one narrow spot: a vision model reading the ballooned PDF and the model-based definition to extract dimension, tolerance, and GD and T callouts into draft characteristics, with the QE confirming rather than typing. In our delivery experience, the correct target is not full automation, it is getting the QE from 14 hours to under 2, with a human sign-off gate that the auditor can see.

Problem: traceability lives in three systems and none of them agree

AS9100 clause 8.5.2 wants identification and traceability. In practice this means: this serialized part came from this heat lot of 15-5PH, which came from this mill cert PDF, which was cut on this machine by this operator, then went out to a Nadcap heat treat house on this purchase order, came back with this cert referencing this AMS2750 furnace run, then to chem film, then to a source inspection. When Spirit or Collins calls about a suspect lot, you need every part number and every ship date touched by that heat lot within hours.

Your ERP tracks a lot number for inventory value. It does not link that lot to a scanned PDF sitting in a folder named 2023-Q3, and it does not track the outside processor's cert as a child record of the operation. So the answer to "which parts touched heat lot 7A2214" is a person opening folders. Bolt-on QMS tools like ETQ Reliance or uniPoint add document control and CAPA workflow on top, but they inherit the same broken link, because they do not own the router either.

What a custom build does differently: one traceability graph. Serial or lot to heat lot to mill cert document to work order operation to machine to operator to outside process PO to returning cert to shipment to prime. Every edge is queryable, so a containment question becomes a search, not an archaeology project. Certs get ingested by AI document extraction on receipt: the mill cert PDF or the heat treat house's cert is parsed for alloy, heat number, spec revision, and expiration, then auto-matched to the receiving line and flagged when the spec called out on the PO does not match the spec on the cert. That single check catches the failure that produces most DPRV findings we have seen: the paperwork is present and technically wrong. Add shelf-life and cure-date tracking for sealants and prepreg driven off the same ingestion, with freezer log capture, and the Excel tab dies.

Problem: audits become a two-week fire drill instead of a query

Nadcap reaccreditation, AS9100 surveillance, and prime audits all ask the same shape of question: show me evidence, sampled at random, for the last 12 months. Calibration records for the gage used on this inspection. Operator certification for this weld. Pyrometry compliance for this furnace run. Training records tied to the revision of the work instruction in effect on the date the part was made. Most shops answer this by pulling three people off the floor for a week and building a binder.

Off-the-shelf QMS modules store the documents. They rarely store the point-in-time link, which is what the auditor actually tests. Your ERP knows the current revision of the work instruction. It does not know which revision was in effect on 14 March when serial 0042 ran, and it does not know that the operator's certification lapsed for eleven days in that window.

What a custom build does differently: everything is versioned and time-stamped, and the association is stored at the moment of use, not resolved at query time. When the operator scans into an operation, the system captures the work instruction revision, their current certification status, and the gage's calibration state and due date, and refuses the scan if the gage is out of cal. Audit prep becomes a filter: pick a date, pick a job, print the evidence chain. We have shipped this in a first release, and the honest result is not that the audit gets easier, it is that the shop stops paying three weeks of payroll to rehearse for it twice a year.

Problem: every prime wants a different format, and the scorecard punishes you for it

Boeing wants Exostar. Some programs want Net-Inspect for FAI and NCR submission. Lockheed, Northrop, and the rest have their own portals, and your name sits in the IAQG OASIS database while your delivery and quality scores sit on a prime scorecard that decides whether you get the next package. Meanwhile purchasing runs through SAP Ariba or Coupa and your ASN and packing slip formats differ per customer.

No ERP vendor will build first-class connectors to a dozen prime portals for a customer base your size. So you pay a person to be the portal. They rekey the same FAI into two places, and they find out about a scorecard hit six weeks after the shipment that caused it.

What a custom build does differently: one canonical record, many renderings. The FAI, the C of C, the ASN, and the packing list are all generated from the same data model, with a per-customer output profile that handles their part numbering scheme, their required fields, and their file format. Where an API exists, push directly; where only a portal exists, generate the exact upload file and log the submission. Then mirror the scorecard: track your own on-time delivery and quality escape rate against each prime's definition of it, including their clock (ship date versus dock date matters, and they do not use the same one), so the number surprises nobody. Forecasting helps concretely here: a model over your own routing history and current WIP that flags at day 4 of a 30-day lead time that this job will miss, while there is still time to expedite the outside process.

Problem: one escape turns into 40 hours of 8D archaeology

A prime returns 12 parts with an out-of-tolerance bore. You owe an 8D, containment within 24 hours, root cause and corrective action in 30 days. Containment means answering: what else did we ship with that same condition. If your inspection results are values typed into a PDF that got scanned back in, that question cannot be answered with software. It is answered by reading PDFs.

This is the compounding cost of the FAI problem. Because measurement data was never structured, you have no process capability history, no Cpk trend per characteristic per machine, and no ability to see that the bore drifted for three weeks before it went out. Off-the-shelf SPC tools can chart it if somebody feeds them, and nobody feeds them, because feeding them is more typing.

What a custom build does differently: because in-process and final inspection results are captured as structured values against the characteristic, containment is a query returning every serial with that characteristic outside limits, filtered to the ones already shipped, with the customer and ship date attached. Capability charts fall out for free. AI is useful in a narrow, verifiable way: drafting the 8D from the linked evidence (the NCR, the inspection history, the machine, the operator, the tool change log) and surfacing the three closest historical NCRs with the same characteristic and machine, so the QE argues with a draft instead of staring at a blank template. The signature and the root cause stay human.

What this costs and how long it takes

These bands are Digital Heroes delivery experience across 2,000+ projects, not a market survey. A focused first release in this category typically lands at $60k to $130k and ships in 12 to 16 weeks. Focused means: the characteristic data model, FAI generation with CMM import and revision diffing, the traceability spine with cert ingestion, and a read integration with your existing ERP. That is the release that stops the bleeding. A full platform, adding shop floor scan-in with gage and certification gating, NCR and CAPA and SCAR workflow, prime portal outputs, supplier quality, and scorecard mirroring, runs $150k to $400k phased over 6 to 12 months.

What drives price up specifically in aerospace supply: CMMC 2.0 Level 2 and NIST 800-171 scope, which can add meaningful engineering for access control, audit logging, FIPS-validated encryption, and a documented boundary, and which pushes you toward GovCloud hosting. ITAR handling, which constrains where data sits and who can touch the codebase, including your developer's own staffing. Deep CMM and DPD integration beyond report parsing. Multi-site with different Nadcap accreditations per site. And the number of prime-specific output profiles, because each one is a small integration with its own quirks. What does not drive price much: the number of users. Price scales with regulatory surface and integration count, not seats.

Build versus buy: take the position

Buy, without apology, if you are under roughly 25 people, single site, running a handful of part numbers on repeat orders, and your FAI volume is low. E2 Shop System plus High QA plus disciplined folder hygiene is a rational stack at that size, and a $90k build will not pay back. Buy also if your problem is accounting and inventory. Kinetic and Global Shop are better at that than anything we would write for you, and we will tell you so.

Build when these signals show up, and they show up together. Your quality headcount is growing faster than revenue. Somebody's full-time job is retyping data between systems. A containment question takes more than a day to answer. You have added a second site or a second Nadcap-accredited process and the tribal knowledge did not clone. Or a prime has made a scorecard number a condition of the next package and you cannot see that number in real time. At that point the off-the-shelf stack is not cheaper, it is just billed as payroll instead of capex, and it does not compound. Our position: keep the ERP for jobs, inventory, and money. Build the quality and traceability layer on top of it and own it, because that layer is the thing your primes are actually buying from you.

How to choose a developer for aerospace manufacturing software

Make them draw the data model on a whiteboard before you sign anything. If they cannot separate part, revision, characteristic, lot, heat lot, serial, and operation instance without prompting, they will build you a document manager with an aerospace paint job. The characteristic and the point-in-time association are the whole game, and a team that has not built this before gets it wrong in week two and finds out in month six.

Ask what they have integrated, specifically. Not "we do integrations." Have they parsed a PC-DMIS or Calypso report. Have they pushed to Exostar or Net-Inspect. Have they read from E2 or JobBOSS2 or Kinetic, including how they handled the vendor's read-only database posture and the fact that some of these systems will not give you an API worth the name. The answer tells you whether the estimate is real.

Test them on compliance before they test you. They should ask you about ITAR and CMMC scope in the first conversation, unprompted, and they should have an opinion about where the data lives and who on their team can see it. A developer who says "we will figure out hosting later" has just told you they will re-architect on your budget.

Insist on code ownership, a repository you control from commit one, and a written exit path. You are buying an asset that has to outlive the relationship and survive an auditor asking who can change a signed record. If the contract does not spell out who owns the code, the auditor question and the vendor question become the same question, and you will not like the answer.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. Large companies globally have captured, on average, only 31% of the expected revenue lift and 25% of the expected cost savings from their digital and AI transformations - a significant gap between expected and realized value. Source: McKinsey & Company (2023) →
  2. McKinsey estimates that digitizing the supply chain (Supply Chain 4.0) can cut lost sales by up to 75%, reduce inventories by up to 75%, and lower supply chain operational costs by up to 30%, with up to 30% lower transport and warehousing costs. Source: McKinsey & Company (2016) →
  3. ITIF's 2025 report documents that SMEs operate at roughly 60% of large-firm productivity in advanced economies (citing McKinsey), that CRM platforms deliver a 25-40% improvement in customer retention and a 15-30% boost in sales, and that digital advertising returns about $8 in profit per dollar spent on Google Search and Ads. Source: Information Technology and Innovation Foundation (ITIF) (2025) →
  4. Retailers connecting point-of-sale and loyalty data in an omnichannel strategy reported up to 15% lower cost per purchase and nearly 20% higher incremental store revenue. Source: Deloitte (2024) →
Rohan Malhotra · Enterprise Software Consultant

Rohan advises mid-market and enterprise teams on ERP, CRM and custom software, and has led delivery on dozens of business-software builds.

Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

How much does custom aerospace manufacturing software cost for a 100-person AS9100 supplier?
A focused first release covering the characteristic data model, AS9102 generation with CMM import, and the traceability spine typically runs $60k to $130k and ships in 12 to 16 weeks, based on Digital Heroes delivery experience across 2,000+ projects. A full platform adding shop floor scanning, NCR and CAPA workflow, prime portal outputs, and supplier quality runs $150k to $400k phased over 6 to 12 months. Price scales with regulatory scope such as CMMC and ITAR and with integration count, not with the number of users, so a 100-person shop and a 40-person shop often land in the same band.
Should we replace E2 Shop System or JobBOSS2 entirely, or build alongside it?
Build alongside it. E2 and JobBOSS2 are competent at jobs, routers, inventory, and money, and replacing that is expensive with little payback. The gap they cannot close is characteristic-level quality data, cert linkage, and point-in-time traceability, because those objects do not exist in their model. Build that layer, integrate it read-and-write with the ERP, and revisit replacing the ERP only if it becomes the constraint later.
Will an AS9100 or Nadcap auditor accept records from custom-built software?
Yes, auditors care about controls and evidence, not about who wrote the software. What they test is whether records are attributable, time-stamped, protected from unauthorized change, and traceable to the revision and personnel in effect at the time of manufacture. Build in immutable audit logging, electronic signature with role-based approval, and versioned document association at the point of use, and a custom system usually audits better than a folder tree because the evidence chain is queryable rather than assembled by hand.
How do we handle ITAR and CMMC 2.0 Level 2 with a custom-built system?
Scope it before the first line of code, because it changes hosting, staffing, and cost. ITAR constrains where data resides and who can access it, which means US persons on the development team and controlled infrastructure, commonly AWS GovCloud or Azure Government. CMMC 2.0 Level 2 maps to NIST 800-171 and adds access control, audit logging, FIPS-validated encryption, and a documented system boundary, and in our experience it adds meaningful engineering time to the estimate, so it should be priced in from day one rather than bolted on.
How long does it take to migrate 15 years of job history, mill certs, and FAI packages?
Plan for migration to run in parallel with the build rather than gate it. Structured ERP data such as parts, jobs, and lots typically migrates in weeks; the long pole is unstructured PDFs, where AI document extraction can parse mill certs and C of Cs to recover heat numbers, specs, and dates for automatic linkage to the traceability graph. A pragmatic approach is to migrate the last 2 to 3 years fully, index the rest for search, and leave the archive readable, since retention obligations mostly require retrievability, not live records.
Do we own the code if Digital Heroes builds it?
Yes. The repository is yours from the first commit, you hold the credentials, and full IP ownership transfers to you. That matters more in this category than most, because an auditor may ask who can change a signed record, and the answer needs to be your organization under your access controls, not a vendor with a black box.
Is a custom build better than Net-Inspect or High QA for first article inspection?
Net-Inspect and High QA solve real slices well: prime submission format and ballooning plus a characteristic library respectively. What neither does is connect characteristics to your router, lot, heat, operator, and gage, so the join still happens in a person's head and containment questions still require reading PDFs. If your FAI volume is low and you only need the submission, keep them; if quality headcount is growing faster than revenue and traceability questions take a day to answer, a custom layer that owns the characteristic and generates the submission is worth building.
Can AI actually fill out an AS9102, or is that marketing?
AI helps in two verifiable places: extracting dimensions, tolerances, and GD and T callouts from a ballooned PDF or model-based definition into draft characteristics, and parsing mill certs and outside process certs into structured fields on receipt. What it does not do is sign the form or replace the quality engineer's judgment. The realistic outcome we target is a first article dropping from roughly 14 hours to under 2, with a human confirmation gate that an auditor can inspect.
What do we actually get in the first 12 to 16 weeks?
A working system your quality engineers use daily, not a prototype: the characteristic data model keyed to part and revision and balloon, AS9102 Forms 1, 2, and 3 generated from data rather than typed, CMM report import matched by balloon number, revision diffing that opens a partial FAI on only the affected characteristics, and the traceability spine linking serial or lot to heat lot to cert to operation to shipment. ERP integration is read-first in that window, with write-back sequenced into the next phase once the data model has proven itself against real jobs.
Why do companies replace NetSuite with custom software?
The three reasons we hear most at Digital Heroes are per-user license growth, SuiteScript customizations that became fragile, and workflows the platform cannot model without workarounds. A company adding 50 users to NetSuite takes on roughly $59,000 per year in extra licenses at the commonly quoted $99 per user rate, which is often the moment the custom math starts winning. Replacements usually keep the accounting structure intact and migrate module by module.
What does it cost to keep custom software running after launch?
Budget 15-20% of the original build cost per year, which on a $100,000 system means $15,000 to $20,000 for security patches, dependency updates, bug fixes, and small improvements as real usage reveals what the spec missed. Cloud hosting for a typical business application adds $50 to $300 a month on top. Skipping maintenance does not save the money; in Digital Heroes rescue work, unmaintained systems typically need a far more expensive rebuild within about three years.
What happens to my ERP if the agency shuts down or we part ways?
If ownership was set up correctly, nothing breaks: you hold the source code, the system runs in cloud accounts you own, and handover documentation lets a new team take over. Insist on repository access from day one, admin ownership of all hosting and third-party accounts, and documentation as a contract deliverable rather than a favor. This is the single most important clause to check before signing an ERP contract.
What should I prepare before contacting an ERP development agency?
Bring a list of your current tools and spreadsheets, a rough map of how an order or job moves through the company today, your user count by role, and the three problems costing you the most hours. You do not need a formal specification; a good agency writes that with you during discovery. Companies that arrive with those four things typically cut two to three weeks off scoping in our experience.
How much does a custom ERP cost for a small business?
A small-business ERP covering two or three core modules typically runs $40,000 to $120,000, with inventory, ordering, and accounting sync being the usual starting set. Across 2,000+ Digital Heroes projects, integration count and user roles drive cost far more than screen count. A full mid-market ERP with six or more modules usually lands between $150,000 and $400,000.
Is a custom ERP cheaper than NetSuite over five years?
Often yes once you pass roughly 20 to 30 users. NetSuite is commonly quoted at $999 per month for the base platform plus about $99 per user per month, so a 30-user company spends over $200,000 on licenses across five years before paying for implementation. A custom build in the $120,000 to $250,000 range is a one-time cost, and in Digital Heroes projects annual upkeep runs 15 to 20 percent of build cost with no per-seat fees as you hire.
Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?