Custom Software for Manufacturing — ERP, Shop Floor, and Quote Configurators
Quote configurators, shop-floor data capture, customer portals, ERP integration, and ITAR-aware compliance — built for fabricators, machine shops, contract manufacturers, and assembly operations that need software fitted to the way the shop actually runs.
Why manufacturing is a special case
Manufacturing combines three pressures that almost no other industry faces simultaneously. The existing systems of record are old, deeply embedded, and famously rigid. NetSuite, Acumatica, Epicor, IQMS, Plex, JobBOSS, ProShop, and Fishbowl each model the shop differently, expose different integration surfaces, and lock the business into their workflow opinions. Most US manufacturers running mid-volume contract work have a system that does 70% of the job correctly and forces the other 30% into Excel, paper travelers, and email — at the exact volume where that overhead starts to cost real production time.
The shop floor itself is a real, physical environment. Ethernet-connected machines on an OT network deliberately segregated from the IT side. Operators wearing gloves who need a tablet interface that responds to a knuckle tap. Paper travelers that still circulate because someone in the front office is comfortable with them. Barcode scanners that have been on the floor for fifteen years and need to keep working. Web-app design for office workers does not survive contact with this environment. We build with the assumption that the tooling will be used in a hot shop by tired people, and that the interface needs to be fast and durable.
The compliance perimeter is also intense. ITAR and EAR for defense and dual-use exports. CMMC Level 2 with 110 NIST 800-171 controls for defense subcontractors handling CUI. FDA Quality System Regulation (21 CFR Part 820) for medical-device manufacturers. IATF 16949 for automotive. AS9100 for aerospace. ISO 9001 across most of the rest. Compliance failures cost contracts, not just fines.
What we build for manufacturers
- Quote and estimate configurators — material catalog, labor units, tooling overhead, customer-specific pricing
- Customer-facing order portals — order status, drawings, shipping, invoice history
- Shop-floor data capture — operator clock-in, job traveler tracking, downtime reasons, scrap and yield
- ERP integration on top of NetSuite, Acumatica, Epicor, or IQMS
- Machine integration — OPC UA, Modbus, MTConnect data ingest into a unified analytics layer
- Quality control workflows — incoming inspection, in-process checks, FAI reports, deviation/CAR/CAPA
- Document control and revision management — drawings, work instructions, ECN/ECO routing
- Vendor and supplier portals — RFQ-to-PO, packing slip capture, ASN ingest
Common manufacturing projects we scope
- Quote configurator for a job shop. Multi-step configurator with material catalog, labor units, tooling overhead, and customer-specific markup. Produces a branded PDF quote and a structured estimate that lands cleanly into the ERP.
- Shop-floor data capture tablet app. Operator clock-in, job traveler tracking, downtime reason codes, scrap and yield reporting, and barcode-driven workflows. Built to run on inexpensive Android tablets in a hot shop environment.
- ERP integration layer. REST adapter between the manufacturer's custom tooling and NetSuite, Acumatica, or Epicor. Quotes, sales orders, work orders, item masters, BOMs, and inventory updates synchronized with conflict-resolution rules and audit logging.
- Machine data ingest. Small Linux gateway in the OT zone pulling OPC UA, Modbus, or MTConnect data from PLCs and CNC controllers. Publishes through a controlled DMZ into IT-side analytics and OEE dashboards.
- Customer-facing order portal. Branded portal where customers view order status, download drawings and certs, request changes, and pay invoices. Often the highest-leverage win because it removes a meaningful share of inbound support load.
- Quality control workflow. Incoming inspection, in-process checks, first-article inspection (AS9102 forms), supplier deviation requests, and CAR/CAPA tracking with evidence retention aligned to ISO 9001 and AS9100 audits.
- Document control and ECN/ECO routing. Drawing revision management, work-instruction versioning, engineering change order approval routing, and a clean audit trail showing who approved what and when.
- Vendor and supplier portal. RFQ-to-PO workflow for outside processing, packing slip and ASN capture, vendor scorecard, and supplier quality follow-up.
- OEE and downtime analytics. Real-time OEE calculation by machine and by shift, downtime Pareto, and trend dashboards for plant management. Built on top of the machine-data ingest layer.
- ITAR or CMMC-aware data segregation. Hardened environment for ITAR-controlled or CUI data — US-only data residency, US-citizen engineering team, encrypted-at-rest with US-controlled keys, and audit logging mapped to NIST 800-171 controls.
Compliance and security considerations
ITAR and EAR. Defense articles and technical data under ITAR (22 CFR 120-130) require US-person workforce on the data, US-only data residency, controlled access, and a documented technology control plan. EAR-controlled data (15 CFR 730-774) follows a parallel but slightly different model. We build environments that meet these requirements; we coordinate with your empowered official on TCP integration.
CMMC and NIST 800-171. The DoD CMMC program (Level 2 for most subcontractors handling CUI) requires 110 controls drawn from NIST SP 800-171. We map architectural decisions to each applicable control family: access control, audit and accountability, configuration management, identification and authentication, incident response, media protection, system and communications protection, and system and information integrity.
FDA QSR / 21 CFR Part 820. Medical-device manufacturers need design controls, document control, CAPA, change control, and complete traceability through device history records. We build the digital surfaces (QMS modules, eDHR, ECN routing) that produce the evidence trail your FDA auditor expects.
IATF 16949, AS9100, ISO 9001. Industry-specific QMS standards have specific record retention, traceability, and process-evidence requirements. Our builds capture the evidence by default rather than as an afterthought.
21 CFR Part 11 (electronic records and signatures). For medical and pharma manufacturers, electronic records require validation, audit trails, controlled change to records, and binding electronic signatures. We integrate Part 11-aware e-signature workflows where the regulation applies.
OT/IT segmentation. Operational Technology networks running PLCs and CNC controllers must remain segmented from the IT side. We build gateways that bridge the data flow without putting web-facing services on the OT network. See network penetration testing for the assessment side.
Tech stack we recommend for manufacturing
Next.js 15 or 16 with React 19 and TypeScript for the web layer — office and customer-facing surfaces. For shop-floor tablet apps, the same stack runs as a PWA installed on inexpensive Android tablets with offline-capable form capture, optimistic writes, and background sync to the backend. Postgres on Neon, Supabase, or RDS for the system of record. Prisma or Drizzle as the ORM.
For ERP integration, a normalized internal adapter layer abstracts the carrier-specific quirks of NetSuite, Acumatica, Epicor, or IQMS behind a clean internal API. Each ERP target becomes a new adapter rather than a rewrite. For machine data, a small Linux gateway (Raspberry Pi 5 or an industrial fanless box) running Node-RED or a custom Rust service pulls OPC UA, Modbus, or MTConnect data; the gateway publishes through a controlled DMZ into an MQTT broker or Kafka topic on the IT side, where it feeds analytics and ERP integration. For CUI or ITAR workloads, deployment shifts to AWS GovCloud or Azure Government with US-citizen-only engineering access and KMS-managed envelope encryption.
Pricing transparency
Focused shop tool
Quote configurator with branded PDF output, a tablet-based shop-floor data capture app, or a customer-facing order portal. 4 to 8 weeks.
Shop-floor + ERP integration platform
Quote-to-cash workflow integrated with NetSuite, Acumatica, or Epicor, plus shop-floor data capture and an OEE dashboard. 12 to 18 weeks.
Multi-plant or CMMC-ready platform
Multi-plant scoping, ITAR or CMMC-aware data segregation, machine-data ingest from the OT side, QMS document control, and full audit-evidence capture. 18 to 36 weeks.
Discovery is paid separately at $2,500 and creditable against any full engagement. Book a scope call to walk through your ERP, your shop-floor environment, and your compliance posture.
Pitfalls we have seen
Three patterns recur. First, the team tries to replace the ERP. Almost always the wrong move — the ERP is good at receivables, inventory, and the GL, and ripping it out at the same time as a new shop-floor system creates an unbearable transition. The right scope is to keep the ERP and build the shop-floor and customer-facing surfaces that the ERP is poor at.
Second, machine data gets pulled into the web app directly. A web service connects to an OPC UA endpoint on the OT network and now web-facing infrastructure sits inside what was supposed to be a segregated environment. The right pattern is a small dedicated gateway on the OT side publishing into a buffered, controlled message channel that the IT side consumes. Build that segmentation in. The cost is small; the risk reduction is large.
Third, ITAR and CMMC requirements get treated as a paperwork problem. A defense subcontractor signs the contract, plans to handle the compliance after launch, and discovers six months later that the architecture cannot retrofit US-only data residency or US-citizen access controls. The fix is a rebuild. Build the controls in at architecture time, not as a phase-two upgrade.
FAQs
Why is manufacturing treated as a special case for software development?
Three pressures: ERP systems are deeply embedded and rigid, the shop floor is a real physical environment that web-design conventions don't survive, and the compliance perimeter (ITAR, CMMC, FDA QSR, IATF, AS9100) is intense enough that mistakes cost contracts.
Can you integrate with our ERP (NetSuite, Acumatica, Epicor, IQMS)?
Yes. NetSuite has the best modern API surface. Acumatica and Epicor are workable. IQMS is harder — usually flat-file or scheduled-export integration.
Are you familiar with ITAR and CMMC?
Yes. ITAR/EAR requires US-citizen workforce, segregated storage, and US-only data residency. CMMC Level 2 maps to 110 NIST 800-171 controls. We build the technical safeguards; you author the System Security Plan.
Can you replace ProShop or JobBOSS?
We can build the parts they cover well plus the parts they cover badly or not at all. The economic case usually breaks on unique workflows or per-seat fees outpacing engineering cost.
What does a $25,000 manufacturing build look like?
A focused tool — quote configurator, shop-floor data capture app, or customer portal. 4 to 8 weeks. Discovery sprint paid separately.
How do you handle ITAR-controlled data?
US-only AWS or Azure regions, US-citizen-only engineering team with cleared access, encrypted-at-rest with US-controlled keys, audit logging, and a documented technology control plan integrated with the customer's program.
Can you handle OT/IT network segmentation for shop-floor systems?
Yes. A small Linux gateway in the OT zone pulls data from PLCs and CNC controllers and publishes through a controlled DMZ into the IT-side analytics and ERP integration. We do not put web-facing services on the OT network.
Do you build for job shops, repetitive manufacturers, or hybrids?
All three. Job shops need quoting, traveler management, and shop-floor capture. Repetitive manufacturers need MRP-adjacent planning, lot tracking, and yield analytics. Hybrids — most US contract manufacturers — need both.
Related services
Custom Business Software
Quote configurators, shop-floor tablet apps, and ERP-adjacent operations tools.
Web Applications
Customer order portals, vendor portals, and office-facing dashboards.
Network Pentest
OT/IT segmentation review and shop-floor network assessment.
Penetration Testing
CMMC- and ITAR-aware penetration testing for defense subcontractors.
Cloud Infrastructure
AWS GovCloud, Azure Government, and US-citizen-controlled deployment patterns.
Custom Stripe Integration
Deposit collection, milestone billing, and reconciliation into the ERP.
Manufacturing software reading
All postsCustom Internal Tools vs Retool (2026)
Where Retool wins, where it caps you, and when to write a real Next.js app.
Read postInternal Tools Platform Engineering Guide
Architectural patterns for ops dashboards, admin panels, and back-office UIs.
Read post2026 State of Custom Software Development
Industry-wide pricing, timelines, and engagement-model benchmarks for the year ahead.
Read post
Build the tools the ERP cannot.
Call William Beltz at (770) 652-1282 or book a 20-minute scope call. Mutual NDA before discovery. Founder-led from quote to handoff.