CMMC may be changing, but the consequences of inaccurately representing your cybersecurity posture to the federal government are not.
Defense contractors that handle Controlled Unclassified Information (CUI) may be required to implement NIST SP 800-171, maintain supporting cybersecurity documentation, and submit an assessment score to the Supplier Performance Risk System (SPRS). That score should reflect what is actually implemented across the environment covered by the assessment.
When the score, System Security Plan (SSP), or other cybersecurity representations don't match what's actually in place, the issue can go beyond a compliance gap. If a contractor knowingly misrepresents its cybersecurity practices while continuing to perform and bill under federal contracts, it can create False Claims Act exposure.
And that risk is becoming harder to ignore. Cybersecurity-related False Claims Act settlement agreements announced under the DOJ's Civil Cyber-Fraud Initiative reached approximately $51.8 million in 2025, up 233% from 2024, according to an analysis of DOJ-announced settlements.
Recent cases involving defense contractors show the same underlying lesson: what you tell the government about your cybersecurity posture needs to match what you can actually prove.
How Cybersecurity Compliance Can Become a False Claims Act Issue
The False Claims Act (FCA) allows the federal government to pursue organizations that knowingly submit false claims or make false statements material to government payment.
For defense contractors, that risk can extend to cybersecurity. Contractors handling Controlled Unclassified Information (CUI) may be required to implement NIST SP 800-171 and comply with applicable DFARS requirements. Under DFARS 252.204-7019, contractors subject to the clause must have a current NIST SP 800-171 assessment in SPRS for each covered contractor information system relevant to an offer.
The problem begins when what a contractor reports doesn't match what it can demonstrate—whether that's an unsupported SPRS score, an inaccurate System Security Plan (SSP), or security requirements represented as implemented when they are not.
That's one reason DOJ launched the Civil Cyber-Fraud Initiative in 2021, targeting government contractors and grant recipients that knowingly misrepresent cybersecurity practices, fail to meet required cybersecurity standards, or violate monitoring and reporting obligations.
For defense contractors, the distinction is simple: a cybersecurity gap is one problem. Representing that the gap doesn't exist can create another.
Cybersecurity False Claims Act Enforcement Is Increasing
Cybersecurity compliance is no longer just an IT or assessment issue. It has increasingly become an enforcement priority for the Department of Justice.
Since launching the Civil Cyber-Fraud Initiative in 2021, DOJ has pursued cases involving contractors that allegedly failed to meet required cybersecurity standards, misrepresented their security practices, or failed to satisfy cybersecurity-related contractual obligations.
That enforcement comes amid broader growth in False Claims Act activity. In fiscal year 2025, DOJ reported more than $6.8 billion in False Claims Act settlements and judgments—the highest single-year total in the statute's history—and a record 1,297 qui tam lawsuits. Cybersecurity enforcement followed the same trend: an analysis of DOJ-announced Civil Cyber-Fraud Initiative settlements found that values rose from $15.6 million in 2024 to $51.8 million in 2025—a 233% increase.

For defense contractors, the cybersecurity cases are particularly important because enforcement isn't limited to what happens after a data breach. The government can also examine whether required security controls were actually implemented, whether cybersecurity assessments accurately reflected the environment, and whether representations made while performing and billing under federal contracts could be supported.
Recent settlements involving LOGZONE, MORSECORP, Georgia Tech, Raytheon-related companies, and Aerojet Rocketdyne show how these risks can play out in practice. Let's look at the cases defense contractors should know.
The Numbers Behind the Rise in Cybersecurity Enforcement
Recent DOJ cases show how cybersecurity deficiencies and inaccurate representations can create False Claims Act exposure for organizations performing federal work.

LOGZONE — $507,144 (June 2026)
The Alabama-based defense contractor agreed to pay $507,144 to resolve False Claims Act liability involving cybersecurity requirements on two U.S. Navy contracts. DOJ alleged that LOGZONE knowingly failed to fully comply with required NIST SP 800-171 controls while submitting claims for payment between 2021 and 2025. The case is a timely reminder that changes to CMMC implementation do not eliminate cybersecurity obligations already contained in federal contracts.
Georgia Tech Research Corporation — $875,000 (September 2025)
DOJ alleged that Georgia Tech submitted a 98-point NIST SP 800-171 assessment based on an environment that did not accurately represent the systems used to perform the relevant DoD contracts. The government also raised allegations involving its System Security Plan and other cybersecurity practices. Georgia Tech Research Corporation agreed to pay $875,000 to resolve the litigation, with no determination of liability.
Raytheon and Nightwing — $8.4 million (May 2025)
Raytheon and Nightwing agreed to pay $8.4 million to resolve allegations involving cybersecurity requirements across numerous DoD contracts and subcontracts. DOJ alleged that certain systems failed to comply with applicable federal and DoD cybersecurity requirements while claims for payment were submitted.
MORSECORP — $4.6 million (March 2025)
MORSECORP agreed to pay $4.6 million to resolve allegations involving cybersecurity requirements on Army and Air Force contracts. Among the issues, DOJ said MORSE used a third-party email provider without ensuring applicable security requirements were met and submitted an inaccurate NIST SP 800-171 self-assessment score. The case originated from a whistleblower lawsuit filed by MORSE's former head of security, who received approximately $851,000.
Aerojet Rocketdyne — $9 million (July 2022)
Aerojet Rocketdyne agreed to pay $9 million to resolve allegations that it misrepresented its compliance with cybersecurity requirements in certain federal contracts. The case began with a qui tam lawsuit filed by a former employee, who received $2.61 million from the settlement.
Different organizations, different contracts, and different cybersecurity failures—but the cases point to the same underlying concern:
What you tell the government about your cybersecurity posture needs to match what you can actually prove.
The Common Thread: Your SPRS Score Has to Match Reality
Across these cases, one pattern stands out: what an organization represented did not always match what it could demonstrate. For defense contractors, that gap can appear in an unsupported SPRS score, an SSP that doesn't reflect the actual environment, or controls reported as implemented without sufficient evidence.

Under the NIST SP 800-171 DoD Assessment Methodology, your SPRS score should reflect actual implementation. The goal isn't simply the highest score—it's a score your SSP, security controls, and evidence can support. If the government asked you to validate that score today, could you prove it requirement by requirement?
How Defense Contractors Can Reduce Their FCA Risk
- Make sure your SPRS score is accurate and defensible. Review your assessment against the applicable NIST SP 800-171 DoD Assessment Methodology and make sure every score decision can be supported.
- Keep your SSP aligned with your actual environment. Your SSP should accurately reflect your CUI environment, system boundaries, technologies, and how security requirements are actually implemented.
- Maintain evidence behind your assessment. Policies alone aren't enough. Keep appropriate configurations, logs, screenshots, procedures, records, and other evidence that demonstrates implementation.
- Document gaps instead of hiding them. If a requirement isn't fully implemented, document it accurately and use a POA&M where permitted rather than representing the requirement as complete.
- Revalidate as your environment changes. New systems, cloud services, users, and configurations can make an old assessment inaccurate. Keep your SSP, evidence, and SPRS assessment aligned with those changes.
The goal isn't simply to get a higher SPRS score. It's to have a score you can prove.
Where SecureITSM Helps
CMMC may evolve, but your SPRS score, SSP, controls, and evidence should always align. SecureITSM achieved 110/110 on our first CMMC Level 2 assessment and helps defense contractors strengthen NIST SP 800-171 implementation, documentation, and assessment readiness.
Book a free 15-minute CMMC compliance consultation to review your current compliance posture and see how SecureITSM can help.
Frequently Asked Questions
1. Can an inaccurate SPRS score create False Claims Act risk?
Potentially. An inaccurate score alone does not establish liability, but knowingly misrepresenting cybersecurity compliance or submitting an assessment that does not reflect actual implementation can create False Claims Act exposure.
2. Does a data breach have to occur for the False Claims Act to apply?
No. DOJ's Civil Cyber-Fraud Initiative also targets knowing failures to meet required cybersecurity standards, misrepresentation of cybersecurity practices, and certain monitoring or reporting failures.
3. Does the CMMC Phase II suspension change NIST SP 800-171 requirements?
No. Current DoW CMMC guidance states that Phase I self-assessment requirements remain in place and that NIST SP 800-171 Rev. 2 compliance will continue to be enforced through self-assessments and selected government-led assessments during the reform period.
4. Does every defense contractor need a 110 SPRS score?
Not necessarily; applicable requirements depend on the contractor and contract. A 110 represents full implementation under the applicable assessment methodology, but contractors should never claim implementation they cannot support with evidence.
5. How should defense contractors validate an SPRS score?
Compare the score with the applicable NIST SP 800-171 DoD Assessment Methodology, current SSP, actual technical implementation, and supporting evidence. Your organization should be able to explain and substantiate how each assessed requirement contributed to the submitted score.