
CMMC Cybersecurity Misrepresentation: The False Claims Act Cases DIB Contractors Should Know
Emily Bonnie
Senior Content Marketing Manager
With the Phase 2 C3PAO requirement currently on pause, self-assessment is now the active path for all new CMMC Level 2 solicitations. That means every covered contractor is in the same position: your team evaluates the 110 NIST SP 800-171 requirements, your Affirming Official attests to your score, and whatever you submit in SPRS is your company's formal representation to the federal government. There is no external assessor to validate your implementation and your submission.
That representation carries legal weight. The False Claims Act allows the government to pursue contractors who knowingly submit false or misleading information as part of a claim for payment. In a defense contracting context, that includes cybersecurity certifications and SPRS scores. If your score overstates what's actually implemented and you continue billing under contracts where compliance was a condition of award, each invoice can be treated as a separate claim.
In fiscal year 2025, the Department of Justice recovered more than $6.8 billion under the False Claims Act, the highest annual total in the statute’s history. Whistleblowers filed 1,297 qui tam lawsuits, also a record.
As CMMC requirements move from policy guidance into active contract language, and as cybersecurity certifications receive more scrutiny, the link between what contractors certify and what they can actually prove is becoming more important.
Below, we’ll break down what the False Claims Act covers, why this record enforcement year matters for primes and subcontractors in the DIB, and where contractors should pay closer attention now.
What the False Claims Act covers
The False Claims Act is a civil law that allows the government to recover damages when an entity knowingly submits false claims for payment or makes false statements that influence government payment decisions.
What gives the statute real teeth comes down to two things.
First, damages can be tripled. If the government suffers $10 million in losses, liability can reach $30 million before penalties are added. Second, the Act imposes penalties per claim, meaning each invoice or request for payment under a contract may count as a separate violation.
In a defense contracting context, that exposure can scale quickly. A multi-year contract with recurring invoices doesn’t create a single point of risk. Each request for payment may be treated as its own claim. When combined with treble damages, even a narrow gap between what was certified and what was implemented can translate into significant financial exposure.
Importantly, “knowingly” doesn’t require proof of intent to defraud. It includes reckless disregard or deliberate ignorance of whether a statement is accurate.
For defense contractors, that distinction matters. Many FCA cases don’t involve blatant fraud. They often come from situations where what was certified doesn’t match reality. Controls may be partially implemented, evidence may be outdated, or configurations may have drifted over time.
The DOJ launched its Civil Cyber-Fraud Initiative in 2021, signaling a clear intent to use the False Claims Act to pursue contractors whose cybersecurity representations don't match their actual practices. The cases below are the first wave of that enforcement in practice.
MORSECORP, Inc. — $4.6 million settlement
MORSE is a Cambridge-based defense contractor that held contracts with the Army and Air Force. In January 2021, it submitted an SPRS self-assessment score of 104 out of 110, suggesting near-total compliance with NIST SP 800-171 requirements.
A third-party gap analysis conducted in July 2022 found MORSE's actual score was -142. MORSE did not update its score in the Department of Defense reporting system until June 2023, three months after the US served MORSE with a subpoena concerning its cybersecurity practices.
The case originated from a whistleblower complaint filed by an employee who resigned after uncovering the compliance failures, and MORSE agreed to pay $4.6 million in the settlement. The whistleblower who filed the complaint received $851,000 as part of the settlement.
Penn State University — $1.25 million settlement
Penn State's $1.25 million settlement is notable because it didn't involve an inaccurate SPRS score. The university submitted SPRS scores that correctly reflected it had not implemented certain controls, but it misrepresented the dates by which it would remediate those gaps and did not follow through on its plans of action. There was also a separate allegation that it used a cloud service provider that didn't meet DoD security requirements on certain contracts.
FCA exposure doesn't require an inflated score. Accurate scores paired with false remediation commitments are sufficient.
Georgia Tech Research Corporation — $875,000 settlement
Two former members of Georgia Tech's cybersecurity team filed a qui tam lawsuit in July 2022 alleging that the Georgia Tech Research Corporation failed to meet cybersecurity requirements on its DoD contracts. The DOJ intervened in February 2024 and filed its complaint in August 2024, the first time the government intervened in a cybersecurity FCA case under the Civil Cyber-Fraud Initiative.
The settlement resolved three separate allegations: first, that GTRC failed to install, update, or run antivirus and anti-malware tools on computers and networks at Georgia Tech's Astrolavos Lab while the lab conducted sensitive cyber-defense research for DoD, until December 2021. Second, that there was no system security plan in place for the Astrolavos Lab until at least February 2020. Third, that in December 2020, GTRC submitted a summary-level SPRS score of 98 to DoD that was allegedly false on two grounds. One, there was no campus-wide IT system at Georgia Tech to which a single score could apply. Two, the score was premised on a "fictitious" or "virtual" environment and did not apply to any actual covered contracting system at Georgia Tech that would process, store or transmit covered defense information.
Aerojet Rocketdyne — $9 million settlement
Aerojet Rocketdyne settled for $9 million over allegations that it misrepresented its compliance with cybersecurity requirements in certain federal government contracts with the DoD, NASA, and other agencies. The case was filed by a former Aerojet employee with inside technical knowledge of the company's cybersecurity posture, who received $2.61 million as part of the settlement.
The Aerojet case predates CMMC but established the pattern the later cases followed: an insider with detailed knowledge of the company's compliance posture, a gap between what was represented and what was implemented, and a qui tam filing that gave the DOJ an opening to pursue the case.
How these cases should inform your compliance program
These cases may involve different organizations and different specific failures, but they reflect common themes that federal contractors must pay close attention to.
Only attest to what you can prove
Every case in this list began with a formal representation that outran the underlying reality. A score of 104 when implementation was at 22%. A score of 98 based on an environment that didn't exist. In each case, the liability wasn't the gap itself; it was certifying a posture the organization couldn't demonstrate. Before your Affirming Official signs the annual affirmation, the question isn't whether your score looks reasonable. It's whether every MET determination in SPRS is backed by evidence you can produce today.
Accurate scores with false remediation timelines still constitute risk
Penn State's settlement involved no inflated score. The university accurately reported that certain controls weren't implemented, then misrepresented when it would fix them and didn't follow through. POA&M items aren't a safe harbor unless you're actively working them. Committing to a remediation date you don't meet, or creating a plan of action you don't pursue, is its own exposure.
Remediation after the fact doesn't undo a false claim
MORSE eventually reached a score of 110 and fully remediated its environment, but the settlement still covered the period of misrepresentation that preceded the remediation. If you discover a gap between your posted score and your actual posture, the right move is to update your SPRS score promptly and begin remediation. Waiting, or achieving compliance without correcting the record, doesn't reset the clock.
Continuously monitor your controls, not just your score
MORSE's score went unchallenged until a third-party assessment revealed the gap. Either the environment drifted, or it was never as implemented as the score suggested, and nobody caught it until the subpoena arrived.
Configurations change. Software goes unpatched. Access controls lapse. A score that was defensible at one point in time can become indefensible as the environment changes underneath it. Continuous monitoring is what keeps your score connected to this evolving reality.
Document how you reached your conclusions
Being able to show why a control was considered met, what was reviewed, and how the requirement was interpreted creates a much stronger position than a simple MET/NOT MET record. If your self-assessment is ever scrutinized, the question won't just be what your numerical score was, it will be whether you had a reasonable, documented basis for it.
Recommended reading
CMMC Self-Assessment Guide: Level 1 and Level 2 Process
Why the CMMC Phase 2 pause makes the FCA even more relevant
Before July 2026, the CMMC framework included a C3PAO assessment for Level 2 as an additional verification layer. An assessor would review your implementation, validate your evidence, and either confirm or challenge your conclusions before results went into SPRS.
The Phase 2 suspension removed that layer for all new solicitations. Your team now makes every MET determination, your Affirming Official signs the affirmation, and those entries in SPRS represent your company's posture to the government without an external review. If the score overstates what's actually implemented, the gap between what was submitted and what was true is yours to explain.
In the Defense Industrial Base, cybersecurity obligations are built directly into contract performance. Contractors certify compliance with DFARS 252.204-7012, submit NIST SP 800-171 scores into SPRS, make CMMC self-attestations, provide assurances to prime contractors, and reaffirm representations annually. Each of those is a formal statement tied to eligibility, award, or payment. The DoW's pause of CMMC Phase 2 affected the third-party assessment requirement, not the underlying cybersecurity requirements.
Next steps for DIB contractors
Review your posted SPRS score against what's actually deployed. If a gap analysis or internal review has revealed a lower score than what's on file, update it promptly. Make sure POA&M items have active remediation plans with realistic timelines you're actually tracking. And document how you reached your MET determinations, not just what they are.
If you're not confident your self-assessment reflects what your environment can actually prove, that's the starting point. Secureframe Defense tracks your live SPRS score against your actual control implementation, so the number you submit and affirm reflects what your environment can prove.

CMMC Compliance Kit
If you’re working through CMMC requirements, this kit includes practical resources that walk through how to implement controls, create documentation, and prepare for assessment without relying on guesswork.

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.