" /> CMMC Paused, DOJ Isn't: False Claims Act Risk 2026 | ITSECOPS
Guide

CMMC Is Paused. DOJ Enforcement Is Not: False Claims Act Risk in 2026

Updated · Aug 2026 By ITSECOPS Free · No signup

Enforcement briefing · CMMC / NIST 800-171 / False Claims Act · Updated August 2026

CMMC Level 2 assessments may be paused — the Department of Justice is not. In June 2026, Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 under the False Claims Act after DCMA re-assessed its self-reported cybersecurity posture and scored it −170 out of a possible 110. If your SPRS score is self-assessed and optimistic, you are not “waiting for CMMC.” You are carrying open federal liability, today.

The most expensive sentence in the defense industrial base

“CMMC is paused, so we’ll just self-assess and sort it out later.” Thousands of contractors are saying some version of this in 2026 — and it confuses two completely different things. The CMMC assessment program (who checks you) has shifted timelines. Your obligations (what must be true) never moved: DFARS 252.204-7012 has required full NIST SP 800-171 implementation since 2017, and DFARS 252.204-7019/7020 require a current, accurate SPRS score before award. The moment you submit that score, you have made a representation to the U.S. Government. If it is knowingly false — or recklessly optimistic — every invoice you submit afterward can become a separate false claim.

That is not a theory. It is the exact pattern the DOJ’s Civil Cyber-Fraud Initiative has been settling, case after case, at growing pace.

The enforcement record: real companies, real dollars

Company Amount When What the DOJ alleged
LOGZONE Inc. (Alabama) $507,144 Jun 2026 Claimed compliance on two Navy contracts; DCMA assessment scored the environment −170
Georgia Tech Research Corp. $875,000 Oct 2025 False DFARS 7019/7020 assessment scores, missing anti-malware, delayed System Security Plan
Illumina $9.8M Jul 2025 Misrepresented product cybersecurity and NIST/ISO alignment on government-sold sequencers
Aero Turbine / Gallant Capital $1.75M Jul 2025 Cybersecurity failures on Air Force work — reduced penalty for voluntary self-disclosure
Raytheon / RTX / Nightwing $8.5M May 2025 Ran defense work for years on a system with no compliant NIST 800-171 SSP
MORSE Corp. $4.6M Mar 2025 Unimplemented NIST 800-171 controls, inflated posture — started by a whistleblower
Guidehouse & Nan McKay $11.3M Jun 2024 Skipped required pre-launch cybersecurity testing — whistleblower received $1.95M
Verizon Business $4.09M Sep 2023 Government internet service missing required security controls
Penn State University $1.25M Oct 2023 Misrepresented NIST 800-171 self-assessment scores and POA&M timelines — insider-reported
Aerojet Rocketdyne $9M Jul 2022 Misrepresented 800-171 compliance — the whistleblowing employee received $2.61M
Comprehensive Health Services $930,000 Mar 2022 First Civil Cyber-Fraud settlement — failed to secure medical records as contracted

All settlements resolve allegations; they are not findings of liability. The pattern, however, is unambiguous — and the DOJ has said publicly that cybersecurity FCA enforcement will continue and increase.

How you get caught: your own people are the enforcement mechanism

Most of these cases did not start with a government audit. They started with a qui tam lawsuit — a False Claims Act provision that lets any insider (a sysadmin, a compliance manager, a former employee, even a subcontractor) sue on the government’s behalf and keep 15–30% of the recovery. The Aerojet engineer collected $2.61 million. The Guidehouse relator collected $1.95 million. Every person who has seen your real SPRS evidence has a seven-figure financial incentive to report the gap between what you scored and what you run — and federal law protects them from retaliation.

The math of an FCA case

  • Treble damages: the government recovers three times its loss.
  • Per-claim penalties: roughly $14,000–$28,000 per invoice — and on a multi-year contract, every monthly invoice can count as a separate claim.
  • Contract consequences: suspension, debarment, termination for default — on top of the settlement.
  • The trigger is the lie, not the breach. You do not need to be hacked. An inflated score alone is the false claim.

Five statements that create liability while CMMC is paused

  • “We submitted a 110 to SPRS.” — and any assessor would score you lower.
  • “We have an SSP.” — written last week, backdated in spirit, not describing your real environment.
  • “Those POA&M items are closed.” — they are not, but the score assumed they were.
  • “FIPS-validated encryption everywhere.” — it is enabled, but not validated modules.
  • “The pause means nobody is checking.” — DCMA checked LOGZONE. Score: −170.

What defensible looks like (and how fast you can get there)

The contractors that come through enforcement unscathed all have the same three artifacts: an honest, evidence-backed SPRS score (even if it is low), a real System Security Plan describing the environment as it actually is, and a dated POA&M showing credible remediation in progress. Honesty is a defense; optimism is not. An honest −50 with a funded plan is defensible. A fictional 110 is a lawsuit.

That is exactly what our fixed-fee gap assessment produces: your real score under the official DoD methodology, the evidence file behind every control, and a remediation plan priced 30–50% below typical US rates. See how we took a Virginia contractor from a $20,000 enclave quote to a defensible CMMC Level 2 posture in our CMMC enclave case study, or start with the free tools below.

Related reading

FAQ

Is CMMC Level 2 paused in 2026?

The assessment program’s rollout has shifted, but the underlying obligations have not: DFARS 252.204-7012 (implement NIST SP 800-171), 7019 (current SPRS score) and 7020 (government access to assess) remain in force in existing contracts. The pause changes who checks you and when — not what must be true when you certify.

Can the DOJ really fine me over a self-assessed SPRS score?

Yes. A self-assessment submitted to SPRS is a representation to the government. In June 2026, LOGZONE Inc. paid $507,144 after DCMA re-scored its self-assessed environment at −170, and Georgia Tech Research Corp. paid $875,000 in October 2025 over false 7019/7020 scores. Knowingly or recklessly inflated scores are actionable under the False Claims Act.

What if my SPRS score is honestly low?

A low, honest score with a dated POA&M is not fraud — it is the legally safer position. FCA liability attaches to knowing misrepresentation, not to being mid-remediation. The dangerous position is a high score you cannot evidence.

Can my own employee file a False Claims Act case against my company?

Yes. Under the qui tam provisions, any insider can file on the government’s behalf and receive 15–30% of the recovery — awards in cybersecurity cases have reached $2.61 million (Aerojet Rocketdyne) and $1.95 million (Guidehouse/Nan McKay). Anti-retaliation provisions protect them.

Does the CMMC pause mean I can wait to implement NIST 800-171?

No. The 800-171 obligation dates to 2017 and is contractual today. Waiting simply extends the window in which every invoice under a misrepresented score accumulates potential treble damages and per-claim penalties — and when CMMC assessments resume, unprepared contractors will be competing for scarce assessor slots.

Would your SPRS score survive a DCMA assessment?

Find out before the government — or a whistleblower — does. Free CMMC Level 2 gap assessment: your real score, the evidence gaps, and a fixed-fee remediation plan. Confidential, no obligation.

BOOK A FREE CMMC GAP ASSESSMENT

Need help applying this to your environment?

We turn compliance guides into shipped controls. Talk to an engineer.

Book a consultation