Enforcement briefing · CMMC / NIST 800-171 / False Claims Act · Updated August 2026
CMMC Level 2 assessments may be paused — the Department of Justice is not. In June 2026, Alabama defense contractor LOGZONE Inc. agreed to pay $507,144 under the False Claims Act after DCMA re-assessed its self-reported cybersecurity posture and scored it −170 out of a possible 110. If your SPRS score is self-assessed and optimistic, you are not “waiting for CMMC.” You are carrying open federal liability, today.
The most expensive sentence in the defense industrial base
“CMMC is paused, so we’ll just self-assess and sort it out later.” Thousands of contractors are saying some version of this in 2026 — and it confuses two completely different things. The CMMC assessment program (who checks you) has shifted timelines. Your obligations (what must be true) never moved: DFARS 252.204-7012 has required full NIST SP 800-171 implementation since 2017, and DFARS 252.204-7019/7020 require a current, accurate SPRS score before award. The moment you submit that score, you have made a representation to the U.S. Government. If it is knowingly false — or recklessly optimistic — every invoice you submit afterward can become a separate false claim.
That is not a theory. It is the exact pattern the DOJ’s Civil Cyber-Fraud Initiative has been settling, case after case, at growing pace.
The enforcement record: real companies, real dollars
| Company | Amount | When | What the DOJ alleged |
|---|---|---|---|
| LOGZONE Inc. (Alabama) | $507,144 | Jun 2026 | Claimed compliance on two Navy contracts; DCMA assessment scored the environment −170 |
| Georgia Tech Research Corp. | $875,000 | Oct 2025 | False DFARS 7019/7020 assessment scores, missing anti-malware, delayed System Security Plan |
| Illumina | $9.8M | Jul 2025 | Misrepresented product cybersecurity and NIST/ISO alignment on government-sold sequencers |
| Aero Turbine / Gallant Capital | $1.75M | Jul 2025 | Cybersecurity failures on Air Force work — reduced penalty for voluntary self-disclosure |
| Raytheon / RTX / Nightwing | $8.5M | May 2025 | Ran defense work for years on a system with no compliant NIST 800-171 SSP |
| MORSE Corp. | $4.6M | Mar 2025 | Unimplemented NIST 800-171 controls, inflated posture — started by a whistleblower |
| Guidehouse & Nan McKay | $11.3M | Jun 2024 | Skipped required pre-launch cybersecurity testing — whistleblower received $1.95M |
| Verizon Business | $4.09M | Sep 2023 | Government internet service missing required security controls |
| Penn State University | $1.25M | Oct 2023 | Misrepresented NIST 800-171 self-assessment scores and POA&M timelines — insider-reported |
| Aerojet Rocketdyne | $9M | Jul 2022 | Misrepresented 800-171 compliance — the whistleblowing employee received $2.61M |
| Comprehensive Health Services | $930,000 | Mar 2022 | First Civil Cyber-Fraud settlement — failed to secure medical records as contracted |
All settlements resolve allegations; they are not findings of liability. The pattern, however, is unambiguous — and the DOJ has said publicly that cybersecurity FCA enforcement will continue and increase.
How you get caught: your own people are the enforcement mechanism
Most of these cases did not start with a government audit. They started with a qui tam lawsuit — a False Claims Act provision that lets any insider (a sysadmin, a compliance manager, a former employee, even a subcontractor) sue on the government’s behalf and keep 15–30% of the recovery. The Aerojet engineer collected $2.61 million. The Guidehouse relator collected $1.95 million. Every person who has seen your real SPRS evidence has a seven-figure financial incentive to report the gap between what you scored and what you run — and federal law protects them from retaliation.
The math of an FCA case
- Treble damages: the government recovers three times its loss.
- Per-claim penalties: roughly $14,000–$28,000 per invoice — and on a multi-year contract, every monthly invoice can count as a separate claim.
- Contract consequences: suspension, debarment, termination for default — on top of the settlement.
- The trigger is the lie, not the breach. You do not need to be hacked. An inflated score alone is the false claim.
Five statements that create liability while CMMC is paused
- “We submitted a 110 to SPRS.” — and any assessor would score you lower.
- “We have an SSP.” — written last week, backdated in spirit, not describing your real environment.
- “Those POA&M items are closed.” — they are not, but the score assumed they were.
- “FIPS-validated encryption everywhere.” — it is enabled, but not validated modules.
- “The pause means nobody is checking.” — DCMA checked LOGZONE. Score: −170.
What defensible looks like (and how fast you can get there)
The contractors that come through enforcement unscathed all have the same three artifacts: an honest, evidence-backed SPRS score (even if it is low), a real System Security Plan describing the environment as it actually is, and a dated POA&M showing credible remediation in progress. Honesty is a defense; optimism is not. An honest −50 with a funded plan is defensible. A fictional 110 is a lawsuit.
That is exactly what our fixed-fee gap assessment produces: your real score under the official DoD methodology, the evidence file behind every control, and a remediation plan priced 30–50% below typical US rates. See how we took a Virginia contractor from a $20,000 enclave quote to a defensible CMMC Level 2 posture in our CMMC enclave case study, or start with the free tools below.
- Calculate your real SPRS score — official weights, nothing saved
- All 110 controls with SPRS point values
- What the CMMC pause actually changed — and what it did not
Related reading
- Every cybersecurity False Claims Act settlement, 2022–2026 — amounts, allegations and the pattern behind them
- “CMMC is paused — can I just self-assess?” — what actually changed
- CMMC Phase 2 suspension explained — the timeline in plain English
- What SPRS score do you need for CMMC Level 2?
- CMMC compliance checklist — what assessors actually ask for
- What CMMC certification really costs and our cost index by contractor profile
- Do subcontractors need CMMC? — flow-down obligations
- CMMC for non-US suppliers — same clauses, same exposure
- CMMC readiness consulting — fixed-fee gap analysis and remediation
FAQ
Is CMMC Level 2 paused in 2026?
The assessment program’s rollout has shifted, but the underlying obligations have not: DFARS 252.204-7012 (implement NIST SP 800-171), 7019 (current SPRS score) and 7020 (government access to assess) remain in force in existing contracts. The pause changes who checks you and when — not what must be true when you certify.
Can the DOJ really fine me over a self-assessed SPRS score?
Yes. A self-assessment submitted to SPRS is a representation to the government. In June 2026, LOGZONE Inc. paid $507,144 after DCMA re-scored its self-assessed environment at −170, and Georgia Tech Research Corp. paid $875,000 in October 2025 over false 7019/7020 scores. Knowingly or recklessly inflated scores are actionable under the False Claims Act.
What if my SPRS score is honestly low?
A low, honest score with a dated POA&M is not fraud — it is the legally safer position. FCA liability attaches to knowing misrepresentation, not to being mid-remediation. The dangerous position is a high score you cannot evidence.
Can my own employee file a False Claims Act case against my company?
Yes. Under the qui tam provisions, any insider can file on the government’s behalf and receive 15–30% of the recovery — awards in cybersecurity cases have reached $2.61 million (Aerojet Rocketdyne) and $1.95 million (Guidehouse/Nan McKay). Anti-retaliation provisions protect them.
Does the CMMC pause mean I can wait to implement NIST 800-171?
No. The 800-171 obligation dates to 2017 and is contractual today. Waiting simply extends the window in which every invoice under a misrepresented score accumulates potential treble damages and per-claim penalties — and when CMMC assessments resume, unprepared contractors will be competing for scarce assessor slots.
Would your SPRS score survive a DCMA assessment?
Find out before the government — or a whistleblower — does. Free CMMC Level 2 gap assessment: your real score, the evidence gaps, and a fixed-fee remediation plan. Confidential, no obligation.