Contact Us

Your SPRS Score Is Now a Legal Liability: DOJ’s Cyber-Fraud Initiative Comes for Self-Assessments

⚡ Enforcement Alert

Published September 14, 2026 | TIKC NewsWire

With CMMC’s third-party certification on pause, many defense contractors assumed the cybersecurity pressure eased. The opposite is true. The Department of Justice’s Civil Cyber-Fraud Initiative is using the False Claims Act to hold contractors accountable for the cybersecurity representations they self-report — and a June 2026 settlement shows exactly how your SPRS score can become a legal liability.

The LOGZONE Settlement

On June 18, 2026, defense contractor LOGZONE, Inc. agreed to pay $507,144 to resolve FCA allegations that it failed to meet the cybersecurity requirements in two Navy contracts. Two details make this case a warning shot for small contractors. First, the deficiency surfaced not from a whistleblower but from a government assessment — the Defense Contract Management Agency’s DIBCAC scored LOGZONE’s NIST SP 800-171 implementation at -170, near the bottom of the -203 to 110 range. Second, the restitution portion exceeded one-third of what the contracts had paid.

This Is a Trend, Not a One-Off

DOJ has now settled roughly 15 civil cyber-fraud cases since launching the initiative in October 2021, more than half of them under the current administration, and cyber-fraud resolutions have more than tripled in each of the last two years. In FY2025 alone, the initiative produced over $52 million across nine settlements — part of the record $6.8 billion FCA year. Names on the list include Raytheon/Nightwing ($8.4M), Guidehouse ($7.6M), and Georgia Tech Research Corp ($875K).

GovCon iSource — Your pipeline runs while you run your business.

Why This Hits Small Contractors Hard

The whole model of Phase 1 CMMC is self-assessment — you score yourself against NIST SP 800-171 and post it to SPRS. That self-reported number is a representation to the government. If it’s inflated or unsupported and you keep taking contract payments, that’s the theory of an FCA case. And with DIBCAC actively assessing, the government doesn’t need a whistleblower to find the gap. Your SPRS score is now a legal document, not an internal IT metric.

What to Do Now

Make your SPRS score honest and supportable. Score against the real state of your systems, and keep the evidence — your system security plan and POA&M — that backs it up. Fix the gap between your score and reality. If you claimed controls you don’t have, remediate and correct the score. Treat the score as a certification, because DOJ does. Don’t let IT post a number leadership can’t stand behind in a deposition.

The Bottom Line

The pause on CMMC certification didn’t pause the law. DFARS 252.204-7012 still applies. Your SPRS score is still a legal representation attached to every invoice you submit on a covered contract. DOJ’s Civil Cyber-Fraud Initiative is still running, still settling cases, and — as LOGZONE shows — doesn’t need a whistleblower to find you. A defensible SPRS score, backed by a current system security plan and honest POA&M, is now table stakes for any defense contractor. Brick by brick.

Not sure where you fit? Start with a call. Book Free Call.

Frequently Asked Questions

Isn’t CMMC paused? Why does this matter?

Phase 2 third-party certification is paused, but the underlying NIST SP 800-171 obligations, DFARS 252.204-7012, and your SPRS self-assessment remain fully in force. DOJ is enforcing false cyber representations through the FCA regardless of CMMC’s status — the certification pause changed who verifies your score, not whether your score needs to be accurate.

Do I need a whistleblower for DOJ to act?

No. The LOGZONE case arose from a government DIBCAC assessment, not a qui tam complaint — proactive government audits can trigger enforcement on their own. DIBCAC is actively assessing contractors’ NIST SP 800-171 implementation scores against their actual systems. If your posted score doesn’t match what an assessor finds, you have a problem regardless of whether any employee has filed a complaint.

What is a POA&M and why does it matter?

A Plan of Action and Milestones documents the security controls you have not yet fully implemented, the steps you are taking to implement them, and your target completion dates. It is required alongside your System Security Plan under DFARS 252.204-7012. A current, realistic POA&M is the evidence that your SPRS score accurately reflects a known, managed gap rather than a falsely inflated number — the difference between a compliance problem and an FCA problem.

GovCon iSource — Your pipeline runs while you run your business.

References

Crowell & Moring LLP. (2026, June). How LOGZONE’s DIBCAC challenges put it in DOJ’s crosshairs. https://www.crowell.com

Mayer Brown. (2026, June). Alabama defense contractor to pay $507,144 to resolve False Claims Act cybersecurity allegations. https://www.mayerbrown.com

Sidley Austin LLP. (2026, June 23). DOJ reaches $507,144 settlement with defense contractor. https://www.sidley.com

Melanie Patterson

About the Author

Melanie Patterson

Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact

Most Read

Federal law protects contractor employees who report waste, fraud, or law violations — and punishes
The Anti-Kickback Act and the FAR gratuities rules criminalize improper payments up and down the

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading