Published September 14, 2026 | TIKC NewsWire
With CMMC’s third-party certification on pause, many defense contractors assumed the cybersecurity pressure eased. The opposite is true. The Department of Justice’s Civil Cyber-Fraud Initiative is using the False Claims Act to hold contractors accountable for the cybersecurity representations they self-report — and a June 2026 settlement shows exactly how your SPRS score can become a legal liability.
The LOGZONE Settlement
On June 18, 2026, defense contractor LOGZONE, Inc. agreed to pay $507,144 to resolve FCA allegations that it failed to meet the cybersecurity requirements in two Navy contracts. Two details make this case a warning shot for small contractors. First, the deficiency surfaced not from a whistleblower but from a government assessment — the Defense Contract Management Agency’s DIBCAC scored LOGZONE’s NIST SP 800-171 implementation at -170, near the bottom of the -203 to 110 range. Second, the restitution portion exceeded one-third of what the contracts had paid.
This Is a Trend, Not a One-Off
DOJ has now settled roughly 15 civil cyber-fraud cases since launching the initiative in October 2021, more than half of them under the current administration, and cyber-fraud resolutions have more than tripled in each of the last two years. In FY2025 alone, the initiative produced over $52 million across nine settlements — part of the record $6.8 billion FCA year. Names on the list include Raytheon/Nightwing ($8.4M), Guidehouse ($7.6M), and Georgia Tech Research Corp ($875K).
Why This Hits Small Contractors Hard
The whole model of Phase 1 CMMC is self-assessment — you score yourself against NIST SP 800-171 and post it to SPRS. That self-reported number is a representation to the government. If it’s inflated or unsupported and you keep taking contract payments, that’s the theory of an FCA case. And with DIBCAC actively assessing, the government doesn’t need a whistleblower to find the gap. Your SPRS score is now a legal document, not an internal IT metric.
What to Do Now
Make your SPRS score honest and supportable. Score against the real state of your systems, and keep the evidence — your system security plan and POA&M — that backs it up. Fix the gap between your score and reality. If you claimed controls you don’t have, remediate and correct the score. Treat the score as a certification, because DOJ does. Don’t let IT post a number leadership can’t stand behind in a deposition.
The Bottom Line
The pause on CMMC certification didn’t pause the law. DFARS 252.204-7012 still applies. Your SPRS score is still a legal representation attached to every invoice you submit on a covered contract. DOJ’s Civil Cyber-Fraud Initiative is still running, still settling cases, and — as LOGZONE shows — doesn’t need a whistleblower to find you. A defensible SPRS score, backed by a current system security plan and honest POA&M, is now table stakes for any defense contractor. Brick by brick.
Frequently Asked Questions
Isn’t CMMC paused? Why does this matter?
Phase 2 third-party certification is paused, but the underlying NIST SP 800-171 obligations, DFARS 252.204-7012, and your SPRS self-assessment remain fully in force. DOJ is enforcing false cyber representations through the FCA regardless of CMMC’s status — the certification pause changed who verifies your score, not whether your score needs to be accurate.
Do I need a whistleblower for DOJ to act?
No. The LOGZONE case arose from a government DIBCAC assessment, not a qui tam complaint — proactive government audits can trigger enforcement on their own. DIBCAC is actively assessing contractors’ NIST SP 800-171 implementation scores against their actual systems. If your posted score doesn’t match what an assessor finds, you have a problem regardless of whether any employee has filed a complaint.
What is a POA&M and why does it matter?
A Plan of Action and Milestones documents the security controls you have not yet fully implemented, the steps you are taking to implement them, and your target completion dates. It is required alongside your System Security Plan under DFARS 252.204-7012. A current, realistic POA&M is the evidence that your SPRS score accurately reflects a known, managed gap rather than a falsely inflated number — the difference between a compliance problem and an FCA problem.
References
Crowell & Moring LLP. (2026, June). How LOGZONE’s DIBCAC challenges put it in DOJ’s crosshairs. https://www.crowell.com
Mayer Brown. (2026, June). Alabama defense contractor to pay $507,144 to resolve False Claims Act cybersecurity allegations. https://www.mayerbrown.com
Sidley Austin LLP. (2026, June 23). DOJ reaches $507,144 settlement with defense contractor. https://www.sidley.com
About the Author
Melanie Patterson
Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact


