Contact Us

Certifying a Cybersecurity You Do Not Have: CMMC, NIST 800-171, and Cyber-Fraud

Published 2026 | TIKC NewsWire

For years, cybersecurity requirements felt like checkbox paperwork to many contractors. Those days are over. The Department of Justice now treats a false cybersecurity claim as fraud, pursuing it under the False Claims Act through its Civil Cyber-Fraud Initiative. If you handle federal information and certify that you meet standards like NIST SP 800-171 or carry the required CMMC level, that certification is a representation the government can and will test. The gap between what you claimed and what you actually had in place is the entire case, and it is being enforced right now.

The requirements you are certifying

Defense contractors handling covered defense information are generally required to implement the security controls in NIST SP 800-171 and to report an accurate score reflecting their implementation. The Cybersecurity Maturity Model Certification, or CMMC, builds on this by requiring contractors to demonstrate a certified level of maturity appropriate to the information they handle. When you submit a score or assert a CMMC level, you are telling the government your systems actually meet those controls. If they do not, and you knew it, you have made a false statement tied to the contract.

How a cyber claim becomes a false claim

The theory is the same one behind the broader enforcement wave. When you certify compliance to win or keep a contract and then invoice, the government argues every payment request carried an implied certification that you met the cybersecurity terms. If you reported a near-perfect score while your real posture was far lower, that is a knowing misrepresentation. This is exactly the fact pattern behind the cybersecurity score case we have covered, where the distance between the certified number and the true number was the whole problem.

GovCon iSource. Your pipeline runs while you run your business.

Where small contractors slip

Few small firms set out to lie about security. They overstate readiness under deadline pressure, or they treat a point-in-time assessment as permanent. A common pattern is certifying a score based on a plan to implement controls, then never finishing the plan, so the real posture drifts far below the reported number. Another is assuming your IT vendor handled compliance without confirming it. The protections you build for an insider threat are part of the same framework, so controls you skipped on the cyber side often leave your controlled information exposed in more ways than one.

The whistleblower multiplier

Cyber-fraud cases are especially exposed to insiders, because the people who know your security is weaker than your paperwork says are your own IT staff and engineers. A frustrated employee who watched the company report a score it did not earn is a ready-made relator. Like most False Claims Act matters, these cases frequently begin with a whistleblower suit, which is why an accurate score and an honest plan of action are not just compliance hygiene. They are your best protection against the person down the hall.

What to do now

  • Know your real score. Conduct an honest NIST SP 800-171 assessment and report the number you can actually support with evidence.
  • Finish your plan of action. If you certified based on a plan, track it to completion and keep the milestones current.
  • Verify your vendor. Confirm in writing what your IT provider actually implemented, rather than assuming compliance.
  • Document everything. Keep assessment records, system security plans, and evidence that your controls exist and operate.
  • Prepare for CMMC. Understand the certification level your contracts require and build toward it honestly before you assert it.

Cybersecurity compliance is no longer a form you file and forget. It is a promise the government will test and enforce. Report what is true, finish what you started, and let your paperwork match your systems. Brick by brick.

Not sure where you fit? Start with a call. Book Free Call.

FAQ

What is the Civil Cyber-Fraud Initiative?

A Department of Justice effort that uses the False Claims Act to pursue contractors who knowingly misrepresent their cybersecurity compliance or fail to report cyber incidents as required.

What is the difference between NIST 800-171 and CMMC?

NIST SP 800-171 is the set of security controls for protecting covered defense information. CMMC is the framework that requires contractors to demonstrate a certified level of maturity in implementing those controls.

How does a false cybersecurity claim become fraud?

When you certify compliance to win or keep a contract and then bill, the government treats each payment request as carrying an implied certification that you met the cyber terms. A knowing overstatement is a false claim.

How do these cases usually start?

Often with a whistleblower. Your own IT staff and engineers know whether your real security matches your reported score, which makes insiders a common source of cyber-fraud cases.

GovCon iSource. Your pipeline runs while you run your business.

Sources

U.S. Department of Justice. (2026). Civil Cyber-Fraud Initiative and False Claims Act enforcement for cybersecurity misrepresentations.

National Institute of Standards and Technology. (2026). Special Publication 800-171, Protecting Controlled Unclassified Information, and the CMMC program.

This article is general information, not legal advice.

Melanie Patterson

About the Author

Melanie Patterson

Founder and CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale, brick by brick. Contact

Most Read

When performance slips, the government does not just walk away. It sends a cure notice
On many negotiated contracts you must certify that your cost or pricing data is accurate,

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading