Skip to Main Content
Publications

Cybersecurity Compliance Remains a False Claims Act Risk Despite CMMC Phase II Suspension

Government contractors should not mistake the Department of Defense's (DOD) recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II certification requirements as any sort of reprieve from their cybersecurity requirements or the government's intent to enforce CMMC. The recently announced LOGZONE False Claims Act (FCA) settlement serves as a stark reminder of the Department of Justice's (DOJ) focus on and pursuit of contractors whose cybersecurity representations fail to match reality. This builds on FCA cybersecurity fraud recoveries more than tripling in each of the past two years, exceeding $52 million across nine settlements in fiscal year 2025 alone.1

Bottom Line

The suspension of CMMC Phase II is a welcome development that has dominated most government contracting headlines over the past weeks. Yet the DOJ does not need CMMC third-party assessments to bring claims under the FCA. Existing Defense Federal Acquisition Regulation Supplement (DFARS) contractual obligations – including compliance with NIST Special Publication 800-171 and reporting accurate Supplier Performance Risk System (SPRS) scores – remain fully enforceable, and the DOJ has demonstrated a consistent practice of using FCA liability to punish inaccurate self-assessments and unimplemented cybersecurity controls.2

The LOGZONE Settlement

On June 18, 2026, the DOJ announced that LOGZONE INC., a Huntsville, Alabama, defense contractor, agreed to pay $507,144 to resolve FCA liability relating to cybersecurity violations in Department of the Navy contracts. The settlement is modest in dollar terms but provides important takeaways for the defense industrial base.

LOGZONE provided logistics, inventory, and facilities support services under two Navy contracts at Stennis Space Center. Those contracts incorporated DFARS 252.204-7012 (requiring adequate security for covered defense information and implementation of NIST SP 800-171 controls), DFARS 252.204-7019, and DFARS 252.204-7020 (requiring contractors to post summary-level NIST SP 800-171 self-assessment SPRS scores).

In October 2021, LOGZONE posted a perfect SPRS self-assessment score of 110 out of 110. However, when the company underwent a Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) audit in February 2024, LOGZONE received a score of -170. This score was near the bottom of the possible range of -203 to +110. The DOJ alleged that, from May 2021 through March 2025, LOGZONE had not fully implemented NIST SP 800-171 controls for systems processing, storing, or transmitting covered defense information, including controls whose absence could lead to significant exploitation or exfiltration of that information.

A 280-point gap between a contractor's self-assessed score and the government's own assessment is precisely the type of discrepancy the DOJ will treat as a "knowing" misrepresentation under the FCA, whether through actual knowledge, deliberate ignorance, or reckless disregard.

CMMC Phase II Suspended but Cybersecurity Expectations Remain

On July 13, 2026, DOD announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. The Department stated it will conduct a comprehensive review to "align with acquisition transformation priorities, reduce barriers for small, medium, and nontraditional businesses, and replace bureaucratic compliance with scalable, resilient cybersecurity measures." The announcement coincided with a contemporaneous implementation letter from DOD's chief information officer detailing the impact of the suspension.

What the suspension does:

  • Suspends the transition to Phase II requirements, including all pending and future CMMC Level 2 certification assessments conducted by Certified Third-Party Assessment Organizations (C3PAO) and mandatory Level 3 assessments, conducted exclusively by DIBCAC.
  • Directs program managers to include only CMMC Level 1 (Self) or Level 2 (Self) assessments in solicitations and contracts during the suspension period.
  • Requires solicitations and contracts that include mandatory C3PAO or DIBCAC assessment requirements to be amended or modified.

What the suspension does not do:

  • It does not relieve contractors or subcontractors of their obligations to safeguard covered defense information under DFARS 252.204-7012.
  • It does not relieve contractors or subcontractors from their obligations to post accurate and timely SPRS self-assessment scores.
  • It does not prevent the DOJ from pursuing FCA claims against contractors and subcontractors who fail to uphold these obligations – as the LOGZONE settlement, announced five days before the Phase II suspension, makes clear.

The DOD explicitly stated that it will continue to enforce baseline compliance with NIST SP 800-171 Rev. 2 through Level 1 and Level 2 self-assessments and select DIBCAC-led assessments during the suspension.

Recent Cyber-FCA Enforcement Signals

LOGZONE is not an outlier. The DOJ has built a steady cadence of cybersecurity-based FCA enforcement since launching the Civil Cyber-Fraud Initiative in October 2021. The following settlements within the past 12 months illustrate the breadth and acceleration of enforcement:

Contractor

Amount

Key Allegations

A U.S. Defense Contractor (May 2025)

$8.4 million

Failed to implement required controls on internal development system used on 29 DOD contracts/subcontracts

MORSECORP (Mar. 2025)

$4.6 million

Non-compliant email hosting; inaccurate SPRS score of 104 vs. consultant score of -142

Health Net/Centene (Feb. 2025)

$11.25 million

Failed to scan for vulnerabilities and certified compliance annually despite known deficiencies (TRICARE contract)

Illumina (July 2025)

$9.8 million

Sold federal agencies genomic sequencing systems with known cybersecurity vulnerabilities

Penn State (Oct. 2024)

$1.25 million

Failed to implement controls on 15 DOD and National Aeronautics and Space Administration (NASA) contracts; non-compliant cloud provider for covered defense information

Georgia Tech (Sept. 2025)

$875,000

Failed to meet cybersecurity requirements in Air Force and Defense Advanced Research Projects Agency (DARPA) contracts

Aero Turbine/Gallant Capital (July 2025)

$1.75 million

Failed to comply with Air Force cybersecurity requirements; significant cooperation credit for self-disclosure


Practical Steps for Contractors and Subcontractors

  • Educate teams on identifying what information requires safeguarding. Cybersecurity compliance starts with knowing what information the company receives, creates, stores, transmits, or shares that qualifies as Controlled Unclassified Information (CUI) or Federal Contract Information (FCI). Contractors and subcontractors should not rely on the expectation of specific guidance from DOD or even federal agencies' marking and handling practices, which are often inconsistent with contractors' and subcontractors' obligations.
     
  • Verify SPRS scores against reality. A full self-assessment without the benefit of any independent review is dangerous. Consider conducting a privileged internal assessment comparing your posted SPRS score against actual NIST SP 800-171 control implementation. A 280-point gap of the kind DOJ alleged in LOGZONE is catastrophic; even modest discrepancies create FCA exposure. At a minimum, consult with a third party or counsel to vet some of the most frequent concerns.
     
  • Treat the Phase II suspension as cost relief rather than a compliance holiday. Self-assessment obligations remain. Government-led assessments can and will continue. The FCA does not require a CMMC certification to attach liability; contractual cybersecurity obligations are independently enforceable.
     
  • Review contracts, subcontracts, and flowdowns. Map every safeguarding and reporting obligation across your contracts and subcontracts and ensure subcontractor flowdowns are current and the associated reporting is monitored.
     
  • Preserve evidence of compliance. Document system security plans (SSPs), plans of action and milestones (POA&Ms), remediation timelines, assessment results, and annual attestations. These records are the decisive proof on scienter (knowledge) and materiality elements in FCA disputes.
     
  • Audit cloud service providers and external hosting. The MORSECORP and Penn State settlements demonstrate that using non-compliant third-party hosting or cloud services for covered defense information creates standalone FCA exposure.
     
  • Evaluate self-disclosure and cooperation posture. If an internal review reveals material inaccuracies or control gaps, consult counsel promptly regarding voluntary self-disclosure and remediation. The DOJ acknowledged significant cooperation credit in the Aero Turbine/Gallant Capital settlement, reducing the ultimate resolution amount.
     
  • Strengthen whistleblower intake and non-retaliation discipline. Many of the above cases were initiated by qui tam relators, often former employees with firsthand knowledge of companies' internal practices and posture. Strong internal reporting channels and prompt investigation protocols remain critical.
     
  • Prepare for government-led assessments. Despite the Phase II suspension, DIBCAC retains authority to conduct assessments. The LOGZONE DIBCAC assessment that uncovered the scoring discrepancy was precisely this type of government-initiated review. Additionally, for subcontractors, consider the audit obligations of the prime contractor.

The CMMC Phase II suspension may have shifted the timeline for third-party assessments, but it has done nothing to diminish the risk. Any company doing business with the DOD should assume that its cybersecurity self-assessments are being scrutinized by government assessors, DOJ, and potential qui tam relators. Companies can withstand scrutiny from each of these sources as long as they remain focused on detecting and closing gaps between their representations and the reality of their cybersecurity infrastructure.

Baker Donelson attorneys are actively monitoring developments in this area. For questions or more information about the amendments, please contact a member of the Firm's Government Enforcement and Investigations Group.

---

1 DOJ, FY2025 FCA Statistics Release (Jan. 16, 2026) (reporting $6.8 billion in FCA recoveries and over $52 million in cybersecurity fraud settlements in FY2025).

2 It should be noted that much of the conduct described here represents alleged conduct. The LOGZONE settlement with DOJ includes a disclaimer that the settlement is not an admission of liability or wrongdoing.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept