CMMC on Pause: What Companies in the DoD Supply Chain Should Know and Do Next (Part 3 of 4)

Oct 9, 2026

Author: Jeffrey Lemmermann

CPA, CISA, CITP, CEH - Sr. Information Assurance Consultant

Part 3: The CMMC Pause Does Not Pause False Claims Act Risk

 

In Parts 1 and 2 of this series, we explained that the Department paused the expansion of Phase II certification requirements but left Phase I self-assessment requirements and underlying cybersecurity obligations in place.

That leads to another issue that has not been paused:

Organizations can create significant exposure when their cybersecurity representations do not match actual conditions. This is where the federal False Claims Act becomes relevant.  Exposure to penalties under this act could come from:

  • An SPRS score is wrong or submitted without enough evidence.
  • A known deficiency is excluded from an assessment.
  • An executive signs an affirmation without receiving accurate information.
  • A proposal states that requirements are implemented when the organization is still working on them.
  • A customer is told that an IT environment uses a specific product to attain compliance with a contract requirement, yet the product was never fully configured.

Those situations may not begin as intentional fraud, but they can become serious issues when inaccurate representations are knowingly made, ignored, or allowed to continue.

 

What Is the False Claims Act?

The False Claims Act (FCA) is a federal law used to address false or fraudulent claims for government funds.  It was created in 1863 during the Civil War to stop defense contractors from defrauding the Union Army, then in 1986, it was amended to help fight government fraud.

In general terms, the FCA can be used against a person or organization that knowingly presents a false or fraudulent claim for payment; makes or uses a false statement material to a claim; or avoids an obligation to repay money owed to the government. The potential consequences can include three times the government’s damages and civil penalties associated with the false claims.

For defense suppliers, the core concepts and applicability of the FCA are apparent. If eligibility for a contract or payment depends on meeting cybersecurity obligations, inaccurate statements about those obligations may become material to the government’s decision.

 

“Knowingly” Does Not Always Mean Intentional Fraud

A critical part of the False Claims Act is its definition of knowledge. The government does not always need to prove that someone acted with a specific intent to defraud. The standard can include actual knowledge, deliberate ignorance, or reckless disregard for the truth/accuracy of information.

That matters when management sees warning signs but does not investigate them. Common examples of this would be:

  • An assessor reports that the SPRS score is unsupported, but the score is not corrected.
  • Employees repeatedly identify control failures, but management continues representing that the control is implemented.
  • An SSP describes tools or processes that are no longer in use.
  • A consultant’s findings are omitted from information provided to an executive.
  • Known CUI systems are excluded from scope without a defensible basis.
  • An organization submits the same assessment year after year without considering major changes to the environment.

Certainly not every mistake creates FCA liability, but when evidence shows the error or condition was known, or was consciously avoided, then the liability risk increases. For example, if a DOD contract requires security monitoring and incident reporting, but the organization does not implement the steps to enable the requirements while continuing to bill the government, action using the FCA becomes an option.

 

The Civil Cyber-Fraud Initiative

Utilizing the FCA as an enforcement tool, the DOJ announced its Civil Cyber-Fraud Initiative in 2021. This initiative focuses on organizations and individuals that knowingly provide deficient cybersecurity products or services; misrepresent cybersecurity practices or protocols; or violate obligations to monitor and report cybersecurity incidents. The initiative tells contractors that cybersecurity representations are considered part of contract integrity, and the result has been a growing number of cybersecurity-related settlements. Here are some examples that highlight exposure when contractual cybersecurity obligations, actual technical conditions, and the representations made to the government do not match:

Raytheon / Nightwing — $8.4 Million

Settlement announced: May 1, 2025
Alleged conduct period: 2015–2021

Raytheon Company, RTX Corporation, Nightwing Group LLC, and Nightwing Intelligence Solutions LLC agreed to pay $8.4 million to resolve False Claims Act allegations involving cybersecurity requirements on DoD contracts and subcontracts. The conduct predated Nightwing’s 2024 acquisition of the affected Raytheon business.

What they allegedly did wrong: Raytheon and its then-subsidiary Raytheon Cyber Solutions allegedly used a noncompliant internal development system to perform work on 29 DoD contracts and subcontracts. The government alleged that the system lacked a required System Security Plan and did not comply with other safeguards required under DFARS 252.204-7012 and FAR 52.204-21, even though it was used to develop, store, or process Covered Defense Information and FCI.

Why it matters: This case is a good example of how a seemingly “internal” system can create FCA exposure when it falls within the contract environment but is not included in the contractor’s security program. It also originated from a whistleblower action filed by a former Raytheon Director of Engineering, who received about $1.5 million from the settlement.

MORSECORP — $4.6 Million

Settlement announced: March 26, 2025
Relevant conduct period: 2018–2023

MORSECORP agreed to pay $4.6 million to resolve allegations involving Army and Air Force contracts. Unlike many FCA settlements, MORSE expressly admitted, acknowledged, and accepted responsibility for specific facts identified in the settlement.

What they did wrong: MORSE used a third-party email hosting provider without ensuring the provider met required FedRAMP Moderate-equivalent and DoD incident-response obligations; failed to fully implement required NIST SP 800-171 controls; lacked a consolidated written System Security Plan for covered systems for several years; and submitted an SPRS score of 104 in January 2021. In July 2022, a third-party cybersecurity consultant determined that the correct score was actually -142. MORSE did not update the score until June 2023, after receiving a government subpoena.

Why it matters: This touches nearly every CMMC-readiness issue: third-party providers, incomplete NIST 800-171 implementation, inadequate SSP documentation, and a materially overstated SPRS score. It also demonstrates why obtaining independent review is not enough if management does not act on the results. The whistleblower received $851,000.

Penn State — $1.25 Million

Settlement announced: October 22, 2024
Alleged conduct period: 2018–2023

Penn State agreed to pay $1.25 million to resolve allegations involving cybersecurity requirements in 15 DoD and NASA contracts and subcontracts.

What they allegedly did wrong: The government alleged that Penn State failed to implement required cybersecurity controls, did not adequately develop and execute plans of action to remediate known deficiencies, and submitted assessment information that overstated when deficiencies would be corrected. DOJ also alleged that Penn State used an external cloud service provider that did not satisfy DoD security requirements for Covered Defense Information on certain contracts.

Why it matters: This case is not simply about having open deficiencies. The more significant allegation was that the organization knew about the deficiencies, committed to remediation timelines, and did not adequately execute those plans. It also highlights the risk associated with cloud providers and inherited controls.

The case was initiated by a former Chief Information Officer of Penn State’s Applied Research Laboratory, who received $250,000 from the settlement.

 

The settlements generally resolved allegations without admissions of liability and should not be read as findings that every allegation was proven at trial. They do, however, demonstrate that the government is willing to pursue cybersecurity-related FCA allegations. The settlement itself is only part of the potential impact. Organizations may also face legal fees, forensic and assessment costs, management distraction, and reputational harm among the other direct and non-direct costs.

 

Whistleblowers and Third Parties Change the Risk

FCA risk does not depend only on whether a government assessor discovers a deficiency. The FCA allows private individuals to bring certain actions on behalf of the government. They can be brought by former employees, competitors, consultants, and others that have knowledge of the situation. As additional motivation, these individuals may receive a percentage of the government’s recovery if the case is successful.

Utilizing a third party can reduce this in many ways. A qualified third party can support a more disciplined and defensible process.  Third party assessments often challenge internal assumptions and identify situations where processes aren’t occurring as specified. Primary areas where third party assessors can provide defenses against FCA risk:

  • System boundary definition

An inaccurate boundary can undermine the entire assessment. A third party can help identify overlooked system components, external service providers, and locations where CUI is copied or exported.

  • Recalculate and support the SPRS score

A reviewer can evaluate whether the correct scoring methodology was used and whether deductions were properly applied.  When requirements marked as met are fully implemented, a third party can help identify or produce evidence to support each conclusion.

  • Identify deficiencies before a representation is made

Readiness work can identify a problem before a customer questionnaire is completed, an SPRS score is entered, or an annual affirmation is signed.  Management can then remediate the problem, revise the representation, document an allowable POA&M, or consult legal counsel.

  • Build a defensible evidence record

A third party can help organize evidence demonstrating management’s reasonable due diligence. The goal is not to create a large volume of paperwork but to ensure that important conclusions can be explained and supported.

SynerComm’s Role as a Registered Practitioner Organization

SynerComm has attained Registered Practitioner Organization status with The Cyber AB and has two Registered Practitioners on staff. As an RPO, SynerComm provides non-certified CMMC consulting and implementation assistance. This can include: 

  • readiness assessments
  • CUI scoping
  • review of NIST SP 800-171 implementation
  • SPRS score analysis
  • SSP development and review
  • technical control validation
  • evidence-readiness review
  • preparation for a formal C3PAO assessment

The purpose of this work is to help management develop an accurate, evidence-based, and defensible understanding of its current condition before making important compliance representations. Readiness work helps the organization prepare, improve, and reduce uncertainty.

It is important to note that an RPO cannot perform a CMMC assessment. Official CMMC Level 2 assessments must be performed by an authorized C3PAO. This official assessment process is used to determine and report an official CMMC status.

 

When Legal Counsel Should Be Involved

A cybersecurity consultant can assess systems, controls, documentation, and evidence; however, a consultant should not provide legal conclusions about FCA liability. Organizations should consider involving qualified legal counsel when there are material concerns about FCA risk or exposure.

The Bottom Line

While the Phase II pause may change when certain organizations need a C3PAO certification assessment, it does not reduce the importance of accurate cybersecurity representations. The best way to manage FCA risk is to create a reasonable process that:

  • determines what requirements apply;
  • assesses the correct environment and identifies actual conditions;
  • reports results accurately;
  • corrects known errors and responds to current concerns;
  • documents management decisions; and
  • obtains legal advice when appropriate.

Independent third-party readiness assistance can strengthen that process. It cannot replace management judgment or accountability.

 

Coming Next

Understanding the pause and the associated risk is useful only if it leads to action.

In Part 4, we will provide a practical plan for how defense suppliers should use the pause, determine whether voluntary certification makes sense, and prepare for the program’s next phase.

This article provides general information and does not constitute legal advice. Organizations facing potential contractual, False Claims Act, disclosure, or reporting issues should consult qualified legal counsel.


This series provides general information and does not constitute legal advice. Organizations facing potential contractual, False Claims Act, disclosure, or incident-reporting concerns should consult qualified legal counsel.