Listen to this post

This summer, defense contractors have received two very different signals about federal cybersecurity compliance. On one front, the Department of Justice (DOJ) is continuing to pursue False Claims Act (FCA) liability for contractors that misrepresent their cybersecurity posture—now with two settlements in quick succession targeting noncompliance with NIST SP 800-171 requirements. On the other, the newly renamed Department of War suspended the next phase of the Cybersecurity Maturity Model Certification (CMMC) program. Neither development changes the baseline obligations contractors already have, but together they illustrate how fluid—and consequential—this space remains.

The DOJ Settlements: Self-Assessed Scores Are Not Self-Executing

The government’s theory tracks a pattern we’ve flagged before in this space: a contractor’s own compliance certification became the evidence used against it. According to DOJ, from May 2021 to March 2025, the contractor allegedly submitted a perfect self-assessment score of 110 but failed to implement the cybersecurity controls in NIST SP 800-171. The failures were identified in 2024 when the Defense Contract Management Agency assessed the contractor’s implementation of the NIST SP 800-171 security controls and scored the contractor at a negative 170 (the scoring range in SP 800-171 is from -203 to +110).

The DOJ contends that when these controls are not implemented, the failures could lead to significant exploitation of the system or exfiltration of sensitive defense information. The alleged gap between what the contractor told the government and what it actually had in place surfaced the way these cases increasingly do—through a government-run audit rather than a whistleblower.

As shown by the scoring values, the gap between the contractor’s self-reported score and the DCMA assessment was allegedly substantial. Assistant Attorney General Brett A. Shumate of DOJ’s Civil Division stated: “Government contractors that obtain sensitive defense information in administering their contracts must follow required cybersecurity standards,” and “The Justice Department will continue to investigate potential violations of these cybersecurity requirements in order to protect this critical information from external threats.” The U.S. Attorney for the Northern District of Alabama called the case a reminder that “[a]dherence to the cybersecurity provisions of contracts with the federal government must be a priority for all contractors.”

DOJ also tied the resolution to its broader enforcement infrastructure, noting that “[t]his year the Administration launched the Task Force to Eliminate Fraud and the National Fraud Enforcement Division to enhance the Administration’s war on fraud, waste, and abuse in federal programs” and that FCA matters “will continue to be on the forefront of the battle against fraud.” That  framing positions cyber-related FCA cases within a coordinated, multi-agency enforcement priority.

Less than a week after the settlement announcement, DOJ provided additional context on the scope of its cyber-fraud enforcement. In a June 24, 2026 statement for the record before the House Science, Space, and Technology Committee, Deputy Assistant Attorney General Brenna E. Jenny, who supervises the Civil Fraud Section, stated that “[o]ver the past five years, the Department has settled 15 cyber fraud matters, for total settlements of over $73.5 million” and that “one qui tam relator settled a cyber fraud case during that period for $9 million.” DAAG Jenny characterized cybersecurity enforcement as “an area where the Department has seen significant growth in the last several years,” and confirmed that DOJ has “also opened numerous, non-public, cyber fraud matters” beyond the publicly announced settlements. The data indicates that the settlement is part of a broader enforcement pattern spanning defense contractors, healthcare administrators, universities, and grantees.

A Second Settlement: Larger Dollar Amount, Different Trigger

On September 1, 2026, less than three months after the Huntsville resolution. DOJ announced that a major aerospace defense contractor agreed to pay over $2 million to resolve allegations that it violated the False Claims Act by failing to comply with cybersecurity requirements in a contract with the U.S. Department of Defense.

The enforcement theory is the same: the settlement resolves allegations that over a multi-year period, the contractor submitted false claims for payment by failing to comply with cybersecurity requirements specified in NIST SP 800-171 with respect to one of its networks, as required by the contract and regulation.

The DOJ’s remarks tracked its earlier enforcement messaging. Assistant Attorney General Shumate reiterated that contractors handling defense information “must follow required cybersecurity standards” and that DOJ “will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.” The U.S. Attorney for the district where the case was filed emphasized that “[c]ybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data.”

Unlike the Huntsville case, this matter originated as a whistleblower action. The allegations arose from a qui tam lawsuit filed under the False Claims Act by a former employee of the contractor. Under the settlement, the whistleblower will receive a share of the recovery.

DoW Suspends the Implementation of CMMC Phase II – Third Party Assessments

Shortly after the first DOJ settlement, the Department of War (DoW) moved in a different direction on the compliance side of the ledger. The Department announced the immediate suspension of the implementation of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were originally scheduled to come into effect on November 10, 2026. All self-assessment and annual attestation requirements for CMMC Levels 1 and 2 remain in place. This suspension only applies to the next tier of third-party certification obligations by CMMC Third-Party Assessment Organizations (C3PAOs) for defense contractors handling Controlled Unclassified Information (CUI), not a withdrawal from cybersecurity oversight.

The Department framed the pause as part of a larger deregulatory push tied to Secretary Pete Hegseth’s acquisition priorities. According to the release, the Department will begin a comprehensive review of CMMC aimed at aligning with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS) directives prioritizing speed to capability, lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures. The Department was candid about why: “[w]hile the current CMMC program was designed to enhance DIB cybersecurity, instead it has created prohibitive compliance costs and bureaucratic burdens,” and “[r]ecent data, including reports from the Small Business Administration (SBA), confirmed that CMMC compliance is forcing innovative companies out of the Defense Industrial Base (DIB) which will delay the delivery of critical capabilities to the warfighters.”

DoW Chief Information Officer Kirsten A. Davies stated: “In support of Secretary Pete Hegseth’s directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program.” She added that the underlying security expectations remain: “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape.” Under Secretary of War for Acquisition and Sustainment Michael Duffey described a “strategic imperative to reduce bureaucracy,” stating that the decision “ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain.”

Operationally, the release explains that the Department CIO is establishing a CMMC Reform Task Force to conduct a comprehensive top-to-bottom review of the certification program, drawing on “industry feedback from our public Request for Information (RFI) regarding compliance challenges” and delivering “their final report to the DoW CIO within 60 days.” In the interim, the Department will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, focusing on tangible cyber hygiene rather than administrative overhead.

Why This Matters

The DoW was explicit that this pause does not affect the underlying legal obligation to protect covered defense information: “[i]t is critical to note that this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.”

Read together, the DOJ settlements and the CMMC Phase II suspension reflect two distinct aspects of federal cybersecurity oversight. The Department of War is suspending a layer of third-party certification requirements it views as impeding acquisition, while DOJ continues to use the False Claims Act to address representations contractors make about their NIST SP 800-171 controls. The two settlements—one surfaced by a DCMA audit, the other by a whistleblower—illustrate that these cases can originate from multiple channels. DAAG Jenny’s testimony provides additional scale: 15 settlements totaling more than $73.5 million in five years, with “numerous, non-public, cyber fraud matters” in the pipeline. The suspension of the C3PAO assessments that were called for under CMMC Phase II does not alter the FCA exposure associated with inaccurate compliance representations.

Key Takeaways

• The DOJ resolutions illustrate that a contractor’s cybersecurity representations—whether a self-assessed score contradicted by a government audit or compliance certifications challenged by a whistleblower—can form the basis for FCA liability.

• CMMC Phase II is suspended, not repealed, and DFARS 252.204-7012 and the NIST SP 800-171 baseline remain fully in force during the Department’s 60-day review.

• Contractors may wish to view the suspension as an opportunity to reassess compliance costs, while recognizing that self-assessment accuracy (Phase I obligations that remain in place) is the area where this type of FCA exposure arises.

• Government-led NIST SP 800-171 assessments are expected to continue even without the added Phase II certification layer. As DAAG Jenny’s testimony noted, DOJ’s cyber-fraud enforcement extends beyond the publicly announced cases, and the audit mechanisms that generated the Huntsville matter remain in place. The second settlement demonstrates that whistleblower actions are an additional, independent enforcement channel.

We will continue to track the CMMC Reform Task Force’s work and DOJ’s Civil Cyber-Fraud enforcement activity as both evolve over the coming months.

If you have questions about how these recent developments will impact your organization, contact Erik Dullea, Kip Randall, Nicole Prefontaine, or your Husch Blackwell attorney.