Summary:
LOGZONE settled for $507,144 after the Department of Justice (DOJ) alleged it falsely certified National Institute of Standards and Technology (NIST) SP 800-171 and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 compliance. Under the False Claims Act (FCA), false cybersecurity attestations risk treble damages, per claim penalties, and limited relief via the rare self-disclosure. The risk of inadvertently making false claims can be mitigated by compliance experts like Summit 7.
LOGZONE, a Huntsville, Alabama-based contractor, recently agreed to settle at $507,144 to resolve liability under the False Claims Act (FCA).
Under the False Claims Act, the Department of Justice (DOJ) alleged that LOGZONE knowingly submitted false or fraudulent claims for payment on two Navy contracts, knowing the company had not complied with the contracts’ NIST SP 800-171 and DFARS 252.204-7012 requirements.
DOJ further alleged that in 2021, LOGZONE self-reported a NIST SP 800-171 score of 110 in the Supplier Performance Risk System (SPRS), but a 2024 Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Medium Assessment allegedly scored the company at negative 170.
What is the False Claims Act?
Under the False Claims Act, knowingly false certifications can result in treble damages and civil penalties in the form of per-claim fees. This is what comes into play when your Cybersecurity Maturity Model Certification (CMMC) self-assessment doesn’t hold up under scrutiny.
Importantly, a security breach is not required for enforcement under FCA, only false claims.
What are the consequences under FCA?
Treble Damages
Treble damages mean a contractor guilty of false claims is responsible for paying 3x the amount of damages suffered by the government. For example, if the contractor overbilled the government by $100,000, they are responsible for paying back $300,000 in addition to per-claim fees.
Treble damages are generally mandatory, though the court may reduce the award to double damages under the rare self-disclosure and cooperation exception if:
- Organization discloses false claims before any investigation or legal action begins
- Organization self-reports the misconduct within 30 days of discovery
- Organization fully cooperates with the government
Per-Claim Fees
Under the FCA, each false claim can result in a penalty of up to $28,619. Each of the 110 NIST SP 800-171 controls can incur a separate penalty.
If a company falsely claims all 110 controls, that’s more than $3 million in per-claim fees alone.
Avoid False Claims with Expert Guidance
Hiring a qualified CMMC compliance expert dramatically reduces the risk of making a false claim, whether intentional or accidental. Not all FCA cases around cybersecurity happen because a contractor meant to deceive the government. They also happen because:
- organizations misunderstand the controls
- Internal teams overestimate compliance
- Documentation, evidence, or scope boundaries are incorrect or incomplete
- SPRS scores or affirmations are submitted without independent validation
Summit 7 can help you avoid these pitfalls by:
- Identifying gaps before they become legal liabilities
- Helping you correctly calculate and document your SPRS score
- Preparing accurate evidence packages
- Providing ongoing monitoring so your compliance stays valid throughout the contract lifecycle
Contact a Summit 7 expert to ensure an accurate path to compliance.


