Summary
Jacob and Jason discussed the first False Claims Act cybersecurity settlement based on alleged noncompliance with DFARS 252.204-7012, highlighting that it resulted from a contractor’s inaccurate SPRS self-assessment rather than a whistleblower complaint. They explained why organizations should treat SPRS submissions as legally significant certifications and warned that similar enforcement actions are likely.
Key Takeaways
- The first FCA settlement without a whistleblower stemmed from a DIBCAC assessment that found a contractor’s SPRS score was drastically overstated.
- SPRS self-assessment scores are legal certifications. Submitting a false score and billing the government can create False Claims Act liability under existing DFARS requirements.
- DFARS 252.204-7012 compliance has been enforceable since 2017 and is separate from the phased rollout of CMMC.
- Perfect SPRS scores attracted DIBCAC scrutiny. The DoD has used medium assessments to validate suspicious self-assessment scores and refer serious discrepancies to the Department of Justice.
- More FCA settlements are likely. Jacob and Jason believe many additional cases could emerge from DIBCAC assessments conducted over the past several years.
The DOJ has announced its first cybersecurity False Claims Act settlement of 2026, and the details should get every defense contractor’s attention.
In this episode, we break down the LOGZONE settlement, the difference between DFARS 252.204-7012 and CMMC, how a perfect SPRS score became a DIBCAC assessment score of -170, and why this case may be a preview of additional enforcement actions still working their way through the system.
Topics covered:
What this means for defense contractors moving forward
LOGZONE FCA settlement details
DFARS 252.204-7012, 7019, and 7020
SPRS self-assessment scores
DIBCAC medium assessments
Why no whistleblower was required
Transcript
[00:00] — Jacob
All right, folks. It is June 2026, and the first False Claims Act cybersecurity settlement for alleged noncompliance with DoD cybersecurity requirements has just dropped.
And boy, is it a doozy.
Can a single phone call from DIBCAC auditors cost you 75% of the value of your defense contract?
That’s what we’re going to talk about today.
[00:29] — Jacob
Jason, this is a spicy one because this False Claims Act settlement didn’t involve a whistleblower.
The contractor entered a perfect 110 self-assessment score into the SPRS database.
DIBCAC called them in 2020, and it turned out their actual score was negative 170.
Now they’re paying $500,000 to the government, and the contracts in question were only worth $680,000.
[01:05] — Jason
You say there wasn’t a whistleblower, but sometimes people tell on themselves.
It’s like trying to sneak a couple of cookies and forgetting to wipe the crumbs off your face.
What blows my mind is the percentage of the contract value tied to the penalty.
With previous FCA settlements, we’ve usually said, “I’m surprised that’s so low.”
Then this one comes along.
No whistleblower.
They told on themselves by entering the score.
DIBCAC came calling.
This one’s going to sting.
[01:43] — Jacob
People might hear “$500,000” and think that’s not much money.
If you think that, can you adopt me?
Half a million dollars is a lot of money.
It’s especially significant because this contractor has fewer than 50 employees.
They only earned $680,000 from the contracts in question.
Once you account for overhead, operating costs, and inflation over the years since they were paid, they almost certainly lost money on those contracts.
I don’t know many small defense contractors that can afford to lose money on awarded work.
When you hear “$500,000,” remember the context.
Relative to the contract value, it’s enormous.
Is the False Claims Act juice really worth the squeeze?
I don’t think so.
[02:29] — Jacob
We’ll come back to this at the end, but I have a theory.
I think we know a lot more now about those hundred-plus rumored False Claims Act cases.
This settlement may show exactly how DIBCAC approached many of them.
I think we’re going to see a lot more cases that look just like this.
Let’s get into the details.
DFARS 252.204-7012 and CMMC are different things.
Defense contracts have included DFARS 252.204-7012 since 2017.
When you accept one of those contracts, you’re attesting that you’ve fully implemented the cybersecurity requirements in NIST SP 800-171.
In 2020, CMMC 1.0 was released.
People forget it had two separate parts.
One part was CMMC itself, which paused during rulemaking and is now rolling out.
The other part never paused.
That was the DoD Assessment Methodology, which created DFARS 252.204-7019 and 7020.
Those clauses required contractors to:
- Conduct a self-assessment.
- Calculate a score.
- Upload that score into SPRS.
All of that remained active while people assumed CMMC would never happen.
Many organizations pencil-whipped perfect 110 scores into SPRS.
Those SPRS submissions are official statements to the government.
The moment you submit an invoice under those contracts, you’re certifying compliance.
If that certification isn’t true, you’ve violated the False Claims Act.
Whether a whistleblower reports you or the government investigates on its own is no longer under your control.
Many companies with perfect SPRS scores eventually received calls from DIBCAC.
We discussed DIBCAC’s presentation at CS2, where the DoD explained that perfect SPRS scores were a major red flag.
If you submitted a perfect score, they were likely to call and ask a few questions.
In this case, the contractor failed that sniff test.
They were found noncompliant on contracts performed years ago.
This had nothing to do with CMMC.
If you entered a perfect SPRS score and later got a call from DIBCAC, you probably know exactly what we’re talking about.
[05:29] — Jason
I probably know a few people who are watching right now.
I talk to organizations that say, “We’ll just enter a 110 while we finish the work so we can keep building our government business.”
Every time I hear that, I tell them this isn’t going to end the way they think it will.
One thing that stood out in this settlement is that every invoice they submitted effectively repeated the same false certification.
Every time they billed the government, they were saying, “We’re compliant.”
They weren’t.
That’s exactly what I warn people about.
This isn’t going to end well.
I think we’re going to see a lot more of these.
[06:17] — Jacob
I think so.
Another detail that caught everyone’s attention on LinkedIn:
There was no whistleblower.
Normally, False Claims Act cases involve an employee filing what’s known as a qui tam lawsuit, alleging fraud against the government.
If the government joins the case and reaches a settlement, the whistleblower receives part of the recovery.
We’ve seen many of those.
This case was different.
DIBCAC conducted a medium assessment under the DoD Assessment Methodology.
Even today, DIBCAC can contact organizations and evaluate compliance with existing cybersecurity requirements.
This has nothing to do with the current CMMC rollout.
High assessments were conducted on-site.
Medium assessments were typically conducted over the phone.
According to the allegations, this contractor’s cybersecurity posture was so poor that DIBCAC identified major deficiencies during a phone interview alone.
The case was referred to the Department of Justice.
DIBCAC moved on to the next perfect SPRS score.
Now, years later, the contractor is writing a $500,000 check.
[08:02] — Jason
That’s one of the craziest parts of the story.
A medium assessment is probably the easiest type of assessment to get through.
They’re talking to you over the phone.
They’re not looking at your systems.
They’re asking questions.
If you’ve been submitting perfect 110 scores, earned more than $600,000 on contracts, and still can’t explain your compliance story, that’s a serious problem.
You couldn’t even get the story straight.
[08:29] — Jacob
Maybe they didn’t understand NIST SP 800-171A.
Maybe they planned to update the score later.
There are plenty of possible explanations.
Ultimately, none of them matter.
They told the government they were perfect.
They got paid based on that representation.
It turned out they weren’t.
Now the government wants its money back—with interest.
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.
