
A cybersecurity certification has become one of the most consequential representations a federal contractor makes. When a company tells the government it meets a required security standard, that statement is now treated as a material term of the contract. If the statement is false, and the company knew or recklessly disregarded that it was false, the False Claims Act supplies treble damages and per-claim penalties. No data breach is required. The misrepresentation itself is the violation.
This enforcement theory has moved from emerging to entrenched. In the fiscal year ending September 2025, the Department of Justice recovered roughly $52 million across nine cybersecurity-related settlements, part of a record $6.8 billion in total False Claims Act recoveries, and reported that cybersecurity resolutions had more than tripled in each of the prior two years. The resolutions reached prime contractors, subcontractors, research universities, a product manufacturer, and a healthcare benefits administrator. This paper explains where the exposure attaches, how it flows across the supply chain, and how disciplined governance and self-disclosure mitigate the risk.
The Theory: Misrepresentation, Not Breach
The single most important clarification from DOJ is that these cases are not about data breaches. They are premised on misrepresentations. A company that suffers a sophisticated attack despite genuine compliance is not the target. The target is the company that certified compliance it did not have. As the Civil Division has framed it, enforcement attaches when an organization tells the government it complies with cybersecurity requirements and, in reality, does not.
This distinction matters because it locates the liability in the certification, not in the security incident. Three categories of conduct recur across the settlements:
- Deficient products or services. Delivering cybersecurity products or services that fail to meet the represented standard.
- False compliance representations. Certifying adherence to a required framework, or submitting an inflated assessment score, when the controls are not in place.
- Failure to monitor and report. Neglecting an obligation to scan for known vulnerabilities, remediate them, or report incidents as the contract requires.
A defendant's first analytical task is to determine which category the government's theory occupies, because the defense differs accordingly. A deficient-product theory turns on technical specification and performance. A false-certification theory turns on knowledge and materiality. A failure-to-monitor theory turns on the scope and timing of a contractual duty.
The Frameworks That Become Material Terms
Cybersecurity obligations enter federal contracts through a layered set of regulations. Understanding which framework applies, and at what baseline, is essential to assessing exposure. The principal sources are these.
DFARS 252.204-7012 and NIST SP 800-171. For Department of Defense contractors handling controlled unclassified information, the Defense Federal Acquisition Regulation Supplement requires information systems that meet the controls specified in NIST Special Publication 800-171. A contractor that submits a self-assessment score overstating its implementation of those controls makes a representation the government now treats as material.
FAR 52.204-21. Even outside the defense context, basic safeguarding of federal contract information is mandatory. This clause requires minimum controls such as access limitation, antivirus protection, and firewalls. Settlements have rested on the absence of a system security plan and the lack of these basic controls.
FedRAMP and NIST SP 800-53. A contractor that handles federal data through cloud services must meet FedRAMP authorization at the appropriate baseline, drawing on the NIST SP 800-53 controls. One 2025 settlement rested on a contractor's use of an unapproved third-party email host that did not meet the FedRAMP Moderate baseline.
CMMC, now contractually embedded. Effective November 10, 2025, the Department of Defense incorporated Cybersecurity Maturity Model Certification requirements into DFARS clauses 252.204-7021 and 252.204-7025, making cybersecurity verification a condition of award and of performance. By hardwiring verification into eligibility, the rule raises the stakes for any contractor handling federal contract information or controlled unclassified information.
How Exposure Flows Across the Supply Chain
The 2025 settlements demonstrate that liability is not confined to prime contractors. It reaches down and across the supply chain, and the variety of defendants is instructive.
- Prime contractors. A defense prime resolved allegations that its internal network failed to meet basic safeguarding requirements across numerous contracts, with no system security plan in place.
- Subcontractors. In December 2025, a precision machining supplier resolved allegations that it knowingly failed to provide adequate cybersecurity, as required by DFARS 252.204-7012, for technical drawings it supplied to contractors. The case began with a qui tam action by a former quality control manager.
- Product manufacturers. A genomic sequencing manufacturer paid roughly $9.8 million to resolve allegations that it sold systems with cybersecurity vulnerabilities and falsely represented adherence to security standards.
- Research institutions. A research corporation affiliated with a university paid $875,000 over alleged failures to install required protections and a false assessment score submitted to the Department of Defense. Grant recipients, not only commercial contractors, face exposure.
- Healthcare administrators. A contractor administering health benefits for servicemembers paid roughly $11.2 million over allegations that it falsely certified compliance and failed to timely scan for and remediate known vulnerabilities.
The subcontractor case deserves particular attention. A false-certification theory can attach at any tier where a security representation was made, and the obligation often flows down through contract clauses from the prime to its suppliers. A subcontractor that certifies DFARS compliance to a prime may face direct FCA exposure even though it never dealt with the government directly. Companies should map where in their contracting chain security representations are made, because that is where the liability attaches.
Defending the False-Certification Theory
The FCA requires that the defendant acted knowingly, which includes actual knowledge, deliberate ignorance, and reckless disregard. It does not require a specific intent to defraud. The government must also establish materiality, that the cybersecurity representation was capable of influencing the government's payment decision. These two elements, scienter and materiality, are the core of the defense.
Contest scienter on the certification. A good-faith, reasonable interpretation of an ambiguous standard can defeat the knowledge element. Where the contractor reasonably believed its controls satisfied the requirement, or where the assessment score reflected a defensible methodology, the reckless-disregard standard is not met. Documentation of the compliance judgment at the time it was made is the strongest evidence.
Test materiality rigorously. Not every cybersecurity shortfall is material to payment. Where the government continued to pay with knowledge of the alleged deficiency, or where the requirement was peripheral to the contract's purpose, materiality is contestable. The materiality inquiry is fact-intensive and forum-sensitive, and it is often the most productive line of defense.
Develop the facts early through internal investigation. Because these cases turn on what the company knew and when, disciplined factual development is decisive. Our internal investigations teams reconstruct the compliance timeline, identify who made the representation and on what basis, and assess the gap, if any, between certification and practice before the government's theory hardens.
Governance and Self-Disclosure as Mitigation
The most effective defense begins before any investigation. Two practices materially reduce both the likelihood and the severity of FCA exposure.
Accurate, documented certification governance. A company should ensure that every cybersecurity representation made to the government is accurate when made and supported by a contemporaneous record. Self-assessment scores should reflect a defensible methodology. When a score is later found to be wrong, prompt correction matters, because failure to update a known-incorrect score is precisely the conduct the settlements have punished. A governance process that ties each certification to an evidentiary basis is the single best protection against a false-certification theory.
Timely self-disclosure. When a company discovers a genuine compliance gap, early and voluntary disclosure can reduce exposure and reframe the government's posture. Disclosure decisions are consequential and fact-specific, and they interact with the materiality and scienter analysis. Our pre-litigation counseling teams help contractors evaluate whether, when, and how to disclose, balancing the mitigation benefit against the risk of creating an admission, so that the decision is made deliberately rather than reactively.
Conclusion
Cybersecurity compliance is no longer a matter of technical hygiene alone. It is a source of False Claims Act exposure that reaches every tier of the federal supply chain, driven by whistleblowers and anchored in the gap between what a company certifies and what it actually does. The record recoveries of fiscal year 2025, and the embedding of CMMC verification into the DFARS, signal that this enforcement priority will persist. The defendants best positioned to manage the risk are those who treat every cybersecurity certification as the material representation the government now considers it to be, who document the basis for each, and who develop the facts early when a question arises. Accuracy in what a company tells the government about its security posture is the foundation of the defense, in court and before a matter ever reaches one.
Certifications, contracts, and the read that follows.
Where Your Program Stands
Contractors and grant recipients across the supply chain are asking a version of this question right now, in procurement offices, compliance departments, and general counsel's offices alike. Our attorneys concentrate in False Claims Act Litigation, and bring that same depth to matters touching cybersecurity certifications and government contracts. If it would help to talk through your own posture, we're glad to.