DOJ Ramps Up Cyber-FCA Cases as DoD Pauses CMMC Phase II
Defense contractors face heightened False Claims Act enforcement for cybersecurity lapses even as the Department of War suspends new third-party certification rules.
The Department of Justice has continued its aggressive enforcement of cybersecurity standards for federal contractors, recently securing two False Claims Act (FCA) settlements for over $2.5 million combined. The cases, one prompted by a government audit and the other by a whistleblower, alleged that contractors misrepresented their compliance with NIST SP 800-171 cybersecurity controls. DOJ officials confirmed this is a growing priority, with 15 public cyber-fraud settlements totaling over $73.5 million in the last five years.
In a contrasting move, the Department of War announced a suspension of the CMMC Phase II rollout, which would have mandated third-party cybersecurity certifications. The department cited a need to reduce compliance costs and bureaucratic burdens, particularly for smaller businesses. This pause, however, does not eliminate the underlying contractual requirement for contractors to protect defense information per DFARS clause 252.204-7012.
Sophisticated counsel should advise defense-sector clients that while the CMMC pause provides temporary relief from a new certification layer, FCA risk based on existing self-attestations is higher than ever. Contractors should use this period to rigorously audit their cyber posture to ensure their compliance representations are accurate and defensible. The key development to watch is the outcome of the DoD's 60-day CMMC review.