Government contractors should not mistake the Department of Defense's (DOD) recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II certification requirements as any sort of reprieve from their cybersecurity requirements or the government's intent to enforce CMMC. The recently announced LOGZONE False Claims Act (FCA) settlement serves as a stark reminder of the Department of Justice's (DOJ) focus on and pursuit of contractors whose cybersecurity representations fail to match reality. This builds on FCA cybersecurity fraud recoveries more than tripling in each of the past two years, exceeding $52 million across nine settlements in fiscal year 2025 alone.1 Bottom Line The suspension of CMMC Phase II is a welcome development that has dominated most government contracting headlines over the past weeks. Yet the DOJ does not need CMMC third-party assessments to bring claims under the FCA. Existing Defense Federal Acquisition Regulation Supplement (DFARS) contractual obligations – including compliance with NIST Special Publication 800-171 and reporting accurate Supplier Performance Risk System (SPRS) scores – remain fully enforceable, and the DOJ has demonstrated a consistent practice of using FCA liability to punish inaccurate self-assessments and unimplemented cybersecurity controls.2 The LOGZONE Settlement On June 18, 2026, the DOJ announced that LOGZONE INC., a Huntsville, Alabama, defense contractor, agreed to pay $507,144 to resolve FCA liability relating to cybersecurity violations in Department of the Navy contracts. The settlement is modest in dollar terms but provides important takeaways for the defense industrial base. LOGZONE provided logistics, inventory, and facilities support services under two Navy contracts at Stennis Space Center. Those contracts incorporated DFARS 252.204-7012 (requiring adequate security for covered defense information and implementation of NIST SP 800-171 controls), DFARS 252.204-7019, and DFARS 252.204-7020 (requiring contractors to post summary-level NIST SP 800-171 self-assessment SPRS scores). In October 2021, LOGZONE posted a perfect SPRS self-assessment score
<b>Cybersecurity</b> Compliance Remains a False Claims Act Risk Despite CMMC Phase II Suspension
Read the original article
bakerdonelson.com →