The U.S. Department of Justice’s (DOJ) recent settlement with Alabama defense contractor LOGZONE Inc. (LOGZONE) is a notable reminder that, in the federal contracting context, cybersecurity deficiencies are not merely technical concerns — they can create False Claims Act (FCA) exposure, particularly where a contractor misstates its compliance status to the government. Under the settlement, LOGZONE agreed to pay $507,144 to resolve allegations that it submitted claims for payment under two Department of the Navy contracts while knowing that it failed to comply with those contracts’ cybersecurity requirements. This resolution shows the DOJ’s continued willingness to treat alleged noncompliance with contractual cybersecurity requirements as a fraud issue even in the absence of any data breach or other security incident. The press release reflects a theory that turns not only on the existence of unimplemented security controls, but also on the alleged submission of compliance-related information that did not accurately reflect the company’s actual cybersecurity posture. That combination — known deficiencies coupled with inaccurate compliance representations — presents an especially acute area of FCA risk for government contractors handling sensitive defense information. The Settlement The two Navy contracts at issue incorporated Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, which requires contractors handling covered defense information to provide adequate security for covered contractor information systems, including by implementing the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 security requirements. The applicable framework also required LOGZONE to report a summary-level score from a current NIST SP 800-171 self-assessment in the Supplier Performance Risk System (SPRS). The DOJ alleged that, from May 2021 to March 2025, LOGZONE failed to implement certain NIST SP 800-171 controls that, if left unaddressed, could permit system exploitation or exfiltration of sensitive defense information. The government further alleged that LOGZONE submitted a score of 110 in