DOJ Settles False Claims Act Case Against Defense Contractor for NIST SP 800-171 Cybersecurity Noncompliance
Original: Cybersecurity Noncompliance Just Triggered Another False Claims Act Settlement for a Defense Contractor
Short summary
A defense contractor paid over $500,000 to settle DOJ allegations that it failed to implement NIST SP 800-171 cybersecurity controls while continuing to invoice the Navy for nearly four years. The DOJ is increasingly using the False Claims Act to treat cybersecurity compliance failures as fraudulent conduct when contractors certify compliance but don't meet requirements. A DCMA assessment score of negative 170 underscored the severity of the unimplemented security controls protecting Controlled Unclassified Information.
- •Defense contractor settled for $500K+ over NIST SP 800-171 noncompliance while invoicing the Navy
- •DOJ is framing cybersecurity certification failures as False Claims Act violations, not just contract disputes
- •DCMA assessment score of negative 170 highlighted severe unimplemented security controls for CUI protection
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



