Inside the SPRS Lie: Cybersecurity False Claims Act Whistleblower Guide for NIST 800-171, CMMC, DFARS, and SPRS Fraud
Table of Contents
If You Know the SPRS Score Is False, This Article Is for You
A Supplier Performance Risk System (SPRS) score of 110 looks clean. It can also be the lie that turns a cybersecurity compliance problem into a False Claims Act case.
Maybe the score says every NIST SP 800-171 requirement is implemented, but the engineering team knows half the controls are still open. Maybe the System Security Plan reads like a mature enclave, but the actual CUI environment is scattered across unsupported tenants, legacy systems, and undocumented exceptions. Maybe the POA&M has been “in progress” for years. Maybe the company told a prime, a contracting officer, or DoD that its cloud environment met FedRAMP Moderate equivalence when the shared-responsibility evidence said otherwise.
That is not just “bad cyber.” If the contractor used that representation to win, keep, or bill on federal work, it may be cyber-FCA fraud.
Why This Is Happening Now
The Department of Justice launched the Civil Cyber-Fraud Initiative in October 2021 to use the False Claims Act against government contractors and grant recipients that knowingly fail to comply with cybersecurity requirements, misrepresent cybersecurity practices, or fail to report incidents.
That initiative is no longer theoretical. DOJ’s FY2025 False Claims Act materials reported more than $52 million recovered in nine cybersecurity fraud settlements, and said civil cybersecurity fraud settlements had more than tripled in each of the prior two years.
At the same time, the contractual environment has tightened. DFARS 252.204-7012 requires covered contractors to provide adequate security, implement NIST SP 800-171 for covered contractor information systems when applicable, ensure FedRAMP Moderate equivalence for external cloud services handling covered defense information, rapidly report qualifying cyber incidents to DoD, and flow down the clause to subcontractors handling covered defense information.
Speak with the Lawyers at Brown, LLC Today!
Over $1 billion in aggregate judgments and settlements for our clients in state and federal courts. We fight for maximum damages and results.
DFARS 252.204-7021 now addresses contractor compliance with CMMC level requirements, including CMMC status, affirmations of continuous compliance, and CMMC unique identifiers reflected in SPRS. SPRS itself is not a side database. SPRS states that its NIST SP 800-171 Assessments module stores assessment date, score, scope, POA&M completion date, CAGE codes, SSP name, SSP version, SSP date, and confidence level.
For insiders, the message is simple: the paper trail is getting more formal, more searchable, and more material.
The Legal Architecture, in Plain English
A cyber-FCA case usually needs five pieces.
- A contract, grant, or federal program that required cybersecurity compliance.
- A representation: SPRS score, SSP, POA&M, CMMC status, FedRAMP-equivalence claim, incident report, subcontractor certification, or invoice tied to compliance.
- A mismatch between the representation and technical reality.
- Knowledge: actual knowledge, deliberate ignorance, or reckless disregard.
- Materiality and money: the false statement mattered to contract award, payment, option exercise, continued performance, or government risk assessment.
The False Claims Act is not a general cybersecurity negligence statute. The case is not “they had weak controls.” The case is “they knowingly told the government one thing while the technical record showed another, and then sought or kept federal money.”
Related: Brown, LLC secured two of the year’s largest individual recoveries — a $950M settlement against Raytheon and $350M against Walgreens. Learn about our False Claims Act practice →
DFARS 252.204-7012: The Clause Behind Many Cyber-FCA Cases
DFARS 252.204-7012 matters because it turns cybersecurity obligations into contract terms. The clause defines covered defense information, covered contractor information systems, and cyber incidents. It requires NIST SP 800-171 protections for covered contractor information systems when applicable, FedRAMP Moderate-equivalent security for external cloud services handling covered defense information, reporting of cyber incidents to DoD within 72 hours, and subcontractor flowdown.
That creates several possible false-statement theories: a contractor can overstate implemented controls, hide a non-compliant cloud environment, fail to report a qualifying cyber incident, or represent that subcontractors are flowing down and implementing requirements when nobody has verified that reality.
NIST SP 800-171, CMMC, and SPRS: Why Technical Details Matter
NIST SP 800-171 provides recommended security requirements for protecting CUI in nonfederal systems and organizations; Revision 3 was finalized in May 2024 and superseded Revision 2, although particular contract obligations depend on the contract, solicitation, clause, and contracting officer authorization.
For many DoD contractors, the practical compliance story involves NIST controls, an SSP, a POA&M, a self-assessment, an SPRS score, and now potentially CMMC status and affirmations of continuous compliance. That means an insider who understands the technical environment may see the fraud before lawyers, auditors, or investigators do.
The 12 Patterns of CMMC, SPRS, and DFARS Compliance Fraud
Cybersecurity compliance fraud rarely looks dramatic. It usually looks like quiet institutional pressure to round up, defer, inherit, reclassify, or certify anyway.
1. The Phantom 110
The company submits an SPRS score of 110 or near-110 when the actual implemented controls are materially lower. The assessment was superficial, the evidence was incomplete, or leadership directed the score before the technical review was finished.
2. The Eternal POA&M
POA&Ms are supposed to be living remediation plans. But an open POA&M from 2021 with a missed 2022 target date that remains unresolved in 2026 may not be a plan; it may be evidence that the contractor knew the control was not implemented.
3. Inherited Control Fiction
The contractor claims to inherit controls from a cloud provider, even though the control requires customer-side configuration or documentation. The shared-responsibility model does not let the contractor claim a provider implemented controls the provider explicitly leaves to the customer.
4. The FedRAMP-Equivalence Shell Game
DFARS 252.204-7012 requires external cloud services that store, process, or transmit covered defense information to meet FedRAMP Moderate-equivalent security and comply with the clause’s incident-reporting and forensic-access provisions. The MORSECORP settlement is the clean public example: DOJ alleged that MORSE used a third-party company to host emails without requiring and ensuring FedRAMP Moderate-equivalent security and other DFARS obligations.
5. MFA on Paper, Not in Practice
The SSP says multi-factor authentication is universal. Active Directory, VPN logs, privileged-account policy, or legacy-system exceptions say otherwise.
6. The Non-Validated FIPS Claim
The contractor treats “FIPS mode” or approved algorithms as equivalent to using FIPS-validated cryptographic modules. Technical teams often know the difference; external certifications may blur it.
7. Audit Logs That Are Not Reviewed
A company sends logs to a SIEM and declares the control implemented, while no one reviews alerts, preserves audit integrity, documents escalation, or acts on findings.
Speak with the Lawyers at Brown, LLC Today!
Over $1 billion in aggregate judgments and settlements for our clients in state and federal courts. We fight for maximum damages and results.
8. Incident Reporting That Did Not Happen
DFARS 252.204-7012 requires rapid reporting of certain cyber incidents to DoD within 72 hours of discovery. [2] A contractor that experiences an incident but internally labels it “not reportable” without a defensible basis may create a clean false-statement record.
9. Subcontractor Flowdown Failure
Prime contractors flow clauses down on paper but do not verify that subcontractors handling covered defense information actually protect it. That can become a supply-chain false-certification problem.
10. The Retroactive Assessment
Before an assessment, the contractor creates missing policies, stages screenshots, backdates evidence, or asks staff to “clean up” artifacts that are supposed to show continuous practice.
11. CUI Scope Shrinkage
The company declares “we do not have CUI here,” even though contract markings, DD Form 254 language, technical data, controlled technical information, or the work itself says otherwise.
12. The Two-Version SSP
Engineers maintain an internal SSP that reflects operational reality. Compliance maintains a polished version shown to assessors, primes, or the government. Two versions can be powerful evidence of knowledge.
What the Actual Cyber-FCA Cases Show
The public settlements show the enforcement pattern. The details differ, but the recurring theme is a mismatch between required cybersecurity controls and what the contractor told the government.
Comprehensive Health Services – $930,000
DOJ described the CHS settlement as the first Civil Cyber-Fraud Initiative resolution. CHS allegedly represented compliance with contract requirements related to secure storage of medical records at State Department and Air Force facilities, while some records were allegedly stored on an internal network drive accessible to non-clinical staff.
Aerojet Rocketdyne – $9 million; $2.61 million relator share
Aerojet resolved allegations that it misrepresented compliance with cybersecurity requirements in federal government contracts. DOJ reported that former employee Brian Markus received $2.61 million as the relator share.
Verizon Business Network Services – $4.09 million
Verizon agreed to pay $4,091,317 to resolve allegations that it failed to completely satisfy certain cybersecurity controls in connection with a federal information technology service. DOJ also credited Verizon for self-disclosure, cooperation, and remediation.
Guidehouse and Nan McKay – $11.3 million
Guidehouse paid $7.6 million and Nan McKay paid $3.7 million to resolve allegations that they failed to meet cybersecurity requirements in federally funded contracts involving an emergency rental assistance technology platform. DOJ stated that, as part of the settlement, the companies admitted they did not complete required pre-production cybersecurity testing before launch.
Penn State – $1.25 million
Penn State agreed to pay $1.25 million to resolve allegations that it failed to comply with cybersecurity requirements in certain DoD and NASA contracts and subcontracts.
MORSECORP – $4.6 million; $851,000 relator share
MORSE agreed to pay $4.6 million to resolve allegations that it failed to comply with cybersecurity requirements in Army and Air Force contracts. DOJ said MORSE admitted using a third-party email host without ensuring FedRAMP Moderate-equivalent security, failing to implement all required NIST controls, lacking an SSP for covered information systems, and submitting an inaccurate implementation score. DOJ reported an $851,000 relator share.
Whistleblower tip: If you’ve witnessed Medicare or Medicaid billing fraud at your employer, you may qualify as a qui tam relator with a potential share of the government’s recovery. See our Medicare & Medicaid fraud practice →
Raytheon / Nightwing – $8.4 million
Raytheon and Nightwing agreed to pay $8.4 million to resolve allegations relating to non-compliance with cybersecurity requirements in DoD contracts or subcontracts.
What Makes a Strong Cyber-FCA Case Versus Just a Complaint
Not every cybersecurity failure is fraud. Not every fraud makes a viable qui tam case. The strongest cases have more than “they are insecure.”
| Factor | Strong cyber-FCA signal | Weak signal |
| False statement | SPRS score, CMMC status, SSP, POA&M, FedRAMP claim, incident report, or certification was false or misleading. | General complaint that security was poor. |
| Knowledge | Internal warnings, audits, tickets, emails, meetings, or consultant reports show decisionmakers knew. | No evidence anyone knew or recklessly disregarded the issue. |
| Materiality | The statement mattered to award, payment, option exercise, contract eligibility, or government risk. | Technical defect with no government-payment or eligibility connection. |
| Damages | Affected contracts, invoices, grants, task orders, or option years can be identified. | No clear money path. |
| Evidence path | Relator can identify systems, witnesses, records, and contradictory documents. | Only memory, rumor, or unauthorized materials. |
| Timing | Ongoing or recent misconduct; first-to-file risk understood. | Stale, already public, or fully investigated. |
What to Document – and What Not to Take
Cyber relators often know where the proof is. That does not mean they should take everything they can find. Generally useful information includes your own contemporaneous notes, dates of meetings, who said what, what was submitted, what internal documents contradicted it, which systems contain the SSP or POA&M, where SPRS submission records live, and who else saw the same problem.
High-risk conduct includes removing classified or controlled data, accessing systems outside your normal authority, copying privileged communications, taking trade-secret material without legal advice, altering records, communicating with counsel through company systems, or discussing a sealed qui tam strategy with coworkers. Your value is not only documents. Your value is the map: what was submitted, why it was false, where the proof lives, who knew, and why the government would care.
Retaliation: Strong Statute, Real-World Risk
The FCA’s retaliation provision protects employees, contractors, and agents from being discharged, demoted, suspended, threatened, harassed, or otherwise discriminated against because of lawful acts in furtherance of an FCA action or efforts to stop violations.
That protection matters, but it is not a magic shield. If an insider confronts management before getting advice, the company may create a performance narrative, isolate the employee, revoke access, or characterize the concern as a policy dispute rather than protected activity. Timing and wording matter.
When to Call a Cyber-FCA Lawyer
Call counsel when you can say something specific, such as: “On this date, the company submitted this SPRS score, CMMC affirmation, SSP, POA&M, FedRAMP-equivalence claim, or incident-reporting position, and I know it was false because of these controls, documents, systems, or meetings.”
Do not wait for perfect proof. Also do not make yourself a rogue investigator. A focused whistleblower lawyer can help determine whether the facts support a case and how to preserve the proof path safely.
Why Brown, LLC Is a Strong Fit for Cyber-FCA Whistleblower Cases
Cyber-FCA cases require two translations. First, technical facts must be translated into a coherent government-facing story. Second, that story must be translated into the False Claims Act elements: falsity, knowledge, materiality, damages, first-to-file, seal practice, and retaliation protection.
Brown, LLC evaluates cyber-FCA matters through that legal architecture. The firm is not a cybersecurity audit shop and does not need to become one. The firm’s role is to work with insiders who understand the technical record and determine whether that record shows a knowing misrepresentation to the government.
That can include SPRS scores, SSPs, POA&Ms, FedRAMP-equivalence assertions, CMMC status, cyber-incident reporting, subcontractor flowdown, CUI scoping, consultant reports, audit findings, internal emails, and the gap between engineering reality and contract-facing representations.
The right case is not every gap. The right case is a serious, provable, knowing mismatch tied to federal money.
Bottom Line
The Civil Cyber-Fraud Initiative is not a side issue anymore. DOJ has reported a rapid increase in cybersecurity fraud settlements, and public cases now involve defense contractors, universities, federal IT services, cloud/email environments, grant-funded platforms, health benefits administration, genomic products, and CMMC-related representations.
If you are an ISSO, ISSM, cleared engineer, CMMC consultant, compliance lead, internal auditor, security architect, cloud administrator, or program manager who knows that the government-facing cyber story does not match reality, do not guess and do not freelance.
Build a timeline. Identify the false representation. Identify the proof path. Preserve lawful information. Do not remove restricted data. Then speak with counsel before reporting internally, contacting the government, or taking documents.
FAQ
Can a false SPRS score be a False Claims Act case?
Potentially yes. A false SPRS score may support an FCA theory if it was knowingly inaccurate, material to a federal contract or payment decision, and connected to claims or statements for government money.
Is every NIST 800-171 control gap fraud?
No. A control gap is not automatically fraud. The FCA issue is whether the contractor knowingly misrepresented compliance, hid the gap, or billed the government while making false statements material to payment or eligibility.
What is the difference between bad cybersecurity and cyber-FCA fraud?
Bad cybersecurity is a technical or compliance problem. Cyber-FCA fraud involves a false or misleading representation to the government, knowledge or reckless disregard, materiality, and a money connection.
Should I take screenshots or download the SSP before calling a lawyer?
Do not take new documents or access systems outside your authority without legal advice. Preserve what you lawfully have and make notes about where the proof is located.
Can I be fired for reporting cybersecurity fraud?
The False Claims Act contains anti-retaliation protections, but timing, wording, and proof matter. Speak with counsel before confronting management or reporting internally.
Who is most likely to have useful cyber-FCA information?
ISSOs, ISSMs, cleared engineers, cloud admins, CMMC consultants, compliance leads, internal auditors, program managers, and subcontractor personnel may all see the mismatch between technical reality and government-facing cybersecurity claims.
Sources
[1] DOJ, Civil Cyber-Fraud Initiative launch, Oct. 6, 2021: https://www.justice.gov/archives/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative
[2] DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting: https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
[3] DFARS 252.204-7021, Contractor Compliance With CMMC Level Requirements: https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.
[4] SPRS NIST SP 800-171 Information: https://www.sprs.csd.disa.mil/nistsp.htm
[5] NIST SP 800-171 Rev. 3, Protecting CUI in Nonfederal Systems and Organizations: https://csrc.nist.gov/pubs/sp/800/171/r3/final
[6] DOJ FY2025 False Claims Act Fact Sheet: https://www.justice.gov/opa/media/1424126/dl
[7] DOJ, Aerojet Rocketdyne $9M cybersecurity FCA settlement: https://www.justice.gov/archives/opa/pr/aerojet-rocketdyne-agrees-pay-9-million-resolve-false-claims-act-allegations-cybersecurity
[8] DOJ, Comprehensive Health Services $930K cyber-fraud FCA settlement: https://www.justice.gov/archives/opa/pr/medical-services-contractor-pays-930000-settle-false-claims-act-allegations-relating-medical
[9] DOJ, Verizon Business Network Services $4.09M cyber-controls FCA settlement: https://www.justice.gov/archives/opa/pr/cooperating-federal-contractor-resolves-liability-alleged-false-claims-caused-failure-fully
[10] DOJ, Guidehouse and Nan McKay $11.3M cybersecurity requirements settlement: https://www.justice.gov/archives/opa/pr/consulting-companies-pay-113m-failing-comply-cybersecurity-requirements-federally-funded
[11] DOJ, Penn State $1.25M cybersecurity FCA settlement: https://www.justice.gov/archives/opa/pr/pennsylvania-state-university-agrees-pay-125m-resolve-false-claims-act-allegations-relating
[12] DOJ, MORSECORP $4.6M cybersecurity fraud settlement: https://www.justice.gov/opa/pr/defense-contractor-morsecorp-inc-agrees-pay-46-million-settle-cybersecurity-fraud
[13] DOJ, Raytheon and Nightwing $8.4M cybersecurity FCA settlement: https://www.justice.gov/opa/pr/raytheon-companies-and-nightwing-group-pay-84m-resolve-false-claims-act-allegations-relating
[14] False Claims Act, 31 U.S.C. §§ 3729-3733: https://www.law.cornell.edu/uscode/text/31/chapter-37/subchapter-III




