Skip to main content

Cybersecurity Whistleblower: False Claims Act & CMMC

If you work in IT, security, or compliance at a defense contractor or federal IT vendor and you know your employer’s cybersecurity attestations to the government are false, the False Claims Act gives you a lawful, confidential way to report it. Under 31 U.S.C. § 3729, any person who knowingly presents a false or fraudulent claim for payment to the United States, or knowingly makes or uses a false record or statement material to a false claim, is liable for three times the government’s damages plus civil penalties. A cybersecurity certification the company knows is untrue — an inflated NIST SP 800-171 self-assessment score, a system security plan describing controls that were never implemented, or a CMMC affirmation that misstates compliance — can be exactly that kind of false record or statement.

A cybersecurity whistleblower under the False Claims Act is a private person — often a network administrator, security engineer, or compliance officer — who files a qui tam lawsuit on the government’s behalf over those false certifications. The statute, 31 U.S.C. § 3730, provides that the complaint is filed under seal, that the government may intervene, and that the whistleblower receives a percentage of any recovery and is protected from retaliation. The Justice Department has made this conduct an enforcement priority through its Civil Cyber-Fraud Initiative, and several settlements under it began with insider whistleblowers.

The DOJ Civil Cyber-Fraud Initiative

On October 6, 2021, Deputy Attorney General Lisa O. Monaco announced the Civil Cyber-Fraud Initiative, led by the Civil Division’s Commercial Litigation Branch, Fraud Section. The initiative uses the False Claims Act to pursue cybersecurity-related fraud by government contractors and grant recipients, holding accountable those that put U.S. information or systems at risk by knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches. The announcement also pointed to the False Claims Act’s whistleblower provision, which allows private parties to share in any recovery and protects them from retaliation.

Why a false cybersecurity certification violates the False Claims Act

The False Claims Act does not require proof that anyone intended to defraud the government. Under 31 U.S.C. § 3729(b)(1), a person acts “knowingly” when the person has actual knowledge of the information, acts in deliberate ignorance of its truth or falsity, or acts in reckless disregard of it — and no proof of specific intent to defraud is required. That matters in cybersecurity cases, where executives sometimes sign attestations without checking whether the controls behind them exist.

As the Justice Department noted in a 2025 settlement announcement, the obligation to implement the security controls in National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) has applied to DoD contracts and subcontracts since 2017 and continues under the Cybersecurity Maturity Model Certification (CMMC) program. Contractors handling controlled unclassified information (CUI) must implement the 110 security requirements of NIST SP 800-171, document them in a system security plan, and submit summary assessment scores to the Supplier Performance Risk System (SPRS). When a company submits a score it knows is inflated, or affirms compliance that does not exist, the invoices submitted under that contract may become false claims.

What cybersecurity whistleblower cases have looked like

In October 2024, the Pennsylvania State University agreed to pay $1,250,000 to resolve allegations that, between 2018 and 2023, it failed to implement contractually required cybersecurity controls on fifteen contracts or subcontracts involving DoD or NASA, submitted assessment scores that misrepresented the dates by which it would implement missing controls, did not pursue its plans of action, and used a cloud service provider that did not meet DoD’s security requirements. The whistleblower, Matthew Decker, former chief information officer for Penn State’s Applied Research Laboratory, received a $250,000 share of the settlement; the claims resolved were allegations only. Every False Claims Act matter is different; results depend on the specific facts of each case, and no similar outcome is implied.

In September 2025, Georgia Tech Research Corporation agreed to pay $875,000 to resolve a lawsuit alleging that a Georgia Tech lab performing sensitive cyber-defense research for DoD ran no anti-virus or anti-malware tools until December 2021, had no system security plan until at least February 2020, and submitted a summary assessment score of 98 in December 2020 that was false because it was premised on a fictitious environment rather than any actual system handling covered defense information. The case began as a qui tam complaint by Christopher Craig and Kyle Koza, former members of Georgia Tech’s cybersecurity team; the government intervened, and the whistleblowers received $201,250 as their share. Those claims, too, were allegations only. Every False Claims Act matter is different; results depend on the specific facts of each case, and no similar outcome is implied.

Enforcement reaches well beyond universities. In September 2023, Verizon Business Network Services LLC agreed to pay $4,091,317 over allegations that an internet service provided to federal agencies did not completely satisfy three required cybersecurity controls under General Services Administration contracts from 2017 to 2021. In May 2024, staffing company Insight Global LLC agreed to pay $2.7 million over allegations that it failed to secure health data gathered during federally funded COVID-19 contact tracing and that managers received staff complaints for months before remediation began; whistleblower Terralyn Williams Seilkop, a former staff member, received a $499,500 share. And in July 2025, Aero Turbine Inc. and private equity firm Gallant Capital Partners LLC agreed to pay $1.75 million to resolve liability for knowingly failing to comply with cybersecurity requirements in an Air Force contract, including allegations that files with sensitive defense information reached a software company in Egypt that was not authorized to receive them. In each matter the claims resolved were allegations only. Every False Claims Act matter is different; results depend on the specific facts of each case, and no similar outcome is implied.

CMMC and NIST SP 800-171: the certifications that now matter most

DoD is now moving beyond reliance on contractors’ own representations of compliance. The CMMC Program final rule, published October 15, 2024 and effective December 16, 2024, establishes a tiered verification program at 32 CFR part 170. CMMC Level 1 rests on self-assessment for basic safeguarding of federal contract information (FCI); Level 2 requires implementing all 110 NIST SP 800-171 requirements, verified by self-assessment or by a CMMC Third-Party Assessment Organization (C3PAO); and Level 3 involves government assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). A company that cannot show full compliance may receive only a conditional status — available at a minimum passing score of 80 percent — and must close out its plan of action and milestones within 180 days. DoD estimated that 8,350 medium and large entities will need CMMC Level 2 C3PAO assessments as a condition of contract award.

The companion DFARS final rule, published September 10, 2025 and effective November 10, 2025, puts those requirements into contracts: contracting officers may not award a contract, task order, or delivery order to an offeror without a current CMMC status posted in SPRS at the required level, plus an affirmation of continuous compliance for each information system that will process, store, or transmit FCI or CUI. The requirement phases in over three years — at first applied where program offices choose, and beginning three years and one day after the effective date, applying broadly whenever contractor systems handle FCI or CUI, excluding purchases solely of commercial off-the-shelf items. An “affirming official” must affirm continuing compliance in SPRS, and the obligations flow down to subcontractors.

For potential whistleblowers, CMMC multiplies the formal, signed compliance statements a contractor must make to win and keep federal work. A company that certifies a CMMC level it has not achieved, games the scope of its assessment, or affirms continuous compliance while known deficiencies go unremediated may face the same False Claims Act exposure the settlements above illustrate.

Warning signs IT and security employees often see first

The settlement allegations described above followed patterns insiders tend to recognize long before the government does:

  • SPRS or NIST SP 800-171 self-assessment scores that do not match the actual state of the network;
  • A system security plan describing controls no one has implemented — or no system security plan at all;
  • Plans of action and milestones whose dates keep slipping with no real remediation under way;
  • Assessment scores premised on a “virtual” environment that does not reflect the systems actually handling covered defense information;
  • CUI stored with cloud providers that do not meet DoD security requirements;
  • Sensitive defense information shared with third parties, including foreign vendors, who are not authorized to receive it;
  • Internal complaints about unsecured data that sit unaddressed for months.

If you have raised issues like these internally and watched the certifications go out anyway, you may already hold the kind of first-hand knowledge qui tam cases are built on. Talk to a lawyer before copying files, and do not take materials you are not lawfully entitled to possess.

Whistleblower protections and rewards under the statute

Under 31 U.S.C. § 3730(b), a private person files the civil action in the name of the United States; the complaint is filed in camera, remains under seal for at least 60 days, and is not served on the defendant until the court so orders. The government may intervene and proceed with the action, or decline, in which case the whistleblower may pursue the case.

The statute also fixes the whistleblower’s share. Under § 3730(d), if the government proceeds, the whistleblower receives at least 15 percent but not more than 25 percent of the proceeds of the action or settlement, depending on the person’s contribution; if the government declines and the whistleblower proceeds, the range is 25 to 30 percent, plus reasonable expenses, attorneys’ fees, and costs. And § 3730(h) gives employees, contractors, and agents who face retaliation for lawful acts in furtherance of a False Claims Act action a separate claim for relief, described in the FAQ below.

False cybersecurity certifications are one form of procurement fraud. If your concerns extend beyond security attestations — to billing, material substitution, or other misrepresentations — our overview of government contract fraud under the False Claims Act explains how those cases work.

Price Armstrong LLC is a plaintiff-side law firm representing whistleblowers nationwide in federal False Claims Act matters, associating local counsel where required. Case evaluations are free and confidential.

If this looks familiar from your own workplace, you can discuss what you have seen with a Price Armstrong attorney confidentially and at no cost. Call (888) 670-9542 or use the secure evaluation form below.

Frequently Asked Questions

What is a cybersecurity whistleblower under the False Claims Act?

A private person — frequently an IT, security, or compliance insider — who files a qui tam lawsuit under 31 U.S.C. § 3730(b) alleging that a government contractor or grant recipient knowingly misrepresented its cybersecurity compliance in connection with federal funds. The Justice Department’s Civil Cyber-Fraud Initiative pursues exactly this conduct.

Is a false NIST SP 800-171 self-assessment score enough to support a case?

It can be, depending on the facts. In the Penn State settlement, the government alleged that submitted scores misrepresented when missing controls would be implemented; in the Georgia Tech litigation, it alleged a score of 98 premised on a fictitious environment. Whether a score supports a claim depends on what the company knew and how the score related to contract requirements and payment.

What is CMMC, and when does it apply?

The Cybersecurity Maturity Model Certification program, codified at 32 CFR part 170 by a final rule effective December 16, 2024, lets DoD verify that contractors have implemented required protections for federal contract information and controlled unclassified information. A companion DFARS rule effective November 10, 2025 makes a current CMMC status in SPRS a condition of award, phasing in over three years until it covers most DoD contracts under which contractor systems handle FCI or CUI.

What share of a recovery can a whistleblower receive?

Under 31 U.S.C. § 3730(d), the statute provides for the whistleblower to receive between 15 and 25 percent of the proceeds when the government proceeds with the action, and between 25 and 30 percent when the government declines and the whistleblower litigates, plus reasonable expenses, attorneys’ fees, and costs. The exact percentage depends on factors such as the whistleblower’s contribution to the case.

Will my employer find out right away if I file?

Not through the filing itself. Under § 3730(b), a qui tam complaint is filed in camera and under seal for at least 60 days, and it is not served on the defendant until the court so orders. Confidentiality during the government’s investigation is built into the statute, though no process can remove every risk of identification.

What if I am retaliated against for raising cybersecurity concerns?

Section 3730(h) protects employees, contractors, and agents from being discharged, demoted, suspended, threatened, harassed, or otherwise discriminated against for lawful acts in furtherance of a False Claims Act action, and provides for relief including reinstatement with the same seniority status, two times back pay plus interest, and compensation for special damages, including litigation costs and reasonable attorneys’ fees.

Report Fraud Confidentially — Free Case Evaluation

Before you do anything else: do not publicize your allegations — online, to the press, or at work. False Claims Act cases are filed under seal, and only the first whistleblower to file can recover. Talk to a lawyer before you talk to anyone. Use a personal device and personal email, not your employer’s.

Submitting this form does not create an attorney‑client relationship, and information sent before we complete a conflict check cannot be guaranteed confidential — please do not include detailed evidence or your employer’s name yet. Attorney responsible for this content: Graham Cotten, Price Armstrong LLC, Birmingham, Alabama. We represent whistleblowers nationwide in federal False Claims Act matters, associating local counsel where required.