
Sum IT Up: CMMC News Roundup · 2026-06-25 · 13 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
The defense contracting world's first False Claims Act settlement for DOD cybersecurity noncompliance has arrived - and it's a cautionary tale about DFARS 7012 compliance gone wrong. A small contractor with fewer than 50 employees submitted a perfect 110 self-assessment score into the SPRS database, then received a phone call from DibCAC auditors in 2024 that revealed their actual compliance score was negative 170. The result: a $507,000 settlement on contracts worth only $680,000, effectively destroying the profitability of those awards. This episode clarifies the critical distinction between DFARS 7012 requirements (mandatory since 2017) and CMMC 1.0, explaining how many contractors submitted inflated SPRS scores while waiting for CMMC rulemaking to complete, inadvertently committing False Claims Act violations. The hosts - examining DibCAC's medium assessment methodology and the absence of a whistleblower - predict dozens more similar settlements are incoming from the 100+ FCA cases rumored in the pipeline, all stemming from the variance between self-reported and actual compliance scores that DibCAC identified years ago.
The contractor submitted a perfect 110 self-assessment score into SPRS, but DibCAC's medium assessment determined their actual compliance score was negative 170 - a 280-point swing that triggered the False Claims Act settlement.
The contractor paid $507,000 in settlement costs for contracts worth only $680,000, meaning the penalty consumed 75% of the contract value and exceeded their actual profit margin.
DFARS Clause 252-204-7012 has been mandatory on defense contracts since 2017 and requires compliance with NIST SP 800-171; CMMC 1.0 was released in 2020 but the implementation portion was paused during rulemaking, while the DOD assessment methodology (7019/7020) requiring self-assessment score submission to SPRS remained active throughout.
SPRS score submissions are official statements to the government, and once the contractor submitted invoices to get paid under those contracts while claiming perfect compliance, they violated the False Claims Act - regardless of whether a whistleblower reported them.
DibCAC conducted a medium assessment (typically done over the phone rather than on-site) and determined the contractor's compliance posture was so poor that they immediately referred the case to the Department of Justice, suggesting even a remote audit with no physical inspection caught the fraud.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode contains a handful of genuinely useful operational points - DFARS 7012 vs. CMMC distinction, SPRS submissions as official fraud triggers, and DibCAC medium assessment mechanics - but the same points are repeated multiple times across 13 minutes, diluted by sports analogies, sitcom references, and speculative filler.
SPRS score submissions, folks, are official statements to the government. The second that you submit an invoice to get paid under those contracts, you have now committed fraud.
Medium assessments were typically done just over the phone. So the posture of this contractor specifically was allegedly so bad that Dibcac knew just over the phone that they were in gross violation
The no-whistleblower, DibCAC-initiated FCA angle is a genuinely fresh data point and the prediction that dozens of similar cases will follow from medium assessments is a plausible and non-obvious thesis, but the underlying argument - 'don't lie on your SPRS score' - is well-worn in this space.
There was no whistleblower in this case. uh dibcac conducted what was known as a medium assessment under the dod assessment methodology
I think there going to be a lot of these settlements that come out that don have a whistleblower They were the result of a DBCAC medium confidence assessment
This is a two-host commentary format with no external guests; the hosts demonstrate apparent practitioner knowledge of CMMC and DFARS and reference prior conference presentations, but their specific credentials are never established and no outside expert is brought in to stress-test claims.
We had Nick Del Rosso multiple years ago at CS2 that showed us the slide that this is the variance that we're seeing right now.
We covered years ago, a DOD IG note that came out during the holidays saying that DBCAC was actively referring cases to the Department of Justice
The episode anchors concretely on the $507K settlement vs. $680K contract value, the 110-to-negative-170 score delta, specific DFARS clause numbers (7012, 7019, 7020), and a named DibCAC presenter (Nick Del Rosso at CS2), but the contractor itself is unnamed and most additional data is speculative ('dozens or a hundred or more cases').
The contractor entered a perfect 110 self-assessment score into the SPRS database. Dibcac called them up in 2024, and it turns out their actual score was a negative 170. Now they're paying $507,000 to the government and the contracts that are in question were only worth 680 grand.
DFARS Clause 252-204-7019-7020. Those were the mechanisms that were making you conduct a self-assessment, calculate a score, and upload that score into the SPRS database.
There is no guest to probe and no meaningful pushback between the two hosts; the conversation is largely one co-host affirming the other with affirmations like 'Yep. Yep.' and the probing is replaced by sports analogies and TV show references rather than sharp follow-up questions.
It's like when you try to sneak a couple cookies and forget to get all the crumbs that are on your chin, right?
It's like that extra contributing player in a playoff run that helps the team get over the hump, right? Like the James Joneses of the world for the heat
Computed from the transcript - who did the talking, and the words that came up most.
The DOJ has announced its first cybersecurity False Claims Act settlement of 2026, and the details should get every defense contractor's attention. In this episode, we break down the LOGZONE settlement, the difference between DFARS 252.204-7012 and CMMC, how a perfect SPRS score became a DIBCAC assessment score of -170, and why this case may be a preview of additional enforcement actions still working their way through the system. Topics covered: LOGZONE FCA settlement details DFARS 252.204-7012, 7019, and 7020 SPRS self-assessment scores DIBCAC medium assessments Why no whistleblower was required What this means for defense contractors moving forward Settlement and source documents linked below. Register for Secure The DIB: Register for Summit 7 Live: DOJ Settlement: DoD IG + DOJ (2023): FCA pod w/ Alexander Canizares: FCA pod w/ Stephanie Siegmann: FCA w/ Bruce Judge:
Transcribed and scored by The B2B Podcast Index.
All right, folks, it is June of 2026 and the first False Claims Act cybersecurity settlement for alleged noncompliance with DOD cybersecurity requirements just dropped. And boy, is it a doozy. Can a single phone call from Dibcac auditors cost you 75% of the value of your defense contract? That's what we're going to talk about today.
Jason, this is a spicy one because this False Claims Act settlement did not have a whistleblower. The contractor entered a perfect 110 self-assessment score into the SPRS database. Dibcac called them up in 2024, and it turns out their actual score was a negative 170. Now they're paying $507,000 to the government and the contracts that are in question were only worth 680 grand.
Jacob, you say that there was no whistleblower, but sometimes people just tell themselves. It's like when you try to sneak a couple cookies and forget to get all the crumbs that are on your chin, right? Especially with you, I'm sure things get caught a lot, right? This blows my mind.
And why this blows my mind, Jacob, is because of the percentage value attached to the penalty. Every FCA that we've kind of talked about before, I think the general consensus was like, I'm so surprised this is so low. I'm so surprised this is so low. And then all of a sudden, right here, no whistleblower attached.
They told on themselves, put in the score. Dibcat came a calling. This one's going to sting a little bit. I mean, you might think that 500 grand isn't very expensive.
If that's true, can you adopt me? Because $500,000 is a lot of money. $500,000 is especially a lot of money for this contractor because they have less than 50 employees. It's also a lot for this contractor because they only got paid $680,000 on the contracts in question.
So with overhead, cost of business, all that stuff, plus the inflation after two or three years after they got paid, they definitely lost money on those contracts. I don't know a lot of small business defense contractors that can afford to lose money on contracts that they get awarded. So when you hear 500 grand, you're like, oh, that's not a lot of money. On a relative basis, it's a ton of money.
And when you think about it, is the FCA juice really worth the squeeze? And I don't know, bro. Well, you know, we're gonna talk about this at the end, but I have a theory that we know a lot more about those alleged 100 plus FCA cases that we've been waiting to come around the corner. I think it might have something to do with how Dibcac approach this one, I think there's going to be a lot of cases that are very similar to this.
Let's just get right into the details here. DFARS 7012, CMMC, newsflash, everybody, they are different things. They are distinctly different things. Defense contracts have had DFARS Clause 252-204-7012 in them since 2017.
By accepting the contract, you are attesting to compliance with the cybersecurity requirements in DFAR 7012. That means you are telling the government you have fully implemented the requirements in NIST Special Publication 800 In 2020 the CMMC 1 rule was released but everybody forgets that it had two parts to the rule One part was CMMC That was put on hold while we waited for years for the rulemaking process to complete, which has now completed and now we're in phase one of the rollout.
But the other part that never went on pause was the DOD assessment methodology. That was the part that created DFARS Clause 252-204-7019-7020. Those were the mechanisms that were making you conduct a self-assessment, calculate a score, and upload that score into the SPRS database. All of that was real and valid, 7012, 7019, 7020, while everyone was thinking that CMMC was never going to happen.
So a lot of people pencil whipped perfect 110 self-assessment scores, uploaded those scores into SPRS. SPRS score submissions, folks, are official statements to the government. The second that you submit an invoice to get paid under those contracts, you have now committed fraud. You have now violated the False Claims Act.
And whether a whistleblower turns you in or whether the government decides to pursue you all on their own, that's now outside of your control. So a lot of people got visits from DibCAC auditors as a result of these perfect scores. We had DibCAC at CS2. We talked about the DibCAC slides on this podcast.
And the DOD told everybody a red flag blaring red light is if you have a perfect score in SPRS, we're going to call you and we're going to ask you a couple of questions to see if you pass the sniff test. In this case, they didn't pass the sniff test. They were fine for noncompliance on contracts that they worked on years ago. Nothing to do with CMMC.
So if you entered a perfect score into SPRS and then you got a phone call from Dibcac, you probably know better than I do. Let us know in chat. Are you part of an upcoming FCA settlement? So, Jacob, I might know some people that might be letting us know in chat because a lot of organizations I talk to are like, hey, I've got this requirement that's just, and we break it down, let them know that it's just a DFAR 7012 requirement and the input of the score and things like that.
I'm just going to put in this 110 while we're getting the work done so that I can continue to build a government. And what I say is this is not going to turn out the way that you think it's going to turn out. One of the things that stuck out particularly in this FCA case when reading was that they continuously build the government. And every time they build the government was essentially lying, saying that I am compliant, I am not.
Which is what every single one of those people that I talk to and I'm like, this isn't going to end out good. This is what it turns out to be, Jacob. I'm telling you, we're going to see a lot more of this. I think so.
I think so. Let's talk about this other detail because this was causing people to go for a loop on LinkedIn when we posted this. There was no whistleblower So the False Claims Act has a whistleblower provision in which an employee of a company committing fraud on government contracts can blow the whistle and file a key Tam which ever way they can file a lawsuit essentially saying that this company is committing fraud And then the government can join that lawsuit And the whistleblower if the settlement is reached or fines are issued, gets part of the money.
It's very lucrative for the whistleblowers. We've seen lots of whistleblower settlements come through the pipe over the last couple of years regarding this exact same kind of noncompliance. There was no whistleblower in this case. uh dibcac conducted what was known as a medium assessment under the dod assessment methodology dibcac can show up to this day to this day right now they can show up at any time and say we want to see what's going on in here with regards to your cyber security compliance with existing cyber security requirements folks nothing to do with the cmmc phase rollout fun fact dibcac high assessments as they were commonly referred to were assessments and are assessments conducted in person on premises.
Medium assessments were typically done just over the phone. So the posture of this contractor specifically was allegedly so bad that Dibcac knew just over the phone that they were in gross violation, allegedly referred the case over to the DOJ, moved on to the next perfect score submitted in SPRS. And now a little while later, these guys are writing a check for $500,000. Yeah, I think that's one of the craziest parts of this entire story is that like the medium assessment probably would be the one that if you were able to fluff it just a little bit, you're able to get through that without any, you know, testing of- You're just talking to them on the phone.
They're not looking at anything. Hey, what are you doing here? Sounds like you know what you got going on, right? Like this is a good story.
You have been putting in 110s. You have gotten $600,000 plus in contract money awarded to you. You can't even get the story right. Yep.
Yep. I mean, this could be because they didn't know what 171A was. It could be because they just put in a perfect score and said, we'll update it later. There could be lots of reasons why the score was entered as a 110, but ultimately it doesn't matter because you told the government you were perfect.
You got paid saying that you had done the thing. Turns out you didn't do the thing. And so now they want their money back plus interest. It's the old adage, and I hate to jump off the topic, but one of my favorite television shows is Modern Family.
So I don't know if you've ever watched Modern Family, but the naggy step in the family house, right? The step that goes down from upstairs to downstairs. It felt constantly trips one. Every time he trips one, he goes, I should really fix that, right?
That's kind of what this is. We got the 110. We know it's the naggy stare. Everybody is like, man, we should really fix that.
We should really fix that. But they just keep tripping over it. And eventually somebody falls down the steps or you get hit with an FCA claim. Yeah, well, I mean, this could be a pretty lengthy staircase here because I think that there are a lot more FCA cases to come that are exactly like this.
If you've been listening to the podcast, you know we have heard through the rumor mill, through the grapevine, that there are an absolute ton of these False Claims Act cases moving their way through the system. We just talked about this on our halfway through the year prediction review show because this is the first one we've seen all year. DBCAC made a lot of these phone calls from 2021 to 2025. We covered years ago, a DOD IG note that came out during the holidays saying that DBCAC was actively referring cases to the Department of Justice And so I think there going to be a lot of these settlements that come out that don have a whistleblower They were the result of a DBCAC medium confidence assessment The contractor was completely off from their perfect score.
They slap them with a fine and then they moved on and then they moved on and they moved on and they moved on. There could easily be dozens and dozens or a hundred or more of these cases exactly like this one that could all just go drop, drop, drop, drop, drop. And by the end of the year, we could have a ton of these exactly in the same situation. Yeah.
One of the biggest discussions that we had about the DIPCAC variance and scores was like the 100 point sway from what people reported to what DIPCAC actually had. We had Nick Del Rosso multiple years ago at CS2 that showed us the slide that this is the variance that we're seeing right now. And like you said, it makes you wonder if those cases that they identified that turned into a slide are now cases that have turned into cases. And now we're finally seeing that.
I guess we should probably go back and look at the slide and see if there is one that says perfect to negative 117, 100. What was it? Negative 117. What was their final?
170. Got to go back and look and see if one of the slides had a chart that was negative 170. And maybe that was this one. Maybe there were lots of people that I've heard a grading on a curve and margin for error, but those are pretty large.
This is why the CMMC program exists, folks, because they came out with the 1.0 rule. Everybody said, this is ridiculous. They put the third-party assessment piece on pause.
They kept going with the DibCAC assessment piece, and every time they showed up to a perfect self-assessment score, they had a result like this, and they just referred to the DOJ, referred to the DOJ, referred to the DOJ, and now years later, people are like, Why would they possibly need a third party assessment program? This is why, because why would you give contracts to people and then wait years later to find out they had messed it up, make them prove it up front so we can save this whole process.
It just makes the process faster, but this is definitely not the last false claims act case to come out this year. I think we're going to see a lot of them as the result of Dibkak phone calls, which surprised a lot of people on LinkedIn. So if you get a call from Dibkak, I hope you got your story straight. if you got a perfect score in SPS and it's not real, you better go update it.
It's like that extra contributing player in a playoff run that helps the team get over the hump, right? Like the James Joneses of the world for the heat, right? Where you're just draining threes in the playoff. Nobody knew who you were before.
Everybody thought that it was just going to be whistleblower after whistleblower after whistleblower. And now a new contestant's put their hat in the race, right? And now we got Dibcat contributing. So I'm more confident in our prediction numbers now.
Yeah. Yeah, we'll have to see. But there you go. We'll link to the settlement below.
We'll link to the press release below. What do you think? Do you think we're going to hit the dozen False Claims Act settlements by the end of the year that we predicted? We're coming up on less than six months left in the year.
I don't know. I think so. Let us know what you think in chat. Like and subscribe.
We'll see you next week. See you next week.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.