← Back to list

Your SPRS Score Is a False Claims Act Liability. Here’s Why the Georgia Tech Case Matters.

Self-attestation isn’t a low-stakes exercise anymore. Recent DOJ activity has changed what’s on the line.

Zvi Melkman · 2026-05-26 16:57 · 0 claps · 4.5 min read
#cmmc #cybersecurity #compliance #government-contracting #defense
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 💪 · Fitness & Wellness 🏛️ · Politics

Your SPRS Score Is a False Claims Act Liability. Here’s Why the Georgia Tech Case Matters.

Self-attestation isn’t a low-stakes exercise anymore. Recent DOJ activity has changed what’s on the line.

Source: CyberSheath / Merrill Research, State of the DIB Report 2025; DOJ Civil Cyber-Fraud Initiative public announcements (2022–2025).

Source: CyberSheath / Merrill Research, State of the DIB Report 2025; DOJ Civil Cyber-Fraud Initiative public announcements (2022–2025).

In October 2025, CyberSheath published the fourth annual State of the DIB Report, conducted by Merrill Research. One number drew most of the attention: 1% of defense contractors say they are fully ready for CMMC. Down from 8% in 2023, down from 4% in 2024. Confidence is dropping as the deadline arrives.

The number underneath that headline is the one defense subs should be reading more carefully.

69% of contractors report DFARS compliance through self-assessment. Only 30% have completed a medium or high assessment that would actually validate the claim. 42% have submitted an SPRS score at all. 17% of submitters report a negative score. The required score is 110. The median is 60.

The gap between what contractors say they have and what they can document is wide, and the legal exposure attached to that gap has changed substantially in the last 18 months.

The Georgia Tech case is the pattern, not the outlier

In 2024, the Department of Justice intervened in a False Claims Act qui tam suit against the Georgia Tech Research Corporation. The complaint alleged that GTRC submitted a false self-assessment score in the Supplier Performance Risk System and failed to properly safeguard sensitive defense information. GTRC denied the allegations. The case is still progressing.

That suit followed a documented pattern. Since 2022, DOJ’s Civil Cyber-Fraud Initiative has produced at least 12 cyber-related FCA settlements. Illumina. MORSECORP. Penn State. Raytheon. The pattern across these cases is consistent: a contractor represented a cybersecurity posture to the government that the contractor either did not have or could not produce evidence for, and someone with internal visibility filed a complaint.

The mechanism is structural. SPRS scores, DFARS 252.204–7012 representations, and forthcoming CMMC affirmations all sit on the same legal shelf: statements made to the government as a condition of doing business. When those statements are material to a payment decision, they fall under the False Claims Act. The Initiative has explicitly framed cyber misrepresentation in those terms.

Where the exposure actually lives

For most small and mid-size defense contractors, the exposure does not come from outright fabrication. It comes from four operational gaps that compound:

The four operational gaps that turn a stale SPRS score into False Claims Act exposure.

The four operational gaps that turn a stale SPRS score into False Claims Act exposure.

The score was generated when the environment looked different. SPRS scoring is point-in-time. Most contractors who calculated a score 12 to 24 months ago have since added cloud services, changed identity providers, onboarded subcontractors, or shifted endpoints. The score in SPRS no longer reflects the system.

The score reflects what the SSP says, not what’s running. The System Security Plan describes the intended security posture. Many SSPs were written for the bid and were never revised against the actual implementation. A scored item that reads “implemented” against an SSP description does not survive scrutiny when a C3PAO or a federal investigator asks for the artifact.

The POA&M is treated as a parking lot. Plans of Action and Milestones are designed to track gaps with closure dates. In practice, many POA&Ms accumulate items that age past their deadlines, get rolled forward without rationale, and lose their connection to the score that depends on them. Under the CMMC final rule, POA&M items must be closed within 180 days of conditional status, or the conditional status expires.

Evidence collection is informal. The 110 controls in NIST SP 800–171 require artifacts: policies, screenshots, configuration exports, training records, log samples. Most contractors who score themselves do not have these artifacts organized against control numbers. When a third party assesses or an investigator subpoenas, the absence of artifacts is treated as the absence of the control.

Each gap, individually, can be repaired. The legal exposure shows up when the SPRS score, the SSP, the POA&M, and the actual environment have drifted apart over time and a representation has been made to the government that depends on all four being aligned.

What the November 10, 2026 milestone actually changes

CMMC enforcement began on November 10, 2025 with Phase 1. Contracting officers can now insert CMMC requirements into solicitations. Phase 1 emphasizes Level 1 and Level 2 self-assessments.

Phase 2 begins on November 10, 2026. That is the wave where C3PAO certification becomes a more common solicitation requirement for contracts involving sensitive CUI. The certified assessor reviews the SSP, samples the POA&M, requests evidence against the control families, and produces a finding that goes into the federal record.

The result of that assessment becomes a discoverable artifact. If a contractor’s earlier self-attested SPRS score is materially higher than what a C3PAO finds, the prior representation is now in tension with a third-party finding. Whether that tension produces an enforcement action depends on facts and timing, but the exposure is no longer theoretical.

What to verify this quarter

Three actions a defense sub can take before the Phase 2 window opens:

Pull the current SPRS score and the date it was generated. Compare against the system as it exists today. If the environment has changed materially since the score was calculated, the score is stale.

Match the SSP against the implementation. Walk one control family end to end. Identify where the SSP describes a control the environment does not produce evidence for.

Audit the POA&M against the 180-day closure rule. Anything that has been on the list past its date without documented remediation is a flag a C3PAO or a federal reviewer will pull on.

The contractors most exposed under the new regime are not the ones with low scores. They are the ones with high scores they cannot defend.

If the four-gap pattern above maps to what you are looking at internally, the NIST 800–171 Quick-Reference & Implementation Checklist covers all 110 controls across the 14 families with the artifact each one requires. It is on Gumroad: https://cyberzvi.gumroad.com/l/nist-800-171-checklist

For the full workbook walkthrough that pairs the controls to SSP and POA&M structure, the CMMC 2.0 Compliance Survival Guide is here: https://cyberzvi.gumroad.com/l/cmmc-workbook

Sources

CyberSheath / Merrill Research, State of the DIB Report 2025 (October 2025).

DoD CMMC Final Rule, 32 CFR Part 170; 48 CFR CMMC Acquisition Rule (effective November 10, 2025).

U.S. Department of Justice, Civil Cyber-Fraud Initiative public announcements (2022–2025).

Alston & Bird, “CMMC: New Era of Cybersecurity Compliance for Defense Contractors” (November 2025).

Cyber AB Town Hall, October 2025 (Georgia Tech Research Corporation qui tam case discussion).


메타데이터
post_id
969ecf76adf7
slug
your-sprs-score-is-a-false-claims-act-liability-heres-why-the-georgia-tech-case-matters-969ecf76adf7
url
https://medium.com/@zvi-melkman/your-sprs-score-is-a-false-claims-act-liability-heres-why-the-georgia-tech-case-matters-969ecf76adf7
canonical_url
https://medium.com/@zvi-melkman/your-sprs-score-is-a-false-claims-act-liability-heres-why-the-georgia-tech-case-matters-969ecf76adf7
author_url
https://medium.com/@zvi-melkman
status
ok
fetched_at
2026-06-09 15:37:30