On June 17, 2026, the United States Department of Justice (DOJ) announced a settlement agreement with LOGZONE, Inc., an Alabama-based logistics services provider, resolving allegations under the False Claims Act (Department of Justice, 2026a). The settlement requires LOGZONE to pay $507,144, which includes $253,572 in restitution, to resolve claims that the company knowingly failed to comply with cybersecurity requirements stipulated in two contracts with the Department of the Navy (Department of Justice, 2026a; Department of Justice, 2026b). The case highlights the ongoing enforcement of Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 standards (Department of Defense, 2026).
Between March 2021 and November 2022, the Navy awarded LOGZONE two contracts for logistical, inventory, and facilities support services for the Naval Oceanographic Command Property Management Program at Stennis Space Center in Mississippi (Department of Justice, 2026b). LOGZONE received $682,193.37 under these contracts through March 8, 2025 (Department of Justice, 2026b; Easley, 2026a). Both contracts incorporated DFARS clause 252.204-7012, which mandates that Department of Defense (DoD) contractors provide adequate security for covered defense information by implementing NIST SP 800-171 security requirements (Department of Justice, 2026b). Additionally, the contracts included DFARS clauses 252.204-7019 and 252.204-7020, requiring contractors to post summary-level scores of a current NIST SP 800-171 DoD self-assessment to the Supplier Performance Risk System (SPRS) (Department of Justice, 2026b).
NIST SP 800-171 establishes 110 security controls for defense contractors handling controlled unclassified information (CUI) on non-federal systems (Easley, 2026a). The DoD Assessment Methodology for NIST SP 800-171 dictates that a perfect implementation of all controls results in a score of 110, while unmet requirements subtract from this total, allowing scores to range from a high of 110 to a low of -203 (Department of Defense, 2020). On October 13, 2021, LOGZONE submitted a perfect self-assessment score of 110 to the SPRS (Department of Justice, 2026b; Tobin, 2026).
On February 2, 2024, the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a component of the Defense Contract Management Agency (DCMA), conducted a Medium Assessment of LOGZONE’s NIST SP 800-171 implementation (Department of Justice, 2026b). The DIBCAC is the DoD entity responsible for assessing contractor compliance with DFARS cybersecurity clauses and is the sole entity designated to assess Cybersecurity Maturity Model Certification (CMMC) Level 3 compliance (Defense Contract Management Agency, 2025). Following the assessment, DIBCAC determined that LOGZONE’s actual score was -170, placing it near the bottom of the possible scoring range (Department of Justice, 2026b; Easley, 2026a).
The DOJ alleged that between May 5, 2021, and March 8, 2025, LOGZONE knowingly submitted claims for payment to the Navy despite failing to implement required cybersecurity controls (Department of Justice, 2026a; Department of Justice, 2026b). The unfulfilled controls included measures that, if omitted, could lead to significant exploitation of the system or the exfiltration of sensitive defense information (Department of Justice, 2026a). LOGZONE agreed to the $507,144 settlement without an admission of liability (Department of Justice, 2026b).
The settlement aligns with the DOJ’s Civil Cyber-Fraud Initiative, launched in October 2021 to utilize the False Claims Act against government contractors who fail to follow required cybersecurity standards or knowingly misrepresent their cybersecurity practices (Department of Justice, 2021). Other recent False Claims Act settlements related to cybersecurity include a $4.6 million settlement with MORSE Corp in March 2025, an $8.4 million settlement with Raytheon in May 2025, and an $875,000 settlement with Georgia Tech Research Corporation in October 2025 (Ahuja & Kingsbury, 2026).
DFARS 252.204-7012 has required defense contractors to implement NIST SP 800-171 controls since December 31, 2017 (Department of Defense, 2026). It is a flow-down clause, meaning prime contractors must include it in all subcontracts involving DoD CUI (Department of Defense, 2026). To transition from a self-attestation model to a verification system, the DoD introduced the CMMC program in 2019 (Department of Defense, n.d.). Phase 1 of CMMC implementation officially began on November 10, 2025, requiring self-assessments for Levels 1 and 2, with mandatory third-party assessments by a C3PAO scheduled to begin in Phase 2 in November 2026 (Department of Defense, n.d.; Easley, 2026b). While the LOGZONE case did not involve a direct violation of CMMC rules, the unfulfilled NIST SP 800-171 controls form the foundation of CMMC Level 2 requirements (Easley, 2026a).
References
Ahuja, K., & Kingsbury, S. P. (2026, January 13). Cybersecurity-related enforcement under the False Claims Act in 2025: New settlements, same lessons. Mintz. Cybersecurity-Related Enforcement Under the False Claims Act in 2025: New Settlements, Same Lessons | Mintz
Defense Contract Management Agency. (2025, July). Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). U.S. Department of Defense. https://www.dcma.mil/DIBCAC/
Department of Defense. (n.d.). About CMMC. Office of the Chief Information Officer. https://dodcio.defense.gov/CMMC/about/
Department of Defense. (2020, June 24). NIST SP 800-171 DoD assessment methodology, version 1.2.1. Office of the Under Secretary of Defense for Acquisition and Sustainment. https://www.acq.osd.mil/asda/dpc/cp/cyber/docs/safeguarding/NIST-SP-800-171-Assessment-Methodology-Version-1.2.1-6.24.2020.pdf
Department of Defense. (2026, May 7). 252.204-7012 Safeguarding covered defense information and cyber incident reporting. Defense Federal Acquisition Regulation Supplement. https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.
Department of Justice. (2021, October 6). Deputy Attorney General Lisa O. Monaco announces new Civil Cyber-Fraud Initiative. Office of Public Affairs. https://www.justice.gov/archives/opa/pr/deputy-attorney-general-lisa-o-monaco-announces-new-civil-cyber-fraud-initiative
Department of Justice. (2026a, June 18). Alabama defense contractor agrees to pay $507,144 to resolve False Claims Act liability relating to cybersecurity violations. Office of Public Affairs. Office of Public Affairs | Alabama Defense Contractor Agrees to Pay $507,144 to Resolve False Claims Act Liability Relating to Cybersecurity Violations | United States Department of Justice
Department of Justice. (2026b, June 17). Settlement agreement. https://www.justice.gov/opa/media/1446716/dl
Easley, M. (2026a, June 18). Defense contractor settles cybersecurity False Claims Act allegations. DefenseScoop. Defense contractor settles cybersecurity False Claims Act allegations | DefenseScoop
Easley, M. (2026b, November 10). Pentagon begins enforcing CMMC compliance, but readiness gaps remain. DefenseScoop. Pentagon begins enforcing CMMC compliance, but readiness gaps remain | DefenseScoop
Tobin, S. D. (2026, June 19). Contractor settles false claim allegations over cybersecurity violations. Cohen Seglias. https://www.cohenseglias.com/news-article/contractor-settles-false-claim-allegations-over-cybersecurity/
AI generated