Skip to the main content.

3 min read

Cheap IT and False Claims Act Exposure: What Defense Contractors Need to Understand

Cheap IT and False Claims Act Exposure: What Defense Contractors Need to Understand
6:34

When a defense contractor submits a CMMC self-attestation, they're not filling out a preference form. They're making a legal declaration under federal law. And if that declaration is inaccurate — because the IT provider managing their systems isn't actually delivering what compliance requires — the contractor is the one exposed.

This is the part of the CMMC conversation that doesn't get enough attention. The focus tends to be on controls, timelines, and assessments. The legal consequences of misrepresentation are less discussed — but for manufacturers and DIB suppliers weighing IT proposals right now, they're worth understanding clearly.

What is the False Claims Act?

The False Claims Act is a federal law that imposes civil liability on individuals and organizations that submit false or fraudulent claims to the government. Originally enacted during the Civil War to address defense contractor fraud, it's become one of the government's primary tools for addressing contractor misrepresentation.

In October 2021, the Department of Justice launched the Civil Cyber-Fraud Initiative specifically to apply the False Claims Act to cybersecurity misrepresentation — contractors who certify that required security controls are in place when they aren't. Since then, the government has pursued multiple cases, including a $9 million settlement with a major aerospace and defense contractor over misrepresented compliance with NIST 800-171. The message from DoJ has been consistent: cybersecurity certification is a legal act, not a paperwork exercise.

How This Connects to Your IT Provider

Here's the point that matters for defense contractors evaluating IT proposals: when you self-attest to CMMC compliance, you are the one making the legal declaration. Your IT provider is not.

If your MSP tells you your environment is compliant, you attest to that, and it later emerges that the required controls weren't actually in place — the liability is yours. The provider who underbid the contract, cut the security stack to hit a lower price, and left your compliance program with critical gaps isn't the party facing False Claims Act exposure. You are.

This is not hypothetical. CMMC self-attestation under DFARS 252.204-7021 is a formal, legally binding affirmation. The gap between what a cheaper IT provider delivers and what compliance actually requires is exactly the kind of misrepresentation the Civil Cyber-Fraud Initiative was designed to pursue.

The Whistleblower Problem

The False Claims Act includes qui tam provisions — which allow private parties to file suit on behalf of the federal government and receive a share of any recovery. In practice, this means whistleblowers: employees, former employees, subcontractors, or competitors who have evidence that a contractor misrepresented their compliance status.

For manufacturers in the defense supply chain, the exposure surface for a qui tam action is real. Employees who left on bad terms. Subcontractors who had visibility into your IT environment. A former IT provider who knows what your systems actually looked like. Any of these parties can initiate a False Claims Act suit — and if the government intervenes, the penalties are significant: up to three times the contract value, plus per-claim penalties.

The CMMC Phase II suspension paused third-party assessments. It did not pause the False Claims Act. Self-attestation liability remains fully active.

What Happens During an Incident

If a security incident occurs, the connection between your IT provider's capabilities and your legal exposure becomes concrete very quickly.

When something goes wrong, your MSP is your first responder — containing the threat, isolating affected systems, preserving logs and evidence, and coordinating the handoff to the incident response firm your cyber insurance carrier brings in. That IR firm conducts the forensic investigation and produces a report documenting what happened, when, and how.

If that report shows that the controls you attested to weren't in place — no functioning EDR, logs that weren't monitored, MFA that was never enforced — you now have documented evidence of a compliance gap in a report the government can subpoena. The incident itself may not be the primary problem. What that documentation reveals about your actual security posture can be.

The MSP who promised compliance at a price that couldn't support it isn't named in that report. Your attestation is.

You Can Sue Your IT Provider — But That Doesn't Fix Your Attestation

If your IT provider misrepresented what they were delivering, you may have legal recourse against them. Breach of contract. Misrepresentation. Depending on the circumstances, potentially more. That's a legitimate avenue — and one worth discussing with legal counsel if you find yourself in that situation.

But here's the reality: that litigation takes years. In the meantime, the government's investigation into your attestation doesn't wait for your civil suit to resolve. The False Claims Act action proceeds on its own timeline, against you, based on the declaration you signed. Winning a lawsuit against your IT provider down the road doesn't retroactively make your self-attestation accurate, doesn't recover a lost contract, and doesn't undo the reputational damage of a DoJ inquiry. The two tracks are independent of each other — and the one that moves faster is the one with the government on the other side.

The decision about which IT provider to trust with your compliance program is yours to make. So is the attestation that follows from it.

This Is a Business Decision, Not Just a Technical One

We've written about why a significant price gap between IT proposals is a red flag, about the cycle that repeats when compliance is underfunded, and about what compliance actually requires from your IT provider.

The False Claims Act layer is why the stakes extend beyond service quality. Choosing a cheaper IT provider to manage a CMMC-obligated environment isn't just an operational risk — it's a legal one that attaches to your contracts and your business.

If you want to understand where your compliance program actually stands, contact TotalCare IT. We work with defense contractors and DIB suppliers across Idaho and can give you a straightforward assessment.