The Department of Justice announced that LOGZONE Inc., a logistics services provider headquartered in Huntsville, Alabama, agreed to pay $507,144 to settle False Claims Act (FCA) allegations stemming from cybersecurity non-compliance on two Navy contracts. The settlement is among the starkest examples to date of the gap between contractor self-reporting and verified compliance: LOGZONE submitted a self-assessment score of 110 — the maximum possible — for its implementation of National Institute of Standards and Technology Special Publication 800-171 cybersecurity controls, while a Defense Contract Management Agency (DCMA) audit later found the company's actual score was negative 170 on a scale ranging from negative 203 to 110.

Background

NIST SP 800-171 establishes 110 security requirements that defense contractors must implement to protect Controlled Unclassified Information (CUI) on non-federal systems. The Department of Defense mandates compliance through the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which requires contractors to post self-assessment scores to the Supplier Performance Risk System (SPRS) as a condition of contract eligibility. The SPRS score system assigns positive values for each implemented control and deducts points for controls that are missing or deficient, with negative scores indicating that a contractor has failed to implement the majority of required protections.

According to DOJ, LOGZONE submitted a self-assessment score of 110 in October 2021, representing full compliance with all 110 NIST SP 800-171 controls. The company continued invoicing the Navy under its contracts while allegedly failing to implement the controls it claimed. DOJ alleged that LOGZONE knowingly submitted false payment claims from May 2021 through March 2025 — a period spanning nearly four years across both contracts.

In 2024, DCMA's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducted a formal audit of LOGZONE's systems. The assessment revealed an actual score of negative 170, placing the company near the bottom of the possible scoring range and indicating that the vast majority of required cybersecurity controls were not implemented. The 280-point discrepancy between LOGZONE's self-reported score and its audited score is among the largest documented disparities in publicly disclosed DIBCAC enforcement actions.

Key Details

The two affected Navy contracts covered logistics, inventory management, and facility support at Naval Oceanographic Command, Stennis Space Center, Mississippi, with a combined value of more than $682,000 through March 2025. The $507,144 settlement — which includes $253,572 in restitution — does not include a determination of liability, a standard DOJ qualifier that reflects the civil nature of FCA resolutions rather than an admission of wrongdoing.

DOJ's Civil Cyber-Fraud Initiative specifically targets contractors who misrepresent their cybersecurity posture when seeking or performing government contracts. The LOGZONE case is the latest in a series of enforcement actions brought under the initiative, which uses the FCA's civil investigative demand authority and qui tam whistleblower provisions to surface non-compliance that federal auditors cannot detect through routine contract oversight alone. Agencies involved in the investigation included the U.S. Attorney's Office for the Northern District of Alabama, the Department of the Navy, DCMA, the Naval Criminal Investigative Service, and the Department of the Army Criminal Investigation Division.

The DIBCAC is the primary federal body responsible for conducting high-priority cybersecurity assessments of defense contractors. Its audits involve hands-on technical review of contractor networks, access controls, incident response plans, and system configurations — going well beyond the documentation review that underlies most self-assessments. When a DIBCAC audit uncovers a score significantly below what a contractor has self-reported, the results are shared with affected program offices and can trigger contract remedies including cure notices, termination for default, and referral to DOJ.

Regulatory Context

The LOGZONE settlement comes as DOD advances the Cybersecurity Maturity Model Certification (CMMC) program, which will eventually require third-party assessments rather than self-attestation for contractors handling CUI at higher sensitivity levels. Level 2 certifications — covering NIST SP 800-171 compliance — are anticipated to be required on new solicitations beginning November 2026. Until third-party certification is universally required, self-assessment scores filed in SPRS remain the primary compliance mechanism for most defense contracts, and the accuracy of those scores depends entirely on contractor honesty.

DOJ's Civil Cyber-Fraud Initiative has used the FCA's treble-damages provisions and per-claim penalties as leverage to incentivize voluntary disclosure and accurate self-reporting. Companies that identify and self-report non-compliance before a government audit or whistleblower complaint are typically offered more favorable settlement terms than those discovered through external investigation. LOGZONE's case does not appear to have involved a voluntary disclosure; the DIBCAC audit was the trigger for federal action.

What It Means for Contractors

  • Any contractor that has filed a SPRS self-assessment score should treat that score as a legal representation — not an administrative checkbox. Scores that cannot be substantiated through documented implementation of each NIST SP 800-171 control create FCA exposure for every invoice submitted after filing.
  • DIBCAC audits are increasingly being used as enforcement tools, not just advisory assessments. If your firm is flagged for a high-priority assessment, engage legal counsel before and during the process. Audit findings can be referred directly to DOJ.
  • The nearly four-year window of alleged false claims in the LOGZONE case illustrates that FCA liability is not a one-time event — it accrues with each payment request submitted while a false statement is in effect. A single inaccurate SPRS score can expose a contractor to penalties on every invoice across the entire contract period of performance.
  • Contractors should conduct internal gap assessments against NIST SP 800-171 and develop a System Security Plan (SSP) and Plan of Action and Milestones (POA&M) documenting any deficiencies. A negative score is not automatically disqualifying, but a score that understates deficiencies creates civil risk under the FCA.
  • CMMC implementation will reduce — but not eliminate — self-assessment exposure. Level 1 CMMC (covering Federal Contract Information) will still rely on annual self-attestation by a senior company official. False attestations under CMMC carry the same FCA exposure as false SPRS scores today.
  • Whistleblower qui tam cases are a significant source of Civil Cyber-Fraud Initiative referrals. Employees, subcontractors, and competitors who are aware of NIST SP 800-171 non-compliance have financial incentives to report it to DOJ.

Sources