Most CMMC self-assessment conversations still center on a deadline. That deadline is gone — the DoD scrapped the mandatory November 2026 cutoff. What replaced it as the real driver of urgency is less visible, but far more expensive: the Department of Justice is actively prosecuting contractors whose self-reported cybersecurity scores don’t match reality.
The CMMC self-assessment trap
Every DoD contractor handling Controlled Unclassified Information has to submit a score to the Supplier Performance Risk System (SPRS) based on NIST SP 800-171 — a self-assessment, on the honor system, ranging from -203 to 110. No one is standing over your shoulder while you calculate it. That’s exactly the problem.
A self-reported score isn’t just a compliance artifact. Under the False Claims Act, it’s a certification — and certifying something false to receive a federal contract is fraud, whether or not you meant it that way. “We didn’t think anyone would check” is not a defense. It’s usually the fact pattern in the complaint.

What changed in 2021 — and what’s accelerating now
In October 2021, the DOJ launched the Civil Cyber-Fraud Initiative specifically to pursue government contractors and grant recipients who misrepresent their cybersecurity practices. It gave federal prosecutors a direct legal path — the False Claims Act — to go after inflated security claims the same way they’d go after inflated invoices.
The mechanism matters more than the headline. This isn’t the DoD showing up for a surprise audit. Cases open two ways: a DCMA (Defense Contract Management Agency) assessment that contradicts your submitted score, or a whistleblower — a current or former employee who knows the SPRS score is fiction and files a qui tam lawsuit. Under the FCA, that person can collect a share of whatever the government recovers. Every employee who touched your CMMC self-assessment is a potential plaintiff with a financial incentive to come forward.
Three settlements that show the pattern
- Georgia Tech Research Corporation — $875,000 (2025). Reported a score of 98 out of 110. The DOJ found no antivirus tools installed on the systems in scope, and that the score itself was calculated against a fictitious environment that didn’t match what was actually deployed.
- An unnamed DoD contractor — $4.6 million. Reported a score of 104 out of 110 — close to a perfect assessment. A third-party review found the actual score was -142, on a scale where the floor is -203. That is not a rounding error; it’s a different assessment entirely.
- LOGZONE Inc., Huntsville, AL — $507,144 (2026). A DCMA assessment found a score of -170 across two Navy contracts running from 2021 to 2025. The settlement is recent enough to make clear this isn’t a 2021-era enforcement wave that’s since cooled off.
The DOJ recovered $52 million in FY2025 alone under the Civil Cyber-Fraud Initiative. That number has grown every year since the program launched, and cybersecurity misrepresentation cases now sit alongside billing fraud as a recognized FCA category — not a novelty.
Why this replaces the deadline as the real driver
A mandatory certification deadline creates urgency by forcing a date on the calendar. False Claims Act exposure creates a different kind of urgency: it means every SPRS score you’ve already submitted is a live liability, whether or not CMMC certification is formally required for your contract yet. The clock isn’t ahead of you — it’s already running, on paperwork you may have already filed.
With or without a mandatory certification deadline, the CMMC self-assessment score already on file with the government has to hold up. That’s true today, for contracts signed years ago, not just for future ones.
What an accurate CMMC self-assessment actually requires
“Accurate” doesn’t mean optimistic rounding or crediting a control because a policy document mentions it. It means the score reflects what’s actually configured, actually enforced, and actually documented — the same standard a DCMA assessor or a plaintiff’s expert witness would apply if they looked. A System Security Plan that describes an ideal environment instead of your real one isn’t a shortcut; per the Raytheon settlement ($8.5 million, for exactly this issue), it’s the liability itself.
Practically, that means: testing controls against the environment as deployed, not as designed; documenting gaps honestly with a Plan of Action and Milestones instead of scoring around them; and treating the self-assessment as something that could be independently reproduced by someone with no reason to be generous.
Where to start
If your CMMC self-assessment score was calculated in-house, by whoever had the least time to do it, or more than twelve months ago, it’s worth an outside look before someone else takes one. A gap assessment does exactly what a DCMA reviewer or a whistleblower’s attorney would do — it tells you where your documented score and your actual environment diverge, while you still have time to fix it instead of explain it.
If you want a straightforward read on where your current CMMC self-assessment stands, that’s exactly what I put together at giovelasco.com/gap — no opt-in required.