DOJ’s LOGZONE settlement and the FCA: Lessons learned for small businesses and self-assessments
If you think DOJ is only targeting large aerospace giants, think again. Enforcement continues against small business contractors, targeting alleged failures to adequately safeguard Controlled Unclassified Information (CUI) and, critically, their representations about cybersecurity.
On June 18, 2026, the U.S. Department of Justice (DOJ) announced a settlement with LOGZONE Inc. (LOGZONE) of Huntsville, Alabama, to pay $507,144—about 75% of the total payment it received on two Navy contracts—to resolve False Claims Act (FCA) allegations. This settlement can be read against the backdrop of the U.S. Department of Defense’s (DoD’s) recent acknowledgment that current cybersecurity requirements can impose “significant and often prohibitive burdens” on the defense industrial base, particularly small and nontraditional businesses, and can cause innovative entrants and small businesses to opt out of defense contracts. That policy shift may reduce some compliance friction associated with complex requirements, but it does not eliminate baseline cybersecurity obligations or the FCA exposure created when contractors inaccurately represent their compliance. The FCA imposes liability on contractors that knowingly submit false claims for payment, including invoices tied to false or inaccurate certifications. For example, defense contractors must implement specific cybersecurity controls and self-assess their compliance as a condition of payment, meaning each invoice submitted while out of compliance can trigger a false claim. As cybersecurity obligations grow more complex, accurately self-assessing compliance becomes an increasing challenge for all government contractors, especially small businesses that may have fewer resources.
The LOGZONE settlement sends a message that the government will not limit enforcement based on a contractor’s size. Small businesses and large defense contractors alike should prepare for rigorous scrutiny of their cybersecurity self-assessments and should expect enforcement and real consequences when those assessments misrepresent compliance.
LOGZONE is a defense logistics services provider, certifying as both a small, disadvantaged business and service-disabled veteran-owned business. Between March 2021 and November 2022, the U.S. Navy awarded LOGZONE two contracts, collectively known as the “NAVOCEANO Contracts,” to provide logistical, inventory, and facility support services. In total, LOGZONE was paid $682,193.37 under the NAVOCEANO Contracts.
The NAVOCEANO Contracts integrated the provisions of Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, 252.204-7019 and 252.204-7020. At a high level, these clauses collectively require DoD contractors and subcontractors to implement National Institute of Standards and Technology (NIST) SP 800-171 security requirements on covered information systems to safeguard covered defense information, including CUI, and to post summary-level self-assessment scores in the Supplier Performance Risk System (SPRS), which the government may audit.
In October 2021, LOGZONE reported a perfect 110 self-assessment score in SPRS. In contrast, the Defense Contract Management Agency (DCMA) later assessed LOGZONE’s NIST SP 800-171 implementation during an audit and assigned a score of negative 170, on a scale from negative 203 (i.e., failure to properly implement all controls) to 110 (i.e., implementation of all controls).
The United States alleges that for about a four-year period, LOGZONE did not fully implement all NIST SP 800-171 cybersecurity controls for systems that processed, stored, or transmitted covered defense information. According to the settlement, failure to implement some of the controls could have led to significant exploitation of the system or exfiltration of covered defense information or could have had a specific and targeted effect on the security of the system and its data. The settlement resolved civil and administrative monetary claims for the covered conduct under the FCA, the Program Fraud Civil Remedies Act, and common law theories of liability, conditioned on payment of the settlement amount. The press release credits a coordinated effort by DOJ’s Civil Division, Fraud Section, and DCMA, among other agencies, noting the alignment with the administration’s new Task Force to Eliminate Fraud and National Fraud Enforcement Division.
Given DOJ’s continued emphasis on fraud and enforcing the terms of government contracts, this case highlights important, actionable lessons.
The LOGZONE settlement is a reminder that cybersecurity clauses are not “check the box” exercises. Rather, a cybersecurity clause, like any contract clause, commits a contractor and subcontractors to fulfill certain obligations. When the contractor submits an invoice, they represent that they satisfied each commitment. Every invoice is therefore a potential risk point when a contractor or its subcontractors knows that required cybersecurity controls are not implemented, as reflected by DOJ’s allegation that LOGZONE submitted claims for reimbursement while knowing that it had failed to comply with DFARS 252.204-7012.
LOGZONE reported a perfect 110 self-assessment score, but DCMA later assigned a negative 170 score after a Medium Assessment. This is a significant gap. Contractors and subcontractors should validate their cybersecurity posture before submitting or relying on assessment scores, especially self-assessment scores. Although the conduct the LOGZONE settlement covers occurred before formal implementation of the Cybersecurity Maturity Model Certification (CMMC) program, the contractual obligations corresponded to what is now required for CMMC Level 2 self-assessment. The case now lands against a shifting CMMC landscape: DoD has suspended upcoming CMMC implementation milestones, including the November 2026 Phase 2 transition, which mandated review of covered systems by third-party assessors and directed a “top-to-bottom” review of the CMMC program in the next 60 days. This immediate suspension follows feedback that the CMMC program is “structurally incompatible with our need to rapidly expand the [Defense Industrial Base],” and the “combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines” forces new entrants and small businesses out of the defense market. However, for current contractors, especially small and nontraditional businesses, suspension should not be mistaken for a lack of cyber accountability, because DFARS 252.204-7012 remains in effect and baseline NIST SP 800-171 Rev. 2 compliance will continue through Defense Industrial Base self-assessments and select government-led assessments, the same requirements that were incorporated into LOGZONE’s contracts.
In addition to shifts in the CMMC program, proposed regulations aim to extend and integrate information security requirements across the broader federal procurement system. As part of the Revolutionary Federal Acquisition Regulation (FAR) Overhaul, a proposed rule published on June 23, 2026, introduces CUI safeguarding requirements into the broader procurement framework. Specifically, the rule would add a new CUI provision at FAR 52.240-6, a new CUI clause at FAR 52.240-7, and a standard form to identify the CUI and obligations under NIST SP 800-171. These developments create new paths for enforcement and reinforce the need for both defense and civilian federal contractors to treat cybersecurity compliance as a contract-performance issue and a source of direct legal obligations and risk, not just an IT or business function.
The LOGZONE settlement illustrates that DOJ treats cybersecurity noncompliance not as a mere administrative, technical failing but rather as a basis for legal liability when contractors knowingly submit claims without adequately implementing required controls. The enforcement risk surrounding cybersecurity compliance extends beyond government-initiated investigations, as (1) whistleblower-initiated actions have surged in part due to new incentives (see our Regulatory Roundup, Federal Enforcement Under Trump 2.0: What Government Contractors Need to Know) and (2) data miners use AI to identify potential qui tam cases, as detailed in reporting from DOJ. No matter how an enforcement action is initiated, contractors and subcontractors should remember that the consequences can extend well beyond any monetary payment to resolve alleged false claims. They may also include the costs of internal investigations, defense, remediation and corrective action, reputational harm, and settlement obligations. In appropriate cases, criminal fines and imprisonment may also be at issue, along with increased risks of suspension or debarment, adverse past-performance ratings, and other negative responsibility determinations.
The LOGZONE settlement should prompt contractors and subcontractors to run a focused review of their compliance with contractual cybersecurity requirements. The following practical steps provide a starting point to reduce FCA risk and strengthen cybersecurity posture under contracts containing applicable information security clauses:
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.