There is a temptation, under deadline pressure, to post a NIST SP 800-171 score in SPRS that is rosier than reality. It feels like paperwork optimism. Since 2021, it is something much more serious: potential False Claims Act exposure.
The Civil Cyber-Fraud Initiative
In 2021 the U.S. Department of Justice announced its Civil Cyber-Fraud Initiative, using the False Claims Act to pursue contractors that knowingly misrepresent their cybersecurity — including overstated 800-171 scores and unmet DFARS 252.204-7012 obligations. Publicized settlements have followed. The government’s theory is straightforward: if compliance was a condition of the contract and you claimed it falsely, you defrauded the government.
Why this raises the stakes
The False Claims Act is punishing by design — it allows treble (triple) damages plus substantial per-claim penalties, and it lets insiders (whistleblowers) file suit and share in the recovery. That last part matters: the person who knows your score is inflated may be sitting in your own office.
The honest score is the safe score
None of this is a reason to fear CMMC; it is a reason to be accurate. A truthful score with a credible POA&M is defensible. An inflated one is a liability that compounds over time. This is exactly why we insist on evidence-backed self-assessments — the number you report should be one you would be comfortable defending.