CMMC Fraud: False Certification in Defense Contracting
CMMC fraud occurs when a defense contractor represents a Cybersecurity Maturity Model Certification level it has not achieved, misrepresents its scope to reduce assessment burden, or obtains certification through false statements to an assessor. Because CMMC status conditions contract eligibility, the misrepresentation supports a False Claims Act case.
Why CMMC created a new category of case
CMMC turned self-attestation into third-party assessment for much of the defense industrial base. That change did not remove the fraud risk. It moved it, because a company can misrepresent to an assessor as easily as to a contracting officer.
It also raised the stakes. CMMC status is a condition of eligibility, so a false certification is not a technical footnote on an otherwise valid contract. It goes to whether the contractor should have been awarded the work at all, which is the fraudulent inducement theory.
How CMMC misrepresentation happens
The recurring patterns are about scope, evidence, and timing.
- Scoping the assessment boundary to exclude systems that actually process controlled unclassified information
- Presenting a purpose-built enclave for assessment while real work happens on unassessed systems
- Providing an assessor with policies that exist on paper but are not operating
- Claiming a certification level the company has not achieved
- Continuing to represent certification after the environment has materially changed
- Flowing down CMMC requirements to subcontractors and not verifying them
The scoping problem is the common one
In practice the most frequent issue is not an outright lie about certification. It is a boundary drawn to exclude the messy parts of the environment.
If controlled unclassified information is processed, stored, or transmitted on systems outside the assessed boundary, the certification does not describe the environment that actually handles the government data. People inside the company usually know this, which is what makes them relators.
Frequently asked questions
Is a failed CMMC assessment evidence of fraud?
No. Failing an assessment is the system working. Fraud is representing a level you did not achieve, or shaping the assessment so it does not cover the systems that matter.
What if the company is certified but has since degraded?
Continuing to represent a certification the company no longer satisfies can support a claim, particularly where the degradation is known internally and contracts continue to be billed.
Can an assessor be liable?
A third-party assessor that knowingly issues a certification it knows to be unsupported can face exposure for causing the submission of false claims. Assessor employees are also potential relators.
The attorneys who handle these cases
Related reading
Talk to a whistleblower attorney before you report
A conversation costs nothing and is confidential. We will tell you honestly whether what you have describes a case, and what the first-to-file rule means for your timing.


