Your case is filed under seal. Your employer is not notified.

Free reviewNo fee unless we recoverCases nationwide

The Whistleblower AdvocatesA practice of Kang Haggerty LLCConfidential line(833) 310-3147

CMMC Fraud: False Certification in Defense Contracting

Short answer

CMMC fraud occurs when a defense contractor represents a Cybersecurity Maturity Model Certification level it has not achieved, misrepresents its scope to reduce assessment burden, or obtains certification through false statements to an assessor. Because CMMC status conditions contract eligibility, the misrepresentation supports a False Claims Act case.

Why CMMC created a new category of case

CMMC turned self-attestation into third-party assessment for much of the defense industrial base. That change did not remove the fraud risk. It moved it, because a company can misrepresent to an assessor as easily as to a contracting officer.

It also raised the stakes. CMMC status is a condition of eligibility, so a false certification is not a technical footnote on an otherwise valid contract. It goes to whether the contractor should have been awarded the work at all, which is the fraudulent inducement theory.

How CMMC misrepresentation happens

The recurring patterns are about scope, evidence, and timing.

  • Scoping the assessment boundary to exclude systems that actually process controlled unclassified information
  • Presenting a purpose-built enclave for assessment while real work happens on unassessed systems
  • Providing an assessor with policies that exist on paper but are not operating
  • Claiming a certification level the company has not achieved
  • Continuing to represent certification after the environment has materially changed
  • Flowing down CMMC requirements to subcontractors and not verifying them

The scoping problem is the common one

In practice the most frequent issue is not an outright lie about certification. It is a boundary drawn to exclude the messy parts of the environment.

If controlled unclassified information is processed, stored, or transmitted on systems outside the assessed boundary, the certification does not describe the environment that actually handles the government data. People inside the company usually know this, which is what makes them relators.

Frequently asked questions

Is a failed CMMC assessment evidence of fraud?

No. Failing an assessment is the system working. Fraud is representing a level you did not achieve, or shaping the assessment so it does not cover the systems that matter.

What if the company is certified but has since degraded?

Continuing to represent a certification the company no longer satisfies can support a claim, particularly where the degradation is known internally and contracts continue to be billed.

Can an assessor be liable?

A third-party assessor that knowingly issues a certification it knows to be unsupported can face exposure for causing the submission of false claims. Assessor employees are also potential relators.

The attorneys who handle these cases

Related reading

See what we have recovered for whistleblowers

Talk to a whistleblower attorney before you report

A conversation costs nothing and is confidential. We will tell you honestly whether what you have describes a case, and what the first-to-file rule means for your timing.

Call (833) 310-3147 for a free confidential review