IT and Security Professionals: Reporting False Compliance Certifications
Security professionals are the relators in most cybersecurity False Claims Act cases because they run the assessments that show the real compliance posture. If your employer certified DFARS, CMMC, NIST 800-171, or FedRAMP compliance it does not have, that can be a case worth 15 to 30 percent of the recovery.
You already have the evidence
Security work produces exactly the documentation these cases need. The gap assessment, the system security plan, the plan of action and milestones, the SPRS calculation, the vulnerability scan results.
These are documents you created or maintained as part of your job. You do not need to collect anything new, and collecting outside your normal authorization can create problems for you and for the case.
The moment that makes it a case
Almost every cybersecurity whistleblower describes the same sequence. They ran the assessment, the score was bad, they said so in writing, and the certification went out anyway.
That sequence is the case. The assessment establishes the true state, the escalation establishes knowledge, and the certification establishes the false statement. Whether anyone was ever breached is beside the point.
What to preserve while you decide
The window to build a record closes the moment your access is revoked.
- The dates and content of any assessment you performed or reviewed
- The identifiers of specific controls that were not implemented
- The SPRS score posted, when, and by whom
- Who signed the certification and what they had been told
- Your own escalation emails and the responses
- Which contracts carried the requirement
Clearances and classified programs
If your information touches a classified or controlled program, raise that in the first conversation. The complaint and disclosure statement can be drafted so they contain nothing you are not authorized to share.
Reporting fraud through lawful channels does not endanger a clearance. Mishandling classified material does, and that is the one avoidable way a technical whistleblower creates real personal risk.
Frequently asked questions
I raised this internally and nothing happened. Does that hurt my case?
It helps. A documented internal escalation that produced no action is the clearest possible evidence of knowledge, which is the element the government most needs to prove.
What if I signed off on the assessment myself?
Signing under instruction while documenting your objections is different from designing the misrepresentation. Be candid about your role early so it can be handled properly.
Can a contractor or consultant file?
Yes. Third-party assessors, consultants, and subcontractor employees are all eligible relators.
Is my NDA a problem?
No. Confidentiality agreements cannot lawfully prevent you from reporting suspected violations of law to the government, and provisions attempting to do so are unenforceable.
The attorneys who handle these cases
Related reading
Talk to a whistleblower attorney before you report
A conversation costs nothing and is confidential. We will tell you honestly whether what you have describes a case, and what the first-to-file rule means for your timing.


