Skip to content
Article

What a $507,144 False Claims Act Settlement Says About Your SPRS Score

Last updated — August 29, 2026

In June 2026, the Department of Justice settled with LOGZONE Inc., an Alabama defense contractor, for $507,144. This case involved issues related to the SPRS score False Claims Act.

The company had reported an SPRS score of 110 — the highest score obtainable, meaning every one of the 110 NIST SP 800-171 requirements fully implemented. A government assessment put the real figure at −170.

The scale is worth sitting with. SPRS runs from a floor of −203 to a ceiling of 110. LOGZONE reported the ceiling. The assessed reality was near the floor. That is a 280-point gap, on two Department of the Navy contracts carrying DFARS 252.204-7012, over a period running from May 2021 to March 2025.

The detail that should change your risk assessment

There was no whistleblower.

DOJ has indicated the matter did not originate from a qui tam complaint or a tip from an insider. It came out of a government audit.

That single fact dismantles the most common piece of private reasoning in this space. When contractors quietly justify an optimistic score, the unspoken logic is usually about detection: nobody is going to look, and nobody inside is going to say anything. The first half was already shaky. LOGZONE removes the second half entirely. The government found this by assessing the company, which it is entitled to do, at a time of its choosing.

How a company ends up 280 points wrong

It is tempting to read a gap that large as deliberate fraud, and in some cases it is. But in my experience auditing control environments, a score can drift that far from reality through entirely ordinary organisational failure. Four mechanisms do most of the work.

Scoring intent rather than implementation. Someone works down the requirement list asking “do we do this?” rather than “can we evidence this, for the whole scope, today?” A firewall exists, so 3.13.1 is scored as met. Whether the boundary is defined, documented and monitored is never tested.

Scoring the requirement rather than the objectives. Each of the 110 requirements decomposes into assessment objectives — 320 in total. A requirement is met only when every one of its objectives is met. Score at the requirement level and you will systematically overstate, because partial implementation reads as implementation.

Never applying the weighting. The DoD Assessment Methodology deducts 5, 3 or 1 point depending on the requirement. Forty-four requirements are worth 5 points each. Miss nine of those and you are already 45 points down from 110, before touching anything else. Negative scores are not exotic; they are what arithmetic produces when the heavy requirements are unmet.

Nobody owns the number. The score is produced once, by whoever was available, submitted, and then treated as a fact about the company rather than a claim requiring maintenance. Environments change. Scores do not follow unless someone makes them.

The affirmation is the exposure

Here is the part that makes this a legal matter rather than a compliance one.

When you submit a score to SPRS and affirm it, you are making a representation to the United States government in connection with contracts you are paid under. The False Claims Act attaches to that representation. It is not part of the CMMC program, it predates CMMC entirely, and the Phase 2 suspension of July 2026 does not touch it.

That is why the July suspension changed less than people think. The certification requirement was paused. The thing that produced a half-million-dollar settlement a month earlier — a self-reported score that was not true — is exactly as live as it was in June.

Note also the period: May 2021 to March 2025. Enforcement looks backwards. A score you submitted years ago, under a person who has since left, on a contract that has since closed, is still a representation you made.

What a defensible score actually requires

The standard is not “we believe this is right.” It is: if an assessor arrived tomorrow and worked through the 320 objectives, would they arrive at your number?

In practice that means four things.

  1. A defined scope. You cannot score an environment whose boundary nobody has drawn. Which assets handle CUI, which protect it, which are specialized, which are genuinely out.
  2. Objective-level scoring. All 320, individually, with partial implementation recorded as partial rather than rounded up.
  3. Evidence that exists now. Dated, within the assessment period, and locatable in minutes. Undated evidence is treated as no evidence.
  4. A named owner and a review cadence. A score is a perishable claim. Treat it like one.

None of this is exotic. It is ordinary assessment discipline. What LOGZONE illustrates is the cost of not applying it: roughly half a million dollars, arrived at without anyone inside the company saying a word.

If you suspect your own score is wrong

This is a question for counsel, not for a blog post, and I am not going to pretend otherwise. There are mechanisms — correcting a score in SPRS, voluntary disclosure — and the calculus around them is genuinely legal rather than technical.

What I would say is that the gap between “our score is optimistic” and “our score is defensible” is work you can start today, without a lawyer, and the work is the same work you would need to do eventually anyway. Reassessing honestly costs you a few weeks. The alternative has a published price.

Related reading


Check your own number

The CMMC Level 2 Readiness Kit includes a control assessment workbook that scores at the objective level across all 320 objectives and calculates the SPRS figure with the correct weighting applied — so the number you submit is one you can show your working for.













Free download · 1 page · PDF

Do you need CMMC Level 1 or Level 2?

Four ordered steps that settle which level applies to you, taken straight from the contract clauses — plus the four things people most often get wrong.

Click here to download →

Provided for general information. Not legal, audit or certification advice, and nothing here should be read as guidance on responding to a specific enforcement matter. Rules cited are current as at August 2026.