Defense Contractor Settles Cybersecurity False Claims Allegations for $507,144
- OpusDatum

- Jun 18
- 2 min read

LOGZONE Inc, a Huntsville, Alabama-based defence contractor, has agreed to pay $507,144 to resolve liability under the False Claims Act (FCA) arising from its failure to meet cybersecurity requirements on contracts with the Department of the Navy.
The settlement concerns allegations that LOGZONE knowingly submitted false or fraudulent claims for payment on two Navy contracts despite not complying with the contracts' cybersecurity obligations. Between May 2021 and March 2025, the company allegedly failed to implement controls mandated under National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, deficiencies that could have permitted exploitation of its systems or exfiltration of sensitive defence information.
The shortcomings came to light when the Defense Contract Management Agency (DCMA) assessed LOGZONE's implementation of the NIST SP 800-171 control set. The company recorded a score of -170, near the bottom of the permissible range of -203 to 110, indicating that the substantial majority of required controls were absent or inadequately implemented.
The resolution was reached through coordinated work between the Department of Justice (DOJ) Civil Division's Commercial Litigation Branch, Fraud Section and the US Attorney's Office for the Northern District of Alabama, with support from the Department of the Navy Office of the General Counsel, the Naval Criminal Investigative Service (NCIS), the Department of the Army Criminal Investigation Division, and the DCMA's Defense Industrial Base Cybersecurity Assessment Center.
The matter reflects the continued use of FCA mechanisms to enforce contractual cybersecurity standards, an approach that places measurable assessment scores and demonstrable control implementation at the centre of contractor accountability. For firms holding federal contracts that involve handling controlled unclassified information, the case reinforces that self-attestation to NIST SP 800-171 compliance carries direct liability exposure where the underlying controls are not genuinely in place, and that DCMA assessment scores provide an evidentiary basis on which such liability can be established.
Read the press release here.
%20-%20C.png)
