Register:Blog3 recordsSHA3-256 chainedhead sha3:0b13ce23564103bec7e5ddb23f05e5239446e0cdce06ffa2f53e49618b65a43aIntact
REC 0001BODYsha3-25622d7ea67ebc4f47316c276ce02db26ce4ae0fe2377b423bfa98bed3d080438f4prev:bff8d8617580

July 13, 2026 update: The Department of War suspended the CMMC Phase II transition and future implementation milestones. Phase I self-assessments, selected government assessments, and DFARS 252.204-7012 obligations remain active, so the LOGZONE lesson is more relevant to the score contractors represent now, not a November countdown.

A Score of 110, an Assessment of -170

On June 18, 2026, the Department of Justice announced that LOGZONE Inc., a Huntsville, Alabama defense contractor, agreed to pay $507,144 to resolve False Claims Act allegations tied to its cybersecurity self-assessments on Navy contracts.

The core facts are brutal in their simplicity:

  • In October 2021, LOGZONE self-reported a perfect NIST SP 800-171 score of 110 to the Supplier Performance Risk System (SPRS).
  • In 2024, DoD's own assessors at DIBCAC examined the same environment and scored it negative 170 — the floor of the scoring scale is -203.
  • The gap between what the company affirmed and what was actually true became the basis of a False Claims Act case.

No breach was required. No CUI had to be exfiltrated. The score itself was the false claim, because contract eligibility and payment flowed from it.

If your organization has a number sitting in SPRS right now, this case is about you.

Why This Settlement Matters More Than Its Size

Half a million dollars is small by FCA standards — Raytheon and Nightwing paid $8.4 million in 2025 over related cybersecurity allegations. What makes LOGZONE significant is the pattern it confirms:

  1. DOJ's Civil Cyber-Fraud Initiative is working through the DIB. Since 2021, DOJ has treated cybersecurity misrepresentations as fraud. LOGZONE shows they will pursue mid-size and small contractors, not just primes.
  2. DIBCAC assessments create the evidence. The government does not need a whistleblower to find the gap between your affirmation and your reality. A routine DIBCAC medium or high assessment produces a government-documented delta against your self-reported score.
  3. The math of exposure is asymmetric. LOGZONE's contracts were modest. Treble damages plus per-claim penalties under the FCA can dwarf the value of the underlying contract — and the settlement follows the company's principals around in future responsibility determinations.
CaseYearAmountThe false claim
Aerojet Rocketdyne2022$9.0MMisrepresented 800-171 compliance
Penn State2024$1.25MNon-compliant DFARS 7012 controls
Raytheon / Nightwing2025$8.4MCybersecurity requirement failures
LOGZONE2026$507KInflated SPRS self-assessment score

The Uncomfortable Question: Is Your SPRS Score Defensible?

Most SPRS scores in the DIB were entered years ago, under deadline pressure, by someone interpreting 110 controls generously. Industry assessors report the same pattern over and over: companies that self-scored 100+ arrive at their first gap assessment and discover their defensible score is somewhere between -50 and +50.

The scoring methodology makes optimism expensive. A perfect score is 110, but individual controls are weighted 1, 3, or 5 points — and you subtract for each unimplemented control. Miss multifactor authentication (5 points), FIPS-validated encryption (up to 5), and a handful of audit and access controls, and a "mostly compliant" environment lands deep in negative territory. That is how a company that believed it deserved 110 can be assessed at -170.

Three questions determine whether your current score would survive scrutiny:

  1. Can you produce evidence for every control you claimed? Not a policy document — artifacts. Screenshots, configurations, logs, access reviews. If a DIBCAC assessor asked tomorrow, could you show it?
  2. Was your score calculated against the official DoD Assessment Methodology, with the correct point deductions, or was it a checklist exercise?
  3. Has your environment changed since the score was entered? New cloud accounts, new MSP, new SaaS tools — every change since your affirmation is drift between what SPRS says and what is true.

The Phase II Pause Does Not Remove the SPRS Risk

This is not a legacy problem that CMMC will make obsolete. It is the opposite.

On July 13, 2026, the Department suspended the Phase II transition and future CMMC implementation milestones. It explicitly kept Phase I self-assessment requirements in place and said NIST SP 800-171 Rev. 2 would be enforced through self-assessments and selected government-led assessments during the review.

That affirmation is a signed federal representation. LOGZONE tells you exactly how DOJ views a signed representation that does not match reality. Under CMMC, the affirmation is:

  • Named — a specific senior official signs it, personally.
  • Recurring — annually, not once. Every year is a fresh claim.
  • Checkable — your C3PAO assessment results, DIBCAC reviews, and incident reports all create a paper trail the affirmation can be compared against.

Contractors still face the same underlying trap: representing a score based on temporary fixes or stale evidence while the live environment drifts back. A spreadsheet is a snapshot; the contract representation is about the system that actually exists. FCA exposure lives in that gap.

What To Do Now: The Honest-Score Playbook

1. Re-score yourself against the DoD Assessment Methodology — this quarter. Use the official scoring template with the actual point weights. If your realistic score is materially lower than what SPRS currently shows, updating SPRS is the risk-reducing move. A corrected score with a documented POA&M is defensible; a stale inflated score is not.

2. Build the evidence trail before you need it. For every control you claim, know where the artifact lives. If evidence collection is manual, it will decay — this is the single most common gap C3PAOs report. Our free CMMC Level 2 readiness assessment walks through the control families where evidence gaps cluster.

3. Treat every affirmation like the legal document it is. The senior official signing the SPRS affirmation should see a real compliance report before signing — not a verbal "we're good" from IT. If your affirming official can't get continuous visibility into control status, that is an organizational gap, not just a technical one.

4. Close the drift problem structurally. Point-in-time compliance plus annual affirmations is a liability machine unless something holds the environment in a compliant state between assessments. This is exactly the problem PolicyCortex was built for: continuous control monitoring mapped to all 110 NIST 800-171 controls, autonomous remediation when configurations drift, and an evidence trail generated as changes happen — so the state you affirmed is the state you're actually in. The 30-day CMMC pilot produces a defensible baseline score and a C3PAO-ready evidence bundle in one engagement.

The Timeline Pressure Is Real

If the LOGZONE settlement prompts you to re-examine your SPRS score — and it should — the follow-on question is whether your remediation and evidence plan closes before the next date that actually applies to you: a solicitation, prime review, recompete, selected government assessment, or internal assurance milestone.

Run your actual contract or prime date through our CMMC contract readiness planner, and read the current Phase II suspension analysis before making assessment-spend decisions.

The era of the aspirational SPRS score ended on June 18, 2026. The contractors who treat their score as a legal representation — and build the machinery to keep it true — are the ones who will still be bidding in 2027.

REC 0002RELATED RECORDSsha3-2560b13ce23564103bec7e5ddb23f05e5239446e0cdce06ffa2f53e49618b65a43aprev:22d7ea67ebc4

Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

proof.state
Proof of State. What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
proof.change
Proof of Change. Who or what altered the environment, under what authority, with before and after state hashes.
proof.agency
Proof of Agency. What a machine was permitted to do before it acted, what it did, and what would have stopped it.
architecture
Architecture. How the chain is built and where it lives: inside your tenant, with no egress of evidence.

Further reading in this register

Verify the record this entry describes.

Sealed
Last amended
Author
PolicyCortex Team
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000HEADbff8d86175803bd41c7a2792
REC 0001BODY22d7ea67ebc4bff8d8617580
REC 0002RELATED RECORDS0b13ce23564122d7ea67ebc4

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:0b13ce235641. The product does the same thing to your evidence.