---
title: "LOGZONE FCA Settlement: SPRS Score Liability"
description: "DOJ's $507,144 LOGZONE settlement shows the risk of an unsupported SPRS score. Why that still matters after the CMMC Phase II suspension."
url: https://policycortex.com/blog/logzone-false-claims-act-sprs-score
sealed: 2026-07-01
amended: 2026-07-13
register: blog/logzone-false-claims-act-sprs-score
records: 3
digest: sha3:0b13ce23564103bec7e5ddb23f05e5239446e0cdce06ffa2f53e49618b65a43a
---

# The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act Evidence

Register / Blog

DOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment. Phase II is paused, but the risk of an unsupported score remains.

PolicyCortex Team · Sealed 2026-07-01 · Amended 2026-07-13 · Reading time 9 min

Filed under: [SPRS](https://policycortex.com/blog/tags/sprs), [False Claims Act](https://policycortex.com/blog/tags/false-claims-act), [LOGZONE](https://policycortex.com/blog/tags/logzone), [CMMC](https://policycortex.com/blog/tags/cmmc), [NIST 800-171](https://policycortex.com/blog/tags/nist-800-171), [DFARS 7019](https://policycortex.com/blog/tags/dfars-7019), [enforcement](https://policycortex.com/blog/tags/enforcement)

**Policy note, 2026-07-13.** The Department of War suspended CMMC Phase II on July 13, 2026. Phase I self-assessments, the NIST SP 800-171 Rev. 2 baseline, and DFARS 252.204-7012 safeguarding obligations remain in force while the Department reviews the program. [What changed and what still applies.](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now) [Official release.](https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/)

> **July 13, 2026 update:** The Department of War suspended the CMMC Phase II transition and future implementation milestones. Phase I self-assessments, selected government assessments, and DFARS 252.204-7012 obligations remain active, so the LOGZONE lesson is more relevant to the score contractors represent now, not a November countdown.

## A Score of 110, an Assessment of -170

On **June 18, 2026**, the Department of Justice announced that LOGZONE Inc., a Huntsville, Alabama defense contractor, agreed to pay **$507,144** to resolve False Claims Act allegations tied to its cybersecurity self-assessments on Navy contracts.

The core facts are brutal in their simplicity:

- In October 2021, LOGZONE self-reported a **perfect NIST SP 800-171 score of 110** to the Supplier Performance Risk System (SPRS).
- In 2024, DoD's own assessors at DIBCAC examined the same environment and scored it **negative 170** — the floor of the scoring scale is -203.
- The gap between what the company affirmed and what was actually true became the basis of a False Claims Act case.

No breach was required. No CUI had to be exfiltrated. The *score itself* was the false claim, because contract eligibility and payment flowed from it.

If your organization has a number sitting in SPRS right now, this case is about you.

## Why This Settlement Matters More Than Its Size

Half a million dollars is small by FCA standards — Raytheon and Nightwing paid **$8.4 million** in 2025 over related cybersecurity allegations. What makes LOGZONE significant is the *pattern* it confirms:

1. **DOJ's Civil Cyber-Fraud Initiative is working through the DIB.** Since 2021, DOJ has treated cybersecurity misrepresentations as fraud. LOGZONE shows they will pursue mid-size and small contractors, not just primes.
2. **DIBCAC assessments create the evidence.** The government does not need a whistleblower to find the gap between your affirmation and your reality. A routine DIBCAC medium or high assessment produces a government-documented delta against your self-reported score.
3. **The math of exposure is asymmetric.** LOGZONE's contracts were modest. Treble damages plus per-claim penalties under the FCA can dwarf the value of the underlying contract — and the settlement follows the company's principals around in future responsibility determinations.

| Case | Year | Amount | The false claim |
|---|---|---|---|
| Aerojet Rocketdyne | 2022 | $9.0M | Misrepresented 800-171 compliance |
| Penn State | 2024 | $1.25M | Non-compliant DFARS 7012 controls |
| Raytheon / Nightwing | 2025 | $8.4M | Cybersecurity requirement failures |
| **LOGZONE** | **2026** | **$507K** | **Inflated SPRS self-assessment score** |

## The Uncomfortable Question: Is Your SPRS Score Defensible?

Most SPRS scores in the DIB were entered years ago, under deadline pressure, by someone interpreting 110 controls generously. Industry assessors report the same pattern over and over: companies that self-scored **100+** arrive at their first gap assessment and discover their defensible score is somewhere between **-50 and +50**.

The scoring methodology makes optimism expensive. A perfect score is 110, but individual controls are weighted 1, 3, or 5 points — and you *subtract* for each unimplemented control. Miss multifactor authentication (5 points), FIPS-validated encryption (up to 5), and a handful of audit and access controls, and a "mostly compliant" environment lands deep in negative territory. That is how a company that believed it deserved 110 can be assessed at -170.

Three questions determine whether your current score would survive scrutiny:

1. **Can you produce evidence for every control you claimed?** Not a policy document — artifacts. Screenshots, configurations, logs, access reviews. If a DIBCAC assessor asked tomorrow, could you show it?
2. **Was your score calculated against the official DoD Assessment Methodology,** with the correct point deductions, or was it a checklist exercise?
3. **Has your environment changed since the score was entered?** New cloud accounts, new MSP, new SaaS tools — every change since your affirmation is drift between what SPRS says and what is true.

## The Phase II Pause Does Not Remove the SPRS Risk

This is not a legacy problem that CMMC will make obsolete. It is the opposite.

On **July 13, 2026**, the Department suspended the Phase II transition and future CMMC implementation milestones. It explicitly kept Phase I self-assessment requirements in place and said NIST SP 800-171 Rev. 2 would be enforced through self-assessments and selected government-led assessments during the review.

That affirmation is a signed federal representation. LOGZONE tells you exactly how DOJ views a signed representation that does not match reality. Under CMMC, the affirmation is:

- **Named** — a specific senior official signs it, personally.
- **Recurring** — annually, not once. Every year is a fresh claim.
- **Checkable** — your C3PAO assessment results, DIBCAC reviews, and incident reports all create a paper trail the affirmation can be compared against.

Contractors still face the same underlying trap: **representing a score based on temporary fixes or stale evidence while the live environment drifts back.** A spreadsheet is a snapshot; the contract representation is about the system that actually exists. FCA exposure lives in that gap.

## What To Do Now: The Honest-Score Playbook

**1. Re-score yourself against the DoD Assessment Methodology — this quarter.**
Use the official scoring template with the actual point weights. If your realistic score is materially lower than what SPRS currently shows, updating SPRS *is the risk-reducing move*. A corrected score with a documented POA&M is defensible; a stale inflated score is not.

**2. Build the evidence trail before you need it.**
For every control you claim, know where the artifact lives. If evidence collection is manual, it will decay — this is the single most common gap C3PAOs report. Our [free CMMC Level 2 readiness assessment](https://policycortex.com/cmmc-assessment) walks through the control families where evidence gaps cluster.

**3. Treat every affirmation like the legal document it is.**
The senior official signing the SPRS affirmation should see a real compliance report before signing — not a verbal "we're good" from IT. If your affirming official can't get continuous visibility into control status, that is an organizational gap, not just a technical one.

**4. Close the drift problem structurally.**
Point-in-time compliance plus annual affirmations is a liability machine unless something holds the environment in a compliant state between assessments. This is exactly the problem PolicyCortex was built for: continuous control monitoring mapped to all 110 NIST 800-171 controls, autonomous remediation when configurations drift, and an evidence trail generated as changes happen — so the state you affirmed is the state you're actually in. The [30-day CMMC pilot](https://policycortex.com/engagement) produces a defensible baseline score and a C3PAO-ready evidence bundle in one engagement.

## The Timeline Pressure Is Real

If the LOGZONE settlement prompts you to re-examine your SPRS score — and it should — the follow-on question is whether your remediation and evidence plan closes before the next date that actually applies to you: a solicitation, prime review, recompete, selected government assessment, or internal assurance milestone.

Run your actual contract or prime date through our [CMMC contract readiness planner](https://policycortex.com/tools/cmmc-deadline-calculator), and read the [current Phase II suspension analysis](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now) before making assessment-spend decisions.

The era of the aspirational SPRS score ended on June 18, 2026. The contractors who treat their score as a legal representation — and build the machinery to keep it true — are the ones who will still be bidding in 2027.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Further reading in this register

| Sealed | Entry | Reading |
|---|---|---|
| 2026-07-13 | [CMMC Phase II Is Suspended: What Defense Contractors Still Have to Do](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now): The Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place. | 7 min |
| 2026-06-29 | [The C3PAO Capacity Math After the CMMC Phase II Suspension](https://policycortex.com/blog/c3pao-backlog-2026-cmmc-work-back-schedule): The Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans. Here is how to use the dated 2026 market snapshot without planning from a suspended milestone. | 10 min |
| 2026-03-17 | [CMMC Level 2 Requirements in 2026: The Complete Guide for Defense Contractors](https://policycortex.com/blog/cmmc-level-2-requirements-2026-complete-guide): CMMC Phase II is suspended, but the 110-requirement NIST 800-171 Rev. 2 baseline, Phase I self-assessments, and DFARS safeguarding obligations remain active. | 14 min |

Verify the record this entry describes. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2026-07-01
- **Last amended**: 2026-07-13
- **Author**: PolicyCortex Team
- **Record**: https://policycortex.com/blog/logzone-false-claims-act-sprs-score

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | bff8d8617580 | 3bd41c7a2792 |
| REC 0001 | BODY | 22d7ea67ebc4 | bff8d8617580 |
| REC 0002 | RELATED RECORDS | 0b13ce235641 | 22d7ea67ebc4 |

Head sha3:0b13ce23564103bec7e5ddb23f05e5239446e0cdce06ffa2f53e49618b65a43a. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
