A single number you typed into a federal database can become the basis of a fraud case against your company. That number is your Supplier Performance Risk System self-assessment score, and if it is wrong in the government's favor, the law that governs it is not a cybersecurity regulation. It is the False Claims Act.

Most owners treat the SPRS score as an IT housekeeping task. It is a representation to the United States government, and the gap between those two readings is where the exposure lives. As of July 2026 that gap carries more weight than it did a month ago. With CMMC Phase II suspended, the score you post and affirm is the verification mechanism, and the third-party assessor who would have checked it is the part that got paused.

What is an SPRS score and where does it come from?

The Supplier Performance Risk System (SPRS) is the Department of Defense database that holds your self-assessed cybersecurity score. The score is a single number on a scale that tops out at 110, calculated against the 110 security requirements in NIST Special Publication 800-171, the federal standard for protecting Controlled Unclassified Information (CUI) on a contractor's systems.

The obligation to post that score is not optional, and it is not new. Two DFARS clauses created it:

  • DFARS 252.204-7019 requires you to have a current NIST SP 800-171 assessment on file in SPRS, performed within the prior three years, before you can be awarded a covered contract.
  • DFARS 252.204-7020 requires you to provide the government access to your systems and to post the Basic Assessment result, the self-scored number, in SPRS.

The methodology is the DoD Assessment Methodology. Every one of the 110 controls carries a point value. You start at 110 and subtract the weighted value of each control you have not fully implemented. A perfect score means all 110 controls are in place. A negative score is common and honest for a shop that has not started, because some single controls subtract five points each.

The score is not a grade you give yourself. It is an arithmetic result of which controls are actually implemented on the day you assess.

How does a wrong SPRS score become a False Claims Act problem?

The moment you post a score to win or keep a federal contract, you have made a representation to the government, and an inflated one can become liability under the False Claims Act (31 U.S.C. ยงยง 3729-3733). The False Claims Act imposes liability on anyone who knowingly submits a false claim for payment, or who uses a false record or statement material to a false claim. Cybersecurity attestations sit squarely inside that language.

The mechanism is what compliance lawyers call implied false certification. When you accept and perform a contract that requires DFARS 252.204-7012 safeguarding and a posted SPRS score, every invoice you submit carries an implied representation that you met the conditions of payment. If you knew your true score was 40 and you posted 95 to clear a prime's threshold, the invoices that followed can be treated as false claims.

"Knowingly" under the statute is broad. It covers actual knowledge, deliberate ignorance, and reckless disregard for the truth. You do not have to intend fraud. A score posted by someone who never verified whether the controls were real can meet the reckless-disregard standard.

The penalties are not symbolic. The False Claims Act provides for treble damages, three times the government's loss, plus a per-claim civil penalty, and each invoice can count as a separate claim.

Who actually brings these cases?

Two parties can pursue an inaccurate SPRS score: the Department of Justice directly, and private whistleblowers. The DOJ launched its Civil Cyber-Fraud Initiative to use the False Claims Act against contractors who knowingly misrepresent their cybersecurity practices or knowingly fail to monitor and report incidents. Cybersecurity attestations are the explicit target of that initiative.

The second path is the one owners underestimate. The False Claims Act includes a qui tam provision that lets a private citizen, a relator, file suit on the government's behalf and share in any recovery. In practice the relator is often an insider: a former IT administrator, a departed compliance manager, an engineer who watched the score get inflated and kept the emails. The person who knows your real score is the person with standing to file against you and a financial incentive to do it.

This is why the SPRS score is a people problem as much as a technical one. The score lives in a federal system, but the knowledge of whether it is honest lives with everyone who touched your environment.

What the CMMC Phase II suspension changed, and what it did not

On July 13, 2026 the Department suspended CMMC Phase II, the phase originally scheduled for November 10, 2026 that would have made third-party Level 2 certification a condition in DoD contracts, and opened a reform review of the program. The self-assessment did not pause. Neither did the exposure. If anything the suspension concentrates it, because the outside assessor who would have checked your number is the part that went away.

As of July 2026 the program sits paused in Phase 1. Level 2 requires a self-assessment every three years against the 110 requirements in NIST SP 800-171 Revision 2, with an annual affirmation of compliance. The Department's notice is explicit that the action "does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012," and that during the review it will enforce NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments. DFARS 252.204-7021 remains the clause that flows the CMMC requirement into contracts and onto subcontractors.

Read the enforcement architecture the suspension leaves standing:

  • You score yourself. The number in SPRS is still yours, still posted under -7019 and -7020, still visible to the government, and still the number a prime has to confirm before it can award you a subcontract.
  • You affirm it annually. A signature, every year, that the 110 requirements are met.
  • No independent party is scheduled to check it. The C3PAO assessment that would have surfaced the distance between your posted score and your real environment is the suspended thing.
  • Except when one shows up. Select government-led assessments continue, and they arrive without the runway a booked assessment date would have given you.

An inflated score used to carry a scheduled reckoning. Now it carries an unscheduled one. If your posted score says 100 and any assessor, government-led or otherwise, finds the true implementation is 55, you have a documented record of a representation that does not match reality, created by an independent party. That is the kind of evidence a qui tam relator or the DOJ builds a case on.

The honest reading: CMMC never created the False Claims Act exposure. It was going to expose the exposure that was always there in an inflated self-assessment. With Phase II suspended, that exposure sits exactly where it has sat since -7019 took effect, under a number you typed, waiting for whoever finds it first. The False Claims Act, the DOJ Civil Cyber-Fraud Initiative, and the former IT administrator who watched you post it all run on their own timeline, and none of them were paused on July 13.

How do I score honestly and protect myself?

You protect yourself by scoring the controls as they actually are today and remediating the gaps through a documented plan, not by inflating the number to clear a prime's threshold. The defensible posture has four parts.

  • Assess against the real environment. Walk each of the 110 controls and score it on whether it is implemented now, not whether you intend to implement it. Document the basis for each deduction so the score is reconstructable.
  • Write a System Security Plan (SSP). NIST SP 800-171 requires a written SSP describing how each control is met. An accurate score with a real SSP behind it is the opposite of reckless disregard.
  • Use a POA&M, not a fiction. Open controls go into a Plan of Action and Milestones (POA&M), a tracked list of gaps with owners and target dates. A POA&M is a recognized, legitimate instrument. It lets you post a lower-but-true score and show the government a credible path to closing the gap. A POA&M is honest where an inflated score is fraud.
  • Date it and refresh it. SPRS scores carry a date, and as of July 2026 Level 2 runs on a self-assessment every three years with an annual affirmation in the years between. A stale score performed three years ago against an environment that has since changed is its own false-affirmation risk, and each affirmation you sign in the meantime inherits it. Re-assess when your systems change, not when the calendar reminds you.

The number that survives scrutiny is the one you can defend line by line when an assessor, the DOJ, or a former employee asks how you got it.

The bottom line

Your SPRS score is a representation to the federal government, and a knowingly inflated one converts a cybersecurity gap into False Claims Act liability that the DOJ's Civil Cyber-Fraud Initiative and private whistleblowers can pursue. With CMMC Phase II suspended as of July 2026, that self-assessed number carries the verification weight on its own. The defense is not a higher number. It is an accurate score, a written System Security Plan, and a POA&M that shows real progress on the controls you have not finished. Score it the way a buyer scores a part: on what is actually there, documented well enough to defend.

Sources

  • 31 U.S.C. ยง 3729, False claims. The liability provisions quoted here: knowingly presenting a false claim, or using a false record or statement material to one; treble damages plus a per-claim civil penalty; and the definition of "knowingly" as actual knowledge, deliberate ignorance, or reckless disregard, requiring no proof of specific intent to defraud. Text in effect July 15, 2026.
  • 31 U.S.C. ยง 3730, Civil actions for false claims. The two paths described here: the Attorney General's own action, and the qui tam provision letting a private relator sue on the government's behalf and take 15 to 25 percent of the proceeds when the government joins, or 25 to 30 percent when it does not. Subsection (h) is the anti-retaliation protection that makes an insider relator viable.
  • DOJ, Civil Cyber-Fraud Initiative announcement. The initiative's own stated scope, which is where this article's description comes from: holding accountable those who knowingly misrepresent their cybersecurity practices or protocols, or knowingly violate obligations to monitor and report incidents. Archived DOJ press release, October 6, 2021.
  • DOJ, Alabama defense contractor pays $507,144 to resolve False Claims Act cybersecurity liability. The June 18, 2026 LOGZONE settlement. This is the scenario in the section above, already real: a government assessment by DCMA found the true implementation, scoring the contractor at negative 170 against a possible range of negative 203 to 110, and the gap became a False Claims Act case.
  • DOJ, Raytheon and Nightwing pay $8.4M over cybersecurity requirements. The May 1, 2025 settlement, which turned in part on a failure to develop and implement a system security plan under DFARS 252.204-7012. The whistleblower was a former Director of Engineering at the company and received $1,512,000 of the settlement, which is the insider-relator pattern described above.
  • DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements. The requirement to hold a current assessment, not more than three years old, to be considered for award, and to verify the score is posted in SPRS. Retrieved July 16, 2026.
  • DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements. The government's access to your systems, the SPRS posting procedure, and the rule that a prime may not award a covered subcontract unless the subcontractor has completed a Basic assessment within the last three years. Its accessibility paragraph is also the reason this article says the score is visible to the government rather than to primes: posted scores are available to DoD personnel and to the assessed contractor's own representatives. Retrieved July 16, 2026.
  • NIST SP 800-171 DoD Assessment Methodology, Version 1.2.1. The methodology named in this article: a score of 110 when every requirement is implemented, the value of each unmet requirement subtracted from 110, and a result that may be negative.
  • 32 CFR 170.24, CMMC Scoring Methodology. The codified version of the same scoring, including the 5, 3, and 1 point deductions, and the rule that an assessment cannot be completed without a current System Security Plan.
  • DoD CIO, About CMMC. The July 13, 2026 suspension of Phase II, the Phase 1 pause, Level 2 as a self-assessment every three years with annual affirmation against the 110 requirements in NIST SP 800-171 Revision 2, and the enforcement of Revision 2 during the review through self-assessments and select government-led assessments. Retrieved July 16, 2026.
  • DFARS 252.204-7021, Contractor Compliance With the CMMC Level Requirements. The clause that carries the CMMC requirement into contracts and onto subcontractors. Retrieved July 16, 2026.