enforcementjudicialNewsThe Broadside1 min read

Sierra Nevada Company to Pay $7.75M in FCA Cyber Settlement

The latest Civil Cyber-Fraud Initiative enforcement shows DOJ doesn't need a breach to extract millions. A false cybersecurity attestation is treated like a padded invoice.


TL;DR

Sierra Nevada Company has agreed to pay $7.75 million to resolve False Claims Act allegations that it submitted false claims regarding its cybersecurity compliance in federal contract submissions, the U.S. Attorney's Office for the Eastern District of Virginia announced. The settlement fits a now-familiar Civil Cyber-Fraud Initiative pattern, joining ATI-Gallant, MORSECORP, and Raytheon/Nightwing, in which DOJ has extracted millions without alleging any data breach or system compromise. The false attestation alone was the claim.

Sierra Nevada Company to Pay $7.75M in FCA Cyber Settlement
Editorial illustration · drawn by The Broadside

The Sierra Nevada settlement is the latest in an accelerating Civil Cyber-Fraud Initiative docket. Since the initiative launched in October 2021, DOJ has pursued contractors who attested to cybersecurity compliance they hadn't achieved. It hasn't needed to prove a breach or a system compromise to do it. The false statement in the contract submission is the claim.

Three earlier settlements define the enforcement template. In March 2025, MORSECORP Inc. agreed to pay $4.6 million and admitted it hadn't fully implemented NIST SP 800-171 controls across multiple Army and Air Force contracts, including controls whose absence "could lead to significant exploitation of the network or exfiltration of controlled defense information" [2]. The same month, ATI-Gallant settled over DFARS 252.204-7012 violations involving an information system that held CUI; the government noted ATI had "promptly implemented mechanisms to remediate" after self-disclosing [1]. In May, Raytheon and Nightwing paid $8.4 million to resolve allegations spanning 2015 to 2021. The conduct predated Nightwing's acquisition of the business but followed it anyway [3].

Each of these settlements shares a structure that should concentrate the attention of every compliance director reading this. The government treated the cybersecurity attestation as a claim for payment under the False Claims Act. Nobody had to prove a foreign adversary walked off with technical data. The gap between what the contractor certified and what it had implemented was sufficient.

For primes and subcontractors, the arithmetic is straightforward. Every cybersecurity representation in a contract submission now carries FCA exposure. Self-disclose and cooperate, and the settlement reflects it. Stay silent about known gaps and hope the contracting officer doesn't ask. The MORSECORP and Raytheon settlements suggest that's an increasingly expensive bet.


Published ·Deep Fathom

Sierra Nevada Company to Pay $7.75M in FCA Cyber Settlement — The Broadside