TroutTrout
Back to Blog
CMMCCompliance

The Affirming Official's False Claims Act Risk in CMMC

Trout Team3 min read

Under CMMC, a senior company official must affirm the assessment, and a false affirmation can expose that person and the company to False Claims Act (FCA) liability, including treble damages and per-claim penalties. The affirmation is not a formality. It is a signed attestation, tied to federal contract eligibility, that the organization meets the practices it claims to meet. This post explains what the affirming official is actually signing and how to keep that signature defensible.

What the affirming official signs

CMMC requires a senior official to affirm, in the Supplier Performance Risk System (SPRS), that the organization has implemented and is maintaining the required practices. That affirmation is a representation to the government. When a contractor certifies compliance to win or keep a contract, and that certification is false, the government's theory is straightforward: it paid for security it did not receive.

Why the False Claims Act applies

The Department of Justice's Civil Cyber-Fraud Initiative, launched in 2021, applies the False Claims Act (31 U.S.C. 3729) to cybersecurity misrepresentations. It has already produced settlements, several triggered by qui tam whistleblower suits filed by employees who knew the controls were not really in place. The FCA allows treble damages and per-claim penalties, and it permits naming the individuals who knowingly caused the false claim, not only the company.

What actually triggers liability

Liability is about knowing misrepresentation, not honest gaps. The risk concentrates in a few places:

  • Marking a practice met when the evidence does not support it.
  • Affirming continued compliance while a control has quietly lapsed.
  • Treating an enduring exception or a legacy OT device that cannot meet a practice as if it were fully compliant, instead of documenting the gap and the compensating control.

The affirming official who signs without reviewing the underlying evidence is the person most exposed.

How to keep the affirmation defensible

Affirm only what you can prove. In practice that means:

  • Evidence per control. Every affirmed practice should have an audit trail showing it operating as claimed. Tamper-evident logs of access, authentication, and configuration make the difference between an assertion and a fact.
  • Honest exceptions. Where a legacy asset cannot meet a practice as written, document the enduring exception and the compensating control. See our guide on the enduring exception for OT.
  • Review before signing. The affirming official should see the evidence, not just the summary.

Trout's Access Gate is built to produce exactly this kind of evidence: identity-bound access and tamper-evident audit for the OT and legacy assets that are hardest to prove. The point is not to help you affirm more; it is to make sure everything you affirm is true.

This article is general information, not legal advice. Consult counsel on your specific False Claims Act exposure.

FAQ

Frequently Asked Questions

Can the affirming official be personally liable under CMMC?
Potentially. The affirmation is a signed attestation of compliance tied to federal contract eligibility. Under the False Claims Act, individuals who knowingly cause a false claim can be named alongside the company. The False Claims Act permits naming the individuals who knowingly cause a false claim, not only the company, and the DoJ has signaled through its Civil Cyber-Fraud Initiative that cybersecurity misrepresentations are in scope. This is why the affirmation is a personal-risk decision, not a formality.
What is the DoJ Civil Cyber-Fraud Initiative?
Launched in 2021, the Civil Cyber-Fraud Initiative uses the False Claims Act to pursue government contractors that knowingly misrepresent their cybersecurity practices, use deficient controls, or fail to report incidents. Several settlements have already resulted from whistleblower (qui tam) actions brought by employees.
How do you reduce False Claims Act risk in a CMMC affirmation?
Affirm only what you can evidence. Keep tamper-evident records that show each control operating as claimed, document enduring exceptions and compensating controls honestly rather than marking a practice met when it is not, and make sure the affirming official reviews the actual evidence before signing. The goal is that every affirmed control has an audit trail behind it.