Under CMMC, a senior company official must affirm the assessment, and a false affirmation can expose that person and the company to False Claims Act (FCA) liability, including treble damages and per-claim penalties. The affirmation is not a formality. It is a signed attestation, tied to federal contract eligibility, that the organization meets the practices it claims to meet. This post explains what the affirming official is actually signing and how to keep that signature defensible.
What the affirming official signs
CMMC requires a senior official to affirm, in the Supplier Performance Risk System (SPRS), that the organization has implemented and is maintaining the required practices. That affirmation is a representation to the government. When a contractor certifies compliance to win or keep a contract, and that certification is false, the government's theory is straightforward: it paid for security it did not receive.
Why the False Claims Act applies
The Department of Justice's Civil Cyber-Fraud Initiative, launched in 2021, applies the False Claims Act (31 U.S.C. 3729) to cybersecurity misrepresentations. It has already produced settlements, several triggered by qui tam whistleblower suits filed by employees who knew the controls were not really in place. The FCA allows treble damages and per-claim penalties, and it permits naming the individuals who knowingly caused the false claim, not only the company.
What actually triggers liability
Liability is about knowing misrepresentation, not honest gaps. The risk concentrates in a few places:
- Marking a practice met when the evidence does not support it.
- Affirming continued compliance while a control has quietly lapsed.
- Treating an enduring exception or a legacy OT device that cannot meet a practice as if it were fully compliant, instead of documenting the gap and the compensating control.
The affirming official who signs without reviewing the underlying evidence is the person most exposed.
How to keep the affirmation defensible
Affirm only what you can prove. In practice that means:
- Evidence per control. Every affirmed practice should have an audit trail showing it operating as claimed. Tamper-evident logs of access, authentication, and configuration make the difference between an assertion and a fact.
- Honest exceptions. Where a legacy asset cannot meet a practice as written, document the enduring exception and the compensating control. See our guide on the enduring exception for OT.
- Review before signing. The affirming official should see the evidence, not just the summary.
Trout's Access Gate is built to produce exactly this kind of evidence: identity-bound access and tamper-evident audit for the OT and legacy assets that are hardest to prove. The point is not to help you affirm more; it is to make sure everything you affirm is true.
This article is general information, not legal advice. Consult counsel on your specific False Claims Act exposure.