Skip to main content
$8.4M Settlement Shows Acquirers Inherit CMMC FailuresDue Diligence
4 min readFor Internal Auditors

$8.4M Settlement Shows Acquirers Inherit CMMC Failures

The Department of Justice settled a CMMC non-compliance case last year for $8.4 million. The notable aspect isn't the penalty size but who paid it: the original contractor, the subsidiary that made false claims, and the company that acquired the subsidiary years later.

If you're evaluating an M&A target in the defense industrial base, this settlement clarifies what successor liability means. The acquiring company shared the penalty for violations that happened before they owned the asset. Due diligence is now your shield against inheriting someone else's False Claims Act exposure.

Successor Liability and CMMC Penalties

The DoJ has established that CMMC compliance failures transfer with ownership. When you acquire a company holding Department of Defense contracts, you also acquire its compliance history. The False Claims Act doesn't reset with ownership changes.

Here's how it works: A contractor subsidiary was required to implement CMMC security controls. They claimed compliance but didn't secure the systems. The subsidiary was later spun off, renamed, reorganized, and acquired. When the violations surfaced, all three entities shared the $8.4 million settlement: the former owners, the subsidiary, and the new owners.

The acquiring company paid for violations that occurred before the acquisition closed. That's successor liability. You get the contracts, the revenue stream, and the liabilities.

Key Findings for Your M&A Strategy

Private equity structures don't shield you from liability. The DoJ pursued a private equity firm when an employee disclosed Controlled Unclassified Information to unauthorized personnel. The firm disclosed the breach and paid the penalty. Controlling stake means controlling responsibility, even if you're structured as an investor.

Each false attestation is a separate claim. CMMC Level 1 requires self-assessment and attestation. If a target company attested compliance monthly for two years while failing to implement required controls, that's 24 potential False Claims Act violations. With penalties exceeding $250,000 per claim, the costs add up quickly.

Awareness triggers liability, not intent. You don't need to commit fraud to face FCA penalties. If you discover non-compliance post-acquisition and fail to disclose it, you've assumed liability for those past claims. The clock starts when you know, not when you acted.

System boundaries shift during integration. Adding your admin roles to the acquired company's systems, sharing access across merged IT environments, or consolidating management chains can expand the scope of what's covered under CMMC. What was compliant as a standalone subsidiary might not be compliant once integrated into your broader infrastructure.

Implications for Your Audit Team

Your pre-acquisition audit checklist just expanded. You're not just validating current compliance status. You're investigating compliance history to quantify inherited FCA exposure.

Understand the target's System Security Plan, not just confirm it exists. What's in scope? What boundaries did they draw? How will those boundaries change when you merge networks, share admin access, or consolidate data centers?

Look for gaps between attestation and implementation. A company can self-attest CMMC Level 1 compliance without third-party validation. That attestation creates FCA liability if the controls weren't implemented. Your job is to verify the controls exist, not just that the paperwork says they do.

If you're already CMMC-certified, use that knowledge. If you're not certified but acquiring a certified company, hire someone who can review the System Security Plan, check the Supplier Performance Risk System data, and audit the actual security controls against the documented claims.

Action Items by Priority

Before you close the deal:

Request copies of all CMMC-related documentation: policies for handling Federal Contract Information and CUI, information security policies, System Security Plans, Plans of Action and Milestones, and incident response reports. These artifacts aren't classified, and a compliant company should be able to produce them.

Audit actual implementation against documented claims. Don't just read the SSP. Verify that the controls listed in the plan are configured in the systems. Check access logs, review Privileged Access Management, validate encryption at rest and in transit.

Map how scoping will change post-acquisition. Will you share Active Directory? Merge cloud tenants? Give your IT team access to their systems? Each integration point potentially expands the CMMC boundary. Understand what that means for your compliance obligations before you inherit them.

If you discover non-compliance post-acquisition:

Disclose voluntarily. The DoJ rewards voluntary disclosure. Whistleblowers are entitled to a portion of FCA settlements to encourage disclosure. If you find a problem and hide it, you're compounding the liability.

Document the gap between attestation and reality. How long did the false claims continue? Which contracts were affected? What CUI or FCI was at risk? You need this detail to assess exposure and support your disclosure.

Remediate immediately. Implement the missing controls, update the System Security Plan to reflect actual scope and boundaries, and document the remediation. Speed matters. The longer non-compliance continues after you're aware of it, the worse your position gets.

Department of Justice FCA settlements

You Might Also Like