Skip to main content
Case Law

The Certifier That Did Not Exist: AiNET, the SEC, and the Cost of a Fabricated Certification

DOJ announced a $1,800,000 False Claims Act settlement with AiNET Corp. and former CEO Deepak Jain over allegations that they certified a data center inspection by an entity the United States alleged was not an operating company and never performed the inspection. The standard at issue was infrastructure resilience, but the legal theory is the same one driving cyber enforcement — and it lands as third-party validation becomes the price of eligibility.

Brandon Hancock, J.D., CMMC-RPPublished August 25, 2026Updated August 25, 20266 min read

On August 24, 2026, the Justice Department announced that AiNET Corp. and its former Chief Executive Officer, Deepak Jain, agreed to pay $1,800,000 to resolve allegations that they violated the False Claims Act by knowingly submitting false claims for data center services under a contract with the U.S. Securities and Exchange Commission. AiNET operates a data center in Beltsville, Maryland. The resolution is worth the attention of any contractor whose award depended on a third-party certification, because of where the alleged fraud sat: not in the technical performance, but in the paperwork attesting to it.

What the Government Alleged

According to the Justice Department, AiNET and Jain fraudulently induced the SEC to enter the contract by falsely certifying that the AiNET data center met at least Tier III standards as defined by the Telecommunications Industry Association (TIA) Standards for Data Centers, TIA 942, as the SEC contract required.

The United States alleged that the data center did not comply with Tier III standards. It further alleged that AiNET and Jain falsely certified to the SEC that experts from an entity called UpTime Council had inspected the facility and determined it to be Tier IV under TIA 942 — and that those certifications were false because UpTime Council was not an operating company and never inspected the AiNET data center.

The matter was handled by the Civil Division's Commercial Litigation Branch, Fraud Section, working with the SEC Office of Inspector General; Senior Trial Attorney Greg Pearson handled the case. (A settlement is not an admission of liability. The Justice Department states that the claims resolved by the settlement are allegations only and that there has been no determination of liability.)

Why an Availability Standard Belongs in a Cybersecurity Conversation

Be precise about what was at issue. TIA 942 tiering addresses data center infrastructure — redundancy, power and cooling paths, concurrent maintainability, fault tolerance. It is not a cybersecurity control catalog like NIST SP 800-171. A contractor reading this case should not conclude that DOJ has announced a new cyber theory.

What transfers is the structure of the allegation, and that structure is identical to the one running through the Civil Cyber-Fraud Initiative's docket. In each instance the government contends the contractor made a representation about a security or resilience posture that the contract made a condition of award or payment, and that the representation did not match reality. Whether the representation is a TIA 942 tier, a Supplier Performance Risk System score, a CMMC certification, or an incident-reporting attestation, the legal exposure runs through the same statute. And availability is not a side issue for a federal agency: a data center hosting regulatory systems is protecting government data, and confidentiality, integrity, and availability travel together.

The Part That Should Make Contractors Uncomfortable

Most compliance failures are failures of execution — a control not implemented, a scan not run, a flaw not remediated on schedule. This case alleges something different: a certification traced to a certifying body the government says was not an operating company.

That distinction matters right now, because the government-contracting market is in the middle of a large migration toward third-party validation as the price of eligibility. CMMC Level 2 certification assessments rest on an accredited C3PAO ecosystem whose capacity constraints GAO has already flagged. FedRAMP authorizations rest on third-party assessment organizations. Agency-specific guides increasingly demand external validation rather than self-attestation.

Every one of those regimes converts a certificate into a condition of eligibility — which means every one of them creates a market for a certificate obtained the fast way. Where demand for validation outruns the supply of legitimate validators, the incentive to produce a document rather than earn one grows. Contractors sit on both sides of that risk: as the party making the representation, and as the party accepting a subcontractor's or vendor's certificate at face value under a flowdown obligation.

What to Do About It

Verify the validator, not just the certificate. Before you rely on a third-party assessment — yours or a supplier's — confirm the assessing organization actually exists, is accredited by the body the requirement names, and performed the work described. For CMMC, that means confirming the C3PAO's authorization status through the accreditation body rather than accepting a logo on a PDF.

Match the certificate to the scope. A certification covering one facility, one enclave, or one system boundary is not a certification of your enterprise. The government's Georgia Tech allegations turned partly on a score premised on an environment that did not correspond to any actual covered contracting system.

Treat every eligibility representation as a claim. If a certification, score, or attestation was a condition of award, the government can treat invoices under that contract as claims tainted by the representation. Build a file that shows who assessed what, when, against which standard, and under whose accreditation. Our compliance checklists and requirement-mapping tool are built to produce exactly that record.

Key Takeaways

  • DOJ alleged the certifying entity itself was fictitious. AiNET Corp. and former CEO Deepak Jain agreed to pay $1,800,000 over allegations that they certified a TIA 942 Tier IV inspection by "UpTime Council," which the United States alleged was not an operating company and never inspected the facility.
  • The standard at issue was infrastructure resilience, but the legal theory is the cyber-enforcement theory. A security or resilience representation that conditions award or payment can support False Claims Act liability regardless of which standard it references.
  • Third-party validation is becoming the price of eligibility — so validate the validator. Confirm accreditation status, scope, and that the assessment actually occurred, for your own certifications and for every certificate you accept from a subcontractor.

GovConCyber publishes educational analysis of government contractor cybersecurity obligations. This article is not legal advice and does not create an attorney-client relationship. For a walkthrough of how enforcement theories map to your contract requirements, see our enforcement overview.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?