One of the most closely watched Civil Cyber-Fraud Initiative cases — the one the government actually chose to litigate — has resolved. The settlement is a case study in what a false cybersecurity score really costs.
Georgia Tech Research Corporation (GTRC) agreed to pay the United States $875,000 to resolve allegations that it failed to meet cybersecurity requirements on certain Air Force and DARPA contracts. The Justice Department announced the resolution (Press Release No. 25-1012) on September 30, 2025, closing a matter it had been litigating since intervening the year before. (The claims resolved are allegations only, and there has been no determination of liability.)
We covered the government's decision to file suit when it happened. This is how that fight ended — and the resolution is worth studying precisely because the government took this one to litigation rather than settling quietly at the outset.
What the Government Alleged
The case, captioned United States ex rel. Craig v. Georgia Tech Research Corporation et al., No. 1:22-cv-02698 (N.D. Ga.), centered on research performed at Georgia Tech's Astrolavos Lab, which conducted sensitive cyber-defense work for DoD. The Justice Department alleged three failures:
First, until December 2021, the entities failed to install, update, or run anti-virus or anti-malware tools on desktops, laptops, servers, and networks at the lab. Second, until at least February 2020, there was no system security plan for the lab setting out the cybersecurity controls the contracts required.
Third — and most striking — in December 2020 GTRC and Georgia Tech submitted a false summary-level cybersecurity assessment score of 98 that supposedly applied campus-wide. The government alleged that score was false for two reasons: there was no campus-wide IT system at Georgia Tech, and the score was premised on a "fictitious" or "virtual" environment that did not correspond to any actual covered contracting system that would process, store, or transmit covered defense information. The submission of a cybersecurity assessment score, the government alleged, was a condition of contract award.
Why a "Fictitious" Score Is the Whole Point
A summary-level self-assessment score is meant to describe a real environment — the systems that actually touch covered defense information. Georgia Tech's alleged error was reporting a number for a network that did not exist as scored. That is a different problem than the inflated-but-real scores at issue in settlements like the $507K LOGZONE matter: here the government's theory was that the assessed environment itself was invented.
For contractors, the takeaway is that a cybersecurity score is a representation about specific covered systems, not a campus-wide or enterprise-wide talking point. A high score attached to a "virtual" or aspirational environment does not satisfy the requirement — it can become the misrepresentation that supports False Claims Act liability every time it conditions an award.
"Those who knowingly provide deficient cybersecurity products or services, misrepresent their cybersecurity practices or protocols, or violate obligations to monitor and report cybersecurity incidents and breaches must be held accountable," said Stacy Bostjanick, Chief of Defense Industrial Base Cybersecurity in the DoD CIO's office. The whistleblowers, Christopher Craig and Kyle Koza — former members of Georgia Tech's own cybersecurity team — will receive $201,250.
Why This Resolution Matters
Most Civil Cyber-Fraud Initiative cases settle before the government commits to litigation. Georgia Tech was different: the United States intervened, filed its own complaint in August 2024, and pursued the case through a research university with substantial resources to fight back. The $875,000 resolution signals that the government is willing to litigate cybersecurity-representation cases to conclusion, not just accept early settlements — and that even sophisticated, well-resourced institutions are not immune when the underlying compliance is missing.
The conduct at issue was foundational: anti-malware tools, a system security plan, and an honest self-assessment. These are the same NIST SP 800-171 fundamentals that anchor CMMC Level 2. As third-party assessment ramps up, the distance between a reported score and a verifiable one is exactly what the government keeps finding.
What Contractors Should Do Now
- Score the systems you actually have. A self-assessment must describe the real environment that processes, stores, or transmits covered defense information — not a virtual, planned, or campus-wide abstraction.
- Put the basics in place first. Anti-malware, a current system security plan, and documented controls are table stakes; their absence drove this case.
- Treat the score as a representation. Submitting an assessment score is often a condition of award; under the FCA, a false one can carry treble damages plus penalties.
- Assume verification is coming. If a DCMA or C3PAO assessment would not confirm your posted score today, close the gap before someone else finds it.
Key Takeaways
- Georgia Tech Research Corporation will pay $875,000 to resolve FCA allegations tied to missing anti-malware protection, no system security plan, and a false campus-wide cybersecurity score of 98.
- The government alleged the score reflected a "fictitious" or "virtual" environment rather than any real covered system — the core of the misrepresentation.
- The case is notable as one the government chose to litigate, signaling willingness to pursue cybersecurity-representation cases to resolution even against well-resourced institutions.
For the fundamentals behind an honest self-assessment, see how the SPRS score works and what a system security plan must contain; track the broader trend at Enforcement & Penalties.