When contractors think about cyber-related False Claims Act risk, they picture a failed NIST 800-171 score. There is a second vector that gets less attention and is just as expensive: billing the government for cybersecurity services you were never qualified — or authorized — to sell.
Most of the cyber-fraud enforcement you read about is a safeguarding story: a contractor certified it had implemented controls it hadn't, and the government treated that false representation as a False Claims Act (FCA) violation. But cybersecurity compliance is not only about protecting data. It is also about representing accurately what you are qualified and authorized to do. Selling cyber services outside the scope of your contract vehicle — or claiming a qualification you never earned — is its own path to FCA liability, and it does not require a single mishandled piece of Controlled Unclassified Information.
What Happened in the Hill ASC Settlement
On July 14, 2025, the Department of Justice announced that Hill ASC Inc., doing business as Hill Associates, of Rockville, Maryland, agreed to pay at least $14.75 million to resolve FCA allegations tied to a General Services Administration (GSA) Multiple Award Schedule (MAS) contract for information technology services. From 2018 to 2023, Hill sold IT services to federal agencies through that Schedule.
Two of the resolved allegations are cybersecurity-scope failures worth studying:
- Selling cyber services it wasn't qualified to sell. GSA required contractors to pass a technical evaluation before they could offer highly adaptive cybersecurity services to government customers through the Schedule. According to DOJ, Hill had not passed that evaluation — yet it submitted claims for those cybersecurity services anyway, along with other services outside the scope of its MAS contract.
- Billing unqualified labor. DOJ also alleged Hill billed agencies for IT personnel who did not have the experience or education the contract required for the labor categories charged.
The government based the settlement amount on the company's ability to pay, with additional amounts owed if certain financial contingencies occur. (A settlement is not an admission of liability; the claims resolved are allegations only, and there was no determination of liability.)
Why This Is a Distinct Compliance Risk
The safeguarding cases — the SPRS-score and NIST 800-171 settlements this blog has covered, from LOGZONE forward — turn on whether you implemented the controls you said you did. The Hill ASC theory is different: it turns on whether you were authorized and qualified to sell what you billed for.
GSA's cybersecurity offerings sit behind qualification gates for a reason. Highly Adaptive Cybersecurity Services — penetration testing, incident response, risk and vulnerability assessment, and cyber hunt work — carry a technical evaluation precisely because the government is buying assurance that the vendor can actually do the work. When a contractor bills for that category without clearing the gate, every invoice can be recast as a false claim, and the "scope" defense collapses because the services were never within the awarded vehicle.
The labor-qualification piece is the same idea in a different suit: a labor-category rate represents that the person doing the work meets defined education and experience minimums. Charging a senior cyber rate for staff who don't meet the category is a misrepresentation the government pays for — and can later claw back with treble damages and penalties.
What Contractors Should Actually Do
- Map every service you bill to a specific, awarded scope. Before selling cybersecurity work through a Schedule, confirm the exact Special Item Number or category is on your contract and that you cleared any required technical evaluation. If it isn't awarded, don't bill it — modify the vehicle first.
- Enforce labor-category discipline. Keep resumes, certifications, and education records that substantiate every labor category you invoice, and audit staffing against the category minimums before the work is billed, not after a subpoena.
- Treat "cyber services" claims as representations, not marketing. Capability statements, quotes, and invoices that assert a cybersecurity qualification are representations the government relies on — the same posture that drives enforcement risk across the cyber-fraud landscape.
- Push the same rigor down your supply chain. If a subcontractor performs the cyber work you bill, their qualification gaps become your exposure — the flow-down logic that governs safeguarding obligations applies to qualification representations too.
Key Takeaways
- FCA cyber risk has two lanes: failing to implement the security you certified (SPRS/NIST 800-171 cases) and misrepresenting your authorization or qualification to sell cyber services (the Hill ASC theory). Both cost real money.
- Schedule scope is a compliance control. Selling cybersecurity services you weren't evaluated or awarded to provide — or billing labor categories your staff don't meet — turns each invoice into a potential false claim.
- Substantiate before you bill. Confirm the awarded scope, keep the qualification evidence, and modify the vehicle rather than billing outside it.
Pin down exactly which cybersecurity obligations attach to your contracts with Find My Requirements, see how the standards stack up on Frameworks, and review enforcement exposure on Enforcement & Penalties.
This article is educational information about government-contractor cybersecurity compliance, not legal advice.