Skip to main content
Case Law

Penn State's $1.25M Settlement: When the POA&M Dates You Promised Become the Fraud You Pay For

Penn State agreed to pay $1.25 million to resolve False Claims Act allegations across fifteen DoD and NASA contracts — but the core theory was not a false cybersecurity score. It was allegedly false POA&M milestone dates: promising when gaps would be fixed and then not doing the work. Here is why an unworked plan of action, and an unvetted cloud, are each independent FCA exposure.

Brandon Hancock, J.D., CMMC-RPPublished August 7, 2026Updated August 7, 20266 min read

A major research university reported cybersecurity scores that were honest about the gaps — then allegedly lied about when it would close them. That second part is the whole case.

The Pennsylvania State University agreed to pay $1,250,000 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements across fifteen contracts or subcontracts involving the Department of Defense and NASA. The Justice Department announced the settlement (Press Release No. 24-1338) on October 22, 2024. (The claims resolved are allegations only; there has been no determination of liability.)

Penn State's Applied Research Laboratory does sensitive work for the Department of Defense. The allegations here are worth studying not because a university got a low score — but because of what the government says the university promised about fixing it.

What the Government Alleged

According to the Justice Department, between 2018 and 2023 Penn State failed to implement cybersecurity controls that DoD and NASA contractually required, and did not adequately develop and implement plans of action to correct the deficiencies it had already identified.

DoD requires contractors to submit summary-level scores reflecting their compliance with the controls in NIST Special Publication 800-171 on the systems that store or access covered defense information. The government's core allegation is subtle: Penn State's submitted scores accurately reflected that certain controls were not implemented — but the university allegedly misrepresented the dates by which it would implement them and then did not pursue the plans of action to actually do so. The government also alleged that on certain contracts, Penn State used an external cloud service provider that did not meet DoD's security requirements for covered defense information.

The case was filed under the whistleblower provisions of the False Claims Act. It is captioned United States ex rel. Decker v. The Pennsylvania State University, No. 2:22-cv-03895 (E.D. Pa.). The relator, Matthew Decker — the former chief information officer for Penn State's Applied Research Laboratory — will receive $250,000 of the recovery.

The POA&M Is a Promise, Not a Parking Lot

Most contractors understand that a NIST SP 800-171 self-assessment rarely lands at a perfect score. That is expected — which is why the framework allows a Plan of Action and Milestones (POA&M): a documented commitment to close identified gaps by specific dates. Reporting an imperfect score is not, by itself, fraud.

What Penn State allegedly did was treat the milestone dates as decoration. The government's theory is that the remediation dates it certified were misrepresentations, and the plans behind them were never pursued. That converts an honest low score into a false statement — because the representation the government relied on was not just "here is our score," but "here is our score and here is when we will fix it."

For contractors, this is the sharp edge of the case. A POA&M that no one works is worse than no POA&M at all: it is a written promise you can be held to. If you report a target date of Q3 and Q3 comes and goes with no action, you have created exactly the kind of documented misrepresentation that anchors a False Claims Act theory. Compare the $875K Georgia Tech resolution, where the alleged problem was a score for a "fictitious" network — here the score was real, but the remediation commitment allegedly was not.

The Cloud Piece Matters Too

The second allegation — using an external cloud service provider that did not meet DoD's requirements for covered defense information — is a recurring blind spot. DFARS 252.204-7012 imposes specific conditions on cloud services that store, process, or transmit covered defense information, including FedRAMP-Moderate-equivalent security and rapid incident-reporting cooperation. Standing up covered work in a commercial cloud that has not been vetted against those requirements is its own compliance gap, independent of your SPRS score.

"Universities that receive federal funding must take their cybersecurity obligations seriously," said Principal Deputy Assistant Attorney General Brian M. Boynton, head of the Justice Department's Civil Division. The investigation drew in the Naval Criminal Investigative Service, NASA-OIG, the Defense Criminal Investigative Service, Army Criminal Investigation Division, and the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) — the same DIBCAC that verifies contractor scores.

What Contractors Should Do Now

  • Work your POA&M, and date it honestly. Every milestone date you submit is a representation. If you cannot commit to a date, do not certify one you will not meet.
  • Close the loop on identified gaps. Identifying a deficiency and then ignoring it is worse than never scoring it — the government reads inaction against a documented plan as a misrepresentation.
  • Vet your cloud before covered data lands in it. Confirm any external cloud service provider meets DFARS 252.204-7012's requirements for covered defense information before you use it.
  • Assume DIBCAC verification. The same assessment center that assisted this case can confirm whether your posted score and remediation progress are real.

Key Takeaways

  • Penn State will pay $1.25 million to resolve FCA allegations spanning fifteen DoD and NASA contracts — built on unmet controls, hollow remediation promises, and a non-compliant cloud environment.
  • The central theory was not a false score but false milestone dates: reporting when gaps would be fixed and then not pursuing the plans of action.
  • A POA&M is an enforceable representation; an unworked plan and an unvetted cloud are each independent False Claims Act exposure.

For the mechanics behind these obligations, see how the SPRS score and DFARS 7019/7020 work and what the POA&M process actually requires; map your own duties with Find My Requirements and track the trend at Enforcement & Penalties.

Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?

Keep reading

Case LawThe Georgia Tech Case Ends at $875K: How a 'Fictitious' Network Resolved a Landmark Cyber-Fraud FightGeorgia Tech Research Corporation will pay $875,000 to resolve one of the few litigated Civil Cyber-Fraud Initiative cases — built on missing anti-malware, no system security plan, and a false campus-wide score of 98 premised on a "fictitious" network. Here's how the landmark fight ended and what it means for contractor self-assessments.August 4, 2026 · 6 min readCase LawA Machine Shop, a $421K Settlement, and Proof That Cyber Rules Reach the Supply Chain's Bottom RungA precision machine shop that never held a direct DoD contract paid $421,234 to resolve cyber-fraud allegations over technical drawings it supplied to defense primes. The Swiss Automation settlement is the clearest recent proof that NIST 800-171 cybersecurity flowdown reaches the bottom of the supply chain.August 4, 2026 · 6 min readCase LawA Missing Cybersecurity Narrative Ended a SEWP VI Bid: The InnoVet ProtestIn InnoVet Technologies, LLC (GAO, June 16, 2026), NASA eliminated a small business from the SEWP VI competition — a 10-year GWAC that ultimately produced 2,115 awards — not because its security was weak, but because its proposals omitted a required narrative describing the offeror's own cybersecurity supply chain risk management. GAO denied the protest. The lesson for contractors: on many federal procurements, the cybersecurity write-up is a pass/fail gate for award eligibility, and a checklist attestation is not a substitute for the narrative the solicitation asks for.July 6, 2026 · 5 min read