A precision machine shop that never signed a Defense Department contract still paid to resolve cyber-fraud allegations. The reason is the same word that trips up so many suppliers: flowdown.
Swiss Automation Inc., an Illinois precision machining company, agreed to pay $421,234 to resolve False Claims Act allegations that it failed to adequately safeguard technical drawings it machined and supplied to Department of Defense prime contractors. The Justice Department announced the settlement (Press Release No. 25-1140) on December 5, 2025. (The claims resolved are allegations only; there has been no determination of liability.)
Swiss Automation makes alloy and metal parts for commercial and government customers across many industries. It is not a household defense name — it is exactly the kind of small supplier that sits three or four tiers down a defense supply chain. That is what makes the case worth reading.
What the Government Alleged
According to the Justice Department, Swiss Automation caused the submission of false claims by failing to provide adequate cybersecurity for certain drawings of parts it machined and supplied to DoD prime contractors. The critical allegation is one of knowledge: the government said Swiss Automation knew the requirement to implement certain cybersecurity controls applied not only to prime contractors but also to the subcontractors and suppliers beneath them.
That obligation is not new. As the Department noted, the requirement to implement the controls in NIST Special Publication 800-171, which protects certain DoD information, has applied to DoD contracts, subcontracts, and similar instruments since 2017 — and continues under the Cybersecurity Maturity Model Certification (CMMC) program.
The case was filed under the whistleblower provisions of the False Claims Act. It is captioned United States ex rel. Gomez v. Swiss Automation Inc., No. 1:22-cv-4328 (N.D. Ill.). The relator, Jaime Gomez, a former quality-control manager at the company, will receive $65,291 of the recovery.
Why "Supplier" Is Not a Safe Harbor
Many small manufacturers assume the cybersecurity clauses in a defense contract are the prime's problem. The Swiss Automation settlement is a clean rebuttal. DFARS 252.204-7012 requires the prime to flow the safeguarding and incident-reporting requirements down to subcontractors and suppliers whose work involves covered defense information — and machine drawings of defense parts are exactly that kind of covered technical information.
Once a requirement flows down and a supplier accepts the work, the supplier owns the obligation. It does not matter that the machine shop never negotiated directly with a contracting officer. When it invoices a prime that is, in turn, being paid by DoD, an inadequate cybersecurity posture can taint the entire chain of claims for payment — which is how a supplier with no direct government contract ends up resolving a False Claims Act case.
"As cyber threats continue to evolve, suppliers to defense contractors must be vigilant and take the steps required to protect sensitive government information," said Assistant Attorney General Brett A. Shumate of the Civil Division. The Defense Criminal Investigative Service and Army Criminal Investigation Division assisted the investigation — a reminder that suppliers are squarely inside the enforcement lens, not outside it.
The Pattern for Small Manufacturers
This resolution sits alongside a growing run of Civil Cyber-Fraud Initiative cases, but it targets a different layer of the market. Where settlements like the $507K LOGZONE matter and MORSECORP involved contractors reporting inflated SPRS scores, Swiss Automation is about a supplier's underlying failure to protect the technical data in its shop. Both roads lead to the same place. For the sub-tier, the message is that accepting defense work means accepting the cyber terms attached to it.
What Suppliers Should Do Now
- Assume the clauses flow to you. If your purchase order or subcontract references DFARS 252.204-7012 or NIST SP 800-171, the safeguarding and reporting duties are yours — read the flowdown language, do not skim past it.
- Protect technical data like the covered information it is. Drawings, specs, and models of defense parts are covered defense information; segment and secure the systems that hold them.
- Ask the prime what you are receiving. If you handle covered defense information, you should have a system security plan and be prepared to report a cyber incident within the required window.
- Do not treat "we're just a supplier" as a defense. It was not one here.
Key Takeaways
- Swiss Automation Inc. will pay $421,234 to resolve FCA allegations it failed to adequately safeguard defense-part drawings supplied to DoD primes — despite holding no direct DoD contract.
- The government alleged the company knew NIST SP 800-171 obligations flow down to subcontractors and suppliers, not just primes.
- Cybersecurity flowdown reaches the bottom of the supply chain; a supplier that accepts covered defense work accepts the cyber terms that come with it.
To understand how these obligations move down the supply chain, read our explainer on cybersecurity flowdown from prime to subcontractor; manufacturers can map their own duties with Find My Requirements and see the wider picture at Enforcement & Penalties.