★ Annual Review 2027 tickets now on sale Get your tickets →

News/Compliance & Enforcement/The False Claims Act: Still the Government’s Favorite Hammer
Compliance & Enforcement Brief

The False Claims Act: Still the Government’s Favorite Hammer

This article was researched and written by Ask Pub K, drawing on Pub K's curated library of authoritative GovCon documents. It has been lightly edited by Pub K's editors for accuracy and clarity.

If you’re a federal contractor and you haven’t thought hard about the False Claims Act (FCA) (31 U.S.C. §§ 3729–3733) lately, now’s the time. The FCA remains DOJ’s go-to tool for policing the roughly $700 billion the government spends on contracts every year, and it’s not slowing down. In fact, it’s expanding into new territory, especially cybersecurity.

The basics: The FCA imposes liability—treble damages plus per-claim penalties—on anyone who knowingly submits a false claim for payment to the government, or knowingly makes a false statement material to getting that claim paid. The “knowingly” part covers actual knowledge, reckless disregard, or deliberate ignorance, so “I didn’t know” is a weak defense. The DOJ brings cases directly, or whistleblowers (“relators”) bring qui tam suits and can pocket a healthy cut of any recovery—which is exactly why they keep coming.

Materiality is where the fights happen: A contractor violates the FCA only when it makes a material misrepresentation. Since the Supreme Court’s 2016 Universal Health Services v. Escobar decision, courts have treated materiality as a “demanding” standard — not just a technical violation. A misrepresentation is material if it would (or reasonably could) affect the government’s decision to pay.[1] Suppose the government keeps paying a contractor’s invoices in full even after learning about the alleged violation. That’s strong evidence the requirement wasn’t material after all.[2] On the other hand, when the government stops renewing a contract or intervenes in litigation the moment it learns of a problem, courts read that as evidence the issue was material.[3]

The “implied certification” trap: You don’t need an express, on-the-record certification of compliance to face FCA liability. Escobar confirmed that submitting an invoice while silently violating a material contract requirement can itself be an actionable “misleading” representation, even without checking a false box.[4] That’s a broad net, which is why compliance teams need to consider every representation baked into a claim for payment, not just the ones with a signature line.

Where the action is now: cybersecurity: DOJ’s Civil Cyber-Fraud Initiative is alive and expanding, and a senior DOJ official recently told practitioners that cyber-fraud enforcement is “not about data breaches”—it’s about misrepresentations about compliance with cybersecurity requirements like NIST SP 800-171.[5] Simply put, companies that get hacked despite good-faith compliance aren’t the target; companies that certified security controls they didn’t actually have are. DOJ has already settled cybersecurity FCA cases with defense contractors on exactly that theory.[6]

The bottom line for compliance teams: Every certification, invoice, and progress report is a potential FCA data point. Build a paper trail showing good-faith compliance efforts, train staff on what’s actually being represented when a claim goes out the door, and take internal whistleblower complaints seriously before they become qui tam complaints.


Footnotes

    1. Universal Health Services, Inc. v. United States ex rel. Escobar, 579 U.S. 176 (2016) — materiality is a “demanding” standard under the FCA. ↩
    2. Ninth Circuit Finds Continued Government Payments Show That Alleged False Statements Are Not Material
    3. Fourth Circuit Re-Affirms Sufficiency of Triple Canopy Complaint↩
    4. FCA’s “Implied Certification” Theory Survives ↩
    5. False Claims Act Enforcement: Record-Breaking Year Signals Continued Attention to Cybersecurity↩
    6. Alabama Defense Contractor Agrees to Pay $507,144 to Resolve False Claims Act Liability Relating to Cybersecurity Violations↩

Regulations and enforcement priorities change frequently; this reflects the position as of September 25, 2026. Verify current DOJ guidance and FCA case law before relying on it.

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.