Gov Contract Finder LogoGov Contract Finder Logo
  • ⭐
    AI Bidding Assistant
    Analyze RFPs and draft faster
    Apps
    Browser ExtensionMobile App
    Features
    Email AlertsInsights & AnalyticsProcurement Officers
    Overview →
    OverviewBrowser ExtensionMobile AppEmail AlertsInsights & AnalyticsAI Bidding Assistant
  • Pricing
  • Contracts
  • Learn
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentation
    Comparisons
    Compare PlatformsSAM.gov Alternative
    Solutions
    Why Gov Contract FinderFor Small BusinessFor Capture TeamsSupport
    Proof
    Customer StoriesData Coverage
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentationSupportWhy Gov Contract FinderFor Small BusinessCompare Platforms
  • Services
  • Login
  • Schedule Demo
Gov Contract Finder LogoGov Contract Finder Logo
  • Product
  • AI Bidding Assistant
  • Browser Extension
  • Mobile App
  • Email Alerts
  • Insights & Analytics
  • Pricing
  • Knowledge Base
  • Guides
  • Glossary
  • Q&A
  • Documentation
  • Blog
  • For Small Business
  • For Capture Teams
  • Compare Platforms
  • Services
  • Workflow Automation
  • Support
  • Contact Us
© Copyright 2026 Gov Contract Finder.
  • Terms Of Service
  • Privacy Policy
  • Editorial Policy
Home / Resources / Government Oversight
Government Oversight

What does the DOJ MORSECORP settlement signal contractors must change in cybersecurity compliance?

Published March 5, 2026

DOJ's MORSECORP settlement shows contractors need verified NIST SP 800-171 implementation, written plans, vendor oversight, and prompt score correction.

What does the DOJ MORSECORP settlement signal contractors must change in cybersecurity compliance editorial illustration
Gov Contract Finder Editorial Team
•2 min read•Updated August 26, 2026•Information as of August 26, 2026

AI-assisted and automatically checked against the linked primary sources.

Get more Gov Contract Finder updates in Google

Open Google source preferences

What compliance changes does the DOJ settlement signal?

According to the Department of Justice, the MORSECORP settlement shows that contractors should not rely on partial controls or self-reported compliance. DOJ said MORSE agreed to pay $4.6 million to resolve False Claims Act allegations tied to Army and Air Force contracts. The company admitted that, from January 2018 to September 2022, it used a third-party email host without requiring equivalent security and DoD incident-reporting capabilities, and from January 2018 to February 2023 it had not fully implemented all NIST SP 800-171 controls. DOJ also said MORSE lacked a consolidated written system security plan from January 2018 to January 2021 and reported a NIST score of 104 in January 2021 even though a consultant later found the score was -142; MORSE did not update the score until June 2023, after a subpoena. The enforcement signal is direct: contractors need verified control implementation, documented system plans, third-party oversight, and accurate reporting that is corrected promptly when wrong.
[3]

What was the central enforcement issue?

DOJ said MORSE submitted false or fraudulent claims for payment because it knew it had not complied with the cybersecurity requirements in its Army and Air Force contracts.
Sources: [3] Office of Public Affairs | Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations | United States Department of Justice

Important Note

DOJ highlighted a long delay between learning the NIST SP 800-171 score was wrong and updating the DoD reporting system. Contractors should treat known inaccuracies in cybersecurity reporting as urgent compliance issues.

Process

  1. 1
    Review contract cybersecurity requirements

    Confirm the controls, reporting duties, and documentation required by each contract before you certify compliance.

  2. 2
    Check third-party hosting arrangements

    Require any outside email or hosting provider to meet equivalent security requirements and DoD incident-reporting, malware, media preservation, and forensic support duties.

  3. 3
    Maintain current documentation and reporting

    Keep a consolidated written system security plan and correct any reported cybersecurity score or assessment data as soon as you learn it is inaccurate.

  • DOJ used the False Claims Act to enforce contract cybersecurity requirements in the MORSECORP settlement.
  • Full implementation of NIST SP 800-171 controls mattered; partial implementation was not enough.
  • A consolidated written system security plan was required and missing documentation became part of the alleged noncompliance.
  • Third-party email hosting had to meet equivalent security and incident-reporting obligations, and reported scores had to be corrected when known to be wrong.

Sources & Citations

1. Office of Public Affairs | Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations | United States Department of Justice [Link ↗](government site)Accessed 8/26/2026

Tags

#cybersecurity#DFARS#FCA#government-oversight#procurement

Ready to Win Government Contracts?

Use Gov Contract Finder to discover relevant federal opportunities and prepare stronger bids.

Get StartedSchedule Demo

Related Articles

What should contractors verify in “FAR 4.703 Policy”?

A primary-source checklist for reviewing “FAR 4.703 Policy” without relying on unsupported legacy claims.

Read more →

How was the legacy question “What AI Governance Rules Should Contractors Expect From Federal Agencies in 2026?” narrowed to official sources?

A primary-source brief that replaces the legacy topic “What AI Governance Rules Should Contractors Expect From Federal Agencies in 2026?” with reachable official references and a conservative verification workflow.

Read more →

How was the legacy question “How Should Cloud Vendors Prepare for FedRAMP 20x in 2026?” narrowed to official sources?

A primary-source brief that replaces the legacy topic “How Should Cloud Vendors Prepare for FedRAMP 20x in 2026?” with reachable official references and a conservative verification workflow.

Read more →
Next Step

Reconcile your current controls, written plans, third-party arrangements, and reported cybersecurity scores against your contract requirements.