What does the DOJ MORSECORP settlement signal contractors must change in cybersecurity compliance?
DOJ's MORSECORP settlement shows contractors need verified NIST SP 800-171 implementation, written plans, vendor oversight, and prompt score correction.
AI-assisted and automatically checked against the linked primary sources.
What compliance changes does the DOJ settlement signal?
What was the central enforcement issue?
Important Note
DOJ highlighted a long delay between learning the NIST SP 800-171 score was wrong and updating the DoD reporting system. Contractors should treat known inaccuracies in cybersecurity reporting as urgent compliance issues.
Process
- 1
Review contract cybersecurity requirements
Confirm the controls, reporting duties, and documentation required by each contract before you certify compliance.
- 2
Check third-party hosting arrangements
Require any outside email or hosting provider to meet equivalent security requirements and DoD incident-reporting, malware, media preservation, and forensic support duties.
- 3
Maintain current documentation and reporting
Keep a consolidated written system security plan and correct any reported cybersecurity score or assessment data as soon as you learn it is inaccurate.
- DOJ used the False Claims Act to enforce contract cybersecurity requirements in the MORSECORP settlement.
- Full implementation of NIST SP 800-171 controls mattered; partial implementation was not enough.
- A consolidated written system security plan was required and missing documentation became part of the alleged noncompliance.
- Third-party email hosting had to meet equivalent security and incident-reporting obligations, and reported scores had to be corrected when known to be wrong.
Sources & Citations
Ready to Win Government Contracts?
Use Gov Contract Finder to discover relevant federal opportunities and prepare stronger bids.
Related Articles
What should contractors verify in “FAR 4.703 Policy”?
A primary-source checklist for reviewing “FAR 4.703 Policy” without relying on unsupported legacy claims.
Read more →How was the legacy question “What AI Governance Rules Should Contractors Expect From Federal Agencies in 2026?” narrowed to official sources?
A primary-source brief that replaces the legacy topic “What AI Governance Rules Should Contractors Expect From Federal Agencies in 2026?” with reachable official references and a conservative verification workflow.
Read more →How was the legacy question “How Should Cloud Vendors Prepare for FedRAMP 20x in 2026?” narrowed to official sources?
A primary-source brief that replaces the legacy topic “How Should Cloud Vendors Prepare for FedRAMP 20x in 2026?” with reachable official references and a conservative verification workflow.
Read more →