Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →On September 30, 2025, Georgia Tech Research Corporation (GTRC), the nonprofit affiliate that contracts with federal agencies for research performed at Georgia Tech, agreed to pay $875,000 to resolve U.S. Department of Justice allegations involving certain Air Force and DARPA contracts at the university’s Astrolavos Lab. DOJ alleged deficiencies in a required System Security Plan, antivirus and anti-malware protections, and a Defense Department cybersecurity self-assessment score reported as 98. The settlement contains no admission of liability and is not a judicial finding that the allegations were true.
The settlement in brief
| Item | What the public record says |
|---|---|
| Settling entity | Georgia Tech Research Corporation, Georgia Tech’s contracting affiliate |
| University and worksite | Georgia Institute of Technology; Astrolavos Lab |
| Contracts | Certain Air Force and DARPA contracts |
| Settlement date and amount | September 30, 2025; $875,000 |
| Legal theories | False Claims Act and federal common law |
| Posture | Allegations resolved by settlement; no determination of liability |
DOJ’s announcement identifies GTRC as the affiliate that contracts with government agencies for research carried out at Georgia Tech. The dispute involved work at Astrolavos Lab, which conducts sensitive cyber-defense research for the Department of Defense. The allegations were directed at covered systems and contracts associated with that lab—not every Georgia Tech network or all university research.
Georgia Tech denied that the government’s allegations accurately characterized its cybersecurity commitment, and the parties resolved the matter without an admission of liability. DOJ’s settlement release expressly says the claims were allegations only.
What DOJ alleged
A missing or inadequate System Security Plan
According to DOJ’s complaint, Astrolavos Lab had not developed and implemented a required System Security Plan (SSP) by at least May 2019. The government alleged that a plan put in place in February 2020 was improperly scoped and was not adequately maintained or updated. An SSP is intended to identify the systems in scope and explain how required security controls are implemented, rather than serve as a generic description of an institution’s overall security program.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Antivirus and anti-malware controls
DOJ alleged that, from at least 2019 through December 2021, relevant desktops, laptops, servers and networks lacked properly installed, updated or operating antivirus or anti-malware tools. The complaint also alleged that Georgia Tech approved a decision not to install antivirus software to accommodate demands attributed to the lab director. That governance allegation has not been adjudicated; it is the government’s characterization of events.
The reported score of 98
DOJ alleged that Georgia Tech and GTRC submitted a summary-level DoD cybersecurity assessment score of 98 in December 2020. The government said the score was misleading because it was based on a “fictitious” or “virtual” environment rather than an actual covered contracting system capable of processing, storing or transmitting covered defense information. DOJ further alleged that an appropriate score was a condition of contract award.
The significance of 98 is therefore not simply that it was a high number. The disputed issue was whether the score accurately represented the bounded systems used for the contracts. A broad enterprise score is not automatically invalid; DOJ alleged that this particular score did not correspond to the actual covered environment.
Rules and standards behind the allegations
The contracts implicated requirements associated with NIST Special Publication 800-171, which sets security requirements for protecting controlled defense information in nonfederal systems. DOJ said the obligation to implement NIST SP 800-171 controls for certain DoD contracts, subcontracts and similar instruments had applied since 2017.
Recommended Free Tools
Rank #3
The complaint also cited Defense Federal Acquisition Regulation Supplement (DFARS) provisions concerning security controls, system security plans, antivirus and incident-detection software, and DoD assessment scores. The exact obligations depend on the contract and its incorporated clauses; the case does not establish that every requirement applied identically to every Georgia Tech activity.
DOJ referenced the subsequently finalized Cybersecurity Maturity Model Certification (CMMC) program as part of the continuing DoD compliance environment. CMMC did not cause this settlement: the alleged conduct occurred mainly from 2019 through 2021, before final CMMC implementation. The reference signals that DoD assessment and evidence expectations are continuing to strengthen.
Rank #4
Why the False Claims Act was involved
This was not presented as a case about poor security in the abstract. DOJ’s theory was that cybersecurity duties were contractual conditions connected to eligibility for award or payment, and that the entities nevertheless made claims or representations while materially failing to meet those duties.
Under the False Claims Act (FCA), knowingly submitting a false claim or making a materially false statement tied to government money can create civil liability. The statute also allows a private person to file a qui tam action on the government’s behalf and receive a share of a recovery. FCA cases can expose a defendant to treble damages and civil penalties, although this matter ended in a negotiated settlement rather than a merits judgment. DOJ described the case as also involving federal common-law theories.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
How the case reached the 2025 resolution
| Date | Event |
|---|---|
| May 2019 | DOJ later alleged that the lab lacked a required SSP by at least this point. |
| August 2019 or earlier | The complaint alleged that implementation of required controls had begun but remained deficient. |
| February 2020 | An SSP was allegedly implemented, but DOJ said it was improperly scoped and not properly maintained. |
| December 2020 | Georgia Tech and GTRC allegedly submitted the summary-level score of 98. |
| July 8, 2022 | Former Georgia Tech cybersecurity-team members Christopher Craig and Kyle Koza filed a qui tam action. |
| February 19–20, 2024 | The United States intervened. |
| August 22, 2024 | DOJ filed its complaint-in-intervention. |
| September 30, 2025 | GTRC agreed to pay $875,000 to resolve the allegations. |
The relators received $201,250 from the recovery. That is approximately 23% of $875,000, a simple calculation rather than a percentage separately stated in DOJ’s announcement.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the settlement does not establish
- It does not establish that Georgia Tech or GTRC is legally liable; there was no trial finding and no admission of liability.
- It does not announce a confirmed data breach, exfiltration or compromise of defense information. DOJ’s case centered on alleged control deficiencies, contractual noncompliance and inaccurate representations.
- It does not show that every Georgia Tech system or research project was out of compliance.
- It does not make every high-level cybersecurity score impermissible. The allegation concerned whether this score represented the actual covered contracting environment.
- It does not mean CMMC was the legal basis for the historic conduct; CMMC was discussed as a later, continuing compliance framework.
Why universities and research institutions should pay attention
Research organizations often divide responsibility among a university, an affiliated contracting corporation, central IT, principal investigators and specialized laboratories. That structure can obscure who owns an SSP, who approves exceptions and which systems are actually in scope. The Georgia Tech allegations show how a contracting affiliate can face FCA exposure for representations tied to work performed inside a university lab.
The governance allegation about accommodating a prominent researcher is especially instructive, while still unproven. Contractual security controls cannot depend on informal exceptions for influential investigators or technically inconvenient projects. A documented, authorized and contractually permissible exception process is materially different from an unrecorded override.
Practical checklist for DoD contractors
Organizations pursuing DoD work can use the allegations as a focused compliance review:
- Define the boundary. Identify every workstation, server, network component, cloud service and subcontractor connection that handles covered defense information.
- Map the SSP to reality. Confirm that the System Security Plan names the actual in-scope environment and is reviewed and updated when systems or contracts change.
- Verify controls technically. Check that antivirus, anti-malware, logging and incident-detection tools are installed, operating, updated and producing evidence.
- Support every assessment score. Retain the inventories, test results, findings and remediation records that substantiate a DoD score.
- Control exceptions. Require written approval, a defined owner, an expiration date and a determination that the exception is allowed by the contract.
- Align representations and invoices. Review certifications, invoices and other submissions for accuracy when compliance is a condition of award or payment.
- Include affiliates and researchers. Give the contracting entity, university leadership, principal investigators and subcontractors clear responsibilities and escalation paths.
- Preserve evidence. Keep versioned SSPs, configuration records, security-tool reports and assessment workpapers so the organization can demonstrate what it represented and when.
Bottom line
The $875,000 GTRC settlement illustrates why federal cybersecurity enforcement focuses on the connection between technical controls and contractual representations. For universities and contractors, an assessment score must describe a real, properly scoped environment, and security exceptions must be governed with the same rigor as the underlying DoD contract. The Georgia Tech matter resolved allegations only; its practical warning is that inaccurate or weakly supported cybersecurity representations can become a False Claims Act issue even when no breach has been announced.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




