Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Pennsylvania State University agreed on October 22, 2024, to pay $1.25 million to resolve federal allegations that it failed to meet cybersecurity requirements tied to 15 Department of Defense and NASA contracts or subcontracts. The alleged conduct ran from January 2018 through November 2023 and involved NIST security controls, remediation plans, assessment reporting, and a cloud-service requirement.
This was a contract-compliance case, not a government finding that Penn State suffered a confirmed data breach. The settlement resolved allegations without a determination of liability. That distinction matters: contractors can face False Claims Act exposure over allegedly inaccurate cybersecurity representations even when public materials do not establish that an attacker accessed or stole protected information.
What the government alleged
The contracts concerned unclassified information requiring protection as Covered Defense Information (CDI) or Controlled Unclassified Information (CUI). According to the settlement agreement and the U.S. Attorney’s Office announcement, the government alleged that Penn State:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- Did not implement some security requirements in NIST Special Publication 800-171 on systems used for the covered work.
- Did not adequately develop and carry out plans of action and milestones (POA&Ms) to address identified deficiencies.
- Reported information through the Defense Department’s Supplier Performance Risk System (SPRS) that allegedly misstated the dates by which all 110 NIST SP 800-171 Revision 2 requirements would be implemented.
- For certain contracts, used an external cloud service provider that the government alleged did not meet the required FedRAMP Moderate security baseline.
The SPRS allegation was not simply that Penn State disclosed gaps. The government alleged that the implementation timelines were inaccurate and that related remediation plans were not adequately pursued. A low assessment score or candidly reported deficiency is not, by itself, proof of misconduct; the concern is whether a submission and its supporting records accurately reflect the system’s status and credible plans to correct gaps.
#1 Best Overall
The cloud allegation was limited to certain contracts and a particular external provider. The settlement materials do not establish that every Penn State cloud service or system was noncompliant.
Why cybersecurity requirements became a False Claims Act case
The False Claims Act (FCA) allows the government to pursue claims involving knowingly false or fraudulent statements or claims for federal money. In this matter, the government’s theory connected cybersecurity duties to contract performance and federal payment: the contracts incorporated security requirements, and allegedly inaccurate compliance representations or failures to meet those obligations could create FCA exposure.
The case proceeded under the FCA’s qui tam provisions, which allow a private person to bring a case on the government’s behalf. Matthew Decker, the former chief information officer of Penn State’s Applied Research Laboratory, was the relator. He received $250,000 as the whistleblower share of the recovery.
The settlement does not mean a court found that Penn State violated the FCA or that every allegation was proven. Penn State agreed to pay $1.25 million to resolve the government’s allegations; the settlement was not an adjudicated finding of liability.
The standards and contract terms in the dispute
NIST SP 800-171 Revision 2 sets out 110 security requirements for protecting CUI in nonfederal systems and organizations. The settlement agreement identifies several contract provisions relevant to the work, including DFARS 252.204-7012 on safeguarding covered defense information and cyber-incident reporting, and NASA FAR Supplement 1852.204-76 on security for unclassified information technology resources. It also refers to DoD assessment and reporting provisions, including DFARS 252.204-7019 and DFARS 252.204-7020.
The 15 contracts did not necessarily impose every cited obligation in precisely the same way. The applicable requirements depend on the contract language, data involved, system boundary, and the parties’ roles. A university or subcontractor should not assume that one general cybersecurity policy answers every contract-specific question.
Rank #3
What a meaningful POA&M needs to do
A plan of action and milestones is a documented route from a known deficiency to correction. It is useful only if it describes a real, managed remediation effort—not just a list of open controls. For each item, a defensible record should identify:
- The specific NIST requirement and the affected system or CUI boundary.
- The deficiency, risk, and operational impact.
- An accountable owner and concrete corrective action.
- Dependencies, resources, and a target date the organization can support.
- Evidence needed to verify closure, with a distinction between interim mitigation and full implementation.
- Dated status updates, approvals, and escalation when milestones slip.
A POA&M is not a blanket safe harbor for operating indefinitely outside a contract requirement. In this case the government alleged deficiencies both in the plans and in their implementation; the settlement itself, however, does not establish a general legal holding about POA&Ms.
Why a cloud provider’s label is not enough
A commercial cloud service is not automatically suitable for CUI. Where a contract requires FedRAMP Moderate, the relevant question is whether the specific service and deployment meet that requirement—not whether a vendor generally describes its products as secure. Organizations should verify the service, authorization boundary, region, tenant configuration, inherited controls, data flows, administrator access, subcontractors, and contract terms. The FedRAMP Marketplace is a starting point for checking federal cloud authorizations.
Rank #4
Even an appropriate authorized service does not make the customer compliant on its own. The customer remains responsible for its configurations, accounts and identity controls, endpoints, applications, logging, incident response, and evidence. The same shared-responsibility question applies when a managed service provider or consultant handles CUI or administers systems: determine exactly which controls the vendor supports, what evidence it supplies, and what remains the organization’s responsibility.
What the settlement does—and does not—establish
- It does establish that Penn State agreed to pay $1.25 million to resolve allegations involving 15 DoD and NASA contracts or subcontracts and that Decker received a $250,000 share.
- It does not establish a judicial finding of FCA liability, a confirmed successful cyberattack, or the theft or exfiltration of CUI.
- It does not establish that all 110 controls were missing, that every university system was affected, or that Penn State’s entire cloud environment failed the stated baseline.
- It does not make CMMC the basis of the 2024 allegations. The dispute concerned contract requirements applicable during the alleged 2018–2023 period.
The matter involved the U.S. Attorney’s Office for the Eastern District of Pennsylvania, DOJ’s Civil Division, and multiple investigative, audit, and procurement bodies, including NCIS, NASA’s inspector general, the DoD inspector general, the Defense Criminal Investigative Service, Army and Navy investigative or audit organizations, and the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center. The breadth of the participants illustrates how a cybersecurity contract issue can draw civil-fraud, audit, procurement, and investigative scrutiny.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhy universities and research institutions face particular challenges
A university can have strong general cybersecurity and still fail a specific federal contract requirement. Research work often spans central IT, individual laboratories, principal investigators, shared facilities, outside collaborators, and subcontractors. That can make it difficult to maintain one authoritative inventory of where CUI is stored, who can access it, and which cloud services or endpoints fall inside the system boundary.
Best Value
The reverse is also possible: a system may have effective technical safeguards but weak documentation. If the organization cannot show which controls apply, how they are implemented, what deficiencies remain, and who approved representations, it may be difficult to support an assessment score or compliance affirmation. Contract compliance therefore requires both security work and reliable records.
A practical checklist for contractors and universities
- Inventory contracts and subcontracts involving CUI, CDI, or NASA-controlled unclassified information.
- Map each contract clause to the actual systems, services, facilities, and personnel handling the information.
- Define and document the system boundary before assessing controls or reporting a score.
- Maintain a current system security plan and conduct a control-by-control NIST SP 800-171 assessment.
- Keep evidence that supports each control status, exception, milestone, score, and affirmation.
- Record known deficiencies accurately; make remediation dates achievable, resourced, and approved.
- Review POA&Ms routinely, update status when circumstances change, and escalate missed milestones.
- Verify the exact cloud service and deployment against contract requirements; document inherited and customer-managed controls.
- Review subcontractor and managed-service-provider access, flow-down obligations, data handling, and evidence.
- Have security, contracts, legal, and research-administration personnel review compliance representations together.
- Train those who prepare SPRS submissions and affirmations, and retain the submitted versions and approvals.
- Investigate and correct discrepancies promptly rather than waiting for an audit or inquiry.
Software, consultants, managed security providers, and government-cloud services can help organize evidence or implement controls, but none makes an organization compliant by purchase alone. Any provider selection should spell out the shared-responsibility boundary, whether the vendor itself handles CUI, and what supportable evidence it will produce.
Current CMMC context
As of August 18, 2026, the DoD CMMC overview says the department suspended planned CMMC Phase II implementation on July 13, 2026, while continuing applicable NIST SP 800-171 Revision 2 self-assessment and affirmation requirements. That later program change does not rewrite the historical allegations or erase contractual duties that applied during the 2018–2023 period. CMMC, NIST SP 800-171, DFARS clauses, NASA requirements, and FedRAMP are related compliance concepts, not interchangeable labels.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

