Swiss Automation paid $421,234 over drawing security. What does that mean for your shop?

What analysts called the first cyber False Claims Act settlement below the prime tier started with the shop's own quality manager. What DOJ alleged, how it connects to your SPRS score, and what to do if the number you posted is wrong.

Swiss Automation: $421,234. Quality manager filed it. Your SPRS score is a claim. Wrong score? Counsel first. Working guide.
In this guide

Updated September 30, 2026

It means a small shop can be sued for not protecting a prime's drawings, by its own employee, with no breach and no CMMC certificate involved. On December 5, 2025, the Justice Department announced that Swiss Automation Inc., an Illinois precision machining business, agreed to pay $421,234 to resolve alleged False Claims Act violations (DOJ). The case was brought by the company's former quality-control manager.

If you run a shop that machines parts for defense primes, this is the case to read. The others in the news were a research university, a defense technology firm, and Honeywell. This one looks like you.

What DOJ alleged

The False Claims Act lets the government recover up to three times its losses from anyone who knowingly causes a false claim for payment, and it lets an insider file the suit on the government's behalf. That insider is called a relator, or whistleblower.

Here is what DOJ's release says, in plain terms. Swiss Automation supplies alloy and metal parts to many industries, including DoD prime contractors and their subcontractors. DOJ alleged the company did not provide adequate cybersecurity for certain drawings of parts it machined for DoD primes, and that this caused false claims to be submitted. DOJ also alleged the company knew that the security requirement, the 110 controls in NIST SP 800-171, applied not only to primes but to their subcontractors and suppliers. The release notes that this obligation has applied to DoD contracts and subcontracts since 2017.

Three details matter more than the dollar figure.

Swiss Automation never billed the government. It sold parts to primes. The theory is that it caused the primes' claims to be false. If you think the False Claims Act is a prime contractor's problem, this case ends that idea.

No breach is mentioned. Nobody alleged the drawings were stolen. The alleged failure was not protecting them the way the purchase orders required. According to Arnold & Porter's read of the settlement agreement, it covers nine purchase orders carrying DFARS 252.204-7012 and doesn't name which controls were missing (Arnold & Porter). Crowell & Moring dates those purchase orders from March 2022 to October 2023 (Crowell & Moring).

It's a settlement. DOJ's release says it plainly: "The claims resolved by the United States in the settlement are allegations only. There has been no determination of liability." Swiss Automation didn't admit wrongdoing, and nothing here proves it did anything wrong.

The whistleblower, the company's former quality-control manager, receives $65,291, about 15.5 percent of the settlement. The case is No. 1:22-cv-4328 in the Northern District of Illinois. The docket number puts the filing in 2022, so it took roughly three years to resolve.

Where it sits among the other cases

Case Announced Amount Who brought it
MORSECORP, Cambridge, Mass. March 26, 2025 $4.6 million Head of security
Swiss Automation, Illinois December 5, 2025 $421,234 Quality-control manager
Honeywell Aerospace September 1, 2026 $2,042,518 Former employee

MORSECORP is the case to know for your score. As part of that settlement, MORSE admitted it posted a score of 104 in SPRS (the DoD database where suppliers post their self-assessment score) in January 2021. In July 2022, a consultant it hired scored it at −142. It didn't update SPRS until June 2023, after DOJ had subpoenaed it (DOJ). Honeywell's settlement covers one network that allegedly didn't meet NIST SP 800-171 from April 2020 through December 2023 (DOJ). Penn State paid $1.25 million over 15 DoD and NASA contracts and subcontracts.

In fiscal year 2025, DOJ recovered more than $52 million across nine cybersecurity False Claims Act settlements (Mayer Brown). Swiss Automation came in December, the start of fiscal 2026. Analysts called it the first of these settlements to reach a supplier below the prime (ComplexDiscovery). The pause on third-party CMMC assessments in July 2026 changed none of this. The 7012 clause and the self-assessment are still in your POs.

Why your SPRS score is the exposure

Your SPRS score is a statement to the government. It says how many of the 110 requirements you meet, scored from 110 down to −203. Primes rely on it when they award you work, and so does DoD. A score you can't back up with a working system is the kind of statement these cases are built on. How the score works →

The annual affirmation raises the stakes. Under CMMC, a senior official at your company must affirm in SPRS, every year, that the company "has implemented and will maintain implementation of all applicable CMMC security requirements" (32 CFR 170.22). That's a named person signing a present-tense statement. If you're the owner, it's probably you. What the affirmation commits you to →

Run this check on your own score before your next affirmation. It takes an afternoon.

  1. Log into SPRS and write down your posted score and its date.
  2. Find whoever produced it and the worksheet behind it. If nobody can find the worksheet, treat the score as unsupported.
  3. Start with the written system security plan (3.12.4). Without one, there is no valid score at all. Then pick four 5-point requirements that shops often fail: multi-factor login (3.5.3), encryption of controlled data (3.13.11), the network boundary between office and shop floor (3.13.1), and control of USB sticks (3.8.7).
  4. For each, find proof that works today. A screenshot of the setting, a log, a policy page. "Our IT guy handles it" is not proof.
  5. Check the scope. Did the score cover every place a drawing goes, including the estimator's inbox, the CMM PC, and the plater or heat treater you send it to?

If the plan exists, all four hold, and the scope is right, you're in reasonable shape. If two or more fail, your posted score is probably wrong. Is your score supported? →

If your posted score is wrong

Call a lawyer who handles government contracts and False Claims Act matters before you change anything in SPRS. The order and wording of what you do next matter, and a lawyer should set both.

With counsel, the steps are usually these. Keep every email and document about your security and your score, and tell your staff to delete nothing. Rescore honestly against the DoD methodology, with evidence for every requirement you mark as met. Post the corrected score, and have counsel decide whether to disclose to the government. DOJ's own policy gives credit in False Claims Act cases to companies that make "proactive, timely, and voluntary self-disclosure" (Justice Manual 4-4.112). Then fix the gaps on a dated plan and keep the dates.

MORSECORP is what waiting looks like. It had a −142 in hand and a 104 posted, and it waited eleven months, until after the subpoena. A corrected score posted in the first month reads as a company fixing a problem. The same correction a year later, after an employee has filed suit under seal, reads as something else.

The quality manager already knows

Look at who filed each case. A head of security at MORSECORP. A quality-control manager at Swiss Automation. These are the people whose job is to read the requirements and compare them with what the company actually does.

In a machine shop, that's the quality manager. They run contract review, so they've read the DFARS clauses in every PO and the CUI marking in every title block. They handle AS9100 audits, so they know what "prove it" means. And CMMC often lands on their desk by default. They're the most likely person in your building to know your score is wrong, and the least likely to have the authority to fix it. One bookkeeper who inherited the job wrote in a CMMC forum: "I started last August as a mere book keeper." Another shop described its effort as "blind leading the blind."

The law protects that person. An employee who is fired, demoted, or harassed for pursuing a False Claims Act matter is entitled to reinstatement, double back pay, and attorney fees (31 U.S.C. 3730(h)). A relator's share runs 15 to 25 percent when the government joins the case. Retaliation doesn't make the problem go away. It makes it a second lawsuit.

The fix is cultural, and it's cheap next to what the security work itself costs a shop. Put the SPRS score on the agenda of your quarterly management review, next to scrap rate and on-time delivery. Have the quality manager present it with the evidence behind it. Give them a direct line to the owner when the number is wrong, and a budget line to fix it. A quality manager who can say "we're at 60, not 110" in a meeting has no reason to say it to a judge.

Mock assessment

Know your real score before you sign the next affirmation.

Garde1 scores all 110 Level 2 requirements against evidence from your tools and the records you add, compares the result with the score you posted in SPRS, and assembles the annual affirmation record with the tally, the date, and the signer.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE