DFARS Investigation and Compliance Consultant/Lawyer
When your company enters into a contract with the U.S. Department of Defense (DoD), part of the agreement is that it will satisfy with the agency’s cybersecurity expectations. Because you may have access to extremely sensitive information that other countries are actively trying to obtain, these expectations are rigorous.

DFARS Investigation and Compliance Team Lead
Former DOJ Trial Attorney
DFARS Investigation and Compliance Team
Former HSI Special Agent
Currently, those expectations are laid out in the Defense Federal Acquisition Regulation Supplement (DFARS), Title 48, Chapter 2 of the Code of Federal Regulations (CFR). These DFARS regulations explain what the expectations are for which government defense contractors, what the protocol is if there has been a cyberattack or data breach, and what the penalties are for failing to comply with the regulations.
Given the significant liability that can follow noncompliance, it is extremely important for defense contractors to create, maintain, and audit their cybersecurity system for DFARS compliance.
Cybersecurity in the Defense Industry is Crucial
Governments and foreign nations across the world have turned to hacking and cyberwarfare to gather sensitive and important information about their adversaries, including those that are at odds with the United States.
Given that the information that defense contractors need to provide goods or services to the DoD or other national security agencies often has to do with America’s most closely-guarded secrets, it should come as no surprise that these contractors are likely to become targets of a cyberattack, perhaps even a sophisticated one perpetrated by a powerful foreign state.
The DoD knows this and has acted with increasing urgency to get its contractors to buttress their cybersecurity protocols. Now, it is generally a non-negotiable requirement for defense companies to agree to take strong cybersecurity positions in order to obtain a defense contract. Additionally, defense contractors who do get awarded a contract should be prepared not just for audits and investigations by the federal government, but also for modifications to their cybersecurity compliance obligations.
DFARS Outlines the Defense Department’s Requirements
Those cybersecurity obligations are currently laid out in the DFARS regulations.
Generally, defense contractors must create cybersecurity systems that meet the requirements created by the National Institute of Standards and Technology (NIST) in its Special Publication 800-171 (NIST SP 800-171).
Because the best practices in cybersecurity are in a constant arms race with the best practices in cyberattacks, these Special Publications by the NIST are constantly being revised. Before they can even begin to implement a compliant cybersecurity system, defense contractors need to make sure that they are looking at the right requirements. Contractors can validate the currentness of the publications on NIST’s website, which also lists old versions of the requirements and how they are different.
The two main goals of DFARS and the NIST requirements are to implement adequate protections for the sensitive data that defense contractors routinely handle, and to quickly report any potential data breaches that may have led to unauthorized access of that information.
To reach those goals, NIST SP 800-171 lays out the “recommended security requirements” in 14 different categories:
- Access control
- Awareness and training
- Audit and accountability
- Configuration management
- Identification and authentication
- Incident response
- Maintenance
- Media protection
- Personnel security
- Physical protection
- Risk assessment
- Security assessment
- System and communications protection
- System and information integrity
Defense contractors are expected to comply with these “recommended requirements” and frequently go through DFARS investigations to ensure that they are doing so. If one of these investigations uncovers evidence of noncompliance, it can lead to some stunningly high repercussions.
The Penalties of Noncompliance are Very High
Defense contractors who secure a national defense contract with the DoD, agree to the agency’s demands for a strong cybersecurity system, and then fail to deliver on that promise – even if the failure was in spite of all of its best efforts – the consequences can be massive.
First, the contractor is likely to receive a stop-work order from the DoD. This halts all of your performance under the contract and, importantly, stops all pending payments to your company. To lift the stop-work order, your company will have to reach DFARS compliance.
Second, it will put a significant blemish on your company’s business reputation and brand. Your company signed an agreement that promised that it would implement an adequate cybersecurity system. Even a mistaken allegation of noncompliance can hurt your reputation. If the allegation is not groundless, odds are not small that the contract will be rescinded and your company will struggle to acquire a new one with the government in the future.
But worst of all is the potential for legal liability under the federal False Claims Act. While this law is best known as the leading whistleblower law for reporting government program fraud, 31 U.S.C. § 3729(a)(1)(B) also forbids knowingly making a material and false statement in relation to a claim against the government.
Because defense contracts are claims against the government, and your company’s failure to uphold its promised cybersecurity obligations under the contract could arguably be deemed a “false statement” that is “material” to the contract, it is not unforeseeable for the federal government to try pressing a civil claim under the False Claims Act.
Such a claim carries massive penalties, because the False Claims Act imposes treble damages for violations.
Not only would your company have to reimburse the DoD for damages related to the breach of contract, it would also be liable for three times the amount that it received from the DoD while it was out of compliance with DFARS requirements.
Several Frequently Asked Questions About DFARS Compliance and Investigations
If I Hire a DFARS Consultant or Third Party to Create a Cybersecurity System, Will My Company Still Be Liable if it Fails?
Yes, your company will be held vicariously liable if you got third party help to implement a cybersecurity system to satisfy DFARS requirements. Even if your company completely contracted all of the work out to another party, your company will still be held liable for its failure.
This is why it is so important to find the right DFARS consultants.
Why Should I Hire Outside Help for DFARS Compliance?
Because merely understanding the obligations that you have to satisfy is difficult enough on its own. Actually implementing them requires an in-depth understanding of cybersecurity systems that many defense contractors do not have in-house.
Additionally, by hiring DFARS compliance consultants you can free up resources in your business for what your company actually focuses on – performing its obligations under the defense contract. It lets everyone do what they are best at doing, making everything more efficient and enhancing everyone’s productivity.
The fact that defense contractors are still liable for the failures of the DFARS compliance firm that they hired does not undercut the benefits of the setup. The defense contractor would also be liable for cybersecurity failures if they handled DFARS compliance in-house. By bringing in a consultant or compliance firm that handles DFARS for a living, you level up your cybersecurity capacities and reduce the odds of noncompliance, all without affecting your exposure to liability.
My Company Found Evidence of a Data Breach. What Do We Do?
There are specific DFARS obligations related to data breaches. Broadly speaking, though, defense contractors must immediately investigate the breach, identify which machines and accounts were compromised, and determine the scope of the breach. They must then report the incident within 72 hours to the DoD through its online cyber incident report.
The information that has to be included in this report is listed on the form.
It is not uncommon for defense contractors to hesitate if they find evidence of a data breach. After all, reporting it to the DoD tacitly admits to the shortcomings of their cybersecurity system.
There are 3 extremely important reasons for hesitant contractors to stop hesitating and notify the Department of Defense:
- If the agency learns that a contractor was aware of a data breach and did not report it, the penalties will be extreme
- Just because there was a data breach does not necessarily mean that the cybersecurity system was not in compliance with DFARS requirements
- National security is at stake
Will DFARS Obligations Update in the Future?
Yes, the DoD’s cybersecurity requirements update frequently. In fact, the DoD has a proposed rule that is currently going through the rulemaking process that would completely overhaul the DFARS system with the Cybersecurity Maturity Model Certification (CMMC) Program.
Oberheiden P.C. has written a blog post that details the progress of this proposed rule and the changes that it would make in the cybersecurity needs of defense contractors.
Why Doesn’t Oberheiden P.C. Call Itself the Best DFARS Firm?
That is something that we prefer to let our clients say about us. You can read their testimonials here.
Federal Cybersecurity and DFARS Compliance Consultants at Oberheiden P.C.
Cybersecurity is a notoriously technical field. So is compliance. Finding a good consultant that works at the nexus of these areas is extremely important for defense contractors who want to make sure that they are up-to-date and following their obligations under DFARS.
The DFARS compliance and investigation consultants and lawyers at Oberheiden P.C. help defense contractors understand their contractual cybersecurity obligations, see how they can build cybersecurity systems that are adequate enough to secure a lucrative government contract, assist in implementing such a system, provide audits that test those that have been put in place, and represent contractors who are being investigated for DFARS compliance.
Contact them online or call their national law office at (888) 680-1745.
