Skip to main content
Category: Laws & Executive Orders

False Claims Act

Also known as: FCA, Lincoln Law, False Claims Act of 1863
Simply put

The False Claims Act is a federal law that makes it illegal to knowingly submit, or cause the submission of, false claims for payment to the U.S. government, such as fraudulent claims by government contractors. Violators can face significant financial liability, and the law also allows private citizens to bring lawsuits on the government's behalf. Because of this whistleblower provision, it is sometimes called the 'Lincoln Law' after its Civil War-era origins.

Formal definition

The False Claims Act (originally enacted in 1863) is a federal statute imposing civil liability on any person or entity that knowingly submits, or causes to be submitted, false or fraudulent claims for payment or approval to the federal government, and on those who make or use false records or statements material to such claims. As described in the evidence, the FCA generally provides for treble (three times) damages plus per-claim civil penalties, and includes qui tam whistleblower provisions permitting private citizens to file suit on behalf of the government. This entry addresses the statute at a conceptual level only; specific penalty amounts, which are subject to periodic inflation adjustment, and the precise statutory elements, procedures, and any application to cybersecurity or CUI-related misrepresentations by federal contractors should be verified against the current authoritative text and Department of Justice guidance.

Why it matters

The False Claims Act is one of the federal government's primary tools for combating fraud against the public fisc, and its reach extends well beyond traditional billing fraud. For government contractors, the FCA imposes civil liability for knowingly submitting false claims for payment or approval, and it generally provides for treble (three times) damages plus per-claim civil penalties. Because these penalties accumulate on a per-claim basis and the damages are trebled, potential exposure can escalate quickly, making the statute a significant source of financial and reputational risk for any organization doing business with the federal government.

Of particular relevance to compliance officers in the defense and public sector cybersecurity space is the possibility that misrepresentations about a contractor's security posture or compliance with contractual cybersecurity requirements could form the basis of an FCA claim. This entry does not confirm the specific contours of such theories, and readers should understand that whether a given cybersecurity-related misrepresentation constitutes an actionable false claim is a legal question that must be verified against the current statutory text, Department of Justice guidance, and applicable case law. The general point for practitioners is that attestations, self-assessments, and representations of compliance made to obtain or retain federal payment are not merely administrative formalities, they can carry legal consequences.

The FCA's qui tam whistleblower provisions add a further dimension: private citizens may file suit on the government's behalf, meaning that employees, subcontractors, or other insiders with knowledge of alleged false claims can initiate enforcement action independent of a government-initiated investigation. This structure broadens the universe of parties who may bring an organization's compliance practices under scrutiny and reinforces the importance of accurate, defensible representations across a contractor's dealings with the federal government.

Who it's relevant to

Government Contractors and Subcontractors
Organizations that submit claims for payment to the federal government are directly exposed to FCA liability for knowingly submitting false claims or making false records or statements material to those claims. Because damages are generally trebled and penalties accrue per claim, contractors should ensure that representations of compliance, invoices, and attestations are accurate and defensible. Contractors should confirm with counsel how the FCA may apply to specific contractual obligations, including any cybersecurity-related representations.
Compliance Officers and Ethics Personnel
Those responsible for a contractor's compliance programs should understand that the FCA can convert inaccurate representations to the government into a source of significant legal and financial risk. Compliance functions play a role in ensuring that claims, certifications, and self-assessments submitted to federal agencies are supported by evidence, though the precise legal standards and elements of an FCA violation should be verified with legal counsel.
Information System Security Managers and Security Attestation Owners
Personnel who prepare or approve representations about an organization's security posture or compliance with contractual cybersecurity requirements should be aware that such attestations are made in a context where accuracy carries potential legal weight. Whether a specific cybersecurity misrepresentation could support an FCA claim is a legal question that must be confirmed against current statutory text, DOJ guidance, and applicable case law rather than assumed.
Whistleblowers and Relators
The FCA's qui tam provisions allow private citizens, including employees, contractors, or other insiders, to file suit on the government's behalf when they have knowledge of alleged false claims. Individuals considering such action should consult qualified legal counsel regarding the specific procedures, protections, and requirements, which are outside the scope of this conceptual entry.
Auditors and Investigators
Those who assess contractor claims, certifications, and compliance representations should recognize that findings related to false or unsupported claims may have implications under the FCA. The determination of liability, however, rests on legal standards and procedures that should be evaluated with reference to authoritative Department of Justice guidance and the current statutory text.

Inside FCA

Statutory Basis
The False Claims Act (FCA) is a federal statute, codified at 31 U.S.C. §§ 3729-3733, that imposes liability on persons and entities that knowingly submit, or cause the submission of, false or fraudulent claims for payment to the federal government. Readers should verify the current statutory text and any amendments against authoritative sources.
Knowledge Standard
The FCA generally defines 'knowingly' to include actual knowledge, deliberate ignorance, and reckless disregard of the truth or falsity of information. It generally does not require proof of specific intent to defraud. Confirm the precise scienter language in the current statute.
Qui Tam Provisions
The FCA permits private individuals, known as relators, to file suit on behalf of the government (qui tam actions) and to potentially share in any recovery. The government may elect to intervene in such actions. Specific procedural requirements and relator share percentages should be verified against current law.
Cybersecurity Compliance Nexus
In the defense and public sector cybersecurity context, the FCA can be implicated when a contractor certifies or represents compliance with security requirements, such as those flowing from DFARS clause 252.204-7012, NIST SP 800-171, or other contractual cybersecurity obligations, that are false or not met. This is the basis for the theory of liability sometimes referred to as cyber-fraud enforcement.
Damages and Penalties
The FCA generally provides for treble (three times) damages plus per-claim civil penalties. Penalty amounts are subject to periodic inflation adjustment, so practitioners should confirm current figures against the applicable regulation rather than relying on a fixed amount.
Relationship to Contractual Certifications
Liability can arise from express false certifications and, in some circumstances, from implied certification theories where a claim for payment implies compliance with material requirements. The materiality and application of these theories are fact-specific and evolving in case law; this entry does not cover litigation specifics.

Common questions

Answers to the questions practitioners most commonly ask about FCA.

Does achieving a compliance certification or self-attestation protect a contractor from False Claims Act liability?
No. A certification or self-attestation does not, by itself, insulate a contractor from False Claims Act exposure. The Act generally addresses knowingly false or misleading representations made to obtain or retain government funds. If an attestation of compliance (for example, representing that required cybersecurity controls are implemented) is materially inaccurate and the contractor knew or acted in reckless disregard of its inaccuracy, that attestation can itself become the basis for liability. Compliance status and truthful representation are distinct issues, and readers should confirm specific liability standards against the current statutory text and applicable case law with qualified legal counsel.
Is the False Claims Act only triggered when an organization submits an outright fabricated invoice?
No. Liability under the Act is generally not limited to fabricated invoices. Depending on the theory pursued, it may extend to claims that are false because of noncompliance with underlying requirements, to misrepresentations about eligibility or performance, and to certifications treated as conditions of payment. The scope of these theories, including how materiality and knowledge are interpreted, has evolved and is shaped by case law. This entry does not cover the legal specifics of any particular theory, and readers should verify current interpretations with counsel.
How does the False Claims Act intersect with cybersecurity compliance obligations for government contractors?
In practice, the Act can intersect with cybersecurity obligations when a contractor represents compliance with contractually required security measures, such as safeguarding requirements tied to Controlled Unclassified Information, as a condition of payment or award. If such representations are knowingly false or made with reckless disregard, they may be scrutinized under the Act. The precise contractual and legal linkage depends on the specific clauses, requirements, and facts involved, so organizations should confirm applicability against their actual contract terms and current guidance.
What internal controls help a contractor reduce False Claims Act exposure related to compliance attestations?
Organizations generally reduce exposure by ensuring that representations of compliance are supported by accurate, current evidence before they are submitted. Common practices include validating that stated security controls are actually implemented, maintaining documentation that traces attestations to underlying assessments, establishing review and approval processes for certifications, and reconciling self-reported status with actual system state. These are general risk-management practices and do not substitute for legal advice; specific control expectations should be confirmed against applicable contractual and regulatory requirements.
Who within an organization typically bears responsibility for the accuracy of statements that could be scrutinized under the Act?
Responsibility is generally shared across the individuals who make or authorize representations to the government and those who supply the underlying information, which may include compliance officers, information system security managers, contract signatories, and senior officials who attest to compliance. Because knowledge and intent standards can implicate individuals as well as the organization, roles and sign-off authority should be clearly defined. The specific allocation of legal responsibility depends on facts and applicable law and should be reviewed with counsel.
What should a contractor do when it discovers that a prior compliance representation may have been inaccurate?
As a practical matter, organizations typically treat a discovered inaccuracy as a matter to investigate promptly, document, and evaluate for correction, and many consider whether disclosure or remediation obligations apply. Because decisions about whether and how to disclose, correct records, or notify the government carry legal consequences, these steps are generally taken in coordination with qualified counsel. This entry does not address the specific disclosure mechanisms, timelines, or legal thresholds, which readers must confirm against current authoritative and legal sources.

Common misconceptions

The FCA requires proof that the contractor intended to defraud the government.
The FCA's knowledge standard generally encompasses deliberate ignorance and reckless disregard, not only actual knowledge or specific intent to defraud. A contractor may face liability for false cybersecurity compliance representations made with reckless disregard for their accuracy. Confirm the precise scienter definition in the current statute.
Holding a FedRAMP authorization or an Authority to Operate (ATO) insulates a contractor from FCA exposure.
An authorization or ATO reflects an authorization decision at a point in time and does not certify ongoing contractual compliance. It does not automatically satisfy DoD requirements, and FCA liability can arise from false representations of compliance with specific contractual or regulatory cybersecurity obligations regardless of an existing authorization. Compliance status must be maintained and is subject to continuous monitoring.
The FCA only applies to overt billing fraud, not to cybersecurity requirements.
Under cyber-fraud enforcement theories, false or misleading representations about meeting cybersecurity requirements (for example, those tied to DFARS 252.204-7012 or NIST SP 800-171) tied to a claim for payment can give rise to FCA liability. The application of these theories is fact-specific and readers should consult qualified legal counsel.

Best practices

Ensure that any certification or representation of cybersecurity compliance (for example, regarding NIST SP 800-171 or DFARS 252.204-7012 obligations) is accurate and supported by documented evidence before it is submitted in connection with a claim for payment.
Maintain current, defensible documentation, such as system security plans and plans of action and milestones, so that stated compliance status can be substantiated, and update it as controls, baselines, and requirements change across revisions.
Treat compliance as an ongoing obligation subject to continuous monitoring rather than a one-time event; do not assume an ATO or FedRAMP authorization satisfies distinct contractual or DoD requirements.
Establish internal review and escalation processes so that individuals responsible for compliance representations understand that reckless disregard or deliberate ignorance of accuracy can create liability, not only intentional falsehoods.
Verify current statutory text, penalty amounts (which are subject to inflation adjustment), and applicable contract clauses against authoritative sources, since these change over time.
Engage qualified legal counsel to assess FCA exposure and the application of express and implied certification theories to specific contractual cybersecurity representations, as these are fact-specific and evolving.