Photo of Nkechi Kanu

Nkechi A. Kanu is a counsel in the Washington, D.C. office of Crowell & Moring, where she is a member of the firm’s Government Contracts Group.

Nkechi’s practice focuses on False Claims Act investigations and litigation. Nkechi has significant experience assisting companies with complex internal investigations and represents clients in government investigations involving allegations of fraud. She also focuses on assisting clients with investigations relating to cybersecurity and information security compliance. Her complementary litigation practice involves defending companies in government-facing litigation arising under the FCA, resulting in the dismissal of qui tam complaints and successful settlements of FCA claims with DOJ.

This special edition covers the Pentagon’s recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements and initiation of a 60-day review by the CMMC Reform Task Force, and is hosted by Yuan Zhou, Kate Growley, and Nkechi Kanu. Crowell & Moring’s “Fastest 5 Minutes” is a biweekly podcast that provides a brief summary of significant government contracts legal and regulatory developments that no government contracts lawyer or executive should be without.

Continue Reading Special Edition of the Fastest 5 Minutes: Suspension of CMMC Phase II Requirements

The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.

Continue Reading Department of War Immediately Suspends CMMC Phase II Requirements, Launches 60-Day Reform Review

On June 18, 2026, the U.S. Department of Justice (DOJ) announced that LOGZONE Inc., a defense contractor based in Huntsville, Alabama, agreed to pay $507,144 to resolve allegations that it violated the False Claims Act (FCA) by knowingly failing to satisfy cybersecurity requirements in its contracts with the U.S. Department of the Navy. The resolution is the latest action under DOJ’s Civil Cyber-Fraud Initiative and the first publicly reported settlement this fiscal year. It underscores a continued enforcement posture in which noncompliance with contractual cybersecurity obligations serves as the basis for potential FCA liability. Notably, this settlement did not arise from a whistleblower complaint but from a government-initiated assessment, signaling to contractors that proactive government assessments can pose enforcement consequences.

Continue Reading Logged Out: How LOGZONE’s DIBCAC Challenges Put It Squarely in DOJ’s Crosshairs

Introduction

The Federal Risk and Authorization Management Program (FedRAMP) continues to advance its modernization agenda. On April 8, 2026, FedRAMP released RFC-0031, Updated Incident Communications Procedures for public comment. This RFC proposes replacing the current FedRAMP Incident Communications Procedures (ICP) with what FedRAMP calls “a clear set of reporting requirements … established using a modern rules-based format.” 

Below is a summary of key changes proposed in RFC-0031.    

Continue Reading FedRAMP Solicits Public Comment on Overhaul to Incident Communications Procedures

False Claims Act (FCA) settlements and judgments hit record highs yet again in FY 2025, surpassing the previous record by over $1 billion and setting a new high-water mark for the number of new FCA cases filed.  These records were built both on existing enforcement priorities such as pandemic-related fraud and healthcare enforcement actions and new guidance from the Executive Branch instructing the Department of Justice to enforce its 2025 priorities including Diversity, Equity, and Inclusion (DEI), civil rights, and customs issues.  Procurement fraud, cybersecurity issues, and small business fraud also remained focal points, with significant settlements in each of those areas. 

Continue Reading The Top FCA Developments of 2025

Earlier this month, the Department of Justice (DOJ) announced that Swiss Automation Inc., an Illinois-based precision machining company, agreed to pay $421,234 to resolve allegations that it violated the False Claims Act (FCA) by inadequately protecting technical drawings for parts delivered to Department of Defense (DoD) prime contractors.  This settlement reflects DOJ’s persistent emphasis on cybersecurity compliance across all levels of the defense industrial base, reaching beyond prime contractors to encompass subcontractors and smaller suppliers.  The settlement is also a reminder to all contractors not to overlook the often confusing relationship between Controlled Unclassified Information (CUI) and export-controlled information.

Continue Reading An ITAR-ly Critical Reminder of Cybersecurity Requirements: DOJ Settles with Swiss Automation, Inc.

On September 30, 2025, the Department of Justice (DOJ) announced that Georgia Tech Research Corporation (GTRC) agreed to pay $875,000 to settle allegations that it violated the False Claims Act (FCA) and federal common law by failing to meet cybersecurity requirements under certain Air Force and Defense Advanced Research Projects Agency (DARPA) contracts.  The settlement adds to the growing list of recoveries under DOJ’s Civil Cyber-Fraud Initiative and is yet another example of DOJ’s ongoing enforcement focus on cybersecurity obligations for federal contractors handling sensitive government information.  The settlement also provides insight into how government contractors may challenge FCA liability when faced with allegations of cybersecurity noncompliance.

Continue Reading From Yellow Jackets to Red Flags: DOJ Stings Georgia Tech for Alleged Cybersecurity Noncompliance

On July 31, 2025, the Department of Justice (DOJ) announced that Illumina, Inc. will pay $9.8 million to resolve allegations that it violated the False Claims Act (FCA) by selling genomic sequencing systems with software containing cybersecurity vulnerabilities to federal agencies. This is the first FCA settlement involving claims that a medical manufacturer failed to incorporate adequate product cybersecurity into its software design and development.

Continue Reading Hardening Software Security: DOJ’s Civil Cyber Fraud Settlements Continue to Illumina[te] the Importance of Cybersecurity

On May 19, 2025, Deputy Attorney General Todd Blanche issued a Memorandum creating the Civil Rights Fraud Initiative that will “utilize the False Claims Act to investigate and . . . pursue claims against any recipient of federal funds that knowingly violates federal civil rights laws.” According to the Memorandum, though racial discrimination has “always been illegal,” the Administration posits that “many corporations and schools continue to adhere to racist policies and preferences—albeit camouflaged with cosmetic changes that disguise their discriminatory nature.” In an effort to prevent federal funds from being used in connection with or support of these purportedly racist policies and preferences, the Initiative will wield the power of the False Claims Act, the government’s most powerful tool to fight fraud, waste, and abuse.

Continue Reading DOJ’s Civil Rights Fraud Initiative Bolsters Threat of False Claims Act Enforcement Under “Anti-DEI” Executive Order

On March 26, 2025, the Department of Justice (DOJ) announced that defense contractor MORSECORP Inc. (MORSE) will pay $4.6 million to settle allegations that MORSE violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements and subsequently submitting false or fraudulent claims for payment in its contracts with the Departments of the Army and Air Force. This is the first FCA settlement that is based on a defense contractor’s failure to reevaluate and promptly update its self-assessment score in the Supplier Performance Risk System (SPRS) after a third-party assessment resulted in a lower score.

Continue Reading For Better or MORSE: Another Settlement Under DOJ’s Civil Cyber-Fraud Initiative