Navigating CMMC and FedRAMP Together: From Assessment-Ready to Authorized | July 22nd

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Building a Defensible CMMC Program: What the False Claims Act Means

Federal Assessments | CMMC

Published: Jun 9, 2026

CMMC certification is mandatory if you want federal contracts, but the journey doesn't end there.

What happens after you're certified? What happens if you get investigated? What happens if a disgruntled employee reports you to the Department of Justice?

In this LinkedIn Live session, Greg Peterson (Principal Consultant, RKON) and Doug Barbin (President, Schellman) discuss the often-overlooked intersection of CMMC compliance and the False Claims Act, and the importance of creating a defensible CMMC program.

This conversation covers:

  • The certification trap: Why passing a C3PAO audit creates a false sense of security and why the audit itself is just the beginning
  • False Claims Act exposure: The real financial penalties (up to treble damages), the role of whistleblowers, and why company size doesn't protect you
  • Personal liability: What signing an annual affirmation actually means and why executives need to understand their personal risk
  • The 52-year-old law with modern teeth: How the False Claims Act is being weaponized against contractors and how enforcement is escalating (enforcement cases rose 20-30x from 2024 to 2025)
  • Program vs. project mentality: Why CMMC is not a point-in-time event and what "defensibility" really looks like
  • Common gaps that trigger liability: SSPs that don't match reality, scoping misunderstandings, inflated SPRS scores, and how to avoid them
  • Real-world examples: How whistleblowers from Georgia Tech, Illinois machine shops, and other organizations have exposed compliance failures, and the seven-figure fines that followed
  • How primes manage supplier risk: Why your prime contractor has skin in the game and how that affects your defensibility
  • Practical steps to reduce risk: Independent gap assessments, annual health checks, self-disclosure strategies, and when to engage a C3PAO

Whether you're a defense contractor pursuing CMMC certification, a prime managing suppliers, or an executive tasked with compliance, this session reveals the stakes beyond the checkbox and what real defensibility looks like.

Watch to understand why CMMC compliance is becoming both a legal imperative and a personal liability topic.

Schellman is a C3PAO with extensive CMMC assessment experience. RKON is a leading advisory firm specializing in CMMC and federal compliance. Both are committed to helping organizations build defensible programs, not just compliant ones.

About Douglas Barbin

As President and National Managing Principal, Doug Barbin is responsible for the strategy, development, growth, and delivery of Schellman’s global services portfolio. Since joining in 2009, his primary focus has been to expand the strong foundation in IT audit and assurance to make Schellman a market leading diversified cybersecurity and compliance services provider. He has developed many of Schellman's service offerings, served global clients, and now focuses on leading and supporting the service delivery professionals, practice leaders, and the business development teams. Doug brings more than 25 years’ experience in technology focused services having served as technology product management executive, mortgage firm CTO/COO, and fraud and computer forensic investigations leader. Doug holds dual-bachelor's degrees in Accounting and Administration of Justice from Penn State as well as an MBA from Pepperdine. He has also taken post graduate courses on Artificial Intelligence from MIT and maintains multiple CPA licenses and in addition to most of the major industry certifications including several he helped create.