In May False Claims Act enforcement against government contractors. Leadership at organizations holding federal contracts or subcontracts must now answer three questions: What cybersecurity incidents trigger disclosure obligations? Who inside the organization owns the decision to disclose? What constitutes the timely cooperation and remediation that earns mitigation credit?
The stakes are not theoretical. The revised policy explicitly addresses cybersecurity and cyber fraud, creating a framework where contractors can receive substantial credit for voluntary disclosure—or face the full consequences of non-disclosure if incidents come to light through other means. The policy does not create new legal obligations, but it clarifies how DOJ will evaluate contractor conduct when violations occur.
Why This Matters Now
Federal contractors operate under an expanding web of cybersecurity requirements: DFARS 252.204-7012, CMMC, FAR 52.204-21, and sector-specific mandates. A material cybersecurity incident—unauthorized access to controlled information, compromise of systems processing federal data, or failure to maintain required safeguards—can constitute a False Claims Act violation if the contractor has certified compliance with these requirements.
The May 2024 policy creates a defined path: contractors who discover violations, voluntarily disclose them within a reasonable time, cooperate fully, and remediate effectively may receive what DOJ terms a "presumption" that the agency will decline prosecution or substantially reduce any monetary penalty. Contractors who fail to disclose face the policy's full force when DOJ discovers the incident through audit, whistleblower, breach notification to other agencies, or investigation.
The business consequence is straightforward. An incident that might resolve through mitigation and limited penalty under voluntary disclosure becomes a full civil enforcement action without it. The difference is measured in millions of dollars, contract suspension or debarment risk, and organizational reputation.
What the Policy Actually Requires
The May 2024 policy establishes specific elements a contractor must satisfy to qualify for mitigation credit. Understanding these elements is essential because partial compliance yields no benefit.
Voluntary Self-Disclosure
Disclosure must be voluntary—made before DOJ or another agency has commenced investigation or the contractor has received notice that disclosure is or will be required. It must also be timely, meaning within a reasonable time after the organization becomes aware of the violation. What constitutes "reasonable" depends on the circumstances, but measured delay while investigating internally does not satisfy the policy if it crosses into avoidable postponement.
For cybersecurity incidents, this timeline creates tension. Incident investigation takes time; determining whether an incident constitutes a contractual violation requiring disclosure takes more time; and legal review adds another layer. Yet the clock starts when the organization becomes aware of facts suggesting a violation, not when investigation concludes. Leadership must have a pre-established process for escalating potential violations and making disclosure decisions under uncertainty.
Full Cooperation
The policy requires full cooperation with any government investigation. This means preserving and producing relevant documents and information, making employees and former employees available for interviews, and disclosing all relevant facts including those that might be inculpatory. The cooperation obligation continues throughout the investigation—initial disclosure is not sufficient if cooperation later becomes selective.
Timely and Appropriate Remediation
The contractor must remediate the violation and implement measures to prevent recurrence. For cybersecurity incidents, this extends beyond patching the immediate vulnerability. It requires examining why controls failed, whether the failure was isolated or systemic, and what governance or technical changes will prevent similar incidents. DOJ expects this remediation to be appropriate in scope, timely in execution, and verified as effective.
Who Owns This Inside Your Organization
The May 2024 policy creates an accountability problem that many contractor organizations have not resolved. Determining whether an incident meets the voluntary disclosure threshold requires integrated judgment across cybersecurity, legal, contracts, and compliance functions. No single department owns this decision by default, and the consequence of unclear ownership is missed disclosure windows or inconsistent decisions.
Consider what must happen in the first hours after detecting a significant cybersecurity incident: Technical staff must assess scope and impact. Cybersecurity leadership must determine whether the incident affects systems or data subject to federal contract requirements. Contracts personnel must identify which contract provisions apply and what certifications the organization has made. Legal must evaluate whether the incident, combined with those certifications, creates a potential False Claims Act exposure. Compliance must determine whether other disclosure obligations run in parallel. And executive leadership must decide whether to disclose voluntarily, knowing that decision must be made quickly and with incomplete information.
This is not a process that assembles itself during an incident. It requires pre-established governance: designated executive ownership, defined escalation paths, clear decision criteria, and documented authority to make binding commitments on behalf of the organization. It requires someone who can translate technical incident data into business and legal context, who understands both the cybersecurity requirements in federal contracts and the DOJ's enforcement posture, and who has the organizational authority to coordinate across functions under time pressure.
Many contractors assign cybersecurity to IT, compliance to contracts administration, and legal questions to counsel. The May 2024 policy requires something different: strategic cybersecurity leadership that operates at the executive level, understands the regulatory environment, and owns the organization's risk posture. This is the defined role of a virtual Chief Information Security Officer—executive leadership that bridges technical capability, business context, and regulatory obligation.
The Connection to Incident Readiness and Response Planning
The May 2024 policy makes incident response planning a compliance requirement, not merely a technical precaution. An organization cannot satisfy the policy's "timely" cooperation and remediation expectations without pre-existing capability to investigate incidents, preserve evidence, assess scope, and execute containment and recovery while maintaining operational continuity.
Incident readiness means having answers before questions arrive: Who has authority to declare an incident? What communication protocols govern internal coordination and external notification? How will the organization preserve forensic evidence while containing damage? What documentation will DOJ expect if voluntary disclosure becomes necessary? Which legal and technical resources can the organization activate on short notice? These decisions cannot be made effectively in the middle of an active incident.
Response planning under the voluntary disclosure policy must account for parallel obligations. Many cybersecurity incidents that affect federal contractors trigger multiple reporting requirements simultaneously: DFARS 252.204-7012 requires reporting to DoD within 72 hours of discovery; FAR 52.204-21 requires reporting to the contracting officer; agency-specific requirements may impose additional timelines; and now the voluntary disclosure policy creates a separate calculus about DOJ notification. An effective response plan maps these obligations, identifies potential conflicts, and establishes coordination protocols.
Organizations that discover incident readiness gaps during actual incidents face an impossible choice: delay response while building capability, or proceed with inadequate preparation and risk failing to meet the policy's standards. Neither option preserves eligibility for mitigation credit. Readiness must exist before it is tested, which requires executive ownership of the planning process itself. [Virtual CISO leadership](/vciso/) provides this ownership as an integrated service: strategy, governance, incident readiness planning, and the executive coordination that makes plans executable under pressure.
What Leadership Should Do Next
Federal contractors and subcontractors should take four immediate actions to address the May 2024 policy's requirements:
- **Designate clear executive ownership for cybersecurity incident disclosure decisions.** Identify by name and role the person accountable for evaluating whether incidents meet voluntary disclosure thresholds, coordinating cross-functional assessment, and making time-sensitive disclosure recommendations to executive leadership. Document this designation in governance policies and incident response plans. If no individual in your organization currently has the technical knowledge, regulatory understanding, and organizational authority this role requires, that gap represents immediate risk.
- **Audit your current incident response capability against the policy's cooperation and remediation standards.** Can your organization investigate an incident while preserving forensic evidence to DOJ standards? Can you produce comprehensive documentation of technical facts, business impact, and remediation actions under compressed timelines? Can you demonstrate that remediation addresses root causes rather than symptoms? If your assessment reveals capability gaps, address them before an incident forces the question.
- **Map the disclosure obligations that apply to your specific contracts and determine how they interact with voluntary self-disclosure.** Different contracts impose different cybersecurity requirements and different breach notification obligations. The interplay between contract-specific notification requirements and the DOJ voluntary disclosure policy is not always obvious. Work through scenarios with specific contract language, specific types of incidents, and specific timelines to identify potential conflicts or coverage gaps before they become urgent.
- **Test your incident response plan with a tabletop exercise that includes the voluntary disclosure decision.** Most incident response exercises focus on technical containment and recovery. Add a realistic disclosure scenario: How does your organization determine whether an incident potentially violates the False Claims Act? Who participates in that determination? How long does the decision process take? What information do decision-makers need and who provides it? Walking through the process in a controlled exercise reveals procedural gaps, authority confusion, and coordination problems while stakes are low.
These actions share a common requirement: sustained executive attention to cybersecurity governance, not as an IT initiative but as a strategic risk and compliance function. Organizations that lack internal executive leadership with the necessary technical and regulatory knowledge face a decision about how to fill that gap. Deferring the decision does not reduce the risk; it merely ensures the gap will be discovered during an incident when options are limited and consequences are certain.
How Heights Consulting Group Can Help
Heights Consulting Group provides federal contractors with the executive cybersecurity leadership the May 2024 policy effectively requires. Our virtual CISO service delivers strategic guidance, governance frameworks, incident readiness planning, and ongoing oversight—the capabilities necessary to make informed disclosure decisions, satisfy cooperation and remediation standards, and demonstrate sustained control improvement.
We work directly with chief executives, general counsel, and compliance leadership to build cybersecurity governance appropriate to your organization's risk profile and contract obligations. This includes evaluating your current incident response capability against regulatory expectations, designing escalation and decision protocols that function under time pressure, and establishing the documentation practices that support both operational response and potential disclosure obligations.
If your organization needs to strengthen its cybersecurity governance and incident readiness in light of the May 2024 voluntary disclosure policy, we offer a confidential consultation to assess your current position, identify specific gaps, and recommend a practical path forward. Contact Heights Consulting Group to schedule a discussion about your organization's needs.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Incident Readiness and Response Planning
A response plan that names decision makers, defines escalation and notification paths, and has been tested with the executives who would have to use it.