CMMC Phase 2 enforcement begins November 10, 2026. Nine documented incidents. $26M+ in False Claims Act settlements. Four active threat actor campaigns targeting Texas DIB. This is your compliance and threat reference for the Texas defense industrial base.
Primes can flow subcontract awards through CoreRecon to meet FAR 19.14 SDVOSB set-aside goals under DFARS 252.219-7012. No other Texas MSSP has this certification.
| Company | Incident | Date | Financial Exposure | Key Source |
|---|---|---|---|---|
| Aerojet Rocketdyne | Qui tam FCA suit alleging false DFARS 252.204-7012 compliance certifications. Nation-state breach concealed from government (2013–2014). DOJ intervened. | FCA July 2022 | $9M | DOJ Press Release 22-726, E.D. California |
| Penn State Applied Research Lab | Former CIO filed qui tam alleging false SPRS scores, 15 NIST 800-171 controls unimplemented, non-FedRAMP cloud for CUI on DoD/NASA contracts. | FCA Oct 2024 | $1.25M | DOJ U.S. Attorney E.D. Pennsylvania, Oct 22, 2024 |
| MORSECORP Inc. | Admitted failure to ensure third-party SaaS email hosting met FedRAMP Moderate on Army/Air Force contracts (DFARS 252.204-7012), Jan 2018–Sep 2022. | FCA Mar 2025 | $4.6M | DOJ Civil Division, March 26, 2025, D. Massachusetts |
| Raytheon / RTX / Nightwing | Non-compliant internal development network ("1.0") used across 29 DoD contracts (2015–2021). No SSP. NIST 800-171 controls not implemented. DOJ civil fraud. | FCA May 2025 | $8.4M | DOJ Civil Division, May 1, 2025, D. Massachusetts |
| Georgia Tech Research Corp. | DOJ intervened Aug 2024 — false SPRS scores, missing antivirus, absent security plan on Air Force/DARPA contracts (Astrolavos Lab). Disputed, filed motion to dismiss. | Settlement Sept 2025 | $875K | DOJ Civil Division, Sept 30, 2025, N.D. Georgia |
| Boeing | LockBit ransomware on parts and distribution business. $200M ransom demanded, refused. ~43GB data published including engineering specs, supplier data, internal comms. Exploited Citrix Bleed (CVE-2023-4966). | Oct–Nov 2023 | Undisclosed (IP, supply chain, reputational) | DOJ indictment; Cloudskope; BleepingComputer; Bloomberg |
| HENSOLDT (Germany, UK subsidiary) | Lorenz ransomware claimed attack on UK subsidiary. Stolen files published on Lorenz leak site (labeled "Paid"). Confirmed compromise. Prior Snatch ransomware at French subsidiary (Nexeya, 2019). | Dec 2021–2022 | Undisclosed | BleepingComputer, Dec 2021; Security Affairs |
| L3Harris Technologies | $62M FCA settlement (pre-merger with Harris) for inaccurate cost/pricing data on communications equipment contracts. Cyber-adjacent FCA climate. | FCA FY2025 | $62M | DOJ FY2025 FCA Fact Sheet, Jan 2026 |
| Aerojet Rocketdyne (breach context) | Reuters: company concealed nation-state breach from Pentagon while representing it was secure. Internal ethics reports ignored. Qui tam filed 2015. | Breach 2013–2014 | $9M FCA + ongoing monitoring | Reuters; Thyberglaw client alert |
All settlements are FCA civil fraud actions. "No admission of wrongdoing" in all cases — but the money was real and the reputational damage was real.
| Company | Location | Key Programs | TX Workforce |
|---|---|---|---|
| Lockheed Martin Aeronautics | Fort Worth | F-35 Lightning II final assembly; F-16; classified programs | ~17,000 |
| Bell Textron | Amarillo / Fort Worth | V-280 Valor tiltrotor (Army FLRAA); Bell 412; FTUAS | ~9,500 |
| L3Harris Technologies | Greenville | ISR/aerospace comms; EW; classified C4ISR | ~4,000 |
| BAE Systems P&S | Austin, San Antonio | Armored vehicles; combat vehicles; Fort Bliss/Cavazos sustainment | Major (4 sites) |
| Raytheon Missiles & Defense | McKinney | AIM-120 AMRAAM; Patriot PAC-3; Precision fires; SM-6 | ~1,800 |
| Peterson Manufacturing | Waco | Tactical vehicle lighting; DFARS-subjected manufacturer | ~1,000 |
| General Dynamics OTS | Austin, Marion | Ammunition; small arms; training systems | TX ops |
| Boeing Defense, Space & Security | Houston | Space systems; missile defense; Phantom Works | TX ops |
| Installation | Location | Key Mission | Contractor Concentration |
|---|---|---|---|
| Joint Base San Antonio (JBSA) | San Antonio | Medical training; Air Force basic training; pilot training | Highest in TX; BAE, Booz Allen, CACI, SAIC, SDVOSBs |
| Fort Cavazos (formerly Fort Hood) | Killeen/Copperas Cove | III Corps / largest armored division in Army | Vehicle sustainment, logistics, IT contractors |
| Fort Bliss | El Paso | Army air defense; large-scale training; 1st Armored Division | Vehicle sustainment, electronics, comms contractors |
| NAS Fort Worth JRB | Fort Worth | F-35 training and logistics | Lockheed Martin prime; small subcontractors |
| NAS Corpus Christi | Corpus Christi | T-6 training aircraft; Coast Guard helicopter training | Small subcontractors for naval aviation |
| Dyess AFB | Abilene | B-1 bomber mission | Contractor support for bomber sustainment |
Gartner/DoD research estimated 60–70% of DoD contractors were NIST 800-171 non-compliant as of 2021. DFARS 252.204-7012 has applied to Texas defense contractors since December 2017 — over 8 years of required compliance. Lockheed Martin Fort Worth has been checking SPRS scores in subcontract solicitations since 2024.
Dual-mandate: cyber espionage for Beijing + financially motivated operations for personal gain. Targets defense contractors to steal source code, F-35/V-280/ISR program data, and weapons system specifications under "Made in China 2025." CISA AA20-275A specifically names DIB as an APT41 target.
★ CISA: DIB is primary target. TX aerospace manufacturers handling F-35/V-280/ISR data are high-priority.
Distinct from espionage: pre-positioning persistent access inside U.S. critical infrastructure — comms, energy, transportation, water — to enable disruptive or destructive cyberattacks during a future Taiwan crisis. FBI Director Wray: "the defining threat of our generation." CISA Director Easterly: "the real-world threat the Chinese government poses to our critical infrastructure."
★ CISA AA24-038A: Volt Typhoon specifically named Texas — targeting military strategic locations, power grids, water systems, comms.
DPRK's cybersecurity unit: funds nuclear and ballistic missile programs. Linked to 2014 Sony Pictures attack, 2017 WannaCry global outbreak (~$8B in damages), 2022 Ronin bridge hack ($625M crypto). CISA advisory AA22-108A documents Hidden Cobra targeting defense contractors via browser exploitation and weaponized LinkedIn job offer lures.
★ CISA: Defense contractors considering M&A are specifically targeted by Lazarus. Vet acquisition targets' cybersecurity posture as carefully as their financial posture.
Ransomware-as-a-service. Despite Operation Cronos takedown (Feb 2024) and LockBit's own internal data leaked (April 2025), the ecosystem is resilient — successor group SuperBlack uses LockBit Black as foundation. Extorted ~$91M from 1,700+ U.S. organizations since 2020. Boeing case: $200M ransom demanded and refused; 43GB of engineering specs, supplier data, internal comms published.
★ CISA: LockBit is the most active RaaS operation targeting U.S. organizations. Defense contractors handling ITAR/CUI are among the highest-value targets.
| Control Family | Controls | Point Impact if Unimplemented | Realistic Score Impact |
|---|---|---|---|
| Access Control (AC) | 22 | −2 to −5 per control | −15 to −25 pts |
| Audit and Accountability (AU) | 9 | −3 to −5 per control | −8 to −12 pts |
| Configuration Management (CM) | 9 | −3 per control | −8 to −15 pts |
| Identification and Authentication (IA) | 11 | −3 per control | −10 to −18 pts |
| Incident Response (IR) | 3 | −3 to −5 per control | −3 to −9 pts |
| Media Protection (MP) | 9 | −3 per control | −6 to −12 pts |
| Personnel Security (PS) | 2 | −1 per control | −1 to −2 pts |
| Physical Protection (PE) | 6 | −1 to −3 per control | −3 to −6 pts |
| Risk Assessment (RA) | 3 | −3 per control | −3 to −9 pts |
| Security Assessment (CA) | 4 | −3 per control | −3 to −6 pts |
| System and Communications Protection (SC) | 16 | −3 to −5 per control | −10 to −20 pts |
| System and Information Integrity (SI) | 7 | −3 per control | −6 to −12 pts |
| Awareness and Training (AT) | 3 | −1 to −3 per control | −2 to −5 pts |
| Maintenance (MA) | 6 | −1 to −3 per control | −3 to −6 pts |
| Realistic Texas defense manufacturer score | 110 | Realistic score: 60–85 (significant compliance gap) | |
A score of 60–85 is not unusual for a Texas defense manufacturer with active NIST 800-171 work underway. The gap between a score of 85 and 110 is the difference between a conditional certification (revocable within 180 days of C3PAO assessment) and a final certification that protects your contract eligibility for 3 years.
| Cost Category | Amount | Source |
|---|---|---|
| Average cost of a data breach — industrial sector (global) | $5.00M | IBM Cost of a Data Breach Report 2025 (604 orgs, 17 industries) |
| Average cost of a data breach — U.S. organizations (all sectors) | $10.22M | IBM Cost of a Data Breach Report 2025 (record high, +9% YoY) |
| Average cost of a data breach — financial services | $5.56M | IBM Cost of a Data Breach Report 2025 |
| DIB-specific breach cost range (medium contractor) | $5M–$15M+ | IBM industrial benchmark + DIB regulatory/legal costs |
| Breach lifecycle — global average | 241 days | IBM Cost of a Data Breach Report 2025 |
| Supply chain / third-party breach cost | $4.91M | IBM Cost of a Data Breach Report 2025 |
| Ransomware attack cost — industrial sector | $4.76M | Sophos State of Ransomware Report 2024 |
| DoD contract loss — no CMMC L2 cert | 100% | 32 CFR Part 170 / 48 CFR DFARS rule (condition of award) |
| C3PAO assessment cost — mid-size contractor | $20K–$100K+ | Industry benchmarks; C3PAO market pricing |
| SPRS fraud — FCA penalty per claim | $28,619 | 31 U.S.C. § 3729 (2025 adjusted) + treble damages |
| Aerojet Rocketdyne FCA settlement | $9M | DOJ, July 2022 |
| Penn State FCA settlement | $1.25M | DOJ, October 2024 |
| Raytheon/Nightwing FCA settlement | $8.4M | DOJ, May 2025 |
| MORSECORP FCA settlement | $4.6M | DOJ, March 2025 |
| Georgia Tech FCA settlement | $875K | DOJ, September 2025 |
If a Texas defense contractor earns $5M/year from DoD contracts, losing those contracts due to CMMC non-compliance costs $5M annually — compounding. The cost of achieving CMMC Level 2 compliance with a managed security provider is a fraction of one year's lost contract revenue.
| Feature | Sentinel | Fortress Recommended | Command |
|---|---|---|---|
| Price | $89/endpoint/month | $129/endpoint/month | $2,500+/month |
| Best for | Subcontractors, small manufacturers, Level 1 self-assessment only | Organizations handling CUI, targeting CMMC Level 2 self-assessment pathway | Defense primes, large manufacturers, full DFARS/NIST compliance, co-managed SOC |
| CMMC Level | Level 1 readiness (17 controls) | CMMC Level 2 readiness (110 controls) | CMMC Level 2 + Level 3 preparation |
| Endpoint protection | ✓ EDR, AV, patch mgmt | ✓ EDR, AV, patch, OT/IT segmentation | ✓ Full EDR, network, OT security, SIEM |
| 24/7 SOC | Business hours monitoring | 24/7 SOC (SecurityCore+) | Dedicated or co-managed SOC |
| SPRS score assessment | Basic score calculation | Full 110-control gap assessment, SSP, POA&M | Full SPRS + DIBCAC pre-assessment |
| CMMC documentation | SSP template, basic POA&M | Full SSP, POA&M, CUI flow-down docs | Complete CMMC evidence package |
| C3PAO readiness | Pre-assessment preparation | C3PAO readiness assessment, gap remediation | Full C3PAO assessment support |
| Incident response | Tier 1 triage, escalation path | Direct IR, DFARS 72-hr reporting support | Full IR retainer, forensics |
| DFARS 252.204-7012 coverage | Basic | Full compliance support | Full compliance + DCMA audit support |
| SDVOSB flow-through | Basic | Subcontract flow-through support, SDVOSB docs | Subcontract structure optimization |
| TX SB 2610 safe harbor | ✓ Included | ✓ Included | ✓ Included |
Every day you delay is another day your competitors who have their score locked in are ahead. CoreRecon's SPRS Calculator gives you the accurate 110-control gap assessment — not a marketing estimate.