Get Your Free SPRS Score

Get Your Free SPRS Score

Book a personalized demo to unify tasks, pass audits, and scale.

CMMC Due Diligence in M&A: Successor Liability

CMMC Due Diligence in M&A Successor Liability
Facebook
Twitter
Pinterest
LinkedIn

Let's posit a hypothetical situation for you to think about.

Let's say that you're a large company already CMMC-compliant and working with the DoD. You've identified a smaller company that offers a service complementary to your own, and you've decided to acquire that company.

That smaller company claims to be CMMC-compliant, and you move forward with the acquisition. You successfully purchase the company, roll their services into your overall banner, and continue their operations with the DoD supply line.

Then your DoD contact brings up a few questionable details. You go looking, and you find that the company you acquired wasn't actually CMMC-compliant.

Who is liable? Does the DoD or the DoJ go after the leadership of the acquired company? Does the responsibility fall to you? Both?

This is the concept of risk, liability, and due diligence in mergers and acquisitions, or M&A. It's a very important concept to know about when it comes to government cybersecurity frameworks, especially CMMC.

This isn't just a thought experiment. Near the end of last year, the DoJ settled a case with a defense contractor and the company that acquired it, to the tune of $8.4 million dollars.

BLUF - Bottom Line Up Front

Liability travels with sensitive data: any firm that holds, has access to, or runs systems with controlled information must secure it. Buyers inherit seller faults through successor liability and can share False Claims Act penalties. Strong due diligence before a deal and prompt voluntary disclosure after a problem reduce risk. CMMC requires clear scope, system plans, and records. Centralized compliance tools help keep artifacts and proof ready.

You Can't Escape Liability

The key thing to understand, that underpins the actions of the DoD, the DoJ, and the Cyber-AB, is tracking responsibility and liability.

Too many people, in our experience, get bogged down with technical checklists, letter-of-the-law implementation, and loopholes based on precise language interpretation.

The truth is, it's all simple when you work at it from a conceptual level.

You Can't Escape Liability

CMMC exists to protect specific kinds of sensitive information. The responsibility for protecting that information is carried along with it. Any prime contractor, any subcontractor, any sub-subcontractor, no matter how far down the chain you go, has their responsibilities determined by the information.

Does the information reach the company? CMMC is required. Does the information pass through a system? That system must be secured. Does it enter an environment? The environment must be secured. Does an account have access? That account must be secured and the employee trained.

Viewed through that lens, the responsibility is clear. A company that fails to maintain CMMC security is liable for their faults. A company that acquires that company, unless they detect and immediately remedy those faults, is liable for the same.

Successor Liability: Inheriting Risk

When your company acquires another company, it's expected that you bring that company up to your standards. The assumption that the company is already up to your standards, or even the trust that they are when they say they are, is something you need to verify.

Successor Liability Inheriting Risk

Certainly, there are a lot of different kinds of mergers and acquisitions. Joint ventures, stock purchases, asset purchases, private equity; all of these present different, unique challenges to the leadership who are tasked with maintaining compliance.

As the aforementioned $8.4 million settlement showcases, liability is shared.

In the example, a contractor subsidiary was required by contract to implement security controls according to CMMC standards. They attested that they did, but failed to actually do so. They were spun off, renamed, and reorganized. Eventually, the case made its way through the system and came to the point of settlement.

Who ended up needing to pay that $8.4 million? All three entities. The former owners, the subsidiary itself, and the new owners all shared liability.

The shocking part, for many, is that the new owners share liability. The violations happened years before the new owners acquired the subsidiary, so why should the new owners be liable?

It comes down to successor liability. This isn't a term unique to CMMC or to government contracts, but rather is common throughout M&A.

When one company acquires the other, they get the bad with the good. They acquire the assets, control, and benefits, but along with it comes the debts, obligations, and liabilities. Those violations are part of the history of the subsidiary, and that history comes along with the acquisition.

The Source of the Punishment: FCA

The FCA is something we've talked about before. It's called the False Claims Act, and it's basically the "don't lie to the government" law. It has been around for over 150 years and serves as the primary mechanism by which companies are punished for making false claims to the government.

The Source Of The Punishment FCA

There have been many different initiatives, legislative pushes, memos, and other government errata to pursue various kinds of violations of government contracts and responsibilities. Most of them use the FCA as their primary enforcement mechanism.

Violations of the FCA are usually punished financially. Steep fines come alongside settlements and lawsuits, with huge numbers associated with each individual false claim made. Since CMMC, especially at Level 1, only requires self-assessment and attestation, those attestations can go on for quite a while before they're caught and punished.

When each attestation, each invoice sent, each record presumed to be secure when it's not can be considered a record, and each one can be punished by $250,000 or more in fines, the number adds up very quickly.

This is a lot of potential liability to take on when you acquire a company. How can you avoid it?

Due Diligence: the Route to Avoiding a Problem

There are a lot of different ways to structure a merger, acquisition, or other change in control and ownership. Pretty much all of them have a corresponding case somewhere in the recent roster of DoJ settlements that shows that it doesn't work to avoid liability.

Due Diligence The Route To Avoiding A Problem

A big example is private equity. Private equity firms are often buying and selling "ownership" by way of investment and advisement, to have a controlling stake without the responsibility of a full acquisition.

A DoJ case occurred where a private equity firm's employee disclosed CUI they shouldn't have to people not authorized to have it. When it was detected, the equity firm disclosed the breach and agreed to pay the FCA penalty.

Could the equity firm have avoided liability? Maybe, if they had been completely divorced from access to controlled systems. On the other hand, the DoJ has set its sights on private equity before, so it wouldn't be a surprise for it to happen again.

So, no matter what form of merger, acquisition, change in ownership, or transfer of company is occurring, liability is carried along with it. Again, it's simple; the information is still there, so the responsibility and liability are still there, along for the ride.

The way to mitigate this risk is through due diligence.

Due diligence is simply the responsibility to understand that liabilities come with any acquisition or merger, so they need to be investigated prior to closing a deal. Once the deal is closed, as you assume the assets, so too do you assume the liabilities.

If You Aren't CMMC Certified

If you're not CMMC certified, but you're acquiring a company that is, you have a lot of work ahead of you.

CMMC is not simple. There are a lot of responsibilities that come along with the government contracts it opens up. When you acquire a CMMC-certified company, it's your job to understand what needs to change to ensure compliance is carried through.

Since CMMC rides on the back of a system security plan, you need to understand what that plan is and what it says. More importantly, you need to understand what will change in terms of scoping and system boundaries as you merge companies and assets.

Even something as simple as adding new admin roles, sharing tasks and systems access, or adding new managers to a chain of command can have far-reaching impacts on the scoping and boundaries surrounding controlled and sensitive information.

If You Aren't CMMC Certified

There's a lot you can do to lay the groundwork for protection. Much of it you want to do prior to closing the deal, as a contingency or as part of your evaluation of whether or not the acquisition is worthwhile.

You can ask for copies of policies, processes, and procedures used for handling FCI and CUI. You can request copies of infosec policies, of SSPs, of POA&Ms, and of other kinds of documentation that comes along with CMMC, like incident responses and reports. You can request a history of incident reports.

It can be tricky to review this documentation if you don't know what you're looking at. You might even consider hiring a consultant to review SPRS information, check certification and attestation documents, and review scoping.

The nice thing about a framework like CMMC is that there are a lot of documents and artifacts that are part of compliance, which are not themselves secured assets, and which can be used to prove compliance.

If You Are CMMC Certified

If you already are CMMC-compliant, you know how much work it is to achieve and maintain compliance. You also know what to look for to make sure another entity is equally in compliance.

If You Are CMMC Certified

Fortunately, this means you're better equipped to evaluate any potential mergers and acquisitions. You already know how to write a system security plan, how to define boundaries and scope, how to evaluate security controls, and more.

This doesn't mean you'll have an easier time of it, though. You do still need to go through the work to get it done.

Uncovering Liability: What to Do if an Acquisition Goes Bad

Perhaps the most likely case of successor liability is where the company you're acquiring is currently CMMC-certified, but formerly wasn't. If they had made claims but had not upheld their security, they're liable for FCA violations. As the acquiring or merged company, you assume that liability.

Uncovering Liability What To Do If An Acquisition Goes Bad

How do you handle it if this happens?

If you haven't closed the deal yet, this can be the definition of a deal-breaker. Tell the company to get their act together and sort out their FCA liability, and then you'll consider it. If you've already closed, the situation is different.

As the private equity example showcases, the best thing you can do is voluntarily disclose the problem. Even if you weren't responsible, even if there are no current violations, a past violation is still a problem. It's also much better to disclose it when you're aware of it than to hide it until it's discovered. Whistleblowers are entitled to a portion of the payout for a reason, and it's specifically to encourage disclosure.

Remember, as far as the FCA is concerned, awareness of a false claim is all it takes to trigger a penalty. You don't have to have the intent to commit fraud to be penalized.

Security in Context: Broadened Scope, Tightened Rules

What this all comes down to, conceptually, is an extension of the government's overall push to expand cybersecurity compliance.

Security In Context Broadened Scope Tightened Rules

It goes hand in hand with another recent "change" that was not a change: the trickle-down of responsibility. The goal is not to rules-lawyer the letter of the law or to set up "gotcha" traps for companies to extort for fines. The goal is to protect information with as broad a scope as is reasonable to enforce.

When information flows down, it must be secured. When companies change ownership, new ownership must maintain responsibility. Liability cannot be shed through jumping through legal hoops, changing names and ownership, or otherwise ducking scrutiny. False claims can still trigger penalties years and leadership changes down the line.

It's all about closing loopholes and gaps in security. A subcontractor can't claim ignorance with the flowdown of information, and an acquiree cannot avoid liability by being acquired before penalties come home to roost.

Making it Easy with Ignyte

The Ignyte Platform is a powerful tool that is also uniquely positioned to help with this exact kind of problem. A company that uses our platform has a centralized dashboard with ready access to all of the reports, logs, artifacts, and tracking information necessary to prove compliance, with a history and a future mapped out.

Making It Easy With Ignyte

Whether you're just now dipping your toes into CMMC or you've been certified for years, whether you're acquiring or being acquired, whether you're merging or investing, the Ignyte Assurance Platform can help. To see just how it can benefit you in your specific situation, all you need to do is schedule a call for a free strategy session and demo of the platform.

We're deeply experienced with CMMC at all levels, both inside and out, and we're more than willing to lend a hand. Don't hesitate to reach out to discuss your needs.

Stay up to date with everything Ignyte