# DOJ Clarifies FCA Liability Standards

The U.S. Department of Justice’s revised Justice Manual clarifies that agency guidance alone generally cannot establish False Claims Act liability against federal contractors; the underlying obligation must come from a statute, regulation, or enforceable contract term. Guidance may still be relevant evidence of a contractor’s knowledge, materiality, or industry practice, so the distinction matters when contractors assess certifications and requirements, including cybersecurity-related requirements.

- Contractors should trace each material requirement to its legal source and review whether contract clauses or certifications incorporate it as an enforceable obligation.
- The clarification does not make agency guidance irrelevant: it may still inform how the government evaluates knowledge, materiality, or industry practice in a False Claims Act matter.
- Procurement and compliance teams should assess whether cybersecurity or other agency guidance has been made binding through statute, regulation, or contract language before treating it as a mandatory contractual obligation.

**Jurisdictions:** federal
**Topics:** Regulatory Compliance, Policy
**Published:** October 05, 2026

### Government Entities
- U.S. Department of Justice (DOJ)

### Sources
- [DOJ Clarifies When Agency Guidance Can Support FCA Liability - Ogletree](https://ogletree.com/insights-resources/blog-posts/doj-clarifies-when-agency-guidance-can-support-fca-liability) - Ogletree