← All Briefings

Directors and Officers Liability and False Claims Act Exposure for Government Contractors in 2026

For a company that sells to the federal government, the sharpest liability of 2026 is not a jobsite injury or a data breach. It is the allegation that the company billed the government for something it should not have. The False Claims Act is the statute that turns that allegation into exposure, and the Department of Justice recovered a record $6.8 billion under it in the fiscal year ending September 30, 2025 — the highest single-year total in the Act’s history. Whistleblowers filed 1,297 qui tam suits, breaking the prior record, while the Department opened 401 investigations of its own. The question for a contractor’s leadership is no longer whether the enforcement environment is active. It is whether the company’s insurance answers when that environment turns toward them.

The False Claims Act reaches any knowingly false claim for federal payment — an inflated invoice, a product that does not meet specification, a certification of compliance that was not true, a cybersecurity attestation the company could not support. Its teeth are in the arithmetic: liability runs to three times the government’s damages plus a per-claim penalty, and each individual invoice can be a separate claim. A billing practice that felt like a gray area can compound into a number that threatens the enterprise. And the “knowing” standard reaches reckless disregard, not only intent, which means a documentation failure can carry the same exposure as a deliberate one.

Health care drew the largest share of the FY2025 dollars, at $5.7 billion, but procurement and defense contractors sit squarely in the enforcement lens. The Department’s Civil Cyber-Fraud Initiative has continued to advance cases against contractors that misrepresented their compliance with federal cybersecurity requirements — the same CMMC and DFARS obligations that already dominate a govcon’s compliance calendar. A false cybersecurity attestation is now a False Claims Act theory, which fuses two exposures a contractor once treated as separate.

The exposure does not stop at the company. FCA matters routinely name the individuals who signed the certifications and directed the billing — officers, and at times directors — and the government has been explicit for a decade about pursuing individual accountability. Defense costs alone in an FCA investigation are substantial, and they arrive long before any finding of liability. This is the terrain directors-and-officers liability insurance is built for: it funds the defense of the individuals and the entity when a claim or investigation targets their conduct in running the business.

The coverage is essential and, in the False Claims Act context, complicated, and three issues recur. First, most D&O policies exclude coverage for fraud and for the return of ill-gotten gains — but that exclusion typically applies only after a final adjudication of actual fraud, so the defense of a contested matter and the settlement of one can remain covered; the wording of that carve-back is decisive. Second, treble damages and civil penalties raise insurability questions that vary by policy and by state law, and a contractor cannot assume the punitive multiple is covered. Third, timing matters intensely: an FCA matter often begins as a sealed qui tam complaint or a Civil Investigative Demand, and whether that early stage triggers the policy’s claim definition and reporting clock can decide whether coverage responds at all.

D&O is not the only policy in the conversation. Contractors performing professional services — engineering, information technology, consulting — may find that errors-and-omissions coverage responds to some FCA theories tied to the quality of the work, while D&O answers the management conduct. The two policies have to be read together, with attention to which one responds to a given allegation and whether their definitions and exclusions leave a seam. A contractor that carries both but has never mapped how they interact is carrying an assumption, not a plan.

For a federal contractor, the structural questions are specific. The company should confirm that its D&O policy does not exclude regulatory or governmental claims outright, that the fraud exclusion requires final adjudication rather than mere allegation, that defense costs are covered and adequate given the length of an FCA investigation, that Side A coverage protects individual officers when the company cannot indemnify them, and that the reporting provisions capture a Civil Investigative Demand or a sealed complaint at the earliest stage. These are not default terms — they are negotiated ones, and the negotiation happens at placement, not after a subpoena arrives.

Our four-step Strategic Process is built to align that program with the enforcement reality. Strategic Discovery maps the certifications the company makes — cybersecurity, cost accounting, small-business status, country of origin — because each is a potential False Claims Act theory. Risk Assessment measures the D&O and E&O programs against where a claim would actually land and where defense costs would accrue. Solution Design negotiates the exclusions, the notice provisions, and the limits against the length and cost of a federal investigation. Ongoing Optimization keeps the program current as enforcement priorities and the contract portfolio shift. In a year when False Claims Act recoveries set a record, the contractors who treat their management-liability program as a controlled discipline — rather than a certificate in a drawer — are the ones who will meet an investigation from a position of strength.

Sources