In cybersecurity and privacy, low-cost compliance can look attractive. Budgets are tight. Deadlines are real. Buyers want speed. But when a provider promises audit-ready compliance at a price so low it seems impossible, leaders should pause.
Recent public reporting around Delve has intensified that warning. A widely circulated article, Delve - Fake Compliance as a Service - Part I, alleges that Delve helped create or support misleading compliance evidence and that hundreds of companies may have been affected. Those allegations are serious, and organizations should treat them as a broader lesson: if compliance is sold as a shortcut, it may become a liability rather than a safeguard.
Fake or fraudulent compliance usually does not begin with a forged certificate. It starts earlier:
- Controls are described as operating when they are not.
- Evidence is templated, recycled, or backfilled.
- Screenshots replace real governance.
- Vendors market “fast” and “cheap” outcomes without the work needed to support them.
- Executives assume a report equals security and fraudulently attests to it.
This is compliance theater: the appearance of assurance without the substance.
In the Delve allegations, the concern is not just one vendor. It is the business model behind “too good to be true” compliance.
If a provider can deliver a complex attestation unusually quickly and inexpensively, buyers should ask what was skipped, simulated, or misrepresented.
Real compliance requires interviews, control design, evidence review, remediation, testing, and executive accountability. That takes time and qualified labor.
When the price is dramatically below market, one of three things is often happening:
1. Scope is being quietly reduced.
2. Testing is superficial or rubber-stamped.
3. Evidence is being manufactured, reused, or accepted without proper validation.
That creates risk for both the provider and the customer. The customer may believe it is protected in sales, contracting, cyber insurance, or regulatory disclosures when it is not.
The U.S. Federal Trade Commission has repeatedly taken action against companies that falsely claimed participation in privacy frameworks such as EU-U.S. Privacy Shield and Safe Harbor. The legal principle is straightforward: if you claim certification or compliance you do not actually hold, regulators may treat that as deceptive conduct and fraud.
That matters beyond privacy frameworks. The same logic can apply when a company markets itself as compliant, audit-ready, or independently validated without a defensible basis.
The SEC has pursued companies for materially misleading cybersecurity disclosures.
- In 2024, the SEC charged four companies for misleading cyber-risk disclosures tied to the SolarWinds compromise.
- In 2023, the SEC also charged SolarWinds and its CISO, alleging misleading statements about cybersecurity practices and known risks.
The takeaway is clear: if a company publicly overstates its controls, governance, or readiness, the issue can move from marketing puffery to securities enforcement.
For government contractors, false compliance claims can expose them to False Claims Act liability. DOJ settlements involving Raytheon, Nightwing, and Verizon Business show that alleged failures to meet cybersecurity contract requirements can become expensive enforcement matters when companies certify compliance they did not actually achieve.
For defense contractors and regulated suppliers, this is especially relevant. A false statement about compliance is not just a branding problem. It can become a fraud allegation.
Deceptive or misleading claims about certification, privacy, or security controls can result in an FTC judgment against your company. It's important to note that the FTC regulates all entities that provide services to anyone in the USA; thus, any entity doing business in the USA is regulated by the FTC.
Misleading disclosures to investors about cyber controls, incidents, or governance.
False Claims Act exposure where compliance representations affect government contracts or payments. This is a major consideration when dealing with CMMC.
Unfair or deceptive trade practice claims that indicate criminal fraud.
- Breach of customer security addenda or representations and warranties.
- Termination rights triggered by false certifications.
- Indemnity claims after a failed audit, breach, or vendor review.
- Lost deals when enterprise buyers discover the compliance posture is unreliable.
- Insurance coverage disputes if underwriting relied on inaccurate control statements.
- Emergency remediation under deadline pressure.
- Re-performance of audits and assessments.
- Board scrutiny and reputational damage.
- Delayed sales cycles and failed procurement reviews.
If a compliance service is dramatically cheaper than credible alternatives, ask:
- Who is performing the testing, and what are their qualifications?
- How is evidence collected and validated?
- What controls are independently tested versus self-attested?
- Is the auditor truly independent?
- What happens when evidence is missing or a control fails?
- Can the provider explain the methodology in plain English?
- Does the timeline make sense for the scope?
If those answers are vague, the low price may be hiding a high downstream cost.
Compliance should reduce risk, strengthen trust, and support growth. Fake compliance does the opposite. It creates a paper shield that can collapse under customer diligence, regulator scrutiny, litigation, or breach response.
If the promise is “fast, cheap, and effortless,” leaders should assume the real question is not whether they are buying compliance. It is whether they are buying exposure.
Arrakis has built over several months numerous platforms that can help reduce risk. Read more here and those platforms are listed below.
- Compliance Chatbot - a free chatbot relating to compliance, cybersecurity, and privacy.
- Prosikon - A feature rich vendor due diligence platform to help increase visibility and provide more information for safer decisions. Read more here.
- PolicyForge - Build out your policies based on the regulatory environment you care about. Policy and Procedure Templates are included as well as control mapping. Read more here.
- Fortuna Risk Compass - Feature rich risk assessment platform that helps you visualize risk and cost better. Numerous graphical displays and ability to export risks to Prothesis. Read more here.
- Prothesis PoAM Builder - Build your PoAMs to prove you are mitigating risk and demonstrating maturity. Expands on Fortuna risks and demonstrates the "why" on the need for PoAMs. Read more here.
- Mutina SecurePath - Construct your SSPs to meet CMMC, or other frameworks, to provide assurance to external parties. SSPs are required for CMMC compliance. Read more here.
- CyberPrep Test Engine - A subscription based practice test platform covering 50+ certifications. Designed to be more difficult than the actual test to increase certification chances.
Regardless of the platforms, Arrakis suggests contracting professional consultation when seeking certification or compliance.
- Delve - Fake Compliance as a Service - Part I (Substack)
- FTC press releases on false Privacy Shield and Safe Harbor claims
- SEC Press Release 2024-174 on misleading cyber disclosures
- SEC Press Release 2023-227 on SolarWinds and cybersecurity statements
- DOJ press releases on Raytheon/Nightwing and Verizon cybersecurity-related False Claims Act settlements