{"id":34185,"date":"2026-07-31T12:56:57","date_gmt":"2026-07-31T16:56:57","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=34185"},"modified":"2026-07-31T13:29:47","modified_gmt":"2026-07-31T17:29:47","slug":"ig-complaint-filed-against-stacy-bostjanick-alleging-multiple-felonies","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/ig-complaint-filed-against-stacy-bostjanick-alleging-multiple-felonies\/","title":{"rendered":"IG Complaint Filed Against Stacy Bostjanick Alleging Multiple Felonies"},"content":{"rendered":"<p>Oxebridge has filed a formal whistleblower complaint with the Dept. of War Inspector General&#8217;s office (DODIG) alleging multiple felonies by former &#8220;<em>CMMC architect<\/em>&#8221; Stacy Bostjanick.<\/p>\n<p>The complaint centers on Bostjanick&#8217;s sudden resignation from the DoD as head of the CMMC Program Management Office and immediate hire by CMMC C3PAO, Cybersec Investments. It also alleges that Bostjanick used her role as PMO head to block CMMC-related complaints that would have impacted companies such as Cybersec, and for immediately performing lobbying for CMMC while not registered under the Lobbying Disclosure Act (LDA).<\/p>\n<p>It is important to emphasize that the complaint highlights <em><strong>allegations<\/strong><\/em>, and that it is up to the Inspector General and the Department of Justice to determine if felonies were actually committed.<\/p>\n<p><span style=\"font-size: 18pt;\"><strong>History of Obstruction and Suppression<\/strong><\/span><\/p>\n<p>Bostjanick led the CMMC program for the DoD alongside Katie Arrington, and appeared at multiple events publicizing the program alongside various CMMC service providers. At least one event included Cybersec Investments, in which she gave a joint speech on CMMC alongside Cybersec&#8217;s Fernando Machado and assessor Tara Lemieux. She also consistently promoted the Cyber AB, which was created by the DoD to oversee the CMMC program.<\/p>\n<p>At the same time, Bostjanick personally blocked or ignored formal complaints filed with her office against the Cyber AB and various CMMC service providers, including C3PAOs. Between the period of March 2021 through March of 2025, Oxebridge filed nearly a dozen complaints against CMMC actors; Bostjanick took no action on any of them. Sometime in 2023, Bostjanick stopped replying to the complaints entirely. Some of these included serious matters such as a C3PAO issuing a forged CMMC assessment report that had been photoshopped with the DoD logo to appear as if it were an official government document.<\/p>\n<p>Bostjanick went so far as to overrule a formal FOIA request to release the DoD&#8217;s contract with the Cyber AB, going so far as to deny it even to the DODIG itself when presented with a FOIA. Federal contracts are required to be publicly available unless they include classified information, which the Cyber AB&#8217;s contract does not. In response to the FOIA, the DODIG reported that the documents produced by Bostjanick&#8217;s \u201c<em>do not consist of the contract described in your request<\/em>.\u201d Bostjanick then wrote in an email to Oxebridge that she decides what is &#8220;<em>of benefit<\/em>&#8221; to the American people, appearing to ignore FOIA law entirely.<\/p>\n<p>The relationship with Cybersec is problematic in that not only did Bostjanick help promote the company while acting in her official DoD role, but she also became employed by them in mere hours after announcing her retirement, suggesting she may have negotiated the employment while still acting in her government role. Just two months later, Cybersec hired her son, Mark Bostjanick Jr., as a &#8220;<em>Financial Analyst.<\/em>&#8221;<\/p>\n<p>The moves made by Bostjanick while at the DoD now appear to benefit Cybersec. For example, Cybersec later became &#8220;<em>accredited<\/em>&#8221; as a C3PAO to ISO 17020. However, the Cyber AB does not hold ISO 17011 accreditation itself, so it is not authorized to accredit any organization. Instead, it now appears that the Cyber AB outsourced ISO 17020 accreditation work to the US accreditation body ANAB. Because Bostjanick blocked the release of the Cyber AB&#8217;s contract, it is unknown if the use of ANAB by the Cyber AB violates that contract. Therefore, we cannot know if Cybersec&#8217;s &#8220;<em>accreditation<\/em>&#8221; is valid or not.<\/p>\n<p>ANAB has no record of Cybersec on its public registry of ISO 17020 accredited inspection bodies.<\/p>\n<p>Furthermore, Cybersec is now using Bostjanick to lobby the Senate Armed Services Committee on its behalf; however, neither Cybersec Investments nor Bostjanick herself appear in entries in the official LDA registry of registered lobbyists.<\/p>\n<p><span style=\"font-size: 18pt;\"><strong>Alleged Felony Violations<\/strong><\/span><\/p>\n<p>The initial filing with DODIG alleged multiple felony violations by Bostjanick. Specifically, these include:<\/p>\n<ul>\n<li><strong>18 U.S.C. Section 207(c)<\/strong> &#8211; requires a one-year &#8220;cooling off&#8221; period before a former Executive branch employee may make representational communications with, or appearances before, officers or employees of the executive branch on behalf of a third party with the intent to influence official action. Bostjanick appeared at an event representing Cybersec alongside her DoD replacement, Aaron Bishop.<\/li>\n<li><strong>18 U.S.C. Section 207(a)(1)<\/strong> &#8211; requires a lifetime ban for any former Executive branch employee if their work included conducting or overseeing administrative matters involving specific parties. Oxebridge argues that Bostjanick performed highly specific acts to benefit the Cyber AB and Cybersec, among others, through her willful suppression of complaints, FOIAs, and other actions that might have restricted those parties.<\/li>\n<li><strong>18 U.S.C. Section 208<\/strong> &#8211; governs acts by employees affecting a personal financial interest. Oxebridge argues Bostjanick&#8217;s actions while at the DoD were conducted to benefit parties whom she then intended to work with once leaving employment. If she negotiated her employment at Cybersec while at DoD, Oxebridge argues this is a violation. Oxebridge also argues that by Bostjanick used her public office for private gain by co-marketing Cybersec Investments while in her official DoD capacity.<\/li>\n<li><strong>5 C.F.R. Part 2635<\/strong> &#8211; defines Standards of Ethical Conduct. Oxebridge argues that Bostjanick clearly violated Subpart G (Misuse of Position) and Subpart A (creating the appearance of violating the law or ethical standards, and giving preferential treatment to a private organization).<\/li>\n<\/ul>\n<p>That complaint was filed with the DODIG early this morning. Only a half hour later, Bostjanick <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7488943497799094272\/\">posted on LinkedIn<\/a> that she had just been on a lobbying trip, on behalf of Cybersec Investments, at Senate Armed Services Committee members Senator Mike Rounds and Senator Rick Scott. This included a photo of herself and Cybersec CEO Fernando Machado outside the offices of the Armed Services Committee.<\/p>\n<p><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/07\/LinkedIn-post-07-31-2026.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-34187\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/07\/LinkedIn-post-07-31-2026.jpg\" alt=\"\" width=\"400\" height=\"692\" \/><\/a><\/p>\n<p>When Oxebridge founder Christopher Paris asked Bostjanick to &#8220;<em>explain why this is not a felony violation<\/em>,&#8221; she blocked Paris on LinkedIn.<\/p>\n<p>Oxebridge performed a search on the official LDA registry and found no entries for Bostjanick, Machado, or Cybersec Investments, suggesting any lobbying activities performed by them were illegal under 2 USC \u00a7 1601, as well as the other laws already cited.<\/p>\n<p><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/07\/bostjanicklda.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-34188\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2026\/07\/bostjanicklda.jpg\" alt=\"\" width=\"300\" height=\"455\" \/><\/a><\/p>\n<p>Oxebridge has submitted a supplemental report to the DODIG with the new evidence and is preparing new complaints with the Senate Armed Services Committee and other agencies against Bostjanick.<\/p>\n<p>Oxebridge is requesting the recipients forward the matters to the Dept. of Justice for criminal prosecution if felonies are believed to have occurred. A single felony under most of these laws would result in up to five years in prison, if Bostjanick were convicted.<\/p>\n<p>Bostjanick has gone on a campaign against the Small Business Administration (SBA) and the new Dept. of War CIO, Kirsten Davies, since her retirement and the DoD&#8217;s announcement of a 60-day pause on C3PAO certifications, which directly impacts Cybersec Investments. Davies launched a &#8220;<em>CMMC Reform Task Force&#8221;<\/em> to investigate the CMMC program.<\/p>\n<p>Some have suggested that Bostjanick was pushed out by the Davies team but allowed to announce her retirement, although this has not been independently confirmed by Oxebridge. The timing of the CMMC &#8220;<em>pause<\/em>&#8221; and Bostjanick&#8217;s sudden retirement would suggest the two are connected, however.<\/p>\n<p>Cybersec Investments was previously embroiled in a scandal after hiring Tara Lemieux, who appeared at the RASC event with Bostjanick. In 2020, Lemieux promised to do &#8220;free&#8221; CMMC assessments &#8220;<em>any damned day of the year<\/em>&#8221; out of patriotism. She posted an image of her hand on the American flag to demonstrate her seriousness. There is no evidence that Cybersec&#8217;s CMMC assessments are &#8220;<em>free<\/em>.&#8221;<\/p>\n<p><a href=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-23106\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost.jpg\" alt=\"\" width=\"400\" height=\"461\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost.jpg 565w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost-130x150.jpg 130w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost-21x24.jpg 21w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost-31x36.jpg 31w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2020\/11\/tarapost-42x48.jpg 42w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>Bostjanick appears to have used her DoD position to benefit herself and her new employer, Cybersec Investments.<\/p>","protected":false},"author":644,"featured_media":34193,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[7774,3],"tags":[7679,8917,7683,7699,8907,176,8909,8918,7681,7700,8919],"class_list":["post-34185","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cmmc","category-news","tag-cmmc","tag-cybersec-investments","tag-cybersecurity-maturity-model-certification","tag-dept-of-defense","tag-dept-of-war","tag-dod","tag-dow","tag-fernando-machado","tag-katie-arrington","tag-stacy-bostjanick","tag-tara-lemieux","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/644"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=34185"}],"version-history":[{"count":8,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34185\/revisions"}],"predecessor-version":[{"id":34196,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/34185\/revisions\/34196"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/34193"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=34185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=34185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=34185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}