Honeywell Aerospace Inc. (Honeywell) agreed to pay $2,042,518 to resolve allegations that it violated the False Claims Act (FCA) by failing to comply with cybersecurity requirements in a Department of Defense (DoD) contract. The settlement covers alleged noncompliance from April 2020 through December 2023, during which time Honeywell allegedly submitted claims for payment while failing to meet the cybersecurity standards required by its government contract.
The government alleged that Honeywell failed to implement the security controls required by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, which were incorporated into its DoD contract through the Defense Federal Acquisition Regulation Supplement (DFARS). Under DFARS clause 252.204-7012, contractors handling controlled unclassified information (CUI) must implement the 110 security controls in NIST SP 800-171 to safeguard that information on their systems.
The allegations arose from a whistleblower lawsuit filed under the False Claims Act’s qui tam provision, which allows private citizens to sue on behalf of the government and share in any recovery. This type of qui tam action is not an anomaly. Whistleblowers, often current or former employees, have been the catalyst in other recent cybersecurity FCA settlements. Employees who have information regarding potential false claims have both the legal right and a significant financial incentive to pursue a qui tam action. The government has made cybersecurity compliance a priority in recent years. In Fiscal Year 2025, DOJ cybersecurity settlements alone totaled $52 million, more than triple the prior year.
Link to What Contractors Should Do Now What Contractors Should Do Now
The Honeywell settlement is a reminder that cybersecurity compliance in the federal contracting space demands ongoing attention and diligence. Contractors should:
- Review contracts carefully. The first step to ensuring compliance with federal cybersecurity requirements is to know exactly what your contract requires.
- Implement and maintain required controls. Do not wait for an audit or a whistleblower complaint to ensure compliance with the cybersecurity requirements. Identify deficiencies through regular internal reviews and remediate them promptly.
- Maintain a culture of compliance. The best way to avoid an FCA allegation is to maintain a company culture that values contract compliance and ethical responsibility.
- Monitor subcontractors. Government contract cybersecurity requirements often are required to be flowed down to subcontractors handling covered defense information. Prime contractors face significant potential consequences for failing to ensure compliance by their subcontractors.
- Stay current on regulatory developments. The cybersecurity compliance landscape for government contractors is constantly evolving, and regulatory changes can have significant implications for your obligations. For example, DoD’s indefinite suspension of CMMC Phase II on July 13, 2026 eliminated the upcoming third-party certification requirement, but it did not relieve contractors of their underlying obligations under DFARS 252.204-7012 to implement NIST SP 800-171 security controls and report cyber incidents. Contractors should consult with legal counsel to understand how regulatory developments may affect their specific compliance obligations.
