Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

DOJ Continues Increased Cybersecurity Enforcement:  Honeywell Aerospace Agrees to $2M FCA Settlement for Cybersecurity Noncompliance on DoW Contracts

By Edwin O. Childs, Michael J. Podberesky, Brett Barnett, Abram J. Pafford, Jack White, John S. Moran, Sophie Marsh, Jason M. Vespoli, Léa Dickinson, John Sullivan & Joshua Davis on September 29, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On September 1, 2026, the U.S. Department of Justice (“DOJ”) announced a $2,042,518 False Claims Act (“FCA”) settlement with Honeywell Aerospace Inc. (“Honeywell Aerospace” or “Honeywell” or “the company”), resolving allegations that the company failed to comply with certain cybersecurity requirements in a contract with the U.S. Department of War (“DoW”). This settlement is the latest in a growing line of enforcement actions under DOJ’s Civil Cyber-Fraud Initiative and underscores the government’s continued willingness to use the FCA to hold defense contractors accountable for apparent failures to comply with cybersecurity-related requirements.

Specifically, the settlement resolves allegations that, from April 2020 through December 2023, Honeywell Aerospace (then operating as a business unit of Honeywell International) submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-171 with respect to one of Honeywell’s networks, as required by the applicable DoW regulations and the company’s DoW contracts. The company’s DoW contracts incorporated Defense Federal Acquisition Regulation Supplement (“DFARS”) clause 252.204-7012, which requires contractors and subcontractors handling Controlled Defense Information, including Controlled Unclassified Information (“CUI”) to implement, or have a plan to implement, the 110 security controls set forth in NIST SP 800-171 rev. 2. These controls span an array of categories, including access controls, audit and accountability, incident reporting, physical protection, and risk and security assessments.

The allegations that resulted in the settlement arose out of a qui tam whistleblower lawsuit under the FCA by a former Honeywell employee. The FCA’s qui tam provisions allow private citizens to sue on behalf of the government and share in any recovery under the claim.  The resolution was a coordinated effort between the DOJ Civil Division’s Commercial Litigation Branch, the U.S. Attorney’s Office for the Western District of North Carolina, and the Defense Criminal Investigative Service. The case is captioned United States ex rel. Rachel Tenney v. Honeywell International Inc., Civil Action No. 3:22-cv-129 (W.D.N.C.). As with many FCA settlements, the settlement expressly provided that the claims resolved constituted only allegations, with no determination or admission of liability.

Significance and Enforcement Context

The Honeywell Aerospace settlement continues in DOJ’s escalating cyber-enforcement posture. Specifically, in October 2021, DOJ launched the Civil Cyber-Fraud Initiative, which leverages the FCA to pursue government contractors and grant recipients that provide deficient cybersecurity products or services, misrepresent their cybersecurity practices, or violate obligations to monitor and report cybersecurity incidents. Since its inception, the Initiative has produced a growing series of settlements,  including the $9 million Aerojet Rocketdyne settlement in 2022 and the $1.75 million Aero Turbine/Gallant Capital settlement in July 2025. To that end, DOJ has reported that cybersecurity fraud resolutions have more than tripled in each of the past two fiscal years; in fiscal year 2025 alone, DOJ recovered $52 million across nine cyber-related FCA settlements, part of a record-breaking $6.8 billion in total FCA recoveries.

The Honeywell Aerospace case involved a multi-year period of alleged noncompliance with controls related to a single network, reinforcing that DOJ scrutiny extends not only to systemic failures, but also to lapses affecting discrete systems or enclaves. The case also highlights the central role of whistleblowers, with the qui tam relator being a former employee, consistent with DOJ’s observation that insider tips remain a primary driver of cybersecurity FCA enforcement.

The enforcement trend also comes as the government has paused implementation of the Cybersecurity Maturity Model Certification (“CMMC”) 2.0 program, which was poised to require third-party assessments for certain levels of contractor cybersecurity compliance. The CMMC 2.0 pause has, at a minimum, extended the use of certain cybersecurity self-certifications and may place more significance on enforcement actions as a means for ensuring compliance with cybersecurity requirements. The evolving regulatory landscape thus creates an increasingly challenging enforcement environment for contractors and subcontractors handling CUI.

Key Takeaways for Government Contractors

DoW contractors and subcontractors would be well served to continue to regularly evaluate their cybersecurity compliance postures, including in the following areas:

  1. Assess and document NIST SP 800-171 compliance rigorously. DoW contractors and subcontractors handling CUI should ensure that compliance with NIST SP 800-171 is not only implemented but also documented with current, scoped evidence. Having policies on paper is insufficient. Contractors may need to demonstrate that policies match operating practice and that gaps are identified, remediated, or formally accepted with a plan of action and milestones.
  2. Scope your compliance precisely.  The Honeywell Aerospace case involved alleged noncompliance on a single network. Contractors should define clear system boundaries for each covered contractor information system, ensure that applicable controls are implemented and tested within those boundaries, and verify the accuracy of any Supplier Performance Risk System (“SPRS”) scores before submission.
  3. Take whistleblower risk seriously. Many recent cybersecurity FCA cases have originated from qui tam relators, often current or former employees with inside knowledge of compliance gaps. DoW contractors and subcontractors should maintain robust internal reporting channels (as required under many government contracts), take employee cybersecurity concerns seriously, and investigate and address reported deficiencies promptly.
  4. Consider the value of voluntary self-disclosure. While the Honeywell Aerospace settlement was triggered by a whistleblower’s qui tam complaint, DOJ has demonstrated (as in the recent Aero Turbine/Gallant Capital matter) that it will credit contractors that self-disclose cybersecurity violations, cooperate with investigations, and take prompt remedial action. Contractors that identify compliance gaps may wish to carefully evaluate whether voluntary self-disclosure may mitigate potential FCA exposure.
  5. Prepare for the evolving regulatory landscape. With CMMC 2.0 implementation paused, the importance of cybersecurity self-certifications by defense contractors may be subject to increased scrutiny, including through Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”) and other DoW subagency audits or assessments. Contractors may wish to continue evaluating their readiness for third-party assessments and monitoring developments in both DFARS and CMMC requirements, given that those requirements mirror the DFARS 252.204-7012 requirements that are already mandatory under all DoW contracts involving CUI.

For questions about this settlement, the Cyber-Fraud Initiative, or how these developments may affect your organization’s government contracts or cybersecurity programs, please contact a member of the McGuireWoods Government Contracts or Data Privacy & Cybersecurity teams.

Photo of Edwin O. Childs Edwin O. Childs

As a leader of the firm’s Defense, National Security and Government Contracting industry team, Ned Childs is a government contract and investigations and enforcement attorney who represents companies across a wide range of sectors, including the defense, services, technology, and aerospace industries. His…

As a leader of the firm’s Defense, National Security and Government Contracting industry team, Ned Childs is a government contract and investigations and enforcement attorney who represents companies across a wide range of sectors, including the defense, services, technology, and aerospace industries. His practice, spanning more than a decade in Washington, encompasses a broad array of legal services, including government contract investigations, disclosures, and regulatory enforcement actions; bid protests and government contract disputes; government contract counseling; export licensing and enforcement; prime contractor-subcontractor disputes; corporate ownership and acquisition issues; and election law investigations and enforcement matters.

Read more about Edwin O. ChildsEmail
Show more Show less
Photo of Michael J. Podberesky Michael J. Podberesky

Michael Podberesky, a former federal prosecutor in the U.S. Department of Justice’s Civil Fraud Section, is a partner in the firm’s nationally recognized Government Investigations and White Collar Litigation Department and co-leader of the firm’s Healthcare Litigation and Enforcement Practice Group. Employing his…

Michael Podberesky, a former federal prosecutor in the U.S. Department of Justice’s Civil Fraud Section, is a partner in the firm’s nationally recognized Government Investigations and White Collar Litigation Department and co-leader of the firm’s Healthcare Litigation and Enforcement Practice Group. Employing his extensive experience with False Claims Act cases in the healthcare and defense sectors, Michael represents clients confronting high-stakes government investigations and litigation arising from allegations of healthcare and procurement fraud and also counsels clients regarding compliance issues.

Read more about Michael J. PodbereskyEmail
Show more Show less
Photo of Brett Barnett Brett Barnett

Brett is the co-leader of McGuireWoods’ False Claims Act Investigations & Litigation Practice Group. He focuses his practice on representing clients in high-stakes False Claims Act matters, healthcare fraud and abuse investigations, and complex commercial litigation across the country. Brett routinely leads internal…

Brett is the co-leader of McGuireWoods’ False Claims Act Investigations & Litigation Practice Group. He focuses his practice on representing clients in high-stakes False Claims Act matters, healthcare fraud and abuse investigations, and complex commercial litigation across the country. Brett routinely leads internal and government-facing investigations involving the U.S. Department of Justice and other federal and state agencies, and defends clients in civil FCA litigation, often involving parallel proceedings and regulatory scrutiny.

Read more about Brett BarnettEmail
Show more Show less
Photo of Abram J. Pafford Abram J. Pafford

Abe focuses his practice on protecting the rights and interests of companies and individuals who face disputes or conflicts with the federal government in its role as purchaser, prosecutor, and chief regulator. For more than twenty years, Abe has represented government contractors, participants…

Abe focuses his practice on protecting the rights and interests of companies and individuals who face disputes or conflicts with the federal government in its role as purchaser, prosecutor, and chief regulator. For more than twenty years, Abe has represented government contractors, participants in regulated industries, and companies and individuals targeted for federal investigation or prosecution, consistently achieving successful results for clients confronting difficult odds.

Read more about Abram J. PaffordEmail
Show more Show less
Photo of Jack White Jack White

Jack is an accomplished trial lawyer and legal strategist who guides clients through complex challenges, including high-profile and sensitive litigation and government investigations. He focuses his practice on civil litigation, regulatory enforcement, and congressional investigations for clients in the defense, technology, federal contracting…

Jack is an accomplished trial lawyer and legal strategist who guides clients through complex challenges, including high-profile and sensitive litigation and government investigations. He focuses his practice on civil litigation, regulatory enforcement, and congressional investigations for clients in the defense, technology, federal contracting, higher and K-12 education, and other business sectors.

Read more about Jack WhiteEmail
Show more Show less
Photo of John S. Moran John S. Moran

John Moran is a member of the firm’s nationally recognized Government Investigations and White Collar Litigation department. A former senior official at the U.S. Department of Justice (DOJ) and the White House and an experienced litigator and counselor, John draws on his broad…

John Moran is a member of the firm’s nationally recognized Government Investigations and White Collar Litigation department. A former senior official at the U.S. Department of Justice (DOJ) and the White House and an experienced litigator and counselor, John draws on his broad experience from private practice and government service to advise and represent clients in government enforcement, congressional investigations, high-stakes civil disputes, and regulatory litigation. He also serves as co-chair of the firm’s Congressional Investigations practice, representing both companies and individuals in congressional investigations and hearings and is a member of the firm’s Appeals & Issues group.

Read more about John S. MoranEmail
Show more Show less
Photo of Sophie Marsh Sophie Marsh

Sophie focuses her practice on government contracts and government investigations matters.

Read more about Sophie MarshEmail
Photo of Jason M. Vespoli Jason M. Vespoli

Jason focuses his practice on federal and state procurement, government technology, bid protests and government contract disputes, and regulatory compliance. He utilizes experience in state government, government technology, and complex procurement to solve problems in innovative and efficient ways.

Read more about Jason M. VespoliEmail
Photo of Léa Dickinson Léa Dickinson

Léa focuses her practice on government contracts, government investigations, regulatory compliance, and white collar defense. She advises clients on contract performance disputes, alternative dispute resolution, litigation, and small business issues for government contractors and assistance awardees. Léa holds a certification from the Organization…

Léa focuses her practice on government contracts, government investigations, regulatory compliance, and white collar defense. She advises clients on contract performance disputes, alternative dispute resolution, litigation, and small business issues for government contractors and assistance awardees. Léa holds a certification from the Organization for Economic Cooperation and Development’s (OECD) Nuclear Energy Agency in International Nuclear Law Essentials.

Read more about Léa DickinsonEmail
Show more Show less
Photo of John Sullivan John Sullivan

John is an associate within the Government Investigations and White Collar Litigation group.

Read more about John SullivanEmail
Photo of Joshua Davis Joshua Davis
Email
  • Posted in:
    Corporate Governance and Compliance, Government Contracts, Privacy and Cybersecurity
  • Blog:
    Subject to Inquiry
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo