On September 1, 2026, the U.S. Department of Justice (“DOJ”) announced a $2,042,518 False Claims Act (“FCA”) settlement with Honeywell Aerospace Inc. (“Honeywell Aerospace” or “Honeywell” or “the company”), resolving allegations that the company failed to comply with certain cybersecurity requirements in a contract with the U.S. Department of War (“DoW”). This settlement is the latest in a growing line of enforcement actions under DOJ’s Civil Cyber-Fraud Initiative and underscores the government’s continued willingness to use the FCA to hold defense contractors accountable for apparent failures to comply with cybersecurity-related requirements.
Specifically, the settlement resolves allegations that, from April 2020 through December 2023, Honeywell Aerospace (then operating as a business unit of Honeywell International) submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-171 with respect to one of Honeywell’s networks, as required by the applicable DoW regulations and the company’s DoW contracts. The company’s DoW contracts incorporated Defense Federal Acquisition Regulation Supplement (“DFARS”) clause 252.204-7012, which requires contractors and subcontractors handling Controlled Defense Information, including Controlled Unclassified Information (“CUI”) to implement, or have a plan to implement, the 110 security controls set forth in NIST SP 800-171 rev. 2. These controls span an array of categories, including access controls, audit and accountability, incident reporting, physical protection, and risk and security assessments.
The allegations that resulted in the settlement arose out of a qui tam whistleblower lawsuit under the FCA by a former Honeywell employee. The FCA’s qui tam provisions allow private citizens to sue on behalf of the government and share in any recovery under the claim. The resolution was a coordinated effort between the DOJ Civil Division’s Commercial Litigation Branch, the U.S. Attorney’s Office for the Western District of North Carolina, and the Defense Criminal Investigative Service. The case is captioned United States ex rel. Rachel Tenney v. Honeywell International Inc., Civil Action No. 3:22-cv-129 (W.D.N.C.). As with many FCA settlements, the settlement expressly provided that the claims resolved constituted only allegations, with no determination or admission of liability.
Significance and Enforcement Context
The Honeywell Aerospace settlement continues in DOJ’s escalating cyber-enforcement posture. Specifically, in October 2021, DOJ launched the Civil Cyber-Fraud Initiative, which leverages the FCA to pursue government contractors and grant recipients that provide deficient cybersecurity products or services, misrepresent their cybersecurity practices, or violate obligations to monitor and report cybersecurity incidents. Since its inception, the Initiative has produced a growing series of settlements, including the $9 million Aerojet Rocketdyne settlement in 2022 and the $1.75 million Aero Turbine/Gallant Capital settlement in July 2025. To that end, DOJ has reported that cybersecurity fraud resolutions have more than tripled in each of the past two fiscal years; in fiscal year 2025 alone, DOJ recovered $52 million across nine cyber-related FCA settlements, part of a record-breaking $6.8 billion in total FCA recoveries.
The Honeywell Aerospace case involved a multi-year period of alleged noncompliance with controls related to a single network, reinforcing that DOJ scrutiny extends not only to systemic failures, but also to lapses affecting discrete systems or enclaves. The case also highlights the central role of whistleblowers, with the qui tam relator being a former employee, consistent with DOJ’s observation that insider tips remain a primary driver of cybersecurity FCA enforcement.
The enforcement trend also comes as the government has paused implementation of the Cybersecurity Maturity Model Certification (“CMMC”) 2.0 program, which was poised to require third-party assessments for certain levels of contractor cybersecurity compliance. The CMMC 2.0 pause has, at a minimum, extended the use of certain cybersecurity self-certifications and may place more significance on enforcement actions as a means for ensuring compliance with cybersecurity requirements. The evolving regulatory landscape thus creates an increasingly challenging enforcement environment for contractors and subcontractors handling CUI.
Key Takeaways for Government Contractors
DoW contractors and subcontractors would be well served to continue to regularly evaluate their cybersecurity compliance postures, including in the following areas:
- Assess and document NIST SP 800-171 compliance rigorously. DoW contractors and subcontractors handling CUI should ensure that compliance with NIST SP 800-171 is not only implemented but also documented with current, scoped evidence. Having policies on paper is insufficient. Contractors may need to demonstrate that policies match operating practice and that gaps are identified, remediated, or formally accepted with a plan of action and milestones.
- Scope your compliance precisely. The Honeywell Aerospace case involved alleged noncompliance on a single network. Contractors should define clear system boundaries for each covered contractor information system, ensure that applicable controls are implemented and tested within those boundaries, and verify the accuracy of any Supplier Performance Risk System (“SPRS”) scores before submission.
- Take whistleblower risk seriously. Many recent cybersecurity FCA cases have originated from qui tam relators, often current or former employees with inside knowledge of compliance gaps. DoW contractors and subcontractors should maintain robust internal reporting channels (as required under many government contracts), take employee cybersecurity concerns seriously, and investigate and address reported deficiencies promptly.
- Consider the value of voluntary self-disclosure. While the Honeywell Aerospace settlement was triggered by a whistleblower’s qui tam complaint, DOJ has demonstrated (as in the recent Aero Turbine/Gallant Capital matter) that it will credit contractors that self-disclose cybersecurity violations, cooperate with investigations, and take prompt remedial action. Contractors that identify compliance gaps may wish to carefully evaluate whether voluntary self-disclosure may mitigate potential FCA exposure.
- Prepare for the evolving regulatory landscape. With CMMC 2.0 implementation paused, the importance of cybersecurity self-certifications by defense contractors may be subject to increased scrutiny, including through Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”) and other DoW subagency audits or assessments. Contractors may wish to continue evaluating their readiness for third-party assessments and monitoring developments in both DFARS and CMMC requirements, given that those requirements mirror the DFARS 252.204-7012 requirements that are already mandatory under all DoW contracts involving CUI.
For questions about this settlement, the Cyber-Fraud Initiative, or how these developments may affect your organization’s government contracts or cybersecurity programs, please contact a member of the McGuireWoods Government Contracts or Data Privacy & Cybersecurity teams.