Honeywell Aerospace’s $2 Million Cybersecurity Settlement: The False Claims Act Keeps Finding NIST 800-171 Gaps

The Justice Department announced a settlement with Honeywell Aerospace requiring the company to pay $2,042,518 to resolve allegations that it violated the False Claims Act by failing to meet cybersecurity requirements built into a Department of Defense contract. This case adds to a growing body of enforcement actions confirming that DOJ’s Civil Cyber-Fraud Initiative is not slowing down, and it’s a useful reminder that cybersecurity compliance failures don’t need to result in an actual breach to generate significant False Claims Act exposure.
What the Government Alleged
According to DOJ’s announcement, the allegations cover the period from April 2020 through December 2023, during which a business unit of Honeywell International submitted claims for payment while failing to comply with the cybersecurity requirements specified in NIST Special Publication 800-171, as applied to one of the company’s networks. NIST SP 800-171 is the federal cybersecurity standard that governs how contractors must protect controlled unclassified information, and compliance with it is a standard contractual and regulatory requirement built into defense contracts handling that category of government data. The government’s theory here follows the now-familiar False Claims Act framework applied throughout the Civil Cyber-Fraud Initiative: when a contractor certifies or represents that it meets required cybersecurity standards in order to obtain payment under a government contract, and that representation turns out to be false, the resulting claims for payment can themselves become actionable false claims, independent of whether any actual data breach or security incident ever occurred.
It’s worth being precise about what DOJ’s press release does and doesn’t say here. The claims resolved by the settlement are allegations only, and DOJ’s release explicitly notes there has been no determination of liability. Honeywell Aerospace, now a standalone public company as of June 29, was previously a business segment of Honeywell International, and the settlement is being announced under Honeywell Aerospace’s name even though the underlying conduct occurred while it operated as part of the larger Honeywell International structure.
The Whistleblower’s Role

This case originated from a whistleblower lawsuit filed under the False Claims Act’s qui tam provisions, which allow private citizens with knowledge of fraud against the government to bring suit on the government’s behalf and share in any resulting recovery. The whistleblower here, Rachel Tenney, a former Honeywell employee, will receive $375,823 as her share of the settlement, just under 20 percent of the total recovery. That relator’s share sits within the typical range courts and DOJ award in qui tam matters and reflects a now well-established pattern in cybersecurity-related False Claims Act cases: these matters are frequently surfaced not through government audits or external security assessments, but through insiders, often IT, security, or compliance personnel, who have direct visibility into gaps between what a contractor represents to the government about its security posture and what its systems actually look like in practice.
Why This Case Fits a Clear Enforcement Pattern
DOJ’s public statements accompanying this settlement make the enforcement priority explicit. Assistant Attorney General Brett Shumate stated that government contractors obtaining defense information while administering their contracts must follow required cybersecurity standards, and that the department will continue investigating potential violations of these requirements to protect that information. U.S. Attorney Russ Ferguson for the Western District of North Carolina reinforced the same point, noting that cybersecurity requirements exist specifically to protect government systems and prevent unauthorized access to government data, and that companies profiting from government contracts have an obligation to ensure that sensitive data is actually protected, not just formally certified as protected on paper.
This case was handled jointly by DOJ’s Civil Division Commercial Litigation Branch, the U.S. Attorney’s Office for the Western District of North Carolina, and the Defense Criminal Investigative Service, a coordination pattern that reflects how seriously the government now treats cybersecurity compliance failures tied to defense contracting: not as a narrow contractual or IT issue, but as a matter warranting the same interagency law enforcement coordination applied to other significant fraud matters.
What This Means for Government Contractors
The Honeywell Aerospace settlement reinforces several lessons that should already be familiar to any organization holding defense contracts involving controlled unclassified information, but that bear repeating given how frequently they continue to generate enforcement action.
First, cybersecurity compliance representations made in connection with government contracts are being treated as material to the government’s payment decision, meaning a gap between actual network security practices and required NIST SP 800-171 controls can generate False Claims Act liability even absent any breach, data loss, or known compromise. Contractors should not assume that the absence of an actual security incident insulates them from liability for underlying compliance gaps.

Second, this remains a whistleblower-driven enforcement area. Organizations holding defense contracts with cybersecurity compliance obligations should assume that internal personnel, particularly those with direct technical visibility into network security posture, are a realistic and increasingly common source of enforcement referrals, which means internal reporting channels and genuine responsiveness to raised security concerns matter as much as the underlying technical controls themselves.
Third, the multi-year window covered by this settlement, spanning nearly four years from 2020 through 2023, illustrates how these compliance gaps tend to persist quietly across many billing cycles before surfacing through litigation, which underscores the value of periodic, genuinely independent verification of NIST SP 800-171 compliance status rather than relying on point-in-time attestations that may not reflect a network’s actual, current security configuration.
Any organization holding, or seeking to hold, a Department of Defense contract involving controlled unclassified information should treat this settlement as confirmation that DOJ’s Civil Cyber-Fraud Initiative remains an active, well-resourced enforcement priority, and that closing the gap between documented cybersecurity compliance and actual network security practice is not a discretionary IT project. It’s a genuine False Claims Act exposure that continues to generate multimillion-dollar settlements years after the underlying conduct occurred.











