Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Sports
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Advanced Manufacturing and Industrials
    • Art and Cultural Property
    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Entertainment & Sports
    • Financial Institutions
    • Healthcare
    • Higher Education
    • Infrastructure
    • Nonprofit Organizations
    • Real Estate
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Alerts
    4. Honeywell settlement shows FCA risk for NIST 800-171 gaps

      Alerts

    Alert / Government Contracts

    Honeywell settlement shows FCA risk for NIST 800-171 gaps

    Sep 9, 2026

    LinkedInX (Twitter)EmailCopy URL

    Honeywell Aerospace will pay $2.04M to resolve allegations of NIST SP 800-171 failures—a reminder that DFARS cyber duties bind contractors even with CMMC Phase II paused.

    What’s the impact?

    • The over two million dollar settlement confirms DOJ’s Civil Cyber-Fraud Initiative is active and that failing to meet NIST SP 800-171 controls required by DFARS 252.204-7012 can drive False Claims Act liability.
    • A pause on CMMC Phase II does not suspend the existing, independent duty to safeguard covered defense information under DFARS 252.204-7012 and NIST SP 800-171.
    • Invoicing while knowingly out of compliance can turn routine payment claims into “false” claims, exposing contractors to whistleblower suits, treble damages, and penalties.

    DOWNLOAD

    Honeywell settlement shows FCA risk for NIST 800-171 gap (PDF)

    Authors

    • Cara A. Wulf

      Partner
      • Washington, DC +1 202.585.8337
      • cwulf@nixonpeabody.com
      Cara A. Wulf
    • Peter I. Belk

      Partner
      • Washington, DC +1 202-585-8035
      • pbelk@nixonpeabody.com
      Peter I. Belk
    • Adam R. Tarosky

      Partner / Leader, False Claims Act Team
      • Washington, DC +1 202.585.8036
      • atarosky@nixonpeabody.com
      Adam R. Tarosky

    Overview

    On September 1, 2026, the US Department of Justice announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act (FCA) allegations that it failed to comply with cybersecurity requirements in a US Department of Defense/War (DoD) contract. The settlement resolves allegations that, from April 2020 through December 2023, a Honeywell business unit submitted false claims for payment by failing to comply with the controls in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 on one of its networks, as required by the contract and regulation. The claims are allegations only, with no determination of liability. Honeywell Aerospace, headquartered in Phoenix, became a standalone public company on June 29, 2026, having previously been a segment of Honeywell International Inc. of Charlotte, North Carolina.

    The case originated in a 2022 qui tam complaint by former employee Rachel Tenney, captioned United States ex rel. Rachel Tenney v. Honeywell International Inc., No. 3:22-cv-129 (W.D.N.C.). On August 18, 2026, the United States intervened in part—covering the cybersecurity noncompliance—and declined to intervene in the remaining allegations. Tenney will receive $375,823 as her relator’s share. Announcing the deal, Assistant Attorney General Brett A. Shumate said contractors “that obtain defense information in administering their contracts must follow required cybersecurity standards,” and US Attorney Russ Ferguson emphasized that companies profiting from government contracts “have an obligation to ensure sensitive data is protected.”

    Why DFARS 252.204-7012 matters

    DFARS 252.204-7012 appears in most DoD contracts. It requires contractors handling covered defense information (CDI) on non-federal systems to provide “adequate security”—principally the 110 controls in NIST SP 800-171—and to report cyber incidents to DoD, generally within 72 hours. The clause flows down to subcontracts where subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services. Related clauses (DFARS 252.204-7019 and -7020) require a NIST SP 800-171 self-assessment with the score posted in the Supplier Performance Risk System (SPRS) as a condition of award. Because these duties attach at award and continue through performance, a contractor’s SPRS score, system security plan, plan of action and milestones (POA&M), and incident-reporting conduct can each support an FCA theory that the contractor falsely represented compliance when seeking payment. Honeywell shows the stakes: conduct spanning nearly four years on a single network produced a seven-figure recovery.

    Compliance continues despite the CMMC Phase II pause

    Much of the contractor community is focused on the phased rollout of the Cybersecurity Maturity Model Certification (CMMC) program. CMMC Phase 1 took effect on November 10, 2025, the effective date of the DFARS acquisition rule and its clause at DFARS 252.204-7021. During Phase 1, DoD could require, in applicable solicitations and contracts, that contractors complete a self-assessment at the CMMC level assigned to the contract—a Level 1 self-assessment against the 15 requirements in FAR 52.204-21 for systems processing Federal Contract Information, or a Level 2 self-assessment against the 110 requirements in NIST SP 800-171 Revision 2 for systems processing Controlled Unclassified Information—and to affirm that compliance in the Supplier Performance Risk System (SPRS). Phase II was scheduled to take effect on November 10, 2026, and would have required third-party (C3PAO, in this instance) certification at CMMC Level 2 as a condition of award.

    On July 13, 2026, DoD immediately and indefinitely suspended the CMMC Phase II transition, which would have required more than 100,000 businesses in the defense industrial base to seek third-party certification. The DoD framed the suspension as a way to reduce compliance barriers for small and mid-sized businesses, consistent with the Department’s ongoing Acquisition Transformation Strategy. The newly established CMMC Reform Task Force was tasked with studying the CMMC program, and a report is due imminently.

    With that said, even where DoD has paused Phase II, the pause affects only when and how compliance is independently verified; it does not suspend the underlying duty to safeguard CDI under DFARS 252.204-7012 and NIST SP 800-171, which has been enforceable for years. DoD actions in July 2026 were not intended to absolve responsibility under DFARS, but to reduce the administrative and procedural actions associated with compliance. Further, the alleged Honeywell conduct at issue predated any CMMC verification requirement yet still produced FCA liability. A contractor deferring remediation while awaiting clarity on the future of the CMMC program may simply be widening the gap between its representations and its actual security posture; accountability remains for cybersecurity best practices, both practically and under applicable regulations.

    Practical takeaways

    The Honeywell settlement is a reminder of the value for companies at every stage of business maturity benefit to incorporate compliance governance into their ordinary business routines, and to be mindful of these requirements. The settlement also illustrates why this oversight must reach across the enterprise: the allegations concerned cybersecurity deficiencies on one network, and the matter originated in a former employee’s whistleblower lawsuit. Above all, the internal compliance reality must match the representations made to the government. This means:

    • For contractors and subcontractors handling CDI, this requires concrete, recurring action. Companies should confirm that assessments posted in the SPRS are current and supportable, that system security plans accurately describe implemented controls, and that plans of action and milestones assign responsibility and track remediation against documented deadlines.
    • Management should receive enough information to identify overdue corrective actions and resolve resource constraints, and a remediation plan should never be treated as evidence that an outstanding requirement has already been satisfied.
    • Incident-response procedures should enable reporting of covered cyber incidents within 72 hours of discovery, with clear escalation authority and personnel prepared to act within that window.
    • Applicable subcontractor flow-down obligations should be incorporated into agreements and monitored throughout performance.
    • Compliance reviews should cover every environment that processes, stores, or transmits CDI, including relevant cloud services and systems operated for the contractor.

    Practices

    Government ContractsCybersecurity & PrivacyExport Controls & Economic SanctionsGovernment Investigations & White Collar DefenseHealthcareLabor & Employment

    Industries

    Healthcare
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Contact Us
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Supplier Code of Conduct
    • Nixon Peabody International LLP
    • PAL
    © 2026 Nixon Peabody. All rights reserved