Overview
On September 1, 2026, the US Department of Justice announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act (FCA) allegations that it failed to comply with cybersecurity requirements in a US Department of Defense/War (DoD) contract. The settlement resolves allegations that, from April 2020 through December 2023, a Honeywell business unit submitted false claims for payment by failing to comply with the controls in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 on one of its networks, as required by the contract and regulation. The claims are allegations only, with no determination of liability. Honeywell Aerospace, headquartered in Phoenix, became a standalone public company on June 29, 2026, having previously been a segment of Honeywell International Inc. of Charlotte, North Carolina.
The case originated in a 2022 qui tam complaint by former employee Rachel Tenney, captioned United States ex rel. Rachel Tenney v. Honeywell International Inc., No. 3:22-cv-129 (W.D.N.C.). On August 18, 2026, the United States intervened in part—covering the cybersecurity noncompliance—and declined to intervene in the remaining allegations. Tenney will receive $375,823 as her relator’s share. Announcing the deal, Assistant Attorney General Brett A. Shumate said contractors “that obtain defense information in administering their contracts must follow required cybersecurity standards,” and US Attorney Russ Ferguson emphasized that companies profiting from government contracts “have an obligation to ensure sensitive data is protected.”
Why DFARS 252.204-7012 matters
DFARS 252.204-7012 appears in most DoD contracts. It requires contractors handling covered defense information (CDI) on non-federal systems to provide “adequate security”—principally the 110 controls in NIST SP 800-171—and to report cyber incidents to DoD, generally within 72 hours. The clause flows down to subcontracts where subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services. Related clauses (DFARS 252.204-7019 and -7020) require a NIST SP 800-171 self-assessment with the score posted in the Supplier Performance Risk System (SPRS) as a condition of award. Because these duties attach at award and continue through performance, a contractor’s SPRS score, system security plan, plan of action and milestones (POA&M), and incident-reporting conduct can each support an FCA theory that the contractor falsely represented compliance when seeking payment. Honeywell shows the stakes: conduct spanning nearly four years on a single network produced a seven-figure recovery.
Compliance continues despite the CMMC Phase II pause
Much of the contractor community is focused on the phased rollout of the Cybersecurity Maturity Model Certification (CMMC) program. CMMC Phase 1 took effect on November 10, 2025, the effective date of the DFARS acquisition rule and its clause at DFARS 252.204-7021. During Phase 1, DoD could require, in applicable solicitations and contracts, that contractors complete a self-assessment at the CMMC level assigned to the contract—a Level 1 self-assessment against the 15 requirements in FAR 52.204-21 for systems processing Federal Contract Information, or a Level 2 self-assessment against the 110 requirements in NIST SP 800-171 Revision 2 for systems processing Controlled Unclassified Information—and to affirm that compliance in the Supplier Performance Risk System (SPRS). Phase II was scheduled to take effect on November 10, 2026, and would have required third-party (C3PAO, in this instance) certification at CMMC Level 2 as a condition of award.
On July 13, 2026, DoD immediately and indefinitely suspended the CMMC Phase II transition, which would have required more than 100,000 businesses in the defense industrial base to seek third-party certification. The DoD framed the suspension as a way to reduce compliance barriers for small and mid-sized businesses, consistent with the Department’s ongoing Acquisition Transformation Strategy. The newly established CMMC Reform Task Force was tasked with studying the CMMC program, and a report is due imminently.
With that said, even where DoD has paused Phase II, the pause affects only when and how compliance is independently verified; it does not suspend the underlying duty to safeguard CDI under DFARS 252.204-7012 and NIST SP 800-171, which has been enforceable for years. DoD actions in July 2026 were not intended to absolve responsibility under DFARS, but to reduce the administrative and procedural actions associated with compliance. Further, the alleged Honeywell conduct at issue predated any CMMC verification requirement yet still produced FCA liability. A contractor deferring remediation while awaiting clarity on the future of the CMMC program may simply be widening the gap between its representations and its actual security posture; accountability remains for cybersecurity best practices, both practically and under applicable regulations.
Practical takeaways
The Honeywell settlement is a reminder of the value for companies at every stage of business maturity benefit to incorporate compliance governance into their ordinary business routines, and to be mindful of these requirements. The settlement also illustrates why this oversight must reach across the enterprise: the allegations concerned cybersecurity deficiencies on one network, and the matter originated in a former employee’s whistleblower lawsuit. Above all, the internal compliance reality must match the representations made to the government. This means:
- For contractors and subcontractors handling CDI, this requires concrete, recurring action. Companies should confirm that assessments posted in the SPRS are current and supportable, that system security plans accurately describe implemented controls, and that plans of action and milestones assign responsibility and track remediation against documented deadlines.
- Management should receive enough information to identify overdue corrective actions and resolve resource constraints, and a remediation plan should never be treated as evidence that an outstanding requirement has already been satisfied.
- Incident-response procedures should enable reporting of covered cyber incidents within 72 hours of discovery, with clear escalation authority and personnel prepared to act within that window.
- Applicable subcontractor flow-down obligations should be incorporated into agreements and monitored throughout performance.
- Compliance reviews should cover every environment that processes, stores, or transmits CDI, including relevant cloud services and systems operated for the contractor.


