On September 1, 2026, the Justice Department announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a U.S. Department of Defense contract. The allegations concern conduct from April 2020 through December 2023 by a business unit of Honeywell International Inc. — and the entity paying is a company that did not exist in its current form until June 29, 2026.
What the Government Alleged
According to DOJ, from April 2020 through December 2023 a Honeywell International business unit submitted false claims for payment by failing to comply with the cybersecurity requirements specified in NIST SP 800-171, with respect to one of Honeywell's networks, as required by the contract and by regulation.
The case originated as a whistleblower action under the False Claims Act's qui tam provisions, captioned United States ex rel. Rachel Tenney v. Honeywell International Inc., Civil Action No. 3:22-cv-129 (W.D.N.C.). Tenney, a former Honeywell employee, receives $375,823 as her statutory share.
The resolution was a coordinated effort of the Civil Division's Commercial Litigation Branch, the U.S. Attorney's Office for the Western District of North Carolina, and the Defense Criminal Investigative Service. Assistant Attorney General Brett A. Shumate of the Civil Division framed the government's position plainly: contractors that obtain defense information in administering their contracts must follow the required cybersecurity standards, and DOJ will continue investigating potential violations.
(A settlement is not an admission of liability. As DOJ stated, the claims resolved are allegations only and there has been no determination of liability.)
The Scoping Lesson: "One of Honeywell's Networks"
The most instructive phrase in the announcement is the narrowest one. The government did not allege enterprise-wide failure at one of the largest aerospace suppliers in the country. It alleged non-compliance as to a single network.
That is how DFARS 252.204-7012 and NIST SP 800-171 actually operate. The obligation attaches to covered contractor information systems — the environments that process, store, or transmit covered defense information — not to the enterprise in the abstract. A contractor can run a mature, well-funded security program across most of its estate and still have a covered enclave that drifted out of compliance: a legacy engineering network, an acquired business unit's environment, a program-specific segment stood up quickly to win work.
That is also why scoping is not a paperwork exercise. If a network holds covered defense information and does not meet the 800-171 requirements, the compliance representations covering it are exposed regardless of how strong the rest of the environment is. Our explainer on CMMC Level 2 scoping and asset categories walks through how to draw those boundaries defensibly, and Find My Requirements helps identify which obligations attach to which work.
The Four-Year Tail
The timeline is worth sitting with. The relator filed suit in 2022. The alleged non-compliance continued through December 2023. The settlement was announced in September 2026.
Two consequences follow.
First, qui tam complaints stay sealed. A False Claims Act relator files under seal while the government investigates. A contractor can be under active investigation for years without knowing it, which means the compliance posture you have today is what will be examined years from now, in a document review you cannot anticipate.
Second, the conduct window keeps running. The alleged non-compliance here spanned roughly 45 months. Each invoice submitted during that period is a potential claim. That arithmetic — not the severity of any single control gap — is what turns a scoping oversight into a seven-figure exposure.
Corporate Separation Does Not Separate the Liability
Honeywell Aerospace became a standalone public company on June 29, 2026, having previously been a business segment of Honeywell International Inc. The conduct at issue predates that separation entirely. The settling party is the successor.
For contractors contemplating a spin-off, carve-out, divestiture, or acquisition, the point generalizes: cybersecurity compliance history travels with the business. Unresolved 800-171 gaps, stale SPRS scores, POA&M items that were never closed, and certifications made on behalf of a business unit are all live diligence items — and they surface on the buyer's or the spun-off entity's books.
Cyber diligence in a govcon transaction should include, at minimum: the scoping documentation for every covered environment, the System Security Plan and its parameters, SPRS submission history, and any internal or third-party assessment findings that remain open. See the broader pattern across the enforcement docket and the defense sector page.
What Contractors Should Do
1. Re-verify your covered-system inventory. Confirm that every network touching covered defense information is inside your assessed boundary — including environments inherited through acquisition or stood up for a single program.
2. Treat each invoice as a representation. Compliance status is not a point-in-time checkbox; it persists across every claim for payment during the performance period.
3. Build cyber into transaction diligence. Scoping records, SSPs, SPRS history, and open findings belong in the data room on both sides of a deal.
4. Take internal reports seriously. Relators are usually employees who raised something first. A functioning internal escalation path is a compliance control, not an HR nicety. Our build-a-program guide covers governance structures that make that work.
Key Takeaways
- Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve allegations that a Honeywell International business unit failed to comply with NIST SP 800-171 on one network from April 2020 through December 2023, resolving United States ex rel. Tenney v. Honeywell International Inc., No. 3:22-cv-129 (W.D.N.C.).
- Exposure attached to a single covered network, not the enterprise — making scoping accuracy, not overall program maturity, the decisive variable.
- Compliance history survives corporate reorganization: the settling entity became a standalone public company in June 2026 and paid for conduct that ended in December 2023.