Key Takeaways
- DOJ used the FCA to settle with Honeywell Aerospace Inc. for $2,042,518 over allegations that a Honeywell business unit submitted claims for payment under a DoW contract while failing to comply with NIST SP 800-171 cybersecurity requirements incorporated through DFARS 252.204-7012, reinforcing that cybersecurity compliance failures can create significant FCA exposure for defense contractors.
- The settlement arose from a 2022 qui tam whistleblower action filed by a former Honeywell employee, and DOJ reported a record 1,297 qui tam lawsuits filed in FY 2025, underscoring the critical role of internal whistleblowers in driving cybersecurity FCA enforcement under DOJ’s Civil Cyber-Fraud Initiative.
- Notably, the government’s allegations focused on Honeywell’s failure to satisfy required NIST SP 800-171 controls rather than any identified cyberattack or data breach, confirming that FCA risk can arise from a disconnect between contractual cybersecurity obligations and a contractor’s actual compliance posture even in the absence of a security incident.
The Department of Justice (DOJ) continues to use the False Claims Act (FCA) to pursue government contractors for alleged failures to comply with contractual cybersecurity requirements. On September 1, DOJ announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve allegations that a Honeywell business unit failed to comply with required cybersecurity controls under a Department of War (DoW) contract. The settlement is the latest example of DOJ treating cybersecurity compliance as more than an information technology issue. For federal contractors, deficiencies in required cybersecurity controls can also create significant FCA exposure.
Continue Reading DOJ’s $2 Million Honeywell Settlement Under the Civil Cyber-Fraud Initiative: What Compliance Failures Mean for Defense Contractors