# Honeywell Settles DoD Cybersecurity Compliance Allegations

Honeywell Aerospace Inc. has agreed to pay over **$2 million** to resolve allegations under the False Claims Act related to failures in meeting NIST SP 800-171 cybersecurity requirements on a Department of Defense contract active from April 2020 through December 2023. The settlement includes a whistleblower share of approximately $376,000 and underscores heightened enforcement risks for contractors submitting cybersecurity attestations that do not accurately reflect their network security posture. This case highlights the increasing legal and financial consequences for defense contractors who fail to comply with mandated cybersecurity standards.

- The Department of Defense contract required strict adherence to NIST SP 800-171 cybersecurity standards, emphasizing the criticality of protecting controlled unclassified information.
- Procurement professionals should recognize that inaccurate cybersecurity attestations now pose False Claims Act risks beyond cure notices, increasing contractor liability.
- Contractors must ensure robust compliance programs and accurate reporting to mitigate legal exposure and maintain eligibility for DoD contracts.
- This settlement signals intensified government scrutiny and enforcement actions, making cybersecurity compliance a top priority in defense procurement risk management.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 25, 2026

### Government Entities
- U.S. Department of Defense (DoD)
- Justice Department Civil Division
- U.S. Attorney's Office for the Western District of North Carolina (USAO-WDNC)
- Defense Criminal Investigative Service (DCIS)

### Vendors
- Honeywell Aerospace Inc. (prime contractor)
- Honeywell International Inc. (parent company)

### Key Quotes
> Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data.
> — Russ Ferguson, U.S. Attorney for the Western District of North Carolina

> Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards.
> — Brett A. Shumate, Assistant Attorney General

### Sources
- [Honeywell Aerospace: $2.04M to resolve alleged failures to meet NIST 800-171 on a DoD contract (allegations only; whistleblower share ~$376K). Cyber attestations that do not match the real network are now FCA risk, not just a cure notice. https://t.co/IbUVyzyARo](https://x.com/FormerFeds/status/2103571489660498167) - twitter-defense