The DOJ announced Honeywell Aerospace will pay over $2 million to settle False Claims Act allegations tied to NIST 800-171 non-compliance on a DoD contract.
The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U.S. Department of Defense. Honeywell Aerospace, a corporation headquartered in Phoenix, Arizona, provides aerospace products and solutions to government and commercial customers. Prior to June 29, when Honeywell Aerospace became a standalone public company, it was a business segment of Honeywell International Inc., of Charlotte, North Carolina.
“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.”
“Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data,” said U.S. Attorney Russ Ferguson for the Western District of North Carolina. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”
The settlement resolves allegations that from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, with respect to one of Honeywell’s networks, as required by the contract and regulation.
Justin Beals, CEO & Founder, Strike Graph had this to say:
“”Two million dollars gets the headline, but the number I keep coming back to is eight years. NIST 800-171 has been a contractual requirement since 2017, and Honeywell Aerospace isn’t a two-person shop that couldn’t find the standard — it’s one of the most sophisticated suppliers in the defense industrial base. The government is alleging that from 2020 through 2023, one of its networks didn’t meet requirements the company had already represented to the Department of Defense that it met. That’s the part people miss when they treat a self-assessment like a checkbox. It isn’t a checkbox. When you put a score in SPRS or sign an attestation, you’re making a legal representation to the federal government, and the False Claims Act is the mechanism that turns a paperwork gap into a fraud claim. The whistleblower here was a former employee who walked away with $375,000. Every disgruntled employee, every competitor, every subcontractor in your flow-down is now someone who can see whether your practice actually matches your paperwork. I spent my career building and shipping software, and I’ll say it plainly:
I have never met the engineer who could grade their own work and be right every time. Quality assurance saved me more times than I can count. This settlement is what happens when nobody checked the work.Here’s what actually worries me about this pause. A third-party assessment was never just a hoop to jump through — it was risk mitigation. A C3PAO comes in, validates your implementation, and stands behind that determination, which absorbs exactly the kind of exposure Honeywell just paid two million dollars to resolve. Suspend the phase-two rollout and that requirement doesn’t go anywhere. 800-171 is still in the contract, and the False Claims Act is still the enforcement engine. What goes away is the guidance and the validation. So companies are now shouldering the full weight of getting it right on their own, with no assessor checking whether their self-attestation would survive contact with a whistleblower or a DCIS investigation. And here’s the operator’s reality nobody’s saying out loud: doing this without an experienced assessor usually costs more, not less. I’ve watched companies burn months on false starts because they couldn’t even identify where their controlled data lived or which systems touched it. A good assessor catches that early. Go it alone and you find it in year three, after you’ve already built the wrong thing — or you find out the way Honeywell just did. The ‘delay’ didn’t take the cost off the table. It pushed the cost downstream, pulled the guidance out of the room, and left the fine sitting right where it was. I have loved ones in and around this mission, and the people who wear the uniform are counting on this data being protected. A steady, honest path is cheaper than a settlement, every single time.”
Organizations need to ensure that they follow all rules and regulations at all times without fail. Otherwise I hope that the DoJ smacks them silly until they comply.
Related
This entry was posted on September 4, 2026 at 2:34 pm and is filed under Commentary with tags DoJ. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Honeywell’s $2M settlement shows self-attestation is now a legal liability, not a formality
The DOJ announced Honeywell Aerospace will pay over $2 million to settle False Claims Act allegations tied to NIST 800-171 non-compliance on a DoD contract.
The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U.S. Department of Defense. Honeywell Aerospace, a corporation headquartered in Phoenix, Arizona, provides aerospace products and solutions to government and commercial customers. Prior to June 29, when Honeywell Aerospace became a standalone public company, it was a business segment of Honeywell International Inc., of Charlotte, North Carolina.
“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” said Assistant Attorney General Brett A. Shumate of the Justice Department’s Civil Division. “The Justice Department will continue to investigate potential violations of these cybersecurity requirements to protect this critical information.”
“Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data,” said U.S. Attorney Russ Ferguson for the Western District of North Carolina. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”
The settlement resolves allegations that from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with cybersecurity requirements specified in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, with respect to one of Honeywell’s networks, as required by the contract and regulation.
Justin Beals, CEO & Founder, Strike Graph had this to say:
“”Two million dollars gets the headline, but the number I keep coming back to is eight years. NIST 800-171 has been a contractual requirement since 2017, and Honeywell Aerospace isn’t a two-person shop that couldn’t find the standard — it’s one of the most sophisticated suppliers in the defense industrial base. The government is alleging that from 2020 through 2023, one of its networks didn’t meet requirements the company had already represented to the Department of Defense that it met. That’s the part people miss when they treat a self-assessment like a checkbox. It isn’t a checkbox. When you put a score in SPRS or sign an attestation, you’re making a legal representation to the federal government, and the False Claims Act is the mechanism that turns a paperwork gap into a fraud claim. The whistleblower here was a former employee who walked away with $375,000. Every disgruntled employee, every competitor, every subcontractor in your flow-down is now someone who can see whether your practice actually matches your paperwork. I spent my career building and shipping software, and I’ll say it plainly:
I have never met the engineer who could grade their own work and be right every time. Quality assurance saved me more times than I can count. This settlement is what happens when nobody checked the work.Here’s what actually worries me about this pause. A third-party assessment was never just a hoop to jump through — it was risk mitigation. A C3PAO comes in, validates your implementation, and stands behind that determination, which absorbs exactly the kind of exposure Honeywell just paid two million dollars to resolve. Suspend the phase-two rollout and that requirement doesn’t go anywhere. 800-171 is still in the contract, and the False Claims Act is still the enforcement engine. What goes away is the guidance and the validation. So companies are now shouldering the full weight of getting it right on their own, with no assessor checking whether their self-attestation would survive contact with a whistleblower or a DCIS investigation. And here’s the operator’s reality nobody’s saying out loud: doing this without an experienced assessor usually costs more, not less. I’ve watched companies burn months on false starts because they couldn’t even identify where their controlled data lived or which systems touched it. A good assessor catches that early. Go it alone and you find it in year three, after you’ve already built the wrong thing — or you find out the way Honeywell just did. The ‘delay’ didn’t take the cost off the table. It pushed the cost downstream, pulled the guidance out of the room, and left the fine sitting right where it was. I have loved ones in and around this mission, and the people who wear the uniform are counting on this data being protected. A steady, honest path is cheaper than a settlement, every single time.”
Organizations need to ensure that they follow all rules and regulations at all times without fail. Otherwise I hope that the DoJ smacks them silly until they comply.
Share this:
Like this:
Related
This entry was posted on September 4, 2026 at 2:34 pm and is filed under Commentary with tags DoJ. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.