
Honeywell Aerospace’s $2M Settlement Shows the Government Doesn’t Need CMMC Phase 2 to Enforce NIST 800-171
Key takeaways
- The major aerospace prime’s failure to meet cybersecurity requirements on one network resulted in a $2 million False Claims Act settlement that originated from a whistleblower lawsuit filed by a former employee.
- Every enforcement mechanism that produced this settlement was operating before CMMC existed and is still operating now that Phase 2 is on hold. Similarly, every reason to comply with contractual cybersecurity requirements stands during this interim period: national security, contract-eligibility, legal risk.
- The expanded rollout of third-party assessment requirements under CMMC Phase 2 was just one verification mechanism that the government had to ensure contractors’ cybersecurity compliance. There are still five in place, and these are all based on the accuracy and defensibility of your self-attestations and self-reported scores.
On September 1, 2026, the Justice Department announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a Department of Defense contract. The allegations cover April 2020 through December 2023 and concern one of Honeywell's networks that was subject to NIST SP 800-171 under the contract and applicable regulation. The claims are allegations only, and there has been no determination of liability.
The settlement landed seven weeks into the CMMC Phase 2 pause and provides a concrete example of what government and industry leaders alike have emphasized: The Department paused the transition to the CMMC phase that would require a third-party assessor in the room to check your work. It did not pause the underlying cybersecurity requirements, the self-reported representations you make about the implementation of those requirements, or the consequences of getting those representations wrong.
Honeywell is the second cybersecurity False Claims Act settlement involving a defense contractor in under three months, following LOGZONE's $507,144 settlement on June 18. Assistant Attorney General Brett A. Shumate of the Civil Division said the Justice Department "will continue to investigate potential violations of these cybersecurity requirements."

A whistleblower alleged failure to comply with NIST 800-171 in one network
Before becoming a standalone public company on June 29, 2026, Honeywell Aerospace Inc. was a business segment of Honeywell International Inc.
The settlement alleges that from April 2020 through December 2023, a business unit of Honeywell International Inc. submitted false claims for payment by failing to comply with contractually obligated cybersecurity requirements specified in NIST 800-171 in one of its networks.
These allegations originated in whistleblower suit, United States ex rel. Rachel Tenney v. Honeywell International Inc., Civil Action No. 3:22-cv-129 (W.D.N.C.), filed by a former Honeywell employee who will receive $375,823 of the recovery.
Two details are worth flagging. First, the exposure was attached to a single network, not to the enterprise a company-wide security posture. False Claims Act risk follows the boundary that touches covered defense information, so a large contractor with a generally mature security posture can still carry real liability inside an enclave.
Second, the liability traveled with the business through a corporate separation. The conduct belonged to a Honeywell International business unit, and Honeywell Aerospace settled it as a standalone company.
The alleged non-compliance predates CMMC, violates DFARS 7012
The period of time in which Honeywell allegedly failed to comply with contractual cybersecurity requirements (April 2020 through December 2023) took place before the CMMC phased rollout began. It was a year before the final 32 CFR CMMC Program Rule was even published in the Federal Register. Meaning, there was no CMMC assessment requirement in force during any period of the alleged conduct so no C3PAO certification or SPRS score or CMMC status to check in SPRS.
But the government did not need any of those CMMC requirements to verify and enforce compliance with NIST 800-171. The hook was DFARS 252.204-7012, which has required contractors handling covered defense information to implement NIST 800-171 Rev 2 requirements since 2017. CMMC was designed to verify that contractors were meeting that obligation more rigorously and at scale, but was never the source of the obligation, and it was never the only way the government could verify it.
This is the clearest answer to date to the question a lot of contractors have been asking since July 13: if nobody is coming to assess me, who is checking? Why should I care if I fully and correctly implement and maintain my cybersecurity requirements when I have so many other priorities?
U.S. Attorney Russ Ferguson for the Western District of North Carolina provides a compelling answer: “Cybersecurity requirements and standards for federal contractors are in place for a reason: to protect government systems and prevent unauthorized access to government data. Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected.”
Avoiding False Claims Act settlement is not the only reason you should follow required cybersecurity standards. Neither is contract-eligibility or revenue. The real reason is protecting defense information and the greater supply chain.
Recommended reading
CMMC Cybersecurity Misrepresentation: The False Claims Act Cases DIB Contractors Should Know
The verification layers for contractual cybersecurity still in place during the CMMC pause
The Phase 2 pause removed one specific thing: the authority for DoW contracting officers to designate Level 2 (C3PAO) and Level 3 (DIBCAC) assessment requirements in new solicitations, along with the removal of those designations from active ones. Memo 26-P-1023 binds Department contracting personnel. It does not touch the following verification and enforcement mechanisms.
1. Self-assessment and SPRS score
CMMC Phase 1 requirements remain firmly in place. Under these requirements or clause DFARS 7021, you must submit Level 1 or Level 2 self-assessment results and a score along with an annual affirmation signed by a named senior executive attesting to the accuracy of that assessment. These are legal representations you make to the government, and the pause increased how much weight they carry rather than reducing it. Self-assessment is now the de facto standard for the entire Defense Industrial Base.
2. Prime flowdown requirements
Prime flowdown deadlines are business decisions about supply chain risk and were never tied to the Department's rollout calendar. Elbit America told suppliers to stay the course three days after the pause and to confirm with their buyer before cancelling a scheduled C3PAO assessment.
As the Cyber AB's Matthew Travis put it when the pause was announced, a Level 2 certification remains "the best insurance policy against False Claims Act risk."
3. Government-led assessments
As the DoW Chief Information Officer Kirsten A. Davies said in her announcement of the CMMC Phase 2 pause: “During this interim period, the Department will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments.”
This refers to assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), part of the Defense Contract Management Agency (DCMA), to evaluate DoD’s contractors’ compliance with DFARS 7012, NIST 800-171, and DFARS 7020 (renumbered to 7997) and can result in False Claims Act settlements. The LOGZONE case, for example, began with a DCMA assessment that scored an environment at -170 against a self-reported score of 110.
4. Whistleblowers under the False Claims Act
The qui tam provisions of the False Claims Act let a private citizen sue on the government's behalf and share in the recovery. The complaint is filed under seal while the government investigates, and the defendant often does not know it exists for years. As an example, the Tenney v. Honeywell case began in 2022, four years prior to the False Claims Act settlement.
That means your current SPRS score, your current System Security Plan, and the affirmation you sign this year could all be evidence of non-compliance with current cybersecurity requirements in a case that may not be filed or surface for years, well after the CMMC Reform Task Force has finished its work and a potentially revised assessment timeline is in place.
In the meantime, the people best positioned to notice a gap between what your SSP or SPRS submission claims and what your network actually does are the engineers and administrators who work in it every day. Ms. Tenney's $375,823 share is roughly 18 percent of the settlement, and it is a standing structural incentive.
Waiting out the pause does not run out the clock. It only widens the window of conduct a later case can reach.
5. DOJ and DCIS investigations under the False Claims Act
In addition to whistleblower complaints, voluntary self-disclosure of cybersecurity noncompliance by a defense contractor can trigger the DoJ, the DoD Office of Inspector General’s Defense Criminal Investigative Service (DCIS),” and others’ scrutiny under the False Claims Act.
For example, the $1.75 million False Claims Act settlement with defense contractor Aero Turbine Inc. (ATI) and its private equity company originated from two voluntary self-disclosures by ATI of cybersecurity violations relating to a contract with the Department of the Air Force.
It was ultimately resolved by the coordinated effort of multiple bodies, including the Department of Justice Civil Division, DCIS, Commercial Litigation Branch, Fraud Section, the U.S. Attorney’s Office for the Eastern District of California, AFOSI, and the Air Force Materiel Command Law Office Procurement Fraud Division.
Recommended reading
CMMC Phase 2 Paused: Which Cybersecurity Requirements Still Apply to Defense Contractors?
How to reduce False Claims Act exposure before someone else checks your work
The CMMC Reform Task Force is due to deliver a final report with recommended changes around late September or early October, according to Matthew Travis’s estimates in the July Cyber AB Town Hall.
While some organizations are deferring a C3PAO assessment during this interim period, they should not defer implementation of the underlying cybersecurity requirements that are in place today. Doing so leaves them vulnerable to security incidents and breaches, losing out on bids and work with the Department and primes to compliant suppliers, and even whistleblower complaints and False Claims Act settlements.
Here’s what to do as soon as possible:
- Confirm your SPRS score is supportable today. If it reflects planned controls rather than implemented ones, fix the score or fix the controls. A gap analysis is the fastest way to find out which one you are dealing with. Both LOGZONE and Honeywell turned on the gap between a representation and an environment.
- Match your scope to your score. Honeywell's exposure attached to one network. Verify that the boundary your score describes is actually the boundary where covered defense information lives, including anything that has changed since your last assessment.
- Treat your annual affirmation as the legal representation it is. A named senior executive signs it. Make sure that person has evidence behind the signature and understands what they are attesting to.
- Keep your SSP and evidence current. Your documentation needs to describe the environment you run today. A stale SSP is the document a relator's counsel reads first.
- Work down open POA&Ms instead of rolling them forward. A paused deadline is the cheapest remediation window you will get, and open POA&Ms are the first thing a prime's supplier questionnaire asks about.
- Give your engineers a working internal channel. Whistleblower cases start with someone who saw a gap and had no credible way to raise it. An internal path that actually resolves findings is a genuine risk control, not an HR formality.
- Ask your primes in writing what still applies. Do not infer an answer from silence, and do not cancel a scheduled C3PAO assessment before you have asked.
- Check your sub-tier suppliers. Your own flowdown obligations did not pause either.
Talk to a CMMC expert for guidance on scoping and meeting your current NIST 800-171 Rev 2 and CMMC assessment requirements to get secure and stay contract-eligible.
FAQs
Does the CMMC Phase 2 pause reduce False Claims Act risk? No. The pause changes who is required to verify cybersecurity compliance for certain contracts, not what is required. DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS score submissions, and annual affirmations remain in effect, and those representations are what False Claims Act cases are built on. The Honeywell settlement resolved conduct from a period when no CMMC assessment requirement existed at all.
Did Honeywell fail a CMMC assessment? No. The alleged conduct ran from April 2020 through December 2023, before CMMC Phase 1 began on November 10, 2025. The requirement at issue was NIST SP 800-171 as incorporated into the contract by regulation.
Was there a breach at Honeywell? The Justice Department's announcement does not allege there was a breach. False Claims Act liability is not actually based on breaches or security incidents, it is based on the misrepresentation of cybersecurity compliance with DFARS 7012 and NIST 800-171 to win or get paid for a defense contract.
How did the government find out? A former employee filed a whistleblower suit under the False Claims Act in 2022. Private citizens can sue on the government's behalf and share in the recovery, and in this case the relator receives $375,823.
If our score is wrong, what should we do? Correct it, and document when and why you corrected it. In the 2025 MORSECORP settlement, the Justice Department specifically pointed to the company's failure to update a score it knew was inaccurate. A corrected score is a materially different position than an uncorrected one.