Sunday, Sep 20, 2026
Managed by Visioneerit
IndustrialBriefs
Managed by Visioneerit

Honeywell Aerospace Pays $2M to Settle DOJ Cybersecurity Claims

Honeywell Aerospace's $2M settlement with the DOJ highlights the importance of cybersecurity compliance for defense contractors, emphasizing adherence to CMMC standards.

Advertisement
Honeywell Aerospace Pays $2M to Settle DOJ Cybersecurity Claims
IB_KEY_FACTS:[{"stat":"$2.04 million","label":"**Settlement Amount**","sublabel":"Honeywell Aerospace's payment to resolve DOJ claims."},{"stat":"April 1, 2020 - Dec. 31, 2023","label":"**Period of Alleged Non-Compliance**","sublabel":"Timeframe during which Honeywell allegedly failed to meet cybersecurity requirements."},{"stat":"$375,823","label":"**Whistleblower Award**","sublabel":"Amount received by Rachel Tenney for her role in the lawsuit."}]

Honeywell Aerospace has agreed to a $2.04 million settlement with the U.S. Department of Justice over allegations that it failed to comply with cybersecurity requirements under a Department of Defense (DOD) contract. This settlement, announced on September 14, 2026, resolves claims that Honeywell submitted false claims for payment by not adhering to the DOD’s Cybersecurity Maturity Model Certification (CMMC) program.

What Happened
The allegations against Honeywell stem from a period between April 1, 2020, and December 31, 2023, during which the company allegedly did not meet the mandatory cybersecurity assessment requirements set forth by the National Institute of Standards and Technology (NIST). These requirements are part of the DOD's CMMC program, which has been in place since 2019 to protect sensitive information. A whistleblower lawsuit, filed by former Honeywell employee Rachel Tenney under the False Claims Act in March 2022, claimed that Honeywell's IT unit, Advanced Connected Sustainability Technologies (ACST), failed to report a cybersecurity incident involving SolarWinds' Orion software, which was used in Honeywell’s Gray Network for quantum computing contracts. This network was intended to secure confidential government and research data. However, during the global SolarWinds hack, Honeywell allegedly only addressed its commercial business unit, neglecting its government contracting unit.

What This Means for Your Business
For companies engaged in government contracting, this settlement underscores the critical importance of adhering to cybersecurity requirements. Non-compliance can lead to significant financial penalties and damage to reputation. The settlement serves as a reminder for contractors to ensure their cybersecurity measures align with federal standards, particularly the CMMC and NIST regulations. Compliance with these standards is not only a legal obligation but also a strategic necessity to maintain competitive positioning and secure future contracts. This case highlights the need for robust internal controls and audit mechanisms to prevent fraudulent claims and ensure compliance.

What US Operators Should Watch
US operators, particularly those in defense contracting, should closely monitor updates to the CMMC framework and ensure their systems are compliant. The CMMC 2.0, expected to be fully implemented by 2026, will require all contractors to meet specific cybersecurity levels. Companies should prepare for potential audits and assessments by establishing comprehensive cybersecurity policies and incident response plans. Additionally, they should be vigilant about reporting any cyber incidents to the DOD to avoid penalties similar to those faced by Honeywell.


Source: https://www.manufacturingdive.com/news/honeywell-aerospace-doj-false-claims-act-cmmc-defense-settlement/830203/. Read the original story ->

Advertisement
Advertisement
Advertisement

Is your firm ready for what’s next?

VisioneerIT helps AECM and government contractors modernize operations, achieve compliance, and implement AI.

Explore VisioneerIT Solutions →
Sponsored
Turn GovCon relationships into pipeline — Try OryonIQ Free