DOJ Hammers Home Cybersecurity as Key Risk Factor for Government Contractors
The Department of Justice (DOJ) has reinforced cybersecurity as a False Claims Act risk for government contractors, particularly those in the defense industry. Honeywell Aerospace Inc., a Phoenix-based aerospace company, agreed to pay $2,042,518 to resolve allegations that one of its business units failed to comply with cybersecurity requirements on a Department of Defense contract.
The settlement, announced on September 1, 2026, adds to a growing body of cybersecurity-related False Claims Act enforcement actions. In fiscal year 2025 alone, the DOJ recovered more than $52 million across nine cybersecurity-related FCA settlements as part of a record-shattering $6.8 billion in total FCA recoveries.
The allegations against Honeywell Aerospace stemmed from its failure to comply with National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171) requirements, which are incorporated into federal contracting requirements through the Defense Federal Acquisition Regulation Supplement (DFARS).
DOJ emphasized that cybersecurity certifications should be treated with the same seriousness as other representations made to obtain or retain government business. The agency is examining more than whether an organization has suffered a cyberattack; enforcement has focused on whether required controls were actually implemented, and whether system security plans accurately described the environment.