← All posts
Filed in / cmmc · compliance · security

Honeywell's Cybersecurity Settlement: What Defense Contractors Should Review

In this piece
  1. 01 What DOJ alleged
  2. 02 Start with the contract and the network
  3. 03 Compare the paperwork with daily work
  4. 04 Resolve differences before making assurances

Honeywell Aerospace’s cybersecurity settlement is a reason to check whether your contract commitments match the controls operating on the relevant network. DOJ announced the resolution on September 1, 2026. The resolved claims remain allegations, with no determination of liability, according to the DOJ announcement.

What DOJ alleged

DOJ said the settlement concerned a Honeywell business unit’s alleged failure to meet NIST SP 800-171 requirements on one network from April 2020 through December 2023. The government alleged that the unit submitted false payment claims while failing to satisfy cybersecurity requirements imposed by its contract and regulation.

The matter arose from a whistleblower lawsuit brought by a former employee. The release does not identify individual failed controls or describe a CMMC assessment failure.

Start with the contract and the network

For contractors reviewing their own exposure, start with the obligations actually attached to the work. Have the contract owner and security lead identify the applicable clauses, system boundary, and supporting evidence together. Use the following practical review method for your own environment.

DFARS 252.204-7012 addresses adequate security for covered contractor information systems and specifies NIST SP 800-171 requirements for systems within paragraph (b)(2). Check the version and any authorized variations applicable to your contract. The current clause also addresses incident reporting and external cloud providers; include those obligations in the review.

Use a worksheet that another reviewer can follow:

Review item Evidence to locate Owner to involve
Contract obligation Applicable clause and version Contract manager
System boundary Network description and information flows System owner
Control implementation Configuration records and test results Security lead
Known gaps Open findings, decisions, and assigned actions Remediation owner
Customer statements Submitted representations and their supporting records Authorized signatory

Compare the paperwork with daily work

Choose a fictional technical-document exchange for a rehearsal. Trace its email notification, shared file, recipient access, and any downloaded copy. Compare that path with the systems described in your security documentation.

Ask for evidence that corresponds to the specific environment being described:

  • Access: Named users, approved permissions, and removal results
  • Activity: Records connecting actions to people and files
  • Changes: Configuration history and responsible reviewers
  • Exceptions: Known gaps, accountable owners, and follow-up dates

Use the results to identify gaps that need a fuller review. A vendor demonstration should use the same scope and acceptance criteria as your intended workflow.

If collaboration is part of the review, request a defense pilot around a document exchange with IRONKEEP. Bring synthetic files, intended participants, and the evidence your reviewer needs. Confirm deployment suitability and contractual requirements before introducing controlled information.

Resolve differences before making assurances

If a configuration record conflicts with a customer-facing statement, preserve both and involve the responsible security, contracts, and legal reviewers. Record what was observed, which environment it concerns, and which time period the evidence covers. Avoid describing a planned correction as an implemented control.

Set the next review around one contract, one network, and the people authorized to describe its security posture. Keep the resulting decisions with the supporting evidence so the next reviewer can reconstruct what was known and what still needed work.

Defense · Private beta

Plan your CMMC workspace.

Request a defense pilot and get the Level 2 readiness checklist: 39 prompts across 11 assessment areas.

Request a defense pilot