October 01, 2026
Can the Government Penalize You for 800-171 Gaps Without a Breach?
Your contracts promise cybersecurity controls that your networks may not yet meet.
On September 1, the Department of Justice (DOJ) announced a settlement with Honeywell Aerospace. The company agreed to pay $2,042,518 to resolve allegations under the False Claims Act (FCA). The FCA is the law against false billing claims to the government (LexBlog, shareholder notice).
From April 2020 through December 2023, a Honeywell business unit allegedly billed the government while missing required cybersecurity controls. The failures were on two networks, called the Grey Network and the Gold Network.
The required controls came from NIST SP 800-171, which protects controlled unclassified information (CUI) on contractor systems. NIST is the National Institute of Standards and Technology. The rules applied through the contract and DFARS clause 252.204-7012. DFARS is the Defense Department's contract rulebook.
This week the case surfaced again. A September 30 notice reminded shareholders of a November 23, 2026 deadline. That is the lead plaintiff cutoff in a related class action.
This article answers one question: can the government penalize you for 800-171 gaps when nobody breached your network? The answer is yes, and the Honeywell case shows exactly how.
What did the government allege?
DOJ said Honeywell knowingly submitted payment claims while its networks did not meet NIST SP 800-171.
Of the $2,042,518, the government counted $972,628 as restitution. Restitution means money paid back.
Honeywell did not admit liability. The settlement does not mean the government's claims lacked merit either.
Was there a breach?
Neither DOJ's announcement nor the settlement agreement names a cyberattack or data breach.
The case was about control gaps, not stolen data. That is the key lesson.
FCA exposure can come from a gap between contract requirements and actual network controls, even with no breach.
How did the case start?
It began as a 2022 whistleblower action filed by a former Honeywell employee. The legal name for this is a qui tam action.
The FCA lets private people sue on the government's behalf and keep part of the recovery. The former employee received $375,823.46 as their share.
DOJ reported a record 1,297 whistleblower suits in fiscal year 2025. DOJ runs the Civil Cyber-Fraud Initiative, started in 2021, to pursue contractors that misstate their cybersecurity posture.
Earlier this year, defense contractor LOGZONE paid $507,144 to settle similar allegations under Navy contracts.
What should you check on your networks this week?
First, list every system that holds CUI. Name the network and the owner.
Second, match each 800-171 requirement to proof that you meet it. A written policy alone is not proof.
Third, close known gaps before someone inside the company files them. The Honeywell case started with a former employee.
Fourth, keep your evidence dated and current. Old screenshots do not answer today's questions.
Sources
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DOJ's $2 Million Honeywell Settlement Under the Civil Cyber-Fraud Initiative, LexBlog, September 21, 2026
- Levi & Korsinsky shareholder notice, September 30, 2026
Next step
Evidence of every 800-171 control beats a settlement every time. See how PolicyCortex collects your Azure evidence automatically.