MILESTONECUI Vault has achieved FedRAMP Moderate equivalency.FedRAMP Moderate equivalency achieved.Read the announcement

Honeywell just paid $2 million over a single network

No assessor was involved and no breach was alleged. A former employee’s suit reached back nearly three years — and liability attached to the one network where covered defense information actually lived.

On September 1, the Department of Justice announced that Honeywell Aerospace agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to meet the NIST SP 800-171 cybersecurity requirements its Defense Department contract required under DFARS 252.204-7012. The alleged non-compliance ran from April 2020 through December 2023.

Two details are worth sitting with. The first is scope. DOJ’s description is precise: the failure concerned one of Honeywell’s networks. This is not a company short of security engineers or budget. Liability didn’t attach to the enterprise’s overall maturity — it attached to the single boundary where covered defense information actually lived.

The second is how the case started. It wasn’t a DIBCAC review or a C3PAO assessment. It was a qui tam suit filed in 2022 by Rachel Tenney, a former Honeywell employee, which sat under seal for years before surfacing. Tenney received $375,823 — roughly 18% of the recovery.

Assistant Attorney General Brett A. Shumate put the principle plainly: “Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards.” DOJ signaled it will keep investigating potential violations. The claims were resolved as allegations only, with no determination of liability.

So what: False Claims Act exposure follows the boundary that touches covered defense information — not your company’s size, not its general security reputation, and not the status of the assessment calendar. Two questions are worth answering before Friday: does your scored SPRS boundary actually cover every enclave where CDI lives, and would someone who left your company last year describe your posture the way your affirmation does? A suit filed today can reach back years.

1,100 responses, 10,500 pages — and the Task Force date has slipped

The Cyber AB’s August 26 town hall put hard numbers on the Reform Task Force’s request for information, which closed August 14. The response was substantial: nearly 1,100 submissions totaling more than 10,500 pages, with over 1,300 individuals participating through listening sessions and stakeholder meetings.

The friction points that recurred most: FIPS-validated cryptography, audit log management, media sanitization documentation, and wireless access controls — plus two systemic complaints, improper CUI designations and FedRAMP friction, that will sound familiar to anyone who read this brief last week.

The Cyber AB also brought its own reform recommendations, split between near-term fixes and longer-horizon ideas:

Friction pointHow it works todayCyber AB’s proposed fix
Assessment team sizeThree assessors per C3PAO assessmentReduce to two
Maintaining a certificationFull reassessment cycleContinuous monitoring and delta assessments
CCA / CCP background checksGovernment-run processCommercialize the investigations
ESP and FedRAMP scopeA recurring source of confusionFormal clarification

Read that list for what isn’t on it. Every proposed quick win concerns how an assessment gets staffed, scheduled, or repeated. None of them touches the 110 requirements in NIST SP 800-171. The longer-horizon items — AI-assisted assessment tooling, reciprocity with alternative standards, and adding operational technology security — point the same direction: the mechanics may get cheaper, the substance does not get smaller.

One scheduling note. Last issue we flagged mid-September for the Task Force’s recommendations. That has drifted: the Cyber AB now expects public information as late as early October, and the DoW CIO has said late September or early October. Plan accordingly, but don’t treat the slip as slack.

The CIO isn’t aiming at less security — the target is moving to your shop floor

At DIBX 2026 in Philadelphia on August 26, DoW CIO Kirsten Davies gave the clearest signal yet about where reform is headed — and it isn’t backward. The now-quotable line from the fireside chat: “We want results, not red tape. We want performance, not paperwork.”

The substance behind it matters more than the soundbite. Davies framed protecting federal data as “table stakes” — and then argued that the harder problem is operational technology: the programmable logic controllers, machine tools, and production-floor systems that actually build things. The cited example was the recent wave of attacks on water utilities across several states, which targeted exactly that class of equipment. For a defense manufacturer, that’s not an analogy; it’s a preview.

“Table stakes” is not a synonym for optional. It is the floor you are expected to already be standing on while the Department turns its attention somewhere harder. The RFI data supports the shift rather than a retreat: more than half of respondents backed reform, and small businesses reportedly spend $250,000 to $500,000 over three years on assessment and certification — a cost problem the Department wants to solve without lowering the security outcome.

Here’s the calendar that follows from all of it:

  • Aug 26, 2026
    DIBX fireside chat and Cyber AB town hall — same day, same message: reform means efficiency and OT, not relaxation.
  • Aug 28, 2026
    Second batch of Revolutionary FAR Overhaul proposed rules clears OMB review.
  • Sep 29, 2026
    Next Cyber AB town hall — the most likely venue for a first public read on the recommendations.
  • Sep 30, 2026
    CCI credentialing grace period closes for the instructor transition.
  • Late Sep – early Oct 2026
    CMMC Reform Task Force recommendations — the single most consequential item on this list, and now the most likely to define Q4.
  • Mid-Oct 2026 (earliest)
    Formal determinations on program changes — actual rule text, not a memo.

What to do this week

The theme this issue: boundaries and evidence. Honeywell’s $2M turned on where CUI actually lived — and on what one departing employee knew about it.

  • Map your CDI boundary network by network. List every system, file share, and enclave that touches covered defense information, then confirm your SPRS score was scored against that exact scope — not a tidier version of it.
  • Give your own people somewhere to raise a gap. The Honeywell case started with an employee, not an auditor. An internal reporting channel that actually gets an answer is a control in its own right.
  • Close open POA&Ms instead of rolling them forward. Your annual affirmation represents controls that are implemented, not controls that are planned. That distinction is what these cases turn on.
  • Don’t cancel a scheduled assessment on the strength of the pause. Get your prime’s position in writing first — flow-down obligations live in your contract, not in the Department’s memo.
  • Start asking who owns OT security in your shop. The CIO has now said out loud where attention goes next. If the answer is “nobody, exactly,” you have a head start on a question that’s coming.

Quick hits

  • Aug 28, 2026
    FAR Overhaul’s second batch clears OMB.
    Four proposed rules covering 16 FAR parts approved “consistent with change,” with Federal Register publication and a 30-day comment window expected shortly. The basic safeguarding clause formerly at FAR 52.204-21 gets a new number — the requirement is unchanged, but your contract references and flow-down templates will need updating.
  • Aug 26, 2026
    More than 2,000 Level 2 certifications already issued.
    The Cyber AB reported C3PAOs have completed over 2,000 final Level 2 certifications, that roughly 80% of C3PAOs are small businesses, and that participants from more than 30 nations are now in the ecosystem. The pause stopped the mandate, not the market.
  • Aug 26, 2026
    Legal read from the town hall: certify anyway.
    Attorney Eric Crucius advised organizations to pursue Level 2 certification regardless of whether a current contract requires it, citing reduced security risk and reduced liability exposure.
  • Sep 30, 2026
    CCI grace period closes at month’s end.
    76 Certified CMMC Instructors are fully credentialed with 14 applications pending as the transition window shuts — a small number relative to the training demand a restarted program would create.

Not sure where your organization stands?

CUI Vault gives you a live, always-audit-ready picture of your CUI environment and NIST 800-171 posture — so headlines like today’s are a footnote, not a fire drill. Reach out to your NtelSec team to talk through your current gaps.

This briefing is a general-information summary of publicly reported CMMC and CUI developments. It is not legal advice; consult your compliance counsel before making contractual or certification decisions.
Talk to us about CUI Vault All issues