What the Honeywell settlement teaches about your SPRS score

Honeywell paid $2,042,518 over one network that allegedly fell short of NIST SP 800-171. Three months earlier, a company that posted a perfect 110 was scored at -170. What both cases say about your number.

Posted 110, scored -170. Posted in SPRS: 110. DCMA found: -170. Honeywell: $2,042,518. Working guide.
In this guide

Updated September 30, 2026

The lesson is that your SPRS score is a statement the government can test, and a large company paid $2 million over one network that allegedly didn't match it. If the number you posted is higher than the evidence behind it, fix the gap now, because the cases that end in settlements start years before anyone calls.

On September 1, 2026, the Justice Department announced that Honeywell Aerospace agreed to pay $2,042,518 to resolve allegations that it broke the False Claims Act, the federal fraud law for anyone who bills the government, by failing to meet cybersecurity requirements in a Department of Defense contract (DOJ). The release says a Honeywell business unit submitted claims for payment from April 2020 through December 2023 without meeting NIST SP 800-171 "with respect to one of Honeywell's networks." NIST SP 800-171 is the list of 110 security requirements that defense contractors handling controlled technical data must meet.

What did DOJ actually say about Honeywell?

Less than the headlines. Read the release itself before you read anyone's take on it. It names the period, the standard, and the dollar amount. It names the whistleblower, former employee Rachel Tenney, who receives $375,823. (A whistleblower who files a False Claims Act suit for the government is called a relator and gets a cut of what the government recovers.) It names the investigators, the Defense Criminal Investigative Service. It closes with the standard line: "The claims resolved by the settlement are allegations only and there has been no determination of liability."

What it doesn't name is a breach, a stolen file, a specific control, or a score. The words SPRS, system security plan and POA&M don't appear. The lawyers who wrote client alerts afterward drew the SPRS lesson themselves. Nixon Peabody's alert, for example, says a contractor's "SPRS score, system security plan, plan of action and milestones (POA&M), and incident-reporting conduct can each support an FCA theory" (Nixon Peabody). That's a fair reading of the law. It isn't something DOJ alleged about Honeywell.

So take three facts from Honeywell and leave the rest. One network was enough. Nearly four years of invoices were in play. And the case started with someone on the inside. The suit was filed in 2022 (No. 3:22-cv-129, W.D.N.C.) and settled in 2026. Four years passed between the filing and the check.

For what Honeywell's settlement says about restitution, the money the government says it actually lost, the best we have is a law firm's reading of the agreement: Bass, Berry & Sims reports that $972,628 of the total is restitution (Bass, Berry & Sims via Legal 500). Roughly double, in other words. Keep that ratio in mind.

The case that is about a score

If you want the SPRS lesson stated by DOJ in writing, it's in a smaller settlement from June. SPRS, the Supplier Performance Risk System, is the DoD website where you post your self-assessment score out of 110.

On June 18, 2026, DOJ announced that LOGZONE, a Huntsville logistics contractor with two Navy contracts, agreed to pay $507,144 (DOJ). The settlement agreement spells out what happened to its score (settlement agreement):

  • On October 13, 2021, LOGZONE posted a perfect self-assessment score of 110 in SPRS.
  • On February 2, 2024, DCMA's assessment team (DIBCAC, the Defense Contract Management Agency's cybersecurity assessors) finished a Medium Assessment and scored it at −170. The lowest possible score is −203.
  • The agreement says LOGZONE billed the Navy from May 2021 to March 2025 "despite knowing" it hadn't met DFARS 252.204-7012, the contract clause that requires the 110 controls.
  • Of the $507,144, $253,572 is restitution. Exactly double.

No whistleblower is named. A government assessment found the gap. That's the other way these cases start.

And the case that set the pattern, MORSECORP in March 2025, was about a score too. MORSE posted 104 in January 2021. A consultant it hired told it in July 2022 that the real number was −142. It didn't update SPRS until June 2023, "three months after the United States served MORSE with a subpoena," and paid $4.6 million (DOJ).

Case Announced Paid What started it The gap
MORSECORP March 26, 2025 $4.6 million Whistleblower Posted 104; consultant found −142
LOGZONE June 18, 2026 $507,144 DCMA assessment Posted 110; DCMA found −170
Honeywell Aerospace September 1, 2026 $2,042,518 Former employee One network, April 2020 to December 2023

Notice the size of the gaps. Nobody in these cases was off by four points. A score of 110 doesn't drift to −170 by accident. It starts as a spreadsheet where every row was marked "met" because nobody was asked to prove one.

What your score actually is

Your SPRS score is a summary of a self-assessment against the DoD scoring method, and the rules behind it are stricter than most people who post one realize.

It has to be current. DFARS 252.204-7019 requires an assessment "not more than 3 years old" posted in SPRS to be eligible for award (DFARS 252.204-7019). Current means the date. It doesn't mean the score is still true. That part is on you.

A plan doesn't earn points. The CMMC scoring rule says it plainly: a POA&M (plan of action and milestones, your list of gaps and when you'll close them) "is not a substitute for a completed requirement," and anything not implemented is NOT MET "whether described in a POA&M or not" (32 CFR 170.24(c)(2)(i)(6)). Shops that scored themselves 110 because every gap "was on the plan" have a wrong number.

Drafts don't count. Under the same section, a requirement is met only when "all evidence" is "in final form and not draft." Working papers and unapproved policies are listed as unacceptable.

No SSP, no score. Without an up-to-date system security plan, the written description of your environment and how each requirement is met, the rule says the assessment "could not be completed." Not a low score. No score.

That's why the score, the SSP and the POA&M have to agree. Say your SPRS entry says 110, your SSP says multi-factor login covers everyone, and your POA&M lists "roll out MFA to shop floor" as open. That's three documents telling the government three different things, and whoever reads them side by side, whether a DCMA assessor, a prime, or a former employee's lawyer, will notice.

Why the dates matter more than the dollars

Look at the periods. Honeywell: April 2020 to December 2023. LOGZONE: May 2021 to March 2025. MORSE: the score sat wrong for eleven months after the company knew.

The False Claims Act counts claims, and every invoice submitted while the requirements weren't met can be one (31 U.S.C. 3729). The law allows triple damages plus a penalty per claim. The settlements above landed near double. DOJ's own policy gives credit for "proactive, timely, and voluntary self-disclosure" (Justice Manual 4-4.112). The bill grows with every month the score is wrong and you keep billing, and with every month you knew.

For a small shop, this is the scene to picture. The score was posted in 2023 by an IT contractor who has since left. Nobody kept the worksheet. The owner has renewed contracts and signed invoices every month since. The quality manager, who reads every DFARS clause in every purchase order, mentioned in a meeting last year that "I don't think we really have MFA on the shop floor PCs." Nothing changed. That is the fact pattern in all three cases above, minus the zeros.

Check your number against an assessment, not a memory

You can do a rough version of this yourself in a day. Pull up three things: your SPRS entry with its date, your SSP, and your POA&M if you have one. Then go requirement by requirement and ask one question of each "met": what would I hand an assessor today to prove it? Not a policy. The setting, the log, the export, the signed record.

Start with the requirements that cost 5 points each when missing, because those move a score the most: limiting system access to authorized users (3.1.1), audit logging (3.3.1), multi-factor login (3.5.3), encryption of controlled data (3.13.11), boundary protection (3.13.1), and fixing security flaws on time (3.14.1). Then check the scope. A score only covers the systems you included, and a drawing in the estimator's inbox outside that scope is still a drawing.

If the honest result is meaningfully below what you posted, stop there. Call a lawyer who handles government contracts before you touch SPRS, because the order of what you do next matters. We wrote up that sequence separately, and the Swiss Automation case shows how a quality manager fits into it.

The cheaper version is to have someone else score you first, against evidence, before DCMA or a relator does. That's what a mock assessment is for. How the score is calculated →

Common questions

Did Honeywell admit anything? No. The release says the claims "are allegations only and there has been no determination of liability."

Did Honeywell's case involve its SPRS score? DOJ's release doesn't say. It alleges non-compliance on one network while billing. The SPRS-score cases with published numbers are LOGZONE and MORSECORP.

We're a 20-person shop. Does this apply to us? The law is the same. Swiss Automation, an Illinois machining supplier, paid $421,234 in December 2025, and it sold its parts to primes rather than to DoD (DOJ).

Didn't the CMMC pause change this? No. The July 2026 pause suspended the third-party certificate deadline. The 7012 clause, the 110 requirements and SPRS scores are all still in force. What the pause did and didn't change →

If our score is wrong, should we just lower it? Not on your own. Preserve the record and talk to counsel first. Then correct it.

Mock assessment

Check your score against a mock assessment.

Garde1 runs a mock assessment against all 320 assessment objectives behind the 110 requirements, scores anything without evidence as Not Met with no override, and shows you where its number and the one in SPRS disagree.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE