Contractor confidence in CMMC is growing as the ability to prove it is lagging

Two industry surveys released this week paint a consistent picture of the defense industrial base: Contractors say they are more confident about their cybersecurity compliance than ever, even as their ability to prove compliance is lagging.

Kiteworks survey 273 defense contractors in the days following the Pentagon’s July suspension of CMMC 2.0 Phase 2 third-party assessments. Ninety-six percent said they were confident their Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could support that claim with both a current SPRS submission and a FedRAMP-authorized platform.

Kiteworks combined its two readiness measures — one tracking compliance maturity, the other tracking how contractors responded to the shutdown itself — by multiplying them instead of averaging them, producing a combined score of 60 out of 100, well below the roughly 77 a simple average would yield. Nearly a third of respondents scored low on both measures at once, the largest single group in the report.

The suspension of CMMC Phase 2 has not removed contractors’ legal exposure. DFARS’ primary duty to accurately certify has never been suspended, although third-party verification of those certifications has, and 84% of contractors told Kiteworks they are concerned about False Claims Act liability associated with an inaccurate result. In fact, 92% said they had already done a legal or compliance check.

It is concerning that nearly half of respondents were unaware that Phase 1 self-assessment duties continued through the break, and performers who called themselves “very confident” in their understanding of the changes did not perform better on a factual test than those who called themselves only “somewhat confident.”

The market is already reacting to the lowered bar. Fifty-five percent of contractors told Kiteworks that they are now bidding on work they previously avoided because of CMMC Level 2 requirements, while 52% have pulled out of a War Department bid and 38% reported losing or being disqualified from a contract because of the same requirement. Smaller subcontractors bore the brunt: Tier 2 subcontractors and below reported bid losses of 55%, nearly double the rate of 31% among prime contractors.

Advertising. Scroll to continue reading.

Second report, 2026 DIB report status by CyberSheath and Merrill Research, surveyed 302 contractors in May 2026, before the shutdown went into effect, and found a similar disconnect building over a longer stretch.

The average SPRS score climbed to a five-year high of +51, up from +33 in 2025 against a perfect possible score of 110. But confidence that those scores were accurate fell sharply: 65 percent of contractors said they were extremely or very confident, down from 89 percent a year earlier and 94 percent in 2024. Only 1 percent considered themselves fully ready for CMMC certification. unchanged from the previous year.

As for costs, CyberSheath found that average annual budgets for DFARS compliance have risen to $155,000, with 53% of contractors calling that amount “just right” and 24% calling it more than enough.

Adoption of core security technologies also increased, with multi-factor authentication at 63%, secure backup at 48%, data leakage protection and vulnerability management at 44%, and endpoint detection at 40%.

Contractors in both surveys want verification to remain part of the process, rather than disappearing along with third-party audits. Kiteworks found that 93 percent of respondents said independent third-party clearance would be essential or important to future vendor selection, and 93 percent planned to comment on the War Department’s request for information, with 58 percent expecting Phase 2 to return in some modified form.

CyberSheath found that 90% of contractors want the government to mandate minimum cybersecurity standards for all federal contractors, and 77% say DFARS compliance significantly improves national security. On the other hand, 74% want deployment to be easier and 70% want more vendor options.

“The finding that matters is the distance between confidence and evidence,” said Frank Balonis, field CISO at Kiteworks.

Emil Sayegh, CEO of CyberSheath, puts it differently, noting that most contractors are manufacturers and engineers focused on supporting the military mission, not cybersecurity specialists. Sayegh argues that any reform of the CMMC must make it easier to achieve compliance without sacrificing objective, verifiable proof that the protections actually work.

Connected: Industry Reactions to Pentagon Shutdown of CMMC Phase 2

Connected: Eternal Conformity: Why Better Questions Win Over Bigger Frames

Connected: The White House is mobilizing security firms for operations against foreign cybercrime gangs

Leave a Reply

Your email address will not be published. Required fields are marked *