Contractors more confident in CMMC compliance even as proof lags

Two industry surveys found defense contractors reporting higher confidence in CMMC compliance while evidence to back self-attested scores remains limited.

Two industry surveys found defense contractors reporting higher confidence in their Cybersecurity Maturity Model Certification (CMMC) compliance even as evidence to back self-attested scores remained limited. Kiteworks surveyed 273 defense contractors in the days after the Pentagon suspended CMMC 2.0 Phase 2 third-party assessments in July and reported that 96% of respondents were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review. Only 29% of those respondents could produce both a current SPRS submission and access to a FedRAMP-authorized platform. Kiteworks combined two readiness measures by multiplying them and produced a composite score of 60 out of 100, lower than the roughly 77 that a simple average would have produced. Nearly one-third of respondents scored low on both measures.

The suspension did not remove the Defense Federal Acquisition Regulation Supplement (DFARS) obligation to attest accurately. Eighty-four percent of contractors reported concern about False Claims Act liability tied to inaccurate scores, and 92% said they had engaged legal or compliance reviewers. Nearly half of respondents were unaware that Phase 1 self-assessment duties continued during the pause. Respondents who described themselves as “very confident” about their understanding of the pause performed no better on a factual quiz than those who said they were only “somewhat confident.”

The market reacted quickly. Fifty-five percent of contractors told Kiteworks they were bidding on work they had previously avoided because of CMMC Level 2 requirements. Fifty-two percent reported withdrawing from a Department of War bid and 38% said they had lost or been disqualified from a contract over the same requirement. Smaller subcontractors reported higher losses: Tier 2 and lower subcontractors experienced bid losses at 55%, compared with 31% among prime contractors.

A separate 2026 State of the Defense Industrial Base report from CyberSheath and Merrill Research, based on a May 2026 survey of 302 contractors conducted before the suspension, found a similar pattern. The average SPRS score rose to +51, up from +33 in 2025 on a scale where a perfect score is 110. Still, only 65% of contractors said they were extremely or very confident in those scores, down from 89% a year earlier. One percent said they were completely prepared for CMMC certification, unchanged from the prior year.

CyberSheath reported that average annual DFARS compliance budgets increased to $155,000. Fifty-three percent of firms called that amount “just right” and 24% said it was more than enough. Adoption of core security tools increased: multi-factor authentication at 63%, secure backup at 48%, data-loss prevention and vulnerability management at 44%, and endpoint detection at 40%.

Both surveys showed strong demand for independent verification. Kiteworks found 93% of respondents said independent third-party authorization would be essential or important to future vendor selection, and 93% planned to comment on the government request for information; 58% expected Phase 2 to return in a modified form. CyberSheath found 90% of contractors want the government to mandate minimum cybersecurity standards across all federal contractors, and 77% said DFARS compliance meaningfully improves national security. At the same time, 74% said implementation should be easier and 70% wanted more vendor options.

Frank Balonis, field chief information security officer at Kiteworks, described the key finding as “the distance between confidence and evidence.” Emil Sayegh, chief executive of CyberSheath, noted that most contractors are manufacturers and engineers focused on supporting the military mission rather than cybersecurity specialists and called for reforms that make compliance easier to achieve while preserving objective, verifiable proof that protections are working.

Background: Phase 2 of CMMC was designed to require third-party assessments to verify contractors’ cybersecurity posture. The Pentagon’s July pause removed the third-party check temporarily but left self-attestation requirements and DFARS obligations in place, creating legal and market uncertainty across the defense supply chain.

Articles by this author