HackMyIP
← Back to News
2026-08-21 SecurityWeek

Defense Contractors' CMMC Confidence Outpaces Their Ability to Prove Compliance

RegulationSupply Chain

Two new industry surveys reveal a widening gap between perception and reality across the defense industrial base: defense contractors are reporting record confidence in their cybersecurity compliance posture, yet their ability to substantiate those claims continues to deteriorate. Kiteworks surveyed 273 defense contractors immediately after the Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments and found that 96% believed their self-attested Supplier Performance Risk System (SPRS) score would withstand scrutiny. However, only 29% could produce both a current SPRS submission and operate on a FedRAMP-authorized platform. Kiteworks combined its two readiness indices by multiplication rather than averaging, yielding a composite score of 60 out of 100, well below the 77 a simple mean would have produced, with nearly a third of respondents scoring low on both dimensions simultaneously. Contractors seeking to validate their own infrastructure can run a quick SSL/TLS checker against any FedRAMP-aligned platform they rely on.

The CMMC Phase 2 suspension has not erased contractors' legal exposure. The underlying DFARS attestation obligation never paused alongside the third-party verification mechanism, and 84% of respondents flagged False Claims Act liability tied to an inaccurate SPRS score as a concern. Some 92% had already engaged legal or compliance counsel in response, though nearly half were unaware that Phase 1 self-assessment duties remained in force throughout the pause. Notably, contractors who described themselves as "very confident" in their understanding of the changes scored no better on a factual knowledge test than those reporting only "somewhat confident," suggesting confidence is not tracking competence. Organizations auditing their broader compliance hygiene can use a privacy checkup to identify gaps that may parallel SPRS scoring weaknesses.

The market has already adjusted to the lowered assurance bar. Fifty-five percent of contractors told Kiteworks they are now bidding on opportunities they previously avoided due to CMMC Level 2 requirements, while 52% withdrew from a Department of War bid and 38% reported losing or being disqualified from a contract over the same requirement. Smaller subcontractors absorbed disproportionate damage: Tier 2 and lower subcontractors reported bid losses at 55%, nearly double the 31% rate observed among prime contractors. A second study from CyberSheath and Merrill Research, the 2026 State of the DIB Report based on 302 contractors surveyed in May 2026, captured the longer arc. The average SPRS score climbed to a five-year high of +51, up from +33 in 2025 against a maximum of 110, while confidence in those scores collapsed, with only 65% describing themselves as extremely or very confident, down from 89% a year earlier and 94% in 2024. Just 1% considered themselves completely prepared for CMMC certification, unchanged from the prior year, underscoring that rising SPRS numbers and shrinking confidence are moving in opposite directions across the defense supply chain.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →