Contractors’ CMMC Compliance Confidence Grows, But Proof Lags Behind
Contractors in the defense industrial base report heightened confidence in their cybersecurity compliance measures despite significant challenges in demonstrating adherence to standards, according to two recent industry surveys.
Survey Findings and Compliance Gaps
According to a Kiteworks survey of 273 defense contractors conducted after the July 2026 suspension of CMMC 2.0 Phase 2 third-party assessments, 96% of respondents believed their self-attested Supplier Performance Risk System (SPRS) scores would withstand scrutiny. However, only 29% could substantiate this claim with a current SPRS submission and a FedRAMP-authorized platform. The firm combined its compliance maturity metrics with responses to the assessment suspension, generating a composite score of 60 out of 100—substantially lower than a hypothetical average of 77. Nearly one-third of participants scored poorly on both metrics, indicating a critical gap in preparedness.
Legal Risks and Compliance Concerns
The suspension of Phase 2 assessments has not eliminated legal risks for contractors. The Defense Federal Acquisition Regulation Supplement (DFARS) mandates accurate self-attestations, and 84% of surveyed contractors expressed concerns about potential False Claims Act liability stemming from inaccuracies. Additionally, 92% reported engaging legal or compliance reviews to mitigate risks. However, nearly half of respondents were unaware that Phase 1 self-assessment obligations remained active during the pause, and those who claimed high confidence in their understanding of the changes performed no better on factual tests than those with lower confidence levels.
Market Dynamics and Contracting Shifts
Market dynamics have shifted in response to the reduced verification requirements. Fifty-five percent of contractors indicated they are now pursuing work previously avoided due to CMMC Level 2 mandates, while 52% withdrew from Department of War bids and 38% faced disqualification or loss of contracts over the same criteria. Smaller subcontractors, particularly Tier 2 and lower, experienced disproportionately higher bid losses at 55%, compared to 31% among prime contractors.
Financial Investments and Technology Adoption
A separate 2026 State of the DIB Report by CyberSheath and Merrill Research, based on a May 2026 survey of 302 contractors, revealed a similar trend of declining confidence in the accuracy of SPRS scores. While average scores reached a five-year high of +51 (out of a possible 110), confidence in their validity dropped to 65% from 89% in 2025 and 94% in 2024. Financial investments in compliance have increased, with average annual DFARS budgets rising to $155,000. Fifty-three percent of contractors deemed this amount sufficient, while 24% found it excessive. Adoption of core security technologies also grew, including multi-factor authentication (63%), secure backups (48%), data-leakage protection and vulnerability management (44%), and endpoint detection (40%).
Expert Opinions and Calls for Reform
Frank Balonis, field CISO at Kiteworks, highlighted the critical gap between confidence and evidence, while Emil Sayegh, CEO of CyberSheath, noted that many contractors prioritize military mission support over cybersecurity expertise. Sayegh argued that CMMC reforms should prioritize ease of compliance without compromising verifiable security measures.
Conclusion
The surveys collectively reveal a complex landscape where perceived readiness outpaces demonstrable compliance, raising concerns about the effectiveness of current frameworks in safeguarding sensitive defense operations.
