Two industry surveys published this week describe the same growing gap inside the defense industrial base: contractors say they trust their cybersecurity compliance scores more than ever, even as their ability to document and prove that compliance falls behind.
Kiteworks surveyed 273 defense contractors shortly after the Pentagon suspended CMMC 2.0 Phase 2 third-party assessments in July. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System (SPRS) score would survive a review, but only 29% could support that confidence with both a current SPRS submission and a FedRAMP-authorized platform. Kiteworks combined its compliance-maturity and suspension-response metrics multiplicatively rather than averaging them, yielding a combined readiness score of 60 out of 100, well under the roughly 77 a simple average would have produced. Nearly a third of respondents scored poorly on both measures simultaneously.
Legal Exposure Hasn’t Paused
The suspension halted third-party checks, but the underlying DFARS obligation to attest accurately never stopped. Eighty-four percent of contractors told Kiteworks they were worried about False Claims Act liability tied to an inaccurate score, and 92% said they had already engaged legal or compliance review. Nearly half of respondents did not realize that Phase 1 self-assessment obligations continued through the pause, and self-described ‘very confident’ contractors scored no better on a factual knowledge test than those who called themselves only ‘somewhat confident’.
The market has already adjusted to the lowered bar. Fifty-five percent of contractors said they are now bidding on work they previously avoided because of CMMC Level 2 requirements, while 52% withdrew from a Department of War bid and 38% reported losing or being disqualified from a contract tied to those requirements. Smaller subcontractors absorbed most of the damage: Tier 2 and lower subcontractors reported bid losses at 55%, nearly double the 31% rate among prime contractors.
A Longer-Running Trend
A second study, the 2026 State of the DIB Report from CyberSheath and Merrill Research, surveyed 302 contractors in May 2026, before the suspension took effect, and found the same disconnect building over time. The average SPRS score climbed to a five-year high of +51 (out of a possible 110), up from +33 in 2025. But confidence in score accuracy dropped sharply, from 94% in 2024 and 89% in 2025 to 65% this year. Only 1% of contractors considered themselves fully prepared for CMMC certification, unchanged from the prior year. Average annual DFARS compliance budgets rose to $155,000, and adoption of core controls increased, with MFA at 63%, secure backup at 48%, and endpoint detection at 40%.
Contractors in both surveys want independent verification to remain part of the process. Kiteworks found 93% consider third-party authorization essential or important to future vendor selection, and 93% plan to comment on the Department of War’s request for information. CyberSheath found 90% want the government to mandate minimum cybersecurity standards across all federal contractors. Kiteworks field CISO Frank Balonis said the key finding is the distance between confidence and evidence, while CyberSheath CEO Emil Sayegh argued reform should simplify compliance without sacrificing verifiable proof that protections actually work.
