Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

A Growing Divide Between Defense Contractors’ Confidence and Reality

Two recent surveys paint a concerning picture for defense contractors: while they claim to be more confident than ever in their cybersecurity compliance, their ability to prove it is lagging behind. This disconnect has significant implications for both individual companies and the broader national security landscape.

According to Kiteworks, a survey of 273 defense contractors found that an overwhelming 96% were confident that their self-attested Supplier Performance Risk System (SPRS) scores would hold up under review. However, only 29% could back this claim with concrete evidence – specifically, both a current SPRS submission and a FedRAMP-authorized platform. This suggests that many contractors are relying on faith rather than fact to ensure their compliance.

The data also reveals that nearly half of respondents were unaware that Phase 1 self-assessment obligations continued during the pause in third-party assessments. Moreover, those who claimed to be “very confident” in their understanding of the changes scored no better on a factual test than those who said they were only “somewhat confident”. This highlights a concerning lack of clarity and knowledge among contractors about what is required for compliance.

Despite the suspension of CMMC 2.0 Phase 2 third-party assessments, contractors remain concerned about False Claims Act liability tied to inaccurate scores. A staggering 84% of respondents expressed concern, and an equally high number (92%) have already brought in legal or compliance review experts. This suggests that while confidence is high, the actual risk remains significant.

The market has already begun to respond to these changes. Contractors are now more likely to bid on work they previously avoided due to CMMC Level 2 requirements – a trend that may continue even if third-party assessments resume. Smaller subcontractors have been disproportionately affected, with nearly double the rate of bid losses compared to prime contractors.

A separate survey by CyberSheath and Merrill Research found similar results. The average SPRS score rose to a five-year high, but confidence in the accuracy of those scores plummeted – from 94% just two years ago to only 65%. Only 1% of respondents considered themselves completely prepared for CMMC certification.

While adoption of core security technologies has increased, with nearly two-thirds using multi-factor authentication and over 40% employing endpoint detection, there is a clear disconnect between confidence and evidence. Contractors want verification to remain an essential part of the process rather than fade alongside third-party audits – a sentiment echoed by both surveys.

Ultimately, this divide highlights the need for greater clarity and transparency in compliance requirements. As Frank Balonis, field CISO at Kiteworks, noted, “The finding that matters is the distance between confidence and evidence.” It’s time for defense contractors to shift from relying on faith to backing their claims with concrete proof – a move that will not only improve cybersecurity but also boost national security.


Source: SecurityWeek — 2026-08-21