Cybersecurity Compliance Confidence Soars Among Defense Contractors, but Can They Back It Up?
The defense industry is breathing a collective sigh of relief as contractors express increased confidence in their cybersecurity compliance. However, a closer look at two recent surveys reveals a concerning disconnect between confidence and actual readiness.
According to a survey by Kiteworks, 96% of defense contractors are confident that their self-attested Supplier Performance Risk System (SPRS) scores will hold up under review. But here’s the catch: only 29% can actually back those claims with both a current SPRS submission and a FedRAMP-authorized platform. This means nearly three-quarters of contractors are relying on self-assessment, rather than independent verification.
The surveys also highlight a concerning trend: despite increased confidence, actual readiness is lagging behind. Kiteworks’ combined score, which measures compliance maturity and response to the Pentagon’s suspension of CMMC 2.0 Phase 2 third-party assessments, sits at a paltry 60 out of 100. Nearly one-third of respondents scored low on both measures simultaneously.
The market has already begun to feel the effects of this disconnect. Contractors are now bidding on work they previously avoided due to CMMC Level 2 requirements, with 55% reporting an increase in bid activity and 38% withdrawing from contracts altogether. Smaller subcontractors have borne the brunt of these changes, with Tier 2 and lower subcontractors reporting bid losses at a staggering 55%.
CyberSheath’s survey, which polled contractors before the suspension took effect, found similar results. Average SPRS scores climbed to a five-year high, but confidence in those scores plummeted, with only 1% considering themselves completely prepared for CMMC certification.
The takeaway from these surveys is clear: while defense contractors may be confident in their cybersecurity compliance, they are struggling to demonstrate actual readiness. This disconnect has significant implications for national security and contractor liability. As Frank Balonis, field CISO at Kiteworks, noted, “The finding that matters is the distance between confidence and evidence.”
To bridge this gap, contractors should prioritize independent verification and objective proof of their cybersecurity protections. Rather than relying on self-assessment, they should invest in core security technologies and robust compliance programs.
In the words of Emil Sayegh, CEO of CyberSheath, “Reform of CMMC should make compliance easier to achieve without sacrificing objective, verifiable proof that protections are actually working.” Until then, defense contractors will continue to face significant risks and liabilities.
Source: SecurityWeek — 2026-08-21