تخطي إلى المحتوى الرئيسي
Cyber News SecurityWeek 5 hours ago

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

Se
SecurityWeek
Defense industry CMMC

Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in their cybersecurity compliance than ever, even as their ability to prove that compliance lags behind.

Kiteworks surveyed 273 defense contractors in the days following the Pentagon’s July suspension of CMMC 2.0 Phase 2 third-party assessments. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform. 

Kiteworks combined its two readiness measures — one tracking compliance maturity, the other tracking how contractors responded to the suspension itself — by multiplying rather than averaging them, producing a combined score of 60 out of 100, well below the roughly 77 a simple average would have produced. Nearly a third of respondents scored low on both measures at once, the report’s largest single grouping.

The CMMC Phase 2 suspension hasn’t removed contractors’ legal exposure. The underlying DFARS obligation to attest accurately never paused, even though the third-party check on those attestations did, and 84% of contractors told Kiteworks they were concerned about False Claims Act liability tied to an inaccurate score. In fact, 92% said they had already brought in legal or compliance review. 

Concerningly, nearly half of respondents didn’t know that Phase 1 self-assessment obligations continued through the pause, and contractors who called themselves ‘very confident’ in their grasp of the changes scored no better on a factual test than those who called themselves only ‘somewhat confident’.

The market has already reacted to the lowered bar. Fifty-five percent of contractors told Kiteworks they’re now bidding on work they previously avoided over CMMC Level 2 requirements, while 52% withdrew from a Department of War bid and 38% reported losing or being disqualified from a contract over the same requirement. Smaller subcontractors bore the brunt: Tier 2 and lower subcontractors reported bid losses at 55%, nearly double the 31% rate among prime contractors.

Advertisement. Scroll to continue reading.

A second report, the 2026 State of the DIB Report from CyberSheath and Merrill Research, surveyed 302 contractors in May 2026, before the suspension took effect, and found a similar disconnect building over a longer stretch. 

Written By Eduard Kovacs

View Original Report

This intelligence was aggregated from SecurityWeek.

Read on Source
Advertisement