[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0FXpbV29JSoYfg1pGQdPPqz9-74P6NVOB04dwlgqxWA":3},{"article":4,"iocs":53},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":35},"4fb4a8db-5607-4cc5-acf7-dc71c1156f4a","Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind","contractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind-abb668","Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek.","Two recent surveys reveal a growing disconnect within the defense industrial base regarding CMMC compliance. Contractors express high confidence in their self-attested scores, yet struggle to provide evidence of actual compliance, such as using FedRAMP-authorized platforms. This confidence gap persists despite concerns about False Claims Act liability and the ongoing DFARS obligation to attest accurately.","Defense contractors are more confident in CMMC compliance, but their ability to prove it is falling behind.","Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in their cybersecurity compliance than ever, even as their ability to prove that compliance lags behind. Kiteworks surveyed 273 defense contractors in the days following the Pentagon’s July suspension of CMMC 2.0 Phase 2 third-party assessments. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform. Kiteworks combined its two readiness measures — one tracking compliance maturity, the other tracking how contractors responded to the suspension itself — by multiplying rather than averaging them, producing a combined score of 60 out of 100, well below the roughly 77 a simple average would have produced. Nearly a third of respondents scored low on both measures at once, the report’s largest single grouping. The CMMC Phase 2 suspension hasn’t removed contractors’ legal exposure. The underlying DFARS obligation to attest accurately never paused, even though the third-party check on those attestations did, and 84% of contractors told Kiteworks they were concerned about False Claims Act liability tied to an inaccurate score. In fact, 92% said they had already brought in legal or compliance review. Concerningly, nearly half of respondents didn’t know that Phase 1 self-assessment obligations continued through the pause, and contractors who called themselves ‘very confident’ in their grasp of the changes scored no better on a factual test than those who called themselves only ‘somewhat confident’. The market has already reacted to the lowered bar. Fifty-five percent of contractors told Kiteworks they’re now bidding on work they previously avoided over CMMC Level 2 requirements, while 52% withdrew from a Department of War bid and 38% reported losing or being disqualified from a contract over the same requirement. Smaller subcontractors bore the brunt: Tier 2 and lower subcontractors reported bid losses at 55%, nearly double the 31% rate among prime contractors.Advertisement. Scroll to continue reading. A second report, the 2026 State of the DIB Report from CyberSheath and Merrill Research, surveyed 302 contractors in May 2026, before the suspension took effect, and found a similar disconnect building over a longer stretch. The average SPRS score climbed to a five-year high of +51, up from +33 in 2025 against a perfect possible score of 110. But confidence that those scores were accurate fell sharply: 65% of contractors said they were extremely or very confident, down from 89% a year earlier and 94% in 2024. Only 1% considered themselves completely prepared for CMMC certification, unchanged from the prior year. As for spending, CyberSheath found average annual DFARS compliance budgets rose to $155,000, with 53% of contractors calling that amount “just right” and 24% calling it more than enough. Adoption of core security technologies also increased, with multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, and endpoint detection at 40%. Contractors in both surveys want verification to remain part of the process rather than fade alongside third-party audits. Kiteworks found 93% of respondents said independent third-party authorization would be essential or important to future vendor selection, and 93% plan to comment on the Department of War’s request for information, with 58% expecting Phase 2 to return in some modified form. CyberSheath found 90% of contractors want the government to mandate minimum cybersecurity standards across all federal contractors, and 77% said DFARS compliance meaningfully improves national security. On the other hand, 74% wanted implementation made easier and 70% wanted more vendor options. “The finding that matters is the distance between confidence and evidence,” said Frank Balonis, field CISO at Kiteworks. Emil Sayegh, CEO of CyberSheath, framed it differently, noting that most contractors are manufacturers and engineers focused on supporting the military mission rather than cybersecurity specialists. Sayegh argued that any reform of CMMC should make compliance easier to achieve without sacrificing objective, verifiable proof that protections are actually working. Related: Industry Reactions to Pentagon Suspending CMMC Phase 2 Related: Timeless Compliance: Why Better Questions Beat Bigger Frameworks Related: White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training PausesHackers Using AI to Target Siemens PLCs in Critical US SectorsCl0p Ransomware Group Names Over 40 Victims of PTC Windchill CampaignCareCloud Data Breach Impact Grows to 3.7 Million IndividualsFortinet Acquires AI Security Company Virtue AIIrregular Details How a Naming Error Let AI Models Attack a Real Company Conflicting Test Goals Pushed Claude Agents to Deploy Self-Replicating MalwareCritical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure Latest News Rust Supply Chain Attack Linked to North Korean HackersMicrosoft Rolls Out 22 Fresh Security PatchesCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesHackers Target Zimbra Servers in Active Exploitation CampaignSurveillance – Everything You Wanted to Know, But Were Afraid to AskThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesMLflow Vulnerability Exploited for Cloud Credential Theft Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveDaniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.Allied Universal has named Jordan Avnaim Global Chief Information Security Officer.Cycode has promoted Seth Robbins to President and Chief Revenue Officer.More People On The MoveExpert Insights The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dea","https:\u002F\u002Fwww.securityweek.com\u002Fcontractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F02\u002FDefense-industry-DIB.jpeg","2026-08-21T08:41:06+00:00","2026-08-21T10:00:26.062737+00:00",7,[18,21,23,25,28],{"name":19,"type":20},"CMMC 2.0","product",{"name":22,"type":20},"SPRS",{"name":24,"type":20},"FedRAMP",{"name":26,"type":27},"cybersecurity","technology",{"name":29,"type":27},"DFARS","53f9c4b6-8bc6-4964-9169-d09e5cd41d72",{"id":30,"icon":32,"name":33,"slug":34},null,"Compliance","compliance",[36,38,43,48],{"category":37},{"id":30,"icon":32,"name":33,"slug":34},{"category":39},{"id":40,"icon":32,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":45,"icon":32,"name":46,"slug":47},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":49},{"id":50,"icon":32,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]