DoD Contractors Face Verification Gap Amidst Rising CMMC Confidence
Recent industry surveys reveal a concerning disconnect within the Defense Industrial Base (DIB): while contractors express growing confidence in their cybersecurity compliance, their ability to verifiably prove adherence to standards like the Cybersecurity Maturity Model Certification (CMMC) is notably lagging. This trend carries significant implications for national security, contract eligibility, and legal exposure, especially as the Department of Defense (DoD) refines its CMMC implementation strategy. The findings underscore the critical need for DoD contractors to move beyond self-assurance towards demonstrable cybersecurity maturity, particularly in light of ongoing regulatory expectations, as reported by SecurityWeek.
Key Findings from Industry Surveys
Two primary reports—one from Kiteworks and another from CyberSheath and Merrill Research—collectively paint a consistent picture of the DIB’s current state:
-
Confidence vs. Verifiable Proof: Kiteworks surveyed 273 defense contractors following the July suspension of CMMC 2.0 Phase 2 third-party assessments. An overwhelming 96% expressed confidence that their self-attested Supplier Performance Risk System (SPRS) score would withstand scrutiny. However, only 29% could substantiate this claim with both a current SPRS submission and a FedRAMP-authorized platform. The combined readiness score from Kiteworks, which accounted for compliance maturity and contractor response to the suspension, stood at 60 out of 100, significantly below a simple average. Nearly a third of respondents scored low on both measures, highlighting a systemic challenge in DoD contractor cybersecurity verification.
-
Market Impact and Legal Exposure: The CMMC Phase 2 suspension did not alleviate contractors’ legal obligations. The underlying DFARS requirement for accurate attestations continued, leading 84% of contractors to express concern about False Claims Act liability CMMC implications tied to inaccurate scores. Consequently, 92% had already engaged legal or compliance review. The market has reacted, with 55% of contractors now bidding on work previously avoided due to CMMC Level 2 requirements. Conversely, 38% reported losing or being disqualified from contracts, with smaller Tier 2 and lower subcontractors disproportionately affected (55% bid losses compared to 31% for prime contractors).
-
Technology Adoption and Spending Trends: The 2026 State of the DIB Report from CyberSheath and Merrill Research, which surveyed 302 contractors, corroborated the confidence-to-evidence gap. While the average SPRS score reached a five-year high of +51 (out of 110), confidence in the accuracy of these scores sharply declined, from 89% in 2025 to 65% in 2026. Only 1% of contractors felt completely prepared for CMMC certification. Regarding expenditures, the average annual DFARS compliance budget increased to $155,000. Adoption of core security technologies also saw an uptick, with multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, and endpoint detection at 40%.
Despite the challenges, a strong consensus exists for retaining independent verification. Both surveys indicated that over 90% of contractors consider independent third-party authorization essential or important for future vendor selection, and a significant majority expect CMMC 2.0 Phase 2 third-party assessments to return in some form.
Actionable Recommendations for DoD Contractors
To navigate this evolving compliance landscape and mitigate risks, organizations within the DIB should prioritize the following:
- Prioritize Verifiable Documentation: Move beyond self-attestation by systematically documenting all cybersecurity controls, processes, and evidence. Ensure that all claims made in SPRS submissions are directly supported by auditable artifacts and system configurations.
- Proactive Independent Assessment Readiness: Prepare for potential third-party assessments by conducting internal audits and readiness checks. This includes validating the functionality and effectiveness of implemented security controls, rather than solely focusing on their presence.
- Understand Continuing Obligations: Clarify all current CMMC and DFARS obligations, especially regarding Phase 1 self-assessment requirements, which continued through the Phase 2 suspension. Consult with legal and compliance experts to minimize False Claims Act liability.
- Strategic Investment in Security Technologies: While technology adoption is increasing, ensure that cybersecurity investments are strategic and align directly with CMMC and DFARS requirements. Focus on solutions that provide demonstrable evidence of control implementation and continuous monitoring capabilities.
- Engage with Regulatory Processes: Actively participate in DoD Requests for Information (RFIs) and other feedback mechanisms regarding CMMC evolution. This allows contractors to influence future compliance frameworks and stay abreast of upcoming changes.
Related: Cloudflare Achieves FedRAMP High Status for Government, Outdated Cybercrime Laws Threaten Security Researchers