Two recent studies on the defense industrial base paint a consistent picture: many contractors feel increasingly confident about their cybersecurity compliance related to CMMC. At the same time, the CMMC proof—the substantive backing that supports that confidence—appears to be falling behind. The gap between trust and verifiable facts is becoming more visible, especially since the CMMC 2.0 rules around third-party assessments have been temporarily paused.
For organizations, the key question is therefore not only whether they are “ready,” but whether they can also prove that readiness with up-to-date submissions and checkable systems. Below, you’ll find what the surveys measure, what friction shows up in practice, and what contractors expect going forward.
Why contractors have more confidence right now
In one study by Kiteworks (273 defense contractors, conducted in the days following the Pentagon suspension of CMMC 2.0 Phase 2 third-party assessments), the majority says things are fine based on their own assessment. A large group, in particular, says they trust that their Supplier Performance Risk System (SPRS) score will hold up when assessed.
On paper, compliance looks stable—or even improved. That matters because contractors must keep track of what they do under the relevant obligations, including the self-attested components needed to support their own compliance. But that’s where the friction appears: trusting the score is not the same as being able to substantiate it with the right data and platforms.
The gap: lots of certainty, too little provable CMMC proof
The most notable detail from the Kiteworks study is the difference between “thinking it’s correct” and “being able to prove that it’s correct.” Of the respondents, 96% say they have confidence in their SPRS score. Only 29%, however, can back that up with two specific conditions: an up-to-date SPRS submission and a platform authorized under FedRAMP.
To capture that discrepancy quantitatively, Kiteworks combined two readiness measures. The reporting shows that it’s not enough to score well on just one item: the combination is handled more strictly by multiplying scores rather than averaging them. As a result, the combined outcome lands at 60 out of 100—significantly lower than what you’d get if you simply “averaged” those two components.
Roughly one-third of respondents stands out as the largest single group: organizations that score low on both dimensions at the same time. This suggests the issue is not, for everyone, “a small detail,” but that the core CMMC proof for part of the market is structurally harder to produce.
Legal obligations kept running
An important point for compliance teams is that pausing third-party testing did not automatically eliminate legal risk. The underlying DFARS obligation to attest accurately did not stop. In other words: a paused assessment changes nothing about the requirement to explain truthfully and correctly.
That’s why contractors also explicitly say they are concerned about liability, including risks that could arise from the False Claims Act if the score is incorrect. In the study, 84% of contractors who expressed concerns said so. In addition, 92% report that they have already engaged legal or compliance review to stay on the right track.
Here too, you can see the gap. Nearly half of the respondents did not know that the self-assessment obligations from Phase 1 continued during the pause. What’s more, organizations that describe themselves as “extremely confident” about the actual test component do not perform better than parties that rate it as “somewhat confident.” That suggests self-assessment doesn’t always match the concrete knowledge required to meet the rules.
Impact on bids: lower thresholds, different outcomes
Market shifts after lowering or moving CMMC components are also noticeable in procurement. In the Kiteworks study, 55% say they are bidding again on work they previously avoided due to CMMC Level 2 requirements. At the same time, some report negative effects: 52% withdrew from an award process in war-domain-like procedures, and 38% says it lost a contract or was disqualified based on the same requirements.
Smaller subcontractors appear to take a relatively harder hit. In the data, Tier 2 and lower subcontractors report bid losses of 55%, almost double the 31% seen among prime contractors. This indicates that practical capacity to translate compliance into evidence is not distributed evenly.
A recurring pattern in 2026: confidence falls, scores rise
A second report—the 2026 State of the DIB Report from CyberSheath and Merrill Research—questions 302 contractors (May 2026) before the suspension effect kicked in. This research shows a similar difference that builds up over a longer period.
In it, the average SPRS score rises to a five-year high of +51 (versus +33 in 2025), with a perfect possible score of 110. At the same time, confidence that those scores are accurate declines: 65% say they are extremely or very confident, compared to 89% a year earlier and 94% in 2024. Only 1% considers itself fully prepared for CMMC certification, and that changes little compared with the previous year.
In other words: improvements in measured scores do not automatically come with a proportional increase in confidence in the correctness of those scores. For CMMC compliance, this means organizations need to strengthen their proof process—not just their reporting or tooling.
Investments and security technologies increase
The studies also look at the financial side and the implementation of core security measures. CyberSheath cites an average annual DFARS compliance budget of $155,000. Of that, 53% considers the amount “about right,” while 24% says it is too low and that they have more than enough.
Adoption of multiple security technologies also rises. Multi-factor authentication is used by 63%, secure backup by 48%, and data-leakage protection and vulnerability management by 44%. Endpoint detection is at 40%. The pattern suggests teams are investing in safeguards, but the endpoint—the CMMC proof that is explainable and auditable—still needs extra attention.
What contractors want: verification stays important
A striking difference from debates in the public sphere is that contractors do not want verification to disappear. In the Kiteworks study, 93% say independent third-party authorization remains essential or important when selecting suppliers. In addition, 93% say they will respond to a request for information, with 58% expecting Phase 2 to return in an adjusted form.
The CyberSheath study points in the same direction. 90% wants the government to require minimum cybersecurity standards for all federal contractors. Additionally, 77% says DFARS compliance demonstrably contributes to national security. At the same time, they also want practical feasibility: 74% asks for easier implementation, and 70% wants more options in terms of suppliers.
The real message: the distance between trust and evidence
The combined interpretation from both studies is clear: it’s not only about compliance “on paper,” but about verifying what is actually happening. As one field CISO puts it: the key insight is the gap between “we’re confident” and “we can prove it.” That’s exactly the area where many organizations can tighten their processes.
For security and compliance teams, the practical takeaway is that you can’t just ensure controls exist. You also need to be able to demonstrate them at the right time—with up-to-date submissions, suitable platforms, and well-governed internal documentation.
Conclusion
The two surveys depict a market that is moving forward while also struggling. Scores and investments are increasing, but CMMC proof remains difficult for part of the defense-industrial base to fully get in place. Moreover, gaps in knowledge about ongoing obligations create additional risk, while legal and compliance review is being engaged increasingly often.
For anyone serious about supporting CMMC, it’s therefore wise to treat verification not as a one-time third-party check, but as an ongoing part of the compliance process. Only then can certainty turn into verifiable proof—the exact shift contractors and governments expect.
Related reading: if you want more context on obligations and risks around CMMC, this topic connects to insights on regulation and verifiability, such as in
