Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek .
AI Analysis
Technical Summary
Two surveys conducted by Kiteworks and CyberSheath in 2026 highlight a disconnect in the defense industrial base regarding Cybersecurity Maturity Model Certification (CMMC) compliance. Following the Pentagon's suspension of CMMC 2.0 Phase 2 third-party assessments, 96% of surveyed contractors expressed confidence in their self-attested SPRS scores, but only 29% could substantiate these with both current SPRS submissions and FedRAMP-authorized platforms. The suspension did not pause contractors' legal obligations to attest accurately, with 84% concerned about False Claims Act liability. Nearly half of respondents were unaware that Phase 1 self-assessment requirements continued. The market reacted with increased bidding on contracts previously avoided due to CMMC Level 2 requirements, but also with significant bid losses, especially among Tier 2 and lower subcontractors. CyberSheath's earlier survey showed rising SPRS scores but declining confidence in their accuracy and minimal preparedness for certification. Contractors increased spending on DFARS compliance and adoption of core security technologies. Both surveys indicate strong contractor support for independent third-party verification and government-mandated minimum cybersecurity standards, alongside calls for easier implementation and more vendor options. The findings underscore a significant gap between perceived compliance confidence and verifiable evidence.
Potential Impact
The suspension of CMMC Phase 2 third-party assessments has not relieved contractors of their legal obligations to accurately attest compliance, exposing them to potential False Claims Act liability. The discrepancy between high confidence and low ability to prove compliance may lead to increased legal and contractual risks. Smaller subcontractors face disproportionate challenges, including bid losses and disqualifications, potentially impacting the defense supply chain. The gap in verifiable compliance evidence could undermine trust in contractor cybersecurity postures and affect future contract awards. Increased compliance spending and technology adoption indicate resource allocation toward meeting requirements, but low preparedness for certification suggests ongoing vulnerability to compliance failures.
Mitigation Recommendations
Since the Pentagon has suspended CMMC Phase 2 third-party assessments, contractors must continue to meet their legal obligations to accurately self-attest compliance under DFARS. Contractors should ensure current SPRS submissions and utilize FedRAMP-authorized platforms where possible to substantiate compliance claims. Legal and compliance reviews are advisable to mitigate False Claims Act liability. Contractors should stay informed about potential modifications to CMMC Phase 2 and participate in government requests for information. Emphasis should be placed on achieving verifiable proof of compliance while advocating for streamlined implementation and expanded vendor options. No official fix or patch applies as this is a compliance and procedural issue rather than a software vulnerability.
Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
Description
Two industry surveys released this week by Kiteworks and CyberSheath paint a consistent picture of the defense industrial base. The post Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Two surveys conducted by Kiteworks and CyberSheath in 2026 highlight a disconnect in the defense industrial base regarding Cybersecurity Maturity Model Certification (CMMC) compliance. Following the Pentagon's suspension of CMMC 2.0 Phase 2 third-party assessments, 96% of surveyed contractors expressed confidence in their self-attested SPRS scores, but only 29% could substantiate these with both current SPRS submissions and FedRAMP-authorized platforms. The suspension did not pause contractors' legal obligations to attest accurately, with 84% concerned about False Claims Act liability. Nearly half of respondents were unaware that Phase 1 self-assessment requirements continued. The market reacted with increased bidding on contracts previously avoided due to CMMC Level 2 requirements, but also with significant bid losses, especially among Tier 2 and lower subcontractors. CyberSheath's earlier survey showed rising SPRS scores but declining confidence in their accuracy and minimal preparedness for certification. Contractors increased spending on DFARS compliance and adoption of core security technologies. Both surveys indicate strong contractor support for independent third-party verification and government-mandated minimum cybersecurity standards, alongside calls for easier implementation and more vendor options. The findings underscore a significant gap between perceived compliance confidence and verifiable evidence.
Potential Impact
The suspension of CMMC Phase 2 third-party assessments has not relieved contractors of their legal obligations to accurately attest compliance, exposing them to potential False Claims Act liability. The discrepancy between high confidence and low ability to prove compliance may lead to increased legal and contractual risks. Smaller subcontractors face disproportionate challenges, including bid losses and disqualifications, potentially impacting the defense supply chain. The gap in verifiable compliance evidence could undermine trust in contractor cybersecurity postures and affect future contract awards. Increased compliance spending and technology adoption indicate resource allocation toward meeting requirements, but low preparedness for certification suggests ongoing vulnerability to compliance failures.
Defensive Guidance
Since the Pentagon has suspended CMMC Phase 2 third-party assessments, contractors must continue to meet their legal obligations to accurately self-attest compliance under DFARS. Contractors should ensure current SPRS submissions and utilize FedRAMP-authorized platforms where possible to substantiate compliance claims. Legal and compliance reviews are advisable to mitigate False Claims Act liability. Contractors should stay informed about potential modifications to CMMC Phase 2 and participate in government requests for information. Emphasis should be placed on achieving verifiable proof of compliance while advocating for streamlined implementation and expanded vendor options. No official fix or patch applies as this is a compliance and procedural issue rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/contractors-cmmc-confidence-rises-as-ability-to-prove-it-falls-behind/","fetched":true,"fetchedAt":"2026-08-21T08:52:12.067Z","wordCount":1432}
Threat ID: 6a8811bcacd9273b49dec4ad
Added to database: 08/21/2026, 08:52:12 UTC
Last enriched: 08/21/2026, 08:52:21 UTC
Last updated: 08/22/2026, 02:23:05 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.