US defense contractors reported stronger cybersecurity compliance scores under the Pentagon’s Supplier Performance Risk System (SPRS), but new survey data shows growing doubts about whether those self-assessments are accurate or defensible. CyberSheath and Merrill Research found the average SPRS score rose to a five-year high of +51, up from +33 in 2025, while confidence in score accuracy fell to 65%, down from 89% a year earlier. At the same time, only 1% of contractors said they were fully prepared for Cybersecurity Maturity Model Certification (CMMC), despite increased compliance spending and broad support for mandatory cybersecurity standards.
A separate 2026 survey cited by SecurityWeek found 96% of contractors believed their self-attested SPRS score would survive review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform. The findings come after the Pentagon suspended planned Phase 2 third-party CMMC assessments, but researchers and industry observers warned that DFARS self-attestation requirements remain in force and that contractors could still face False Claims Act exposure if their claims cannot be substantiated. Contractors largely said the standards improve national security, while calling for simpler implementation and more vendor choices to meet compliance demands.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
CyberSheath published its 2026 State of the DIB Report on August 20, 2026. The report found average SPRS scores had risen to +51 in 2026 even as confidence in score accuracy dropped and only 1% of contractors said they were fully prepared for CMMC certification.
In the days following the Pentagon's July 2026 suspension of CMMC 2.0 Phase 2 assessments, Kiteworks surveyed 273 defense contractors. The survey examined contractor confidence, evidence gaps, and legal concerns after the pause.
The Trump administration suspended CMMC Phase II in July 2026, pausing the rollout of independent third-party assessments by C3PAOs. The suspension came ahead of the phase's planned November 2026 start.
CyberSheath and Merrill Research conducted a survey of 302 defense contractors in May 2026 for the 2026 State of the DIB Report. The survey underpinned findings on SPRS scores, confidence, budgets, and CMMC preparedness.
A previous CyberSheath study published in October 2025 found that only 1% of contractors believed they were completely prepared for CMMC certification. The 2026 report said this figure was unchanged.
CyberSheath reported that 89% of contractors were very or extremely confident their SPRS score was accurate in 2025. This was down from 94% in 2024.
CyberSheath found that the average SPRS self-assessment score across surveyed defense contractors reached +33 in 2025, the first positive average in the report's history. The score later rose further in 2026.
CyberSheath reported that 94% of surveyed defense contractors said they were very or extremely confident that their self-reported SPRS score was accurate in 2024. This serves as the earliest benchmark in the later decline in confidence.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.