Defense Contractors Continue to Struggle with Basic CMMC Requirements

0
2

Key Takeaways

  • Only about two‑thirds of defense contractors are highly confident that their CMMC self‑assessment scores truly reflect their cybersecurity posture.
  • Contractor confidence in self‑assessments has dropped sharply, from 94 % in 2024 to 65 % in 2026.
  • The median contractor believes it is only 70 % ready for a formal CMMC certification review, with just 1 % claiming full readiness.
  • Despite low confidence, self‑assessment scores have turned positive (+51 in 2026) and adoption of core security practices is rising.
  • A “confidence disconnect” exists: contractors report stronger programs and higher scores yet doubt the accuracy of those claims.
  • When third‑party reviews were conducted, 63 % passed on the first attempt.
  • Over 80 % of contractors want the DFARS cybersecurity rules to extend to managed security service providers, managed service providers, and other technology vendors.
  • Concerns about supply‑chain risk drive the push for broader third‑party standards.
  • The Trump administration continues to enforce cybersecurity representations via the False Claims Act, even after pausing CMMC’s second phase.
  • CyberSheath’s findings are based on a survey of 302 defense contractors (prime, subcontractor, and dual‑role firms) with revenues between $500 k and $1 M.
  • The data suggest that while technical controls are improving, cultural and procedural trust in self‑certification remains weak, posing ongoing risk to the defense industrial base.

Introduction to CMMC Challenges
The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program aims to elevate cybersecurity hygiene across the defense industrial base. However, implementation has been uneven, with contractors voicing persistent concerns about the burden of compliance. Even as the Pentagon attempts to ease those burdens—most notably by pausing the second phase that would mandate independent third‑party assessments—many firms still report difficulty meeting the existing first‑phase requirements. The tension between the need for robust security and the practical limits of contractor resources remains a central theme in ongoing discussions about defense procurement reform.

Self‑Assessment Confidence Levels
According to a CyberSheath report released in 2026, only 65 % of contractors that submitted CMMC self‑assessment scores expressed extreme or very high confidence that those scores accurately captured their cybersecurity posture. This figure marks a notable decline from prior years, indicating a growing skepticism about the reliability of self‑reported data. The remaining one‑third of respondents either expressed moderate confidence or were uncertain, underscoring a widespread lack of trust in the self‑assessment process as a true measure of readiness.

Declining Confidence Over Time
Confidence in self‑assessed cybersecurity readiness has eroded steadily since 2024. In that year, 94 % of contractors reported high confidence in their scores; the proportion fell to 89 % in 2025 and further dropped to 65 % in 2026. This three‑year trend suggests that, despite incremental improvements in security controls, contractors are becoming less convinced that their internal evaluations align with objective standards. The erosion of confidence may reflect heightened awareness of gaps, increased scrutiny from regulators, or a growing complexity of threat landscapes that outpaces internal validation efforts.

Perceived Readiness for Certification
When asked to gauge their preparedness for a formal CMMC certification review, the median contractor indicated they felt only 70 % ready. A mere 1 % of respondents claimed to be fully prepared, while about one‑third believed they were at least 80 % prepared. These readiness estimates reveal a significant gap between perceived capability and the threshold required for certification, highlighting that many firms still view themselves as lacking sufficient maturity to withstand rigorous third‑party evaluation.

Adoption of Core Security Practices
Paradoxically, while confidence and readiness scores are low, contractors have shown measurable progress in implementing foundational security controls. In 2026, the mean self‑assessment score turned positive at +51, up from -25 in 2022 and -12 in 2024, and a marked increase from +33 in 2025. Moreover, for the first time, at least four in ten contractors reported having adopted five key practices: multifactor authentication (63 %), secure backups (48 %), data‑leakage protections (44 %), vulnerability management (44 %), and endpoint detection (40 %). These figures suggest that technical hygiene is improving, even if trust in self‑reported metrics lags behind.

The Confidence Disconnect
CyberSheath characterizes the prevailing situation as a “confidence disconnect.” Contractors simultaneously report stronger cybersecurity programs, higher compliance scores, and greater investment than ever before, yet they remain doubtful about the accuracy of those self‑generated claims. This disconnect may stem from several factors: the evolving nature of CMMC requirements, the difficulty of producing sufficient evidence to support executive attestations, and a growing awareness that internal audits may overlook subtle vulnerabilities. As a result, contractors are increasingly wary that their self‑assessments could misrepresent true risk exposure to the government.

Outcomes of Third‑Party Reviews
When contractors did undergo independent third‑party reviews—a process currently paused for CMMC Phase 2—the results were relatively favorable. Approximately 63 % of those reviewed passed on the first attempt, indicating that a substantial subset of the defense base can meet the standard when subjected to objective evaluation. This pass rate offers a benchmark for what is achievable under rigorous scrutiny and underscores the potential value of reinstating mandatory third‑party assessments once concerns about cost and burden are addressed.

Desire for Broader DFARS Application
Reflecting anxieties about supply‑chain exposure, a strong majority of contractors advocate extending cybersecurity requirements beyond immediate defense suppliers. More than eight in ten respondents said the Defense Federal Acquisition Regulation Supplement (DFARS) should apply to managed security service providers; 63 % supported its extension to managed service providers; and 58 % argued it should cover other technology providers. These preferences reveal a consensus that the current scope of DFARS leaves critical links in the supply chain insufficiently regulated, creating potential weak points that adversaries could exploit.

Supply‑Chain Concerns and Third‑Party Expectations
Contractors’ push for broader DFARS coverage is rooted in tangible supply‑chain risks. As organizations increasingly rely on third parties to safeguard controlled unclassified information (CUI), many believe those providers should be held to comparable cybersecurity standards. The perception that external vendors may not adhere to the same rigor heightens vulnerability to nation‑state hacking campaigns that target the defense industrial base through less‑secure intermediaries. By advocating for uniform standards, contractors aim to close these gaps and raise the overall security posture of the ecosystem.

Enforcement via the False Claims Act
Even after the Trump administration suspended the enhanced CMMC requirements, it has continued to leverage the False Claims Act to pursue defense firms that allegedly misrepresent their cybersecurity postures to the government. CyberSheath notes that this enforcement trend sends a clear signal: while the obligation for third‑party certification may be delayed, the responsibility to truthfully attest to compliance remains firmly in place. Contractors thus face legal and financial repercussions for inaccurate self‑reporting, reinforcing the need for honest, evidence‑based assessments despite any regulatory flexibilities.

Survey Methodology Overview
CyberSheath’s insights derive from a survey of 302 defense contractors conducted in 2026. The sample included 184 prime contractors, 107 subcontractors, and 11 firms that operated in both capacities. Respondents spanned the IT, manufacturing, healthcare, and transportation sectors, with all reporting annual revenues between $500,000 and $1 million. This diverse cross‑section provides a representative view of the challenges faced by midsize firms that form a substantial portion of the defense supply chain, lending credibility to the reported trends in confidence, readiness, and control adoption.

Implications and Outlook
The data paint a nuanced picture: technical defenses are strengthening, yet confidence in self‑certification is waning, and contractors remain uncertain about their readiness for formal evaluation. This dichotomy suggests that simply investing in controls may not be sufficient without parallel improvements in governance, evidence‑gathering, and trust‑building processes. Moving forward, policymakers may need to balance regulatory rigor with practical support—such as streamlined attestation frameworks, enhanced training, and clearer guidance on third‑party expectations—to close the confidence gap. Simultaneously, extending cybersecurity requirements to a broader array of service providers could mitigate supply‑chain risks, aligning the defense industrial base more closely with the evolving threat landscape posed by nation‑state actors. Ultimately, sustaining progress will depend on aligning contractors’ internal confidence with objective measures of security, ensuring that self‑assessments serve as reliable proxies for true cybersecurity resilience.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here