**Defense Contractors Express Growing Cybersecurity Confidence, But Proof Remains Elusive**
A pair of recent industry reports highlights a significant and growing disconnect within the defense industrial base (DIB). While contractors are reporting unprecedented levels of confidence in their cybersecurity compliance, a simultaneous inability to provide concrete evidence of that compliance has created a persistent and risky gap between assertion and verification.
The findings from two major industry surveys—one conducted in the wake of the CMMC 2.0 Phase 2 suspension and another looking at the landscape prior to the halt—reveal a DIB that feels increasingly prepared on paper but struggles to demonstrate its readiness to outside reviewers. This growing confidence-verification chasm has major implications for government contracting, legal liability, and national security.
### A Growing Divide Between Confidence and Evidence
The most striking data comes from a survey by Kiteworks, which polled 273 defense contractors shortly after the Pentagon suspended third-party assessments for CMMC 2.0 Phase 2. The results show a dramatic surge in self-assurance. An overwhelming 96% of respondents stated they were confident that their Supplier Performance Risk System (SPRS) self-attestation scores would withstand government scrutiny.
However, this confidence is not backed by the necessary documentation. Shockingly, only 29% of those same contractors could produce both a current SPRS submission and a FedRAMP authorization for their file-sharing platforms. This disconnect led analysts to combine compliance maturity and survey response readiness into a single score, resulting in an average of just 60 out of 100—a figure well below what a simple average would suggest. The data suggests that nearly a third of all respondents are both underprepared and overconfident in their own readiness.
The consequences of this gap are already being felt in the marketplace. With the bar effectively lowered due to the suspension, 55% of contractors say they are now bidding on work they previously avoided due to stringent CMMC Level 2 requirements. Conversely, 52% withdrew from a Department of War bid, and 38% reported losing or being disqualified from a contract specifically because they could not meet the required compliance standard. Small subcontractors are being hit the hardest, with Tier 2 and lower vendors reporting bid losses at 55%, nearly double the rate of their prime contractor counterparts.
### Lingering Liability and Confusion
Perhaps the most concerning finding is the persistent legal exposure for contractors. The CMMC Phase 2 suspension did not remove the underlying DFARS (Defense Federal Acquisition Regulation Supplement) obligations. The requirement to attest accurately remains in force, meaning that any inaccurate self-reporting could open the door to False Claims Act liability.
In response to this legal risk, 84% of contractors surveyed by Kiteworks expressed concern about such liability, and a sweeping 92% have already brought in legal or compliance teams to review their processes. Adding to the confusion, nearly half of all respondents were unaware that the obligations for Phase 1 self-assessments continued throughout the suspension period. The data also revealed a troubling correlation between overconfidence and competence: contractors who rated their understanding of the changes as “very confident” scored no better on a factual knowledge test than those who were merely “somewhat confident.”
A second report, the 2026 State of the DIB Report from CyberSheath and Merrill Research, paints a similar picture of a widening divide. This survey, which was conducted before the suspension took effect, showed SPRS scores hitting a five-year high. However, the proportion of contractors who were “extremely or very confident” in the accuracy of those scores plummeted from 94% in 2024 to just 65%. Just 1% of respondents felt completely prepared for CMMC certification, a number that has remained stagnant for a year.
### The Path Forward: Verification Over Virtue
Despite the challenges, both reports indicate that the industry is not abandoning the core principles of cybersecurity compliance. Contractors overwhelmingly agree that independent third-party verification must remain a cornerstone of the vendor selection process. An astounding 93% of respondents in the Kiteworks survey said that such authorization would be essential or important to them when choosing a vendor in the future. Furthermore, 93% of contractors plan to submit comments on the Department of War’s request for information regarding CMMC, with the majority expecting a modified Phase 2 to return in some form.
There is also a clear desire for the government to take a more active role. The CyberSheath report found that 90% of contractors want the government to mandate minimum cybersecurity standards across all federal contractors, a move that 77% believe would meaningfully improve national security. At the same time, contractors are asking for pragmatic support; 74% want the implementation process to be made easier, and 70% want more vendor options to work with.
The central takeaway from both studies is a plea for a more sustainable balance. As Frank Balonis, field CISO at Kiteworks, noted, the most critical finding is the “distance between confidence and evidence.” Emil Sayegh, CEO of CyberSheath, echoed this sentiment, arguing that contractors are primarily manufacturers and engineers focused on the mission, not cybersecurity specialists. He argued that any future reform of the CMMC framework must focus on making compliance easier to achieve without sacrificing the objective, verifiable proof that the necessary protections are actually in place.
***
### FAQ
**Q: What is the CMMC, and what happened to Phase 2?**
The Cybersecurity Maturity Model Certification (CMMC) is a framework designed to ensure defense contractors meet certain cybersecurity standards. The Pentagon suspended Phase 2 of the rollout, which would have required third-party assessments of contractors’ security posture. This suspension did not remove the legal requirements for accurate self-attestation under DFARS.
**Q: Why are contractors so confident if they can’t prove their compliance?**
Many contractors rely on their SPRS self-attessment scores, believing their internal evaluations are sufficient. However, the data shows that very few have the accompanying documentation, such as a current SPRS submission and FedRAMP authorization, to prove their systems are secure.
**Q: What are the legal risks for contractors?**
Even with the suspension, contractors are still legally required to provide accurate information. Inaccurate SPRS scores can lead to liability under the False Claims Act, prompting 92% of surveyed contractors to seek legal or compliance review.
**Q: How did the market react to the suspension?**
With the requirements seemingly loosened, many contractors are now willing to bid on work they previously avoided. However, there has also been a notable withdrawal from bids and disqualifications, particularly among smaller subcontractors who may lack the resources to navigate the complex compliance landscape.
**Q: What do contractors want moving forward?**
Contractors overwhelmingly want verification to remain part of the process. They desire government-mandated minimum standards for all federal contractors and want the implementation process to be easier and offer more vendor options, ensuring compliance is both verifiable and achievable.
***
### Conclusion
The reports from Kiteworks and CyberSheath offer a clear, if troubling, picture of the defense industrial base. A chasm has opened between the perceived and actual state of cybersecurity readiness. While contractors feel more confident than ever, this optimism is largely unsubstantiated, creating a significant risk for false claims and legal exposure.
The suspension of CMMC 2.0 Phase 2 has not weakened the underlying obligations; rather, it has created a vacuum where confidence has surged, but proof has lagged. For the government and the DIB to move forward, the focus must shift from mere confidence to demonstrable evidence. As the industry calls for a more workable framework, the central challenge remains finding a way to ensure robust security without placing an unbearable burden on the very companies that defend the nation. The path forward must bridge the gap between what contractors believe and what they can prove.



