Security1 distinct publisher3 min readUpdated
Kiteworks found 96% of defense contractors trust their self-attested SPRS score and 29% can substantiate it. The DFARS duty to attest accurately never stopped when the third-party audits did.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Two industry surveys released this week found defense contractors more confident in their cybersecurity compliance than at any point measured, and less able to demonstrate it [1]. That is a problem specifically because the Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments removed the check on attestations without removing the obligation to make them accurately [8].
Kiteworks surveyed 273 defense contractors in the days after the suspension [2]. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System score would survive review; 29% could support that with both a current SPRS submission and a FedRAMP-authorized platform [3]. The 67-point spread between belief and evidence is the entire story [4]. Kiteworks scored its two readiness measures by multiplying rather than averaging them, producing a combined 60 out of 100 against roughly 77 for a simple average, a 17-point difference that reflects how many firms are weak on both dimensions at once [5][6]. Nearly a third of respondents were in that group, the largest single cluster in the report [7].
The legal exposure is understood, if unevenly. Eighty-four percent told Kiteworks they were concerned about False Claims Act liability tied to an inaccurate score, and 92% had already brought in legal or compliance review [9][10]. But nearly half did not know that Phase 1 self-assessment obligations continued through the pause, and contractors who called themselves "very confident" in their grasp of the changes scored no better on a factual test than those who said they were only somewhat confident [11][12]. Confidence, on this evidence, is not a proxy for knowledge.
The market repriced quickly. Fifty-five percent said they are now bidding on work they had previously avoided because of CMMC Level 2 requirements, while 52% had withdrawn from a Department of War bid and 38% had lost or been disqualified from a contract over the same requirement [13][14]. Tier 2 and lower subcontractors reported bid losses at 55%, against 31% for primes [15].
The longer-running data points the same direction. CyberSheath and Merrill Research surveyed 302 contractors in May 2026, before the suspension took effect [16]. Average SPRS scores hit a five-year high of +51, up from +33 in 2025 against a possible 110 [17]. Confidence that those scores were accurate fell to 65% extremely or very confident, from 89% a year earlier and 94% in 2024 [18]. One percent considered themselves completely prepared for CMMC certification, unchanged year over year [19]. Average annual DFARS compliance budgets reached $155,000, and 53% called that just right with another 24% calling it more than enough [20]. Adoption of basics remains partial: multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, endpoint detection at 40% [21].
"The finding that matters is the distance between confidence and evidence," said Frank Balonis, field CISO at Kiteworks [24]. CyberSheath CEO Emil Sayegh framed it as a workforce problem, noting that most contractors are manufacturers and engineers rather than security specialists, and argued reform should make compliance easier without giving up objective, verifiable proof [25].
Watch the comment record. Ninety-three percent of Kiteworks respondents plan to file on the Department of War's request for information, and 58% expect Phase 2 to return in modified form [22]. Ninety-three percent also said independent third-party authorization would be essential or important in future vendor selection, and 90% of CyberSheath respondents want minimum standards mandated across all federal contractors [23][26]. The industry is asking for the audit back. Until it returns, the score on file is the only artifact, and it is the one a relator reads.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
96% of Kiteworks respondents said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform.
93% of Kiteworks respondents said independent third-party authorization would be essential or important to future vendor selection.
Kiteworks surveyed 273 defense contractors in the days following the Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments.
Kiteworks combined its two readiness measures, one tracking compliance maturity and one tracking response to the suspension, by multiplying rather than averaging them, producing a combined score of 60 out of 100 versus roughly 77 for a simple average.
The gap between contractors confident in their SPRS score and those able to substantiate it is 67 percentage points.
Nearly a third of Kiteworks respondents scored low on both readiness measures at once, the report's largest single grouping.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Two sized surveys, one publisher, no primary documents
The quantitative base is real and disclosed - 273 contractors surveyed by Kiteworks just after the July suspension and 302 surveyed by CyberSheath/Merrill Research in May 2026 - and the reporting is specific about figures and fielding windows. But everything reaches us through one publisher summarizing two vendor-sponsored surveys of self-reported data, with no sampling frame, weighting, questionnaire, government comment, or enforcement statistics available, and with the central 29% substantiation bar defined by the sponsor rather than by regulation.
Behavior already moving across the supplier base
Adoption here is measured as observable behavior in the defense industrial base rather than uptake of a product, and the signals are concrete: control-deployment rates (MFA 63% down to endpoint detection 40%), $155,000 average annual compliance budgets, average SPRS scores at a five-year high of +51, 92% engaging legal or compliance review, and bid behavior visibly repricing after the suspension with 55% re-entering previously avoided competitions. What is not adopted is provable assurance - 29% substantiation and 1% claiming full certification readiness - so the score reflects broad but shallow uptake.
Sober reporting on top of sponsor-shaped metrics
The article itself is restrained - it flags the multiplicative scoring choice, the pre- versus post-suspension fielding difference, and the awareness gaps - so the gap is modest rather than large. It is positive because the most quotable numbers are sponsor-constructed: the 67-point confidence-versus-evidence spread depends on a substantiation test that requires a FedRAMP-authorized platform sold by the survey's sponsor, the 60/100 readiness score is 17 points below a simple average by methodological choice, and the 'more confident than ever' framing sits awkwardly beside the other survey's confidence decline from 94% to 65%. Legal exposure is asserted through respondent worry rather than any enforcement data.
Both datasets published by vendors selling the remedy
Both surveys are commissioned by companies with direct commercial exposure to the conclusion. Kiteworks markets a FedRAMP-authorized platform and its own substantiation test counts having such a platform as evidence of compliance, while 93% of its respondents conveniently rate independent third-party authorization as essential or important to vendor selection; its field CISO supplies the framing quote. CyberSheath sells DIB compliance services and its CEO argues for reform that preserves verifiable proof. The reporting outlet has no disclosed stake, but no independent or government voice offsets the sponsors.
Numbers are firm, interpretation is sponsor-shaped
Confidence is mid-range: the specific figures are consistently and precisely reported by an established security trade publication, and the central legal observation - that DFARS attestation liability outlived the Phase 2 assessment pause - is straightforward and independently plausible. It is held down by single-publisher sourcing, reliance on two self-reported vendor surveys with undisclosed methodology, unresolved tension between the two datasets on the direction of confidence, and the absence of any government or enforcement corroboration.
security
Defense suppliers' cyber scores hit a five-year high just as the audits were paused1 distinct publisher
invest
L3Harris shows what forfeiture can reach, and what it cannot1 distinct publisher
invest
Code Metal's $80M WarMatrix award shows OTA is where defense revenue now shows up1 distinct publisher
product
Boeing locks in seven years of SM-3 parts before anyone commits to a missile count1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026