Skip to content

Security1 publisher3 min readPublished

CMMC Phase 2 Assessments Are Paused. The False Claims Act Is Not.

Kiteworks found 96% of defense contractors trust their self-attested SPRS score and 29% can substantiate it. The DFARS duty to attest accurately never stopped when the third-party audits did.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Two industry surveys released this week found defense contractors saying they are more confident in their cybersecurity compliance than ever, even as their ability to prove that compliance lags behind.
  • Kiteworks surveyed 273 defense contractors in the days following the Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments.
  • 96% of Kiteworks respondents said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform.
  • The gap between contractors confident in their SPRS score and those able to substantiate it is 67 percentage points.
  • Kiteworks combined its two readiness measures, one tracking compliance maturity and one tracking response to the suspension, by multiplying rather than averaging them, producing a combined score of 60 out of 100 versus roughly 77 for a simple average.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Two industry surveys released this week found defense contractors more confident in their cybersecurity compliance than at any point measured, and less able to demonstrate it [26]. That is a problem specifically because the Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments removed the check on attestations without removing the obligation to make them accurately [7].

Kiteworks surveyed 273 defense contractors in the days after the suspension [3]. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System score would survive review; 29% could support that with both a current SPRS submission and a FedRAMP-authorized platform [1]. The 67-point spread between belief and evidence is the entire story [5]. Kiteworks scored its two readiness measures by multiplying rather than averaging them, producing a combined 60 out of 100 against roughly 77 for a simple average, a 17-point difference that reflects how many firms are weak on both dimensions at once [4][25]. Nearly a third of respondents were in that group, the largest single cluster in the report [6].

The legal exposure is understood, if unevenly. Eighty-four percent told Kiteworks they were concerned about False Claims Act liability tied to an inaccurate score, and 92% had already brought in legal or compliance review [8][9]. But nearly half did not know that Phase 1 self-assessment obligations continued through the pause, and contractors who called themselves "very confident" in their grasp of the changes scored no better on a factual test than those who said they were only somewhat confident [10][11]. Confidence, on this evidence, is not a proxy for knowledge.

The market repriced quickly. Fifty-five percent said they are now bidding on work they had previously avoided because of CMMC Level 2 requirements, while 52% had withdrawn from a Department of War bid and 38% had lost or been disqualified from a contract over the same requirement [12][13]. Tier 2 and lower subcontractors reported bid losses at 55%, against 31% for primes [14].

The longer-running data points the same direction. CyberSheath and Merrill Research surveyed 302 contractors in May 2026, before the suspension took effect [15]. Average SPRS scores hit a five-year high of +51, up from +33 in 2025 against a possible 110 [16]. Confidence that those scores were accurate fell to 65% extremely or very confident, from 89% a year earlier and 94% in 2024 [17]. One percent considered themselves completely prepared for CMMC certification, unchanged year over year [18]. Average annual DFARS compliance budgets reached $155,000, and 53% called that just right with another 24% calling it more than enough [19]. Adoption of basics remains partial: multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, endpoint detection at 40% [20].

"The finding that matters is the distance between confidence and evidence," said Frank Balonis, field CISO at Kiteworks [22]. CyberSheath CEO Emil Sayegh framed it as a workforce problem, noting that most contractors are manufacturers and engineers rather than security specialists, and argued reform should make compliance easier without giving up objective, verifiable proof [23].

Watch the comment record. Ninety-three percent of Kiteworks respondents plan to file on the Department of War's request for information, and 58% expect Phase 2 to return in modified form [21]. Ninety-three percent also said independent third-party authorization would be essential or important in future vendor selection, and 90% of CyberSheath respondents want minimum standards mandated across all federal contractors [2][24]. The industry is asking for the audit back. Until it returns, the score on file is the only artifact, and it is the one a relator reads.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories