Security1 distinct publisher3 min readUpdated
CyberSheath's 2026 survey puts the average SPRS self-assessment at +51, but only 65% of contractors trust their own number. Treat supplier scores as claims, not findings.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The average self-reported cybersecurity score across the US defense industrial base reached a five-year high of +51 this year, up from +33 in 2025, according to the 2026 State of the DIB Report published on August 20 by CyberSheath and based on a survey by Merrill Research [1][2]. In the same data set, the share of contractors who said they were extremely or very confident that their score was accurate fell to 65%, down from 89% a year earlier and 94% in 2024 [3].
Numbers going up while confidence in those numbers goes down is a measurement problem, not a security improvement. David M. Schneer, CEO of Merrill Research, called the divergence "the most striking finding this year," and said that "measuring progress requires looking beyond the reported score itself" [9].
The timing matters. Scores in the Supplier Performance Risk System are self-assessments against the 110 controls in NIST SP 800-171, where a perfect score is 110 [4][5]. Self-reporting is the only mandate under Phase I of the Cybersecurity Maturity Model Certification program; Phase II was to introduce independent verification by Certified Third-Party Assessment Organizations [6]. That phase was scheduled to take effect on November 10, 2026, and was suspended by the Trump administration in July 2026 [7]. So the record high arrived in the same year the outside check on it went away, and the scores still sit 59 points short of a perfect 110 on average [17].
The report does not support a story about underfunding. Fifty-three percent of respondents said their compliance budgets felt "just right" and 24% said they were more than enough, with average annual DFARS compliance spending rising sharply to $155,204 [11][12]. CyberSheath's own read is that the issue "is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security" [13]. Only 1% of contractors said they were completely prepared for CMMC certification, unchanged from CyberSheath's October 2025 study [10].
For anyone buying from this base, the operational conclusion is narrow and firm. A SPRS score is a supplier assertion carried into a contract by DFARS [8][4], and roughly one in three suppliers will not vouch for the accuracy of their own assertion [20]. Primes and program offices running supplier risk files off SPRS numbers are aggregating unverified claims, and the 18-point year-over-year rise in the average [18] should not be read into scorecards as a 18-point reduction in exposure. Ask instead for the System Security Plan, the dates on the underlying assessment, the open items in the plan of action and milestones, and who performed the scoring.
The appetite for rules is not the obstacle. Ninety percent of respondents still favor a legal mandate for minimum cybersecurity standards, 77% said DFARS compliance meaningfully improves national security, and 52% fear losing contracts over non-compliance [14][15]. What they want is different plumbing: 74% asked for easier implementation and 70% for more vendor options [15]. Emil Sayegh, CEO of CyberSheath, described the base as manufacturers and engineers "whose mission is supporting the warfighter, not becoming cybersecurity experts," and argued that "meaningful verification and accountability should remain central" however CMMC evolves [16].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The average SPRS score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report's history.
The 2026 State of the DIB Report was published on August 20 by CyberSheath; the underpinning survey was conducted by Merrill Research.
Confidence in score accuracy fell 24 percentage points: just 65% of contractors said they were extremely or very confident their score was accurate, down from 89% last year and 94% in 2024.
SPRS is the framework used by US defense contractors to self-assess their cybersecurity maturity under CMMC.
Using SPRS, DIB contractors and subcontractors assess their maturity against 110 security controls referred to in NIST SP 800-171; a perfect assessment score is 110.
Self-reporting is currently the only mandate under Phase I of the CMMC program; a second phase was about to introduce independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs) to verify compliance.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source but methodologically disclosed survey
Every claim traces to one article reporting one vendor-published study, which is a meaningful limit. Against that, the underlying dataset is unusually well specified for a trade survey: 302 US defense contractors split into 195 primes, 118 subcontractors and 11 both, fielded May 2026 by a named research firm, with named executives quoted and multi-year comparison points (94% in 2024, 89% in 2025, 65% in 2026). The regulatory facts -- Phase I self-reporting, the planned Phase II C3PAO regime, DFARS, the 110-control NIST SP 800-171 scale -- are checkable public structures. What is absent is any independent measurement of actual control implementation and any second publisher.
Widely mandated, but uptake evidence is self-attested
Adoption of the SPRS self-assessment regime itself is effectively universal for DoD suppliers because DFARS makes it contractual, and 302 surveyed contractors report both rising scores and rising compliance spend ($155,204 average). But the substance being measured -- implemented security against 110 controls -- is only self-reported: the average sits 59 points below a perfect 110, just 1% feel completely prepared for certification, only 65% trust their own number, and the Phase II independent-assessment mechanism that would have verified any of it is suspended. Real uptake of verified controls is therefore materially lower than the headline score implies.
Headline metric overstates verified security
The overstatement sits in the metric, not primarily in the coverage. A 'five-year high' of +51 reads as progress while remaining 59 points short of full implementation, is entirely self-attested, is distrusted by roughly a third of the contractors who filed it, and coincides with the removal of the audit step that would have tested it. The article itself flags this tension and quotes both executives conceding it, which keeps the gap moderate rather than severe; the residual risk is downstream consumers treating a supplier's SPRS number as an audit finding.
Vendor-published survey advocating a mandate it serves
The dataset is published by CyberSheath, a company in the DIB compliance market, and its CEO uses the findings to argue that verification and accountability mandates should be preserved as CMMC is reformed -- a position aligned with continued demand for compliance services. The survey vendor's CEO likewise frames the confidence gap as the year's most striking finding. Respondent incentives also cut both ways: contractors self-report scores that affect contract eligibility, 52% fear losing contracts over non-compliance, and 70% want more vendor options. None of this makes the figures wrong, but the direction of interest is visible on the record and the publisher does not disclose it.
Consistent, well-specified, but uncorroborated
Internal consistency is good: the numbers, quotes, methodology and regulatory chronology hang together and the two structural findings (score up, confidence down) are reported with multi-year baselines. Confidence is held below the mid-sixties by the absence of any second publisher, the absence of independent or DoD confirmation of the Phase II suspension and its scope, and the fact that the core measurements are self-attested by parties with contractual exposure.
science
The Pentagon wants to test soldiers' testosterone. The label for treating it is narrow.1 distinct publisher
product
A titanium powder order that waited on paperwork, not particle size1 distinct publisher
product
Castelion's $13bn valuation rests on $500m of contracts and a 2027 delivery date2 distinct publishers
build
Hybrid Post-Quantum TLS: Same Protocol, a 1,216-Byte Key Share1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026