Skip to content

Security1 publisher3 min readPublished

Defense suppliers' cyber scores hit a five-year high just as the audits were paused

CyberSheath's 2026 survey puts the average SPRS self-assessment at +51, but only 65% of contractors trust their own number. Treat supplier scores as claims, not findings.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • The average SPRS score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report's history.
  • The 2026 State of the DIB Report was published on August 20 by CyberSheath; the underpinning survey was conducted by Merrill Research.
  • Confidence in score accuracy fell 24 percentage points: just 65% of contractors said they were extremely or very confident their score was accurate, down from 89% last year and 94% in 2024.
  • SPRS is the framework used by US defense contractors to self-assess their cybersecurity maturity under CMMC.
  • Using SPRS, DIB contractors and subcontractors assess their maturity against 110 security controls referred to in NIST SP 800-171; a perfect assessment score is 110.

Compiled by The WatchSomething wrong?How this is made

Why it matters

The average self-reported cybersecurity score across the US defense industrial base reached a five-year high of +51 this year, up from +33 in 2025, according to the 2026 State of the DIB Report published on August 20 by CyberSheath and based on a survey by Merrill Research [1][2]. In the same data set, the share of contractors who said they were extremely or very confident that their score was accurate fell to 65%, down from 89% a year earlier and 94% in 2024 [3].

Numbers going up while confidence in those numbers goes down is a measurement problem, not a security improvement. David M. Schneer, CEO of Merrill Research, called the divergence "the most striking finding this year," and said that "measuring progress requires looking beyond the reported score itself" [9].

The timing matters. Scores in the Supplier Performance Risk System are self-assessments against the 110 controls in NIST SP 800-171, where a perfect score is 110 [4][5]. Self-reporting is the only mandate under Phase I of the Cybersecurity Maturity Model Certification program; Phase II was to introduce independent verification by Certified Third-Party Assessment Organizations [6]. That phase was scheduled to take effect on November 10, 2026, and was suspended by the Trump administration in July 2026 [7]. So the record high arrived in the same year the outside check on it went away, and the scores still sit 59 points short of a perfect 110 on average [17].

The report does not support a story about underfunding. Fifty-three percent of respondents said their compliance budgets felt "just right" and 24% said they were more than enough, with average annual DFARS compliance spending rising sharply to $155,204 [11][12]. CyberSheath's own read is that the issue "is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security" [13]. Only 1% of contractors said they were completely prepared for CMMC certification, unchanged from CyberSheath's October 2025 study [10].

For anyone buying from this base, the operational conclusion is narrow and firm. A SPRS score is a supplier assertion carried into a contract by DFARS [8][4], and roughly one in three suppliers will not vouch for the accuracy of their own assertion [20]. Primes and program offices running supplier risk files off SPRS numbers are aggregating unverified claims, and the 18-point year-over-year rise in the average [18] should not be read into scorecards as a 18-point reduction in exposure. Ask instead for the System Security Plan, the dates on the underlying assessment, the open items in the plan of action and milestones, and who performed the scoring.

The appetite for rules is not the obstacle. Ninety percent of respondents still favor a legal mandate for minimum cybersecurity standards, 77% said DFARS compliance meaningfully improves national security, and 52% fear losing contracts over non-compliance [14][15]. What they want is different plumbing: 74% asked for easier implementation and 70% for more vendor options [15]. Emil Sayegh, CEO of CyberSheath, described the base as manufacturers and engineers "whose mission is supporting the warfighter, not becoming cybersecurity experts," and argued that "meaningful verification and accountability should remain central" however CMMC evolves [16].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories