Record-High Scores, Record-Low Trust
Defense contractors are reporting their best-ever cybersecurity scores under the Pentagon’s CMMC program. They just don’t believe the numbers themselves.
The CyberSheath 2026 State of the DIB Report, released August 20, found the average Supplier Performance Risk System (SPRS) score jumped to +51 — a five-year high, up from +33 in 2025. That was already the first positive score in the report’s history.
SPRS is the self-assessment tool defense contractors use to gauge their cybersecurity maturity under the Cybersecurity Maturity Model Certification (CMMC), the DoD program that governs how companies protect federal contract information and controlled unclassified information.
But here’s the catch: confidence in those scores cratered. Only 65% of contractors said they were extremely or very confident their score was accurate. A year ago, that figure was 89%. In 2024, it was 94%.
That’s a 24-point drop — and it’s the starkest finding in the entire report.
Why Contractors Doubt Their Own SPRS Scores
David M. Schneer, CEO of Merrill Research, which conducted the survey of 302 defense contractors, called the disconnect between rising scores and falling confidence “the most striking finding this year.”
“Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially,” Schneer said. “That tension suggests that measuring progress requires looking beyond the reported score itself.”
The timing isn’t a coincidence. In July 2026, the Trump administration suspended CMMC Phase II, which would have introduced independent verification by Certified Third-Party Assessment Organizations (C3PAOs). Originally set to take effect November 10, 2026, that phase is now on hold.
Without external checks, contractors are left to grade their own homework — and they know it.
Only 1% Feel Fully Prepared
Just 1% of contractors believe they’re completely ready for CMMC certification. That number hasn’t budged since a previous CyberSheath study in October 2025.
So while scores are climbing, actual readiness isn’t. The two metrics are telling different stories.
Money Isn’t the Main Problem
The bottleneck isn’t budget — at least not in the way you’d expect.
- 53% of respondents said their cybersecurity budgets felt “just right”
- 24% said they had more than enough
- Average DFARS compliance spending rose to $155,204 annually
DFARS, the Defense Federal Acquisition Regulation Supplement, is the rulebook that makes CMMC a binding legal requirement for DoD contracts. Contractors assess themselves against 110 security controls from NIST SP 800-171, with a perfect score of 110.
The CyberSheath report argues the real challenge isn’t how much contractors spend, but “how effectively those investments translate into implemented, sustainable and verifiable security.”
Contractors Want Reform — But Not Deregulation
Here’s the twist: even as they struggle with compliance, contractors aren’t asking to ditch the rules.
90% of respondents still support a legal mandate for minimum cybersecurity standards. 77% said DFARS compliance meaningfully improves national security.
What they want is a better path to get there:
- 74% want easier implementation processes
- 70% want more vendor options to support compliance
And 52% fear losing contracts due to non-compliance. That fear is real, but it hasn’t soured them on the program’s purpose.
What’s Next for CMMC?
Emil Sayegh, CEO of CyberSheath, points out that most DIB contractors are manufacturers, engineers, and specialized businesses “whose mission is supporting the warfighter, not becoming cybersecurity experts.”
His ask to the federal administration: reform CMMC to “make effective cybersecurity easier to consume while preserving objective, verifiable assurance that the protections are actually in place and working.”
The report’s bottom line is a warning wrapped in a suggestion. Self-reported scores are rising, but if contractors themselves don’t trust them, the numbers are close to meaningless. When CMMC Phase II eventually resumes — and most observers think it will — the C3PAO verification process will be the real test.
Until then, the DIB is flying on instruments it knows are miscalibrated.