Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    In China, AI has reached dumpling shops where you also get to feed on compute tokens

    August 23, 2026

    One programmer left his initials inside every ZIP file you open

    August 23, 2026

    China is quietly building a data center empire in its poorest provinces to win the AI race

    August 23, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
    Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind
    Cybersecurity

    Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind

    The Tech GuyBy The Tech GuyAugust 23, 2026No Comments4 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Two industry surveys released this week paint a consistent picture of the defense industrial base: contractors say they’re more confident in their cybersecurity compliance than ever, even as their ability to prove that compliance lags behind.

    Advertisement

    Kiteworks surveyed 273 defense contractors in the days following the Pentagon’s July suspension of CMMC 2.0 Phase 2 third-party assessments. Ninety-six percent said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review, but only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform. 

    Kiteworks combined its two readiness measures — one tracking compliance maturity, the other tracking how contractors responded to the suspension itself — by multiplying rather than averaging them, producing a combined score of 60 out of 100, well below the roughly 77 a simple average would have produced. Nearly a third of respondents scored low on both measures at once, the report’s largest single grouping.

    The CMMC Phase 2 suspension hasn’t removed contractors’ legal exposure. The underlying DFARS obligation to attest accurately never paused, even though the third-party check on those attestations did, and 84% of contractors told Kiteworks they were concerned about False Claims Act liability tied to an inaccurate score. In fact, 92% said they had already brought in legal or compliance review. 

    Concerningly, nearly half of respondents didn’t know that Phase 1 self-assessment obligations continued through the pause, and contractors who called themselves ‘very confident’ in their grasp of the changes scored no better on a factual test than those who called themselves only ‘somewhat confident’.

    The market has already reacted to the lowered bar. Fifty-five percent of contractors told Kiteworks they’re now bidding on work they previously avoided over CMMC Level 2 requirements, while 52% withdrew from a Department of War bid and 38% reported losing or being disqualified from a contract over the same requirement. Smaller subcontractors bore the brunt: Tier 2 and lower subcontractors reported bid losses at 55%, nearly double the 31% rate among prime contractors.

    Advertisement. Scroll to continue reading.

    A second report, the 2026 State of the DIB Report from CyberSheath and Merrill Research, surveyed 302 contractors in May 2026, before the suspension took effect, and found a similar disconnect building over a longer stretch. 

    The average SPRS score climbed to a five-year high of +51, up from +33 in 2025 against a perfect possible score of 110. But confidence that those scores were accurate fell sharply: 65% of contractors said they were extremely or very confident, down from 89% a year earlier and 94% in 2024. Only 1% considered themselves completely prepared for CMMC certification, unchanged from the prior year.

    As for spending, CyberSheath found average annual DFARS compliance budgets rose to $155,000, with 53% of contractors calling that amount “just right” and 24% calling it more than enough. 

    Adoption of core security technologies also increased, with multi-factor authentication at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, and endpoint detection at 40%.

    Contractors in both surveys want verification to remain part of the process rather than fade alongside third-party audits. Kiteworks found 93% of respondents said independent third-party authorization would be essential or important to future vendor selection, and 93% plan to comment on the Department of War’s request for information, with 58% expecting Phase 2 to return in some modified form. 

    CyberSheath found 90% of contractors want the government to mandate minimum cybersecurity standards across all federal contractors, and 77% said DFARS compliance meaningfully improves national security. On the other hand, 74% wanted implementation made easier and 70% wanted more vendor options.

    “The finding that matters is the distance between confidence and evidence,” said Frank Balonis, field CISO at Kiteworks. 

    Emil Sayegh, CEO of CyberSheath, framed it differently, noting that most contractors are manufacturers and engineers focused on supporting the military mission rather than cybersecurity specialists. Sayegh argued that any reform of CMMC should make compliance easier to achieve without sacrificing objective, verifiable proof that protections are actually working.

    Related: Industry Reactions to Pentagon Suspending CMMC Phase 2

    Related: Timeless Compliance: Why Better Questions Beat Bigger Frameworks

    Related: White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

    August 23, 2026

    Microsoft Patches Exploited Entra ID Vulnerability

    August 23, 2026

    Rust Supply Chain Attack Linked to North Korean Hackers

    August 23, 2026

    New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

    August 22, 2026

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    August 22, 2026

    Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

    August 22, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    In China, AI has reached dumpling shops where you also get to feed on compute tokens

    August 23, 2026

    One programmer left his initials inside every ZIP file you open

    August 23, 2026

    China is quietly building a data center empire in its poorest provinces to win the AI race

    August 23, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.