Self-Reported Cyber Scores Draw Skepticism
US defense contractors report record-high self-assessed cybersecurity scores, but confidence in their accuracy drops sharply.
The US defense industrial base is reporting the strongest self-assessed cybersecurity scores in five years — yet the people filing those numbers are increasingly skeptical they mean anything. A new study finds a widening gap between what contractors claim and what they actually believe.
According to the 2026 State of the DIB Report, published August 20 by CyberSheath, the average Supplier Performance Risk System (SPRS) score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report’s history. But confidence in the accuracy of those scores fell 24 percentage points, a disconnect the study’s authors call striking.
What SPRS and CMMC Measure
SPRS is the framework used by US defense contractors to self-assess their cybersecurity maturity under the Cybersecurity Maturity Model Certification (CMMC). CMMC is a program designed to enhance cyber hygiene for US defense contractors and subcontractors handling federal contract information (FCI) and controlled unclassified information (CUI) for the Department of Defense (DoD).
Defense contractors who wish to secure a DoD contract must comply with the Defense Federal Acquisition Regulation Supplement (DFARS), the official DoD rulebook that turns CMMC into a binding legal contract requirement. Using SPRS, DIB contractors and subcontractors assess their maturity against 110 security controls referred to in NIST SP 800-171, a standard published by the US National Institute of Standards and Technology (NIST). A perfect assessment score is 110.
Self-Reporting Under Phase I
This self-reporting is currently the only mandate under Phase I of the CMMC program. A second phase was about to introduce independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs) to verify compliance, but CMMC Phase II was suspended by the Trump administration in July 2026, originally scheduled to come into effect on November 10, 2026.
The study, conducted by Merrill Research and underpinning the report, found that just 65% of contractors said they were extremely or very confident their score was accurate — down sharply from 89% last year and 94% in 2024. David M. Schneer, CEO of Merrill Research, described the gap between reported self-reporting cybersecurity score progress and confidence in that progress as “the most striking finding this year.”
“Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially. That tension suggests that measuring progress requires looking beyond the reported score itself,”
— David M. Schneer, CEO of Merrill Research
Preparedness Still Lacking
What’s more, only 1% of contractors believe they are completely prepared for CMMC certification, unchanged from a previous CyberSheath study published in October 2025.
This suggests that even as self-reported numbers climb, the underlying readiness for formal certification remains low.
Budget Isn't the Main Issue
The main bottleneck doesn’t seem to be financial, with 53% of respondents saying their budgets felt “just right,” while 24% said they were more than enough. DFARS compliance budgets were found to have risen sharply this year to an average of $155,204 annually.
“The findings suggest that the challenge facing the DIB is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security,” said the CyberSheath report.
Contractors Want Easier Compliance
Additionally, the study showed that while more than half (52%) of DIB members fear of losing contracts because of non-compliance, most (90%) are still in favor of a legal mandate for minimum cybersecurity standards for defense contractors and subcontractors.
While a majority (77%) said DFARS compliance meaningfully improves national security, contractors are also calling for changes to how it's implemented, with 74% asking for easier implementation processes and 70% for more vendor options to support compliance efforts. Emil Sayegh, CEO of CyberSheath, highlighted that most DIB contractors are manufacturers, engineers and specialized businesses “whose mission is supporting the warfighter, not becoming cybersecurity experts.”
He called for the federal administration to reform the CMMC program in a way that “makes effective cybersecurity easier to consume while preserving objective, verifiable assurance that the protections are actually in place and working.” “However, CMMC evolves, meaningful verification and accountability should remain central to ensuring that reported compliance reflects operational cybersecurity,” he concluded.
How the Study Was Conducted
The 2026 State of the DIB Report is based on a survey of 302 US defense contractors (195 prime contractors, 118 subcontractors, and 11 organizations identifying as both), conducted by Merrill Research in May 2026.
Why It Matters for the DIB
The findings come at a critical moment, with CMMC Phase II suspended and the future of independent assessments uncertain. If contractors themselves lack faith in the self-reported scores, the Pentagon's reliance on SPRS as a compliance signal becomes harder to justify.
This could mean that without third-party verification, the DoD may be making procurement decisions based on numbers that even the reporting companies don't fully trust. The tension between reported progress and confidence suggests that any future reform of CMMC must prioritize verifiable assurance over simple self-assessment, or risk undermining the entire certification program's credibility.
Sources
- Infosecurity Magazine Original source
Continue Reading
Android Banking Trojans Gain On-Device Fraud Tools
ToxicPanda 2.0 and GoldDigger expand targets with automated fraud and credential theft.
Citrix NetScaler flaws: patch gap may invite attackers
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
AI-Assisted Attacks Target Water Systems
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.