CMMC Scores Hit Five-Year High as Contractor Confidence Drops 24 Points

Share Article:

Table of Contents:

Something strange showed up in the defense industrial base this month. Contractors are reporting the best cybersecurity scores in the history of the program — and simultaneously trusting those scores less than they ever have.

CyberSheath’s 2026 State of the DIB report, published August 20, found the average self-reported Supplier Performance Risk System score climbed to +51, a five-year high, up from +33 in 2025 and -12 in 2024. On a scale that runs from -203 to 110, that’s a genuine trajectory. Four years ago the average was -25.

Now the other number. The share of contractors expressing high or very high confidence that their submitted score actually reflects their cybersecurity posture fell to 65% — down from 89% in 2025 and 94% in 2024. Scores up 24 points. Confidence in those scores down 24 points.

A separate Kiteworks survey released the same day put it even more bluntly: 96% of contractors are confident they would pass a CMMC audit, but only 30% can prove it.

That gap — between what an organization believes about itself and what it can demonstrate to someone else — is the single most valuable thing an MSP can sell right now. And it has almost nothing to do with CMMC specifically.

What the numbers are actually telling us

Look at the control adoption data underneath the scores. Among the contractors reporting that five-year-high average, 63% said they use multifactor authentication. Secure backups: 48%. Data-leakage protection: 44%. Vulnerability management: 44%. Endpoint detection: 40% (Cybersecurity Dive).

Those numbers cannot coexist with a +51 average unless something in the middle is broken. A firm that has not deployed EDR and does not run vulnerability management is not scoring +51 on an honest 800-171 self-assessment. What’s happening is that scoring has become an exercise in interpretation — generous readings of partially implemented practices, POA&M line items counted as closed, controls marked “met” because a tool was purchased rather than because it’s deployed, tuned, and monitored.

The contractors know it. That’s precisely why confidence is falling while scores rise. When a client says “our score is fine but I’m not sure I could defend it,” they are describing an evidence problem, not a security problem.

The readiness data confirms it. Only about one-third of contractors believe they’re at least 80% prepared for an assessment, and just 1% say they’re fully ready. The median contractor rates itself 70% ready. Among firms that have actually gone through third-party review, only 63% passed on the first attempt.

The pause that isn’t a pause

Here’s what makes this urgent rather than academic. On July 13, the Department of War announced the immediate suspension of CMMC Phase II, which was scheduled to take effect November 10 and would have required certified third-party assessments for new solicitations involving controlled unclassified information. The stated reason was cost burden, particularly on smaller defense firms.

A lot of contractors read that headline and stopped reading. What the DoW CIO page actually says is that all Phase I self-assessment requirements remain firmly in place. NIST SP 800-171 obligations did not change. DFARS did not change. What was removed was the assessor — not the requirement, and not the attestation.

That distinction matters because the enforcement mechanism didn’t go anywhere either. The administration has continued using the False Claims Act to prosecute defense firms that misrepresented their cybersecurity posture to the government. A False Claims Act case doesn’t hinge on whether you failed an audit. It hinges on whether a signed attestation was accurate and whether you had a reasonable basis for it.

So the suspension didn’t reduce risk. It changed the shape of the risk. Instead of a scheduled assessment your client can prepare for, they now face an unscheduled legal inquiry they cannot prepare for retroactively. Every inflated SPRS score submitted in 2026 is a signed government representation sitting in a database, with no assessor coming to catch the error before it becomes a liability.

The part where contractors ask for help

The most interesting finding in the CyberSheath data, for anyone reading this as a service provider, is what contractors said about their own supply chain. More than 80% believe DFARS should apply to managed security service providers. 63% said it should apply to MSPs. 58% said other technology providers.

That’s not contractors trying to offload blame. CyberSheath framed it as frustration with their own supply-chain exposure — organizations increasingly depend on third parties to protect CUI, and they want those third parties held to comparable standards.

Read that as market demand. Your DIB clients are actively saying they want their providers inside the compliance boundary, accountable and demonstrable. The provider who shows up with evidence infrastructure wins the relationship. The provider who says “compliance is the client’s responsibility” is going to lose it to someone who doesn’t.

What to actually do in the next ninety days

The framework here is CMMC, but the pattern generalizes to every client you serve. Substitute HIPAA, PCI DSS, SOC 2, CIS Controls, or a cyber insurance questionnaire and the work is nearly identical.

Reconcile the score against reality. Pull each DIB client’s current SPRS submission and walk it against implemented controls, not intentions. Where is MFA actually enforced, and where does it have exceptions? Are backups tested or just configured? Is EDR deployed on every endpoint that touches CUI, or only on the ones IT remembered? Most clients have never had anyone do this side by side, and the first pass usually finds a double-digit score discrepancy.

Rebuild the System Security Plan and POA&M as living documents. A stale SSP is the most common single point of failure. It should describe the environment as it exists today, with each of the 110 practices tied to a specific artifact — a policy version, a screenshot, a configuration export, a ticket, a log sample — carrying a date.

Close the visible four first. MFA coverage, tested restores, a running vulnerability management cycle, and EDR everywhere. These are the controls with the lowest reported adoption and the highest scoring weight, and they’re the ones an investigator or assessor will check first because they’re easy to verify and impossible to fake.

Find out what backed the attestation. Ask who signed the last submission and what they relied on. If the answer is “the IT guy said we were good,” that is the finding. Document a defensible basis going forward, and keep the record of how the number was reached.

Get your own house in order. If you touch client CUI, assume flow-down obligations are coming and that clients will start asking for your evidence. Being able to hand a client your own control documentation is fast becoming table stakes rather than a differentiator.

Why this is bigger than the DIB

Strip away the acronyms and the story is this: an entire sector spent five years improving its security posture, got better at self-reporting, and ended up less certain it could prove anything. The controls got deployed. The evidence never got built.

That’s not a defense contracting problem. It’s the default condition of nearly every small and mid-sized business operating under a compliance obligation. The healthcare practice with a risk analysis from 2022. The manufacturer whose insurance questionnaire says “yes” to controls nobody has verified since onboarding. The SaaS client heading into its first SOC 2 with no artifact trail.

Awareness has never been the bottleneck. Everybody knows they need MFA. The bottleneck is the operational discipline of continuously capturing proof that controls are working — and that is exactly the kind of repeatable, unglamorous, high-value work MSPs are structurally best positioned to own.

The CMMC Phase II suspension handed the defense industrial base a remediation window nobody asked for. Contractors who treat it as relief will still be at +51 with 65% confidence when third-party assessment returns. The ones with an MSP who used the window to build evidence infrastructure will walk into their first C3PAO review already holding the file.


FAQ

Q: Was CMMC canceled?

A: No. On July 13, 2026, the Department of War suspended CMMC Phase II, which would have required third-party certification assessments starting November 10, 2026. All Phase I self-assessment requirements remain in effect, along with NIST SP 800-171 and DFARS obligations (DoW CIO).

Q: What is a good SPRS score?

A: SPRS scores run from -203 to 110, with 110 representing full implementation of all 110 NIST SP 800-171 practices. The 2026 DIB average is +51, a five-year high (Cybersecurity Dive). A score above zero is common but still means dozens of practices are unimplemented.

Q: Can a contractor be penalized without a CMMC assessment?

A: Yes. False Claims Act enforcement targets inaccurate attestations rather than failed audits, and it remains active (Cybersecurity Dive). Liability attaches to the signed representation, not to an assessment outcome.

Q: Do MSPs have to comply with CMMC?

A: MSPs handling controlled unclassified information on a client’s behalf fall within the assessment scope of that client’s environment, and CMMC compliance is often addressed through contractual flow-down. Notably, more than 80% of contractors surveyed said DFARS should apply directly to managed security service providers and 63% to MSPs (Cybersecurity Dive).

Q: What evidence should a client keep for each control?

A: A dated artifact that a third party could independently verify: policy documents with version history, configuration exports, tool coverage reports, backup restore test results, vulnerability scan output, training completion records, and tickets showing remediation follow-through.

Schedule a Demo of Blacksmith!

Check Out Our Compliance Podcast on Spotify!