-

New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points

RESTON, Va.--(BUSINESS WIRE)--The Cybersecurity Maturity Model Certification (CMMC) program is a Pentagon framework that became federal defense contract law last November, requiring defense contractors to prove their cybersecurity practices meet federal standards. In July, the Pentagon paused the requirement for third-party verification, leaving the defense industrial base (DIB) to rely on self-attestation. A study conducted by Merrill Research and commissioned by CyberSheath found that contractors’ self-reported cybersecurity scores are rising, but their confidence in the accuracy of those scores has drastically declined.

The 2026 State of the DIB Report found that the average Supplier Performance Risk System (SPRS) score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report’s history. A perfect NIST SP 800-171 assessment score is 110. Yet as reported scores improved, confidence in their accuracy fell 24 percentage points. Only 65% of contractors say they're extremely or very confident that their score is accurate, down sharply from 89% last year and 94% in 2024. What’s more, only 1% of contractors believe they are completely prepared for CMMC certification, unchanged from last year.

“Most contractors are manufacturers, engineers, and specialized businesses whose mission is supporting the warfighter, not becoming cybersecurity experts,” said Emil Sayegh, CEO of CyberSheath. “That is exactly why CMMC reform should make effective cybersecurity easier to consume while preserving objective, verifiable assurance that the protections are actually in place and working. However CMMC evolves, meaningful verification and accountability should remain central to ensuring that reported compliance reflects operational cybersecurity.”

The survey also showed that Defense Federal Acquisition Regulation Supplement (DFARS) compliance budgets rose sharply this year to an average of $155,204 annually, and 53% said their budgets felt “just right,” while 24% said they were more than enough. The findings suggest that the challenge facing the DIB is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable, and verifiable security.

Other key findings from the report include:

  • The biggest fear of non-compliance remains losing contracts (52%), yet 90% of contractors still want the federal government to mandate minimum cybersecurity standards for every federal contractor, and 77% say DFARS compliance meaningfully improves national security.
  • At the same time, 74% want easier implementation and 70% want more vendor options.
  • Adoption of core cybersecurity technologies continued to increase, including multi-factor authentication (63%), secure backup (48%), data-leakage protection (44%), vulnerability management (44%), and endpoint detection (40%).

“The most striking finding this year is the widening gap between reported progress and confidence in that progress,” said Dr. David M. Schneer, CEO of Merrill Research. “Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially. That tension suggests that measuring progress requires looking beyond the reported score itself.”

The 2026 State of the DIB Report is based on a survey of 302 U.S. defense contractors (195 prime contractors, 118 subcontractors, and 11 organizations identifying as both), conducted by Merrill Research in May 2026.

The findings will be a focus of CMMC CON 2026, CyberSheath’s annual virtual conference on Sept. 23-24, 2026, as government and industry leaders discuss CMMC reform and what comes next for defense contractors. Registration is open for the free event. Read the full report for complete findings.

About CyberSheath
Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. The company helps defense contractors assess, implement, operate, and continuously improve secure environments that meet DOD cybersecurity requirements, including NIST SP 800-171, DFARS, and CMMC. Learn more at www.cybersheath.com.

Contacts

CyberSheath
Kristen Morales
Kristen.Morales@cybersheath.com

Lexie Capperella
Gregory on behalf of CyberSheath
cybersheath@gregoryagency.com

CyberSheath


Release Versions

Contacts

CyberSheath
Kristen Morales
Kristen.Morales@cybersheath.com

Lexie Capperella
Gregory on behalf of CyberSheath
cybersheath@gregoryagency.com

Social Media Profiles
More News From CyberSheath

CyberSheath Guides Woman-Owned Small Business Gemini Industries Forward with CMMC Level 2 Certification Despite Phase 2 Pause

RESTON, Va.--(BUSINESS WIRE)--The Pentagon suspended CMMC Phase 2 requirements on July 13, pausing the mandatory third-party assessment requirement that had been set to take effect Nov. 10. For some defense contractors, the announcement was a reason to wait. For Gemini Industries, a technology solutions provider specializing in mission-critical support for U.S. government agencies and national security customers, it reaffirmed a decision the company had already made: invest in cybersecurity and...

CyberSheath Helps SEP Achieve CMMC Level 2 Certification With Scalable Enclave Built for Defense Business Growth

RESTON, Va.--(BUSINESS WIRE)--CyberSheath helped SEP, one of Indiana’s largest software development companies, achieve CMMC Level 2 certification to support current defense operations and future business development. SEP has served aerospace and defense clients since 1989, building software across web, mobile, desktop, embedded systems, and cloud. With the Department of Defense estimating that over 118,000 companies will need CMMC Level 2 certification, SEP pursued early certification to mainta...

CyberSheath Reopens Free Defense Contractor Cybersecurity Compliance Training Program as the DIB Races Toward CMMC Phase 2 Deadline

RESTON, Va.--(BUSINESS WIRE)--With the Phase 2 Cybersecurity Maturity Model Certification (CMMC) deadline arriving Nov. 10, 2026, defense contractors that haven’t started preparing face a shrinking window to get certified before third-party assessments become mandatory. The most recent State of the DIB Report, conducted by Merrill Research, found that only 1% of defense contractors felt fully prepared for CMMC assessments, and 69% rated achieving and maintaining compliance at 7 out of 10 or hig...
Back to Newsroom