New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points
New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points
RESTON, Va.--(BUSINESS WIRE)--The Cybersecurity Maturity Model Certification (CMMC) program is a Pentagon framework that became federal defense contract law last November, requiring defense contractors to prove their cybersecurity practices meet federal standards. In July, the Pentagon paused the requirement for third-party verification, leaving the defense industrial base (DIB) to rely on self-attestation. A study conducted by Merrill Research and commissioned by CyberSheath found that contractors’ self-reported cybersecurity scores are rising, but their confidence in the accuracy of those scores has drastically declined.
The 2026 State of the DIB Report found that the average Supplier Performance Risk System (SPRS) score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report’s history. A perfect NIST SP 800-171 assessment score is 110. Yet as reported scores improved, confidence in their accuracy fell 24 percentage points. Only 65% of contractors say they're extremely or very confident that their score is accurate, down sharply from 89% last year and 94% in 2024. What’s more, only 1% of contractors believe they are completely prepared for CMMC certification, unchanged from last year.
“Most contractors are manufacturers, engineers, and specialized businesses whose mission is supporting the warfighter, not becoming cybersecurity experts,” said Emil Sayegh, CEO of CyberSheath. “That is exactly why CMMC reform should make effective cybersecurity easier to consume while preserving objective, verifiable assurance that the protections are actually in place and working. However CMMC evolves, meaningful verification and accountability should remain central to ensuring that reported compliance reflects operational cybersecurity.”
The survey also showed that Defense Federal Acquisition Regulation Supplement (DFARS) compliance budgets rose sharply this year to an average of $155,204 annually, and 53% said their budgets felt “just right,” while 24% said they were more than enough. The findings suggest that the challenge facing the DIB is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable, and verifiable security.
Other key findings from the report include:
- The biggest fear of non-compliance remains losing contracts (52%), yet 90% of contractors still want the federal government to mandate minimum cybersecurity standards for every federal contractor, and 77% say DFARS compliance meaningfully improves national security.
- At the same time, 74% want easier implementation and 70% want more vendor options.
- Adoption of core cybersecurity technologies continued to increase, including multi-factor authentication (63%), secure backup (48%), data-leakage protection (44%), vulnerability management (44%), and endpoint detection (40%).
“The most striking finding this year is the widening gap between reported progress and confidence in that progress,” said Dr. David M. Schneer, CEO of Merrill Research. “Contractors are reporting higher SPRS scores and greater adoption of important cybersecurity capabilities, but confidence in the accuracy of those scores has fallen substantially. That tension suggests that measuring progress requires looking beyond the reported score itself.”
The 2026 State of the DIB Report is based on a survey of 302 U.S. defense contractors (195 prime contractors, 118 subcontractors, and 11 organizations identifying as both), conducted by Merrill Research in May 2026.
The findings will be a focus of CMMC CON 2026, CyberSheath’s annual virtual conference on Sept. 23-24, 2026, as government and industry leaders discuss CMMC reform and what comes next for defense contractors. Registration is open for the free event. Read the full report for complete findings.
About CyberSheath
Established in 2012, CyberSheath is one of the most experienced and trusted IT security services partners for the U.S. defense industrial base. The company helps defense contractors assess, implement, operate, and continuously improve secure environments that meet DOD cybersecurity requirements, including NIST SP 800-171, DFARS, and CMMC. Learn more at www.cybersheath.com.
Contacts
CyberSheath
Kristen Morales
Kristen.Morales@cybersheath.com
Lexie Capperella
Gregory on behalf of CyberSheath
cybersheath@gregoryagency.com
