New Report Shows Defense Contractors’ Self-Reported Cybersecurity Scores Are Rising as Confidence in Their Accuracy Plunges 24 Points
The Cybersecurity Maturity Model Certification (CMMC) program is a Pentagon framework that became federal defense contract law last November, requiring defense contractors to prove their cybersecurity practices meet federal standards. In July, the Pentagon paused the requirement for third-party verification, leaving the defense industrial base (DIB) to rely on self-attestation. A study conducted by Merrill Research and commissioned by CyberSheath found that contractors’ self-reported cybersecurity scores are rising, but their confidence in the accuracy of those scores has drastically declined.
The 2026 State of the DIB Report found that the average Supplier Performance Risk System (SPRS) score rose to a five-year high of +51, up from +33 in 2025, which was the first positive score in the report’s history. A perfect NIST SP 800-171 assessment score is 110. Yet as reported scores improved, confidence in their accuracy fell 24 percentage points. Only 65% of contractors say they're extremely or very confident that their score is accurate, down sharply from 89% last year and 94% in 2024. What’s more, only 1% of contractors believe they are completely prepared for CMMC certification, unchanged from last year.








