Dive Brief:
- Defense contractors are struggling to meet the requirements of the U.S. military’s Cybersecurity Maturity Model Certification (CMMC) program, even as the Pentagon tries to accommodate their complaints about compliance burdens.
- Only two-thirds of contractors that have submitted CMMC self-assessment scores to the military in 2026 are extremely or very confident that those scores accurately reflect their cybersecurity posture, and the median contractor believes it is only 70% ready to undergo a CMMC certification review, the consulting firm CyberSheath said in a report published on Thursday.
- The report — which also finds that defense contractors want a wider range of firms to be subject to cybersecurity requirements — underscores the difficulty of protecting the defense industry at a time of increasing nation-state hacking threats.
Dive Insight:
The Department of Defense in July suspended CMMC’s second phase, saying its requirement for independent third-party reviews would have cost companies too much. But the first phase remains in effect, and companies are still struggling to meet those standards, much as they have for the past few years.
In fact, defense contractors are less confident in their self-assessed cybersecurity readiness than they were in years past. While 65% reported high confidence in 2026, 89% said the same in 2025, and 94% said so in 2024.
Only one-third of contractors believe they are at least 80% prepared to face a CMMC assessment, with a scant 1% saying they are fully ready.
Contractors “continue to struggle with navigating evolving requirements, producing the evidence necessary to support executive attestation, and demonstrating compliance,” CyberSheath said.
On the other hand, contractors’ mean self-assessment score reached +51 in 2026, the second year in a row that it was positive. (It had edged upward from -25 in 2022 to -12 in 2024, before jumping to +33 in 2025.) And for the first time, in 2026, at least four in 10 contractors had implemented five key security practices: multifactor authentication (63% reported adopting it), secure backups (48%), data-leakage protections (44%), vulnerability management (44%) and endpoint detection (40%).
CyberSheath said there was a “confidence disconnect” at play in the defense industrial base.
“Contractors report stronger cybersecurity programs, higher compliance scores, and greater investment than ever before,” researchers wrote, “yet their confidence in the accuracy of those claims continues to decline.”
When companies did submit to third-party reviews, 63% of them passed on the first try.
Defense contractors want the military’s procurement rules to cover a broader range of firms. More than eight in 10 said the Defense Federal Acquisition Regulation Supplement (DFARS) should apply to managed security service providers, with 63% saying it should cover managed service providers and 58% saying it should cover other technology providers.
CyberSheath researchers said those findings reflected contractors’ frustration with their own supply-chain exposures.
“As organizations increasingly depend on third parties to protect [controlled unclassified information],” the company said, “many contractors believe those providers should be held to comparable cybersecurity standards.”
Despite freezing enhanced CMMC requirements, the Trump administration has continued to use the False Claims Act to prosecute defense firms that misrepresent their cybersecurity postures to the government. CyberSheath said that trend sent a clear message to contractors.
“While the requirement for third-party certification may have been delayed,” researchers wrote, “the responsibility to accurately represent cybersecurity compliance has not.”
CyberSheath’s report is based on a survey of 302 defense contractors, 184 of them prime contractors, 107 of them subcontractors and 11 serving in both roles. The companies, which spanned the IT, manufacturing, healthcare and transportation industries, all had annual revenues between $500,000 and $1 million.