Average contractor self-assessments on the Pentagon’s Supplier Performance Risk System (SPRS) climbed to a five‑year high, rising to +51 in 2026 from +33 in 2025 — even as confidence that those numbers are accurate plunged sharply.
SPRS scores climbed to a five‑year high
The 2026 State of the DIB Report, published August 20 by CyberSheath and based on a Merrill Research survey, found the average SPRS score among surveyed US defense contractors reached +51 — the highest level tracked in the report’s five‑year series. SPRS is the framework US defense industrial base (DIB) contractors use to self‑assess cybersecurity maturity under the Cybersecurity Maturity Model Certification (CMMC). Using SPRS, contractors measure themselves against 110 security controls from NIST SP 800‑171; a perfect assessment score is 110.
Under Phase I of CMMC, self‑reporting through SPRS remains the only current mandate. CMMC was designed to raise cyber hygiene for contractors and subcontractors handling federal contract information (FCI) and controlled unclassified information (CUI), and the Defense Federal Acquisition Regulation Supplement (DFARS) converts those cybersecurity requirements into binding contract obligations for organizations seeking Department of Defense (DoD) work.
Confidence in self‑assessments collapsed
Despite higher reported SPRS scores and wider adoption of cybersecurity capabilities, contractor confidence in the accuracy of their scores fell sharply. The Merrill Research survey found that just 65% of contractors said they were "extremely" or "very" confident their SPRS score was accurate — down 24 percentage points from 89% in 2025 and down from 94% in 2024. Merrill Research CEO David M. Schneer called the divergence between rising scores and falling confidence “the most striking finding this year.”
Only 1% of respondents said they were completely prepared for CMMC certification, a figure unchanged from a CyberSheath study published in October 2025. That persistent low readiness sits alongside rising self‑reported scores and greater investment, underlining the report’s central tension: reported progress may not equal verifiable, operational security.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCMMC Phase II suspension leaves verification pending
CMMC was scheduled to introduce independent, third‑party verification in Phase II through Certified Third‑Party Assessment Organizations (C3PAOs). Those independent assessments were originally set to begin on November 10, 2026, but Phase II was suspended by the Trump administration in July 2026. With independent audits on hold, self‑assessments remain the primary metric for many contractors’ compliance claims.
CyberSheath’s report stresses that meaningful verification and accountability are central to ensuring reported compliance reflects operational cybersecurity — a point the firm’s CEO, Emil Sayegh, emphasized: most DIB contractors are “manufacturers, engineers and specialized businesses whose mission is supporting the warfighter, not becoming cybersecurity experts.”
Budgets rose but contractors want easier processes and more vendors
Money does not appear to be the main bottleneck. Average DFARS compliance budgets rose sharply to $155,204 annually. A slim majority (53%) of respondents said their budgets felt “just right,” and 24% said their budgets were “more than enough.”
Still, contractors called for changes to how compliance is implemented: 74% requested easier implementation processes and 70% asked for more vendor options to support compliance efforts. The report framed this as an effectiveness problem — not simply how much is spent but how well investments translate into implemented, sustainable, and verifiable security.
What this means for prime contractors, subcontractors, and the federal administration
- Prime contractors: With 195 prime contractors included in the survey, primes will likely continue to report higher SPRS scores but must grapple with lower internal confidence and an absence of Phase II third‑party verification.
- Subcontractors: Among 118 subcontractors surveyed (and 11 organizations identifying as both prime and subcontractor), the call for easier implementation and more vendor options speaks to operational burdens on smaller, specialized firms that fund compliance but may lack cyber expertise.
- The federal administration: Policymakers face a choice between reinstating independent assessments to restore verifiable assurance or relying on self‑reports that contractors increasingly view with skepticism; CyberSheath’s leadership urged reforms “that make effective cybersecurity easier to consume while preserving objective, verifiable assurance.”
The CyberSheath 2026 State of the DIB Report draws on a Merrill Research survey of 302 US defense contractors conducted in May 2026 (195 prime contractors, 118 subcontractors, and 11 identifying as both). The survey found broader support for minimum standards — 90% of respondents favor a legal mandate for minimum cybersecurity standards — and anxiety about enforcement: 52% fear losing contracts due to non‑compliance, while 77% said DFARS compliance meaningfully improves national security.
The picture is now stark and unresolved. Self‑reported SPRS scores have climbed to a five‑year high even as internal confidence has eroded and the planned shift to third‑party verification has been suspended. Contractors want simpler pathways and more vendor help; CyberSheath’s executives insist on keeping “objective, verifiable assurance” at the center of any reform. Until independent assessments resume, the DIB will have to reconcile rising numbers with a growing lack of faith that those numbers reflect reality.
https://www.infosecurity-magazine.com/news/us-defense-contractors-cmmc-scores/




