Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

US defense contractors are reporting a significant increase in their self-assessed cybersecurity scores, reaching a five-year high, yet their confidence in the accuracy of these scores has sharply declined. This trend emerges from the 2026 State of the DIB Report, published on August 20 by CyberSheath, which surveys the cybersecurity posture of the US defense industrial base (DIB).
The average Supplier Performance Risk System (SPRS) score, a self-assessment framework used by contractors for the Cybersecurity Maturity Model Certification (CMMC), rose to +51. This marks a substantial increase from +33 in 2025, which was the first positive score recorded in the report's history. CMMC is a Department of Defense (DoD) program designed to improve cyber hygiene for contractors handling federal contract information (FCI) and controlled unclassified information (CUI). Compliance with the Defense Federal Acquisition Regulation Supplement (DFARS) makes CMMC a binding legal requirement for securing DoD contracts.
Contractors use SPRS to assess their adherence to 110 security controls outlined in NIST SP 800-171, a standard from the US National Institute of Standards and Technology (NIST), with a perfect score being 110. While self-reporting is currently the only mandate under CMMC Phase I, Phase II was intended to introduce independent assessments by Certified Third-Party Assessment Organizations (C3PAOs) to verify compliance. However, CMMC Phase II, originally slated for November 10, 2026, was suspended by the Trump administration in July 2026.
Despite the reported rise in self-assessment scores, the CyberSheath study, based on a May 2026 survey of 302 US defense contractors conducted by Merrill Research, revealed a concerning drop in confidence. Only 65% of contractors expressed extreme or very high confidence in the accuracy of their scores, a significant decrease from 89% in 2025 and 94% in 2024. This 24-percentage-point decline highlights a growing tension between reported progress and belief in its veracity.
The study also found that only 1% of contractors believe they are completely prepared for CMMC certification, a figure unchanged from an October 2025 CyberSheath study. The primary obstacle does not appear to be financial, as 53% of respondents felt their budgets were "just right," and 24% considered them more than sufficient. DFARS compliance budgets saw a sharp increase this year, averaging $155,204 annually.
The report suggests that the core challenge for the DIB is not merely the amount spent on cybersecurity, but the effectiveness of these investments in translating into implemented, sustainable, and verifiable security measures. While 52% of DIB members fear losing contracts due to non-compliance, a vast majority (90%) still support a legal mandate for minimum cybersecurity standards.
Furthermore, 77% of contractors believe DFARS compliance meaningfully enhances national security, yet they are calling for changes to its implementation. Specifically, 74% desire easier implementation processes, and 70% seek more vendor options to support compliance efforts.
Emil Sayegh, CEO of CyberSheath, emphasized that most DIB contractors are manufacturers, engineers, and specialized businesses focused on supporting military operations, not on becoming cybersecurity experts. He advocated for federal administration reform of the CMMC program to simplify effective cybersecurity consumption while maintaining objective, verifiable assurance that protections are operational. He concluded that regardless of CMMC's evolution, meaningful verification and accountability must remain central to ensuring reported compliance reflects actual operational cybersecurity.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a