US defense contractors are reporting a significant increase in their self-assessed cybersecurity scores, reaching a five-year high, yet their confidence in the accuracy of these scores has sharply declined. This trend emerges from the 2026 State of the DIB Report, published on August 20 by CyberSheath, which surveys the cybersecurity posture of the US defense industrial base (DIB).
The average Supplier Performance Risk System (SPRS) score, a self-assessment framework used by contractors for the Cybersecurity Maturity Model Certification (CMMC), rose to +51. This marks a substantial increase from +33 in 2025, which was the first positive score recorded in the report's history. CMMC is a Department of Defense (DoD) program designed to improve cyber hygiene for contractors handling federal contract information (FCI) and controlled unclassified information (CUI). Compliance with the Defense Federal Acquisition Regulation Supplement (DFARS) makes CMMC a binding legal requirement for securing DoD contracts.
Contractors use SPRS to assess their adherence to 110 security controls outlined in NIST SP 800-171, a standard from the US National Institute of Standards and Technology (NIST), with a perfect score being 110. While self-reporting is currently the only mandate under CMMC Phase I, Phase II was intended to introduce independent assessments by Certified Third-Party Assessment Organizations (C3PAOs) to verify compliance. However, CMMC Phase II, originally slated for November 10, 2026, was suspended by the Trump administration in July 2026.
Despite the reported rise in self-assessment scores, the CyberSheath study, based on a May 2026 survey of 302 US defense contractors conducted by Merrill Research, revealed a concerning drop in confidence. Only 65% of contractors expressed extreme or very high confidence in the accuracy of their scores, a significant decrease from 89% in 2025 and 94% in 2024. This 24-percentage-point decline highlights a growing tension between reported progress and belief in its veracity.
The study also found that only 1% of contractors believe they are completely prepared for CMMC certification, a figure unchanged from an October 2025 CyberSheath study. The primary obstacle does not appear to be financial, as 53% of respondents felt their budgets were "just right," and 24% considered them more than sufficient. DFARS compliance budgets saw a sharp increase this year, averaging $155,204 annually.
The report suggests that the core challenge for the DIB is not merely the amount spent on cybersecurity, but the effectiveness of these investments in translating into implemented, sustainable, and verifiable security measures. While 52% of DIB members fear losing contracts due to non-compliance, a vast majority (90%) still support a legal mandate for minimum cybersecurity standards.
Furthermore, 77% of contractors believe DFARS compliance meaningfully enhances national security, yet they are calling for changes to its implementation. Specifically, 74% desire easier implementation processes, and 70% seek more vendor options to support compliance efforts.
Emil Sayegh, CEO of CyberSheath, emphasized that most DIB contractors are manufacturers, engineers, and specialized businesses focused on supporting military operations, not on becoming cybersecurity experts. He advocated for federal administration reform of the CMMC program to simplify effective cybersecurity consumption while maintaining objective, verifiable assurance that protections are operational. He concluded that regardless of CMMC's evolution, meaningful verification and accountability must remain central to ensuring reported compliance reflects actual operational cybersecurity.






