US defense contractors are reporting their highest cybersecurity self-assessment scores in five years, but confidence in the accuracy of those scores has plummeted, according to the 2026 State of the DIB Report published August 20 by CyberSheath. The average Supplier Performance Risk System (SPRS) score climbed to +51, up from +33 in 2025, marking the first time in the report's history that scores reached positive territory in back-to-back years. The findings come after the Trump administration suspended a planned second phase of the Cybersecurity Maturity Model Certification (CMMC) program in July 2026, which would have required independent third-party audits to verify contractor compliance.

Despite the record-high self-reported scores, just 65% of contractors said they were extremely or very confident their score was accurate—a sharp drop from 89% last year and 94% in 2024, representing a 24-percentage-point decline in confidence over the past year alone. Only 1% of contractors believe they're completely prepared for CMMC certification, unchanged from a previous CyberSheath study released in October 2025. The survey, which underpins the report and was conducted by Merrill Research in May 2026, polled 302 US defense contractors including 195 prime contractors, 118 subcontractors, and 11 organizations identifying as both. Defense contractors use SPRS to evaluate their maturity against 110 security controls outlined in NIST SP 800-171, a standard from the US National Institute of Standards and Technology, with 110 representing a perfect score. Annual DFARS compliance budgets rose sharply to an average of $155,204, with 53% of respondents describing their budgets as "just right" and 24% saying they were more than enough.

David M. Schneer, CEO of Merrill Research, called the disconnect between rising scores and falling confidence "the most striking finding this year," noting that contractors are reporting greater adoption of cybersecurity capabilities while simultaneously expressing less trust in the accuracy of their assessments. The report concludes that "the challenge facing the DIB is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security." While more than half—52%—of defense industrial base members fear losing contracts due to non-compliance, an overwhelming 90% still support a legal mandate for minimum cybersecurity standards for defense contractors and subcontractors. Additionally, 77% said DFARS compliance meaningfully improves national security, though 74% called for easier implementation processes and 70% requested more vendor options to support compliance efforts.

The suspension of CMMC Phase II, originally scheduled to take effect November 10, 2026, eliminated the requirement for independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs), leaving self-reporting as the only mandate under Phase I. Emil Sayegh, CEO of CyberSheath, emphasized that most defense industrial base contractors are manufacturers, engineers, and specialized businesses "whose mission is supporting the warfighter, not becoming cybersecurity experts," and urged the federal administration to reform CMMC in a way that makes effective cybersecurity easier to adopt while maintaining objective, verifiable assurance that protections are actually functioning. He concluded that "meaningful verification and accountability should remain central to ensuring that reported compliance reflects operational cybersecurity" regardless of how the program evolves. The tension between rising self-reported scores and cratering confidence suggests that without external validation, contractors may be uncertain whether their investments are genuinely closing security gaps or simply checking boxes on a compliance form. The political question facing policymakers now isn't whether standards matter, but whether trust can survive in a system that asks organizations to grade their own homework.