Recent surveys from Kiteworks and CyberSheath/Merrill Research reveal a discrepancy within the defense industrial base. Contractors report high confidence in their cybersecurity compliance, with 96% believing their self-attested Supplier Performance Risk System (SPRS) scores would withstand review. However, only 29% of those surveyed by Kiteworks could substantiate this claim with both a current SPRS submission and a FedRAMP-authorized platform.
The Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments has not removed contractors' legal exposure. The underlying DFARS obligation for accurate attestations remains, and 84% of contractors expressed concern about False Claims Act liability due to inaccurate scores. Furthermore, 92% have already sought legal or compliance review.
A significant number of contractors, nearly half, were unaware that Phase 1 self-assessment obligations continued through the pause. This lack of understanding persists even among those who claim high confidence in their grasp of the changes. The market has reacted to the perceived lowered bar, with 55% of contractors now bidding on work previously avoided due to CMMC Level 2 requirements. Conversely, 52% withdrew from a Department of War bid, and 38% reported losing or being disqualified from contracts over the same requirement, disproportionately affecting smaller subcontractors.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Two industry surveys indicate that defense contractors are increasingly confident in their cybersecurity compliance, yet many lack the necessary documentation to prove it. This disconnect raises concerns about potential False Claims Act liability and highlights confusion regarding CMMC requirements, even after the CMMC 2.0 Phase 2 assessment suspension.