← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Defense Contractors Confident in CMMC Compliance, But Struggle to Prove It

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 96% of contractors are confident in their self-attested SPRS scores.
  • Only 29% can back claims with a current SPRS submission and FedRAMP-authorized platform.
  • 84% of contractors are concerned about False Claims Act liability.
  • Nearly half of respondents were unaware of continued Phase 1 self-assessment obligations.

Confidence vs. Proof in Cybersecurity Compliance

Recent surveys from Kiteworks and CyberSheath/Merrill Research reveal a discrepancy within the defense industrial base. Contractors report high confidence in their cybersecurity compliance, with 96% believing their self-attested Supplier Performance Risk System (SPRS) scores would withstand review. However, only 29% of those surveyed by Kiteworks could substantiate this claim with both a current SPRS submission and a FedRAMP-authorized platform.

Impact of CMMC 2.0 Phase 2 Suspension

The Pentagon's July suspension of CMMC 2.0 Phase 2 third-party assessments has not removed contractors' legal exposure. The underlying DFARS obligation for accurate attestations remains, and 84% of contractors expressed concern about False Claims Act liability due to inaccurate scores. Furthermore, 92% have already sought legal or compliance review.

Confusion and Market Reactions

A significant number of contractors, nearly half, were unaware that Phase 1 self-assessment obligations continued through the pause. This lack of understanding persists even among those who claim high confidence in their grasp of the changes. The market has reacted to the perceived lowered bar, with 55% of contractors now bidding on work previously avoided due to CMMC Level 2 requirements. Conversely, 52% withdrew from a Department of War bid, and 38% reported losing or being disqualified from contracts over the same requirement, disproportionately affecting smaller subcontractors.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 15 stories · Aug 20

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Two industry surveys indicate that defense contractors are increasingly confident in their cybersecurity compliance, yet many lack the necessary documentation to prove it. This disconnect raises concerns about potential False Claims Act liability and highlights confusion regarding CMMC requirements, even after the CMMC 2.0 Phase 2 assessment suspension.