Essential Background Reading:

Related Content:

Next Steps:

See It In Action:

Capabilities
Industries
Quality & Engineering
Resources
About
Learning Center

The CMMC Confidence Gap Is a Documentation Problem

September 4, 2026

The CMMC Confidence Gap Is a Documentation Problem
Manufactured with Speed and Precision

The manufacturing capabilities you need and the engineering support you want, all from a single partner.

Submit a Design

Key Points

  • Contractor confidence in self-assessment accuracy dropped from 94% in 2024 to 65% in 2026, according to CyberSheath's survey of 302 defense contractors.
  • The Department of Defense suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 in July, but Phase 1 self-assessment obligations and False Claims Act exposure remain fully in force.
  • Rising self-assessment scores paired with falling confidence point to an evidence and documentation gap.
  • Supply chain exposure is driving contractor demand for broader Defense Federal Acquisition Regulation Supplement (DFARS) coverage, with more than 8 in 10 wanting managed security service providers included.
  • Suppliers holding CMMC Level 2 certification today remove a documentation risk their customers would otherwise carry.

Confidence Is Falling Because Evidence Is Hard

Contractors are getting better at cybersecurity and less certain they can prove it. That is the finding buried in the new CyberSheath data.

Scores are up. The mean self-assessment score reached +51 in 2026, the second consecutive positive year, after climbing from -25 in 2022. Adoption of core practices improved across the board.

Confidence went the other direction. Only 65% of contractors submitting 2026 self-assessment scores are extremely or very confident those scores reflect their posture, down from 89% in 2025 and 94% in 2024.

That gap comes from experience. Contractors now know what an assessor will ask them to produce, and the ask is more intense than they feel ready to handle.

What CyberSheath Found

CyberSheath published its report Thursday, and Cybersecurity Dive's coverage of the findings put the numbers in front of a wider audience. The survey covered 302 defense contractors: 184 primes, 107 subcontractors, and 11 operating in both roles across IT, manufacturing, healthcare, and transportation.

The median contractor believes it is 70% ready for a CMMC certification review, and only one-third put themselves at 80% or better. One percent say they are fully ready.

CyberSheath researchers named the pattern directly, writing that contractors "continue to struggle with navigating evolving requirements, producing the evidence necessary to support executive attestation, and demonstrating compliance."

CMMC readiness signal202420252026
High confidence in self-assessment accuracy94%89%65%
Mean self-assessment score-12+33+51
Contractors at least 80% assessment-readyNot reportedNot reported33%
First-attempt pass rate on third-party reviewNot reportedNot reported63%

Essential Background Reading:

  • DFARS and CMMC Resources: A starting point for understanding how DFARS clauses and CMMC requirements interact for defense suppliers.
  • CMMC Resource Center: A collection of guides covering CMMC levels, timelines, and compliance requirements.
  • Guide to CMMC: A foundational overview of what CMMC requires and how the certification levels are structured.
  • CMMC Level 2: Details on the specific practices and assessment requirements at the Level 2 tier most defense suppliers must meet.

The Phase 2 Suspension Changed the Timeline, Not the Liability

The Department of Defense suspended CMMC's second phase in July, citing the cost of independent third-party reviews. Plenty of suppliers read that as breathing room, but that may not be the reality.

Phase 1 remains in effect. Self-assessment scores still get submitted, and an executive still signs an attestation that those scores are accurate. The Trump administration has continued using the False Claims Act against defense firms that misrepresent their cybersecurity posture to the government.

CyberSheath clarified the consequence: "While the requirement for third-party certification may have been delayed, the responsibility to accurately represent cybersecurity compliance has not."

A supplier sitting at 70% readiness with a signed attestation on file carries legal exposure that no schedule change touches. The 63% first-attempt pass rate among contractors who did face third-party review suggests roughly one in three self-assessments would not survive outside scrutiny.

Related Content:

Supply Chain Exposure Is the Signal Buried in the Data

More than eight in ten contractors told CyberSheath that DFARS should apply to managed security service providers. Sixty-three percent said it should cover managed service providers, and 58% wanted other technology providers included. Contractors depend on third parties to protect controlled unclassified information (CUI), and they have limited visibility into whether those third parties can defend it.

The same logic applies to the hardware supply chain. When a prime sends a drawing containing CUI to a machine shop or a gasket supplier, that drawing crosses a boundary. The prime's attestation covers the prime's environment, it stops at the edge of a supplier's network.

Many of the suppliers holding sensitive drawings are small manufacturers whose compliance program consists of a policy document nobody has tested.

Next Steps:

What to Do Before Phase 2 Returns

Phase 2 will come back in some form. The work that closes a 30-point readiness gap takes longer than the notice period is likely to be, so start with the items that carry legal weight now.

  • Audit your attestation evidence: for every practice you scored as implemented, identify the artifact an assessor would accept as proof. Missing artifacts are the most common gap.
  • Test your system boundary against reality: confirm where CUI lives, including engineering file shares, email attachments, and supplier transmittals that never got documented in your System Security Plan.
  • Map CUI flow to your hardware supply chain: identify every supplier receiving controlled drawings and document their compliance status. Unverified suppliers are the largest exposure surface.
  • Treat the 63% pass rate as your planning baseline: assume a one-in-three chance your current self-assessment fails third-party review, and prioritize remediation accordingly.
  • Ask suppliers for certification status: a supplier working toward compliance and a supplier holding certification carry very different risk profiles for your program.

Multifactor authentication adoption sits at 63%, secure backups at 48%, and endpoint detection at 40%, according to the CyberSheath survey. Those numbers are improving and still leave large gaps in basic controls across the defense industrial base.

See It In Action:

How Modus Advanced Approaches CMMC Certification

Modus Advanced is CMMC Level 2 certified, alongside AS9100, ISO 9001, and ITAR registration.

When a program manager maps CUI flow through the supply chain and reaches a supplier producing machined components, form-in-place gaskets, or EMI shielding, our certification status is a verified fact rather than a question that has to be chased down and documented.

The compliance work is already done, which means the engineering conversation can be about tolerances, materials, and lead times.

Somewhere downrange, a soldier is carrying the radio you're designing. What matters to them is that the part works. Let's solve this.

New call-to-action