The CMMC Confidence Gap Is a Documentation Problem
September 4, 2026
.png?width=900&name=Breaking%20News%20(1).png)
Manufactured with Speed and Precision
The manufacturing capabilities you need and the engineering support you want, all from a single partner.
Submit a DesignKey Points
- Contractor confidence in self-assessment accuracy dropped from 94% in 2024 to 65% in 2026, according to CyberSheath's survey of 302 defense contractors.
- The Department of Defense suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 in July, but Phase 1 self-assessment obligations and False Claims Act exposure remain fully in force.
- Rising self-assessment scores paired with falling confidence point to an evidence and documentation gap.
- Supply chain exposure is driving contractor demand for broader Defense Federal Acquisition Regulation Supplement (DFARS) coverage, with more than 8 in 10 wanting managed security service providers included.
- Suppliers holding CMMC Level 2 certification today remove a documentation risk their customers would otherwise carry.
Confidence Is Falling Because Evidence Is Hard
Contractors are getting better at cybersecurity and less certain they can prove it. That is the finding buried in the new CyberSheath data.
Scores are up. The mean self-assessment score reached +51 in 2026, the second consecutive positive year, after climbing from -25 in 2022. Adoption of core practices improved across the board.
Confidence went the other direction. Only 65% of contractors submitting 2026 self-assessment scores are extremely or very confident those scores reflect their posture, down from 89% in 2025 and 94% in 2024.
That gap comes from experience. Contractors now know what an assessor will ask them to produce, and the ask is more intense than they feel ready to handle.
What CyberSheath Found
CyberSheath published its report Thursday, and Cybersecurity Dive's coverage of the findings put the numbers in front of a wider audience. The survey covered 302 defense contractors: 184 primes, 107 subcontractors, and 11 operating in both roles across IT, manufacturing, healthcare, and transportation.
The median contractor believes it is 70% ready for a CMMC certification review, and only one-third put themselves at 80% or better. One percent say they are fully ready.
CyberSheath researchers named the pattern directly, writing that contractors "continue to struggle with navigating evolving requirements, producing the evidence necessary to support executive attestation, and demonstrating compliance."
| CMMC readiness signal | 2024 | 2025 | 2026 |
|---|---|---|---|
| High confidence in self-assessment accuracy | 94% | 89% | 65% |
| Mean self-assessment score | -12 | +33 | +51 |
| Contractors at least 80% assessment-ready | Not reported | Not reported | 33% |
| First-attempt pass rate on third-party review | Not reported | Not reported | 63% |
Essential Background Reading:
- DFARS and CMMC Resources: A starting point for understanding how DFARS clauses and CMMC requirements interact for defense suppliers.
- CMMC Resource Center: A collection of guides covering CMMC levels, timelines, and compliance requirements.
- Guide to CMMC: A foundational overview of what CMMC requires and how the certification levels are structured.
- CMMC Level 2: Details on the specific practices and assessment requirements at the Level 2 tier most defense suppliers must meet.
The Phase 2 Suspension Changed the Timeline, Not the Liability
The Department of Defense suspended CMMC's second phase in July, citing the cost of independent third-party reviews. Plenty of suppliers read that as breathing room, but that may not be the reality.
Phase 1 remains in effect. Self-assessment scores still get submitted, and an executive still signs an attestation that those scores are accurate. The Trump administration has continued using the False Claims Act against defense firms that misrepresent their cybersecurity posture to the government.
CyberSheath clarified the consequence: "While the requirement for third-party certification may have been delayed, the responsibility to accurately represent cybersecurity compliance has not."
A supplier sitting at 70% readiness with a signed attestation on file carries legal exposure that no schedule change touches. The 63% first-attempt pass rate among contractors who did face third-party review suggests roughly one in three self-assessments would not survive outside scrutiny.
Related Content:
- CMMC Certified Manufacturing: How a CMMC Level 2 certified manufacturing partner removes a compliance variable from your supply chain.
- CMMC Subcontractors: What prime contractors should verify when vetting subcontractors for CMMC compliance.
- CMMC Certified FIP Gasket Dispensing: How form-in-place gasket dispensing for defense electronics is handled under CMMC controls.
- CMMC Certified CNC Machining: How machined component production fits inside a CMMC Level 2 certified environment.
- Cybersecurity in Aerospace Defense: What Suppliers Must Do Now: A broader look at cybersecurity obligations facing aerospace and defense suppliers.
Supply Chain Exposure Is the Signal Buried in the Data
More than eight in ten contractors told CyberSheath that DFARS should apply to managed security service providers. Sixty-three percent said it should cover managed service providers, and 58% wanted other technology providers included. Contractors depend on third parties to protect controlled unclassified information (CUI), and they have limited visibility into whether those third parties can defend it.
The same logic applies to the hardware supply chain. When a prime sends a drawing containing CUI to a machine shop or a gasket supplier, that drawing crosses a boundary. The prime's attestation covers the prime's environment, it stops at the edge of a supplier's network.
Many of the suppliers holding sensitive drawings are small manufacturers whose compliance program consists of a policy document nobody has tested.
Next Steps:
- How to Build a Manufacturing Readiness Evidence Package That Passes DOD Review: A practical guide to assembling the documentation an assessor will actually accept.
- Manufacturing Readiness Level Assessments: What Defense Contractors Need to Know: How readiness assessments intersect with compliance and production timelines.
- From Breadboard to Full Rate Production: A Program Manager's MRL Roadmap: A roadmap for program managers moving a design from prototype to full-rate production.
- Cost Modeling and Should Cost Analysis Across Manufacturing Readiness Levels: How cost modeling changes as a program moves through manufacturing readiness levels.
What to Do Before Phase 2 Returns
Phase 2 will come back in some form. The work that closes a 30-point readiness gap takes longer than the notice period is likely to be, so start with the items that carry legal weight now.
- Audit your attestation evidence: for every practice you scored as implemented, identify the artifact an assessor would accept as proof. Missing artifacts are the most common gap.
- Test your system boundary against reality: confirm where CUI lives, including engineering file shares, email attachments, and supplier transmittals that never got documented in your System Security Plan.
- Map CUI flow to your hardware supply chain: identify every supplier receiving controlled drawings and document their compliance status. Unverified suppliers are the largest exposure surface.
- Treat the 63% pass rate as your planning baseline: assume a one-in-three chance your current self-assessment fails third-party review, and prioritize remediation accordingly.
- Ask suppliers for certification status: a supplier working toward compliance and a supplier holding certification carry very different risk profiles for your program.
Multifactor authentication adoption sits at 63%, secure backups at 48%, and endpoint detection at 40%, according to the CyberSheath survey. Those numbers are improving and still leave large gaps in basic controls across the defense industrial base.
See It In Action:
- Custom Part Manufacturing for Space-Based Interceptors: How custom manufacturing supports missile defense programs with strict compliance requirements.
- Custom Manufactured Parts for Missile Manufacturers and OEMs: How OEMs source custom parts for missile platforms through certified manufacturing partners.
- Custom Manufacturers for Ground-Based Interceptor Parts and Components: A look at component manufacturing for ground-based interceptor systems.
- Counter-UAS Systems: Inside the Hardware That Makes CUAS Components Work: How component manufacturing supports counter-drone defense systems.
How Modus Advanced Approaches CMMC Certification
Modus Advanced is CMMC Level 2 certified, alongside AS9100, ISO 9001, and ITAR registration.
When a program manager maps CUI flow through the supply chain and reaches a supplier producing machined components, form-in-place gaskets, or EMI shielding, our certification status is a verified fact rather than a question that has to be chased down and documented.
The compliance work is already done, which means the engineering conversation can be about tolerances, materials, and lead times.
Somewhere downrange, a soldier is carrying the radio you're designing. What matters to them is that the part works. Let's solve this.
