A survey of 273 defense contractors found widespread compliance activity despite the DOD’s suspension of CMMC 2.0 Phase II assessments, but significant readiness gaps remain.

Defense contractors largely continued their cybersecurity compliance efforts after the Pentagon suspended third-party assessments under its Cybersecurity Maturity Model Certification (CMMC) program, but many remain unprepared for those requirements to return, according to a new report from cybersecurity technology company Kiteworks.

The 2026 “State of CMMC 2.0 Preparedness in the DIB” report is based on a survey of 273 defense contractors in the days following the Defense Department’s (DOD) July 13 suspension of CMMC 2.0 Phase II third-party assessments. The department announced a 60-day review of the program while keeping Phase 1 requirements in place.

Under the Trump administration, the DOD was rebranded as the War Department.

The survey found that 98% of surveyed organizations took at least one concrete action in response to the suspension, while just 2% took no action.

Among respondents, 62% said they continued implementing technical controls as planned, and the same percentage communicated with prime contractors or subcontractors about flow-down expectations. Another 51% began evaluating new compliance tools or platforms, while 32% paused or slowed vendor or tooling evaluations.

Nearly half – 49% – said they reallocated CMMC-related budgets to other priorities, but the report found that did not necessarily mean shifting money away from compliance.

Among respondents who reallocated funding, 63% directed money toward independently audited platforms such as FedRAMP-authorized tools, 55% toward expanded audit logging and evidence-generation capabilities, and 49% toward legal or compliance staff. Twenty-four percent moved funding to cybersecurity priorities outside CMMC entirely.

Despite that activity, the report identified a significant gap between contractors’ confidence in their compliance posture and the evidence supporting it.

Ninety-six percent of respondents said they were confident their self-attested Supplier Performance Risk System (SPRS) score would hold up under review. However, only 60% reported having a current SPRS submission, 36% said they operate on a FedRAMP-authorized platform, and 29% reported having both.

SPRS scores measure contractor compliance with National Institute of Standards and Technology (NIST) Special Publication 800-171 security requirements, which also form the cybersecurity foundation of the CMMC program.

“Ultimately, fewer than three in ten organizations that consider themselves ‘audit-ready’ have the key components in place to accurately make the claim,” the report said.

To measure readiness based on evidence rather than confidence, the report introduced two indicators based on the survey responses. The CMMC Compliance Maturity Score averaged 78.2 out of 100, while the Suspension Governance Score averaged 74.9.

Researchers multiplied the two scores to produce a combined CMMC Suspension Readiness Index of 60.0. According to the report, that score falls well below the roughly 77 that a simple average would produce.
The largest single group, representing 31% of respondents, scored low on both measures.

The survey also uncovered confusion about what the suspension actually changed. Forty-eight percent of contractors did not know that Phase 1 self-assessment obligations remain in effect during the pause.

Respondents who described themselves as “very confident” in their understanding of the suspension averaged just 2.48 out of 4 on Kiteworks’ assessment. Those who described themselves as “somewhat confident” posted the same average score.

The report warned that contractors could face legal exposure if their self-attested compliance claims do not match their actual cybersecurity posture.
While DOD suspended the third-party assessment requirement, the report noted that “it did not pause the law.”

“DFARS clause 252.204-7012 has required contractors handling covered defense information to implement NIST SP 800-171 controls and self-report their compliance status in the Supplier Performance Risk System since long before CMMC existed. Phase II was the independent-verification layer sitting on top of that obligation,” the report states. “Removing the verification layer does not remove the obligation – it removes the check on whether a contractor’s own claim about its compliance is true.”

That distinction is particularly important for contractors concerned about potential False Claims Act liability tied to inaccurate compliance attestations.

Eighty-four percent of surveyed contractors said they were concerned about False Claims Act exposure stemming from an inaccurate self-attested score, and 92% said they had already engaged legal or compliance review. At the same time, 80% of organizations with the weakest compliance posture remained confident their score would hold up under review.

“An organization that treats the Phase II suspension as license to slow down is not avoiding cost. It is deferring risk into a period with less independent verification standing between a self-attestation and a False Claims Act referral, not more,” the report states.

“The organizations that use the pause to turn confidence into evidence will be the ones ready when the assessor returns. The rest will still be exposed when it does,” the report concludes.

Read More About