Back to Articles Compliance

96% vs. 29%: The CMMC Compliance Gap Exposing Defense Contractors to False Claims Act Liability

By Asaf Levy · · 7 min read

Last reviewed: August 2026

Executive Answer

Two surveys published in August 2026 found the same thing: 96% of US defense contractors are confident their CMMC self-attestation would hold up under review. Only 29% can actually demonstrate it. The Pentagon suspended CMMC Phase 2 third-party assessments in July 2026. It did not suspend the DFARS obligation to attest accurately. It did not suspend False Claims Act liability for false attestations. For defense contractor CISOs, the practical question is not whether a C3PAO assessor is coming. It is whether the current SPRS score would survive a Department of Justice review.

Key Numbers

  • 96% - Defense contractors confident their self-attested SPRS score would hold up under formal review (Kiteworks, 273 contractors surveyed).
  • 29% - Contractors who can back that confidence with both a current SPRS submission and a FedRAMP-authorized platform for handling CUI.
  • 84% - Contractors concerned about False Claims Act liability tied to their SPRS attestation (Kiteworks survey).
  • 273 + 302 - Total contractors surveyed. Kiteworks surveyed 273 after the CMMC Phase 2 suspension. CyberSheath and Merrill Research surveyed 302 in May 2026 before the suspension.
  • +51 - Average SPRS score across the defense industrial base (out of a possible 110), a five-year high according to CyberSheath.
  • 1% - Contractors who consider themselves completely prepared for formal CMMC certification (CyberSheath).
  • $155,000 - Average annual DFARS compliance budget among surveyed contractors (CyberSheath).

The most important detail in these surveys is not the confidence gap. It is who has legal exposure because of it.

Kiteworks surveyed 273 defense contractors in the days following the Pentagon's July 2026 suspension of CMMC Phase 2 third-party assessments. Ninety-six percent said they were confident their Supplier Performance Risk System (SPRS) score would hold up under review. But Kiteworks also asked whether contractors could back that claim with documented evidence. Only 29% had both a current SPRS submission and a FedRAMP-authorized platform for handling Controlled Unclassified Information. The other 71% were confident without the evidence to support that confidence.

CyberSheath's fifth annual State of the Defense Industrial Base report, drawn from 302 contractors surveyed in May 2026, found a parallel picture that had been building for years. Average SPRS scores reached a five-year high of +51 (out of a possible 110). Confidence that those scores were accurate dropped sharply: 65% called themselves extremely or very confident, down from 89% in 2025 and 94% in 2024. Only 1% considered themselves completely prepared for formal CMMC certification.

The Suspension That Did Not Stop the Clock

The Pentagon's July 2026 suspension of CMMC Phase 2 third-party assessments removed the near-term pressure of external audits. It did not change the underlying legal framework.

DFARS clause 252.204-7021 requires defense contractors to self-attest their cybersecurity posture through SPRS as a condition of contract eligibility. That clause was not suspended. The requirement to submit an accurate SPRS score before bidding on covered DoD contracts remains in effect.

Nearly half of respondents in the Kiteworks survey did not know this. They believed Phase 1 self-assessment obligations had also been paused. They had not. And their contracts contain attestations that predate the suspension and may not accurately reflect their current security posture.

The Kiteworks finding that stands out: 84% of contractors said they were concerned about False Claims Act liability tied to an inaccurate SPRS score. And 92% had already brought in legal or compliance review. These are not organizations that are unaware of the risk. They are organizations that are aware of the risk and uncertain whether their attestation would survive scrutiny.

What False Claims Act Liability Actually Means Here

The False Claims Act (31 U.S.C. § 3729) imposes civil liability of up to three times actual damages plus civil penalties on any person who knowingly submits a false claim to the federal government. In the CMMC context, a contractor that attests CMMC compliance in SPRS while not actually implementing the required practices is submitting a false claim for each contract payment received under that attestation.

The Department of Justice has been pursuing FCA cases against defense contractors for cybersecurity misrepresentations since at least 2022. The first major settlement under this enforcement theory was in 2021, when Aerojet Rocketdyne paid $9 million after a former employee filed a qui tam complaint alleging the company misrepresented its cybersecurity compliance on government contracts.

The suspension of CMMC Phase 2 assessments does not reduce this exposure. It may increase it. Without a third-party assessor validating contractor SPRS scores, the gap between claimed compliance and actual security posture is wider and less visible. The enforcement mechanism that remains active is the Department of Justice, acting on qui tam complaints from employees with direct knowledge of the gap.

The survey data makes clear that a significant portion of the defense industrial base is in a position where their SPRS attestation does not reflect their actual security posture. Fifty-five percent of contractors are now bidding on work they previously avoided due to CMMC Level 2 requirements, suggesting that the suspension is being read as lowering the bar. It has not.

Where the Actual Security Gaps Are

CyberSheath's survey provides visibility into which security controls are most commonly missing. The adoption rates among surveyed defense contractors reveal the specific gaps that drive the distance between SPRS scores and actual CMMC readiness:

Multi-factor authentication has the highest adoption at 63%. That means 37% of defense contractors handling CUI do not have MFA in place, despite it being one of the most basic NIST SP 800-171 requirements. Secure backup stands at 48%. Data-loss prevention and vulnerability management are both at 44%. Endpoint detection and response is at 40%.

These are not advanced security capabilities. They are foundational controls that CMMC Level 2 requires. An organization that does not have EDR deployed cannot truthfully attest to Practice AC.L2-3.1.1 through Practice IR.L2-3.6.2 without significant caveats. An organization without MFA cannot honestly claim compliance with IA.L2-3.5.3.

The average annual compliance budget of $155,000, which 53% of contractors describe as "just right," reflects a fundamental mismatch. Building a credible CMMC Level 2 program with an enclave approach, documented policies, and implemented technical controls typically costs substantially more for organizations of any meaningful size. The satisfaction with a $155,000 budget is consistent with a compliance program focused on documentation rather than actual implementation.

The Confidence Problem Is a Measurement Problem

The 96% vs. 29% gap is not primarily a security problem. It is a measurement problem. Contractors that cannot verify their own compliance posture with documented evidence are relying on confidence built from incomplete self-assessment. The Kiteworks data points to what that looks like in practice: contractors who call themselves "very confident" in their understanding of CMMC requirements score no better on a factual test of those requirements than contractors who call themselves only "somewhat confident."

Self-assessment without objective evidence tends to drift toward optimism over time. Annual reviews built around questionnaires rather than control validation allow gaps to accumulate between assessment cycles without triggering a score adjustment. CMMC was designed to break this pattern through mandatory third-party certification. The suspension of Phase 2 has temporarily restored the conditions that CMMC was supposed to eliminate.

What CISOs and Compliance Teams Should Do Now

Run an honest internal gap assessment against NIST SP 800-171. Not against the SPRS score. Against the 110 practices. For each practice, ask whether you can produce objective evidence of implementation: configuration records, audit logs, policy documentation with last-review dates, and test results. If you cannot produce the evidence, the practice is not implemented for CMMC purposes regardless of what your SPRS score says.

Engage legal counsel before the next contract renewal. If your SPRS score includes practices that your gap assessment reveals are not fully implemented, you need legal advice on how to handle the attestation before submitting a new bid. The FCA exposure attaches to each contract payment, not just the initial bid. Getting ahead of this before renewal is significantly less costly than responding to a qui tam complaint.

Address the three most common gaps first. MFA at 63% adoption, EDR at 40%, and secure backup at 48% are the controls where the defense industrial base shows the most systematic weakness. These are also the controls that a DoJ investigator would check first and that a qui tam plaintiff would most likely have direct evidence about. Closing these three gaps closes the highest-probability legal exposure.

Build your SPRS score from evidence, not from memory. For each practice you claim in SPRS, maintain a file with the objective evidence that would satisfy a C3PAO assessor: configuration screenshots, policy documents, training records, audit logs. If Phase 2 assessments return in a modified form (58% of survey respondents expect this), that evidence base is what determines whether you pass. Building it after the assessor arrives is too late.

Educate your team on what the suspension did and did not change. Nearly half of contractors surveyed did not know Phase 1 obligations continued. If your procurement, legal, and technical teams have the same misunderstanding, decisions about contract bids, SPRS submissions, and security investments are being made on faulty assumptions. A brief internal briefing from counsel on the actual state of DFARS obligations is worth the time.

Asaf's Take

The gap between 96% and 29% is a picture I have seen in other compliance frameworks, but rarely this stark. When you remove the external verification mechanism, self-assessment scores rise and actual readiness falls. The CMMC Phase 2 suspension did exactly what removing external audit pressure always does: it allowed the natural human tendency toward optimistic self-reporting to run unchecked. The contractors in these surveys are not lying. Most of them genuinely believe their attestations are accurate. That is what makes the FCA exposure so dangerous. The government does not need to prove intent to deceive under the FCA's reckless disregard standard. It needs to show that the contractor submitted a false claim without adequate care to determine whether the claim was true. A confidence level of 96% combined with an evidence base that supports 29% is a textbook example of reckless disregard. CISOs at defense contractors should be treating this moment, while the auditors are absent, as the time to build the evidence base that will either survive a review or inform an accurate score adjustment before one arrives.

If your CMMC attestation were reviewed under the False Claims Act tomorrow, would the evidence support your SPRS score?

Assess Your CMMC Compliance Posture

Sources

  • Kiteworks: "2026 CMMC 2.0 Defense Industrial Base Readiness Report" (August 2026), kiteworks.com
  • CyberSheath and Merrill Research: "2026 State of the DIB Report" (August 2026), cybersheath.com
  • SecurityWeek: "Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind" (August 2026)
  • US Department of Defense: DFARS Clause 252.204-7021 (Cybersecurity Maturity Model Certification)
  • US Department of Justice: Civil Cyber-Fraud Initiative, first enforcement case Aerojet Rocketdyne (2022)
  • False Claims Act, 31 U.S.C. § 3729
  • NIST Special Publication 800-171, Rev. 2: Protecting Controlled Unclassified Information

Frequently Asked Questions

What is CMMC and who must comply?

CMMC is the US Department of Defense framework for cybersecurity requirements in the defense industrial base. Under DFARS clause 252.204-7021, contractors must meet specific CMMC levels to bid on DoD contracts. Level 2, which covers the 110 practices from NIST SP 800-171, applies to organizations that handle Controlled Unclassified Information. Compliance is a contract eligibility requirement, not a best-practice recommendation.

What happened with the CMMC Phase 2 suspension?

The Pentagon suspended CMMC Phase 2 third-party assessments in July 2026, removing the near-term requirement for contractors to obtain independent certification from a C3PAO. The underlying DFARS obligation to self-attest cybersecurity posture through SPRS was not suspended. Contractors must still submit accurate SPRS scores, and false attestations remain subject to False Claims Act liability.

What is the False Claims Act risk for defense contractors?

The False Claims Act (31 U.S.C. § 3729) imposes civil liability of up to three times actual damages plus civil penalties for knowingly submitting false claims to the federal government. A contractor that attests CMMC compliance in SPRS while not implementing required security practices may be submitting a false claim for each contract payment received. The DoJ has been pursuing FCA cases against defense contractors for cybersecurity misrepresentations since 2021.

What does the 96% vs. 29% gap mean in practice?

The gap reflects the difference between confidence in self-assessed compliance and the ability to produce documented evidence of that compliance. Contractors who claim CMMC readiness but cannot back it with a current SPRS submission and a FedRAMP-authorized environment for CUI handling are potentially submitting inaccurate attestations on DoD contracts. The practical risk is False Claims Act liability if that gap is identified by a qui tam plaintiff or DoJ investigation.

What should CISOs do to close the CMMC readiness gap?

The priority is an honest internal gap assessment against the 110 NIST SP 800-171 practices, with objective evidence for each claimed implementation. Organizations should engage legal counsel to review DFARS attestations before the next contract renewal. The highest-probability gaps to close are MFA (only 63% adoption in the DIB), EDR (40%), and secure backup (48%), which are both foundational requirements and the controls most likely to be examined in an enforcement action.