Defense Contractors Report Higher Cybersecurity Scores Amid Plummeting Confidence in Accuracy

  • Average Supplier Performance Risk System (SPRS) scores for defense contractors rose to +51 in 2026, up from +33 in 2025.
  • Confidence in the accuracy of these scores dropped 24 percentage points to 65%, from 89% in 2025.
  • Only 1% of contractors believe they are completely prepared for CMMC certification.
  • DFARS compliance budgets increased sharply to an average of $155,204 annually, with 53% of contractors feeling their budgets are 'just right'.
  • Adoption of core cybersecurity technologies like multi-factor authentication (63%) and secure backup (48%) continued to rise.

The rising SPRS scores amid declining confidence highlight a critical tension in the defense industrial base: contractors are investing more in cybersecurity, but the effectiveness and verifiability of these investments remain uncertain. This dynamic is exacerbated by the Pentagon's pause on third-party CMMC verification, leaving contractors to self-attest their compliance. The broader industry trend points to a need for more objective, verifiable assurance mechanisms to ensure reported compliance reflects operational cybersecurity.

Regulatory Uncertainty
How the Pentagon's pause on third-party CMMC verification will impact long-term compliance and security standards.
Budget Efficiency
Whether increased DFARS compliance budgets will translate into more effective and sustainable cybersecurity measures.
Confidence Gap
The pace at which the disconnect between reported cybersecurity progress and contractor confidence will affect contract awards and national security.