Defense Contractors Report Higher Cybersecurity Scores Amid Plummeting Confidence in Accuracy
Event summary
- Average Supplier Performance Risk System (SPRS) scores for defense contractors rose to +51 in 2026, up from +33 in 2025.
- Confidence in the accuracy of these scores dropped 24 percentage points to 65%, from 89% in 2025.
- Only 1% of contractors believe they are completely prepared for CMMC certification.
- DFARS compliance budgets increased sharply to an average of $155,204 annually, with 53% of contractors feeling their budgets are 'just right'.
- Adoption of core cybersecurity technologies like multi-factor authentication (63%) and secure backup (48%) continued to rise.
The big picture
The rising SPRS scores amid declining confidence highlight a critical tension in the defense industrial base: contractors are investing more in cybersecurity, but the effectiveness and verifiability of these investments remain uncertain. This dynamic is exacerbated by the Pentagon's pause on third-party CMMC verification, leaving contractors to self-attest their compliance. The broader industry trend points to a need for more objective, verifiable assurance mechanisms to ensure reported compliance reflects operational cybersecurity.
What we're watching
- Regulatory Uncertainty
- How the Pentagon's pause on third-party CMMC verification will impact long-term compliance and security standards.
- Budget Efficiency
- Whether increased DFARS compliance budgets will translate into more effective and sustainable cybersecurity measures.
- Confidence Gap
- The pace at which the disconnect between reported cybersecurity progress and contractor confidence will affect contract awards and national security.
Related topics
