State of CMMC 2.0 in the DIB: What 273 Defense Contractors Reveal About Compliance After the Assessment Pause
The pause of third-party CMMC assessments did not lower the compliance bar for a single defense contractor. It only made the gap between what contractors say and what they can prove harder to see. That gap is now the most important risk in the Defense Industrial Base, and a new survey of 273 organizations puts hard numbers on it.
Days after the July 13, 2026 Department of War (DoW) suspension of CMMC 2.0 Phase II third-party assessments, we fielded one of the first post-suspension reads of the market. Every respondent was a confirmed DoW business with an active CMMC 2.0 requirement. The findings, captured in the “State of CMMC 2.0 in the DIB” report, describe a base that is moving fast, spending money, and, in too many cases, mistaking motion for readiness.
The headline is not apathy. Fully 98% of contractors took at least one concrete action after the suspension; only 2% did nothing. The problem is direction. When you separate what an organization has built from how it is behaving, the picture splits in two. A large share of the base is scrambling or exposed, and a striking number of the least-prepared firms remain the most confident. For anyone who handles CUI or bids on defense work, that combination is where audits, disqualifications, and False Claims Act settlements come from.
Kiteworks built its secure data exchange platform for this exact problem: proving, with evidence, that sensitive data moved the way regulators require. This post walks through the report’s core findings and what they mean for CMMC 2.0 compliance planning over the next two quarters.
Key Takeaways
1. The suspension paused assessments, not obligations.
DFARS 252.204-7012, NIST SP 800-171, the Phase 1 self-assessment, and SPRS reporting all remain in force, and the False Claims Act still applies to every attestation a contractor has already made.
2. Confidence outruns evidence across the base.
While 96% of contractors are confident their SPRS score would hold up under scrutiny, only 29% have both a current SPRS submission and a FedRAMP-authorized platform to back it. Fewer than three in ten can fully support the claim they are making.
3. Movement is not the same as readiness.
A compliance-signaling index that multiplies current posture by recent behavior lands at a mean of 60.0, far below the roughly 77 a simple average would show. Only 2% of contractors scored a perfect result on both dimensions.
4. Enforcement is already live and does not need a whistleblower.
A June 2026 Department of Justice settlement of $507,144 shows how a routine government audit can turn a self-attested SPRS score into a fraud claim when the real posture is far lower than reported.
5. The market is repricing itself around proof.
More than half of contractors are now bidding solicitations they once avoided, more than half have withdrawn from a bid over readiness, and 89% are using or plan to adopt a FedRAMP-authorized platform within six months.
The Suspension Paused Assessments, Not the Rules
The most damaging misreading of the July 13 announcement is that CMMC went away. It did not. The suspension halted Phase II third-party assessments, the certification step where a C3PAO validates an organization’s controls. Everything upstream of that step is untouched.
DFARS clause 252.204-7012 still requires contractors to safeguard covered defense information and report cyber incidents. NIST 800-171 still defines the 110 controls that protect CUI. The Phase 1 self-assessment obligation continues, and contractors must still post and maintain a current score in the Supplier Performance Risk System. Most consequentially, the False Claims Act still governs the accuracy of every score already submitted. A pause on assessments is not a pause on liability.
Contractors mostly understand the legal exposure, even when they misunderstand the mechanics. In the survey, 84% said they were concerned about False Claims Act exposure, and 92% had engaged legal or compliance review since the suspension. That is the right instinct. The disconnect shows up in what firms lean on for confidence. When asked what most supports their position, 47% pointed to an audit trail, 36% to a FedRAMP-authorized platform, and only 11% to legal review. Documentation is doing the reassuring; verification often is not.
CMMC 2.0 Compliance Roadmap for DoD Contractors
Movement Is Not Readiness: Inside the Compliance-Signaling Index
To separate posture from performance, the report built two indices. The Current Compliance Maturity Score (CCMS) measures where an organization stands today across eight indicators of implemented controls. It came in at a mean of 78.2 out of 100, respectable on its face. The Signal-to-Governance Score (SGS) measures active behavior since July 13 across eight indicators, and it landed at 74.9. Read separately, both look healthy.
The insight comes from how they combine. Instead of averaging the two, the report multiplies them into a Compliance-Signaling Readiness Index (CSRI = CCMS × SGS/100). Multiplication is the honest operation here, because weakness in either dimension undercuts the whole. A firm with strong controls but no recent action is not ready, and neither is a firm that is busy but built on a shaky foundation. The result is a mean CSRI of 60.0 with a median of 65.6. A simple average of the two component scores would have produced roughly 77, a number that flatters the base and hides the interaction between posture and behavior.
Sort contractors into quadrants using a demanding 7-of-8 threshold on each dimension and the split becomes concrete. Only 23% are Audit-Ready, strong on both current posture and recent behavior. Another 28% are Coasting, solid controls but little movement since the suspension. Eighteen percent are Scrambling, acting hard but from a weak base. The largest group, 31%, is Exposed: weak on both counts. Just 2% earned a perfect 8-of-8 on both dimensions. The typical contractor is not audit-ready; the typical contractor is one audit away from a bad week.
The Confidence-Evidence Cascade
Nowhere is the say-do gap clearer than in what the report calls the confidence-evidence cascade. Start with belief and watch it drain as you add each requirement for proof.
Ninety-six percent of contractors are confident their SPRS score would hold up under scrutiny. Ask who holds a current SPRS submission on file and the number falls to 60%. Add the requirement to run sensitive data on a FedRAMP-authorized platform and it drops to 36%. Require both a current submission and the authorized platform, and only 29% qualify. Fewer than three in ten contractors can fully back the score they are so confident about.
This is not a rounding error. It is a 67-point gap between stated confidence and demonstrable evidence, and it is exactly the space an auditor, a contracting officer, or a Department of Justice attorney operates in. Confidence does not survive contact with a document request. Evidence does. The contractors who close this gap are the ones who can produce a complete audit trail on demand, who touched which piece of CUI, when, from where, and under what policy, rather than an attestation that rests on memory. This is the core reason a system security plan needs a live evidence layer underneath it, not a static document.
Enforcement Is Already Here: A $507,144 Settlement
If the cascade sounds theoretical, one recent case makes it concrete. On June 18, 2026, the Department of Justice settled a False Claims Act matter with LOGZONE Inc. of Huntsville, Alabama for $507,144 over two Navy contracts. The company had self-attested an SPRS score of 110, a perfect mark. When DIBCAC ran an independent assessment, the real score came back at negative 170. The gap between the claim and the reality was the case.
Two details deserve attention. First, the matter surfaced through a routine government audit, not a whistleblower. The False Claims Act qui tam provisions get most of the coverage, but this settlement shows the government does not need an insider to find an inflated score, it needs a spreadsheet and an assessor. Second, the enforcement ran through the DOJ Civil Cyber-Fraud Initiative, the mechanism built specifically to hold contractors accountable for cybersecurity misrepresentations. The suspension of assessments did nothing to slow that initiative down.
The lesson for the 96% who are confident is direct. A self-attested score is a legal statement, and the distance between an optimistic self-assessment and an independent one is measured in dollars. Organizations that treat SPRS scoring as a documentation exercise rather than an evidence-backed claim are carrying that same risk whether they know it or not. Getting the POA&M and the underlying controls right is cheaper than settling.
The Knowledge Illusion Behind the Confidence
Why are so many contractors confident about a position they cannot fully support? The report points to a knowledge illusion, confidence built on an incomplete understanding of what the suspension changed.
The good news is that very few contractors think the whole framework stopped: only 3% believe all requirements are paused. The bad news is in the details that matter. Forty-eight percent do not know that the Phase 1 self-assessment continues. Fifty-seven percent do not know that select government-led assessments continue. These are not obscure footnotes; they are the obligations most likely to generate an enforcement action in the current window.
The most revealing finding is what confidence does not predict. On a four-point knowledge test, contractors who described themselves as “very confident” averaged 2.48 out of 4, identical to the score of those who were only “somewhat confident,” also 2.48. Confidence and knowledge were completely decoupled. Nearly half of the very confident group, 49%, scored below 3 out of 4. High certainty is not tracking high understanding, which is the precise condition under which organizations sign attestations they should not. Closing that gap starts with treating CMMC 2.0 compliance as an ongoing program, not a certification milestone that got postponed.
The Market Is Repricing Around Proof
While compliance teams sort out obligations, the business side is already moving. The suspension reshaped bidding behavior across the base, and the direction is toward proof as a competitive weapon.
More than half of contractors, 55%, are now bidding on solicitations they previously avoided, treating the pause as an opening. At the same time, 52% have withdrawn from a bid because they could not meet the readiness bar, and 38% have lost work or been disqualified over a Level 2 requirement. The pattern is not evenly distributed. Tier 2 and deeper subcontractors lose bids at a 55% rate, nearly double the 31% rate primes report. The further you sit from the prime relationship, the harder the market judges your ability to prove CMMC Level 2 posture. Aerospace and defense firms are the most insulated, with only a 16% loss rate. Those firms tend to carry deeper compliance investment and tighter customer relationships.
That subcontractor exposure is why flow-down anxiety is so high. Concern about contractual flow-down requirements reached 86% across the base, climbing to 92% among Tier 1 subcontractors and 89% among Tier 2 and deeper, versus 79% for primes. Flow-down is how a prime’s supply chain risk management obligation becomes every subcontractor’s problem, and the smaller firms feel it most. External data reinforces the stakes: the Verizon 2026 Data Breach Investigations Report found third-party breaches grew 60% year over year to 48% of all breaches, and the World Economic Forum’s Global Cybersecurity Outlook 2026 reported that 65% of large organizations now rank third-party and supply-chain risk as their top challenge, up from 54%.
Demand Is Consolidating Around Independent Authorization
If proof is the new currency, contractors are voting with their budgets for the strongest available form of it: independent, third-party authorization. This is the clearest forward-looking signal in the data.
Eighty-nine percent of contractors are using or plan to adopt a FedRAMP-authorized platform within six months. Ninety-three percent say independent third-party authorization is essential or important, a rejection of self-attestation as a sufficient basis for handling CUI. And 96% have engaged a C3PAO, with 32% saying they will continue voluntarily even though assessments are paused. Contractors are not waiting for the government to restart the clock; they are building the evidence now.
They are also engaging the policy process. Ninety-three percent plan to comment on the DoW’s Request for Information, which closed August 14, 2026. Expectations skew toward return rather than repeal: 58% expect Phase II to come back in modified form, and only 4% think it disappears entirely. Meanwhile, 70% have achieved or expect within six months to achieve full compliance readiness, an ambitious target given that only 23% are Audit-Ready today, and a reminder that the gap between intention and demonstrated readiness is the theme of this entire report. The organizations that get there will be the ones who treat NIST 800-171 compliance as a running system rather than a one-time push.
Not Every Contractor Faces the Same Risk
The base is not monolithic, and the CSRI makes the differences visible. By industry, aerospace and defense leads with a readiness index of 66.2, followed by IT and cloud services at 61.9, telecommunications at 59.3, and all other sectors trailing at 52.2. The firms closest to the mission are, unsurprisingly, the most prepared to prove it.
The sharper divide is geographic. North American contractors (n=163) posted a CSRI of 64.7, while European contractors (n=104) came in at 53.9. Europe is the most exposed segment in the study: 44% fall into the Exposed quadrant and only 15% are Audit-Ready. On the concrete evidence measures, just 43% of European contractors have a current SPRS submission, versus 70% in North America, yet 94% of European respondents remain confident. That is the confidence-evidence gap in its most extreme form, and it is a warning to primes with cross-border supply chains. A subcontractor’s data sovereignty posture and its CMMC readiness are not the same thing, and the survey shows the overseas segment of the base needs the most attention.
What This Means for How You Handle CUI
The through-line across every finding is that attestation without evidence is a liability, and the fix is an evidence-generating system for sensitive data. The cost of getting it wrong is not abstract. The IBM Cost of a Data Breach 2026 report identified supply-chain compromise as the top cost-amplifying factor at $227,250 per breach, with noncompliance adding another $201,112, against a global average breach cost of $4.99 million. For a defense contractor, a compliance failure and a breach are often the same event.
This is where the Kiteworks secure data exchange platform fits the problem. Kiteworks runs on a single-tenant architecture, supports CMMC Level 2, and is FedRAMP High In Process and FedRAMP Moderate Authorized. Every file, email, form, and transfer that carries CUI moves through one governed layer, the Kiteworks Control Plane, that records who accessed what, when, and under which policy. That is the difference between telling an auditor your SPRS score is defensible and showing them the audit logs that prove it. The 47% of contractors leaning on an audit trail for confidence are directionally right; the platform they run it on determines whether that trail holds up.
Practical steps follow from the data. Reconcile your self-attested SPRS score against what an independent assessor would find, the way that Alabama contractor did not. Consolidate CUI onto a FedRAMP-authorized platform so the 36% evidence tier becomes your baseline rather than your ceiling. Extend readiness expectations down your subcontractor tiers, where the DIB is weakest. And treat the assessment pause as the time to build proof, not the excuse to stop. The contractors who read the suspension correctly are the ones who will be ready when Phase II returns.
The “State of CMMC 2.0 in the DIB” report goes deeper on the indices, the quadrant model, the segment breakdowns, and the enforcement outlook than any summary can. To see the full data set and where your organization stands against 273 of your peers, download and read the full report.
Frequently Asked Questions
No. The suspension halted Phase II third-party assessments only. DFARS 252.204-7012, the NIST 800-171 control set, the Phase 1 self-assessment requirement, and SPRS score reporting all remain in force. The False Claims Act continues to govern the accuracy of any attestation a contractor has already submitted, so the legal exposure did not pause with the assessments. Contractors should treat this window as time to strengthen evidence, and a CMMC compliance checklist is a practical way to confirm nothing has lapsed.
It is the distance between how confident contractors feel and what they can prove. In the survey, 96% were confident their SPRS score would hold up, but only 29% had both a current SPRS submission and a FedRAMP-authorized platform to support it. That gap is where enforcement actions live, because auditors and Department of Justice attorneys evaluate evidence, not confidence. Closing it means building a live audit trail rather than relying on documentation that rests on memory.
The Department of Justice’s June 2026 settlement with an Alabama defense contractor, $507,144 over a self-attested SPRS score of 110 that an independent DIBCAC assessment scored at negative 170, shows that inflated self-assessments carry real financial and legal risk. Critically, the case surfaced through a routine government audit with no whistleblower, and it ran through the DOJ Civil Cyber-Fraud Initiative. That initiative continued straight through the assessment suspension. Contractors should reconcile their SPRS scores against what an independent assessor would find, before the government does it for them.
The market is judging the ability to prove readiness, and that judgment falls hardest on firms furthest from the prime relationship. Tier 2 and deeper subcontractors lose bids at a 55% rate, nearly double the 31% rate primes report, and flow-down concern climbs to 92% among Tier 1 subcontractors. Primes push their supply chain risk management obligations down through contractual flow-down, so a smaller firm inherits the same evidence burden with fewer resources. Consolidating CUI handling onto a CMMC Level 2-capable platform is one of the fastest ways for a subcontractor to close that gap.
Kiteworks unifies the exchange of sensitive data, file sharing, email, managed file transfer, and web forms, onto a single-tenant platform that supports CMMC Level 2 and is FedRAMP High In Process and FedRAMP Moderate Authorized. Every interaction with CUI generates audit-ready evidence through the Kiteworks Control Plane, so a contractor can show, not just assert, how sensitive data was governed. That capability turns an SPRS attestation from a hopeful statement into a defensible one. You can see how the platform maps to the framework through the CMMC 2.0 compliance resources and the broader FedRAMP compliance documentation.
Additional Resources
- Blog Post
CMMC Compliance for Small Businesses: Challenges and Solutions - Blog Post
CMMC Compliance Guide for DIB Suppliers - Blog Post
CMMC Audit Requirements: What Assessors Need to See When Gauging Your CMMC Readiness - Guide
CMMC 2.0 Compliance Mapping for Sensitive Content Communications - Blog Post
The True Cost of CMMC Compliance: What Defense Contractors Need to Budget For