CMMC's paradox: Scores are up, but confidence is down

Gettyimages.com / Yuichiro Chino
As the cyber standard's third-party assessments are on pause, new research shows contractors’ self-reported scores are climbing even as their confidence in those ratings is sliding fast.
The government has decided to pause third-party assessments of how defense contractors protect controlled but unclassified information, so the quality of the current self-assessment regime remains an important line of defense against cyber risks.
In a bit of good news-bad news, a new study by Merrill Research and commissioned by CyberSheath found that contractors self-reported cybersecurity scores are rising but at the same time their confidence in the accuracy of those scores declined significantly.
The assessment program is the heart of the Cybersecurity Maturity Model Certification program, which the Defense Department has been working toward for nearly a decade. DOD initiated the pause in July to consider the impact on small business and whether CMMC was imposing an undue regulatory burden.
The research found that the average Supplier Performance Risk System score rose to a five-year high of +51, up from +33 in 2025.
2025 was also the first year where a positive score was reported. A perfect NIST SP 800-171 score is 110.
While the average scores rose, confidence fell with only 65% of respondents saying they were extremely or very confident that their scores were accurate. Last year, the rate stood at 89%.
At the same time, only 1% said they believed they were completely prepared for CMMC certification. That is the same figure from the 2025 study.
“Most contractors are manufacturers, engineers, and specialized businesses whose mission is supporting the warfighter, not becoming cybersecurity experts,” said Emil Sayegh, CEO of CyberSheath.
CMMC reform should focus on making effective cybersecurity easier to consume while “preserving objective, verifiable assurance that protections are actually in place and working,” he said.
Verification and accountability are critical to ensuring reported compliance reflects operational cybersecurity, Sayegh said.