Post-CMMC Suspension, More Feel Confident ... Less Can Back It Up

The most dangerous misreading is that the rules relaxed. They did not.

Protection Background Technology Security 524882074 701x502 (1)

On July 13, 2026, the Department of War suspended Phase II third-party assessments under CMMC 2.0. The defense industrial base moved fast. In a Kiteworks survey of organizations fielded in the two weeks that followed, and published in the new report State of CMMC 2.0 in the DIB, 98 percent had already taken at least one concrete action. Only two percent did nothing.

That is a workforce paying attention. It is not, however, a workforce that can prove much. And in a False Claims Act environment, the gap between action and proof is where careers and companies get lost.

Here is the finding that should stop every defense CISO cold: 96 percent of respondents said they were confident their self-attested SPRS score would hold up under review. Of that confident majority, 60 percent had a current SPRS submission on file. Another 36 percent were running on a FedRAMP-authorized platform, but just 29 percent had both. 

Fewer than three in 10 contractors who feel confident can fully back that feeling with the two things a reviewer will ask for first.

I have spent enough time inside compliance programs to recognize the pattern. Confidence is not evidence. It rarely correlates with it. When we scored the same 273 organizations on both current compliance and post-suspension behavior, then combined the two, the composite readiness index landed at 60.0 out of 100 – well below the roughly 77 you would get by averaging the parts. 

Multiplying instead of averaging matters, because a contractor who has done the work but cannot document it is not partly ready. They are exposed.

Exposed is not a rhetorical flourish here. It is the largest segment. Sort the DIB into four quadrants by what they have completed and what they have sustained since the suspension, and 31 percent fall into the Exposed quadrant – confident, active, but unable to produce current evidence on demand. Only two percent score a clean sweep across both dimensions. The rest sit somewhere in the middle, doing things, generating little they could hand to an auditor.

The Suspension Changed the Calendar, Not the Obligation

The most dangerous misreading of July 13 is that the rules relaxed. They did not. The suspension paused one thing: the third-party assessment. DFARS 252.204-7012 still binds. NIST SP 800-171 still defines the controls. Phase 1 self-assessment continues. The SPRS submission is still required, and it is still a representation to the federal government.

That last point is the one that carries teeth. A self-attested score is a claim. Under the False Claims Act, a knowingly inflated claim is actionable, and the Department of Justice’s Civil Cyber-Fraud Initiative exists to pursue exactly that. The assessor going quiet does not make the attestation go away. If anything, it removes the third party who would have caught the error before it became a liability.

Contractors sense this, as 84percent said they were concerned about FCA exposure, and 92 percent had engaged legal or compliance review since the suspension. That is the right instinct. But legal review is not a substitute for evidence, and the survey shows the industry knows it. 

Asked what would most increase their confidence, 47 percent named an audit trail and 36 percent named FedRAMP authorization. Only 11 percent pointed to legal review alone. The market is telling us that lawyers cannot manufacture a control record after the fact.

There is a knowledge problem underneath the confidence problem. Only three percent of respondents believed all CMMC requirements were paused, so the headline understanding is sound. Dig one layer down and it frays: 48 percent did not know that Phase 1 self-assessment obligations continue. 

On a short knowledge test, respondents who called themselves “very confident” averaged 2.48 out of 4 – statistically indistinguishable from those who were merely “somewhat confident,” and nearly half of the very confident scored below 3 out of 4. Certainty and competence had come unbundled.

Why the Current Posture Fails

Step back and the DIB gap fits a broader pattern that should worry anyone in a regulated supply chain. Verizon’s 2026 Data Breach Investigations Report found that breaches involving a third party grew 60 percent year over year, now reaching 48 percent of all breaches. 

IBM’s Cost of a Data Breach Report 2026 put supply-chain compromise as the single largest cost-increasing factor at $227,250 per incident, with regulatory noncompliance adding another $201,112. The World Economic Forum’s Global Cybersecurity Outlook 2026 reported that 65 percent of large organizations now rank third-party and supply-chain risk as their greatest challenge to cyber resilience.

Defense contractors are the third party in someone else’s risk model. Flow-down makes that literal: 86 percent of respondents were concerned about CMMC requirements cascading down their subcontractor tiers, rising to 92 percent among Tier 1 subs. A prime’s attestation is only as sound as the weakest supplier feeding its programs. When most of those suppliers cannot produce current evidence, the whole chain inherits the exposure.

The failure mode is not effort. It is architecture. Compliance treated as a periodic project produces a binder that is stale the day after it is signed. Compliance treated as a byproduct of how sensitive data moves produces evidence continuously, without a scramble before each review.

The Two-Track Path Forward

The organizations that will survive the next assessment cycle are running two tracks at once, not choosing between them.

The first track is evidence generation. Every transfer of controlled unclassified information should leave an audit-ready record as a matter of course – who touched the data, under what policy, to what destination. This is where architecture earns its keep. 

Platforms built for CMMC Level 2 workloads, such as the Kiteworks Control Plane operating on a single-tenant, FedRAMP High In Process and FedRAMP Moderate Authorized foundation, turn everyday data exchange into the documentation an assessor expects, rather than a report someone has to reconstruct under deadline.

The second track is independent validation. The C3PAO assessment is coming back in some form – 58 percent of respondents expect Phase II to return modified, and only four percent think it disappears. However, 93 percent already consider independent third-party authorization essential or important to how they select vendors. The contractors continuing their scheduled assessments voluntarily, even with the requirement paused, are the ones who understand that self-attestation and independent verification are not interchangeable.

The suspension bought the DIB time. It did not buy anyone an excuse. Confidence was never the deliverable. Proof is. The contractors who close that gap now will be the ones still bidding when the assessors come back – and they will be able to show exactly why they belong there.

Frank Balonis is the Field CISO at Kiteworks.

More in Cybersecurity