Contractor SPRS Confidence Falls from 89% to 65% in One Year
More defense contractors are reporting SPRS scores than ever, but confidence in their accuracy has collapsed, undercutting the self-attestation model while CMMC phase two remains paused.
TL;DR
Per Inside Cybersecurity, CyberSheath's annual survey of 302 defense contractors found 88% now report a positive SPRS score, but only 65% are confident in their accuracy, down from 89% last year and 94% in 2024. Average annual cybersecurity spend hit $155,204, yet median self-assessed CMMC readiness sits at 70%. Just 1% of respondents say they're completely ready. CyberSheath, a managed security provider that sells CMMC compliance services, commissioned the survey conducted by Merrill Research.
The SPRS confidence collapse is the survey's most consequential finding. Contractors are doing the paperwork. Eighty-three percent now document system security plans, 76% maintain POA&Ms. But they're losing faith in the numbers they're submitting. That's a structural problem for a program built on self-attestation, and it lands at an awkward moment: CMMC phase two, which would introduce third-party assessments, has been paused since July 13 pending a Pentagon review.
CyberSheath positions the spending data as a counterweight to the SBA's July estimate of $593,800 per small-business certification for third-party assessment. The survey's $155,204 average annual spend isn't directly comparable. CyberSheath acknowledges the figures measure different things. But the firm argues the magnitude of difference is noteworthy. It's also in CyberSheath's commercial interest to argue the cost burden is lower than regulators claim, since the firm sells managed services aimed at making compliance cheaper.
The readiness numbers tell a harder story. Despite years of investment and a rising SPRS reporting rate, the median contractor says they're only 70% ready for certification. Thirty-two percent believe they've cleared 80% readiness. One percent are done. Those figures haven't translated into urgency for half the respondents: 59% want current security requirements kept as-is and 50% want enforcement levels unchanged. The same survey that documents a confidence crisis also documents a contractor base that isn't clamoring for weaker rules. They're asking for a path to meeting them that doesn't require a six-figure annual spend to get 70% of the way there.
Published ·Updated ·Deep Fathom