Defence Contractors Say They Feel Ready for the Pentagon's New Security Rules, But Can't Actually Prove It

Two new surveys find that American defence suppliers are more confident than ever about meeting the Pentagon's cybersecurity standard, while their ability to demonstrate that confidence on paper is getting worse, not better.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Two industry surveys published this week found rising self-reported confidence among US defence contractors about meeting the Pentagon's CMMC cybersecurity standard.
  • At the same time, both surveys found that contractors' ability to document and prove that readiness has fallen further behind.
  • CMMC, short for Cybersecurity Maturity Model Certification, is a set of security rules the US Department of Defense requires companies in its supply chain to meet before winning contracts.
  • The surveys were conducted independently by security firms Kiteworks and CyberSheath, and both reached strikingly similar conclusions.
  • Ordinary workers at defence suppliers could be affected if their employers lose contracts or face audits due to compliance gaps.

Feel confident. Can't show your work. That gap, according to two surveys released this week, is now the defining problem for the companies that build and supply America's military.

The surveys, from security firms Kiteworks and CyberSheath, both looked at how well US defence contractors are keeping up with CMMC, which stands for Cybersecurity Maturity Model Certification. Think of CMMC as a report card the Pentagon hands out to the thousands of private companies that supply it with everything from software to aircraft parts. To keep winning government contracts, those companies must prove they meet a long checklist of cybersecurity practices: things like encrypting sensitive files, controlling who can access certain systems, and keeping detailed records of security activity.

So what's the actual problem?

Contractors feel more prepared than they did a year ago. The trouble is that feeling and proof are two different things.

Both surveys found that the share of contractors who believe they are ready for a CMMC audit has climbed. Good news, on the face of it. But dig a little deeper and the same surveys show that fewer companies can actually produce the written evidence an auditor would demand: policies, logs, test results, the paperwork trail that turns a feeling of readiness into a passing grade.

This is a pattern security professionals have a name for: the confidence-competence gap. A company tightens a few obvious controls, feels better, and stops there. The harder, less visible work of documenting every step gets pushed aside.

The analogy isn't subtle. It's a bit like a restaurant that cleans the dining room before a health inspection but hasn't touched the kitchen in months. The staff feel ready. The inspector sees something different.

SecurityWeek flagged the dual-survey findings as notable precisely because the two companies arrived at the same conclusion independently.

What does this mean for people who work at these companies?

For employees at defence suppliers, a compliance failure is not abstract. Companies that cannot pass a CMMC audit risk losing their Pentagon contracts entirely. That means possible layoffs, restructuring, or a scramble to bring in expensive outside consultants under deadline pressure.

For the broader public, the concern is what gaps in contractor cybersecurity could mean for sensitive government data. CMMC exists because defence suppliers have historically been a soft target: attackers who cannot break into the Pentagon directly go after the smaller companies in its supply chain instead.

Common questions

What exactly is CMMC and who has to follow it?

What exactly is CMMC and who has to follow it?

CMMC is the Pentagon's cybersecurity rulebook for its private-sector suppliers. Any company that handles certain government information and wants a Department of Defense contract must meet its requirements, which are verified by independent auditors.

Does this affect me if I'm not in the defence industry?

Not directly. But the core lesson, that self-assessed readiness and documented, auditable readiness are very different things, applies to almost any organisation handling sensitive data.

© 2026 Threat Vectr