AI Security AI安全 20h ago Updated 15h ago 更新于 15小时前 41

Contractors' CMMC Confidence Rises as Ability to Prove It Falls Behind 承包商对CMMC的信心上升,但证明能力却落后

Two major surveys reveal a stark confidence-evidence gap: 96% of defense contractors claim confidence in their SPRS scores, yet only 29% can substantiate that claim with current submissions and FedRAMP-authorized platforms The Pentagon's suspension of CMMC 2.0 Phase 2 third-party assessments has not eliminated legal exposure, with 84% of contractors concerned about False Claims Act liability for inaccurate self-attestations Combined compliance readiness scores fell to 60/100 when measured multip 两份行业调查显示国防承包商对网络安全合规的信心与实际证明能力之间存在显著差距,96%自信评分能经得起审查,但仅29%能提供有效证据 CMMC 2.0 Phase 2第三方评估暂停后,承包商仍面临《虚假索赔法》法律责任,84%担忧不准确评分的法律风险,92%已引入法律审查 市场已对门槛降低做出反应:55%承包商投标此前回避的项目,Tier 2及以下分包商投标损失率达55%,是主承包商的近两倍 SPRS平均分升至五年高点+51,但对评分准确性的信心从2024年的94%骤降至65%,仅1%认为自己完全准备好通过CMMC认证 行业强烈希望保留独立第三方验证机制(93%认为对供应商选择至关重要),同时要

62
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Two major surveys reveal a stark confidence-evidence gap: 96% of defense contractors claim confidence in their SPRS scores, yet only 29% can substantiate that claim with current submissions and FedRAMP-authorized platforms
  • The Pentagon's suspension of CMMC 2.0 Phase 2 third-party assessments has not eliminated legal exposure, with 84% of contractors concerned about False Claims Act liability for inaccurate self-attestations
  • Combined compliance readiness scores fell to 60/100 when measured multiplicatively, with nearly a third of respondents scoring low on both compliance maturity and suspension-response measures simultaneously
  • SPRS scores reached a five-year high of +51, but contractor confidence in score accuracy dropped sharply from 94% in 2024 to 65% in 2026, while only 1% feel completely prepared for CMMC certification
  • 93% of contractors want independent third-party verification to remain part of future vendor selection, and 90% want the government to mandate minimum cybersecurity standards across all federal contractors

Why It Matters

This article highlights a critical vulnerability in the defense industrial base: a growing disconnect between perceived compliance and verifiable security posture, which directly impacts national security readiness. For AI practitioners and security professionals operating in or with the defense sector, understanding this compliance landscape is essential for designing systems that meet both regulatory expectations and actual security requirements.

Technical Details

  • Kiteworks surveyed 273 defense contractors post-CMMC Phase 2 suspension, measuring compliance maturity and suspension-response readiness; the multiplicative scoring method (60/100) revealed a larger at-risk population than averaging would have shown
  • CyberSheath's 2026 State of the DIB Report surveyed 302 contractors pre-suspension, tracking SPRS score trends against a perfect score of 110, alongside technology adoption rates: MFA at 63%, secure backup at 48%, data-leakage protection and vulnerability management at 44%, and endpoint detection at 40%
  • Average annual DFARS compliance budgets rose to $155,000, with 53% of contractors considering this adequate and 24% viewing it as sufficient
  • The DFARS obligation to attest accurately remains in effect despite the CMMC Phase 2 pause, creating ongoing legal exposure under the False Claims Act
  • Tier 2 and lower subcontractors experienced bid losses at 55%, nearly double the 31% rate among prime contractors, indicating disproportionate impact on smaller supply chain participants

Industry Insight

  • The confidence-evidence gap represents a systemic risk: contractors may be over-attesting to compliance without the technical infrastructure to back it up, creating false assurance for the defense supply chain
  • The market is already adapting to the lowered compliance bar, with 55% of contractors bidding on previously avoided work, suggesting the suspension may inadvertently reduce overall security postures in the supply chain
  • Industry consensus strongly favors maintaining verification mechanisms; any CMMC reform should prioritize making compliance verifiable and achievable rather than removing third-party oversight entirely

TL;DR

  • 两份行业调查显示国防承包商对网络安全合规的信心与实际证明能力之间存在显著差距,96%自信评分能经得起审查,但仅29%能提供有效证据
  • CMMC 2.0 Phase 2第三方评估暂停后,承包商仍面临《虚假索赔法》法律责任,84%担忧不准确评分的法律风险,92%已引入法律审查
  • 市场已对门槛降低做出反应:55%承包商投标此前回避的项目,Tier 2及以下分包商投标损失率达55%,是主承包商的近两倍
  • SPRS平均分升至五年高点+51,但对评分准确性的信心从2024年的94%骤降至65%,仅1%认为自己完全准备好通过CMMC认证
  • 行业强烈希望保留独立第三方验证机制(93%认为对供应商选择至关重要),同时要求简化实施流程(74%)并增加供应商选择(70%)

为什么值得看

本文揭示了国防网络安全合规领域的"信心-证据鸿沟"现象,对理解政策暂停对行业实际影响具有重要参考价值。两份独立调查相互印证,为CMMC改革方向提供了行业视角的实证依据。

技术解析

  • Kiteworks调查覆盖273家国防承包商,采用乘法而非平均法合并两项准备度指标,得出综合得分60/100,显著低于简单平均的77分,近三分之一受访者在两项指标上同时得分较低
  • CyberSheath 2026年DIB报告显示平均年度DFARS合规预算升至15.5万美元,核心安全技术采用率:多因素认证63%、安全备份48%、数据防泄漏和漏洞管理44%、端点检测40%
  • 调查时间线显示CyberSheath数据收集于2026年5月(暂停前),Kiteworks调查于五角大楼7月暂停CMMC 2.0 Phase 2第三方评估后进行,两份报告形成前后对比
  • SPRS评分满分110分,平均分从2025年的+33升至+51,但"完全准备好认证"的比例连续两年维持在1%

行业启示

  • 政策暂停不等于义务暂停:DFARS准确证明义务持续有效,承包商需建立合规证据链而非仅依赖自我声明,建议加强内部合规审计与文档管理
  • 供应链合规风险呈级联效应:小型分包商承受不成比例的影响(投标损失率55% vs 31%),国防项目采购方应关注二级供应商的合规能力建设
  • 行业期望"简化但不降低标准"的改革路径:93%支持保留第三方验证,74%要求简化实施,未来CMMC改革需在可操作性和可验证性之间寻求平衡

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Regulation 监管 Policy 政策