HomeComplianceCMMC SPRS Score Confidence Is Falling While False Claims Act Exposure Persists

CMMC SPRS Score Confidence Is Falling While False Claims Act Exposure Persists

Two separate 2026 surveys of defense contractors show rising SPRS scores paired with falling confidence in their accuracy, the same year DoD suspended third-party review. Here is what the gap means for your own attestation.

CMMC SPRS Score Confidence Is Falling Even as Self-Reported Scores Rise

If your firm holds a CUI-touching DoD contract, you have a Supplier Performance Risk System (SPRS) score on file today. It was almost certainly self-generated. Two separate 2026 surveys show CMMC SPRS score confidence falling, even as the scores themselves rise. In the Kiteworks survey, 84% of respondents already worry about False Claims Act liability tied to their own attestation. That risk does not pause when third-party certification does. A claim you know is false, or file with reckless disregard for the truth, is a False Claims Act exposure today, not a future compliance deadline. DFARS 252.204-7020 calls a self-generated score a Basic Assessment. The clause rates it “Low” confidence by definition. Small businesses filing their own score and mid-market primes managing subcontractor flow-down answer to that same clause. Both sit on the same side of the DIB compliance picture the numbers below describe.

Field Answer
Signal Average self-reported SPRS scores hit a five-year high in 2026, while contractor confidence in their own scores’ accuracy fell 24 points in the same period
BD implication Compliance and legal-exposure risk: False Claims Act liability tied to a self-attested score that does not match current posture, with a documented settlement precedent
Customer DoD’s Defense Industrial Base cybersecurity posture, assessed through self-attestation under DFARS 252.204-7019/7020
Buyer Not applicable; this is a compliance-exposure signal, not a federal purchase
Funding Not applicable; the only dollar figure is a False Claims Act settlement recovery, not federal spend
Vehicle / path DFARS 252.204-7019/7020 self-attestation clauses and 32 CFR Part 170 (CMMC 2.0), not an acquisition vehicle
Incumbents / ecosystem The reader’s own existing CUI-touching contract or subcontract, not a third-party incumbent
Access strategy Self-diagnostic: audit your own current SPRS score against your actual NIST SP 800-171 implementation
Timing DoD suspended CMMC Phase 2 third-party assessment in July 2026; the self-attestation requirement remains in force regardless
Confidence Moderate
Pursuit posture DEFEND
Upgrade triggers A further Civil Cyber-Fraud Initiative settlement naming a specific DIBCAC/SPRS score gap as the trigger, or a settlement tied to a score filed during the current Phase 2 suspension window
Downgrade triggers DoD reinstating third-party assessment on an accelerated timeline

Scores Hit a Five-Year High While Confidence in Them Fell 24 Points

SPRS scores run on a -203 to 110 scale. The average score rose to +51 in 2026, a five-year high. It was +33 in 2025, the first positive average on record. Only 65% of contractors said they were extremely or very confident their score was accurate, down from 89% the year before. Just 1% considered themselves completely prepared for CMMC certification, unchanged from 2025. A 2026 survey of 302 defense contractors found that the average SPRS score rose to +51, while confidence in score accuracy fell to 65%. The survey was published August 20, 2026. The survey timing relative to the July CMMC Phase 2 suspension is unclear, so the results should not be treated as a direct before-and-after measurement of the suspension.

DFARS 252.204-7020 defines a self-generated NIST SP 800-171 score as a “Basic Assessment.” It assigns that score a “Low” confidence level by regulation, because it is self-generated. Medium and High Assessments are the government-conducted exceptions.

A second 2026 survey of 273 defense contractors, conducted shortly after DoD suspended CMMC Phase 2 third-party assessments in July, found that 96% were confident their self-attested score would hold up under review. Only 29% could back that claim with both a current SPRS submission and a FedRAMP-authorized platform, where their environment requires one. Either survey’s numbers are reason enough to check your own score now. The temptation is to assume DCMA’s DIBCAC program, the mechanism that catches a mismatched score, paused along with everything else. It didn’t.

Line up what each survey measured, and a consistent picture still emerges:

  • CyberSheath’s respondents report rising self-reported scores paired with falling confidence those scores are accurate.
  • Kiteworks’ respondents report high confidence a score would survive scrutiny, precisely when there is no scrutiny scheduled to test it.
  • Fewer than a third of Kiteworks’ respondents could pair a current SPRS submission with a FedRAMP-authorized platform, one marker of a defensible score among others.

Those two confidence numbers, 96% and 65%, look contradictory. They are not. Kiteworks and CyberSheath surveyed two separate respondent pools, and they asked different questions at different moments. That is the CMMC SPRS score confidence gap in one picture. Kiteworks asked whether a score would survive scrutiny. It fielded that question just after DoD suspended the third-party certification that would have tested it. CyberSheath asked a different group whether their own score is accurate. Taken together, the results suggest that contractors may be more confident that their self-reported scores would survive scrutiny than they are that those scores accurately reflect their current security posture.. The 24-point confidence decline should not be interpreted as a direct effect of the July suspension. The comparison uses a 2025 baseline rather than a before-and-after measurement of the suspension.

DCMA’s DIBCAC Program Catches a Bad Score, and It Was Never Suspended

DCMA, the Defense Contract Management Agency, runs the Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC. DIBCAC independently assesses contractor environments under the same NIST SP 800-171 methodology contractors use to self-report. That program was never suspended. On June 18, 2026, DOJ announced a case built on that gap. LOGZONE Inc., a Huntsville, Alabama defense contractor, agreed to pay $507,144 to resolve False Claims Act allegations. LOGZONE had self-reported a perfect score of 110 on two Navy contracts. DCMA’s independent DIBCAC assessment of the same environment returned -170. The role of any whistleblower in the case has not been established.

What did pause is different. In July 2026, the Department of War (DoW) suspended CMMC Phase 2. The stated purpose was to weigh the rule’s impact on small business and whether it imposed an undue regulatory burden. The Department of War (DoW), formerly the Department of Defense, is referred to as DoD throughout this article. Phase 2 had been scheduled to take effect November 10, 2026. It would have added C3PAO third-party certification, an outside assessor hired to check a contractor’s work before award. That certification is what is paused, not DIBCAC.

The self-attestation requirement did not go anywhere either. DFARS 252.204-7019/7020 still require a current NIST SP 800-171 DoD Assessment posted to SPRS before award. A contractor still cannot award a subcontract subject to those security requirements unless the subcontractor has completed a Basic Assessment within the last three years. Both clauses stayed in force through the Phase 2 suspension. If you are a mid-market prime, that flow-down requirement is your exposure too. A DIB sub’s stale or inflated score is a gap you are on the hook to catch, not just them.

  • DCMA’s DIBCAC program can independently re-score your environment at any time, suspension or no suspension, just as it did to LOGZONE.
  • The gap between a confident attestation and an accurate one becomes a legal question, not just a technical one, the moment a contract representation relies on that score.
  • A contractor’s own certifying official signs the SPRS submission personally, the direct line to False Claims Act exposure if the submission is false.

A Wider Pool Is Bidding on the Same CUI Work, Still on Self-Attestation Alone

After the Phase 2 suspension, 55% of Kiteworks’ surveyed contractors began bidding on CMMC Level 2 work they had previously avoided. That figure is self-reported bidding intent from one vendor-commissioned survey, not observed award data. It also describes what respondents did after the suspension, not necessarily because of it. Level 2 covers work touching Controlled Unclassified Information (CUI). That is the category where a Basic Assessment’s DFARS self-attestation requirement and its False Claims Act exposure both apply.

“‘Basic Assessment’ means a contractor’s self-assessment of the contractor’s implementation of NIST SP 800-171 that… [r]esults in a confidence level of ‘Low’ in the resulting score, because it is a self-generated score.” (DFARS 252.204-7020)

The 55% figure does not identify individual companies or a specific bidder pool; it describes contractor behavior in aggregate. The 55% figure describes contractor behavior in aggregate, not identified firms. What it means if you compete for this work:

  • More bidders than before now report competing for CUI-touching contracts they had been avoiding.
  • With third-party certification paused, that wider field is competing on the same kind of Low-confidence, self-generated score the regulation flags by default.
  • A current, defensible score is a differentiator against that field, not just a compliance checkbox.
What changed Before the suspension After the suspension
Third-party verification Scheduled to phase in by Nov. 10, 2026 Suspended by DoD in July 2026
Self-attestation requirement In force (DFARS 252.204-7019/7020) Still in force, unchanged
Contractors bidding CMMC Level 2 work Baseline, pre-suspension 55% began bidding on work they had previously avoided

Audit Your Own Score Before You Rely on It in a Proposal

Your next move depends on whether your current SPRS score reflects your current environment.

  1. Pull your current SPRS submission and confirm its date. A score older than three years is not current under DFARS 252.204-7019/7020.
  2. Compare that submission line by line against your actual NIST SP 800-171 implementation today, not the implementation you had when you last scored.
  3. Confirm you can support the score with a FedRAMP-authorized platform where your environment requires one. Not every environment does. Only 29% of surveyed contractors reported having both a current submission and the applicable platform.
  • Your SPRS score reflects your current environment, not a snapshot from a prior assessment cycle.
  • You can produce documentation behind every point on your score, not just the summary figure.
  • Your BD team is not citing your SPRS score as a proposal differentiator without confirming it is current and defensible.
  • If your environment requires a FedRAMP-authorized platform, you can name it, not just assume one is in place.
  • If you are a prime, you have checked your subcontractors’ Basic Assessment currency yourself, not just taken their word for it.
Pull your own SPRS submission today. Check its date, and check every line against your current environment. A score you know does not match reality, or file with reckless disregard for whether it does, is a False Claims Act exposure. That exposure attaches the moment the score appears in a contract representation, suspension or no suspension.

FAQ

What happens to a score filed during the suspension window once Phase 2 resumes?

The treatment of a score filed during the suspension window remains unclear. Once C3PAO third-party certification restarts, a contractor holding only a self-attested score would presumably face the applicable certification requirements. A suspension-era self-attestation should not be assumed to substitute for the later third-party assessment requirement.

What makes a self-attested score legally risky under the False Claims Act?

A claim submitted to the government with knowledge it is false, or with reckless disregard for whether it is true, can trigger False Claims Act liability. A compliance attestation tied to a contract award counts as such a claim. Kiteworks found 84% of surveyed contractors already worry about this exposure. The LOGZONE settlement above shows the risk exists whether or not third-party certification is active.

Why did scores rise while confidence in them fell?

No single cause has been established. One plausible explanation is that additional compliance activity and tooling have helped contractors raise their self-reported scores, while greater familiarity with the requirements has also made weaknesses more visible.

Is a FedRAMP-authorized platform required to pass a NIST 800-171 assessment?

A FedRAMP-authorized platform is not universally required. The requirement depends on which controls your environment touches. A current SPRS submission combined with the applicable FedRAMP-authorized platform provides one indicator of a more defensible score. Only 29% of surveyed contractors reported having both.

Has this confidence gap led to enforcement?

Yes, at least once. DOJ’s June 18, 2026 settlement with LOGZONE Inc. resolved False Claims Act allegations built on a score gap. LOGZONE self-reported 110 on two Navy contracts. A DCMA/DIBCAC independent assessment of the same environment returned -170, and the company paid $507,144. Whether a qui tam relator was involved has not been established. What is documented is the score mismatch DCMA found. Further settlements naming a score gap, especially one filed during the current suspension window, would show whether LOGZONE is a pattern rather than one case.

BD classification: DEFEND Confidence: Moderate Evidence that would upgrade this: A further Civil Cyber-Fraud Initiative settlement naming a specific DIBCAC/SPRS score gap, especially one tied to a score filed during the current Phase 2 suspension window. Evidence that would downgrade this: DoD reinstating CMMC Phase 2 third-party assessment on an accelerated timeline.

The Contract Opportunity Atlas

Two issues a week.. Free.

Two issues a week. Data-driven intelligence for small tech firms selling to the federal government. Free.

Subscribe to Contract Opportunity Atlas

Get federal technology, AI, procurement, and GovCon insights delivered to your inbox.

Shahid Shah
Shahid Shah
Shahid specializes in bringing world-class CTO, CISO, and EiR expertise to startups, business units and companies on a part-time (fractional) basis. With a rich background in regulated, safety-critical industries like Med Devices, Digital Health, and Gov 2.0, he possess a unique understanding of complex, high-demand products and services. He is a C-suite native that can easily blend in with technical and engineering teams that need to deliver revenue-generating solutions to the marketplace. He has served as an Entrepreneur in Residence when a market seems lucrative but it's unclear how to build and launch products and services for such opportunities. Shahid has years of leadership experience as a co-founding startup CTO for multiple venture-backed companies, business unit CTO and EiR, and public company CTO helping transform product teams from marginal to high performance. His software/hardware engineering and cybersecurity body of knowledge is up to date because he rolls up his sleeves to create code when appropriate & dive into system architecture and design when required. He also conduct technology due diligence exercises for corporate acquisition or product integration requirements.
RELATED ARTICLES

Most Popular

CATEGORIES