The self-assessment is honesty-based. It shows.
CMMC certification is paused pending a federal task force review. Your DFARS obligation to self-assess against NIST SP 800-171 and post a current score to SPRS isn't — it's been due every three years since 2017, and most subcontractors are scoring like it's optional.
CMMC enforcement paused. The scoring requirement didn't.
The Department of Defense suspended CMMC Phase 2 rollout in July 2026 pending a task force review. That freeze applies to third-party certification — not to DFARS 252.204-7019/7020, which has required a current NIST SP 800-171 self-assessment score in SPRS since 2020. Primes are already using that score to screen subs out of teaming decisions.
Median SPRS self-assessment score vs. requirement
CyberSheath / Merrill Research, Sept 2025The median self-assessment score across the defense industrial base rose to 60 in 2025 — up from 20 in 2022, but still barely more than half of the 110 points DFARS requires for full NIST SP 800-171 compliance. 17% of contractors reported a negative score.
companies in the defense industrial base will need CMMC Level 2 certification. As of late 2025, only 270 organizations held a final certificate.
of defense contractors say they feel fully prepared for a CMMC assessment — down from 8% in 2023 and 4% in 2024. Readiness is going the wrong way.
claim DFARS compliance through self-attestation alone. Only 30% have completed a medium- or high-level assessment that actually validated it.
The gap isn’t tooling. It’s ownership.
Contractors aren't failing because they lack security products. They're failing because nobody owns the 110-point program day to day — who's handling Controlled Unclassified Information (CUI), how, and whether anyone would notice if that changed.
Where the DIB actually stands, 2025
Self-attestation isn’t verification
Seven in ten contractors say they’re compliant. Fewer than a third have actually had that checked by anyone outside the company.
A median score of 60 isn’t close
Against a required 110, a median score of 60 describes a program that hasn’t started — not one that’s nearly there.
Tooling is going in. Process isn’t
MFA and endpoint tools are being purchased. What’s missing is a named owner walking the 14 control families end to end.
Big enough to hold CUI. Too lean to staff a compliance team.
Subs and lower-tier vendors across the defense supply chain
Machine shops, engineering firms, IT services vendors, and other subs who touch Controlled Unclassified Information under a DoD prime or direct contract. You carry the DFARS 800-171 obligation and the SPRS score primes now use to screen partners — but there's no CISO on staff, and the program lives in a folder nobody's opened since the last award.
Three ways to work together.
Same arc every time: find the gaps, train the eyes, build the program that holds.
Before the Breach
A half-day session for your ops lead, IT contact, and anyone who touches CUI — what the 14 control families actually require, and a one-page escalation playbook for when something looks wrong.
NIST SP 800-171 / SPRS Gap Assessment
2–3 weeks: score your current posture against the real 110-point methodology, document what's driving the gap, and leave you with a prioritized roadmap and a defensible SPRS number to post.
Program Advisory
A monthly advisor who owns the program between assessments — POA&M tracking, control-family tuning, and CMMC Level 2 readiness as the certification requirement returns.
Curious what your SPRS score would actually be?
A 20-minute call, no pitch. Tell us where you're exposed and what your contracts require — we'll tell you honestly where we'd start.
Book a 20-minute call