Skip to main content
Defense Contractors Can't Trust Their Own CMMC ScoresRegulatory Compliance
5 min readFor Board Members

Defense Contractors Can't Trust Their Own CMMC Scores

Scope

This guide addresses the gap between self-reported CMMC compliance scores and actual security posture for defense industrial base (DIB) organizations. It covers SPRS self-assessment mechanics, the implications of suspended third-party verification, and practical steps to improve assessment accuracy before Phase II enforcement resumes.

If you're a prime contractor or subcontractor handling federal contract information (FCI) or controlled unclassified information (CUI), this guide will help you build credible self-assessments that withstand scrutiny.

Key Concepts and Definitions

SPRS (Supplier Performance Risk System): The DoD's self-assessment framework where contractors score themselves against 110 security controls from NIST SP 800-171. A perfect score is 110; the DIB average hit +51 in 2026.

CMMC (Cybersecurity Maturity Model Certification): The DoD's program requiring defense contractors to demonstrate cyber hygiene appropriate to the sensitivity of information they handle. Currently in Phase I (self-assessment only), with Phase II (independent third-party audits) suspended as of July 2026.

DFARS (Defense Federal Acquisition Regulation Supplement): The rulebook that makes CMMC compliance a binding contract requirement. Non-compliance can disqualify you from DoD contracts.

NIST SP 800-171: The 110-control baseline for protecting CUI in non-federal systems. Your SPRS score reflects how many of these controls you've implemented.

C3PAO (Certified Third-Party Assessment Organization): Independent auditors who were scheduled to verify CMMC compliance under Phase II before the program was suspended.

The Core Problem

Confidence in SPRS score accuracy dropped from 89% to 65% between 2025 and 2026, even as average scores rose from +33 to +51. Only 1% of contractors believe they're completely prepared for certification.

This isn't a budget problem. DFARS compliance spending averaged $155,204 annually, and 53% of contractors say their budgets feel "just right." The issue is verification: without third-party assessment, you're guessing whether your controls actually work as documented.

Requirements Breakdown

NIST SP 800-171 Control Families

Your SPRS score reflects implementation across 14 control families. Here's where self-assessment typically breaks down:

Access Control (AC): 22 controls covering least privilege, session management, and remote access. Common gap: documented policies without technical enforcement.

Incident Response (IR): 5 controls for detection, reporting, and recovery. Common gap: tabletop exercises that don't test real detection capabilities.

System and Communications Protection (SC): 17 controls including boundary protection and transmission security. Common gap: assuming firewall rules equal adequate boundary protection without testing egress controls.

Configuration Management (CM): 9 controls for baseline configurations and change control. Common gap: configuration standards exist but drift isn't monitored.

Identification and Authentication (IA): 11 controls for user and device identity. Common gap: multi-factor authentication deployed but not enforced for all privileged access.

Scoring Methodology

Each control receives 0 to 5 points:

  • 5 points: Fully implemented
  • 3 points: Partially implemented
  • 1 point: Documented plan to implement
  • 0 points: Not implemented
  • -1 point: Not implemented and no plan

Your total minus 110 equals your SPRS score. A +51 average means the DIB is claiming roughly 161 points across 110 controls.

Implementation Guidance

Build Evidence Before You Score

Don't score based on what you've documented. Score based on what you can demonstrate.

For each control, collect:

  • Configuration exports showing the setting is active
  • Log samples proving the control generates alerts
  • Test results from attempting to circumvent the control
  • Change tickets showing the control survived system updates

If you scored AC-2 (Account Management) as fully implemented, you should be able to produce a user list, show automated deprovisioning logs, and demonstrate that terminated accounts can't authenticate.

Separate Assessment from Remediation

Create two teams: one that scores honestly, one that fixes gaps. Don't let the same people who built controls grade their own work.

Your assessment team should include someone who understands NIST SP 800-171 control intent, not just your documentation. A control that "meets the requirement on paper" but fails under testing gets partial credit at best.

Test Before You Certify

Run a mock C3PAO assessment before Phase II resumes. Have an external assessor:

  • Interview system owners without your documentation present
  • Attempt to access systems they shouldn't reach
  • Review logs for evidence of monitoring
  • Check if your incident response plan matches actual runbooks

The gap between what you think you've implemented and what an auditor can verify is where your confidence score drops.

Document Your Scoring Logic

For every control, record:

  • What you implemented (specific tools, configurations, processes)
  • What evidence proves it's working
  • What gaps remain and why you scored it partially vs. fully implemented
  • When you last tested the control

When Phase II resumes, this documentation becomes your audit trail. Without it, you're defending a score you can't reconstruct.

Common Pitfalls

Scoring policies as implementations: A documented password policy isn't the same as enforced password complexity. If your directory allows weak passwords, you haven't implemented IA-5.

Assuming vendor defaults equal compliance: Your firewall ships with logging enabled, but if you're not reviewing those logs or alerting on anomalies, you haven't implemented AU-6 (Audit Review).

Conflating partial with full implementation: Partial means the control works sometimes or in some places. If MFA covers VPN but not privileged workstations, that's partial for IA-2(1), not full.

Ignoring system boundaries: If you scored SC-7 (Boundary Protection) based on your corporate network but CUI lives in a cloud tenant with different controls, your score is wrong.

Treating SPRS as a one-time exercise: Controls drift. If you haven't re-validated your score in six months, your confidence should drop accordingly.

Quick Reference Table

Control Family Controls High-Risk Self-Assessment Gaps
Access Control (AC) 22 Remote access logging, session timeout enforcement
Awareness & Training (AT) 3 Phishing test results, role-based training completion
Audit & Accountability (AU) 9 Log retention, review frequency, alert tuning
Configuration Management (CM) 9 Baseline enforcement, unauthorized change detection
Identification & Authentication (IA) 11 MFA coverage for privileged access, device authentication
Incident Response (IR) 5 Tested playbooks, detection capability validation
Maintenance (MA) 6 Remote maintenance logging, tool authorization
Media Protection (MP) 8 Sanitization procedures, physical media tracking
Personnel Security (PS) 2 Termination process validation
Physical Protection (PE) 6 Visitor logs, physical access reviews
Risk Assessment (RA) 3 Vulnerability scan coverage, remediation tracking
Security Assessment (CA) 7 Assessment frequency, POA&M management
System & Communications Protection (SC) 17 Transmission encryption, boundary protection testing
System & Information Integrity (SI) 5 Malware detection coverage, patch compliance

What Changes When Phase II Resumes

Third-party assessments will expose the gap between your SPRS score and verifiable implementation. C3PAOs won't accept documentation without evidence. They'll test controls, interview staff, and score based on what they observe.

The 24-percentage-point drop in confidence suggests contractors know this. If you're not confident in your score now, start closing the gap before audits become mandatory. The average $155,204 compliance budget is sufficient if spent on implementation rather than documentation.

Your contract eligibility depends on credible scores. Build them now while you control the timeline.

You Might Also Like