Report by CyberSheath

From Readiness to Reality: The 2025 State of the DIB on CMMC Compliance

13 FINDINGSPublished Oct 1, 2025
View Original Report →

Key Findings

The median SPRS score has improved from 20 in 2022’s inaugural report to 60 this year, but 17% of contractors still report negative scores, far below the required 110 benchmark.

CMMCSPRS

The estimated number of defense contractors that require Level 2 certification is 80,000.

CMMC

78% of defense contractors lack patch management solutions.

CMMCSecurity toolsPatch management

The number of organizations that currently hold final CMMC certificates is 270.

CMMC

The approximate annual budget contractors are investing in compliance, as budgets have grown, is nearly $50,000.

CMMCInvestmentBudgetsCompliance

42% of contractors have submitted SPRS scores (a fundamental requirement for demonstrating compliance).

CMMCSPRS

79% of defense contractors lack vulnerability management solutions.

CMMCSecurity toolsVulnerability management

74% of defense contractors lack data leakage protection.

CMMCSecurity toolsData leakage protection

Only 1% of defense contractors report being fully prepared for the upcoming CMMC assessments.

CMMC

30% of contractors completed medium or high assessments that would validate their actual security posture.

CMMCSecurity posture

73% of defense contractors lack multi-factor authentication (MFA).

CMMCSecurity toolsMFA

69% of contractors claim DFARS compliance through self-assessment.

CMMCDFARS

Nearly 9 in 10 defense contractors have already suffered financial, reputational, or business losses due to cyber incidents.

CMMCCyber attack consequences