Defense Contractors Feel Ready for CMMC—But Can They Prove It?
Two separate industry surveys released this week, from Kiteworks and CyberSheath, highlight a growing gap in the US defense industrial base: contractors say they feel more confident about meeting Cybersecurity Maturity Model Certification (CMMC) requirements, but their actual ability to prove that compliance is falling behind.
CMMC is the US Department of Defense's framework for ensuring that contractors and subcontractors handling sensitive information maintain adequate cybersecurity practices. While confidence in meeting these standards appears to be rising across the sector, the surveys suggest that documentation, evidence-gathering, and audit-readiness processes haven't kept pace with that confidence.
This mismatch matters because compliance frameworks like CMMC are increasingly used as a benchmark for trustworthy cybersecurity practices, even outside the defense sector. Australian businesses working with international supply chains, particularly those with US defense or government-adjacent clients, should take note: feeling secure and being able to demonstrate security through solid documentation and evidence are two very different things, and gaps between the two can create real risk during audits or after an incident.