The latest CMMC reporting exposes a problem that every defense contractor should take seriously:

SPRS scores are rising. Confidence in those scores is falling. The ability to prove compliance is lagging even further behind.

This is the CMMC paradox.

On August 20, Washington Technology reported that contractors’ average Supplier Performance Risk System (SPRS) score reached a five-year high of +51, up from +33 in 2025. Yet only 65% of respondents said they were extremely or very confident that their scores were accurate, down sharply from 89% the prior year.

On August 21, SecurityWeek reported an equally important gap: 96% of contractors believed their self-attested SPRS score would hold up under review, but only 29% could substantiate that belief with both a current SPRS submission and a FedRAMP-authorized platform.

The conclusion is direct:

A rising SPRS score means very little if your organization cannot produce credible, current evidence when challenged.

The CMMC Paradox: Better Numbers, Weaker Confidence

The numbers appear encouraging at first glance. Contractors are improving their understanding of NIST SP 800-171 scoring. More organizations are implementing multifactor authentication, secure backups, endpoint detection, vulnerability management, and other foundational controls.

But scoring familiarity is not the same as operational compliance.

The recent surveys reveal three separate realities:

  1. Self-reported scores are increasing.
  2. Confidence in score accuracy is declining.
  3. Validated readiness remains extremely limited.

The Washington Technology report also found that only 1% of contractors considered themselves completely prepared for CMMC certification, the same percentage reported the previous year.

That should end the assumption that a positive SPRS score automatically means an organization is ready for a CMMC assessment.

A SPRS score is a snapshot of reported alignment. It is not a continuously verified security posture. It does not, by itself, prove that:

  • Technical controls are correctly configured
  • Policies are actually followed
  • Evidence is complete and current
  • Security logs are retained and reviewable
  • System boundaries are accurate
  • CUI is properly contained
  • Employees completed required training
  • Vulnerabilities are remediated on schedule
  • Backups can be restored
  • Incident-response procedures work
  • The organization can explain its score to an assessor, contracting officer, or investigator

The government does not need to accept an unsupported number simply because it appears in SPRS.

Split-screen illustration contrasting a rising SPRS score with fragmented audit evidence

The Phase 2 Pause Did Not Pause Accountability

The suspension of CMMC Phase 2 third-party assessments changed the timing of certain assessments. It did not erase the underlying obligations.

DFARS 252.204-7012 requirements remain relevant. NIST SP 800-171 obligations remain relevant. Accurate self-assessment and reporting to SPRS remain relevant. The responsibility to protect Controlled Unclassified Information (CUI) remains relevant.

In fact, the pause makes evidence more important, not less.

When third-party verification is delayed, self-attestation becomes a more significant line of defense and a more significant source of risk. Contractors must be able to demonstrate that their score is based on implemented, functioning controls rather than optimistic interpretation.

The SecurityWeek reporting noted that 84% of surveyed contractors were concerned about False Claims Act liability connected to inaccurate scores, and that 92% had already involved legal or compliance review.

This is the new operating reality:

Your SPRS score is not just a compliance number. It is a representation of your organization’s cybersecurity posture.

If your score is challenged, the question will not be, “Did you enter a number?”

The question will be:

“Show us how you know.”

From Self-Attestation to Evidence-Backed Proof

Planet Security’s CPE Level 2 is engineered to close the gap between what a contractor reports and what that contractor can prove.

Built on Planet Security’s NIST Compliant Infrastructure Server, CPE Level 2 provides 100% coverage of all 110 security requirements and 320 assessment objectives under CMMC 2.0 Level 2.

This is not a spreadsheet exercise. It is not a collection of disconnected security products. It is an integrated protected enclave combining:

  • Hardware
  • Software
  • Security configurations
  • Network segmentation
  • Organizational policies
  • Procedures
  • Training
  • Monitoring
  • Maintenance
  • Backup
  • Evidence collection
  • Audit preparation
  • Ongoing managed security operations

The objective is simple: create a security environment where compliance evidence is generated as part of normal operations, not reconstructed under pressure.

What Evidence-Backed Compliance Looks Like

A defensible CMMC program must connect each requirement to an implemented control, an accountable owner, and verifiable evidence.

CPE Level 2 supports that connection through continuous operational coverage, including:

1. Technical configuration evidence

The enclave is configured to address the complete scope of CMMC 2.0 Level 2, including access control, audit and accountability, configuration management, identification and authentication, system and communications protection, system and information integrity, and other control families derived from NIST SP 800-171.

2. Continuous monitoring

Periodic reviews can miss changes that occur between assessment windows. Continuous monitoring helps identify configuration drift, security events, availability concerns, and control degradation as they occur.

The result is a living compliance picture, not an annual scramble.

3. Policy and procedure alignment

CMMC is not satisfied by technology alone. The organization must also establish and follow documented policies and procedures governing CUI, access, media, incident response, physical protection, personnel security, and more.

CPE Level 2 includes required security policies, procedures, security awareness training, insider-threat coverage, and methods for protecting hard-copy CUI.

4. Backup and recovery evidence

A backup that has never been tested is an assumption, not proof. Integrated onsite warm and offsite cold backup capabilities support resilience and provide a foundation for demonstrating recoverability.

5. Audit preparation and representation

The environment is designed to support preparation for a C3PAO assessment and representation during DIBCAC or official assessment activity. The goal is to ensure that evidence is organized, traceable, and connected to the controls it supports.

Why Generic AI Tools Cannot Be Trusted With Client Data

Many organizations are rushing to apply generic artificial intelligence to compliance documentation, policy writing, ticket analysis, and security operations.

That creates a serious risk when the input includes CUI, client information, credentials, system details, proprietary designs, or sensitive operational data.

Generic AI tools cannot be trusted with client data by default. Their data handling, retention, training, access, and jurisdictional practices may not align with the security obligations surrounding sensitive information.

Planet Security takes a different approach.

When AI-enabled workflows are used within the protected-enclave model, Planet Security emphasizes AI-obfuscated data. Sensitive client and government information is protected from exposure to generic AI systems while still allowing automation, analysis, workflow support, and security intelligence.

Secure operations center with continuous monitoring and an AI privacy shield protecting sensitive data

This distinction matters. AI should strengthen a compliance program without becoming a new avenue for data leakage.

A Practical Four-to-Eight-Week Path to Proof

For organizations with a defined scope and cooperative stakeholders, full implementation is commonly targeted within approximately four to eight weeks, depending on deployment requirements, data migration, user count, network complexity, and organizational readiness.

A typical implementation focuses on:

  1. Defining the CUI boundary
  2. Establishing the enclave architecture
  3. Deploying the NIST Compliant Infrastructure Server
  4. Applying security configurations and segmentation
  5. Implementing policies and procedures
  6. Migrating or onboarding authorized users and data
  7. Enabling monitoring, backup, and evidence workflows
  8. Preparing for assessment and ongoing operational review

This approach is fundamentally different from spending months attempting to coordinate dozens of vendors, manually map controls, and assemble evidence after the fact.

The fastest path to a defensible SPRS score is not simply raising the number. It is building an environment that continuously supports the number.

What Should Contractors Do Now?

Every defense contractor should ask five direct questions:

Is our SPRS score current?

An outdated score creates uncertainty. A current score demonstrates that leadership understands the organization’s present posture.

Can we prove every scored requirement?

If a control is marked implemented, can your team produce configuration records, policies, logs, training records, tickets, screenshots, and other objective evidence?

Is our system boundary accurate?

A score is only as defensible as the environment it describes. Unmanaged endpoints, cloud services, remote users, personal devices, and third-party systems can create hidden gaps.

Are we monitoring continuously?

A control that was operating last quarter may not be operating today. Continuous monitoring is the difference between historical compliance and current assurance.

Could we explain our score tomorrow?

If an assessor or contracting officer asked for evidence immediately, would your team be prepared, or would it need weeks to reconstruct what happened?

If the answer is uncertain, your confidence problem is an evidence problem.

Frequently Asked Questions

Does a high SPRS score equal CMMC certification?

No. A SPRS score reflects self-reported alignment. CMMC assessment provides independent validation. A high score is useful, but it must be supported by implemented controls and credible evidence.

Does the Phase 2 assessment pause eliminate the need for compliance?

No. The pause affects assessment timing. It does not eliminate the need to meet applicable DFARS requirements, protect CUI, maintain accurate reporting, or prepare for future verification.

How does CPE Level 2 help with SPRS defensibility?

It provides an integrated environment designed for 100% coverage of the 110 CMMC requirements and 320 objectives under CMMC 2.0 Level 2, supported by monitoring, policies, training, security operations, backup, maintenance, and audit preparation.

Can AI be used safely in CMMC workflows?

Yes: but not by sending sensitive client data into generic AI tools. Planet Security’s AI-obfuscated data approach helps protect sensitive information while supporting privacy-conscious automation and analysis.

Turn the Number Into Proof

The CMMC market is moving beyond score inflation and general confidence. Contractors will increasingly be judged by whether they can demonstrate that their reported posture is real, current, and operational.

A score is a claim. Evidence is what makes the claim credible. Continuous monitoring is what keeps it credible.

CPE Level 2 gives defense contractors a direct path from self-attestation to evidence-backed assurance: with complete coverage of 110 CMMC requirements and 320 objectives under CMMC 2.0 Level 2.

There is no substitute for an environment built to support the proof.

Review the CPE Level 2 technical details or contact Planet Security at 702.634.7233.

We welcome a discussion on how we may assist in your CMMC success story!

Sources

Scroll to Top