Nearly all defense contractors believe their self-reported compliance scores would hold up under scrutiny, but fewer than a third can back that belief with documented evidence, according to new research from Kiteworks. The secure data exchange vendor surveyed 273 defense contractors following the government's July suspension of CMMC 2.0 Phase II third-party assessments. The company argues the pause in assessments doesn't signal reduced compliance demand but instead opens a wider services market for managed service providers and compliance consultants.
The survey revealed 96% of defense contractors subject to active CMMC 2.0 requirements believe their self-attested compliance score would survive review. However, only 29% can support that confidence with both a current Supplier Performance Risk System submission and an audited platform, the research found. Despite the suspension, 98% of contractors took some action after the pause was announced, with just 2% doing nothing. Thirty-two percent are moving ahead with scheduled third-party assessments on a voluntary basis even though those reviews are temporarily no longer mandatory, while 89% are using or plan to adopt a FedRAMP-authorized platform within six months.
"It's one thing to say you're compliant, and especially when you're self-attesting. But you need to be able to prove it," Kiteworks Chief Revenue Officer Kurt Michael said. He emphasized that organizations ultimately need to demonstrate their controls and handling of controlled unclassified information are functioning as intended. The suspension affects only one piece of the compliance process, according to Kiteworks, while DFARS 252.204-7012, NIST SP 800-171, Phase I self-assessments, and SPRS submissions remain in effect. Michael told Channel Insider the company continues to see customers actively seeking CMMC-related solutions despite the pause, with several inquiries arriving each week from organizations of varying sizes.
The gap between self-attestation and audit-ready proof creates a recurring services opportunity for MSPs, Kiteworks argues. The company identified gap assessments, evidence collection, System Security Plan remediation, continuous monitoring, and managed compliance retainers as potential services that partners can offer. That shift could transform what might otherwise be a one-time CMMC project into an ongoing managed service. Kiteworks is positioning its Control Plane platform as supporting CMMC Level 2 requirements and holding FedRAMP Moderate Authorization, while partners can layer assessment preparation, remediation, consulting, and ongoing monitoring on top of the technology.
Michael said partners that develop CMMC expertise can apply the same consulting-led approach as customers face a growing number of cybersecurity, data protection, and privacy requirements. The compliance environment will become increasingly difficult for businesses over time, he noted, creating continued opportunity for partners that can provide an independent view, consult on best practices, and recommend appropriate technologies. The opportunity extends beyond defense contractors to any organization navigating complex regulatory demands. Partners positioned to combine technical controls with independent advisory services may find regulatory expertise itself becomes a competitive advantage, particularly as enforcement uncertainty drives organizations to seek proof rather than simply claim compliance.

