Skip to main content
The state of ai impact assessment
Self-Assessment Scores Don't Mean What You Think They DoRegulatory Compliance
6 min readFor Compliance Officers

Self-Assessment Scores Don't Mean What You Think They Do

When defense contractors report their CMMC cybersecurity scores have climbed to a five-year high while admitting they don't trust those numbers, you're witnessing a compliance framework unraveling from within.

The average SPRS score rose to +51 in 2026 from +33 in 2025. Yet, confidence in score accuracy fell from 89% to 65% in the same period. Only 1% of contractors believe they're completely prepared for CMMC certification. Your team might be making similar mistakes, inflating metrics while undermining the controls those metrics are supposed to represent.

Why These Mistakes Keep Happening

Self-assessment frameworks fail when unclear control design, weak verification, and pressure to show compliance progress converge. CMMC's SPRS system asks contractors to rate themselves against 110 security controls from NIST SP 800-171. Without independent validation, teams interpret control requirements generously, score partial implementations as full compliance, and mistake documentation for operational effectiveness.

The Pentagon's suspension of third-party assessments in July 2026 removed the accountability that would have caught these scoring gaps. Without external verification, teams fail to internalize rigorous self-assessment discipline, leading to rising scores that mask static or declining readiness.

Mistake 1: Scoring Control Documentation Instead of Control Effectiveness

Your team implements a security control, writes the procedure document, and marks it complete in SPRS. The control exists on paper, so you assign full points.

Why it happens: Control design and control effectiveness are different, but self-assessment frameworks often blur them. Teams conflate "we have a process" with "the process works as intended." Without audit training, compliance officers don't apply professional skepticism to their own implementations.

Real consequence: You report a +51 SPRS score while your patch management control only covers 60% of endpoints, your access review process hasn't run in four months, and your Incident Response Structure has never been tested. When a breach occurs or a C3PAO audits you, the gap between your score and your actual security posture becomes a regulatory liability.

The fix: Separate control design documentation from control testing evidence in your GRC platform. For each NIST SP 800-171 control, require three artifacts: the control design document, the testing procedure, and the most recent test result. Don't score a control as implemented until you have evidence it operated effectively in the last 90 days. Document your scoring methodology and apply it consistently across all 110 controls.

Mistake 2: Treating Self-Assessment as a Solo Exercise

Your compliance officer completes the SPRS assessment alone, consulting documentation but not interviewing control owners or observing processes in operation.

Why it happens: Teams assume self-assessment means "internal assessment" rather than "independent third-party assessment." They miss the critical verification step. With DFARS compliance budgets averaging $155,204 annually, organizations spend on tools and consultants but not on internal audit rigor.

Real consequence: Your SPRS score reflects what your compliance officer believes is true based on outdated documentation, not what's actually happening in production systems. When control owners change, processes drift, or exceptions accumulate, the score becomes fiction. The 24-percentage-point confidence drop signals that contractors are discovering these gaps themselves.

The fix: Build a three-line verification model even without C3PAOs. First line: control owners self-assess and provide evidence. Second line: your compliance function reviews evidence and conducts spot checks. Third line: internal audit or an external consultant samples controls quarterly using the same testing procedures a C3PAO would apply. This won't replace formal third-party assessment, but it prevents the most egregious scoring errors and builds the discipline you'll need when independent audits resume.

Mistake 3: Optimizing for Score Improvement Rather Than Risk Reduction

Your team focuses on closing the easiest control gaps to raise your SPRS score quickly, leaving high-risk weaknesses unaddressed because they're technically complex or politically difficult.

Why it happens: Self-assessment scores become performance metrics. When leadership tracks score trends quarter-over-quarter, teams game the metric by implementing low-effort controls first. The CMMC framework treats all 110 NIST SP 800-171 controls as equally weighted, so you get the same score boost for fixing documentation controls as for implementing multifactor authentication on privileged accounts.

Real consequence: You achieve a +51 SPRS score while your most critical CUI systems remain vulnerable to the attack vectors that actually matter. Adversaries don't care about your compliance score. They exploit the gaps in your boundary protection, account management, and audit logging, which are often the hardest controls to implement correctly.

The fix: Map each NIST SP 800-171 control to your cybersecurity risk register. Score controls by implementation status and by risk reduction value. Prioritize controls that address your highest-severity risks, even if they're harder to implement. Report two metrics to leadership: SPRS score and risk-weighted control coverage. Make it clear that a rising SPRS score doesn't necessarily mean falling cyber risk if you're implementing low-value controls.

Mistake 4: Confusing Budget Adequacy with Implementation Effectiveness

Your organization increased DFARS compliance spending to $155,204 annually, matching the industry average. You assume adequate budget means adequate controls.

Why it happens: Compliance officers measure inputs (budget, headcount, tools purchased) rather than outcomes (controls operating effectively, risks reduced, audit findings closed). When 53% of contractors say their budgets feel "just right," they're evaluating budget size, not ROI.

Real consequence: You spend heavily on compliance tools, consultants, and training while your actual control environment remains weak. Money flows to vendors who promise easier compliance rather than to the hard work of remediating control deficiencies. The CyberSheath report notes that "the challenge facing the DIB is not simply how much contractors spend on cybersecurity, but how effectively those investments translate into implemented, sustainable and verifiable security."

The fix: Track compliance spending by control domain, not by vendor or project. For each major investment, define the control improvement you expect and measure it. If you spent $40,000 on a vulnerability management platform, your metric isn't "tool deployed" but "percentage of critical vulnerabilities remediated within SLA." If you hired a consultant to design access controls, measure privilege creep reduction and access review completion rates six months after the engagement ends. Budget adequacy is meaningless without implementation effectiveness.

Mistake 5: Assuming Self-Assessment Rigor Will Emerge Organically

Your team believes that once third-party assessments resume, you'll tighten your self-assessment practices. Until then, you maintain the status quo.

Why it happens: Organizations treat the Phase II suspension as a compliance holiday rather than an opportunity to build internal verification capability. The mindset is "we'll get serious when C3PAOs are mandatory again." This ignores the fact that effective self-assessment is a learned skill that takes time to develop.

Real consequence: When third-party assessments restart, you face a massive gap between your self-reported SPRS score and your C3PAO assessment results. The remediation effort is compressed, expensive, and disruptive. Worse, if you're competing for contracts against firms that maintained rigorous self-assessment during the suspension, you're at a competitive disadvantage.

The fix: Treat the Phase II suspension as preparation time. Engage a C3PAO or qualified auditor to conduct a gap assessment now, before it's mandatory. Use their findings to recalibrate your SPRS scoring methodology and identify control deficiencies while you still have time to fix them. Document your verification procedures and train your compliance team to apply professional skepticism to internal assessments. When mandatory third-party assessments resume, you'll be ready.

Prevention Checklist

Use this checklist quarterly to maintain self-assessment discipline:

  • Every control marked as implemented has testing evidence from the last 90 days
  • Control scores reflect operational effectiveness, not just documentation existence
  • Second-line review verified at least 20% of first-line control assessments this quarter
  • Risk-weighted control coverage metric reported alongside raw SPRS score
  • Compliance spending tracked by control domain with effectiveness metrics defined
  • Control owners interviewed directly, not just documentation reviewed
  • Scoring methodology documented and applied consistently across all 110 controls
  • Gap between self-assessment and most recent external review is under 15 points
  • Remediation priorities set by risk reduction value, not by ease of implementation
  • Internal audit or external consultant sampled controls using C3PAO-equivalent rigor

Your self-assessment scores should make you more confident in your security posture, not less. If your team's confidence is falling while your scores rise, you're measuring the wrong things.

Application Security Isn’t Optional Anymore.

You Might Also Like