Dominic Jainy stands at the forefront of the intersection between advanced technology and national security, bringing years of expertise in artificial intelligence and secure systems to the complex world of defense compliance. As the defense industrial base grapples with the transition into a new era of digital warfare, his insights offer a grounded perspective on why the road to cybersecurity maturity remains so rocky for many organizations. This discussion explores the evolving landscape of the Cybersecurity Maturity Model Certification (CMMC), the mounting pressure of supply chain accountability, and the psychological shift occurring as executives realize that checking a box is no longer enough to safeguard the nation’s most sensitive data. We look into the friction between rising technical implementation scores and the sharp decline in executive confidence, while examining how the threat of legal repercussions is reshaping the way contractors report their readiness.
Self-assessment scores have trended upward to an average of +51 this year, yet executive confidence in the accuracy of those figures has plummeted from 94% two years ago to just 65% in 2026. What do you believe is driving this “confidence disconnect” within the defense industrial base?
The disconnect we are seeing is a direct result of contractors finally coming to terms with the sheer complexity of the evidentiary requirements needed to prove their security posture. While the jump in mean scores from -12 in 2024 to +51 today suggests that technical controls are being implemented, there is a lingering anxiety about whether these systems would actually hold up under the cold light of a formal audit. Executives are beginning to feel the weight of nation-state hacking threats, which makes them realize that a positive score on paper doesn’t always equate to a fortress in reality. This year, only two-thirds of contractors feel truly confident in their self-assessments because they are now seeing the “moving goalposts” of evolving requirements and the difficulty of producing the specific evidence required for executive attestation. It is a sobering moment for the industry where the “gut feeling” of being secure is being replaced by the realization that they might be missing critical vulnerabilities hidden in their digital architecture.
Even though the Pentagon recently suspended the requirement for independent third-party reviews in CMMC’s second phase due to cost concerns, many firms are still struggling to reach full readiness. Why is the “1% fully ready” statistic so persistent despite these accommodations?
The reality is that achieving 100% readiness is an incredibly labor-intensive mountain to climb, and currently, a scant 1% of the industry feels they have reached the summit. We are seeing progress in specific areas—for instance, 63% of firms have finally implemented multifactor authentication and 48% have secure backups in place—but these are only individual pieces of a much larger puzzle. The median contractor currently believes they are only 70% ready for a review because they are drowning in the administrative burden of documenting every single process to meet military standards. There is a palpable sense of exhaustion among IT teams who have managed to implement endpoint detection for 40% of their systems but find themselves stalled when it comes to more complex tasks like data-leakage protections, which only 44% of firms have mastered. This gap exists because modernizing a legacy manufacturing or IT environment isn’t just about buying new software; it’s about a fundamental cultural shift in how data is handled, and that takes more than just a few years of effort.
We are seeing a significant shift in how contractors view their partners, with over 80% suggesting that managed security service providers should be subject to the same DFARS requirements. How does this reflect the current anxieties regarding supply chain vulnerabilities?
There is a growing sense of frustration among contractors who feel they are being held to a standard that their own service providers are not yet required to meet. When 80% of companies demand that managed security service providers be brought under the DFARS umbrella, they are essentially signaling that they know their greatest risks often lie with the third parties they trust to protect their controlled unclassified information. This isn’t just a minor concern; 63% of contractors want managed service providers covered, and 58% want other technology providers included because they see the glaring holes in the supply chain. They are tired of being the only ones in the hot seat when a breach occurs through a vendor’s backdoor, especially since many of these organizations have annual revenues between $500,000 and $1 million and cannot afford the fallout of a partner’s mistake. It’s a call for a level playing field where everyone in the ecosystem is forced to carry the same weight of responsibility for national security.
The statistic that only one-third of contractors feel at least 80% prepared for a CMMC review is striking, yet when firms actually undergo third-party reviews, 63% of them pass on the first try. How do you interpret this discrepancy between perceived readiness and actual performance?
This discrepancy highlights a “fear of the unknown” that is currently paralyzing much of the defense industrial base. The 63% pass rate for those who have actually braved a third-party review suggests that many organizations are actually more prepared than they give themselves credit for, yet they remain haunted by the 1% “fully ready” mindset. The pressure of the False Claims Act plays a huge role here; companies are terrified that if they claim to be 100% ready and a reviewer finds even a minor flaw, they could face prosecution for misrepresenting their cybersecurity posture. This has led to a culture of extreme caution where firms would rather underestimate their readiness at 70% than risk the stinging bite of legal action. It is a paradoxical environment where the very regulations designed to improve security are causing firms to become overly critical of their own successful implementations, such as vulnerability management which is now at a 44% adoption rate across the board.
What is your forecast for the defense industry’s cybersecurity posture over the next few years?
I expect we will see a “shake-out” period where the divide between the leaders and the laggards in the defense industrial base becomes impossible to ignore. As the government continues to use the False Claims Act as a primary enforcement tool, the current trend of rising technical scores—which hit +51 this year—will likely continue, but the reporting will become even more conservative. We will likely see a surge in the adoption of automated compliance tools as the 40% of firms currently using endpoint detection realize that manual tracking is no longer sustainable. Ultimately, the industry will have to move toward a model where cybersecurity is treated as a continuous operational requirement rather than a static certification event, or they risk being left behind in a procurement environment that increasingly favors the 63% who can actually prove their resilience during a first-time audit. The days of “vague compliance” are over, and the era of demonstrable, data-driven security is now the only way forward for anyone wanting to do business with the Pentagon.
