, ,

Compliance and Confidence: What a New Report Says About Continuous Assurance

September 14, 2026 | By Dale Hoak
What a New Report Says About Continuous Assurance

RegScale recently earned CMMC Level 2 certification, the latest in a growing portfolio of certifications that let customers adopt RegScale with confidence. What matters more than the certification itself is how we got there: we did not approach CMMC as a one-time evidence sprint. Our cybersecurity program is built on continuous controls monitoring (CCM), so the assessment validated a system that holds up between assessments, not just during them. 

A newly published report suggests many organizations across the defense industrial base can’t say the same about their own systems. The findings make a strong case for why security and compliance leaders need to move toward continuous assurance, and why relying on manual, point-in-time processes creates unnecessary risk. 

Understanding the Compliance Confidence Gap  

CMMC Level 2 is designed for organizations that handle Controlled Unclassified Information (CUI) in the U.S. defense supply chain. It assesses implementation of the 110 security requirements in NIST SP 800-171 Rev. 2 across 320 assessment objectives. When a contract requires a Level 2 certification assessment, a Certified Third-Party Assessment Organization (C3PAO) independently evaluates whether those requirements are implemented. 

The 2026 State of the Defense Industrial Base Report, commissioned by CyberSheath and conducted by Merrill Research, surveyed 302 U.S. defense contractors. It examined self-reported Supplier Performance Risk System (SPRS) scores, confidence in those scores, CMMC preparedness, spending, enforcement, and third-party risk. 

On paper, the numbers show progress. The average self-reported SPRS score rose 18 points, from +33 in 2025 to +51 in 2026. The report also found that documentation and adoption of core cybersecurity capabilities are improving. 

But confidence moved in the opposite direction. The percentage of contractors who were extremely or very confident in the accuracy of their SPRS score fell 24 percentage points, from 89% to 65%. Only 1% said they were completely prepared for CMMC certification. 

That gap matters. Organizations may be reporting progress, but many are not confident that the number they submitted reflects what is actually operating in their environment, or that they can produce the evidence needed to defend it. At the same time, 74% of respondents said they want an easier way to implement the requirements. 

This is what happens when compliance depends too heavily on manual evidence collection and point-in-time reviews. Those methods may document a moment, but they cannot keep pace on their own with environments, threats, and control implementations that change continuously. 

A Risky Choice   

This is not only a security and resilience issue. Inaccurate representations can also create significant legal and financial exposure. 

The report points to recent False Claims Act settlements involving cybersecurity representations. In June 2026, LOGZONE agreed to pay $507,144 to resolve allegations that it failed to comply with cybersecurity requirements in Department of the Navy contracts. In March 2025, MORSECORP agreed to pay $4.6 million to resolve allegations that included submitting a NIST SP 800-171 score of 104 and failing to update it after a third-party assessment produced a much lower score. In both matters, the settlements resolved allegations; there was no determination of liability. 

That makes verifiable compliance a board-level issue. If an executive is expected to stand behind an attestation, the organization needs objective, current, and traceable evidence to support it. 

A Better Approach   

This is where CCM changes the model. It turns compliance from a periodic exercise into a continuous view of control health, ownership, evidence, and implementation. Evidence can be collected from across the security stack, mapped to CMMC requirements, reviewed for quality, and used to drive remediation when a control is not operating as intended. 

Compliance as code strengthens that approach by translating testable requirements into machine-readable checks where appropriate. It accelerates evidence collection, improves consistency, and helps teams identify control drift before an assessment or an attacker finds it first. 

The goal is not simply to pass an assessment. It is to build a more resilient business and stronger operational security. The evidence produced by that program can then support CMMC, FedRAMP 20x, and other frameworks. When teams understand the status of their controls, assets, vulnerabilities, and risks, the audit becomes validation of what they already know, not a major event where they scramble for evidence and discover problems too late. 

Using this approach, we were able to: 

  • Meet all 110 CMMC Level 2 security requirements
  • Satisfy all 320 assessment objectives
  • Resolve 76% of assessor follow-up requests live 
  • Complete the assessment with zero POA&M items 

RegScale required 28 hours of internal preparation and follow-up support. The DoD’s modeled small-entity baseline estimates 286 hours of director and external-provider labor for assessment preparation and conduct. Measured against that model—not as a direct cost comparison—our internal support burden was 90.2% lower. 

Compliance Done Right 

This is what compliance should look like: a continuously operated, evidence-backed security program that produces a more efficient assessment and a clean certification outcome. 

As the CyberSheath report concludes: 

“Ultimately, full compliance is not a destination or a certificate. It is the ability to consistently demonstrate that cybersecurity controls are operating as intended, that risks are being actively managed, and that leadership can confidently stand behind every compliance assertion the organization makes.” 

That is compliance done right: not paperwork layered on top of security operations, but the evidence-backed result of operating securely and building for resilience. It is how we approach continuous assurance inside RegScale, and it is the outcome we help our customers achieve across frameworks. 

Ready to get started?

Choose the path that is right for you!

Skip the line

My organization doesn’t have GRC tools yet and I am ready to start automating my compliance with continuous monitoring pipelines now.

Supercharge

My organization already has legacy compliance software, but I want to automate many of the manual processes that feed it.