In the upcoming months, the Cybersecurity Maturity Model Certification (CMMC) will go live. Thousands of third party assessors will begin cybersecurity assessments of hundreds of thousands of U.S. Defense contractors. What will the assessors find?
There has never been a comprehensive, objective assessment conducted of the security posture of the U.S. Defense Industrial Base -- reportedly exceeding 300,000 companies. How is the Defense sector actually doing with respect to cybersecurity? Are there areas of strength? Vulnerability? Common issues among companies? Are improvements possible? If so, how?
By continuously and non-intrusively collecting security performance information across the global Internet, Bitsight can help answer some of these critical questions. For this study, Bitsight analyzed the data of more than 3,500 Department of Defense (DoD) contract holders, many of whom will be subject to the new CMMC requirements. Among the findings from our assessment:
- Defense sector cybersecurity performance is on par with other sectors. In comparing Defense to other sectors, there’s not much difference in the average cybersecurity performance. But should the DoD expect stronger performance given the criticality of the data?
- “Critical” vulnerabilities persist among Defense contractors at high rates. The Defense sector is challenged to remediate “Critical” and “High” vulnerabilities, as measured by the CVSS, raising questions about whether organizations can satisfy certain requirements in the CMMC. Analysis shows that some of the most important vulnerabilities that have been announced by the National Security Agency (NSA) and Department of Homeland Security (DHS) in the last year still persist within the sector. For example, the rate at which the Defense sector remediated the major BlueKeep vulnerability underperforms other sectors.
- Open port exposure puts Defense contractors at risk. Configuration management -- particularly with respect to managing risky Internet exposure through “open ports” -- is a challenge for Defense contractors. In reviewing the Defense contractor cohort, Bitsight finds a large number of open ports that we would characterize as highly risky activity.
- Defense contractors with larger networks underperform contractors with smaller networks. Conventional wisdom is that smaller Defense contractors have weaker security compared to large Defense contractors. But the data suggests there is more to the story. According to Bitsight analysis, on average, Defense contractors who operate larger networks have weaker security performance than contractors who operate smaller networks.
Background
There are reportedly over 300,000 companies that comprise the U.S. Defense Industrial Base (DIB) -- a sector that enables R&D, designs and produces military weapons systems, sustains military operations, delivers technology and support to the warfighter, and many other critical functions.
For years, policymakers and military officials alike have raised deep concern about the cybersecurity posture of the organizations that comprise the DIB, warning that foreign countries and malicious actors are jeopardizing U.S. national security by actively stealing secrets and data. Officials warn that the theft of both classified information and sensitive, unclassified information poses a threat to the United States.
In an effort to gain visibility into the cybersecurity posture of the DIB, the DoD began work in 2019 on the Cybersecurity Maturity Model Certification (CMMC), a program requiring any company doing business with the DoD to have its cybersecurity hygiene assessed by an independent third party assessor. The CMMC is administered by the CMMC-AB, an organization that trains and certifies assessors and collects the data gathered by its assessors. Assessments are performed onsite and are valid for approximately three years. There are also plans to supplement data collected through the assessments with real-time, continuous data collection.
The CMMC is not optional. Required CMMC levels will be specified in each contract, clearly stated in all RFPs, and will be a “go/no go” decision. In other words -- if a company fails to meet the required Level, they can’t win the contract.
Bitsight Analysis of the Defense Sector
Policymakers are hoping that assessors will help the DoD develop a better understanding for the Defense sector’s cybersecurity performance. But what will the assessors find when they go into the market?
Bitsight analyzed the security posture of more than 3,500 DoD contractors to better understand the current state of DIB cybersecurity.
Bitsight continuously collects over 200 billion security events on a daily basis from around the global Internet in an automated, non-intrusive fashion, and leverages this data to create objective research and analytics.
DoD Contractors Perform Similarly to Non-Defense Companies in Other Sectors
The first thing apparent in our analysis is that, overall, U.S. Defense contractor cybersecurity performance actually looks very similar to the performance of other companies and sectors. Bitsight continuously rates organizations on a 250-900 scale, similar to a credit rating model. The lower the score, the greater the likelihood of breach. Bitsight also divides security performance into 3 segments: Basic (250-640), Intermediate (640-740), and Advanced (740-900).
The chart below shows the distribution of security performance across nearly 180,000 companies in all sectors.

When Bitsight reviewed the security posture of a cohort of 3,661 companies that held DoD contracts in FY2019, we found a very similar breakdown in overall security performance, albeit with a slightly smaller percentage of organizations performing at the “Advanced” level and slightly greater percentage of organizations performing at the “Intermediate” level.

Bitsight took a closer look at organizations who possess “Controlled Unclassified Information” -- sensitive but unclassified data that is often a target of malicious actors. Bitsight reduced the broader cohort of 3,661 “DoD contract holders” down to the companies that were most likely to possess CUI data (e.g. aerospace companies, manufacturers, healthcare organizations), leaving us with a cohort of 2,457 companies. These “CUI Likely” companies performed nearly identically to the larger DoD contractor cohort.

Critical Vulnerabilities Persist Within Defense Contractor Ecosystem
CMMC assessors will soon be reviewing the risk and vulnerability management programs of Defense contractors. This is an important area of focus within the CMMC Framework, which includes various requirements for risk and vulnerability management. For example, the Framework requires any organization at Level 2 or higher to develop plans, scan for, and remediate vulnerabilities within their systems. Organizations are also required to monitor security controls for effectiveness.
In an effort to assess the effectiveness of current vulnerability management programs, Bitsight reviewed the “CUI Likely” cohort to understand whether any significant vulnerabilities may be present within this group. Bitsight turned to the Common Vulnerability Scoring System (CVSS), an open framework for communicating the characteristics and severity of software vulnerabilities. Bitsight specifically looked at a number of known “Critical” (CVSS 9.0+) and “High” (CVSS 7.5+) vulnerabilities identified recently by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).





