New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment Even as Some Pause CMMC Efforts

PR Newswire
Today at 2:11pm UTC

New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment Even as Some Pause CMMC Efforts

PR Newswire

Late adopters are most inclined to slow certification progress

NASHVILLE, Tenn., Oct. 1, 2026 /PRNewswire/ -- Redspin, the leader in Cybersecurity Maturity Model Certification (CMMC) services for the Defense Industrial Base (DIB), today released Committed to the Mission: The State of the DIB with CMMC in Flux, its third annual study examining how defense contractors are approaching CMMC, including their investment, existing NIST and DFARS requirements, and their CMMC journey. Conducted in summer 2026, the report gathers feedback from contracting organizations that store, process, and/or transmit Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

Redspin Logo

Findings reveal that the Department's temporary pause of CMMC Phase 2, scheduled to start on November 10, 2026, gave some DIB organizations an opportunity to delay or slow their certification efforts. However, most respondents report continuing their progress toward CMMC certification or having already achieved Level 2, while maintaining or improving their existing Defense Federal Acquisition Regulation Supplement (DFARS) and National Institute of Standards and Technology (NIST)cybersecurity efforts as required under DFARS 252.204-7012, enforced in 2017.

Redspin Vice President and Lead CCA Dr. Thomas Graham noted, "The data shows that yes, the pause gave an opportunity for some organizations to slow their CMMC efforts, but on the other hand many have actually continued moving forward. What is particularly encouraging is that organizations continue to recognize the value of independent, third-party validation. CMMC may be in flux, but DFARS and NIST obligations haven't gone away, and neither has the responsibility to protect CUI."

According to Redspin's research:

  • 75% of respondents say despite the Phase 2 pause, achieving Level 2 certification provides value beyond contract eligibility, with 68.8% citing the value as independent cybersecurity validation, 62.5% citing commitment to protecting CUI, and 58.3% citing improved cyber posture.
  • 78.2% of organizations report continuing their progress toward CMMC certification or already being Level 2 certified by a third party. 21.9% of respondents report delaying certification or significantly slowing their implementation and certification efforts.
  • A majority, 75.4%–84.4% of respondents, report no change in their cybersecurity spend across multiple technologies and lines of effort. Increased spending appears more common than decreased spending in security-related categories, especially implementation efforts, including managed services, cloud infrastructure and services, governance, risk and compliance tools, and NIST/DFARS consulting.

Spending on CMMC certification is seeing some pullback, with 20.3% pausing certification spend and another 3.1% decreasing it. 100% of those pausing spend on NIST 800-171 consulting, security operations center/security information and event management/managed service provider services or cloud platforms also reported pausing or slowing CMMC efforts. Unlike certification spending, these investments support underlying cybersecurity implementation and operations that remain important regardless of the CMMC Phase 2 timeline.

Dr. Graham stated: "The fact that so many DIB organizations continue hardening their cybersecurity posture and making investments is a testament to the value CMMC brings. Even with the third-party certification requirement paused, 75% of respondents still see value in achieving Level 2, and independent cybersecurity validation is one of the top reasons why. Despite DFARS 252.204-7012 being a requirement since 2017, it was the official launch and enforcement of CMMC that lit a fire for many who had neglected their defense posture. This is momentum that continues even with the recent pause."

The data also underscored the role prime contractors will likely continue to play in determining certification timelines for their subcontractors. Only 23.3% of prime contractors (primes) are relaxing requirements for their subcontractors (subs) to meet Phase 2 requirements, with 39.5% more still deciding. 76.6% of subs say they have not received any communication from their prime about the pause, with only 10.6% saying their prime paused CMMC requirements.

"As was the case before the Phase 2 pause, primes are going to play a big role in determining when their subs need to be certified. The phased CMMC timeline is important, but it's not necessarily the only timeline contractors should be watching. If your prime tells you they need a third-party assessment by a certain date, that timeline may matter a lot more to your business," said Dr. Graham. 

Now in its third year, Redspin's annual CMMC research report tracks the DIB's progress and momentum as organizations work toward stronger cybersecurity and CMMC readiness. This year's research spanned several weeks both before and after the Phase 2 pause was announced, providing a unique view into how organizations responded to the change. Following the pause, the survey was adjusted to focus on how DIB companies are approaching cybersecurity, meeting DFARS and NIST security obligations, and conducting CMMC efforts. This year's findings show a DIB that has matured in its approach to cybersecurity, with organizations continuing to invest in the protection of sensitive information critical to our warfighters and their mission.

To download Redspin's full report, please visit https://redspin.com/2026-2027-cmmc-report

About Redspin

Redspin, helps federal agencies and Defense Industrial Base (DIB) organizations strengthen cyber resilience, defend Controlled Unclassified Information (CUI), and meet the cybersecurity requirements of NIST SP 800-171 and DFARS 252.204-7012. As a trusted managed security and compliance partner, we provide cybersecurity consulting, migration, management, and ongoing 24/7 threat detection across GCC High, on-prem, and hybrid cloud environments. Redspin is the long-standing leader for all things CMMC, training, certification, and is a trusted ESP. We help reduce cyber risk, strengthen resilience, and protect the sensitive information critical to national security. To learn more, visit redspin.com.

Committed to the Mission Report Cover

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/new-2026-redspin-report-finds-sustained-dib-cybersecurity-commitment-even-as-some-pause-cmmc-efforts-302895176.html

SOURCE Redspin