Only 38% of organizations over 20,000 employees actively pursuing CMMC 2.0 certification achieve top-tier encryption (76-100% coverage).
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseEncryptionCMMC 2.0
51% of all organizations actively pursuing CMMC 2.0 certification managing international data flows report increased complexity in policy development and control implementation.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseCMMC 2.0
Organizations without governance tracking show 5 percentage points higher rates of low-encryption outcomes (20% vs. 15%).
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseGovernanceGovernance tracking
11% of organizations actively pursuing CMMC 2.0 certification are in Europe.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseEncryptionCMMC 2.0
Only 56% of organizations have fully implemented end-to-end encryption for all sensitive data.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseEncryption
While 95% of organizations actively pursuing CMMC 2.0 certification track some governance tracking effectiveness metrics, only 38% have instituted comprehensive governance control and tracking systems.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseGovernanceGovernance tracking
Vendor compliance ranks as the second-highest challenge for the organizations actively pursuing CMMC 2.0 certification (scoring 73 out of 100).
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseVendor complianceCMMC 2.0
39% of organizations actively pursuing CMMC 2.0 certification cite vendor compliance as a top concern. This is 7 percentage points higher than non-CMMC organizations.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseVendor complianceCMMC 2.0
Only 22% of organizations actively pursuing CMMC 2.0 certification implement contractual security requirements with suppliers. This is below the 27% industry average.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseCMMC 2.0
The challenge of data inventory accuracy affects 27% of organizations actively pursuing CMMC 2.0 certification. It ranks sixth among seven key challenges.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseCMMC 2.0
20% of organizations actively pursuing CMMC 2.0 certification are in Asia-Pacific.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseCMMC 2.0Asia-Pacific
7% of organizations actively pursuing CMMC 2.0 certification are in Middle East/Africa.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseCMMC 2.0Middle EastAfrica
Just over half of organizations have centralized governance processes.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025
DefenseGovernance
63% of organizations actively pursuing CMMC 2.0 certification are in North America.
KiteworksBlind Spots Exposed: Navigating AI, Third-Party Risks, and Compliance in 2025 ·Sep 9, 2025