Report by Redspin

Committed to the Mission: The State of the DIB with CMMC in Flux

13 FINDINGSPublished Oct 1, 2026
View Original Report →

Key Findings

75% of defense contractors say achieving CMMC Level 2 certification provides value beyond contract eligibility.

CMMCDefense

68.8% of defense contractors cite independent cybersecurity validation as a reason achieving CMMC Level 2 provides value.

CMMCCybersecurity ValidationThird-Party AssessmentDefense

58.3% of defense contractors cite improved cyber posture as a reason achieving CMMC Level 2 provides value.

CMMCCyber PostureDefense

78.2% of organizations continue progressing toward CMMC certification or are already Level 2 certified by a third party.

CMMCCertificationDefense

21.9% of organizations delay CMMC certification or significantly slow implementation and certification efforts.

CMMCCertificationDefense

20.3% of organizations paused spending on CMMC certification.

CMMCCertificationDefenseSpending

23.3% of prime contractors relaxed Phase 2 CMMC requirements for their subcontractors.

CMMCDefense

39.5% of prime contractors are still deciding whether to relax Phase 2 CMMC requirements for their subcontractors.

CMMCDefense

76.6% of subcontractors report not receiving any communication from their prime about the Phase 2 pause.

CMMCDefense

10.6% of subcontractors say their prime paused CMMC requirements.

CMMCDefense

100% of organizations that pause spending on NIST SP 800-171 consulting, SOC/SIEM/MSP services, or cloud platforms also pause or slow their CMMC efforts.

NIST SP 800-171Cloud SecurityCMMCDefense

62.5% of defense contractors cite commitment to protecting Controlled Unclassified Information (CUI) as a reason achieving CMMC Level 2 provides value.

CMMCCUI ProtectionDefense

3.1% of organizations decreased spending on CMMC certification.

CMMCSpendingDefense