2026 Redspin report finds: DIB continues to invest in network security, despite some companies slowing down the pace of CMMC advancement
PR Newswire
1h ago
Ai Focus
Redspin releases its third annual report stating that despite a pause in the second phase of CMMC, multiple organizations within the defense industry foundation (DIB) are still advancing with certifications or have reached Level and continue to maintain or increase their investments in cybersecurity related to DFARS and NIST. The report also indicates that some companies have paused or slowed down their certification expenditures, but overall, the implementation and operational investments in basic cybersecurity remain stable.
Helpful
No.Help

Those who adopt later are most likely to slow down the authentication process.

Nashville, Tennessee, October 1st / PRNewswire / -- The Defense Industrial Base ( DIB ) CMMC service provider Redspin today released the Committed to the Mission : The State of the DIB with CMMC in Flux. This is its third annual study, aimed at examining how defense contractors are advancing CMMC, including their investments, existing NIST and DFARS requirements, as well as the CMMC process. The report, conducted in the summer of 2026, gathered feedback from contracting organizations that store, process, and/or transmit controlled unclassified information ( CUI ) and federal contract information ( FCI ).

The research results show that the temporary suspension of the second phase of CMMC, which was originally scheduled to begin on November 10, 2026, by the Department of Defense, provided some DIB organizations with the opportunity to delay or slow down their certification efforts. However, most respondents indicated that they are still continuing to advance their CMMC certification, or have already obtained Level 2, while maintaining or enhancing their existing compliance with the National Defense Federal Acquisition Regulations Supplement ( DFARS ) and the National Institute of Standards and Technology ( NIST ) cybersecurity requirements under DFARS 252.204-7012. These requirements have been in effect since 2017.

The Vice President and Chief CCA Thomas Graham Doctor stated: "Data shows that, indeed, this pause has given some organizations the opportunity to slow down their CMMC efforts. On the other hand, many organizations are actually continuing to move forward. What is particularly encouraging is that organizations still recognize the value of independent third-party verification. Although CMMC is in a state of change, the obligations of DFARS and NIST have not disappeared, nor has the responsibility to protect CUI."

According to the research of Redspin:

  • 75% of the respondents stated that despite the pause in the second phase, the value of obtaining Level 2 certification lies not only in the contractual qualifications. Among them, 68.8% believed its value lies in independent network security verification, 62.5% thought it reflected a commitment to protect CUI, and 58.3% believed it helped to improve the network security situation.
  • 78.2% of the organizations stated that they are still continuing to pursue CMMC certification, or have already obtained Level certification through third parties. 21.9% of the respondents indicated that they are delaying the certification process or have significantly slowed down the implementation and certification efforts.
  • The majority of respondents, ranging from 75.4% to 84.4%, indicated that their cybersecurity expenditures in various technical and work areas remained unchanged. Compared to reducing spending, increasing expenditures is more common in security-related categories, especially in the implementation of related fields, including managed services, cloud infrastructure and services, governance, risk and compliance tools, as well as NIST / DFARS consulting.

CMMC Certification expenditures have seen a certain decline, with 20.3% of respondents pausing such expenditures, and another 3.1% reducing these costs. Among those who paused expenditures on NIST 800-171 consulting, security operation centers/security information and event management/managed service providers, or cloud platform services, 100% also indicated that they had paused or slowed down related efforts. Unlike certification expenditures, these investments support the implementation and operation of basic network security, and regardless of the schedule for the second phase of CMMC, these investments remain important.

Dr. Graham stated: "The fact that so many DIB organizations continue to strengthen their network security posture and make sustained investments proves the value that CMMC brings. Even though third-party certification requirements have been suspended, 75% of respondents still find obtaining Level to be valuable, with independent network security verification being one of the main reasons. Although DFARS 252.204-7012 has been a requirement since 2017, it is the official launch and implementation of CMMC that has prompted many organizations that previously neglected their defense efforts to take action. This momentum continues even after the recent suspension."

Data shows that main contractors may still play a key role in determining the certification timelines for their subcontractors. Only 23.3% of the main contractors are relaxing the requirements for subcontractors to meet the second-phase criteria, while another 39.5% are still in the process of making decisions. 76.6% of the subcontractors stated that they have not received any communication from their main contractors regarding suspensions, and only 10.6% indicated that their main contractors have suspended the CMMC requirements.

Dr. Graham said, "Just as before the pause in the second phase, the main contractor will play a significant role in deciding when their subcontractors need to complete the certification. The phased CMMC schedule is important, but it may not be the only schedule that contractors need to focus on. If your main contractor tells you that they need to complete a third-party assessment by a certain date, then that schedule may be even more important for your business."

Now entering its third year, the annual CMMC research report of Redspin continues to track the progress and momentum of DIB in strengthening cybersecurity and CMMC preparations. This year's research spanned several weeks before and after the announcement of the pause in the second phase, providing a unique perspective on how organizations responded to this change. After the pause, the focus of the investigation shifted to how DIB companies were advancing cybersecurity, fulfilling their DFARS and NIST security obligations, as well as carrying out CMMC work. This year's results show that DIB's approach to cybersecurity has become more mature, and organizations continue to invest to protect sensitive information that is crucial to our combat personnel and their missions.

To download the complete report for Redspin, please visit: https://redspin.com/2026-2027-cmmc-report

About Redspin

Redspin helps federal agencies and DIB organizations enhance network resilience, protect controlled non-classified information ( CUI ), and meet the cybersecurity requirements of NIST SP 800-171 and DFARS 252.204-7012. As a trusted partner in security and compliance management, we provide cybersecurity consulting, migration, management, and continuous 24/7 threat detection in GCC High environments, local deployments, and hybrid clouds. Redspin has long been a leader in areas such as CMMC, training, and certification, and is also a trusted ESP. We help reduce network risks, enhance resilience, and protect sensitive information that is crucial to national security. For more information, please visit redspin.com.

Tip
$0
Like
0
Save
0
Views 13
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
In September, the US ISM manufacturing index continued to expand, but it fell for two consecutive months, and cost pressures surged. The S&P index turned down, and long-term bonds came under pressure.
In September, the U.S. ISM Manufacturing Index fell slightly from 54.6 in August to 54.5, showing a decline for two consecutive months but remaining in an expansionary range for nine straight months; new orders, backlogs, and employment improved, while the price index rose to 77.9, reaching a four-month high, indicating that cost pressures have significantly increased. Following the release of the data, U.S. stocks turned down, and U.S. long-term bonds came under pressure.
Wallstreetcn
·2026-10-01 23:47:39
5
Thomson Reuters Completes Joint Venture in Global Printing Business with KKR
Thomson Reuters announces the completion of the transaction previously announced to sell the majority of its global printing business to the advisory capital account of KKR. This business is now operated under Westbridge Print, and Thomson Reuters states that this move will allow the company to focus more on AI solutions in the areas of law, taxation, auditing, and compliance.
PR Newswire
·2026-10-01 23:47:35
8
Brian Chesky: AI Agents need their own operating system
Airbnb, co-founder and CEO, stated that the company's newly launched AI search is just the beginning; chatbots are not suitable for travel discovery or e-commerce browsing. Chesky believes that in the future, AI will require a richer, more collaborative interface, and applications should also be more “agentic”, with the ultimate goal of achieving interoperability between different agents.
TechCrunch
·2026-10-01 23:36:22
9
Bitcoin price faces a resistance wall of $90,000; large-scale selling orders are piling up – what will happen next?
After a strong rebound, the price of Bitcoin has been consolidating, currently hovering around $83,700. There is significant selling pressure above the range of $85,000 to $90,000. The article states that liquidation, large-scale selling orders by whales (large traders), and technical levels together constitute key resistance. If the price breaks through this range, it could open up further upside potential; if it encounters resistance, consolidation or a pullback may continue.
Coinpedia
·2026-10-01 23:36:21
9
HP Launches the Ryzen-powered Workstation AI Starting at 14,599 Yuan
According to the report from IT, HP has officially released the Ryzen-powered AI high-performance mobile workstation, which will go on sale on the evening of October 12th, starting at a price of 14,599 yuan. The highest configuration features a Ryzen 9 9955HX3D paired with RTX PRO 2000, priced at 21,999 yuan.
The Block
·2026-10-01 23:16:30
14
View More