Those who adopt later are most likely to slow down the authentication process.
Nashville, Tennessee, October 1st / PRNewswire / -- The Defense Industrial Base ( DIB ) CMMC service provider Redspin today released the Committed to the Mission : The State of the DIB with CMMC in Flux. This is its third annual study, aimed at examining how defense contractors are advancing CMMC, including their investments, existing NIST and DFARS requirements, as well as the CMMC process. The report, conducted in the summer of 2026, gathered feedback from contracting organizations that store, process, and/or transmit controlled unclassified information ( CUI ) and federal contract information ( FCI ).
The research results show that the temporary suspension of the second phase of CMMC, which was originally scheduled to begin on November 10, 2026, by the Department of Defense, provided some DIB organizations with the opportunity to delay or slow down their certification efforts. However, most respondents indicated that they are still continuing to advance their CMMC certification, or have already obtained Level 2, while maintaining or enhancing their existing compliance with the National Defense Federal Acquisition Regulations Supplement ( DFARS ) and the National Institute of Standards and Technology ( NIST ) cybersecurity requirements under DFARS 252.204-7012. These requirements have been in effect since 2017.
The Vice President and Chief CCA Thomas Graham Doctor stated: "Data shows that, indeed, this pause has given some organizations the opportunity to slow down their CMMC efforts. On the other hand, many organizations are actually continuing to move forward. What is particularly encouraging is that organizations still recognize the value of independent third-party verification. Although CMMC is in a state of change, the obligations of DFARS and NIST have not disappeared, nor has the responsibility to protect CUI."
According to the research of Redspin:
- 75% of the respondents stated that despite the pause in the second phase, the value of obtaining Level 2 certification lies not only in the contractual qualifications. Among them, 68.8% believed its value lies in independent network security verification, 62.5% thought it reflected a commitment to protect CUI, and 58.3% believed it helped to improve the network security situation.
- 78.2% of the organizations stated that they are still continuing to pursue CMMC certification, or have already obtained Level certification through third parties. 21.9% of the respondents indicated that they are delaying the certification process or have significantly slowed down the implementation and certification efforts.
- The majority of respondents, ranging from 75.4% to 84.4%, indicated that their cybersecurity expenditures in various technical and work areas remained unchanged. Compared to reducing spending, increasing expenditures is more common in security-related categories, especially in the implementation of related fields, including managed services, cloud infrastructure and services, governance, risk and compliance tools, as well as NIST / DFARS consulting.
CMMC Certification expenditures have seen a certain decline, with 20.3% of respondents pausing such expenditures, and another 3.1% reducing these costs. Among those who paused expenditures on NIST 800-171 consulting, security operation centers/security information and event management/managed service providers, or cloud platform services, 100% also indicated that they had paused or slowed down related efforts. Unlike certification expenditures, these investments support the implementation and operation of basic network security, and regardless of the schedule for the second phase of CMMC, these investments remain important.
Dr. Graham stated: "The fact that so many DIB organizations continue to strengthen their network security posture and make sustained investments proves the value that CMMC brings. Even though third-party certification requirements have been suspended, 75% of respondents still find obtaining Level to be valuable, with independent network security verification being one of the main reasons. Although DFARS 252.204-7012 has been a requirement since 2017, it is the official launch and implementation of CMMC that has prompted many organizations that previously neglected their defense efforts to take action. This momentum continues even after the recent suspension."
Data shows that main contractors may still play a key role in determining the certification timelines for their subcontractors. Only 23.3% of the main contractors are relaxing the requirements for subcontractors to meet the second-phase criteria, while another 39.5% are still in the process of making decisions. 76.6% of the subcontractors stated that they have not received any communication from their main contractors regarding suspensions, and only 10.6% indicated that their main contractors have suspended the CMMC requirements.
Dr. Graham said, "Just as before the pause in the second phase, the main contractor will play a significant role in deciding when their subcontractors need to complete the certification. The phased CMMC schedule is important, but it may not be the only schedule that contractors need to focus on. If your main contractor tells you that they need to complete a third-party assessment by a certain date, then that schedule may be even more important for your business."
Now entering its third year, the annual CMMC research report of Redspin continues to track the progress and momentum of DIB in strengthening cybersecurity and CMMC preparations. This year's research spanned several weeks before and after the announcement of the pause in the second phase, providing a unique perspective on how organizations responded to this change. After the pause, the focus of the investigation shifted to how DIB companies were advancing cybersecurity, fulfilling their DFARS and NIST security obligations, as well as carrying out CMMC work. This year's results show that DIB's approach to cybersecurity has become more mature, and organizations continue to invest to protect sensitive information that is crucial to our combat personnel and their missions.
To download the complete report for Redspin, please visit: https://redspin.com/2026-2027-cmmc-report
About Redspin
Redspin helps federal agencies and DIB organizations enhance network resilience, protect controlled non-classified information ( CUI ), and meet the cybersecurity requirements of NIST SP 800-171 and DFARS 252.204-7012. As a trusted partner in security and compliance management, we provide cybersecurity consulting, migration, management, and continuous 24/7 threat detection in GCC High environments, local deployments, and hybrid clouds. Redspin has long been a leader in areas such as CMMC, training, and certification, and is also a trusted ESP. We help reduce network risks, enhance resilience, and protect sensitive information that is crucial to national security. For more information, please visit redspin.com.











