Back Industrialcyber.Co Redspin finds most DIB organizations maintain CMMC efforts, cybersecurity investment despite Phase 2 pause
A new report from Redspin on cybersecurity across the U.S. Defense Industrial Base (DIB) found that most surveyed organizations continued working toward Cybersecurity Maturity Model Certification (CMMC) Level 2 or had already obtained third-party certification, despite a temporary pause in the program’s Phase 2 rollout. The study found that 78.2% of respondents were continuing certification efforts or had achieved Level 2 certification, while 21.9% reported delaying certification or significantly slowing implementation and assessment activities. The pause provided some defense contractors with an opportunity to reconsider certification timelines, but the findings indicated that cybersecurity commitments across the DIB largely persisted.
Titled ‘ Committed to the Mission: The State of the DIB with CMMC in Flux ,’ the RedSpin report found that 75% of respondents continued to see value in achieving CMMC Level 2 certification beyond contract eligibility, including 68.8% who cited independent cybersecurity validation, 62.5% who pointed to the commitment to protecting Controlled Unclassified Information (CUI), and 58.3% who cited improvements in cybersecurity posture.
Meanwhile, between 75.4% and 84.4% of respondents reported no change in cybersecurity spending across multiple technologies and areas of activity, with increased spending more common than reductions in categories including implementation, managed services, cloud infrastructure, governance, risk and compliance tools, and NIST and Defense Federal Acquisition Regulation Supplement (DFARS) consulting. However, 20.3% reported pausing CMMC certification spending, while another 3.1% reduced it.
Redspin also highlighted continuing influence of prime contractors on certification timelines for subcontractors, despite the Phase 2 pause. Only 23.3% of prime contractors said they were relaxing Phase 2 requirements for subcontractors, while 39.5% were still deciding how to respond. Among subcontractors, 76.6% said they had received no communication from their prime contractor the pause, and 10.6% said their prime had paused CMMC requirements.
“The data shows that yes, the pause gave an opportunity for some organizations to slow their CMMC efforts, but on the other hand many have actually continued moving forward,” Thomas Graham, Redspin vice president and lead CCA, noted in a media statement. “What is particularly encouraging is that organizations continue to recognize the value of independent, third-party validation. CMMC may be in flux, but DFARS and NIST obligations haven’t gone away, and neither has the responsibility to protect CUI.”
“What stood out to me is that among organizations that have slowed their CMMC efforts, many haven’t stopped working on the underlying cybersecurity requirements,” Robert Teague, vice president and lead CCA at Redspin, observed. “That’s encouraging. CMMC may be in flux, but DFARS and NIST obligations haven’t gone away – and neither has the responsibility to protect CUI.”
The report detected that the pause has not stopped CMMC momentum. Nearly eight in 10 organizations are either staying the course toward certification or are already certified. Only 21.9% report delaying certification or significantly slowing their implementation and certification efforts. 46.9% say they are continuing toward 3rd-party certification with no change, while another 31.3% had already achieved Level 2 before the pause and acknowledge its value.
It also identified that the pause has somewhat slowed Level 2 certification spending, but not cybersecurity investment. A majority, 75.4%–84.4% of respondents, report no change in their security spend across multiple technologies and lines of effort. However, CMMC certification is seeing some pullback, with 20.3% pausing their certification spend and another 3.1% decreasing it. At the same time, increased spending appears more common than decreased spending in several security-related categories, including managed services, cloud infrastructure and services, Governance Risk and Compliance (GRC) tools, and NIST/DFARS consulting.
Interestingly, even with the release of the CMMC pause memo, CMMC’s perceived value held up. 75% of respondents still believe achieving Level 2 certification provides value, and not just through Department contract eligibility: 68.8% cite independent cybersecurity validation, 62.5% cite commitment to protecting CUI, and 58.3% cite improved cyber posture as value coming from Level 2. This market isn’t just starting to pay attention. Almost 60% have been working toward NIST 800-171 Rev.2. Protecting CUI clearly predates the current CMMC uncertainty.
Organizations that are continuing as normal and those already Level 2 certified show settled confidence in the value. Those achieving Level 2 see more value, particularly in a few key areas. 79.2% perceive it as independent validation of their cyber posture; 58.3% see it as a competitive differentiator, and 66.7% see value in that the certification meets customer and/ or prime contractor expectations. Interestingly, organizations that are currently implementing controls rate that value higher than those who already achieved Level 2 by 63.9% to 54.2%. This is understandable since organizations that are hardening their security posture are achieving something new and perhaps more fundamental than benefits like competitive differentiation or customer trust.
Of those who are delaying their Level 2 certification efforts, 50% still see value, with the remaining 50% not sure. They are waiting on further Department guidance. For those who have paused or significantly slowed their certification efforts, 50% still see value, but 37.5% do not, with only 12.5% not sure. Beyond uncertainty the Department’s guidance, there is skepticism whether certification is worth it.
The recommendation is to keep moving forward. Organizations should protect the information, because CUI is data that adversaries want and warfighters depend on, and they should keep investing in the people, processes, and protections needed to secure it regardless of where regulatory requirements go . They should also preserve the investment already made in environments, technology, processes, and people, maintaining those as capabilities rather than letting progress erode while policy evolves. Security should be budgeted as a permanent line item rather than a project, since cybersecurity behaves more like insurance or facilities upkeep, a recurring cost that grows if deferred.
Organizations that set aside a defined portion of their annual budget for updates, patching, and workforce training will keep pace with the threat landscape far better, while those that treat the spending as optional will fall behind and pay more to close the gap later.
A paused certification requirement should not be confused with a paused obligation. Level 2 third-party assessment proof may be on hold, but self-attestation under NIST SP 800-171 Rev. 2 and the associated DFARS clauses is still required, and it carries weight whether or not an outside assessor ever reviews it. As past CMMC rulemaking showed, bottlenecks are real. When third-party assessments become required through regulation or by a Prime, organizations that paused will be competing for certified assessors at the same time, and assessor capacity will not expand overnight to meet that surge. Those that keep preparing will be ready to move when demand spikes.
Organizations should also validate their SPRS score before affirming it. The annual affirmation tied to a Supplier Performance Risk System score is a formal representation to the federal government, and an inaccurate score carries exposure under the False Claims Act whether or not a third party ever checks it. Validation should be a standing practice rather than a one-time exercise, confirming that the score still reflects current system configuration and that the supporting documentation would hold up if questioned.
Finally, organizations should stay prepared for what comes . Certification timelines and requirements may change, but those that understand their CUI environment, maintain strong cybersecurity programs, and can demonstrate what they are doing will be better positioned for future requirements, customer expectations, and, most importantly, the threats to U.S. critical infrastructure that continue to emerge.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
