Industrialcyber.Co DIB Organizations Maintain Cybersecurity Commitment Amid CMMC Phase 2 Pause
Article Content
- •78.2% of DIB organizations are pursuing or have achieved CMMC Level 2 certification.
- •75% of respondents value Level 2 certification beyond contract eligibility.
- •75.4% to 84.4% report no change in cybersecurity spending amid the CMMC pause.
A recent Redspin report indicates that despite a temporary pause in the rollout of Cybersecurity Maturity Model Certification (CMMC) Phase 2, a majority of Defense Industrial Base (DIB) organizations are either continuing their certification efforts or have already achieved Level 2 certification. Specifically, 78.2% of surveyed organizations reported ongoing progress toward certification, while 21.9% indicated a slowdown or delay in their efforts. The report highlights that 75% of respondents still see value in achieving Level 2 certification beyond contract eligibility, with many citing independent cybersecurity validation and commitment to protecting Controlled Unclassified Information (CUI) as key reasons. Additionally, 75.4% to 84.4% of organizations reported no change in cybersecurity spending, with increased investment more common than reductions. The findings also reveal that prime contractors continue to influence certification timelines for subcontractors, with only 23.3% relaxing Phase 2 requirements. This suggests a resilient commitment to cybersecurity within the DIB, despite uncertainties surrounding CMMC.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Redspin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What percentage of organizations are still pursuing CMMC certification?
How has the CMMC Phase 2 pause affected cybersecurity spending?
What are the main reasons organizations value CMMC Level 2 certification?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…