Skip to content
DIB Organizations Maintain Cybersecurity Commitment Amid CMMC Phase 2 Pause

DIB Organizations Maintain Cybersecurity Commitment Amid CMMC Phase 2 Pause

First seen 5 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 12:27 UTC
  • •78.2% of DIB organizations are pursuing or have achieved CMMC Level 2 certification.
  • •75% of respondents value Level 2 certification beyond contract eligibility.
  • •75.4% to 84.4% report no change in cybersecurity spending amid the CMMC pause.

A recent Redspin report indicates that despite a temporary pause in the rollout of Cybersecurity Maturity Model Certification (CMMC) Phase 2, a majority of Defense Industrial Base (DIB) organizations are either continuing their certification efforts or have already achieved Level 2 certification. Specifically, 78.2% of surveyed organizations reported ongoing progress toward certification, while 21.9% indicated a slowdown or delay in their efforts. The report highlights that 75% of respondents still see value in achieving Level 2 certification beyond contract eligibility, with many citing independent cybersecurity validation and commitment to protecting Controlled Unclassified Information (CUI) as key reasons. Additionally, 75.4% to 84.4% of organizations reported no change in cybersecurity spending, with increased investment more common than reductions. The findings also reveal that prime contractors continue to influence certification timelines for subcontractors, with only 23.3% relaxing Phase 2 requirements. This suggests a resilient commitment to cybersecurity within the DIB, despite uncertainties surrounding CMMC.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
Redspin report released
Redspin published findings on DIB cybersecurity efforts amid CMMC Phase 2 pause, revealing ongoing commitment.
Prnewswire
2026-10-05
Redspin report highlights DIB cybersecurity status
The report indicates that most DIB organizations are maintaining their cybersecurity investments despite the CMMC Phase 2 pause.
Industrialcyber.Co

More articles in this cluster (3)

Following this threat?

Track Redspin in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What percentage of organizations are still pursuing CMMC certification?
78.2% of surveyed organizations are either continuing their certification efforts or have already achieved Level 2 certification.
How has the CMMC Phase 2 pause affected cybersecurity spending?
75.4% to 84.4% of organizations reported no change in their cybersecurity spending, with many increasing their investments.
What are the main reasons organizations value CMMC Level 2 certification?
Organizations cite independent cybersecurity validation, commitment to protecting CUI, and improved cybersecurity posture as key reasons.