
Redspin's 2026 Report Shows Most Defense Contractors Maintained CMMC Efforts and Cybersecurity Spend After the Phase 2 Pause
A new report from Redspin on the state of the U.S. Defense Industrial Base (DIB) found that nearly 8 in 10 surveyed contractors continued working toward CMMC Level 2 or had already obtained third-party certification despite the pause in the program’s rollout.
This finding came from the third annual edition of Redspin’s survey of defense contractors published on October 1, 2026, Committed to the Mission: The State of the DIB with CMMC in Flux. Fieldwork ran through the summer of 2026 and spanned the weeks before and after the July 13 pause to assess how the Defense Industrial Base (DIB) actually reacted when the Department of War (DoW) paused the transition to CMMC Phase 2.
The major takeaway is that the pause led to some contractors slowing down their certification efforts, but most did not. That’s because contractors are seeing the value of CMMC Level 2 certification beyond contract-eligibility, and because primes are determining when most subcontractors need to be certified, not the DoW.
Takeaway 1: Three-quarters of DIB remain committed to CMMC
The central finding is that most contractors did not stop their momentum around CMMC or cybersecurity more broadly.
Redspin reports that 78.2% of respondents are either continuing toward certification or already hold a third-party CMMC Level 2 certificate, while only 21.9% have delayed or significantly slowed their work on Level 2 certification.
Three quarters still believe achieving Level 2 certification provides value to their organization regardless of the pause, citing independent cybersecurity validation of our cybersecurity program (68.8%) and demonstrates our commitment to protecting controlled unclassified information (CUI) (62.5%) above contract-eligibility. Only 15.6% were not sure, and 9.4% said no.

Contractors that already hold Level 2 certification rated some of these benefits even higher. Among that group, 79.2% cited independent validation, 66.7% said certification meets customer or prime expectations, and 58.3% called it a competitive differentiator.
Redspin argues that this shows the DIB is finally recognizing the importance of cybersecurity, which is why the Phase 2 pause is not changing most organizations’ approach to CMMC:
Takeaway: The pause did not reset the market because contract eligibility is only one reason contractors pursue Level 2. Nearly eight in 10 respondents are still working toward Level 2 certification or already certified, which means a contractor who stopped in July is now behind most of its peers. A C3PAO certificate is the highest level of assurance a contractor can provide to a prime or customer that its security program works, and that value does not depend on the DoW's rollout schedule.
Takeaway 2: The quarter of contractors that slowed down are still doing cybersecurity, but spending less
Of the 21.9% that have delayed or significantly slowed their work on CMMC Level 2 certification, most are still focused on the underlying requirements. Half say they are actively implementing or improving NIST controls and 37.5% are doing self-assessments and maintaining accurate SPRS scores.
That matters because the pause only touched third-party certification. DFARS 252.204-7012 has required NIST SP 800-171 implementation since 2017, and DoW memo 26-P-1023 did not change that. Redspin's own recommendations make the same point: a paused certification requirement is not a paused obligation, and an inaccurate SPRS score carries exposure under the False Claims Act whether or not an assessor ever checks it.
The biggest difference is spend. Among those that paused or significantly slowed their efforts, only 12.5% said they are still investing in cybersecurity technologies, personnel, and processes to protect CUI. Redspin reads this as contractors maintaining compliance with what they already have rather than spending anything new during the pause.
Cost is the major reason that contractors in this group are also the most skeptical about the value of CMMC certification. While 50% still see value in Level 2, 37.5% do not. Respondents who said Level 2 certification does not still provide value pointed to costs and uncertainty:
- Implementation costs outweigh the benefits (100%)
- Assessment costs outweigh the benefits (83.3%)
- The future of the CMMC program is too uncertain (66.7%)
Takeaway: Slowing down on third-party certification is a defensible business decision. Letting DFARS 7012 compliance or SPRS accuracy drift is not, because those underlying cybersecurity obligations (and the threats those obligations were designed to defend against) never paused.
Recommended reading
SPRS Scoring: How to Get a Current CMMC Status and Stay Eligible for Defense Contracts
Takeaway 3: Most defense contractors have invested 2 years and $100K in CMMC already
Almost 60% (59.4%) of post-pause respondents have spent more than two years implementing NIST SP 800-171 Rev 2, the cybersecurity standard behind CMMC Level 2.
The same share (59.4%) report spending more than $100,000 on CMMC to date.
Redspin found that those who have invested the most are also the most likely to stay the course toward certification. Contractors that already achieved Level 2 show the highest spend, with 45% having spent between $101,000 and $250,000 and 15% spending more than $500,000.
Contractors pausing certification spend skew the other way: 62.5% have spent under $100,000, and none reported spending more than $250,000.
The survey also reinforces where the bulk of “CMMC” budgets actually go. "The assessment was actually the least expensive part of our CMMC journey," said Erin Wright, Compliance Officer at ATC Manufacturing, pointing to implementation and ongoing maintenance as the larger costs.
Takeaway: For most contractors, the cost of CMMC is already sunk into implementation of the underlying cybersecurity requirements. Stopping now saves the smallest line item, the assessment, while putting the larger investment at risk of eroding.
Recommended reading
The True Cost of CMMC 2.0
Takeaway 4: The pause mostly did not change cybersecurity spending
Spending held even more consistently than certification activity. Between 75.4% and 84.4% of respondents reported no change in cybersecurity spend across categories. For those that reported changes, increases actually outnumbered decreases or pauses in managed services, cloud infrastructure, GRC tooling, and NIST and DFARS consulting.
CMMC certification is the one clear area of pullback, with 20.3% pausing that spend and another 3.1% decreasing it.
Redspin also found that every respondent pausing spend on NIST SP 800-171 consulting, managed security services, or cloud platforms came from the group that paused or slowed CMMC, so for that segment the cuts go beyond certification.
Not every pause signals less commitment though: all respondents decreasing cloud spend and 44% of those pausing security hiring had already achieved Level 2 certification, which Redspin attributes to post-certification optimization rather than belt-tightening as a result of the pause.
Takeaway: The market is separating certification spend from security spend. Contractors that are deferring the CMMC assessment are continuing to invest in the controls, tooling, and services that an assessment would eventually evaluate.
Takeaway 5: Primes, not the DoW rollout timeline, will set the pace for subcontractors
The survey also suggests that primes, rather than the program timeline, will set the pace for many subcontractors pursuing certification. Only 23.3% of prime contractors said they are relaxing Phase 2 expectations for their suppliers and 39.5% are still deciding, while 76.6% of subcontractors reported hearing nothing at all from their prime about the pause.
Put together, more primes are holding the line on third-party assessments (37.2%) than relaxing them (23.3%), and only about one in 10 subcontractors has been told requirements are paused. That matches what primes and other industry stakeholders have said publicly. Elbit America told its suppliers to stay the course days after the suspension, and the Cyber AB noted at its April 2026 Town Hall that DoW implementation timelines are not the same as prime contractor deadlines.
Redspin's Dr. Thomas Graham put it plainly in the report announcement: "If your prime tells you they need a third-party assessment by a certain date, that timeline may matter a lot more to your business [than the DoW’s phased CMMC timeline]."
Redspin also flags a capacity risk. When third-party assessments become required again, whether by regulation or by a prime, contractors that paused will be looking for a C3PAO at the same time, and assessor capacity will not expand overnight.
Takeaway: Silence from a prime is not a pause. With 39.5% of primes still deciding, subcontractors that wait for guidance risk receiving a deadline with less runway than they need, at the same moment as every other supplier in that prime's chain.
Recommended reading
The 5 Prime Contractors Leading CMMC Enforcement Ahead of the Phased Rollout
What defense contractors should do now
The Redspin data points to the same conclusion as the DoW memo and the prime notices: certification timing is uncertain, but the obligations underneath it are not. If you handle CUI, here is where to focus your efforts and spending.
- Keep implementing NIST SP 800-171 Rev 2. DFARS 7012 still requires it, and the 110 requirements are what any future assessment will test. Use a gap analysis to see where you actually stand.
- Validate your SPRS score before you affirm it. Confirm the score reflects your current environment and that your evidence would hold up if questioned. An inflated self-assessment is a False Claims Act risk with or without a C3PAO.
- Ask your prime directly. Do not treat silence as relief. Ask each prime, in writing, whether its third-party assessment expectations or dates have changed.
- Keep your documentation current. Your System Security Plan (SSP), plan of action and milestones (POA&M), and supporting evidence should describe your environment as it exists today, not as it existed when you last prepared for an assessment.
- Confirm your CUI boundary. If your environment or vendors changed since you last scoped, revisit scoping and your CUI boundary before it becomes an assessment finding.
- Budget security as a recurring line item. Certification is a point in time; compliance is continuous. Plan for patching, monitoring, training, and evidence upkeep every year, whether or not an assessment is on the calendar.
- Keep your assessment path open. If you are close to ready, stay in contact with your C3PAO or consider getting on a calendar now rather than competing for capacity later.
Not sure where your gaps are? Download the free CMMC Level 2 compliance checklist to walk through all 110 requirements, or check your CMMC readiness in a few minutes with our free gap assessment tool.
Recommended reading
CMMC News 2026: Every Program Update, Rule Change & Enforcement Action
About the survey
Redspin collected 131 responses in July and August 2026, split equally between a stage one survey fielded before the July 13 pause and a revised stage two survey fielded after it. The report focuses on post-pause responses and draws pre-pause comparisons where relevant. Respondents were cybersecurity and technical managers or leaders at companies selling to the DoW, and seven in 10 work at organizations with fewer than 500 employees, so the findings largely reflect small and mid-sized contractors.
By company role, 50.8% of respondents act as both prime and subcontractor, 24.6% are subcontractors or suppliers, 16.9% are primes, and 7.7% are service providers. Redspin, a C3PAO and CMMC services provider, sponsored the survey.
FAQs
According to Redspin's 2026 CMMC report, 21.9% of respondents delayed or significantly slowed their CMMC certification work after the July 13, 2026 pause. The remaining 78.2% are either continuing toward third-party certification (46.9%) or already held Level 2 certification before the pause (31.3%).
No. The pause applied to the Phase 2 requirement for third-party Level 2 assessments. DFARS 252.204-7012 and its NIST SP 800-171 requirements remain in effect, and contractors still submit and affirm SPRS scores. See the CMMC enforcement news tracker for current status.
It depends on the prime. Redspin found that only 23.3% of primes are relaxing third-party assessment expectations for suppliers, 37.2% still plan to require them, and 39.5% have not decided. Subcontractors should confirm requirements with each prime directly rather than assume the DoW pause applies to their contracts.