New Redspin Report Finds Lagging Execution Despite Increased CMMC Awareness
Data Shows Thorough Preparation Makes Significant Difference in Achieving Certification at First Formal Assessment
The report finds that CMMC adoption is gaining momentum, but execution is slow. According to Redspin's survey:
- A successful CMMC journey takes time. 68% of respondents report that preparing for CMMC has taken them over a year to date
- Concerns remain with assessment readiness and scheduling. Nearly 37% of respondents are not scheduled for a CMMC assessment at all or are unsure of their next steps
-
Preparation has been costly. 26% of respondents report spending between
$100,000-$250,000 , and 31% report spending more than$250,000 , to date - Level 2 "enforcement" is already happening organically. 47% of those surveyed have received flow-down requests from primes already
Momentum, but Slow Movement: The State of DIB CMMC Readiness helps DIB members assess their CMMC standing against peer organizations and offers insights into helpful practices for those still in the initial CMMC process. Redspin conducted the study in late summer 2025, focusing on feedback from DoD contractor organizations that store, process and/or transmit Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).
Despite the slow movement for some, significantly more organizations than in the 2024 study are reporting good progress on their CMMC readiness:
- Over half of respondents (54%) say their starting point was already having a strong implementation of NIST 800-171 standards and DFARS controls when beginning their CMMC journey
- Cloud service providers (CSPs) are playing a key role in supporting CMMC compliance. Over half (53%) of respondents are already using a CSP to minimize their CMMC scope, with another 14% considering it for the future
- Training up staff on cybersecurity has increased significantly (60%) since last year (37%), indicating that respondents see a need to better educate and prepare their people
The report also highlights what organizations should be aware of when it comes to next steps of CMMC certification. Once certification is achieved, it needs to be sustained.
"
CMMC has officially moved from policy to practice. Redspin's team of experts remain committed to guiding hundreds of DIB companies through every stage of readiness and certification to protect the nation's critical data and sensitive information. To download Redspin's full report, please visit redspin.com/annualreport
About Redspin
Redspin, a division of leading cybersecurity and compliance company Clearwater, specializes in enhancing the cyber readiness and resilience of federal and Defense Industrial Base (DIB) organizations. As the first Authorized CMMC 3rd Party Assessment Organization (C3PAO), Redspin provides expert guidance to organizations seeking to minimize cyber risks and protect sensitive information.
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-redspin-report-finds-lagging-execution-despite-increased-cmmc-awareness-302617493.html
SOURCE Redspin
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- WISEcode® Sets Out to Transform the Food Industry, Ushering In the Era of FoodTruth™
- Sultan Bin Ahmed Attends Media Master's Graduation in Spain
- VEVOR Launches "VEVOR Gameday Houston Giveaway" Bar Activation Across 10 Houston Venues for 2026 tournament
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share