New Redspin Study Finds Significant Gap in CMMC Readiness
Research Shows 58 Percent of Defense Supply Chain Members Feel Unprepared for CMMC
Redspin conducted the study in fall of 2024, focusing on members of the defense supply chain known as organizations seeking certification (OSCs). This includes prime contractors, subcontractors, dual-role companies acting as both primes and subs, and External Service Providers (ESPs) to those organizations. Aware but Not Prepared: The State of Defense Industrial Base CMMC Readiness provides first-hand insights from cybersecurity and technical senior leaders in companies selling to the US Department of Defense (DoD).
The report finds that there is still a significant CMMC readiness gap despite CMMC's almost five-year scoping and rulemaking process. According to Redspin's survey:
- 58% of respondents feel they are not ready for a rule that is now final
- 13% of respondents have not taken any preparatory action at all
- 35% of respondents either don't know what they have spent to date on preparing for CMMC or say they have invested nothing or less than 1% of their budgets
Despite challenges, some organizations are reporting positive forward momentum in their CMMC readiness journey:
- Over 50% of respondents indicated that they worked with an ESP, underscoring the value in third-party partnerships
- 75% of respondents have a CMMC-required System Security Plan (SSP) in place or in process. An SSP encapsulates 'the what' of their needed cyber defenses
The study offers insights on additional topics such as supply chain security, the perceived value of CMMC compliance, plans for maintaining CMMC certification, and more.
"After several years in development and with the entire defense industrial base watching, there have been a lot of disparate opinions on CMMC," said
Redspin's team of experts provides end-to-end support, from assessment preparation and training to managed cloud services, certification, and beyond, ensuring OSCs are fully prepared to meet CMMC's requirements. Redspin's report supplies clear evidence that the support of service provider organizations is seen as a valuable tool in not only establishing but maintaining CMMC certification. To view Redspin's full report, please visit: www.redspin.com/aware-but-not-prepared-cmmc-research-report
About Redspin
Redspin, a division of leading cybersecurity and compliance company Clearwater, specializes in enhancing the cyber readiness and resilience of federal and Defense Industrial Base (DIB) organizations. As the first Authorized CMMC 3rd Party Assessment Organization (C3PAO), Redspin provides expert guidance to organizations seeking to minimize cyber risks and protect sensitive information. To learn more, visit www.redspin.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-redspin-study-finds-significant-gap-in-cmmc-readiness-302359801.html
SOURCE Redspin
Serious News for Serious Traders! Try StreetInsider.com Premium Free!
You May Also Be Interested In
- LifeCare Development Announces The Blake at Chattanooga
- FERRERO GROUP 2025 SUSTAINABILITY REPORT SPOTLIGHTS FERRERO FARMING VALUES AS A DRIVER OF RESILIENCE ACROSS SUPPLY CHAINS
- New Oriental to Report Fourth Quarter 2026 Financial Results on July 29, 2026
Create E-mail Alert Related Categories
PRNewswire, Press ReleasesSign up for StreetInsider Free!
Receive full access to all new and archived articles, unlimited portfolio tracking, e-mail alerts, custom newswires and RSS feeds - and more!



Tweet
Share