CMMC Articles & Mentions
The latest CMMC news articles and announcements from Redspin.

Redspin finds most DIB organizations maintain CMMC efforts, cybersecurity investment despite Phase 2 pause
Titled ‘Committed to the Mission: The State of the DIB with CMMC in Flux,’ the RedSpin report found that 75% of respondents continued to see value in achieving CMMC Level 2 certification beyond contract eligibility.
For Cybersecurity Certification, a Pause is Not a Pass
The government’s implementation timeline may be under review, but the underlying cybersecurity obligations, contractual requirements and business pressures facing the defense industry have not disappeared.
DIB Organizations Continue CMMC Efforts Despite Phase 2 Pause
Redspin’s third annual DIB cyber survey finds most respondents are continuing toward Level 2 certification or have already achieved it, while cybersecurity spending largely remains unchanged.
New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment Even as Some Pause CMMC Efforts
Late adopters are most inclined to slow certification progress.
What is defending our warfighters actually worth?
Stacy Bostjanick, a former DoD executive and Tara Lemieux, an Army veteran, electronic warfare signals intelligence officer, explain why CMMC needs to continue while Rob Teague shares the issue with SMBs tackling additional requirements to contract.
CMMC assessment firms face cuts, delayed audits as defense contractors await potential program changesCMMC assessment firms face cuts, delayed audits as defense contractors await potential program changes
The Pentagon’s decision to pause phase two of the CMMC program has resulted in workforce cuts at some assessment firms and contractors delaying their assessments, as the defense industrial base awaits the results from an internal review of the initiative.
CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn’t.
A Cybersecurity Maturity Model Certification Reform Task Force has until September 13 to report to the Department of
War’s CIO.
CMMC assessment organizations highlight potential program changes to increase capacity
Third party assessment organizations are urging the Pentagon to make changes to requirements for assessors and the clearance process under the CMMC, as the Defense Department considers options to increase capacity during a review of the initiative.
Future of Pentagon Cybersecurity Program Thrown into Question
The ongoing pause and review of CMMC puts the fate of the program — and the assessment organizations planning to certify contractors’ cybersecurity posture — into doubt…
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
Industry professionals, including our very own Ned Butler and Rob Teague weigh in on the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI
BREAKING: Pentagon’s CMMC Pause Draws Praise, Criticism from Industry
The Defense Department on July 13 suspended the Phase 2 requirements for its Cybersecurity Maturity Model Certification program and initiated a review of the effort, drawing both praise and criticism from experts.
What the Pentagon’s new post-quantum cryptography directive means for defense contractors
The Defense Department wants to introduce PQC requirements into the CMMC program, but experts warn industry and the underlying technology is far from ready.
The real reason CMMC costs are shocking companies
Redspin’s Thomas Graham breaks down why CMMC costs are catching many DoD contractors off guard, explaining that the real financial burden stems from years of delayed cybersecurity compliance, not the certification itself.
Pentagon Needs More CMMC Third-Party Assessors to Increase Compliance Rates, Slash Waits & Costs—Experts Weigh In
Thomas Graham discusses assessment demand, costs, readiness timelines, and the rigor of CMMC assessments.
Rev. 3 is coming – Start preparing for the next CMMC requirement
The entire DIB must remember that CMMC compliance is a continual journey that is necessary to protect our warfighters and our nation.
Redspin’s Managed Security Services Achieve Perfect Score in CMMC Level 2 Assessment
Independent Third‑Party Validation Reinforces Redspin as a Trusted External Service Provider (ESP) for the Defense Industrial Base
Disruptive By Design: The Lie We Tell Ourselves About Cybersecurity Ownership
Organizations instinctively assign complete cybersecurity ownership to information technology (IT). Multifactor authentication, phishing drills, security awareness training and virtual private networks are all visible markers of a “serious” program, and they all live within the IT function.
Clearwater Ranked #36 on MSSP Alert’s 2025 Top Global MSSPs List
New Redspin Report finds lagging execution despite increased CMMC awareness.
CMMC enforcement begins with mixed industry readiness
A new survey finds two-thirds of contractors prepared for the cybersecurity certification over many years, while nearly 40% have not yet completed required self-assessments.
Report: CMMC Momentum Grows, Execution Lags
One week into the Pentagon’s effort to move its cybersecurity compliance program from policy to practice, adoption of the CMMC program is gaining momentum, but execution remains slow, according to a new industry survey.

Subscribe to our newsletter
Securing The Nation's Defense Industrial Base
Get started with Redspin Today
Helping you navigate CMMC.

















