# DIB Contractors Continue CMMC Certification

Redspin’s October 1, 2026 survey found that most surveyed Defense Industrial Base organizations are continuing CMMC certification work or have achieved Level 2, while many are maintaining or increasing cybersecurity implementation spending. This continues despite the scheduled pause in CMMC Phase 2 beginning November 10, 2026. The pause does not eliminate applicable DFARS and NIST obligations, and prime contractors may set certification timelines that differ from the federal schedule.

- Contractors should continue applicable DFARS and NIST cybersecurity work and confirm certification deadlines directly with their prime contractors.
- The survey suggests sustained demand for CMMC assessment and cybersecurity implementation services among DIB organizations, including those pursuing or maintaining Level 2 certification.
- Procurement and supplier-management teams can use the findings to inform readiness discussions with subcontractors and avoid assuming that the federal phase pause changes prime-specific expectations.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 01, 2026

### Government Entities
- Department of Defense (DoD)
- National Institute of Standards and Technology (NIST)

### Vendors
- Redspin (Report publisher; CMMC assessment and cybersecurity services provider)

### Sources
- [New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment Even as Some Pause CMMC Efforts](https://www.prnewswire.com/news-releases/new-2026-redspin-report-finds-sustained-dib-cybersecurity-commitment-even-as-some-pause-cmmc-efforts-302895176.html) - PR Newswire
- [New 2026 Redspin Report Finds Sustained DIB Cybersecurity Commitment Even as Some Pause CMMC Efforts](https://www.streetinsider.com/PRNewswire/New+2026+Redspin+Report+Finds+Sustained+DIB+Cybersecurity+Commitment+Even+as+Some+Pause+CMMC+Efforts/27133323.html) - StreetInsider