# Defense Contractors Pursue CMMC Certification

A cybersecurity roundup covering September 28–October 4 highlighted persistent security weaknesses with implications for federal suppliers: 90% of open critical and high-severity vulnerabilities in the analyzed organizations had remained exposed for more than 90 days. The roundup also cited AI identity and access-control weaknesses and gaps in healthcare data governance. In the Defense Industrial Base, most organizations surveyed were continuing toward or had achieved third-party CMMC Level 2 certification, while about one in five were delaying or slowing their efforts. The signals describe security and readiness conditions, not a new procurement, award, or policy change.

- DIB contractors and procurement teams can use the reported certification progress and delays to assess supplier readiness and potential qualification risks in their supply chains.
- The vulnerability backlog statistic points to a practical due-diligence concern: evaluate how prospective suppliers identify, prioritize, and remediate long-standing critical and high-severity exposures.
- Cybersecurity providers may find demand for vulnerability remediation, identity and access-control improvements, and healthcare data-governance support; the roundup does not identify specific solicitations or contract opportunities.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity
**Published:** October 07, 2026

### Vendors
- Redspin ()
- Microsoft ()
- Delinea ()
- Cisco ()
- Netwrix ()

### Key Quotes
> 90% of open critical and high-severity vulnerabilities have been exposed for more than 90 days across the organizations analyzed.
> — Original poster

### Sources
- [Cybersecurity statistics of the week (September 28th - October 4th)](https://www.reddit.com/r/cybersecurity/comments/1x03hff/cybersecurity_statistics_of_the_week_september) - reddit-cybersecurity