New Report by Kiteworks and Coalfire Reveals Significant Gaps in CMMC 2.0 Preparedness Across Defense Industrial Base

March 26, 2025 05:30 PM IST | By EIN Presswire
 New Report by Kiteworks and Coalfire Reveals Significant Gaps in CMMC 2.0 Preparedness Across Defense Industrial Base
Image source: EIN Presswire

Less than half of DIB contractors ready for certification as compliance deadline approaches

These findings should serve as a wake-up call for the Defense Industrial Base.”
— Frank Balonis, CISO and SVP of Operations at Kiteworks
SAN MATEO, CA, UNITED STATES, March 26, 2025 /EINPresswire.com/ -- Kiteworks, which empowers organizations to effectively manage risk in every send, share, receive, and use of private data, and Coalfire, a global services and solutions company specializing in advisory, assessment, and cybersecurity, released today a comprehensive report titled “State of CMMC 2.0 Preparedness in the DIB,” that reveals critical readiness gaps among defense contractors as they work toward Cybersecurity Maturity Model Certification (CMMC) 2.0 compliance.

The report findings indicate that despite approaching deadlines, a majority of Defense Industrial Base (DIB) contractors are significantly behind in their preparedness efforts. Only 46% of organizations surveyed reported being ready to seek CMMC 2.0 Level 2 certification, while 57% have yet to complete a thorough gap analysis against NIST SP 800-171 requirements. The report surveyed 209 senior leaders from DIB organizations—which was conducted by third-party survey provider Centiment—on their CMMC 2.0 Level 2 readiness.

“These findings should serve as a wake-up call for the Defense Industrial Base,” said Frank Balonis, CISO and SVP of Operations at Kiteworks. “With nearly half of contractors lacking a detailed Plan of Action and Milestones to address compliance gaps, and over one-third operating without comprehensive policies for Controlled Unclassified Information protection, the DIB faces substantial cybersecurity vulnerabilities that put sensitive defense information at risk.”

The report highlights several concerning trends:
- Only 44% of DIB contractors have implemented continuous monitoring for systems within the scope of CMMC 2.0 Level 2 compliance.
- Less than 53% have fully implemented required access control measures across all relevant systems.
- Over 30% lack advanced controls to ensure third parties can only access CUI to which they are authorized.
- More than 30% do not enforce multi-factor authentication across all systems processing or storing sensitive data.

Technical implementation challenges represent the greatest perceived obstacle to achieving compliance, cited by 44% of respondents, followed closely by budgetary and resource constraints at 43%.

“The complexity of CMMC 2.0 requirements is driving organizations to seek expert guidance, with nearly 80% of DIB contractors engaging third-party consultants, Registered Provider Organizations, or C3PAOs," said Tom McAndrew, CEO at Coalfire. "As an advisory services provider and an authorized C3PAO, we're witnessing firsthand how critical expert assessment and implementation guidance is for organizations navigating these complex requirements.”

While the compliance landscape appears challenging, the report also outlines pathways to accelerate readiness. Kiteworks' Private Content Network solution helps organizations satisfy up to 90% of the 110 controls required for CMMC 2.0 Level 2 certification, providing a comprehensive approach to securing sensitive defense information across communication channels. Meanwhile, Coalfire's C3PAO certification services offer the expert assessment and validation needed to achieve and maintain compliance.

“The path to CMMC 2.0 compliance doesn't need to be overwhelming,” added Balonis. “With the right technology solutions and expert guidance, DIB contractors can efficiently implement the necessary controls while strengthening their overall security posture against evolving threats.”

The full report, “State of CMMC 2.0 Preparedness in the DIB,” can be downloaded at https://www.kiteworks.com/cmmc-preparedness-dib-report.

Findings from the report will be discussed in-depth in a roundtable on April 2 at 10 AM PST | 1 PM EST featuring subject-matter experts from Kiteworks and Coalfire. Register to attend the roundtable.


About Kiteworks
Kiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive, and save of sensitive content. The Kiteworks platform provides customers with a Private Content Network that unifies, tracks, controls, and secures sensitive content moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all sensitive content communications. Headquartered in Silicon Valley, Kiteworks protects over 100 million end users for over 35,000 global enterprises and government agencies.

About Coalfire
Coalfire, headquartered in Denver, Colorado, is a global services and solutions company specializing in advisory, assessment, and cybersecurity. The company develops cutting-edge technology platforms that automate defenses against security threats for the world’s leading enterprises, cloud providers, and SaaS companies. Coalfire is the foremost provider of FedRAMP compliance assessments and penetration testing services in the United States.

David Schutzman
Kiteworks
+1 203-550-8551
email us here
Visit us on social media:
Facebook
X
LinkedIn
YouTube

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations and video (Content) is a service of Kalkine Media Limited, Company No. 12643132 (“Kalkine Media, we or us”) and is available for personal and non-commercial use only. Kalkine Media is an appointed representative of Kalkine Limited, who is authorized and regulated by the FCA (FRN: 579414). The non-personalized advice given by Kalkine Media through its Content does not in any way endorse or recommend individuals, investment products or services suitable for your personal financial situation. You should discuss your portfolios and the risk tolerance level appropriate for your personal financial situation, with a qualified financial planner and/or adviser. No liability is accepted by Kalkine Media or Kalkine Limited and/or any of its employees/officers, for any investment loss, or any other loss or detriment experienced by you for any investment decision, whether consequent to, or in any way related to this Content, the provision of which is a regulated activity. Kalkine Media does not intend to exclude any liability which is not permitted to be excluded under applicable law or regulation. Some of the Content on this website may be sponsored/non-sponsored, as applicable. However, on the date of publication of any such Content, none of the employees and/or associates of Kalkine Media hold positions in any of the stocks covered by Kalkine Media through its Content. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content. Some of the images/music/video that may be used in the Content are copyright to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures displayed/music or video used in the Content unless stated otherwise. The images/music/video that may be used in the Content are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit the source wherever it was indicated or was found to be necessary.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.


Sponsored Articles


We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.