CMMC penetration testing requirements, in one sentence: Levels 1 and 2 do not require a penetration test. Level 3 does under CA.L3-3.12.1e, while a separate written term or cloud-provider equivalency obligation can still change what you need to prove.
Program status, August 2026: CMMC Phase I began November 10, 2025 and was originally scheduled to run through November 9, 2026. The November 10, 2026 transition to Phase II is suspended. Under Department of War Memorandum 26-P-1023 (July 13, 2026), requiring activities may currently designate only Level 1 (Self) or Level 2 (Self) in new procurement requirements. Level 2 (C3PAO) and Level 3 (DIBCAC) designations are paused, and no waivers are being granted during the review. Phase I self-assessment requirements remain in place; DFARS 252.204-7012 remains in effect; and applicable NIST SP 800-171 assessment results, CMMC statuses, CMMC UIDs, and annual affirmations continue to be recorded in SPRS.
By The Defense Compliance Report Editorial Team Last reviewed: August 2026 · Regulatory sources rechecked August 26, 2026 Editorial research — not formally reviewed by a CMMC Subject Matter Advisor.
No CMMC level below Level 3 requires a penetration test. CMMC Level 1 and CMMC Level 2 contain no security requirement named "penetration testing." Only CMMC Level 3 does — CA.L3-3.12.1e, which 32 CFR 170.14(c)(4) requires at least annually or when significant security changes are made to the system.
That is the whole answer to "CMMC penetration testing requirements," and you can stop reading if that's all you needed.
But three situations change it: a contract, subcontract, or prime flow-down can require testing independently of CMMC; the official Level 2 assessment guidance treats custom-developed software differently; and if you put covered defense information — the CUI to which DFARS 252.204-7012 applies — in a cloud service that is not FedRAMP Moderate authorized and the provider relies on DoD's equivalency path, annual penetration-testing evidence is already required somewhere in your compliance chain — just not necessarily on your network. The obligation can already exist in the provider's Body of Evidence even when you never commissioned the test yourself.
Here's how to tell which one you're in.
One disclosure up front, because it changes how you should read everything below: we do not sell penetration testing, and we have no commercial relationship with any penetration testing firm. Many pages people find for this question are published by companies that sell the service. That doesn't make them wrong. It does mean you should check the citation — and we've put the controlling source next to the regulatory claims that drive the decision.
CMMC penetration testing requirements by source: the obligation ledger
This is the table we built because the controlling sources are scattered. To assemble it yourself you'd need the eCFR, two NIST publications, the DoD CIO's Level 2 Assessment Guide, the relevant DFARS clauses, a 2024 cloud memo, the July 2026 suspension memo, and your own contract file.
Fourteen sources that can plausibly create a testing obligation. Exactly one of them names penetration testing as a CMMC requirement.
| Obligation source | Names penetration testing? | Controlling source | Frequency or trigger | Who performs it | What you may be asked for |
|---|---|---|---|---|---|
| CMMC Level 1 — Federal Contract Information | No | 32 CFR 170.14(c)(2) → FAR 52.204-21(b)(1)(i)–(xv) | None | n/a | n/a |
| CMMC Level 2 — 110 requirements across 14 families | No requirement uses the term | 32 CFR 170.14(c)(3) → NIST SP 800-171 Rev. 2 | n/a | n/a | n/a |
| RA.L2-3.11.1 — risk assessment | No | NIST SP 800-171 Rev. 2 §3.11.1 | Periodic; interval capped at one year by 32 CFR 170.14(d) | You | Risk-assessment records |
| RA.L2-3.11.2 — vulnerability scanning | No. Scanning, not penetration testing | NIST SP 800-171 Rev. 2 §3.11.2 | Periodic and when new vulnerabilities are identified | You or your provider | Scan scope, cadence, and results |
| RA.L2-3.11.3 — remediate vulnerabilities | No | NIST SP 800-171 Rev. 2 §3.11.3 | In accordance with risk assessments | You | Prioritization, tickets, and closure evidence |
| CA.L2-3.12.1 — assess control effectiveness | Method not specified. A penetration test can support selected objectives; it is not a mandate | NIST SP 800-171 Rev. 2 §3.12.1 and the Level 2 Assessment Guide | Periodic; interval capped at one year | You, with an appropriate level of assessor independence | Assessment plan, results, and corrective action |
| CA.L2-3.12.2 — plan of action | No | NIST SP 800-171 Rev. 2 §3.12.2 | When deficiencies are identified | You | Operational plans of action |
| CA.L2-3.12.3 — ongoing monitoring | No | NIST SP 800-171 Rev. 2 §3.12.3 | Ongoing | You | Monitoring records |
| Level 2 Assessment Guide — custom-developed software | Conditional. Says a penetration tester may be required | CMMC Assessment Guide – Level 2, v2.13, RA.L2-3.11.2 | When automated tools are not thorough enough for a custom solution | Qualified penetration tester, if needed | Custom-application analysis and validation records |
| CMMC Level 3 — CA.L3-3.12.1e | Yes. Explicitly. | 32 CFR 170.14(c)(4), Table 1 | At least annually or when significant security changes are made | Subject-matter experts using automated scanning and ad hoc tests | Scope, rules of engagement, report, remediation, and retest |
| DFARS 252.204-7012 — CUI in a non-authorized cloud using the equivalency path | Yes — of the cloud provider's offering | DFARS 252.204-7012(b)(2)(ii)(D) + DoD FedRAMP Moderate Equivalency Memo | Annual 3PAO assessment package under the memo | FedRAMP-recognized 3PAO | Provider Body of Evidence, including SAP, SAR, penetration-test material, SSP, and POA&M |
| Contract, subcontract, flow-down, customer agreement, or questionnaire representation | Sometimes | The applicable written instrument; DFARS 252.204-7021 governs CMMC status and flow-down when included | Whatever the instrument says | Whatever the instrument says | Whatever the instrument says |
| Cyber insurance policy | Sometimes | Your policy | Policy-specific | Policy-specific | Policy-specific |
| The CMMC assessment itself | No separate commercial penetration test is built in | NIST SP 800-171A: examine, interview, and test | Assessment-specific | You for a self-assessment; a C3PAO or DCMA DIBCAC for certification | Objective-specific evidence |
Read the ledger from top to bottom and the shape of the problem becomes obvious. The pressure you're feeling may be coming from your cloud chain, a separate written instrument, an insurance policy, or a lot of marketing — not from a hidden Level 2 requirement.
Definitions, since we'll use these terms throughout. FCI is Federal Contract Information — non-public information provided by or generated for the government under a contract, excluding public and simple transactional information. CUI is Controlled Unclassified Information — information requiring safeguarding or dissemination controls under law, regulation, or government-wide policy. A C3PAO is a CMMC Third-Party Assessment Organization, authorized or accredited to conduct Level 2 certification assessments. DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, which conducts Level 3 assessments. SPRS is the Supplier Performance Risk System, where NIST SP 800-171 assessment scores, CMMC results and statuses, CMMC UIDs, and affirmations are recorded. A CMMC assessment POA&M is the limited conditional-status instrument for documenting eligible requirements not met at an assessment and closing them within 180 days. That is not the same thing as the operational plan of action maintained under CA.L2-3.12.2.
Who this page is for — and who should leave now
Stay if you:
- received a penetration testing quote and want to know whether it's actually required
- have a prime's supplier questionnaire asking about annual testing and need to answer it this week
- are building Level 2 evidence and can't tell what satisfies CA.L2-3.12.1
- put covered defense information in a cloud service and want to know what testing sits underneath it
- are on a Level 3 track
Leave if you:
- want a ranked list of penetration testing vendors. We don't publish those, and we explain why below.
- want someone to promise a report will satisfy your assessor. Nobody can promise that. Anyone who does is selling.
- are trying to determine contract applicability without reading the actual contract. Start with the contract.
Decision point #1: find out which row you're in
You've seen the fourteen sources. The next question is which ones apply to you, and that depends on facts we don't have.
→ Map your CMMC level, scope, and provider category
The two-minute router asks about your contract, CUI, environment, timeline, and budget, then maps the unresolved problem to the provider category that owns the next step. It does not determine a binding contractual obligation, and your information is not sent to a provider unless you explicitly consent.
Do not enter CUI, drawings, credentials, vulnerability details, export-controlled information, or sensitive contract text.
Before you request quotes from anyone
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, a CUI enclave, or qualified federal-contracts counsel) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The requiring activity and contract set a prime contractor's level; the applicable subcontract or flow-down sets a supplier's obligation. Because a general answer can't resolve those facts, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — citing primary sources for regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right path before they spend real money.
Does CMMC require penetration testing?
It depends entirely on your level and on whether a separate written instrument adds a requirement. CMMC Level 1 and Level 2 contain no standalone penetration testing mandate. CMMC Level 3 contains an explicit one: CA.L3-3.12.1e. A contract, prime flow-down, or customer agreement can require testing regardless of what CMMC says.
The confusion on this topic isn't random. It comes from people treating six very different kinds of statements as if they were the same kind of statement. They aren't, and the difference is worth money.
The authority hierarchy, in order of force:
| Layer | What it is | Can it require a penetration test? |
|---|---|---|
| Binding model requirement | 32 CFR Part 170 and the dated standards it incorporates | Yes — at Level 3 only |
| Contract-specific | Your solicitation, contract clause, subcontract, incorporated standard, or flow-down | Yes, independently of the CMMC baseline |
| Assessment method | How an assessor gathers evidence under NIST SP 800-171A | It can be a method. It is not a control. |
| Official guidance | DoD CIO assessment guides | Not by itself; it can explain when an underlying requirement may call for specialist testing |
| Organization policy | What you wrote in your SSP, assessment plan, or security policy | It is not new law, but it becomes evidence of the implementation and cadence you say you follow |
| Vendor recommendation | A proposal in your inbox | No |
When someone tells you a penetration test is required, the only useful next question is which layer is that coming from. Too often the honest answer is layer six wearing layer one's clothes.
The one thing we can't tell you
Here's the limit of this page, and we'd rather you hear it from us than discover it in an assessment.
We found no published DoD statement declaring that a penetration test does or does not, by itself, satisfy CA.L2-3.12.1. We checked the rule, the incorporated NIST publications, and the current Level 2 Assessment Guide through August 26, 2026. They set the frequency and assessment objectives; they do not name one universally acceptable method. So anyone telling you definitively that a penetration test alone "satisfies 3.12.1" — or that it "doesn't count" — is giving you an interpretation. That includes us.
Now the part that matters: the absence of a named method is not the same as an absence of a standard. What is published is quite specific, and it's enough to act on with confidence:
- the two assessment objectives an assessor will check
- the three assessment methods available under NIST SP 800-171A
- the maximum interval you're allowed to define
- the DoD-assigned frequency at Level 3
- what counts as acceptable evidence and what doesn't
Build your evidence against those objectives and the method question stops dominating: the result still has to satisfy every applicable objective, whatever valid method or combination you chose. That's the rest of this page.
Does CMMC Level 2 require a penetration test?
No. CMMC Level 2 requirements are identical to the 110 requirements across 14 families in NIST SP 800-171 Revision 2 under 32 CFR 170.14(c)(3), and none of them names penetration testing. Level 2 does require vulnerability scanning, risk-based remediation, and periodic assessment of whether your security controls are effective — and those obligations are more demanding than most contractors realize.
Four Level 2 requirements get misread as a penetration testing mandate. We pulled their point values directly from the CMMC Scoring Methodology at 32 CFR 170.24(c)(2)(i)(B) and cross-checked their POA&M eligibility against 32 CFR 170.21(a)(2). Here's what they're actually worth.
The 18-point cluster
| Requirement | What it actually asks for | CMMC points deducted if NOT MET | Can it go on a Level 2 POA&M? |
|---|---|---|---|
| RA.L2-3.11.1 | Assess risk to operations and assets | −3 | No |
| RA.L2-3.11.2 | Scan for vulnerabilities, periodically and when new ones are identified | −5 | No |
| CA.L2-3.12.1 | Assess whether your controls are effective | −5 | No |
| CA.L2-3.12.3 | Monitor controls on an ongoing basis | −5 | No |
| Total | −18 | Zero deferrable |
Two more sit in the same cluster and are worth knowing about. CA.L2-3.12.2 (your plan of action) is −3 and also non-deferrable. RA.L2-3.11.3 (remediate what you find) is −1 and is the only requirement in this group you can defer. CA.L2-3.12.4 — your System Security Plan — is not handled as an ordinary point deduction: 32 CFR 170.24(c)(2)(i)(B)(5) says that when the SSP requirement is NOT MET because the SSP is absent or out of date, the assessment cannot be completed.
Add it up: this cluster represents 22 CMMC Level 2 points across seven requirements, and 21 of those 22 points cannot be placed on a CMMC assessment POA&M.
That number matters more than it looks, because of a rule most contractors never read. Under 32 CFR 170.21(a)(2)(ii), nothing worth more than one point may go on a Plan of Action and Milestones, subject to the rule's narrow partial-encryption exception for SC.L2-3.13.11. Not the five-pointers in this cluster. Not the three-pointers. Which means a single unmet three- or five-point requirement in this cluster removes your conditional path at any score; an absent or out-of-date SSP stops the assessment outright. You could sit at 105 out of 110 and still have no way forward.
So here's the trade nobody frames honestly:
A penetration test is optional at Level 2. Proving your controls work is not — and you can't defer it. Plenty of companies buy the optional thing and leave the mandatory thing open.
To check the arithmetic, our 110-requirement scoring guide walks the weighted model and its −203 mathematical floor.
What NIST 800-171 3.12.1 actually requires
CA.L2-3.12.1 requires you to periodically assess your security controls to determine whether they are effective in their application. It does not name a method. Its official discussion identifies vulnerability scanning and system monitoring as activities an organization "can choose to use" — options, not mandates — and requires that assessment results be obtained with an appropriate level of assessor independence.
Three things about this requirement are underpublished and all three are worth money.
1. There are exactly two assessment objectives
An assessor checks whether you defined an assessment frequency, and whether you actually assessed your controls at that frequency to determine effectiveness. That's it. Two determinations. A written control assessment with a defined cadence, adequate scope, documented results, and tracked corrective actions can satisfy both objectives. A penetration test can support them if its scope and evidence actually address control effectiveness and the defined cadence. So can a hybrid.
2. "Periodically" has a hard ceiling, and it's in the rule
This is the sentence most summaries skip. 32 CFR 170.14(d) states that where CMMC requirements use the term periodically, the interval length is organization-defined "with an interval length of no more than one year."
So Level 2 creates a control-assessment interval that can be no longer than one year. It just isn't a penetration testing obligation. You define the cadence inside that ceiling. If your SSP says you assess controls "periodically" and you last did it nineteen months ago, that's a finding — and it's a five-pointer you can't defer.
3. Independence is named in the requirement's own discussion
The official discussion text says organizations ensure that assessment results are current, relevant, and "obtained with the appropriate level of assessor independence." It doesn't define the threshold. But it means the question is live.
Our editorial reading, and we'll label it as ours: if your managed service provider designed and implemented your controls, and the same provider also produces the assessment concluding those controls are effective, you have an independence question to answer in your SSP. Not necessarily a fatal one. But one you should answer on paper before an assessor asks it out loud. If your provider handles security functions inside your boundary, our guide to external service providers under CMMC covers how that gets documented and assessed.
What acceptable evidence looks like
Under 32 CFR 170.24(b)(1), all evidence must be in final form and not draft. The rule specifically names working papers, drafts, and unofficial or unapproved policies as unacceptable. A substantively sound assessment record still fails as evidence if the only version presented is marked "draft."
Your CA.L2-3.12.1 evidence set, minimum viable version — our evidence framework, not a government-prescribed packet:
- An assessment plan that states your defined frequency
- An assessment record with the date, scope, and method used
- Findings, with disposition for each
- Remediation tracking that shows what happened next
- The SSP section documenting all of the above
- A short statement of who performed the assessment and how the appropriate level of assessor independence was considered
None of that requires a penetration test. All of it is final-form, dated, and reviewable.
The custom-software passage people overstate
The official CMMC Assessment Guide – Level 2, Version 2.13 addresses custom-developed software under RA.L2-3.11.2 and says vulnerability analysis of a custom solution may require a penetration tester where automated scanning tools are not thorough enough. The operative word is "may," the context is custom code, and the passage is nonbinding guidance — not a blanket Level 2 mandate.
This is the only place penetration testing appears in official Level 2 guidance, and it's the source of a lot of distorted vendor copy. We've seen it rendered as "CMMC requires a pen test when custom software handles CUI." That's not what the guide says. What it says is narrower and more useful.
Segment yourself honestly:
| Your situation | How much weight the custom-software guidance carries |
|---|---|
| Custom-built application or API processing CUI, internet-facing | Heavy. The guide itself recognizes that automated tools may not be thorough enough for a custom solution. Manual validation is genuinely justified here. |
| Custom internal application inside the CUI boundary | Moderate. It depends on exposure, attack paths, and what your automated analysis can actually evaluate. |
| Commercial off-the-shelf environment, no custom code in scope | None. This passage does not apply to you. Don't let it be quoted at you. |
| Custom code that never touches CUI and is genuinely outside the assessment boundary | None. Out of scope is out of scope — but document why. |
If you're in row one, the honest answer changes: a scoped application penetration test is defensible, and we'd tell you to run one. If you're in rows three or four and someone is citing custom-software guidance at you, ask them to name the custom application.
Decision point #2: if the real gap is evidence, buy the right thing
Most people who land on this page don't need a penetration test. They need to know whether their evidence would survive an assessor reading it — which is a completely different engagement with a completely different price tag. For budget context before you buy either one, see our CMMC Level 2 cost guide.
→ See what a CMMC mock or gap assessment actually covers, and how it differs from a formal assessment
If you'd rather work it yourself first, our NIST 800-171 requirements checklist walks all 110 requirements with the evidence each one expects.
Vulnerability scan, penetration test, CMMC assessment, and "TEST" — four different things
A vulnerability scan enumerates known or detectable weaknesses. A penetration test attempts to validate whether they're exploitable and chainable. A CMMC assessment determines whether the applicable requirements are MET. And "TEST" in NIST SP 800-171A is an assessment method, not a control. They support each other. None substitutes for another.
| Vulnerability scan | Penetration test | CMMC assessment | The NIST "TEST" method | |
|---|---|---|---|---|
| Question it answers | What weaknesses exist? | Can selected weaknesses or attack paths be exploited? | Are the applicable requirements MET? | Does this mechanism or process work as expected under specified conditions? |
| Level 2 status | Required — RA.L2-3.11.2, worth 5 points | Not required; may serve as supporting evidence | The assessment type named in the applicable requirement | One method an assessor may select |
| Level 3 status | Inherited from Level 2 | Required — CA.L3-3.12.1e | DIBCAC path in the model | Also available |
| Output | Scan results, coverage, timestamps | Rules of engagement, attack narrative, findings, retest | MET / NOT MET per requirement | Objective-specific evidence |
| Substitutes for the others? | No | No | No | No |
The fourth column is where most of the argument happens, so let's settle it.
NIST SP 800-171A defines three assessment methods: examine (review documents and artifacts), interview (talk to people), and test (exercise an object under specified conditions to compare actual behavior with expected behavior). Penetration testing is offered as one example of a test activity. But NIST is explicit that there is no expectation every method and every assessment object will be used in every assessment.
Translation: the word "test" appearing in the assessment methodology does not convert into a commercial penetration testing engagement. An assessor exercising your multifactor authentication to see whether it prompts is performing a test. So is watching a scan run. So is checking whether a disabled account actually can't log in.
For the scanning side of this in depth — cadence, scope, coverage reconciliation, and remediation — see our CMMC patch-management and vulnerability-scanning guide.
Why do assessors and consultants still ask for one?
Because a penetration test can be legitimately useful evidence for selected technical objectives — particularly around custom applications, segmentation, and control effectiveness — and because some requesters have simply inherited the assumption. A request is not proof of a hidden requirement. The right response is to ask which objective, clause, or evidence gap the test is meant to close.
We want to be careful here, because the reflex to assume bad faith is wrong. A good assessor asking for technical evidence usually has a real reason. A good consultant recommending a test usually believes it. The problem is that "CMMC requires it" and "I would find this persuasive" get compressed into the same sentence, and only one of them is true.
The five questions that resolve it
- Which specific CMMC requirement or assessment objective is this tied to?
- Is the request based on the CMMC model, a separate contract term, or your preferred evidence method?
- What evidence gap would this close that our existing artifacts don't?
- Which systems and attack paths need to be in scope, and why those?
- Would another valid examine, interview, or test method satisfy the same objective?
Question one usually ends it. Not because anyone is being dishonest, but because the exercise of naming the requirement forces the layer distinction we drew earlier.
The email to send
Copy this. It's deliberately neutral — it gets you the answer without putting anyone on the defensive.
"Please identify the CMMC requirement, assessment objective, contract provision, or specific evidence gap that establishes the requested penetration test, including the expected scope, cadence, and acceptance criteria. We want to make sure the engagement is properly authorized and scoped to the actual obligation."
Every word in that paragraph is doing work. Properly authorized signals you understand active testing needs rules of engagement. Scoped to the actual obligation signals you're not going to buy a generic package. And asking for acceptance criteria tells you immediately whether the requester has thought it through.
Decision point #3: if you're not sure what's driving the request
Sometimes the request is the first visible sign that your CMMC obligations are moving — a prime tightening flow-down, a new solicitation, a customer's security team getting serious.
→ Map your level, scope, and timeline before you answer
The CMMC Path Framework maps your required level, FCI versus CUI handling, assessment type, environment, and contract timeline to the provider category that owns your next step. It routes to a category, not a named provider. It is not a score, a ranking, or compliance advice. Do not submit CUI, drawings, or sensitive contract details.
Our prime's questionnaire asks if we do annual penetration testing. What do we write?
Answer the question that was asked, honestly, and then state what you do perform. If you don't run penetration tests, say so and describe your vulnerability scanning under RA.L2-3.11.2 and your control assessments under CA.L2-3.12.1. A questionnaire answer is not itself a CMMC finding — but a false answer can create contractual and legal risk later.
This is one of the most common reasons people land on this page, so let's make it concrete.
First, understand what you're holding
There's a real hierarchy here, and people collapse it:
| What it might be | What it obligates |
|---|---|
| A supplier survey | By itself, it may only inform the prime's risk picture — unless it is incorporated, certified, or tied to a contractual representation |
| A stated supplier expectation | Commercial pressure; check whether it has been made part of the written agreement |
| A representation in a solicitation | You are representing facts to obtain award. Accuracy matters. |
| An incorporated standard | You are bound by the incorporated terms to the extent the instrument makes them applicable |
| A subcontract clause | Binding. Read the scope, cadence, flow-down, and acceptance terms. |
DFARS 252.204-7021 provides for the required CMMC status to be inserted into the contract, ties it to systems used in performance, and requires the applicable flow-down. It does not convert every security practice a customer asks about into a CMMC requirement. But a valid written contract or subcontract can impose terms above the CMMC floor, and those terms still have to be handled as contract requirements.
A defensible answer template
Adapt this to your facts. Don't send it if it isn't true.
"We do not currently conduct third-party penetration testing. CMMC Level 2 does not require it; penetration testing is required at CMMC Level 3 under CA.L3-3.12.1e. Our program performs vulnerability scanning on a defined periodic cadence and when new vulnerabilities affecting our systems are identified (RA.L2-3.11.2), remediates according to risk (RA.L2-3.11.3), and performs periodic security control assessments to determine control effectiveness (CA.L2-3.12.1). If your contract requires penetration testing beyond the CMMC baseline, please identify the clause and required scope so we can price and schedule it."
That last sentence is the important one. It's cooperative, it's professional, and it moves the burden of specificity back where it belongs.
One thing worth knowing about the current moment
The July 13, 2026 implementation memo directs contracting officers to amend active solicitations that contain Level 2 (C3PAO) or Level 3 designations and to modify existing contracts before the next option exercise or administrative modification. That means an older solicitation, contract, or flow-down can remain visible before the paperwork catches up.
Do not treat silence as either cancellation or confirmation. Ask for the written amendment, modification, or clause that currently controls. If you support multiple contracts, review each applicable instrument and each in-scope system rather than assuming one customer's answer governs the rest.
Does our cloud provider need a penetration test?
If you store, process, or transmit covered defense information in a cloud service that is not FedRAMP Moderate authorized, DFARS 252.204-7012 requires that service to meet security requirements equivalent to the FedRAMP Moderate baseline. The DoD CIO's FedRAMP Moderate Equivalency Memo defines that path as 100 percent compliance with the baseline, assessed by a FedRAMP-recognized third-party assessment organization. The memo's required assessment package includes annual penetration-testing material. The test is your provider's obligation. Obtaining and validating the Body of Evidence is yours.
This is the section we'd read first if we were you, because this obligation is easy to miss and may already apply.
Here's the chain, link by link:
- DFARS 252.204-7012(b)(2)(ii)(D) requires that if you use an external cloud service to store, process, or transmit covered defense information, you require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — plus the incident reporting, media preservation, and access provisions in paragraphs (c) through (g).
- The DoD CIO memo on FedRAMP Moderate equivalency, dated December 21, 2023 and released January 2, 2024, ended the practical ambiguity around what DoD would accept as "equivalent." It requires 100 percent compliance with the latest FedRAMP Moderate baseline, assessed by a FedRAMP-recognized 3PAO, with the supporting documentation presented to you — the contractor.
- That Body of Evidence has four components: the System Security Plan, the Security Assessment Plan, the Security Assessment Report, and the Plan of Action and Milestones.
- The memo requires penetration-testing material in that package: the Security Assessment Plan includes the penetration-testing plan and methodology conducted annually, and the Security Assessment Report includes the resulting penetration-test reports and evidence validated by the FedRAMP-recognized 3PAO.
So if your CUI lives in a cloud service claiming equivalency rather than holding an actual FedRAMP authorization, the provider's annual 3PAO package should already contain penetration-testing evidence in your compliance chain — and the DoD memo requires the Body of Evidence to be presented to you.
Your action, and it takes one email: ask your cloud provider for the Security Assessment Report from their most recent 3PAO assessment, and check whether a penetration test was performed and when. If they don't know what you're asking for, that's your answer.
One honest caveat. The DoD equivalency memo calls for annual penetration-testing material and an annual FedRAMP-recognized 3PAO assessment package for the equivalency path. Verify the current FedRAMP Moderate baseline and the current DoD memo when you review a provider's package; do not let a provider substitute a generic SOC report for the required Body of Evidence.
And one thing this does not mean: a FedRAMP authorization or equivalency package does not automatically make your own 110 Level 2 requirements MET. It can supply inherited or shared-responsibility evidence for the cloud service. Your SSP, customer responsibility matrix, configurations, users, endpoints, and retained responsibilities are still yours.
Decision point #4: if the answer turned out to be a cloud problem
If reading that section made you realize you don't actually know where your CUI lives or what your provider is attesting to, that's a scoping and architecture problem, not a testing problem. Different category, different conversation.
→ Compare enclave and enterprise scope before you buy testing
CMMC Level 3 penetration testing requirements
CA.L3-3.12.1e is the only CMMC security requirement that names penetration testing. Table 1 to 32 CFR 170.14(c)(4) states it as: conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts. Level 3 is assessed by DCMA DIBCAC, not by a C3PAO.
The frequency many summaries publish incorrectly
NIST SP 800-172 leaves the frequency blank — an organization-defined parameter. DoD filled it in. The italicized text in the CFR table is DoD's assignment, and it reads:
at least annually or when significant security changes are made to the system
Many pages on this topic quote the NIST version with the organization-defined parameter still blank, or paraphrase it as "at a specified frequency." That drops DoD's second trigger entirely. The CMMC requirement has an event condition, not just a calendar condition. A significant security change can trigger testing before the annual date arrives.
Two disciplines matter when you write this into your program:
Preserve both conditions. Quote the rule exactly: at least annually or when significant security changes are made. Do not reduce it to a calendar-only requirement. Operationally, evaluate a documented significant-security-change event when it occurs rather than waiting automatically for the next annual date.
Define "significant security change" yourself, in writing. The rule does not publish a list. Our editorial candidates worth evaluating are material network-architecture changes, a new or redesigned CUI enclave, a new internet-facing application or API, major identity or access-control redesign, cloud migration, changes to segmentation or trust boundaries, bringing operational technology into scope, an acquisition, or major remediation following a compromise. Write your threshold down before you need it.
The Level 3 math that changes the buying decision
We pulled this from 32 CFR 170.21(a)(3) and 170.24(c)(3).
- Level 3 is 24 requirements, worth one point each. No weighting.
- Conditional Level 3 requires your score divided by 24 to be at least 0.8. That's 19.2 — so you need 20 of 24 MET, and up to four may be deferred.
- Section 170.21(a)(3)(ii) names seven requirements that may never appear on a Level 3 POA&M: IR.L3-3.6.1e, IR.L3-3.6.2e, RA.L3-3.11.1e, RA.L3-3.11.4e, RA.L3-3.11.6e, RA.L3-3.11.7e, and SI.L3-3.14.3e.
- CA.L3-3.12.1e is not on that list. Penetration testing is technically POA&M-eligible at Level 3 — with a hard 180-day closeout under 32 CFR 170.21(b).
Now the part that reframes it. Under 32 CFR 170.24(c)(3), a maximum score on your Level 2 certification assessment is required before you can even initiate a Level 3 assessment. A perfect 110.
You can defer the penetration test at Level 3. You cannot defer a single one of the 110 requirements underneath it. The door to the level that requires penetration testing only opens at 110 out of 110.
And the current-status fact that changes the answer
Under the current suspension, requiring activities may designate only Level 1 (Self) or Level 2 (Self) in new procurement requirements. Level 3 (DIBCAC) designations are paused, and no waivers are being granted during the review.
The one CMMC level that requires a penetration test is the one level the suspension memo currently bars requiring activities from designating in new procurement requirements.
The underlying requirement is still codified — the suspension paused implementation designations, not the text of 32 CFR 170.14. Existing paperwork may also require a written amendment or modification under the July 13 procedures. If you are being sold urgency around Level 3 penetration testing right now, check the solicitation or contract in front of you before you check the calendar. And note that CMMC incorporates specific dated versions of the NIST publications by reference. NIST SP 800-171 Revision 3 does not control CMMC Level 2 unless and until DoD amends the rule.
For the full Level 3 picture, see our CMMC Level 3 requirements guide.
When a penetration test is still the right call at Level 2
Editorial guidance, not a CMMC requirement. A Level 2 contractor may reasonably choose to run a penetration test where the security value justifies the cost. The strongest cases involve custom applications, internet exposure, CUI enclave segmentation, major architectural change, or validating that a significant remediation actually worked.
Not required doesn't mean not worth doing. We'd rather say that plainly than let this page read as an argument against security testing.
Strong reasons
- A custom-developed application or API processes CUI, and your scanner can't test business logic
- Your CUI enclave's segmentation has never been adversarially validated
- You just completed a cloud migration, identity redesign, or network consolidation
- A high-severity vulnerability was remediated and you want exploitability confirmed
- Incident response left you unsure how far lateral movement could have gone
- A prime or customer wants documented attack-path assurance and is willing to accept it as such
- You want independent assurance before signing an annual affirmation
Weak reasons
- "Everyone in the DIB does one"
- "A vendor said assessors expect it"
- "It'll improve our SPRS score" — it won't, directly. Score comes from requirements MET.
- "It replaces our vulnerability scanning" — it doesn't. RA.L2-3.11.2 is still open.
- "It certifies our enclave" — a penetration-test report does not create a CMMC status
- "We need a compliance PDF"
The four-part fit test
A penetration test is likely worth the money when all four are true:
- You have a specific attack path or security question you want answered
- Your environment is stable enough that the result stays valid for a while
- You have the capacity to remediate what comes back
- The scope and evidence will support an actual decision
If basic asset inventory, vulnerability scanning, patching, multifactor authentication, logging, or access control aren't operational yet, a penetration test will spend most of its budget confirming what a scan would have told you for a fraction of the cost. Fix the floor first.
How to scope it so it isn't wasted money
A penetration test supports only the decisions and assessment objectives its scope can actually reach. When you intend to use it as CMMC evidence, map the scope to the applicable 32 CFR 170.19 boundary — including CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, and Specialized Assets where relevant — and document every exclusion. A perimeter-only test of your public website tells an assessor little about the environment where CUI actually lives.
This is our recommendation drawn from the scoping framework at 32 CFR 170.19, not a regulatory requirement. Label it that way in your own documentation too.
What the statement of work must contain
Purpose. One primary objective, and "CMMC compliance" is not an acceptable answer. Pick: satisfying CA.L3-3.12.1e, satisfying a written contract term, validating a custom application, testing enclave segmentation, supporting selected Level 2 objectives, or validating remediation.
Scope tied to your actual boundary. In-scope hosts, applications, APIs, identities, and cloud accounts. External versus internal. Authenticated versus unauthenticated. Whether custom applications are included. Security protection assets — firewalls, identity infrastructure, logging, authentication servers — that sit in the tested paths. Exclusions, and why.
Rules of engagement. NIST SP 800-115 describes rules of engagement as the constraints established before testing begins that give the team authority to perform defined activity. Yours needs authorized signatories, permitted windows, emergency contacts, stop conditions, prohibited actions, denial-of-service prohibition or explicit authorization, credential handling, whether the test is announced or blind, and incident response coordination so your own SOC doesn't spend a weekend chasing your testers.
CUI and sensitive data handling. Will testers access real CUI or synthetic data? Where do findings live? Who can see raw results? Are screenshots likely to capture sensitive information? What's the encryption, retention, and destruction process? Are subcontractors or third-party testing platforms involved? A penetration test report is one of the most sensitive documents your company will ever hold. Treat it accordingly.
Methodology and human validation. Discovery, vulnerability identification, exploitability validation, attack chain analysis, manual testing where relevant, false-positive handling, severity method, and retest procedure. If a vendor is claiming Level 3 alignment, note that the rule's language expressly includes ad hoc tests using subject matter experts — an automated platform alone shouldn't be assumed to satisfy it.
Acceptance criteria. Every authorized target tested or the exception documented. Every finding reproducible. Critical findings escalated under an agreed process. Retest included. And the report does not claim certification.
Buyer red flags
- "Guaranteed CMMC pass" — nobody can guarantee an assessment outcome
- "C3PAO-approved report," with no named assessor and no written approval
- A prebuilt universal scope that has nothing to do with your CUI boundary
- No signed rules of engagement
- No human testing, on an engagement sold as Level 3 aligned
- No explanation of how your findings will be stored and destroyed
- No retest
- Every vulnerability automatically mapped to a CMMC requirement — mapping is context, not certification
- The intake form asks for network diagrams or contract details before you've signed anything
- The provider can't clearly state whether they're acting as tester, readiness advisor, or formal assessor
That last one matters more than the rest combined, which brings us to the final decision.
Decision point #5: get scoped options from the right category
If you've worked through this page and concluded that testing is justified — by Level 3, by a contract term, or by a real security question — the next move is matching the work to the right kind of firm.
→ Identify the provider category that owns the next step
Tell us only your required level, general environment type, reason for testing, and timeline. Do not submit CUI, vulnerability details, network diagrams, or contract text.
And if you're already assessment-ready — evidence assembled, scope documented, gaps closed — you don't need us for this. Go straight to our CMMC assessment preparation guide and skip the routing entirely. We'd rather lose the click than send a ready company through a matching form it doesn't need.
Which provider category do you actually need?
The right category depends on the unresolved problem, not on the word "penetration test." An offensive security firm or capable MSSP performs technical testing; an RPO or RP helps determine scope and readiness; a GRC platform organizes evidence; a CUI enclave provider changes the boundary; and a C3PAO's role is formal Level 2 assessment — not general remediation. Our who-to-hire-first decision guide resolves the order when more than one category is involved.
| Your unresolved problem | Category that owns it | What to verify before hiring | What this category cannot do |
|---|---|---|---|
| You don't know whether the request is binding | RP/RPO for CMMC scoping; qualified federal-contracts counsel for contract interpretation | Current Marketplace status where applicable, written scope of work, and role boundaries | A readiness provider cannot give legal advice unless separately qualified and engaged to do so |
| You've confirmed a technical test is needed | Penetration-testing firm or offensive-security practice | Methodology, human expertise, CUI handling, retest terms, and signed rules of engagement | Cannot determine your binding CMMC level or grant CMMC status |
| You need controls operated day to day | MSSP — Managed Security Service Provider | Which controls it operates, evidence delivery, incident duties, and external-service-provider implications | Its operation of a control does not transfer your responsibility to document and oversee it |
| You need evidence and workflow organized | GRC platform | Whether it documents controls or actually implements anything | Software alone does not satisfy CMMC |
| Your boundary is too broad and too expensive | CUI enclave or secure-architecture provider | What enters and leaves scope, residual endpoints, and inherited responsibilities | Does not eliminate requirements — it changes and may shrink where they apply |
| You need a formal Level 2 certification assessment | Authorized or accredited C3PAO, when that designation is available and applies | Current Cyber AB Marketplace status, assessment scope, impartiality, personnel conflicts, and fees | Cannot prepare or remediate you for that same assessment and then simply resume as assessor |
On independence, precisely. 32 CFR 170.8(b)(17) requires conflict-of-interest controls and bars a CMMC Ecosystem member from participating in a Level 2 certification assessment when that member served as a consultant preparing the organization for any CMMC assessment within the prior three years. The CMMC Assessment Process, Version 2.0 also says a C3PAO that finds an organization unready cannot give remedial advice and then resume that specific assessment. Get it in writing, before engagement, which role each party is playing — readiness, implementation, technical testing, evidence management, or formal assessment. Do not assume one firm can both remediate and formally assess the same scope simply because it offers both services.
Why there are no vendor names on this page. We publish named-provider content only when we can document the provider's category, status verification, services reviewed, compensation relationship, evaluation depth, and last-verified date. We have not conducted that evaluation for any penetration testing firm. Recommending one here would fail our own standard, and we'd rather leave the section thin than pretend.
What we actually verified
Every regulatory claim on this page was checked against the issuing authority. Here's exactly what we read and when.
Read firsthand or rechecked on August 26, 2026:
- 32 CFR Part 170: §170.14(c)(2)–(4) and Table 1; §170.14(d); §170.19; §170.21; §170.22; and §170.24. Those provisions establish the Level 1, Level 2, and Level 3 baselines; the one-year ceiling on periodically; scoping categories; POA&M limits; annual affirmations; point values; final-form evidence; and the perfect-Level-2 prerequisite for Level 3.
- NIST SP 800-171 Revision 2: the controlling 110-requirement, 14-family Level 2 baseline incorporated by the CMMC rule. NIST has published Revision 3, but the current CMMC rule still incorporates the dated Revision 2 publication.
- NIST SP 800-171A, June 2018: the examine, interview, and test methods; the statement that every method and object need not be used in every assessment; and the CA 3.12.1 objectives. NIST now marks this edition withdrawn and superseded, but 32 CFR 170.2 and 170.14(d) still incorporate the dated June 2018 edition for CMMC assessments.
- NIST SP 800-172, February 2021 and NIST SP 800-172A, March 2022: the enhanced penetration-testing requirement and its assessment objectives. NIST leaves the frequency as an organization-defined parameter; DoD fills it in through 32 CFR 170.14(c)(4).
- CMMC Assessment Guide – Level 2, Version 2.13, September 2024: the RA.L2-3.11.2 custom-software passage, the CA.L2-3.12.1 objectives and independence discussion, and the guide's own notice that it does not have the force and effect of law.
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021: cloud-equivalency duties; current NIST SP 800-171 score-posting and Government-assessment provisions; CMMC status, flow-down, self-assessment, and annual-affirmation requirements.
- DoD CIO FedRAMP Moderate Equivalency Memo, dated December 21, 2023 and released January 2, 2024: 100 percent Moderate-baseline compliance, FedRAMP-recognized 3PAO validation, the four-part Body of Evidence, and annual penetration-testing material.
- CMMC Assessment Process, Version 2.0, December 2024: Marketplace status verification, examine/interview/test use, readiness and remediation boundaries, impartiality handling, and the prohibition on promising or guaranteeing an assessment outcome.
- Department of War CMMC Phase II suspension page and Memorandum 26-P-1023 implementation procedures, July 13, 2026: permitted procurement designations, treatment of active solicitations and existing contracts, continued DFARS 252.204-7012 obligations, and the no-waiver direction during review.
- SPRS official CMMC and NIST resources: the current modules used for NIST SP 800-171 assessment information, CMMC self-assessment information, CMMC statuses, and affirmations.
What we did not use as evidence:
Vendor sales pages. Unsourced "assessors expect it" claims. Forum comments. FedRAMP or SOC 2 testing requirements imported into CMMC. NIST SP 800-53 CA-8 treated as a Level 2 requirement — it isn't; Level 2 is identical to NIST SP 800-171 Revision 2, and an informal mapping between frameworks does not import controls. And obsolete CMMC 1.0 practice identifiers, which still appear in secondary summaries.
What we could not verify, stated plainly: we found no published DoD position saying that a penetration test, by itself, always satisfies or never satisfies CA.L2-3.12.1. The published objectives and methods are specific; the universal shortcut is not.
Frequently asked questions
Does CMMC Level 1 require penetration testing? No. CMMC Level 1 consists of the 15 safeguards in FAR 52.204-21(b)(1)(i)–(xv), and none is a penetration-testing requirement. Level 1 does include periodic system scans and real-time scanning of files from external sources, which is malicious-code protection — not penetration testing.
Does CMMC Level 2 require a penetration test? No. Level 2 is identical to the 110 requirements across 14 families in NIST SP 800-171 Revision 2 under 32 CFR 170.14(c)(3), and none of them names penetration testing. Level 2 does require vulnerability scanning, risk-based remediation, and periodic control-effectiveness assessment.
Does a C3PAO require a penetration test for Level 2? Not as a hidden universal control. Assessors work from the three methods in NIST SP 800-171A — examine, interview, and test — and NIST states there is no expectation that every method will be used in every assessment. If an assessor requests a penetration test, ask which assessment objective or evidence gap it addresses.
Does 32 CFR Part 170 say how often we have to assess our controls? Indirectly, and it's stricter than most people assume. Section 170.14(d) states that where a requirement says periodically, the interval is organization-defined with a length of no more than one year. So CA.L2-3.12.1 carries a maximum twelve-month interval, whichever method you use.
Does custom software require penetration testing at Level 2? Not automatically. The official CMMC Assessment Guide – Level 2 says vulnerability analysis of a custom solution may require a penetration tester where automated tools aren't thorough enough. That's conditional guidance for custom code, not a blanket Level 2 mandate.
What is the CMMC Level 3 penetration testing control? CA.L3-3.12.1e. Table 1 to 32 CFR 170.14(c)(4) requires penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts.
How often does CMMC Level 3 require penetration testing? At least annually, or when significant security changes are made to the system. DoD names both a calendar condition and a significant-change condition. Build the program to evaluate a documented significant change when it occurs rather than waiting automatically for the annual date.
What counts as a significant security change? The rule does not publish a list, so define and document a risk-based threshold before the event occurs. Our editorial candidates include major network-architecture changes, a new or redesigned CUI enclave, new internet-facing applications, identity or access-control redesign, cloud migration, changes to segmentation, or major post-incident remediation.
Can penetration testing go on a POA&M? At Level 3, yes — CA.L3-3.12.1e is not among the seven requirements excluded by 32 CFR 170.21(a)(3)(ii), so it can be deferred with a 180-day closeout. At Level 2 the question doesn't arise, because there's no penetration testing requirement to defer. The Level 2 requirements people confuse with it — RA.L2-3.11.1, RA.L2-3.11.2, CA.L2-3.12.1, and CA.L2-3.12.3 — are all worth more than one point and therefore cannot go on a POA&M at all.
Is Level 3 assessed by a C3PAO? No. Level 3 certification assessments are conducted by DCMA DIBCAC. And under the current suspension, Level 3 designations aren't permitted in new procurement requirements.
Did the 2026 Phase II suspension remove the Level 3 penetration testing requirement? No. The suspension paused implementation and assessment designations. CA.L3-3.12.1e remains in 32 CFR 170.14.
Does NIST SP 800-171 Revision 3 control CMMC Level 2 now? No. NIST published Revision 3, but 32 CFR 170.14 still incorporates the dated NIST SP 800-171 Revision 2 baseline for CMMC Level 2. Revision 3 becomes controlling only if DoD changes the governing rule or other applicable contractual authority.
Where are NIST SP 800-171 scores, CMMC results, and affirmations posted? In SPRS, but under different authorities. DFARS 252.204-7019 and -7020 address NIST SP 800-171 DoD assessment scores. DFARS 252.204-7021 and 32 CFR Part 170 address CMMC self-assessment results or statuses, CMMC UIDs, and annual affirmations when that clause applies.
Does NIST SP 800-53 CA-8 apply to CMMC Level 2? No. CA-8 is a NIST SP 800-53 control. CMMC Level 2 is identical to NIST SP 800-171 Revision 2. Informal crosswalks between the two frameworks are useful for mapping, but they do not import SP 800-53 controls into the CMMC Level 2 baseline.
Is vulnerability scanning the same as penetration testing? No. A scan enumerates known or detectable weaknesses; a penetration test attempts to validate exploitability and chain weaknesses into attack paths. Scanning is required at Level 2 under RA.L2-3.11.2 and carries a five-point deduction when NOT MET. A penetration test does not replace the required scanning process or its evidence.
Can a penetration test replace our CMMC assessment? No. A penetration test can support selected objectives. A CMMC assessment evaluates all applicable requirements using examination, interviews, and testing, and produces a MET or NOT MET determination per requirement.
Can a prime require a penetration test even if CMMC doesn't? Yes, through the applicable written instrument. Ask for the exact clause, scope, cadence, and acceptance criteria rather than accepting "CMMC requires it" as the basis.
Can an automated penetration testing platform satisfy Level 3 by itself? Don't assume so. The rule's language expressly includes ad hoc tests using subject matter experts alongside automated scanning tools. Evaluate any claimed solution against the complete requirement text and your actual scope.
What should be in the rules of engagement? Authorization and signatories, scope and exclusions, permitted testing windows, prohibited actions, stop conditions, emergency contacts, credential handling, data handling and destruction, and coordination with your incident response process — all agreed before active testing begins.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
→ Find My CMMC Path → Use the 32-point CMMC readiness checklist → Request scoped options after you know the category
Do not submit CUI, drawings, credentials, vulnerability reports, network diagrams, export-controlled information, or sensitive contract details.
Disclosure
The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our Editorial & Advertising Policy.
How this page was produced
The Defense Compliance Report Editorial Team compared the current CMMC model in 32 CFR Part 170, the incorporated NIST requirements, official DoD assessment guidance, current DFARS language, the Cyber AB's CMMC Assessment Process, SPRS materials, and current CMMC implementation memoranda. Regulatory and contractual claims are sourced to the issuing authority. Commercial pages and practitioner discussions were used only to identify common confusion and competing claims — never to establish a requirement. See our Methodology and Editorial Standards.
Independence and disclaimer
The Defense Compliance Report is not affiliated with the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, or any U.S. government agency.
This page is educational research, not legal, contractual, cybersecurity, or compliance advice. The applicable solicitation, contract, subcontract, or flow-down and the information handled in performance determine the obligation — not a checklist and not this article. Confirm contractual interpretation with qualified federal-contracts counsel, and confirm CMMC scope and implementation with a qualified CMMC practitioner. Report suspected errors through our Corrections Policy.
Last reviewed: August 2026. Regulatory and implementation sources rechecked August 26, 2026.
