The Department of War suspended the November 2026 transition to CMMC Phase 2 on 13 July 2026, and on 3 September 2026 Class Deviation 2026-O0025, Revision 3 turned that policy into binding instructions for contracting officers. The security requirements did not change. DFARS 252.204-7012 and all 110 requirements of NIST SP 800-171 Revision 2 remain in force, the SPRS score is still a representation to the government, and the CMMC clause is still prescribed for every Federal Contract Information and Controlled Unclassified Information contract awarded on or after 10 November 2028. What changed is who checks the work, which makes the quality of your own evidence the only thing standing between a self-assessed score and a Defense Industrial Base Cybersecurity Assessment Center review.
That is the market this guide is written for: security, compliance and procurement leaders at mid-market and enterprise defense contractors and their suppliers who need a penetration testing company that produces evidence a Level 2 assessor, a DIBCAC team or a Department of Justice investigator will accept.
Quick answer: For defense contractors buying penetration testing in 2026, Stingrai ranks first on the criteria that matter for CMMC evidence: CREST firm-level accreditation, named penetration testers with verifiable certifications, reports mapped to NIST SP 800-171 requirement identifiers, retesting included, an attestation letter, and published pricing. Raxis, GuidePoint Security, NetSPI, Praetorian, Optiv, LevelBlue and Sikich round out the shortlist. None of these companies is a C3PAO, and that separation is a feature rather than a gap.

What the 2026 rules actually require
Two primary documents govern the current state, and both are short enough to read in full.
The DoW CIO memorandum of 13 July 2026 (publication case 26-P-1023) suspended "the upcoming November 2026 transition to Phase 2 of CMMC implementation" along with "all pending and future CMMC milestones." Its attachment sets the operating rules: program managers "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)." The same attachment states that during the suspension the Department "will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments," that DFARS 252.204-7012 requirements "remain in effect," and that "no waivers shall be granted during the review of the program."
The class deviation of 3 September 2026 supersedes Revision 2 of 16 July 2026 and instructs contracting officers to "remove or revise the Cybersecurity Maturity Model Certification (CMMC) requirements in new and existing solicitations and contracts." Its clause prescription is the part buyers should read twice: until 9 November 2028 the CMMC clause goes into a solicitation only where a program office determines a specific level is required, and on or after 10 November 2028 it goes into every solicitation and contract, other than those solely for commercially available off-the-shelf items, where the contractor uses contractor information systems to process, store or transmit FCI or CUI. A CMMC Reform Task Force was launched alongside the suspension; as of 19 September 2026 its report had not been published, and a task force report is advice in any case. Only a further class deviation, a DFARS rule change or an amendment to 32 CFR part 170 changes an obligation. The detail is in our guide to the CMMC Level 2 self-assessment and the evidence that holds up.
Two 2026 False Claims Act settlements explain why the evidence question is not academic. On 18 June 2026 the Department of Justice announced a US$507,144 settlement with LOGZONE over NIST SP 800-171 representations on two Navy contracts, after DIBCAC scored its systems at negative 170 on a scale running from negative 203 to 110. On 1 September 2026 DOJ announced a US$2,042,518 settlement with Honeywell Aerospace covering April 2020 to December 2023, with a US$375,823 whistleblower share and no determination of liability. A self-assessed score that nobody can substantiate is still a representation.
The four requirements your penetration test evidences
No requirement in NIST SP 800-171 Revision 2 mandates a penetration test. Four requirements are nonetheless where penetration test evidence does real work, and under the DoD Assessment Methodology each of them is worth 5 points out of 110, which means each is ineligible for a plan of action under 32 CFR 170.21 and must be met on scoring day.
3.11.2, scan for vulnerabilities. NIST SP 800-171A decomposes this into five assessment objectives, and the one contractors most often miss is that the scope is systems and applications, not hosts alone. DoD's Level 2 Assessment Guide is blunt about the limit of tooling here: for custom-developed software, vulnerability analysis "may require a penetration tester," because scanners "may not be as thorough." A scan report against a commercial off-the-shelf estate does not evidence this objective for an application your own developers wrote.
3.12.1, periodically assess the security controls. A penetration test speaks to this most directly, because the question is effectiveness rather than existence. A control that is documented, configured and demonstrably bypassable is not effective. The assessment guide notes that controls should be "assessed at least annually," and warns against treating the system security plan as a "set it and forget it" artifact.
3.12.3, monitor security controls on an ongoing basis. A single annual test does not evidence ongoing monitoring. A testing cadence with continuity between runs does: periodic retests, tracked findings that move between states, and a record of what changed. This is the requirement that pushes most CUI environments toward a continuous program alongside the annual engagement, rather than instead of it.
3.14.1, identify, report and correct system flaws in a timely manner. The evidence here is not the finding, it is the closure. A retest that re-attacks a specific issue and records a fix on a dated timeline is worth more to an assessor than a longer original report. A vendor that charges extra for retesting is charging you for the part of the engagement that carries the evidentiary weight.
Requirement | What it asks | Penetration test artifact that evidences it |
|---|---|---|
RA.L2-3.11.2 | Scan for vulnerabilities in systems and applications, periodically and on new discoveries | Manual application testing of custom software plus authenticated scan results, with scope and dates |
CA.L2-3.12.1 | Periodically assess the security controls to determine effectiveness | Independent test report with methodology, scope boundary, findings and severity |
CA.L2-3.12.3 | Monitor the security controls on an ongoing basis | Testing cadence records, continuous findings feed, state changes between runs |
SI.L2-3.14.1 | Identify, report and correct system flaws in a timely manner | Retest report showing fixes verified against dated remediation timelines |
Two practical notes. Evidence is graded on scope boundary, not volume: a report covering a boundary other than the one in your system security plan is worth very little. And the requirement identifiers should appear in the report itself. A report that says "high severity: missing output encoding" is a security document; a report that also says "evidences RA.L2-3.11.2 and SI.L2-3.14.1 for the enclave described in section 2" is a compliance document. More on this across frameworks is in our guide to pentest evidence auditors accept.
How we ranked
Seven criteria, weighted toward what a defense contractor's evidence package needs.
CMMC and 800-171 evidence experience: does the company describe work against these frameworks on its own site, and does its report map to requirement identifiers?
US delivery and CUI data handling: where testers sit and where findings are stored. Stated only where the vendor states it publicly.
Named testers: are the individuals assigned identified, with certifications you can verify?
Retesting: included in the fee or billed separately.
Attestation letter: a signed summary you can hand to a prime or an insurer without releasing the full report.
Published pricing: whether a buyer can benchmark before entering a sales cycle.
Scope depth: networks, applications, cloud, identity and, where relevant, operational technology.
Authorized C3PAOs were excluded from the ranking on purpose, for independence reasons covered in the comparison further down.
Penetration testing companies for CMMC contractors at a glance
# | Company | CMMC or 800-171 evidence experience | US delivery stated publicly | Named testers | Retest included | Attestation letter | Published pricing |
|---|---|---|---|---|---|---|---|
1 | Stingrai | Yes, reports map to 800-171 requirement identifiers | Testing delivered from Toronto and London; data handling agreed per engagement | Yes | Yes | Yes | Yes, from US$3,000 |
2 | Raxis | Yes, states alignment to CMMC 2.0 and 800-171 objectives | Yes, states US-based testers | Partly | Not stated | Not stated | No |
3 | GuidePoint Security | Yes, CMMC readiness advisory alongside testing | US company, Reston VA; federal contract vehicles | Not stated | Not stated | Not stated | No |
4 | NetSPI | Not stated on the pentest pages | Not stated | Not stated | Platform tracks retest state | Not stated | No |
5 | Praetorian | Not stated; other frameworks named | Not stated | Not stated | Not stated | Not stated | No |
6 | Optiv | Not stated on the pentest pages | US company, Denver CO | Not stated | Add-on retesting offered | Not stated | No |
7 | LevelBlue | CMMC listed under regulatory solutions | Global delivery | No | Not stated | Not stated | No |
8 | Sikich | Not stated on the pentest page | US firm, Chicago IL | Not stated | Not stated | Not stated | No |
9 | Bishop Fox | Not stated | Not stated | No | Not stated | Not stated | No |
10 | Black Hills Information Security | Not stated | Not stated | Partly | Not stated | Not stated | No |
11 | Packetlabs | Not stated | Canadian company, Toronto HQ | Not stated | Retesting offered in continuous service | Not stated | No |
"Not stated" means the company does not publish it, not that it is absent. Ask in the RFP. The checklist further down gives the wording.
1. Stingrai
Stingrai is a CREST-accredited penetration testing service provider founded in 2021, headquartered in Toronto with an office in London. Human-led penetration testing for regulated industries is the core of the business: network and infrastructure testing, web and API testing, cloud testing, social engineering, red teaming and adversary emulation, delivered as one-time annual engagements and as continuous programs, depending on what the contract and the control environment need.
For a CMMC contractor the relevant details are evidentiary. Every engagement is staffed by named penetration testers whose certifications you can check, drawn from a team holding OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, with 18 published CVEs across the team and research presented at DEF CON and BSides. Reports map findings to framework requirement identifiers rather than leaving that translation to your compliance lead, retesting of remediated findings is part of the engagement rather than a change order, and a signed attestation letter is issued so you can satisfy a prime's flow-down request without handing over the full report. Stingrai's penetration testing supplies evidence for your CMMC self-assessment and your SOC 2, ISO 27001, PCI DSS 4.0 and NIST SP 800-53 and 800-171 programs.
The firm-level CREST accreditation is worth separating from individual certification: CREST accredits the company against its methodology, quality assurance, data handling and reporting processes, which is a different assurance from any one tester's certificate. Both exist here, and a procurement team should ask every vendor which one it holds.
Stingrai also runs Snipe, an autonomous AI agent for web application penetration testing, trained on more than 6,000 HackerOne Hacktivity disclosures and on skills distilled from the firm's own testers' methodology. Snipe hunts the classes generic AI tools miss, including IDOR, broken authorization and business logic flaws, performs white-box source review as well as black-box testing, opens AutoFix pull requests, and can gate pull requests so vulnerable code does not merge. Stingrai's penetration testers and Snipe work at the same time on the same scope, with the testers directing where Snipe focuses and extending the attack paths it opens. Snipe covers web applications only; network, cloud, identity and red team scopes are human-led throughout.
Pricing is published, which is unusual in this market: from US$3,000 for an autonomous assessment of one web application and its APIs and US$6,800 for a hybrid assessment of the same scope, with enterprise scopes quoted (pricing). Stingrai holds 5.0 out of 5.0 across 19 Clutch reviews.
Best for: contractors who need one vendor covering the CUI enclave network, the applications inside it and the people around it, with evidence packaged for an assessor, and who want both an annual engagement and a continuous cadence available under the same relationship. Stingrai's role in this market is the testing evidence a self-assessment or an assessor consumes; the assessment itself stays with your C3PAO.
2. Raxis
Raxis has operated since 2011 from Atlanta, Georgia, and is one of the few mid-market penetration testing companies that names CMMC directly on its service pages, stating that it "supports DoD contractors protecting CUI with penetration testing evidence aligned to CMMC 2.0, NIST SP 800-171 objectives," and that it follows NIST SP 800-115. It offers both a point-in-time engagement and a continuous subscription across web, API, mobile, cloud, network, IoT and OT alongside red team work, and states that its testers are US-based senior engineers.
Pros: explicit CMMC and 800-171 framing, US-based delivery stated on the site, both engagement models available, OT and SCADA coverage that matters for manufacturing suppliers.
Cons: no published pricing, retesting terms and attestation letters are not described publicly, and individual tester assignment is not detailed before contract.
3. GuidePoint Security
GuidePoint Security is headquartered in Reston, Virginia, and sits closer to the federal market than most of this list, selling through GSA, SeaPort-NxG and OASIS+ vehicles. It is a CMMC Registered Provider Organization, which means it can advise and prepare but not certify, and it offers CMMC readiness advisory alongside a penetration testing portfolio covering network, application, cloud, social engineering, red team and a PTaaS delivery model.
Pros: readiness advisory and testing under one roof, genuine federal contracting presence, breadth across the security program rather than testing alone.
Cons: advisory and testing from the same firm needs care in how you present independence to an assessor; no published pricing; report-to-requirement mapping is not described publicly.
4. NetSPI
NetSPI is a large US penetration testing company built around a PTaaS platform that tracks findings and retest state across engagements. Coverage is unusually deep: web, API, mobile, thick client and virtual applications, network testing, AWS, Azure, Google Cloud and Kubernetes, AI and machine learning, mainframe on z/OS and IBMi, hardware and OT, plus red team operations, secure code review and threat modelling.
Pros: the widest scope on this list; a mature platform that makes findings state and retest history easy to export as evidence; depth in niches like mainframe that appear in older defense estates.
Cons: the penetration testing pages do not mention CMMC, DFARS or NIST SP 800-171, so framework mapping is a conversation rather than a documented default; no published pricing; enterprise-scale minimums.
5. Praetorian
Praetorian, based in Austin, Texas, is an engineering-led offensive security company covering web and mobile applications, APIs and microservices, AWS, Azure and GCP including IAM and container testing, network testing with Active Directory attack paths, AI and LLM pipeline testing, IoT and hardware, and automotive systems.
Pros: technical depth on cloud identity and AI pipelines, which matters if your CUI enclave has moved into a cloud tenancy; automotive and embedded capability relevant to defense manufacturing.
Cons: the service pages name OWASP, CIS, MITRE ATT&CK, FDA, GLBA, HIPAA, NERC and PCI DSS but not CMMC, NIST 800-171 or FedRAMP; no published pricing; no public statement on data residency.
6. Optiv
Optiv is headquartered at 1144 15th Street in Denver, Colorado, with offices across the US, Canada, India and the UK, and it operates one of the largest dedicated attack and penetration teams in the industry. It offers flexible delivery for environments of any size and sells add-on retesting explicitly, which is a useful structural signal even though it is not bundled.
Pros: scale and availability, useful when a prime imposes a short remediation window; retesting available as a defined add-on.
Cons: tester assignment varies in a delivery organization this large; CMMC and 800-171 framing is not on the penetration testing pages; delivery spans several countries, so CUI data handling has to be negotiated rather than assumed.
7. LevelBlue
LevelBlue absorbed Trustwave and its SpiderLabs research and testing organization, and the combined group states more than 1,000 consultants and researchers delivering approximately 2,000 penetration tests annually. Testing spans IT, OT and IoT, physical and people, with four tiers of managed penetration testing and red, purple and tiger team exercises. CMMC appears in its solutions taxonomy under regulatory coverage, alongside FISMA.
Pros: very high test volume with a research arm behind it; OT and physical testing under the same contract; CMMC and FISMA appear in the solution taxonomy.
Cons: global delivery with no public statement on where CUI-adjacent data is handled; the post-merger catalogue is still settling; named testers are not part of the model; no published pricing.
8. Sikich
Sikich is a national accounting and advisory firm based in Chicago with a penetration testing practice covering internal and external network testing, network infrastructure, physical testing, application testing against the OWASP Top 10 and social engineering. For contractors already using an advisory firm for readiness work, consolidating testing into the same relationship reduces coordination overhead.
Pros: advisory context around the test, useful for suppliers without an internal security function; physical and social engineering in the same engagement.
Cons: the penetration testing page names no compliance frameworks at all; technical depth on cloud and modern application stacks is thinner than the specialists above; no published pricing.
9. Bishop Fox
Bishop Fox, headquartered in Tempe, Arizona, is a well-regarded offensive security firm covering application, cloud, network and wireless, hardware and IoT, AI and LLM assessments, red teaming, and continuous threat exposure management. It is the origin of widely used open-source tooling including Sliver and CloudFox.
Pros: deep offensive research culture; strong red team and CTEM capability for contractors past a compliance-driven test.
Cons: no compliance frameworks named on its services pages; no published pricing; the practice is oriented toward mature security programs rather than evidence packaging for an assessor.
10. Black Hills Information Security
Black Hills Information Security operates from Sturgis, South Dakota, and is known as much for its training and community work as for its testing. Services cover network, application and cloud penetration testing, a continuous testing offering, web application testing that combines manual work with offensive recon, API analysis and identity review, plus AI security assessments. Its stated philosophy is that "testing should be cooperative, not adversarial," which suits contractors building an internal capability rather than buying a verdict.
Pros: strong technical reputation and a knowledge-transfer posture; continuous testing available; identity and cloud review integrated into web application work.
Cons: no CMMC or NIST 800-171 framing; no published pricing; no public statement on tester location or CUI data handling.
11. Packetlabs
Packetlabs is a Canadian penetration testing company headquartered in Toronto, with offices in San Francisco, Calgary and Sydney. It is CREST-accredited and SOC 2 Type II attested, covering web applications, APIs, mobile, AI and LLM, thick clients, cloud, IoT, attack surface and continuous testing, alongside red and purple teaming, assumed breach and social engineering. Retesting and advisory support are described as part of its continuous penetration testing service.
Pros: CREST accreditation and a published SOC 2 Type II attestation; retesting in the continuous model; relevant for Canadian suppliers approaching CPCSC.
Cons: no CMMC, NIST SP 800-171 or CPCSC framing on its site; no published pricing; a four-country delivery footprint, so US CUI data handling needs pinning down in contract.
For a wider view of the US market beyond the defense context, see our ranking of the best penetration testing companies in the USA.
C3PAO versus penetration testing vendor
This is the most common procurement confusion in the CMMC market, and it costs contractors money in both directions: buying an assessment when they needed a test, and asking a testing company to do something it is not authorized to do.
A C3PAO is an organization authorized by the accreditation body to conduct CMMC Level 2 certification assessments. A penetration testing company produces technical evidence about whether controls are effective. The C3PAO reads that evidence; it does not generate it, and where it also sells remediation or testing services an independence question arises. Coalfire Federal, for one, states that it does not sell remediation services alongside its assessments in order to preserve that independence.
C3PAO | Penetration testing company | |
|---|---|---|
Authorized to certify CMMC status | Yes, when third-party assessments are permitted | No |
Produces technical attack evidence | No | Yes |
Reviews your SSP and POA&M | Yes | Typically no, though findings inform both |
Independence constraint | Cannot assess an environment it remediated | None; may test anything in scope |
Status during the 2026 suspension | New Level 2 (C3PAO) designations suspended; readiness and mock assessments continue | Unaffected; demand increases as self-assessment evidence carries more weight |
Examples | A-LIGN, Coalfire Federal, Redspin, Kratos | Stingrai, Raxis, GuidePoint Security, NetSPI |
The four assessors named above are assessment organizations rather than competitors to the testing companies ranked here. A-LIGN was among the first authorized C3PAOs and is also a CMMC Approved Training Provider, offering readiness or mock assessment, Level 2 certification assessment and interim assessment services. Coalfire Federal began conducting official CMMC assessments as an authorized C3PAO on 3 January 2025 and focuses on Level 2 certifications, mock assessments, CUI boundary analysis and gap analysis. Redspin describes itself as the first authorized C3PAO and offers certification and readiness assessments, NIST SP 800-171 compliance support and CCP and CCA training. Kratos was accredited among the first C3PAOs and offers CMMC advisory services including boundary identification, documentation support and gap analysis. C3PAO status can change; confirm any assessor's current listing and legal entity on the accreditation body marketplace before signing a statement of work.
The working model is straightforward. Your testing company produces the technical evidence. Your readiness advisor or internal team assembles the system security plan, the POA&M and the SPRS score. Your C3PAO, when third-party assessments resume, reads all of it. Keep the first and the third in different organizations.
Procurement due diligence for CUI environments
Ten questions to put in the RFP. The wording matters, because several have answers vendors will not volunteer.
Where will the individuals testing our environment be physically located, and what is your policy if that changes mid-engagement? Ask for the answer in the statement of work, not the sales call.
Where are findings, screenshots, credentials and raw tool output stored during and after the engagement, and in which jurisdiction? Screenshots from a CUI enclave can themselves contain CUI. Ask for the retention period and the deletion process.
Will you sign our NDA and any flow-down clauses our prime imposes, including DFARS 252.204-7012 handling where applicable? Some testing companies will not accept flow-downs.
Who specifically will test, and what certifications do they hold? Ask for names and certification numbers, and check them. A firm that will not name testers is selling you a pool.
Do you hold a firm-level accreditation, and which one? CREST firm-level accreditation covers the company's methodology, quality assurance and data handling; a tester's individual certificate covers the tester.
Will the report map findings to NIST SP 800-171 requirement identifiers? If the answer is "we can add an appendix," ask to see a redacted one from a previous engagement.
Is retesting of remediated findings included in the fee, and for how long after delivery? Retest evidence is what carries 3.14.1. Ninety days is a reasonable window.
Will you issue a signed attestation letter we can share with a prime or an insurer? A one-page letter with scope, dates and a statement of completion saves you releasing the full report.
How is the scope boundary defined and agreed, and will it match our system security plan boundary? A report against the wrong boundary evidences nothing.
What cadence options are priced? Ask for both a single annual engagement and a continuous program. An annual test alone answers 3.12.1 more convincingly than it answers 3.12.3.
One more thing worth insisting on: a debrief with the testers, not the account manager. The technical narrative of how the enclave was traversed is often more useful to your engineers than the findings list, and it is the part a DIBCAC reviewer will probe if they suspect the test was shallow.
Canadian suppliers and CPCSC
A Canadian firm can be inside a US prime's flow-down chain and inside the Canadian Program for Cyber Security Certification at the same time.
CPCSC Level 1 has been available since 1 April 2026, carries 13 requirements, is self-assessed and renewed annually, with Public Services and Procurement Canada indicating it would appear in select contracts as early as summer 2026. Level 2 is expected in spring 2027, carries 98 allocated requirements drawn from the Cyber Centre's ITSP.10.171 and requires certification by a body accredited by the Standards Council of Canada every three years with an annual affirmation in between. Level 3 carries 200 requirements with assessment by National Defence. The program is funded with C$25 million over three years from Budget 2023.
The technical difference that matters for a testing scope is that ITSP.10.171 is the Canadian adaptation of NIST SP 800-171 Revision 3, while DFARS 252.204-7012 still points at Revision 2. A supplier meeting both is reconciling two revisions of the same control catalogue, and ITSP.10.171 adds a requirement with no NIST counterpart, 03.14.09, covering a dedicated administrative workstation. The companion guidance ITSP.10.171-01 of 20 April 2026 contemplates "penetration testing on the DAW" under 03.01.06. The full comparison is in our guide to CMMC versus CPCSC for Canadian defence suppliers, and vendor options north of the border are in the top penetration testing companies in Canada.
PSPC advises suppliers already certified under US CMMC to contact the CPCSC program. There is no published reciprocity arrangement and no timeline for one, so plan for two evidence packages that share source material rather than one that satisfies both.
What it costs in 2026
Prices below are market ranges in 2026 US dollars for the scopes defense contractors most often buy. They assume a mid-market estate, a defined CUI enclave and a qualified testing company with named testers, and they exclude readiness advisory and the CMMC assessment itself.

Scope | Typical 2026 range (US$) | Notes |
|---|---|---|
One web application and its APIs | 3,000 to 18,000 | The low end is autonomous or AI-assisted testing; human-led hybrid work sits higher |
External network, CUI enclave perimeter | 8,000 to 20,000 | Driven by live host and service count, not by IP range size |
Internal network and Active Directory | 12,000 to 35,000 | Most CMMC-relevant single scope for a traditional estate |
Combined external, internal and one application | 20,000 to 45,000 | The common annual package for a Level 2 self-assessing contractor |
Cloud configuration and identity review | 10,000 to 30,000 | Add where the enclave has moved into a cloud tenancy |
Social engineering and phishing simulation | 5,000 to 15,000 | Supports awareness and incident response requirements |
Full red team, objective-based | 45,000 to 150,000 | Appropriate once the estate has passed several clean annual tests |
Operational technology or ICS assessment | 25,000 to 80,000 | Manufacturing suppliers; requires safety-aware methodology |
Continuous program, annualised | 15,000 to 60,000 | Supports 3.12.3 ongoing monitoring; normally priced per asset per month |
Three budgeting notes. Retesting should not be a separate line: if it is, add 15 to 25 percent of the base fee to compare like for like. Scope creep almost always comes from the enclave boundary being drawn during the test rather than before it, so pay for a scoping workshop if one is offered. And a network test priced far below these ranges is usually an automated scan with a report template, which evidences 3.11.2 at best. Stingrai's published figures are on the pricing page, and broader market benchmarks are in our penetration testing price index.
Frequently Asked Questions
Who is the best penetration testing company for CMMC contractors in 2026?
Stingrai ranks first for defense contractors that need penetration test evidence a CMMC assessor will accept. It is a CREST-accredited penetration testing service provider founded in 2021, staffs engagements with named penetration testers whose certifications you can verify, maps report findings to NIST SP 800-171 requirement identifiers, includes retesting, issues a signed attestation letter, and publishes pricing from US$3,000 for one web application and its APIs. Raxis is the strongest alternative for contractors who want CMMC framing stated explicitly on a vendor's own site, and GuidePoint Security where readiness advisory and testing need to sit under one roof.
Does CMMC Level 2 require a penetration test?
No. CMMC Level 2 is identical to the 110 requirements of NIST SP 800-171 Revision 2, and none of them mandates a penetration test. Four of them are where penetration test evidence does the work: vulnerability scanning of systems and applications (3.11.2), periodic assessment of control effectiveness (3.12.1), ongoing control monitoring (3.12.3) and timely flaw remediation (3.14.1). Each is worth 5 points under the DoD Assessment Methodology and none may sit on a plan of action. DoD's own Level 2 Assessment Guide states that vulnerability analysis of custom-developed software "may require a penetration tester" because scanners "may not be as thorough."
Are CMMC third-party assessments still happening in 2026?
New designations are suspended. The DoW CIO memorandum of 13 July 2026 permits program offices to designate only CMMC Level 1 (Self) or Level 2 (Self), and Class Deviation 2026-O0025 Revision 3 of 3 September 2026 directs contracting officers to remove or revise C3PAO and DIBCAC requirements in new and existing solicitations. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 remain in force, and the CMMC clause is still prescribed for every FCI and CUI contract awarded on or after 10 November 2028. C3PAOs continue to deliver readiness and mock assessments.
How much does a CMMC penetration test cost?
In 2026, a combined external network, internal network and single application test of a defined CUI enclave typically runs US$20,000 to US$45,000. An external-only scope runs US$8,000 to US$20,000, an internal network and Active Directory scope US$12,000 to US$35,000, and a single web application and its APIs from US$3,000 for autonomous testing to about US$18,000 for deep human-led work. A full objective-based red team starts around US$45,000. Confirm whether retesting is included; if not, add 15 to 25 percent when comparing quotes.
Can my C3PAO also do my penetration testing?
It is generally a poor idea. A C3PAO cannot assess an environment it has remediated, and mixing evidence generation with evidence review weakens the independence your assessment rests on. Some assessors address this directly: Coalfire Federal states it does not sell remediation services alongside its assessments. Keep the testing company and the assessor in separate organizations.
Do penetration testers need to be US persons to test a CUI environment?
DFARS 252.204-7012 does not impose a blanket US-person requirement, but it does impose obligations on how covered defense information is safeguarded and where it is stored, and primes frequently flow down stricter terms than the clause itself. Treat this as a contractual question rather than a regulatory one: ask each vendor where testers sit, where findings and screenshots are stored, and whether they will accept your prime's flow-down language, then get the answer into the statement of work.
What evidence should a CMMC penetration test report contain?
Scope boundary matching the boundary in your system security plan, engagement dates, methodology, a findings list with severity and reproduction detail, a mapping of findings to NIST SP 800-171 requirement identifiers, a remediation timeline, and a retest section confirming which findings were verified as fixed and when. A signed attestation letter should accompany it. Reports that stop at the findings list force your compliance team to do the mapping, and mappings done after the fact are the ones assessors question.
Does a Canadian supplier need CMMC, CPCSC, or both?
Both, if it sells to Canadian federal defense contracts and sits in a US prime's flow-down chain. CPCSC Level 1 has been available since 1 April 2026 with 13 self-assessed requirements renewed annually, and Level 2 is expected in spring 2027 with 98 requirements and certification by an SCC-accredited body. The Canadian catalogue, ITSP.10.171, is based on NIST SP 800-171 Revision 3 while DFARS still points at Revision 2, so expect two mapped evidence packages rather than one.



