The word "penetration" appears exactly once in the entire text of 32 CFR part 170, the regulation that creates the Cybersecurity Maturity Model Certification, and that single occurrence sits at § 170.14(c)(4)(xx) inside a Level 3 requirement. It appears zero times in NIST SP 800-171 Revision 2, which is the complete Level 2 control set, and zero times in the DoD Assessment Methodology v1.2.1.
That is the regulatory answer, and we sell penetration testing, so take it as given against interest: CMMC Levels 1 and 2 impose no obligation on a contractor to conduct a penetration test. Any vendor telling you your Level 2 assessment mandates an annual third-party pentest is selling against a control that does not exist.
The procurement answer is different and more useful. Four Level 2 requirements are worth 5 points each under the DoD Assessment Methodology and cannot be deferred to a plan of action, the assessor decides whether your controls are effective in their application, and your score is a representation to the government that carries False Claims Act exposure. This guide is for the compliance lead who has to defend that score: what each level requires, what assessors accept, how to scope a CUI enclave, what belongs in the report, and what it costs in 2026 dollars.
The direct answer, by level
CMMC level | Contractor penetration test required? | Governing text | Who assesses | Cadence |
|---|---|---|---|---|
Level 1 (FCI) | No | 15 FAR basic safeguarding requirements at 48 CFR 52.204-21(b)(1), via § 170.14(c)(2) | The contractor | Annual self-assessment (§ 170.15) |
Level 2 (Self) (CUI) | No | § 170.14(c)(3): Level 2 requirements "are identical to the requirements in NIST SP 800-171 R2" | The contractor | Every 3 years, annual affirmation (§ 170.16) |
Level 2 (C3PAO) (CUI) | No | The same 110 requirements, assessed per NIST SP 800-171A | An authorized or accredited C3PAO | Every 3 years (§ 170.17) |
Level 3 | Yes | CA.L3-3.12.1e at § 170.14(c)(4)(xx), one of 24 selected NIST SP 800-172 requirements | DCMA DIBCAC | Every 3 years (§ 170.18), test at least annually |
Three clarifications settle most procurement arguments.
What the Level 2 assessment guide actually says. It does not mandate a penetration test, but it does tell assessors that verifying the vulnerability scanning requirement "may require a penetration tester", that controls should be "assessed at least annually", and that a "set it and forget it" posture fails. That is guidance to the assessor about how deep to go, not a clause you can point a supplier at.
What assessors accept. NIST SP 800-171A gives assessors three method families: EXAMINE, INTERVIEW and TEST. Appendix D describes TEST and lists among typical assessor actions "conducting penetration testing of key system components". Penetration testing is therefore expressly contemplated inside the Level 2 framework, and a current independent test report is the artifact that most reliably answers an assessor asking whether a control is effective rather than merely documented. That is the honest basis for buying one at Level 2: accepted evidence, not a mandate.
Level 3 is not a level you can walk into. Under § 170.18, a Final Level 2 status awarded by a C3PAO is a prerequisite, § 170.19(e) requires the Level 3 scope to be equal to or a subset of the Level 2 scope, and Level 2 POA&M items must be closed first.
The four controls that make a penetration test the practical evidence

Almost every "CMMC requires penetration testing" claim traces back to one of these. None of them prescribes a method. All but one is worth 5 points and cannot go on a POA&M.
Identifier | Requirement text | DoD points | POA&M-eligible? |
|---|---|---|---|
RA.L2-3.11.2 | "Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified." | 5 | No |
CA.L2-3.12.1 | "Periodically assess the security controls in organizational systems to determine if the controls are effective in their application." | 5 | No |
CA.L2-3.12.3 | "Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls." | 5 | No |
SI.L2-3.14.1 | "Identify, report, and correct system flaws in a timely manner." | 5 | No |
RA.L2-3.11.3 | "Remediate vulnerabilities in accordance with risk assessments." | 1 | Yes |
RA.L2-3.11.2 is scanning, not penetration testing. Its discussion covers static, dynamic and binary analysis, SCAP-validated tools, and CVE, OVAL, CWE, NVD and CVSS. One sentence gets quoted out of context: "Security assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan." Read in place, that is context about where scan targets come from, and it obligates nothing. What the requirement does establish is coverage, and the assessment guide's phrasing about all devices connected to the network is where forgotten hosts turn into findings.
CA.L2-3.12.1 is the most misrepresented control in the framework. NIST SP 800-171A decomposes it into exactly two objectives: 3.12.1[a], the frequency of security control assessments is defined, and 3.12.1[b], controls are assessed with that frequency to determine if they are effective in their application. Nothing requires the frequency to be annual and nothing requires the method to be a penetration test. What the objective does require is a judgment about effectiveness, which is exactly what a scan struggles to demonstrate and a test demonstrates directly.
CA.L2-3.12.3 is continuous monitoring. It asks for an ongoing rather than point-in-time view of control effectiveness. Dashboards, recurring reports and evidence that outputs feed risk decisions satisfy it. Contractors who buy one test a year and nothing else often pass 3.12.1 and struggle on 3.12.3.
SI.L2-3.14.1 is flaw remediation, and it is the quiet 5-pointer. Assessors read it end to end: discovery evidence, a reporting path, corrective action, and a defined meaning of "timely". A test report with severity ratings, a ticketed remediation trail and a retest is a single artifact that speaks to all four.
RA.L2-3.11.3 is the only one you can defer. Remediation is worth 1 point, so it is the sole item in this group that a Conditional status can carry on a POA&M.
The scoring trap: the assessment controls cannot go on a POA&M
The POA&M rule at § 170.21(a)(2)(ii) permits a Conditional CMMC Status only where no requirement on the POA&M has a point value greater than 1, with a single exception for CUI encryption that is employed but not FIPS-validated, worth 3 points, and only where the score ratio is at least 0.8.
Scanning, periodic assessment, continuous monitoring and flaw remediation are each worth 5 points. All four are POA&M-ineligible and must be scored MET on assessment day. A contractor planning to sort out testing and monitoring after certification cannot pass. Where a POA&M is permitted, § 170.21(b) starts a hard clock: closure must be confirmed by a closeout assessment within 180 days of the Conditional status date, or the status expires.
Scoring starts at 110 and subtracts. Section 170.24 notes it "may result in a negative score", and 5 points are assigned where non-implementation "could lead to significant exploitation of the network, or exfiltration of CUI". Negative scores are not hypothetical. On 18 June 2026 the Department of Justice announced that LOGZONE paid US$507,144 to resolve False Claims Act allegations concerning two Navy contracts, with a DIBCAC-assessed score of -170 on a scale running from -203 to 110. On 1 September 2026, Honeywell Aerospace agreed to pay US$2,042,518 over NIST SP 800-171 implementation on one network between April 2020 and December 2023, with a whistleblower share of US$375,823 and no determination of liability. Both are civil settlements rather than findings, and both make the same point: the SPRS number is a representation.
Scoping: draw the CUI enclave before you price anything
Scope is the dominant variable in both cost and risk, and under § 170.19 the categorization is largely self-declared.
CUI Assets: assessed against all Level 2 requirements.
Security Protection Assets: assessed against the requirements relevant to their capabilities.
Contractor Risk Managed Assets: if sufficiently documented, not assessed against other CMMC requirements, with limited checks only where the documentation raises assessor concerns.
Specialized Assets (IoT, IIoT, OT, government furnished equipment, restricted information systems, test equipment): the assessor reviews the SSP and does not assess them against other requirements.
Out-of-Scope Assets: not assessed.
A defensible penetration testing scope for a CUI enclave usually has four parts.
External. Every internet-facing asset that fronts the enclave: VPN and remote access, email and collaboration gateways, file transfer portals used to exchange CUI with the prime, and any supplier or engineering portal. The objective is to show that a remote attacker cannot reach CUI, and to surface exposure your asset inventory does not list.
Internal. The enclave itself, from an assumed-breach position on a workstation or a low-privilege account: Active Directory or Entra ID privilege paths, lateral movement from a general corporate segment into the enclave, file share permissions on CUI repositories, and the effectiveness of the segmentation you declared. This is where scoping declarations live or die. A test that reaches CUI from an asset you categorized as Out-of-Scope tells you your boundary is wrong while you can still fix it.
Applications. Web applications and APIs that store, process or transmit CUI: engineering data management, quoting portals, customer-facing document exchange. Authorization and access-control flaws matter more here than injection classes, because CUI leakage usually looks like one authenticated user reading another organization's data.
Cloud enclaves. If your CUI lives in Microsoft 365 GCC High, Azure Government or AWS GovCloud, the work is a configuration and identity review inside your responsibility boundary, not an attack on the provider: conditional access and MFA enforcement, guest and external sharing, privileged role assignment, DLP and sensitivity labels on CUI, sharing links on CUI document libraries, and the federation between your corporate tenant and the government tenant. Respect the provider's testing rules of engagement.
What is out of scope. Government systems, the prime's networks, provider infrastructure, and assets outside the declared boundary. A segmented corporate network carrying no CUI can sit outside the enclave test, but the internal test proving the segmentation holds is what keeps it there. Specialized Assets belong in the report as a documented exclusion with a rationale, not as an untested silence.
How often, and when relative to the assessment
The cadence question has three answers, because three different clocks run.
The regulatory clock. Level 1 self-assessment is annual. Level 2, self or C3PAO, is every three years, as is Level 3, and the DoD Assessment Methodology anticipates roughly the same cycle.
The affirmation clock. Under § 170.22, a named senior Affirming Official attests to continuing compliance in SPRS after every assessment and annually thereafter. That annual personal attestation, not the three-year assessment, is the practical argument for validating posture in between, and it is the hook that carries personal accountability into a False Claims Act case.
The change clock. A new CUI application, a migration into GCC High, a merger that joins networks, a new remote access path: each invalidates last year's evidence, whatever the calendar says.
A workable pattern for a Level 2 (Self) contractor: run the enclave test 8 to 12 weeks before the self-assessment closes, remediate, retest the closed items, then refresh annually ahead of the affirmation and again on significant change. For a Level 2 (C3PAO) contractor, run it 3 to 4 months before the certification window, because artifacts must be frozen and hashed under § 170.17(c)(4) before the assessment begins and you cannot remediate while the artifact list is sealed. At Level 3, CA.L3-3.12.1e sets the floor: at least annually or when significant security changes are made.
Never post a score you cannot defend and then test afterwards. If the test finds that a 5-point control is not effective, you have already made the representation.
What the report must contain for an assessor
For Level 2, the SP 800-171A procedure for CA.L2-3.12.1 has the assessor examine assessment policy and procedures, the security assessment plan, the SSP and other records, interview security assessment personnel, and test the mechanisms supporting assessment and reporting. At Level 3, SP 800-172A names the penetration test report itself as an assessment object and puts the penetration testing team on the interview list. A report that survives both looks like this.
Rules of engagement, signed and dated by both parties. NIST SP 800-172 states that all parties agree to these before testing commences, and it is the first page an assessor turns to.
A scope declaration mapped to § 170.19 categories. Named IP ranges, URLs, cloud tenancies and accounts, tied to CUI Assets, Security Protection Assets and declared exclusions.
A methodology naming both automated tooling and expert-led manual testing. At Level 3 this is not optional: SP 800-172A requires both to be identified and used. A pure scan fails one objective, and a purely manual test with no tooling documented fails the other.
Named testers with their credentials, and the firm's accreditation. Not because CMMC requires a certification, it does not, but because an assessor may interview the testing team.
Findings with severity, evidence and reproduction steps, mapped to the affected asset and, ideally, to the NIST SP 800-171 requirement they bear on.
A defined remediation timeline, which is what makes "in a timely manner" in SI.L2-3.14.1 assessable rather than aspirational.
A retest or remediation verification letter, dated after the fixes. This is the artifact that closes a POA&M inside the 180-day window, and the one most often missing.
An attestation page and artifact hashes, so the report slots into the § 170.17(c)(4) artifact list with its name, hash value and hashing algorithm.
An executive summary a CFO and a contracting officer can read.
Our companion guide covers the artifact patterns framework by framework: pentest evidence auditors accept for SOC 2, ISO 27001, PCI DSS and CMMC.
What CMMC penetration testing costs in 2026
There is no published government rate for this work, so the honest way to price it is scope multiplied by day rate. Our penetration testing price index, built from published supplier rate cards, puts the median published day rate at US$1,364, with rates running from roughly US$655 to US$2,183 a day depending on discipline. US firms with an established defense practice commonly price above that median, so treat the ranges below as a planning band rather than a quote.
Scope component | Typical effort | 2026 planning range (US$) |
|---|---|---|
External perimeter of a small CUI enclave (up to about 25 live hosts) | 3 to 5 days | 4,000 to 10,000 |
Internal enclave and Active Directory, assumed breach | 5 to 10 days | 7,000 to 20,000 |
One web application and its APIs that handles CUI | 5 to 8 days | 6,000 to 16,000 |
Cloud enclave configuration and identity review (GCC High, Azure Government, GovCloud) | 3 to 6 days | 4,500 to 13,000 |
Social engineering and phishing simulation | 2 to 4 days | 3,000 to 8,000 |
Full Level 3 style scope: external, internal, applications and cloud | 18 to 30 days | 30,000 to 65,000 |
Retest of remediated findings | 1 to 2 days | included, up to 4,000 |
Three cost drivers dominate. Enclave size, because a 15-person CUI enclave and a 600-person engineering network are different engagements at the same maturity. Application count, because each application that touches CUI is its own scope. Segregation quality, because a flat network drags the whole estate into the test, which is the same reason it drags the whole estate into the assessment.
For published reference points, Stingrai lists one-time engagements starting at US$3,000 for an autonomous test of one web application and its APIs and US$6,800 for a hybrid test run with penetration testers, alongside continuous programs priced monthly. Current packages are on the Stingrai pricing page. Budget the retest alongside the test: a remediation verification letter dated after the fixes is worth more to an assessor than a longer original report.
Which level are you actually buying for
Level 1 | Level 2 (Self) | Level 2 (C3PAO) | Level 3 | |
|---|---|---|---|---|
Information | FCI | CUI | CUI | CUI, highest risk programs |
Requirements | 15 FAR safeguarding | 110 (NIST SP 800-171 Rev 2) | 110 (NIST SP 800-171 Rev 2) | 110 plus 24 selected SP 800-172 |
Assessed by | Contractor | Contractor | Authorized or accredited C3PAO | DCMA DIBCAC |
Assessment cadence | Annual | Every 3 years | Every 3 years | Every 3 years |
Affirmation | Annual | Annual | Annual | Annual |
Pentest mandated? | No | No | No | Yes, CA.L3-3.12.1e |
POA&M allowed? | No, all 15 must be MET | Yes, limited (§ 170.21) | Yes, limited (§ 170.21) | Yes, with 7 barred requirements |
Available in solicitations today | Yes | Yes | Suspended | Suspended |
What testing buys you | Little, focus on the 15 basics | Score defensibility, scope validation, evidence for four 5-point requirements | All of the above, plus artifacts that survive third-party scrutiny | Direct compliance with the requirement as written |
The last two rows are the 2026 reality. On 13 July 2026 the Department of War Chief Information Officer issued memorandum 26-P-1023, which states that "the upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended," that requiring activities "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period," and that "the allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)." It adds that the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through self-assessment and select government-led assessments, that DFARS 252.204-7012 requirements "remain in effect," and that no waivers shall be granted.
On 3 September 2026 the Office of the Assistant Secretary of War for Acquisition and Sustainment issued Class Deviation 2026-O0025, Revision 3, superseding Revision 2 of 16 July 2026, directing contracting officers to remove or revise CMMC requirements in new and existing solicitations and to modify existing contracts carrying C3PAO or DIBCAC requirements "prior to the exercise of the next option period or through the next scheduled administrative modification." The same deviation preserves the prescription that puts the CMMC clause in every solicitation and contract involving FCI or CUI awarded on or after 10 November 2028.
Everything else in this guide is unchanged. A class deviation departs from the DFARS, it does not rewrite 32 CFR part 170. The Level 2 control set is still the 110 requirements of NIST SP 800-171 Revision 2, the point values and POA&M rules are unamended, SPRS posting and the annual affirmation continue, and CA.L3-3.12.1e still reads as quoted below. The 60-day CMMC Reform Task Force report had not been published as of 19 September 2026, and a report is advice: only a further deviation, a DFARS rule or an amendment to part 170 changes an obligation.
For most contractors today a Level 2 self-assessment is the only assessment in play, which means the evidence behind your own score carries the weight a C3PAO would otherwise have carried. That is covered in detail in CMMC Level 2 self-assessment in 2026: scanning and pentest evidence that holds up.
CA.L3-3.12.1e: the one real mandate
At Level 3, § 170.14(c)(4)(xx) reads:
"Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts."
The cadence is DoD's, not NIST's. The underlying NIST SP 800-172 leaves frequency as an organization-defined parameter. DoD assigned "at least annually or when significant security changes are made" when it selected the requirement into CMMC.
Both tooling and experts are required. NIST SP 800-172A separates the objectives: automated scanning tools are identified, ad hoc tests using subject matter experts are identified, and testing is conducted at the defined frequency using both.
There is no third-party independence mandate. SP 800-172 states that penetration testing or red team exercises "may be organization-based or external to the organization", provided the team has the necessary skills and resources and is objective. OSCP, CREST and CEH appear zero times in 32 CFR part 170, SP 800-171 Rev 2, SP 800-172 and SP 800-172A. Accreditation is a procurement signal and a quality proxy, not a CMMC requirement.
It is not on the barred list. Seven Level 3 requirements cannot go on a POA&M under § 170.21(a)(3)(ii): IR.L3-3.6.1e, IR.L3-3.6.2e, RA.L3-3.11.1e, RA.L3-3.11.4e, RA.L3-3.11.6e, RA.L3-3.11.7e and SI.L3-3.14.3e. CA.L3-3.12.1e is not among them, so a missing penetration test can sit on a Level 3 POA&M and be closed inside the 180-day window.
One correction, because vendors get it wrong: CA.L3-3.12.1e is not a NIST SP 800-171 control. It originates in NIST SP 800-172 and reaches CMMC only through the 24 selected Level 3 requirements.
If you also sell into Canada: the CPCSC pointer
Canadian suppliers, and US primes with Canadian subsidiaries, now face a parallel regime. Public Services and Procurement Canada's Canadian Program for Cyber Security Certification opened Level 1 certification on 1 April 2026, with 13 requirements on an annual cycle, appearing in select contracts from summer 2026. Level 2, expected in spring 2027, carries 98 requirements drawn from the Cyber Centre's ITSP.10.171, is certified by a body accredited by the Standards Council of Canada, runs on a three-year cycle with annual affirmation, and includes a Canadian-specific control for a dedicated administration workstation with no NIST counterpart. Level 3 carries 200 requirements and is assessed by National Defence. The control sets rhyme but do not match, the certification bodies differ, and no reciprocity with CMMC has been announced. Full comparison, including where one penetration test can produce evidence for both programs: CMMC vs CPCSC for Canadian defence suppliers.
How Stingrai fits
Stingrai is an offensive security firm founded in 2021, headquartered in Toronto with a London office. We are a CREST-accredited penetration testing service provider at firm level, our team holds OSCE3, OSCP, OSWE, OSEP and CREST CRT among other certifications, we have published 18 CVEs, and we hold 5.0 out of 5.0 across 19 Clutch reviews. Human-led testing by senior penetration testers is our core work for regulated industries, delivered either as one-time annual engagements or as continuous programs, and our AI agent Snipe adds depth on web applications specifically.
For a defense contractor, our testing supplies evidence in five places: validating that the § 170.19 scope boundary holds under attack, grounding the Affirming Official's annual SPRS attestation, demonstrating effectiveness for the four 5-point requirements you cannot defer, proving POA&M remediations hold inside the 180-day window, and, at Level 3, delivering against CA.L3-3.12.1e as written, with a named testing team available for DIBCAC interview. Assessment and certification decisions sit with your assessor.
Related reading: the best penetration testing companies for CMMC and defense contractors in 2026, our wider ranking of the best penetration testing companies in the USA, and the penetration testing price index.
Frequently Asked Questions
What are the CMMC penetration testing requirements in 2026?
Only CMMC Level 3 requires a contractor to conduct penetration testing, through CA.L3-3.12.1e at 32 CFR 170.14(c)(4)(xx), at least annually or when significant security changes are made, using both automated scanning tools and ad hoc tests by subject matter experts. Levels 1 and 2 impose no penetration testing obligation. At Level 2, testing is the evidence most assessors accept for four requirements worth 5 points each that cannot go on a POA&M: RA.L2-3.11.2, CA.L2-3.12.1, CA.L2-3.12.3 and SI.L2-3.14.1.
Does CMMC Level 2 require penetration testing?
No. Section 170.14(c)(3) makes Level 2 identical to NIST SP 800-171 Revision 2, and the word "penetration" appears zero times in that publication. NIST SP 800-171A lists penetration testing among the typical assessor actions under the TEST method, and the Level 2 assessment guide notes that verifying vulnerability scanning "may require a penetration tester", but both are assessor options rather than contractor duties. Most Level 2 contractors commission a test anyway, because it is the strongest evidence that the 5-point requirements are effective in their application.
What are the CMMC pentest requirements for a Level 2 self-assessment?
There are none as a matter of regulation. A Level 2 self-assessment requires a defined and honored assessment frequency (3.12.1[a] and [b]), vulnerability scanning across all in-scope components, ongoing control monitoring, and timely flaw identification, reporting and correction. Because the Affirming Official personally attests to the SPRS score every year under § 170.22, most contractors run an annual enclave test 8 to 12 weeks before the score is posted, so findings can be remediated and retested first.
Is a CMMC compliance penetration test required before a C3PAO assessment?
No. A C3PAO assesses the 110 NIST SP 800-171 Revision 2 requirements per NIST SP 800-171A, none of which obligates a penetration test report. In practice contractors schedule one 3 to 4 months ahead of the window, because artifacts must be frozen and hashed under § 170.17(c)(4) before the assessment begins. Note that Level 2 (C3PAO) designations are suspended in new solicitations under the July 2026 memorandum and Class Deviation 2026-O0025 Revision 3.
How much does CMMC penetration testing cost?
Budget by scope rather than by level. In 2026, external testing of a small CUI enclave typically runs US$4,000 to US$10,000, an internal enclave and Active Directory test US$7,000 to US$20,000, a CUI-handling web application and its APIs US$6,000 to US$16,000, and a cloud enclave review in GCC High or GovCloud US$4,500 to US$13,000. A full Level 3 style scope across all four commonly lands between US$30,000 and US$65,000. Those bands are derived from published supplier day rates, where the median sits at US$1,364 a day.
How often should a defense contractor run a penetration test for CMMC?
Level 3 sets the only regulatory floor: at least annually or when significant security changes are made. For Levels 1 and 2 the practical cadence is annual, timed ahead of the SPRS affirmation rather than the three-year assessment, plus a fresh test after any significant change such as a new CUI application, a migration into GCC High, or a merger that joins networks. Retest remediated findings rather than closing them on a ticket.
Did the July 2026 suspension remove the CMMC requirements?
No. DoW CIO memorandum 26-P-1023 of 13 July 2026 suspended the November 2026 transition to Phase 2 and limited designations to Level 1 (Self) and Level 2 (Self), and Class Deviation 2026-O0025 Revision 3 of 3 September 2026 made that binding on contracting officers. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 remain in force, 32 CFR part 170 is unamended, SPRS posting and the annual affirmation continue, and the clause attaches to every FCI or CUI contract awarded on or after 10 November 2028.



