The word "penetration" appears exactly once in the entire text of 32 CFR part 170, the regulation that creates the Cybersecurity Maturity Model Certification, including its appendix. That single occurrence sits at § 170.14(c)(4)(xx), inside a Level 3 requirement. The word appears zero times in NIST SP 800-171 Revision 2, which is the complete Level 2 control set, and zero times in the DoD Assessment Methodology v1.2.1 or the 48 CFR CMMC acquisition final rule.
So here is the answer, and we sell penetration testing: CMMC Levels 1 and 2 impose no obligation on a contractor to conduct a penetration test. Only Level 3 does. If a vendor has told you that your Level 2 assessment requires an annual third-party pentest, they are selling against a control that does not exist.
That does not make testing worthless below Level 3. It makes it a decision you take on the merits rather than under a false mandate, and the second half of this post covers exactly where it pays for itself.
The direct answer, by level
CMMC level | Penetration test required? | Governing text | Who assesses |
|---|---|---|---|
Level 1 (FCI) | No | The 15 FAR basic safeguarding requirements at 48 CFR 52.204-21(b)(1)(i) through (xv), via § 170.14(c)(2) | The contractor, annual self-assessment (§ 170.15) |
Level 2 (CUI) | No | § 170.14(c)(3): "The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2" | Self-assessment every 3 years (§ 170.16), or a C3PAO certification assessment every 3 years (§ 170.17) |
Level 3 | Yes | CA.L3-3.12.1e at § 170.14(c)(4)(xx), one of 24 selected NIST SP 800-172 requirements | DCMA DIBCAC, every 3 years (§ 170.18) |
Level 3 is also not a level you can walk into. Under § 170.18, a CMMC Status of Final Level 2 awarded by a C3PAO is a prerequisite, § 170.19(e) requires that the Level 3 scope be equal to or a subset of the Level 2 scope, and any Level 2 POA&M items must be closed before the Level 3 assessment begins.
Why Level 2 has no penetration testing requirement
CMMC Level 2 is not a bespoke DoD control set. Section 170.14(c)(3) makes Level 2 identical to NIST SP 800-171 Revision 2, all 110 requirements. Search the official Rev 2 PDF for "penetrat" and you get nothing: not in a requirement, not in a discussion, not in a footnote.
It is worth noting what § 170.2 actually incorporates, because it is static and slightly odd. CMMC assesses against SP 800-171 Revision 2 (February 2020) and SP 800-171A (June 2018), both of which NIST formally withdrew on 14 May 2024. Revision 3 does not govern CMMC today. Anyone selling you "Rev 3 CMMC readiness" is working from the wrong baseline, and in any case SP 800-171 Rev 3 adds no penetration testing requirement either: "penetration" and "red team" both appear zero times in it.
The three Level 2 controls routinely misrepresented as a pentest mandate
Almost every "CMMC requires penetration testing" claim traces back to one of these three requirements. Here is what each actually says.
Identifier | Requirement text | Frequency | DoD points | POA&M-eligible? |
|---|---|---|---|---|
RA.L2-3.11.2 | "Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified." | Organization-defined, plus on new vulnerabilities | 5 | No |
CA.L2-3.12.1 | "Periodically assess the security controls in organizational systems to determine if the controls are effective in their application." | Organization-defined | 5 | No |
CA.L2-3.12.3 | "Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls." | Ongoing | 5 | No |
RA.L2-3.11.3 | "Remediate vulnerabilities in accordance with risk assessments." | As findings arise | 1 | Yes |
RA.L2-3.11.2 is scanning, not penetration testing. Its discussion talks about static, dynamic and binary analysis, SCAP-validated tools, and CVE, OVAL, CWE, NVD and CVSS. There is one adjacent sentence that gets quoted out of context: "Security assessments, such as red team exercises, provide additional sources of potential vulnerabilities for which to scan." Read it in place and it is descriptive context about where scan targets come from. It sits in the discussion, not the requirement, and it obligates nothing.
CA.L2-3.12.1 is the most misrepresented control in the entire framework. NIST SP 800-171A decomposes it into exactly two assessment objectives: 3.12.1[a], "the frequency of security control assessments is defined", and 3.12.1[b], "security controls are assessed with the defined frequency to determine if the controls are effective in their application." That is the whole test. The objective is that a frequency exists and is honored, not that the frequency be annual and not that the method be a penetration test. The Rev 2 discussion adds that organizations may choose other assessment activities "such as vulnerability scanning and system monitoring", which is permissive language, and that results should be obtained "with the appropriate level of assessor independence", which is a discussion statement rather than a requirement and names neither a party nor a method.
CA.L2-3.12.3 is continuous monitoring. It asks for an ongoing rather than point-in-time view of control effectiveness. Dashboards, recurring reports and evidence that outputs feed risk decisions satisfy it.
The nuance that keeps this honest: 800-171A contemplates pentesting as an assessor action
Anyone who greps SP 800-171A will find the phrase "penetration testing" in it twice, and it is worth pre-empting that. One occurrence sits in Appendix D's description of the TEST assessment method, which lists among typical assessor actions "conducting penetration testing of key system components". Because 800-171A's procedure for 3.12.1 lists TEST as one of three available method families, penetration testing is expressly contemplated inside the Level 2 framework as something a C3PAO assessor may choose to do.
That is an assessor option, not a contractor duty. The 800-171A assessment procedure for 3.12.1 names no penetration test report among its assessment objects: it names assessment and authorization policy, assessment procedures and plans, the SSP, other relevant records, interviews with assessment and security personnel, and "mechanisms supporting security assessment". So the accurate statement is not "penetration testing is absent from Level 2". It is that Level 2 places no penetration testing obligation on the contractor, while leaving the technique available to the assessor.
The scoring trap: the assessment controls cannot go on a POA&M
This is the most commercially useful fact in CMMC and it has nothing to do with penetration testing directly.
Cross-reference the DoD Assessment Methodology point values against the POA&M rule at § 170.21(a)(2)(ii), which permits a Conditional CMMC Status only where "None of the security requirements included in the POA&M have a point value of greater than 1 ... except SC.L2-3.13.11 CUI Encryption may be included on a POA&M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3; and ...", alongside a score ratio of at least 0.8.
Vulnerability scanning (3.11.2), periodic security assessment (3.12.1) and continuous monitoring (3.12.3) are each worth 5 points. All three are therefore POA&M-ineligible and must be scored MET on assessment day. Only remediation (3.11.3, worth 1 point) can be deferred. A contractor planning to "sort out scanning after we certify" cannot pass.
Where a POA&M is permitted, § 170.21(b) sets the clock: "The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire."
CA.L3-3.12.1e: the one real penetration testing mandate
At Level 3, § 170.14(c)(4)(xx) reads:
"Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts."
Three things about that sentence matter.
The cadence is DoD's, not NIST's. The underlying NIST SP 800-172 text leaves frequency as an organization-defined parameter. DoD assigned "at least annually or when significant security changes are made to the system" when it selected the requirement into CMMC. Table 1 to § 170.14(c)(4) contains exactly 24 Level 3 requirements; this is the 20th.
Automated tooling alone fails, and manual testing alone fails. NIST SP 800-172A decomposes the requirement into a defined frequency plus three objectives: [a] "Automated scanning tools are identified"; [b] "Ad hoc tests using subject matter experts are identified"; and [c] testing conducted at the defined frequency using both. A pure scan report fails objective [b]. A purely manual test with no tooling documented fails objective [a]. The methodology section of your report has to evidence both, explicitly.
It is not on the Level 3 POA&M-barred list. Seven Level 3 requirements are categorically barred from a POA&M at § 170.21(a)(3)(ii): IR.L3-3.6.1e, IR.L3-3.6.2e, RA.L3-3.11.1e, RA.L3-3.11.4e, RA.L3-3.11.6e, RA.L3-3.11.7e and SI.L3-3.14.3e. CA.L3-3.12.1e is not among them, so a missing penetration test can in principle sit on a Level 3 POA&M and be closed inside the 180-day window. That is a real, citable procurement window rather than an automatic disqualification.
One clarification worth making because vendors get it wrong: CA.L3-3.12.1e is not a NIST SP 800-171 control. It originates in NIST SP 800-172 (February 2021) and reaches CMMC only through the 24 selected Level 3 requirements.
Who may perform the Level 3 penetration test
There is no third-party independence mandate, and this is routinely overstated in the market.
NIST SP 800-172's discussion says the testing team should have "particular skills and experience that include technical expertise in network, operating system, and application-level security", and then states plainly that the penetration testing or red team exercises "may be organization-based or external to the organization. In either case, it is important that the team possesses the necessary skills and resources to do the job and is objective in its assessment." It also requires that "All parties agree to the specified rules of engagement before the commencement of penetration testing."
OSCP, CREST and CEH appear zero times in 32 CFR part 170, SP 800-171 Rev 2, SP 800-172 and SP 800-172A. An in-house team can satisfy CA.L3-3.12.1e if it is genuinely skilled and objective. Certifications and accreditations are procurement signals and quality proxies; they are not CMMC requirements, and it is worth being clear-eyed about which is which when you compare bids.
One caution on counting: SP 800-172 contains 45 occurrences of the string "penetration", but that number materially overstates its penetration testing content. Thirteen are "penetration testing"; 29 are "Penetration-Resistant", a NIST protection-strategy label attached to many enhanced requirements that have nothing to do with offensive testing; one is a hyphenation artifact across a line break.
Assessment structure, cadence and the annual affirmation
Provision | What it sets |
|---|---|
§ 170.15 | Level 1 self-assessment, annual, all 15 requirements must be MET. "No POA&Ms are permitted for CMMC Level 1." |
§ 170.16 | Level 2 self-assessment of all 110 requirements per SP 800-171A, every three years, with annual affirmation |
§ 170.17 | Level 2 certification assessment: "An authorized or accredited C3PAO must perform a Level 2 certification assessment in accordance with NIST SP 800-171A Jun2018." Every three years |
§ 170.18 | Level 3 assessed by DCMA DIBCAC, not a C3PAO, every three years |
§ 170.22 | A senior Affirming Official attests to continuing compliance in SPRS after every assessment and annually thereafter |
§ 170.24 | Scoring starts at 110 and subtracts points; it "may result in a negative score". Five points where non-implementation "could lead to significant exploitation of the network, or exfiltration of CUI" |
Note the gap this creates. Level 1 is assessed annually, but every Level 2 and Level 3 assessment runs on a three-year cycle, and in all cases a named human being personally affirms continuing compliance every year in SPRS. That annual affirmation is the practical argument for validating your posture between assessments rather than only ahead of one.
Only an authorized or accredited C3PAO may issue a Level 2 Certificate of CMMC Status, and only DCMA DIBCAC conducts Level 3. A penetration testing provider supplies technical evidence and validation that feeds those assessments.
Scoping under § 170.19 is the dominant cost and risk variable
Section 170.19 sorts everything into five categories with sharply different treatment:
CUI Assets: assessed against all Level 2 requirements.
Security Protection Assets: assessed against the requirements relevant to their capabilities.
Contractor Risk Managed Assets: "If sufficiently documented, do not assess against other CMMC security requirements", with limited checks only where the documentation raises assessor concerns.
Specialized Assets (IoT, IIoT, OT, government furnished equipment, restricted information systems, test equipment): "Review the SSP. Do not assess against other CMMC security requirements."
Out-of-Scope Assets: not assessed.
The categorization is largely self-declared. That is what makes scope the dominant variable in both cost and risk: weak or contradictory scoping documentation is exactly what converts an unassessed asset into an assessed one, and it can widen your assessment mid-engagement.
Where a penetration test genuinely helps at Levels 1 and 2
No mandate exists below Level 3. These four uses stand on their own merits.
1. Scoping validation. Asset categorization under § 170.19 is self-declared, and Contractor Risk Managed Assets are accepted on documentation alone unless something raises concerns. A test demonstrating that CUI cannot be reached from an asset you declared out of scope is the strongest possible support for that declaration. A test that does reach CUI from a supposedly segregated asset tells you your scope is wrong while you can still fix it, rather than during a C3PAO assessment.
2. SPRS score defensibility. Your self-assessed score is a representation to the government, and the annual Affirming Official attestation under § 170.22 is the personal-accountability hook that carries False Claims Act exposure. Independent technical validation that the 5-point controls are genuinely effective, rather than documented as effective, is what makes that attestation defensible.
3. POA&M closure evidence. Inside the 180-day window at § 170.21(b), you need to demonstrate that a deficiency is actually remediated. Evidence that the fix holds under attack is stronger than a closed ticket.
4. Pre-assessment rehearsal. Focus it on the 5-point, POA&M-ineligible controls, because those are the ones you cannot defer.
What an assessor actually wants to see
At Level 2, per SP 800-171A, the assessment procedure for CA.L2-3.12.1 has the assessor examine security assessment and authorization policy, procedures addressing assessment planning and assessments, the security assessment plan, the SSP and other relevant records; interview personnel with security assessment and information security responsibilities; and test the mechanisms supporting assessment, plan development and reporting. In practice that means:
A written, dated, approved assessment cadence in the SSP or a security assessment policy. A firm that has run assessments but never documented the interval can fail 3.12.1[a] on paperwork alone.
Scan configuration, scope, schedules and dated output for RA.L2-3.11.2, covering all in-scope components. The Rev 2 discussion specifically calls out networked printers, scanners and copiers.
Remediation records tied back to findings with risk-based prioritization rationale (RA.L2-3.11.3).
Continuous monitoring outputs showing ongoing rather than point-in-time coverage (CA.L2-3.12.3).
An artifact integrity list under § 170.17(c)(4): "a list of the artifact names, the return value of the hashing algorithm, and the hashing algorithm". Artifacts must be frozen and cataloged before the assessment, not assembled during it.
The SSP itself. CA.L2-3.12.4 is POA&M-ineligible.
At Level 3, the penetration test report becomes a named assessment object. SP 800-172A's procedure for 3.12.1e has DIBCAC examine the security assessment policy, procedures addressing penetration testing, the security plan, the security assessment plan, the penetration test report, the security assessment report and assessment evidence. Its interview list includes the penetration testing team itself, alongside personnel responsible for security assessments and system and network administrators. The practical consequence is blunt: a report from a testing team you cannot produce for interview is weak evidence.
The July 2026 policy suspension does not change any of this
Multiple independent law-firm alerts, including from Latham & Watkins, Morgan Lewis, Crowell & Moring, WilmerHale, Wiley and Jenner & Block, alongside reporting from Federal News Network and DefenseScoop, describe a 13 July 2026 DoD announcement suspending the transition to CMMC Phase 2, which had been due to begin on 10 November 2026, together with the pending Phase 3 and Phase 4 milestones, and standing up a 60-day CMMC Reform Task Force. Those are secondary sources; the underlying memoranda were not publicly retrievable at the time of writing.
What is verifiable from primary sources is what matters to your program. As of the eCFR currency date of 1 August 2026, the four-phase structure and one-year increments at § 170.3(e) are unamended, no Federal Register rule, proposed rule or notice amends or delays the phase-in, and the DoD DARS class deviations index contains no CMMC class deviation.
The suspension is therefore an exercise of policy discretion over what DoD chooses to put in solicitations, not a change to the regulation. 32 CFR part 170 remains in force. So does DFARS 252.204-7021, with its requirement to hold the required CMMC status for the contract duration, the annual SPRS affirmation and subcontractor flow-down; the acquisition rule implementing it states "This rule is effective November 10, 2025." Phase 1 Level 1 and Level 2 self-assessment obligations, SPRS submission, annual affirmation and DFARS 252.204-7012 all continue. What is paused is DoD's advance toward requiring third-party C3PAO certification, not the security requirements themselves.
How Stingrai fits
Stingrai is an offensive security firm: penetration testing, red teaming and adversary emulation. We were founded in 2021, we are headquartered in Toronto with a London office, we are a CREST-accredited penetration testing service provider at firm level, our team has published 18 CVEs, and we hold 5.0 out of 5.0 across 19 Clutch reviews.
For a defense contractor, our testing supports your CMMC readiness program in the four places above: validating that your § 170.19 scope boundary holds under attack, giving your Affirming Official technical grounding for the annual SPRS attestation, proving POA&M remediations hold inside the 180-day window, and rehearsing the 5-point controls you cannot defer. At Level 3 we deliver against CA.L3-3.12.1e as written, with both automated tooling and expert-led ad hoc testing documented in the methodology and a named testing team available for DIBCAC interview.
Scope drives price far more than level does. Engagement models and current rates are on the Stingrai pricing page. For the framework-by-framework picture, see our companion piece on what compliance frameworks really require and our guide to scoping a penetration test.
Frequently Asked Questions
Does CMMC require a penetration test?
Only at Level 3. CMMC Levels 1 and 2 impose no obligation on a contractor to conduct a penetration test. The single penetration testing mandate in the framework is CA.L3-3.12.1e at 32 CFR 170.14(c)(4)(xx), which applies to Level 3 only. The word "penetration" appears exactly once in the whole of 32 CFR part 170, and that is the occurrence.
Does CMMC Level 2 require a penetration test?
No. Section 170.14(c)(3) makes CMMC Level 2 identical to NIST SP 800-171 Revision 2, and the word "penetration" appears zero times in that publication. The controls usually cited as a Level 2 pentest mandate are RA.L2-3.11.2 (vulnerability scanning), CA.L2-3.12.1 (periodic control assessment) and CA.L2-3.12.3 (continuous monitoring), none of which prescribes a testing method. NIST SP 800-171A does list penetration testing as an action a C3PAO assessor may take, but that is an assessor option rather than a contractor duty.
What does CA.L3-3.12.1e actually require?
It requires a contractor to conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts. The annual cadence is a DoD-assigned organization-defined parameter; the underlying NIST SP 800-172 text leaves frequency to the organization. NIST SP 800-172A separates the objectives so that automated scanning tools and expert-led ad hoc tests must each be identified, which means a purely automated scan and a purely manual test both fail.
Does the CMMC Level 3 penetration test have to be done by a third party?
No. There is no third-party independence mandate anywhere in CMMC for the penetration test itself. NIST SP 800-172 states that the penetration testing or red team exercises may be organization-based or external to the organization, provided the team has the necessary skills and resources and is objective in its assessment. OSCP, CREST and CEH appear zero times in 32 CFR part 170, SP 800-171 Rev 2, SP 800-172 and SP 800-172A. Independence requirements in CMMC apply to who performs the assessment, not who performs the test.
Can vulnerability scanning or security assessment go on a CMMC POA&M?
No. RA.L2-3.11.2, CA.L2-3.12.1 and CA.L2-3.12.3 are each worth 5 points under the DoD Assessment Methodology, and 32 CFR 170.21(a)(2)(ii) bars any POA&M item worth more than 1 point, with a single exception for non-FIPS-validated CUI encryption at 3 points. All three must therefore be scored MET on assessment day. Only RA.L2-3.11.3, remediation, is worth 1 point and can be deferred to a POA&M.
Does NIST SP 800-171 require penetration testing?
No. The string "penetrat" appears zero times in the official NIST SP 800-171 Revision 2 PDF, in requirements, discussions and footnotes alike, and Revision 3 adds no penetration testing requirement either. The confusion usually comes from vendor content that quotes the penetration testing discussion from NIST SP 800-172, a separate publication covering enhanced requirements, while captioning it as 800-171.
Which NIST revision does CMMC assess against in 2026?
Revision 2. Section 170.2 statically incorporates NIST SP 800-171 Revision 2 (February 2020) and NIST SP 800-171A (June 2018), even though NIST withdrew both on 14 May 2024. Revision 3 does not govern CMMC as of August 2026, so readiness work built against Rev 3 is aimed at the wrong baseline.
Did the July 2026 CMMC suspension remove the security requirements?
No. Secondary reporting from several law firms describes a 13 July 2026 DoD suspension of the transition to CMMC Phase 2 and the standing up of a reform task force, but 32 CFR part 170 is unamended as of the eCFR currency date of 1 August 2026, and no Federal Register document amends or delays the phase-in. The suspension is policy discretion over what DoD puts in solicitations. DFARS 252.204-7021, DFARS 252.204-7012, Phase 1 Level 1 and Level 2 self-assessment obligations, SPRS submission and the annual affirmation all remain in force.



