main logo icon

Published on

September 19, 2026

|

17 min read

FedRAMP Penetration Testing Requirements in 2026: What Cloud Service Providers Actually Have to Do

FedRAMP rewrote its penetration testing expectations in 2026. What the Consolidated Rules for 2026 changed, which classes carry CA-08 and its enhancements, the attack vectors the guidance names, and the evidence a 3PAO needs.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

FedRAMP launched the Consolidated Rules for 2026 on 24 June 2026. They fold penetration testing into a broader Vulnerability Detection and Response obligation, and the Rev5 control guidance for CA-08 now says exactly that. The Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rulesets must be met to obtain and to maintain any FedRAMP Certification from 7 December 2026, with the grace period ending 7 March 2027. Penetration testing controls are still assessed at least once a year by a FedRAMP Recognized independent assessor. Class B packages include CA-08. Class C and Class D packages include CA-08 (01), Independent Penetration Testing Agent or Team, and CA-08 (02), Red Team Exercises. The FedRAMP Penetration Test Guidance version 3.0 still defines the six mandatory attack vectors, the rules of engagement, the report structure, and the schedule of a test within six months before SAR submission and at least every 12 months thereafter. Only a FedRAMP Recognized assessor can produce the assessment. An assessor may not assess a cloud service offering within two years of supplying advisory or consulting services for it, which is why most providers run their own independent testing separately from the assessment. Published advisory-firm estimates put a Moderate 3PAO assessment, penetration test included, at US$125,000 to US$195,000, and a Low impact SaaS assessment at US$30,000 to US$40,000. FedRAMP itself publishes no price list. FedRAMP stops accepting new Rev5 Certifications on 11 June 2027.

FedRAMP launched the Consolidated Rules for 2026 on 24 June 2026, and the single line that matters most to anyone budgeting a penetration test sits in the Rev5 control guidance for CA-08: "Penetration testing is part of vulnerability detection and is subject to the Vulnerability Detection and Response rules." That sentence replaces a decade of treating the FedRAMP penetration test as a discrete annual event with its own rulebook. The test itself has not gone away, the assessor requirements have if anything tightened, and the deadline is close: the vulnerability rulesets must be met to obtain and to maintain any FedRAMP Certification from 7 December 2026.

Quick answer: A FedRAMP penetration test is an authorized attack simulation of a cloud service offering, performed by a FedRAMP Recognized independent assessor (a 3PAO), whose report is included in the Security Assessment Report that a federal agency or FedRAMP reviews before authorizing the service. Penetration testing controls are assessed at least once a year: Class B (Low) packages carry CA-08, and Class C (Moderate) and Class D (High) packages carry CA-08 (01) Independent Penetration Testing Agent or Team and CA-08 (02) Red Team Exercises. The FedRAMP Penetration Test Guidance version 3.0 still sets the six mandatory attack vectors, the rules of engagement, and the report structure, and it requires the initial test no more than six months before the SAR is submitted, with further testing at least every 12 months. Where Stingrai fits: Stingrai is a CREST-accredited penetration testing company founded in 2021, headquartered in Toronto with a London office. Its penetration testers run human-led engagements, as one-time annual tests or as continuous programs, that produce the technical findings and evidence a cloud service provider brings to its 3PAO and its agency sponsor. Published pricing starts at US$3,000 for an autonomous test of one web application and its APIs, with human-led and enterprise scopes quoted (pricing).

What actually changed in 2026

Two things moved at once, and most published guides still describe only the older of them.

The Consolidated Rules for 2026 (CR26) went live on 24 June 2026. They collapse the old sprawl of FedRAMP PDFs into a single machine-readable ruleset covering both the legacy Rev5 path and the new 20x certification classes. Every rule carries an identifier, an applicability statement, and dates. For penetration testing, the governing ruleset is now Vulnerability Detection and Response (VDR). Rule VDR-CSO-DET reads, in full:

Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection.

FedRAMP is explicit about why: "Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed." The rule's companion note also discourages running a separate compliance-only detection process, because FedRAMP wants the testing to be the testing your engineering organisation already relies on.

FedRAMP 20x entered Phase 3. The Low pilot closed in September 2025 with 26 packages submitted and the Moderate pilot ran from November 2025 to March 2026. Phase 3 formalizes Class A, Class B and Class C certifications and opens the submission pipeline, with a Class D (High) pilot in FY27. Phase 5 carries the hard date every CSP should have in a roadmap: FedRAMP will stop accepting new Rev5 Certifications on 11 June 2027.

The practical reading for a security leader is that the requirement did not get lighter. It got less prescriptive and more continuous, and the burden of proving that your detection is actually effective moved onto you.

FedRAMP Consolidated Rules for 2026 deadlines for Rev5 cloud service providers

Which baselines require a penetration test, and how often

FedRAMP's certification classes map onto the familiar impact levels: Class B is Low, Class C is Moderate, Class D is High. Class A is a lighter-weight entry certification for providers with mature security programs.

The controlling rule is IVV-CSF-AIA, Annual Independent Assessments for Rev5, inside the Independent Verification and Validation ruleset. It lists the Rev5 controls that MUST be included in a FedRAMP independent assessment at least once per year, per class. The penetration testing entries are:

Certification class

Impact level

Penetration testing controls in the annual assessment

Class A

Entry certification

Annual independent assessment is optional (MAY, not MUST)

Class B

Low

CA-08, Penetration Testing

Class C

Moderate

CA-08 (01), Independent Penetration Testing Agent or Team; CA-08 (02), Red Team Exercises

Class D

High

CA-08 (01), Independent Penetration Testing Agent or Team; CA-08 (02), Red Team Exercises

Two things in that table catch procurement teams off guard.

First, CA-08 (02) Red Team Exercises sits in the annual assessment list for Moderate and High. A standard application penetration test does not discharge it. Red team work is objective-driven, tests detection and response as much as exposure, and is scoped and staffed differently. If your last three assessments treated the red team enhancement as a policy statement rather than an exercise, that is the gap most likely to surface in a review.

Second, CA-08's own frequency is now organization-defined. The NIST SP 800-53 Revision 5 control text is "Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined system(s) or system components]," and FedRAMP's Rev5 control guidance no longer pins a value into that assignment, routing you to the VDR rules instead. That is not permission to test less often. You now have to define a frequency, justify it against your own risk and change velocity, and show you honour it, while the independent assessment still happens annually.

For anyone still operating under the legacy guidance, the schedule in Penetration Test Guidance v3.0 section 7.0 remains the clearest statement of cadence:

For each initial security authorization, a penetration test must be completed by a 3PAO as a part of the assessment process described in the SAP. This initial penetration test must be performed no more than 6 months prior to the submission of the SAR. Once within the continuous monitoring phase of the FedRAMP process, additional penetration testing activities must be performed at least every 12 months, unless otherwise approved by an authorizing body with documented rationale.

On top of that annual rhythm sits change. Under Significant Change Notification (SCN), providers must evaluate every potential significant change and categorize it as routine recurring, adaptive, or transformative. Rule SCN-CSO-INF requires the notification to include a "Plan and timeline for the change, including for the verification, assessment, and/or validation of impacted Key Security Indicators or Rev5 Controls." A transformative change to an authorization boundary is where an out-of-cycle penetration test usually becomes unavoidable. VDR-CSO-DAC reinforces the same instinct: providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.

The attack vectors the guidance requires

FedRAMP's mandatory attack vectors are the most frequently cited part of the program and the part most often summarized wrongly. Version 3.0 of the guidance defines six, and they apply "regardless of classification (SaaS, IaaS, PaaS, or hybrid)":

  1. External to Corporate. A social engineering campaign, in practice a phishing exercise, against users with access to CSP management systems. The guidance is specific: originating IP addresses and email domains are allow-listed on perimeter security so the email arrives "unflagged, unmodified, and unaltered," and credential harvesting is not the goal.

  2. External to CSP Target System. Testing from the position of an external threat actor with no credentials against the internet-facing surface of the service.

  3. Tenant to CSP Management System. A full application test attempting to escape a tenant and reach the provider's own management plane, including consoles, APIs and command line interfaces.

  4. Tenant to Tenant. A full application test attempting to use provisioned tenant access to reach another tenant's data or environment.

  5. Mobile Application to Target System. Applies where the offering includes a mobile client. Can be scoped out with justification if there is no mobile application.

  6. Client-side Application or Agents to Target System. Applies where the provider ships components that run inside the customer environment.

Deviations are not a quiet matter. If an attack vector cannot be tested, "the deviation must be included" and the assessor documents "non-conformance to testing a particular attack vector as a High Risk finding in the SAR Risk Exposure Table." Refusing the social engineering vector has its own consequence: the assessor is required to document, in section 6.0 of the report, the rationale behind a CSP not agreeing to a social engineering test.

There is real leverage in the inheritance rule. Where a service sits on top of an already-authorized lower layer, "attack vectors already addressed by other FedRAMP Authorized services lower in the cloud stack are not required to be re-evaluated." If your offering runs entirely on an authorized IaaS, the infrastructure layer does not need retesting, provided your authorization boundary is drawn honestly. Drawing that boundary well is the highest-leverage cost decision in the whole program, and it is the same discipline we walk through in our guide to what a cloud provider's compliance report does and does not prove.

Under CR26, the six-vector list is best read as a strong default rather than an immutable statute. VDR-CSO-DET is technique-agnostic and scope is driven by the authorization boundary. In practice, assessors and agency reviewers still expect to see those vectors addressed or explicitly and defensibly ruled out, because nothing has replaced them as a shared reference for coverage.

Who may perform the test

This is where most buying mistakes happen, so it is worth being precise about three different roles.

The 3PAO, formally a FedRAMP Recognized independent assessment service. Only this organization can produce the independent assessment that goes into your package. Recognition is not a FedRAMP paperwork exercise. Under rule REC-IAS-ACC, assessors "MUST obtain and maintain accreditation through the American Association for Laboratory Accreditation (A2LA) Cybersecurity Inspection Body Program," must comply with A2LA's R311 specific requirements, must pass an annual A2LA surveillance assessment and a full reassessment at least every two years, and must complete at least two initial or ongoing assessments for Class B, C or D certifications every two years to keep recognition. They must also report foreign interest, influence or control to FedRAMP annually, and any change within 48 hours. A-LIGN, Coalfire Federal, Schellman and Kratos are examples of assessors that have long operated in this space. Treat them as assessors, not as your offensive testing bench.

The independent penetration testing provider you hire yourself. Nothing stops a CSP from running its own penetration testing program outside the assessment, and most serious CSPs do. The reason is mechanical, not commercial. Rule REC-IAS-SEP, Advisory Separation, states that assessors "MUST NOT perform a FedRAMP independent assessment of the same cloud service offering within 2 years after supplying advisory or consulting services for that offering." Your assessor cannot help you fix what they are about to judge. So the work of finding and closing findings before the assessment, and of testing between assessments, has to come from somewhere else.

Your own engineering and security team. Scanning, automated control testing and drift detection are yours to own under VDR. Assessors validate; they do not run your program.

The pattern procurement should budget for is a two-track year: independent penetration testing driving remediation continuously, and the 3PAO assessment landing on a clean system once a year. Providers who compress both into a single annual 3PAO engagement discover their findings six weeks before a SAR is due.

The 3PAO assessment versus the penetration test itself

3PAO assessment

The penetration test

What it is

An independent verification and validation of the controls and rules applicable to your certification class

An authorized attack simulation against the authorization boundary

Who performs it

A FedRAMP Recognized assessment service, accredited by A2LA under the Cybersecurity Inspection Body Program

A 3PAO for the assessment deliverable; commonly an independent penetration testing provider for the testing that happens between assessments

Scope

The control list for the class, plus applicable FedRAMP rulesets, evidence of implementation and of effectiveness

The attack vectors in the test plan and rules of engagement, bounded by the authorization boundary

Cadence

At least once per year for Class B, C and D; optional for Class A

Initial test within six months before SAR submission, then at least every 12 months, plus after significant change

Primary output

Security Assessment Report, with findings feeding the POA&M

Penetration test report, included in the SAR, with findings, evidence, access paths and risk ratings

Independence constraint

Cannot assess an offering within two years of advising on it

A provider-hired test carries no such restriction, which is exactly why it is useful for remediation

What it proves

That the controls exist and are effective, as judged independently

That an attacker following realistic paths did or did not achieve impact

What the evidence package has to contain

The penetration test report is not a free-form PDF. Section 6.0 of the guidance requires the report to address six areas, and a package reviewer will look for each of them by name:

  • 6.1 Scope of target system. What was assessed, and any deviation from the rules of engagement or test plan.

  • 6.2 Attack vectors assessed. Which vectors were tested and which threat models were followed.

  • 6.3 Timeline for assessment activity. When testing was performed.

  • 6.4 Actual tests performed and results. The tests themselves, mapped to the requirements, with results.

  • 6.5 Findings and evidence. For each finding: a description, the impact on the target system, a recommendation, a risk rating, and evidence.

  • 6.6 Access paths. Where multiple vulnerabilities could be chained "to form a sophisticated attack," the assessor must describe the chain and its impact.

Two operational constraints get missed. There is no FedRAMP template for the penetration test report, so the structure above is the contract. And sanitization is mandatory: sensitive data in screenshots, tables and figures must be rendered "permanently unrecoverable," and passwords must never appear in the final report, encrypted or otherwise.

The report is delivered into the Security Assessment Report. Findings that are not remediated before submission flow to the Plan of Action and Milestones, with owners and dates. Under the Vulnerability Evaluation and Reporting ruleset, that reporting becomes continuous rather than quarterly paperwork: rule VER-TFR-MHR requires providers to report vulnerability detection and response activity "in a consistent format that is human readable at least monthly," rule VER-RPT-PER requires each report to summarize all activity since the previous one, and rules VER-EVA-ELX and VER-EVA-EIR require providers to evaluate whether each detected vulnerability is likely exploitable and whether it is internet-reachable, in the context of the specific offering.

That last pair is the quiet upgrade. A CVSS score copied from a scanner no longer settles the question: someone has to say, on the record, whether the issue is reachable and exploitable in this system, and a well-written penetration test finding is the cleanest way to answer it. The same principle governs evidence across other frameworks, covered in pentest evidence auditors accept and, for the defence supply chain, in the CMMC Level 2 self-assessment evidence guide.

Timelines and 2026 cost ranges

Work backwards from the SAR. The initial penetration test must land no more than six months before the SAR is submitted, which anchors the sequence:

  1. Boundary and scoping, 4 to 8 weeks. The authorization boundary decides everything downstream, including price. This is also when leverage from authorized lower-layer services is claimed or lost.

  2. Independent penetration testing and remediation, 8 to 16 weeks. Test, fix, retest. Running this before the assessor arrives is the whole point.

  3. Rules of engagement and test plan, 2 to 4 weeks. Signed before testing begins. The plan must address every attack vector or justify each exclusion.

  4. 3PAO assessment fieldwork including the penetration test, 4 to 8 weeks.

  5. SAR, POA&M and package assembly, 4 to 8 weeks.

  6. Agency or FedRAMP review, highly variable.

On cost, be careful with any number you read, including these. FedRAMP does not publish an assessment price list. The most widely cited figures come from advisory firms in the space. stackArmor, in a post updated 24 May 2025, puts a Moderate 3PAO assessment including the penetration test and SAR at US$125,000 to US$175,000, with a published correction from Martin Rieger raising the upper bound to US$195,000 depending on the assessor. The same source puts a Low impact SaaS assessment at US$30,000 to US$40,000, advisory and documentation support for Moderate at US$75,000 to US$175,000, and annual continuous monitoring support at US$75,000 to US$125,000.

Published cost ranges for a FedRAMP effort in US dollars

A standalone application penetration test bought outside the assessment is a different market entirely, typically a five-figure engagement priced on application count and complexity rather than on the whole authorization boundary. Our penetration testing price index tracks those ranges, and Stingrai's own published pricing starts at US$3,000 for an autonomous test of one web application and its APIs, with human-led engagements quoted on scope.

The budgeting mistake worth naming: treating the 3PAO fee as the cost of security testing. It is the cost of having security testing independently judged. If the first time anyone attacks your service in a given year is during the assessment, every finding becomes a POA&M item, and POA&M items become the thing agency reviewers ask about.

A vendor due-diligence checklist for procurement

Use this when evaluating an independent penetration testing provider for the work that sits alongside your FedRAMP program. Every item is a written answer, not a sales assurance.

  1. Named testers, named credentials. Ask for the specific people who will test, their certifications, and their published research. A firm that will not name its testers is selling you a scan.

  2. Clearance and citizenship, stated honestly. If your contract or agency sponsor requires US persons, cleared personnel, or on-shore delivery, require the vendor to state in writing exactly what they hold and where testers sit. Many strong commercial testing firms hold no US security clearances at all, which is fine for most FedRAMP application testing and fatal for a classified or ITAR-adjacent requirement. The failure mode is a vendor who lets the question slide.

  3. Methodology, in writing. The FedRAMP guidance requires an assessor to maintain "a defined penetration test methodology." Hold your independent provider to the same bar, and ask how they cover tenant-to-tenant and tenant-to-management-plane paths specifically.

  4. Report format that maps to section 6.0. Ask to see a sanitized sample report with scope, vectors, timeline, tests performed, findings with evidence and risk ratings, and access paths. If the sample has no access-path narrative, the vendor is reporting vulnerabilities rather than attacks.

  5. Retest included, and how it is delivered. Confirm whether retesting of remediated findings is in the fee, how long the window runs, and whether you get an updated report.

  6. Attestation letter. Ask for a signed letter you can share with an agency, a prospect or your 3PAO that states scope, dates, methodology and outcome without exposing finding detail.

  7. Evidence handling. Ask how sensitive data in screenshots is masked, how the report is transmitted, and how long they retain engagement artifacts.

  8. Independence. Confirm the provider is not also your 3PAO and not positioned to become it. Advisory Separation runs two years.

  9. Cadence flexibility. Confirm they can support both an annual engagement and continuous testing across the year, because VDR expects persistent detection and your assessment expects an annual point of judgment.

  10. Change-triggered testing. Ask what a significant-change retest costs and how quickly they can mobilize, then put that in the contract before you need it.

Where Stingrai fits

Stingrai is a CREST-accredited penetration testing service provider, founded in 2021, headquartered in Toronto with an office in London. Its core work is human-led penetration testing for regulated industries, delivered either as an annual one-time engagement or as a continuous testing program, depending on what the compliance calendar and the change velocity of the product demand.

For a cloud service provider on a FedRAMP path, the role is specific: Stingrai's penetration testers produce the technical findings, evidence and reporting that support your security program and that you bring to your 3PAO and your agency sponsor. The engagement model is a joint one. Senior penetration testers and Snipe, Stingrai's autonomous agent for web application testing, work the same engagement at the same time, with the testers directing where the agent focuses and pursuing what it surfaces. Snipe covers web applications and their APIs, including white-box source review and AutoFix pull requests; network, cloud and social engineering scopes are human-led.

Team credentials include OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX, with 18 published CVEs and research presented at DEF CON and BSides. Reporting is built to be handed to an assessor: scope, methodology, findings with evidence and risk ratings, chained access paths, and retest results. Service detail sits on the services page, and providers comparing testing partners on the US federal path often start with our ranking of the best penetration testing companies in the USA.

Frequently Asked Questions

Does FedRAMP require a penetration test?

Yes. Penetration testing controls are in the annual independent assessment for every FedRAMP certification class above the entry level. Class B (Low) packages include CA-08. Class C (Moderate) and Class D (High) packages include CA-08 (01), Independent Penetration Testing Agent or Team, and CA-08 (02), Red Team Exercises, under rule IVV-CSF-AIA. Under the Consolidated Rules for 2026, penetration testing is also named explicitly in VDR-CSO-DET as one of the techniques providers must use to detect vulnerabilities continuously.

How often does FedRAMP require penetration testing?

The independent assessment that includes the penetration testing controls happens at least once per year. The FedRAMP Penetration Test Guidance version 3.0 requires the initial test no more than six months before the Security Assessment Report is submitted, and further testing at least every 12 months during continuous monitoring, unless an authorizing body approves otherwise with documented rationale. Significant changes trigger additional testing outside that cycle. Under CR26 the CA-08 frequency parameter is organization-defined, so providers must define, justify and honour their own cadence.

Who can perform a FedRAMP penetration test?

The assessment deliverable must come from a FedRAMP Recognized independent assessment service, commonly called a 3PAO. Recognition requires accreditation through the A2LA Cybersecurity Inspection Body Program, compliance with A2LA R311, a favourable annual A2LA surveillance assessment, a full reassessment at least every two years, and at least two Class B, C or D assessments completed every two years. Cloud service providers usually also retain a separate independent penetration testing provider for testing between assessments, because rule REC-IAS-SEP bars an assessor from assessing an offering within two years of advising on it.

What are the FedRAMP penetration testing attack vectors?

Version 3.0 of the guidance defines six mandatory attack vectors: external to corporate (a social engineering campaign against users with access to management systems), external to the CSP target system, tenant to CSP management system, tenant to tenant, mobile application to target system, and client-side application or agents to target system. Vectors that cannot be tested must be documented as deviations, and an assessor records non-conformance as a High Risk finding in the SAR Risk Exposure Table.

How much does a FedRAMP penetration test cost in 2026?

FedRAMP publishes no price list, so every figure is a market estimate. stackArmor, in a post updated 24 May 2025, puts a Moderate 3PAO assessment including the penetration test and SAR at US$125,000 to US$195,000 and a Low impact SaaS assessment at US$30,000 to US$40,000, with annual continuous monitoring support at US$75,000 to US$125,000. A standalone application penetration test bought outside the assessment is a much smaller engagement priced on application count and complexity.

What did FedRAMP 20x change for penetration testing?

It moved penetration testing from a standalone annual requirement with its own prescriptive guidance into the Vulnerability Detection and Response ruleset, where it is one of several named techniques inside a continuous obligation to find vulnerabilities. FedRAMP's Rev5 control guidance for CA-08 now states that penetration testing is part of vulnerability detection and subject to those rules. The VDR and Vulnerability Evaluation and Reporting rulesets must be met to obtain and to maintain any FedRAMP Certification from 7 December 2026, with grace ending 7 March 2027.

When does FedRAMP stop accepting Rev5 packages?

FedRAMP will stop accepting new Rev5 Certifications on 11 June 2027, during Phase 5 of FedRAMP 20x, and has committed to publishing a transition path and timeline for existing Rev5 offerings by the end of that phase. Class D (High) certifications are scheduled to be developed during Phase 4 in FY27.

Can a 3PAO also be our penetration testing vendor for the rest of the year?

Not if they are assessing you. Rule REC-IAS-SEP states that assessors must not perform a FedRAMP independent assessment of a cloud service offering within two years of supplying advisory or consulting services for that offering. Remediation-focused testing sits close enough to advisory work that most providers keep the two firms separate by design, which also gives the assessment a genuinely independent look at the system.

0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X