Software Secured Company Logo.
Services
Services
WEB, API & MOBILE SECURITY

Manual reviews expose logic flaws, chained exploits, and hidden vulnerabilities

Web Application Pentesting
Mobile Application Pentesting
Secure Code Review
Infrastructure & Cloud Security

Uncovers insecure networks, lateral movement, and segmentation gaps

External Network Pentesting
Internal Network Pentesting
Secure Cloud Review
AI, IoT & HARDWARE SECURITY

Specialized testing validates AI, IoT, and hardware security posture

AI Pentesting
IoT Pentesting
Hardware Pentesting
ADVANCED ADVERSARY SIMULATIONS

We simulate attackers, exposing systemic risks executives must address

Red Teaming
Social Engineering
Threat Modelling
PENETRATION TESTING AS A SERVICE

PTaaS provides continuous manual pentests, aligned with release cycles

Penetration Testing as a Service
OWASP TOP 10 TRAINING

Practical security training strengthens teams, shifting security left effectively

Secure Code Training

Ethical Hacking

Services Overview

Black arrow icon

Enterprise Deal Support

Services Overview

Black arrow icon
Ready to get started?
Identify real vulnerabilities confidently with zero-false-positive penetration testing
Learn More
Industries
Industries
INDUSTRIES
Data and AI

AI pentesting uncovers adversarial threats, ensuring compliance and investor trust

Healthcare

Penetration testing protects PHI, strengthens compliance, and prevents healthcare breaches

Finance

Manual pentests expose FinTech risks, securing APIs, cloud, and compliance

Security

Penetration testing validates SecurTech resilience, compliance, and customer trust

SaaS

Pentesting secures SaaS platforms, proving compliance and accelerating enterprise sales

CASE STUDY

“As custodians of digital assets, you should actually custodize assets, not outsource. Software Secured helped us prove that our custody technology truly delivers on that promise for our clients in both the cryptocurrency and traditional finance”

Nicolas Stalder,
CEO & Co-Founder, Cordial Systems
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Compliance
Compliance
COMPLIANCE
SOC 2 Penetration Testing

Pentesting validates SOC 2 controls, proving real security to auditors and customers

HIPAA Penetration Testing

Manual pentesting proves HIPAA controls protect PHI beyond documentation

ISO 27001 Penetration Testing

Pentests uncover risks audits miss, securing certification and enterprise trust

PCI DSS Penetration Testing

Pentesting validates PCI DSS controls, protecting sensitive cardholder data

GDPR Penetration Testing

GDPR-focused pentests reduce breach risk, regulatory fines, and reputational loss

CASE STUDY

“Software Secured’s comprehensive approach to penetration testing and mobile expertise led to finding more vulnerabilities than our previous vendors.”

Kevin Scully,
VP of Engineering, CompanyCam
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
PricingPortal
Resources
Resources
resources
Blogs
Case Studies
Events & Webinars
Partners
Customer Testimonials
News & Press
Guides and Checklists
About Us
cybersecurity and secure authentication methods.
Black arrow icon
API & Web Application Security Testing

Attack Chains: The Hidden Weakness in Modern API & Web Application Security

Alexis Savard
November 21, 2025
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Login
Book a Consultation
Deal Blocked?
Guides and checklists
/
Guides

CMMC 2.0 Penetration Testing Requirements Guide

Preparing for a CMMC assessment involves more than checking compliance boxes. This guide explains when penetration testing is required, what C3PAOs expect to see, how to scope testing correctly, and how MSPs and defense contractors can build the evidence needed for CMMC Level 2 and Level 3 certification.

Download document

Key Takeaways

  • Learn when penetration testing is required for each CMMC 2.0 certification level.
  • Understand why C3PAOs expect penetration testing for most Level 2 assessments.
  • Identify which systems belong inside your CMMC assessment scope.
  • Avoid common scoping mistakes that increase cost or delay certification.
  • Discover what evidence C3PAOs expect to see in a penetration testing report.
  • Understand how MSPs and External Service Providers (ESPs) fit into CMMC assessments.
  • Build a CMMC-ready penetration testing program that aligns with NIST SP 800-171 and 800-172.
  • Plan your certification timeline to avoid C3PAO scheduling bottlenecks.
  • Compare CMMC and FedRAMP penetration testing requirements to understand where they differ.
Software Secured · Technical Guide

CMMC 2.0 Pentesting

Penetration Testing Requirements
A guide for MSPs and defense contractors preparing for Phase 2 enforcement. Covers penetration testing requirements by level, scoping decisions, C3PAO evidence expectations, and MSP/ESP obligations under 32 CFR Part 170.
Prepared in partnership with Secureframe
Contents
01What Is CUI? A Key Definition
02Enforcement Timeline
03Requirements by Level
04Level 2 Deep Dive
05Level 3 Requirements
06Assessment Scoping
07The CMMC-Ready Pentest Package
08MSP and ESP Obligations
09Readiness Timeline
10CMMC vs. FedRAMP: Framework Comparison
11Resources
01 What Is CUI? A Key Definition Controlled Unclassified Information
The Cybersecurity Maturity Model Certification (CMMC) 2.0 program is the DoD's framework for verifying that defense contractors and their suppliers have implemented cybersecurity requirements protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC is built on NIST standards — Level 2 maps directly to the 110 controls in NIST SP 800-171 Rev 2, and Level 3 adds 24 enhanced controls from NIST SP 800-172.
Controlled Unclassified Information (CUI) is information the U.S. federal government creates or possesses — or that a non-federal entity creates or possesses on the government's behalf — that requires safeguarding or dissemination controls consistent with applicable laws, regulations, and government-wide policies, but that does not meet the standards for classified information.
The definition originates from Executive Order 13556 (2010), which established the CUI program now managed by the National Archives and Records Administration (NARA). In plain terms: CUI sits between publicly available and classified. It is sensitive but unclassified.

Common Examples of CUI

—
Technical drawings, specifications, or design data on defense contracts
—
Export-controlled technical data governed by ITAR or EAR
—
Law enforcement sensitive information
—
Privacy Act information — Social Security numbers, personnel records, medical data
—
Proprietary business information submitted to the federal government
—
Critical infrastructure security information
CUI IS NOTCUI IS
Classified information (Top Secret, Secret, Confidential)
Publicly available or uncontrolled data
Company-internal information by default
Information with no federal government nexus
Sensitive but unclassified — the category between public and classified
Federally defined — controlled by law, regulation, or government-wide policy
The specific trigger for CMMC Level 2 requirements
Defined by approved category in the NARA CUI Registry
Why This Definition Matters for Scoping
CUI is the boundary line for CMMC compliance. If your client's systems store, process, or transmit CUI — even temporarily — those systems fall within the CMMC assessment scope. The first step in any CMMC engagement is identifying what qualifies as CUI, where it flows, and which systems touch it. Getting this wrong means either failing the assessment for missed controls, or over-scoping and paying for compliance coverage that was not needed.
02 Enforcement Timeline CMMC Phased Rollout
CMMC implementation began November 10, 2025 with a four-phase rollout. Phase 2 — the critical deadline for most defense contractors — begins November 10, 2026, when mandatory C3PAO certification becomes required for Level 2 contracts.
PhaseTimelineRequirement
Phase 1Nov 10, 2025 – Nov 9, 2026Level 1 and 2 self-assessments in applicable solicitations. C3PAO assessments at contracting officer discretion for high-priority contracts.
Phase 2Nov 10, 2026 — you are hereMandatory C3PAO Level 2 certification for applicable contracts involving CUI. Self-attestation no longer accepted for most CUI contracts.
Phase 3Nov 10, 2027Level 3 DIBCAC certification requirements introduced for critical programs and high-value assets handling the most sensitive CUI.
Phase 4Nov 10, 2028Full CMMC implementation across all applicable DoD solicitations. CMMC level is a mandatory condition of contract award.
MSP Action Item for November 2026
Your clients handling CUI need a completed C3PAO Level 2 certification before contract renewal or new award. C3PAO booking windows are already stretching 3–6 months — some assessors are reporting 6–8 month waits for new clients. Organizations that start preparation in Q3 2026 will miss contracts. If your clients have not begun, the time is now.
03 Requirements by Level What CMMC Requires for Pentesting
CMMC's pentest requirements differ significantly by level. At Level 2 — where most contractors operate — the requirement is indirect but practically expected by C3PAOs. Here is how it breaks down:
LevelControl CountPentest RequirementAssessment TypeEnforcement
Level 1 Foundational 17 controls (FAR 52.204-21) No pentest required Annual self-assessment + SPRS entry Annual self-attestation only
Level 2 Advanced 110 controls (NIST SP 800-171 Rev 2) Not explicitly mandated — but strongly expected. C3PAOs evaluate CA.L2-3.12.1 (security assessments) and RA.L2-3.11.2 (vulnerability scanning) C3PAO certification every 3 years + annual affirmation Mandatory C3PAO from Nov 10, 2026
Level 3 Expert 110 + 24 controls (NIST SP 800-172) Penetration testing explicitly required under CA.L3-3.12.1e. Must be threat-informed, APT-simulating, annually recurring, with full evidence chain DIBCAC government assessment every 3 years Introduced Nov 10, 2027
04 Level 2 Deep Dive Why Pentest Matters Without an Explicit Mandate
CMMC Level 2 does not use the word 'penetration test' in its control list — but two controls together create a strong practical expectation that your clients will have one:

CA.L2-3.12.1 — Security Assessments

Requires periodic assessment of security controls to determine effectiveness. C3PAOs interpret this as requiring technical validation that controls actually work — not just documented policies. A pentest is the most defensible form of evidence for a significant subset of controls, particularly those governing access control, network boundaries, authentication, and incident detection.

RA.L2-3.11.2 — Vulnerability Scanning

Requires regular vulnerability scans of organizational systems. While scanning is distinct from pentesting, C3PAOs assess these together. Clients who only run scans and have never tested whether findings can be exploited are exposed — assessors ask what was done with scan results, and a pentest cycle that validates remediation is the cleanest answer.
The Real Risk at Level 2
A C3PAO can mark a control as NOT MET if they cannot find sufficient evidence that it functions as intended. Policies alone rarely satisfy a technical assessor. Penetration testing produces the kind of hands-on evidence — proof-of-exploitation, attack path documentation, and remediation verification — that most clearly demonstrates controls hold under real-world conditions.

What C3PAOs Are Looking For in Practice

Based on how the 110 controls map to real assessments, clients going into a C3PAO assessment should expect technical scrutiny around:
—
Access controls — can privilege escalation be achieved? Are separation boundaries enforced?
—
Network segmentation — is CUI genuinely isolated from non-CUI assets?
—
Multi-factor authentication — is it bypassable via common techniques?
—
Audit logging and detection — would an attack be detected and recorded?
—
Incident response — is there evidence the IR plan has been tested?
—
Patch and vulnerability management — has remediation been verified, not just tracked?
05 Level 3 Requirements Penetration Testing Is Explicitly Required
Level 3 applies to contractors handling CUI associated with critical programs or high-value assets. It builds on all 110 Level 2 controls and adds 24 enhanced requirements from NIST SP 800-172, assessed by the Defense Contract Management Agency's DIBCAC — not a commercial C3PAO.

CA.L3-3.12.1e — The Explicit Pentest Control

NIST SP 800-172 places this control within its penetration-resistant architecture strategy. It requires:
—
Annual penetration testing, at minimum
—
Testing must be threat-informed — simulating the specific tactics, techniques, and procedures (TTPs) of Advanced Persistent Threat (APT) actors
—
Generic scanning tools and standard vulnerability assessments do not satisfy this control
—
Testers must have demonstrated APT expertise, including working knowledge of MITRE ATT&CK behaviors relevant to defense contractor environments
—
A complete evidence chain: test report, remediation records, and documentation that testing recurs on schedule
Level 3 Pentest Is Not a Commercial Engagement
Standard commercial penetration testing does not satisfy CA.L3-3.12.1e. If your client handles CUI on a critical program, they need testers with real threat-intel-driven methodology, APT simulation capability, and the ability to produce a report that a DIBCAC assessor can trace back to specific TTPs and attack scenarios.

The Three Pillars of NIST SP 800-172 Your Pentest Must Address

PillarWhat It MeansTesting Focus
Penetration-Resistant Architecture (PRA)Can one compromised component hand an attacker the rest of the environment?Isolation validation, dual-authorization for high-impact actions, boundary controls between security domains
Damage-Limiting Operations (DLO)How quickly can the defender detect and contain a breach?Detection capability, lateral movement constraints, data exfiltration barriers
Designing for Cyber ResiliencyCan the environment recover and maintain mission capability during an attack?Backup integrity, failover controls, resilience mechanisms under active attack simulation
06 Assessment Scoping How to Scope a CMMC Pentest
Scoping is the most consequential decision in a CMMC assessment. Only systems that store, process, or transmit CUI — and systems that protect them — need to be in scope. Getting scope right reduces cost and assessment complexity. Getting it wrong means failed controls or scope creep that derails certification.
The CMMC Level 2 Scoping Guide (DoD) defines five asset categories. Your pentest scope should mirror the CMMC assessment boundary:
Asset CategoryDescriptionPentest Implication
CUI AssetsAny system, endpoint, or application that stores, processes, or transmits Controlled Unclassified InformationAlways in scope — the core of the assessment boundary
Security Protection AssetsSystems that protect the CUI environment: firewalls, IAM, SIEM, EDR, MFA infrastructure, SSO platformsIn scope — controls must be tested and validated
Contractor Risk Managed AssetsAssets that could impact the CUI environment if compromised but do not directly touch CUIIn scope at L2 assessment — risk must be documented and assessed
Cloud Service Provider (CSP) PlatformsAny cloud platform storing or processing CUI (M365, AWS GovCloud, Azure, etc.)Must meet FedRAMP Moderate equivalency; CSP's boundary is part of the CMMC scope
External Service Providers (ESPs / MSPs)MSPs managing IT infrastructure, security tools, or endpoints within the CUI environmentIn scope if they handle CUI or Security Protection Data; must be included in SSP and Shared Responsibility Matrix
Out-of-Scope AssetsSystems fully isolated from CUI with no logical or physical connectionMust demonstrate documented, verifiable segmentation — segmentation itself should be validated in the pentest
Segmentation Is Not Free
Many clients assume that systems outside the CUI enclave are automatically out of scope for the pentest. That is only true if segmentation is verifiably enforced. Testing whether an out-of-scope system can actually reach CUI assets is a legitimate and often expected part of the engagement — especially for C3PAO readiness.
07 The CMMC-Ready Pentest Package What a CMMC Pentest Should Include

Core Testing Components

—
External network pentest — public-facing assets, internet-exposed services, email infrastructure
—
Internal network pentest — lateral movement, privilege escalation, segmentation validation
—
Web application / API pentest — any application that handles FCI/CUI or authenticates into the CUI environment
—
Cloud configuration review — M365 GCC/GCC High, Azure, AWS GovCloud configurations, conditional access policies, sharing permissions
—
Boundary and segmentation validation — confirm CUI enclave isolation holds under active testing
—
Credentialed testing — validates authentication controls and internal privilege boundaries
—
Remediation retest — documented verification that identified findings were resolved

CMMC Controls Your Pentest Report Should Address

ControlWhat the Pentest Demonstrates
CA.L2-3.12.1Evidence that security controls were technically assessed and validated
RA.L2-3.11.2Confirmation that vulnerability findings were identified, remediated, and verified
AC.L2 controlsProof that access control boundaries hold under active exploitation attempts
SC.L2-3.13.1 / SC.L2-3.13.3Network segmentation and boundary protection validated
SI.L2-3.14.6 / SI.L2-3.14.7Security monitoring and malicious code detection tested

What the Report Must Contain for C3PAO Review

—
Clearly scoped authorization boundary matching the client's System Security Plan (SSP)
—
Methodology and tools used — assessors want to know how testing was performed
—
Exploitable attack paths with proof-of-exploitation artifacts
—
Risk-rated findings with business impact assessment
—
Remediation guidance mapped to CMMC/NIST controls
—
Retest confirmation with dated evidence of fixes validated
08 MSP and ESP Obligations What MSPs Need to Know About Their Own CMMC Position
The CMMC final rule (32 CFR Part 170) removed the term 'MSP' and replaced it with the broader category of External Service Provider (ESP). Where your firm lands in the CMMC picture depends entirely on what you handle on behalf of your clients.

The Key Question: Do You Touch CUI?

—
If your MSP stores, processes, or transmits CUI on your own systems — you are an ESP and need your own CMMC Level 2 assessment
—
If your MSP manages IT/security infrastructure inside the client's CUI environment but does not handle CUI on your own systems — you are in scope for the client's assessment
—
If you provide services with no contact with CUI or Security Protection Data (SPD) — you are generally out of scope, but your services must be documented in the client's SSP
Pentesters, IR firms, and assessors who access a client's environment only temporarily are explicitly carved out — they are not considered ESPs and do not need CMMC certification.
Shared Responsibility Matrix (SRM) — Non-Optional
Every MSP relationship that touches the CMMC assessment boundary must be documented in a Shared Responsibility Matrix. The SRM maps which party (client or MSP) is responsible for each of the 320 NIST 800-171A assessment objectives. C3PAOs will ask for it. Very few MSPs have one ready today — preparing it proactively is one of the highest-value things an MSP can do to help clients prepare for assessment.
09 Readiness Timeline Working Backwards from November 10, 2026
As of July 2026, approximately 80,000 contractors need Level 2 C3PAO certification. Fewer than 500 have completed it. There are fewer than 100 authorized C3PAOs, with booking windows stretching 3–8 months. The math is stark.
TimeframeWhat Should Be Done
12+ months outGap assessment against NIST 800-171 Rev 2. Score in SPRS. Define CUI enclave. Begin remediation of high-priority gaps. Identify C3PAO and get on their calendar.
9–12 months outComplete SSP. Build Shared Responsibility Matrix with MSP. Identify and remediate critical control gaps. Commission internal readiness pentest against CMMC scope.
6–9 months outRemediate pentest findings. Conduct retest. Finalize all CMMC documentation (POA&M, CUI flow diagrams, asset inventory). Confirm C3PAO booking.
3–6 months outFinal review of SSP vs. implemented controls. Conduct mock assessment. Provide pentest report and remediation evidence to C3PAO pre-assessment.
0–3 months outC3PAO assessment window. Ensure evidence is organized, current, and traceable. Have pentest retest confirmation documentation available for assessor review.
Post-certificationAnnual affirmation of compliance. Annual vulnerability scanning. Pentest on any significant architecture changes. 3-year reassessment cycle begins.
10 CMMC vs. FedRAMP: Framework Comparison Key Differences for MSPs Supporting Both Programs
MSPs often support clients across both CMMC and FedRAMP Moderate environments. Understanding how the two frameworks handle pentesting helps you scope correctly and avoid under- or over-delivering.
CMMC Level 2NIST 800-53 Moderate (FedRAMP)
Underlying standardNIST SP 800-171 Rev 2 (110 controls)NIST SP 800-53 Rev 5 (325 controls at Moderate)
Pentest explicitly required?No — but strongly expected by C3PAOsYes — CA-8 is a required control
Who conducts the assessment?C3PAO (accredited commercial 3PAO)3PAO accredited by A2LA / FedRAMP PMO
Assessment cadenceEvery 3 years + annual affirmationAnnual assessment + continuous monitoring
Pentest cadenceRecommended annually; triggered by significant changesAt least annually; triggered by significant changes
Tester citizenship requirementNo federal requirement; agency-specific rules may applyNo federal requirement; agency-specific rules may apply
Cloud service requirementFedRAMP Moderate equivalency for CSPs handling CUIFedRAMP authorization (or agency ATO)
Key pentest controlsCA.L2-3.12.1, RA.L2-3.11.2CA-8, RA-5, CA-2, SI-2, SI-4, SC-7
11 Resources CMMC Compliance and Pentesting References
DoD CMMC Program Page
The official DoD source for CMMC requirements, phased implementation timeline, and links to scoping guides and assessment guides for Levels 1–3. Primary source for all CMMC compliance decisions.
dodcio.defense.gov/CMMC
Secureframe: CMMC Hub and FedRAMP 20x Roadmap
GRC automation platform with strong neutral explainers on CMMC Level 2 requirements, C3PAO process, and FedRAMP overlap. Useful for client conversations and tracking readiness progress.
secureframe.com
Software Secured: NIST SP 800-115 and Pentesting
Explains the testing methodology standard (800-115) that underlies compliant pentesting for NIST-based frameworks including CMMC. Covers what independent testing actually means in practice beyond what a scan delivers.
softwaresecured.com
DoD CMMC Scoping Guide Level 2
Official DoD scoping guidance defining the five asset categories and how to determine what belongs inside vs. outside the CMMC assessment boundary. Essential for defining the CUI enclave.
dodcio.defense.gov
DoD CMMC FAQ: MSPs and External Service Providers (Q33–Q37)
Official DoD FAQ covering how the final rule (32 CFR Part 170) classifies MSPs as External Service Providers and when they need their own CMMC assessment.
dodcio.defense.gov/CMMC
NIST SP 800-171 Rev 2: Protecting CUI in Nonfederal Systems
The underlying 110-control standard that CMMC Level 2 maps to directly. Essential reading for understanding what each control requires and how to build evidence that satisfies a C3PAO assessor.
csrc.nist.gov
NIST SP 800-172: Enhanced Security for CUI
The 24 enhanced controls that CMMC Level 3 adds on top of Level 2. Covers CA.L3-3.12.1e (the explicit penetration testing requirement), penetration-resistant architecture, and damage-limiting operations.
csrc.nist.gov
About Software Secured
Software Secured is a Canadian penetration testing company specializing in manual security testing for high-growth SaaS companies and regulated environments. We help technical teams find real vulnerabilities — not just run scans. Our engagements are scoped and reported to satisfy NIST, CMMC, SOC 2, and FedRAMP evidence requirements.
softwaresecured.com

Ready for Your CMMC Assessment?

Book a free consultation to scope a CMMC-ready pentest for your organization or your clients.

Book a Consultation →

Ready to get in touch? Get started by booking a consultation now.

Book Consultation

Get security insights straight to your inbox

Continue your reading with these value-packed posts

The Best of Both Worlds: Combining Pentesting and Bug Bounties for Maximum Security
Black arrow icon
Penetration Testing Services

The Best of Both Worlds: Combining Pentesting and Bug Bounties for Maximum Security

Cate Callegari
Cate Callegari
8 min read
November 21, 2024
Why Common Vulnerability Scoring Systems Suck & Why We Need Them
Black arrow icon
Vulnerability Management & Scoring

Why Common Vulnerability Scoring Systems (CVSS) Suck

Warren Moynihan
Warren Moynihan
12 min read
December 5, 2022
How to Build the Most Effective Organizational Security Strategy
Black arrow icon
DevSecOps & Shift‑left Security

How to Build the Most Effective Organizational Security Strategy

Shimon Brathwaite
Shimon Brathwaite
10 min read
October 12, 2022

Helping companies identify, understand, and solve their security gaps so their teams can sleep better at night

Book a Consultation
Centralize pentest progress in one place
Canadian based, trusted globally
Actionable remediation support, not just vulnerabilities
Clutch logo
Web, API, Mobile Security
Web App PentestingMobile App PentestingSecure Code Review
Infrastructure & Cloud Security
External Network PentestingInternal Network PentestingSecure Cloud Review
AI, IoT & Hardware Security
AI PentestingIoT PentestingHardware Pentesting
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
More Services
Pentesting as a ServiceSecure Code Training
Industries
Data and AIFinanceHealthcareSecuritySaaS
Compliance
GDPR PentestingHIPAA PentestingISO 27001 PentestingPCI DSS PentestingSOC 2 Pentesting
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
Comparisons
Software Secured vs Cobalt
Security & ComplianceSubprocessorsPrivacy PolicyTerms & Conditions
2026 ©SoftwareSecured