Software Secured Company Logo.
Services
Services
WEB, API & MOBILE SECURITY

Manual reviews expose logic flaws, chained exploits, and hidden vulnerabilities

Web Application Pentesting
Mobile Application Pentesting
Secure Code Review
Infrastructure & Cloud Security

Uncovers insecure networks, lateral movement, and segmentation gaps

External Network Pentesting
Internal Network Pentesting
Secure Cloud Review
AI, IoT & HARDWARE SECURITY

Specialized testing validates AI, IoT, and hardware security posture

AI Pentesting
IoT Pentesting
Hardware Pentesting
ADVANCED ADVERSARY SIMULATIONS

We simulate attackers, exposing systemic risks executives must address

Red Teaming
Social Engineering
Threat Modelling
PENETRATION TESTING AS A SERVICE

PTaaS provides continuous manual pentests, aligned with release cycles

Penetration Testing as a Service
OWASP TOP 10 TRAINING

Practical security training strengthens teams, shifting security left effectively

Secure Code Training

Ethical Hacking

Services Overview

Black arrow icon

Enterprise Deal Support

Services Overview

Black arrow icon
Ready to get started?
Identify real vulnerabilities confidently with zero-false-positive penetration testing
Learn More
Industries
Industries
INDUSTRIES
Data and AI

AI pentesting uncovers adversarial threats, ensuring compliance and investor trust

Healthcare

Penetration testing protects PHI, strengthens compliance, and prevents healthcare breaches

Finance

Manual pentests expose FinTech risks, securing APIs, cloud, and compliance

Security

Penetration testing validates SecurTech resilience, compliance, and customer trust

SaaS

Pentesting secures SaaS platforms, proving compliance and accelerating enterprise sales

CASE STUDY

“As custodians of digital assets, you should actually custodize assets, not outsource. Software Secured helped us prove that our custody technology truly delivers on that promise for our clients in both the cryptocurrency and traditional finance”

Nicolas Stalder,
CEO & Co-Founder, Cordial Systems
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Compliance
Compliance
COMPLIANCE
SOC 2 Penetration Testing

Pentesting validates SOC 2 controls, proving real security to auditors and customers

HIPAA Penetration Testing

Manual pentesting proves HIPAA controls protect PHI beyond documentation

ISO 27001 Penetration Testing

Pentests uncover risks audits miss, securing certification and enterprise trust

PCI DSS Penetration Testing

Pentesting validates PCI DSS controls, protecting sensitive cardholder data

GDPR Penetration Testing

GDPR-focused pentests reduce breach risk, regulatory fines, and reputational loss

CASE STUDY

“Software Secured’s comprehensive approach to penetration testing and mobile expertise led to finding more vulnerabilities than our previous vendors.”

Kevin Scully,
VP of Engineering, CompanyCam
Black arrow icon
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
PricingPortal
Resources
Resources
resources
Blogs
Case Studies
Research and Events
Partners
Customer Testimonials
News & Press
Guides and Checklists
About Us
cybersecurity and secure authentication methods.
Black arrow icon
API & Web Application Security Testing

Attack Chains: The Hidden Weakness in Modern API & Web Application Security

Alexis Savard
November 21, 2025
Ready to get started?
Our comprehensive penetration testing and actionable reports have 0 false positives so you can identify
Learn More
Login
Book a Consultation
Deal Blocked?
Guides and checklists
/
Guides

NIST 800-53 Moderate Pentesting Requirements Guide

This guide explains the penetration testing expectations behind NIST 800-53 Moderate, including required controls, typical testing scope, assessor expectations, red team requirements, and the impact of FedRAMP 20x. Whether you're a SaaS provider, MSP, federal contractor, or cloud service provider, this resource helps clarify what security validation activities are expected and how to prepare for assessments.

Download document

Key Takeaways

  • Understand which NIST 800-53 controls drive penetration testing requirements, including CA-8 and RA-5.
  • Learn what systems and environments should typically be included in scope.
  • Understand the difference between vulnerability scanning and penetration testing.
  • Learn when annual pentests, remediation retesting, and red team exercises are expected.
  • See what FedRAMP Moderate assessors commonly look for during reviews.
  • Understand how cloud infrastructure, web applications, APIs, and internal networks fit into compliance testing.
  • Learn what FedRAMP 20x changes and what remains the same.
  • Clarify common misconceptions around pentester independence and U.S.-based testing requirements

A practical guide for IT leaders, MSPs, and SaaS teams navigating FedRAMP Moderate, U.S. federal systems, and regulated environments.

UPDATED AUGUST 2026

This guide reflects the FedRAMP Consolidated Rules for 2026 (CR26) and the FedRAMP 20x certification pipeline.

01Quick Summary
02What Is FedRAMP Moderate?
03Required Controls
04What Should Be In Scope?
05What Auditors Expect in Practice
06FedRAMP 20x: What's Changing?
07Do Pentesters Need to Be U.S.-Based?
08Resources for MSPs: CMMC & FedRAMP Compliance
01

Quick Summary

What IT Leaders Need to Know

If your organization is pursuing FedRAMP Moderate authorization or supporting federal customers, penetration testing is not optional. Here is the simplified version:

AT A GLANCE

Annual independent penetration testing is expected.
Vulnerability scanning alone is not enough.
Both internal and external attack surfaces must be tested.
Web applications, APIs, cloud infrastructure, and boundary protections are typically in scope.
Retesting after remediation is expected before assessments are considered complete.
Under FedRAMP Rev 5, annual red team exercises are now also required for Moderate environments.
Under the FedRAMP 20x Consolidated Rules for 2026 (CR26), pentesting is now framed as one input into a continuous vulnerability detection obligation — not a standalone annual box to check.

What Is FedRAMP Moderate?

Background & Context

FedRAMP Moderate is a U.S. federal security baseline used for cloud service providers (CSPs) handling sensitive but unclassified government information. The framework is built on NIST SP 800-53 security controls and is commonly required for:

SaaS providers selling to government agencies.
MSPs supporting federal contractors.
Organizations handling Controlled Unclassified Information (CUI).
Cloud platforms pursuing federal authorization.

As of August 2026, FedRAMP Moderate is represented by two parallel paths: the legacy Rev5 baseline (325 controls) and the new FedRAMP 20x Class C certification, which replaces the Moderate impact level under the Consolidated Rules for 2026. This guide focuses specifically on the penetration testing and security validation expectations behind FedRAMP Moderate.

TermPlain English Meaning
Authorization BoundaryThe systems, applications, cloud infrastructure, and services included in your FedRAMP assessment.
CUIControlled Unclassified Information — sensitive government-related information requiring protection.
CSPCloud Service Provider.
3PAOThird-Party Assessment Organization authorized to perform FedRAMP assessments.
CA-8The NIST control covering penetration testing.
RA-5The NIST control covering vulnerability scanning.
Red Team ExerciseA simulated adversary exercise focused on testing detection and response capabilities — distinct from a pentest.
Class CThe FedRAMP 20x certification class that replaces the Moderate impact level under CR26.
03

Required Controls

What Pentesting Is Required for NIST 800-53 Moderate?

NIST 800-53 Moderate does not mandate a specific annual pentest on a fixed schedule. What it requires is penetration testing and vulnerability assessments as part of a continuous monitoring program. Three controls directly drive this. A fourth set indirectly requires testing as part of broader system assurance obligations.

CA-8: Penetration Testing (Core Requirement)

CA-8 is the primary pentesting control. A compliant pentest under CA-8 must:

Be conducted at least annually.
Cover both internal and external attack surfaces.
Be performed by independent testers — not your internal team.
Validate exploitability, not just identify vulnerabilities.
Produce a formal report including proof of exploitation, attack paths, business impact per finding, risk ratings, remediation guidance, and retest confirmation.

RA-5: Vulnerability Monitoring & Scanning (Also Required)

RA-5 governs ongoing vulnerability scanning — a distinct activity from pentesting, but the baseline it establishes matters.

Regular vulnerability scans (typically monthly or quarterly).
Coverage of all internal and external components.
Severity-based remediation timelines.
Validation rescans after fixes are applied.

Scanning is not Pentesting

Vulnerability scanning identifies potential weaknesses automatically. Penetration testing actively validates whether vulnerabilities can be exploited in real-world attack scenarios. Scans alone do not satisfy the CA-8 requirement — and FedRAMP assessors know the difference.

CA-2: Security Assessments (Pentest Evidence Supports This)

CA-2 requires broader technical evaluation and control validation activities. A pentest report directly contributes evidence for CA-2 compliance, including controls testing, technical evaluation of implemented safeguards, and continuous monitoring evidence.

SI-2, SI-4, SC-7: Controls That Indirectly Trigger Testing

ControlWhy It Matters
SI-4Validates monitoring and detection effectiveness — pentest results confirm detection capability.
SI-2Significant infrastructure changes often require a new pentest.
SC-7Segmentation and boundary protections must be validated through testing.
04

Pentest Scope

What Should Be In Scope?

The authorization boundary determines pentest scope. In practice, any system that stores, processes, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) should generally be included.

ComponentTypical Testing Focus
External PerimeterPublic-facing assets, IP ranges, DNS infrastructure.
Internal NetworkSegmentation, lateral movement paths.
Web Applications & APIsAuthentication, authorization, business logic, and any app handling FCI/CUI.
Cloud InfrastructureAWS, Azure, GCP — configuration review and exploitation testing.
Boundary ProtectionsWAF, VPN, SSO, IAM — tested for bypass and misconfiguration.
Configuration ReviewsKey systems assessed for hardening gaps.

What FedRAMP Moderate Does Not Explicitly Require

The following are not directly mandated by the standard, though assessors may expect them depending on system complexity or agency requirements:

Mobile application pentesting.
Source code or white-box reviews.
Social engineering campaigns.
OWASP Top 10-specific reporting formats.

Important Update: Red Team Exercises (CA-8(2)) Now Required for Moderate

Under NIST 800-53 Rev 5 and the FedRAMP Rev 5 baseline (finalized May 2023), CA-8(2) red team exercises have been added to both the Moderate and High baselines. In addition to the standard annual penetration test, Moderate CSPs must now conduct annual red team exercises that simulate real adversary attempts to compromise organizational systems.

Red team exercises differ from pentests in focus: rather than finding and exploiting as many vulnerabilities as possible, red teams assess detection, defense, and response capabilities.

Pentesting vs. Red Teaming

PentestingRed Teaming
Focuses on finding and exploiting vulnerabilitiesFocuses on testing detection and response capabilities
Usually time-boxed and scoped to specific systemsSimulates realistic adversary behavior across the environment
Prioritizes exploit validation and remediation evidencePrioritizes operational resilience and defensive maturity
05

Assessor Expectations

What Auditors Commonly Expect in Practice

Although FedRAMP guidance allows flexibility, most 3PAOs and assessors conducting FedRAMP Moderate reviews expect a practical annual testing package covering the following:

Typically Expected

External network penetration test.
Internal network penetration test.
Web application / API pentest.
Cloud environment review (AWS / Azure / GCP).
Credentialed testing where applicable.
Remediation retest before report is finalized.
Annual red team exercise (CA-8(2) — Rev 5).

Commonly Recommended

Regular vulnerability scanning program (RA-5).
Segmentation validation testing.
Detection and response validation exercises.
Cloud infrastructure configuration review.
Machine-readable evidence mapped to Key Security Indicators (KSIs), if pursuing 20x Class C.
06

FedRAMP 20x

What's Changing for Moderate Authorization

UPDATED AUGUST 2026

On June 25, 2026, FedRAMP finalized the Consolidated Rules for 2026 (CR26) — a single ruleset that formally establishes FedRAMP 20x as the path forward for Low and Moderate authorizations, replacing the FIPS 199 impact levels with four Certification Classes.

The New Certification Classes

CR26 replaces "FedRAMP Low / Moderate / High" with four Certification Classes:

ClassWhat It Means
Class A (Pilot)Entry-level Marketplace listing via SOC 2 Type II; no agency sponsor required. On-ramp only — CSPs have 2 years to reach Class B or higher.
Class B (Low)Replaces the FedRAMP Low impact level.
Class C (Moderate)Replaces the FedRAMP Moderate impact level — the class most commercial SaaS providers land in.
Class D (High)Remains on the Rev5 path for now; a 20x Class D pilot is targeted for FY27.

2026 Pipeline Dates

DateMilestone
Aug 3, 2026FedRAMP 20x Class A pipeline opens.
Aug 10, 2026Temporary Rev5 conversion pipelines open for eligible Class B/C providers without an agency sponsor.
Aug 31, 2026FedRAMP 20x Class B and Class C pipelines open — the major milestone for commercial SaaS.
Jan 1, 2027CR26 becomes mandatory for all stakeholders; existing Rev5 certifications must adopt the new rules.
Jun 11, 2027FedRAMP stops accepting new Rev5 certification applications.

What FedRAMP 20x / CR26 Changes

Replaces static, documentation-heavy assessments with continuous, machine-verifiable validation.
Introduces Key Security Indicators (KSIs) in place of narrative control-by-control documentation — 56 KSIs for Class B (Low) and 61 for Class C (Moderate).
Folds penetration testing into a broader, ongoing Vulnerability Detection and Response obligation: providers must systematically and persistently identify vulnerabilities using a mix of scanning, threat intelligence, bug bounties, penetration testing, and automated control testing — rather than treating a pentest as a single annual compliance artifact.
Requires risk-based remediation timelines — critical vulnerabilities with known exploits must be closed faster; lower-risk findings get more flexibility.

What FedRAMP 20x Does Not Change

CA-8 (penetration testing) remains a requirement — human-led pentests are not replaced by automation.
CA-8(2) (red team exercises) also remains required for Moderate/Class C systems.
Pentester independence requirements remain in place.
Annual pentest cadence is still the expected baseline, now sitting inside a continuous detection program rather than replacing it.
FedRAMP has never accepted a staging or dev environment as a valid substitute for testing production — that expectation predates CR26 and still applies.

Key Takeaway for IT Leaders & MSPs

Automation is increasing — but manual offensive security validation is not disappearing. CR26 makes the path to Class B/C authorization faster and more automated, but the pentesting requirement is not going away; if anything, folding it into a continuous vulnerability detection obligation raises the bar. Organizations preparing for the Class C pipeline opening August 31, 2026 should treat pentesting as part of an ongoing program — not a once-a-year deliverable — and work with a partner whose reports are detailed, remediation-focused, and retest-confirmed.

07

Common Question

Do Pentesters Need to Be U.S.-Based?

This is one of the most frequent questions MSPs ask when evaluating pentesting partners for FedRAMP-scoped work.

Short answer: No. FedRAMP itself has no U.S. citizenship or residency requirement for pentesters. The FedRAMP Program Management Office has directly confirmed there is no government-wide citizenship requirement.

What the framework does require:

Testers are independent from the organization being tested.
Personnel undergo appropriate background screening as described in the System Security Plan.
The CSP discloses its personnel screening approach to the sponsoring agency.

Agency-Level Exception

Individual agencies may impose their own citizenship or CONUS-location requirements as part of their Authorization to Operate (ATO) contract. This is especially relevant for DoD environments, ITAR/EAR-regulated systems, or agency-specific contracts. Always confirm agency-specific requirements before scoping an engagement.

08

Resources for MSPs

CMMC & FedRAMP Compliance

ResourceWhat It Covers
Software Secured: NIST SP 800-115 & PentestingExplains how NIST SP 800-115 (the how-to-test standard) relates to 800-53 (the controls standard).
DoD CMMC Official FAQs (Q33-Q37)Primary source for MSP and ESP classification under the CMMC final rule.
Secureframe: CMMC Compliance GuideCovers the CMMC program rule, enforcement timeline, and Level 2 certification requirements.
Secureframe: Pocket Guide to CMMC for MSPsMSP-specific guide to navigating CMMC for clients in the Defense Industrial Base.
FedRAMP.gov: Consolidated Rules for 2026Official GSA source for CR26, the Certification Classes, and the live Vulnerability Detection and Response rules.
FedRAMP.gov: 20x Program OverviewOfficial GSA roadmap for the FedRAMP 20x modernization and the Class A-D certification system.
Secureframe: FedRAMP 20x RoadmapPractitioner-level breakdown of CR26, the Key Security Indicators, and the deadlines retiring Rev5.

Ready to get in touch? Get started by booking a consultation now.

Book Consultation

Get security insights straight to your inbox

Continue your reading with these value-packed posts

Continuous Pentesting vs Traditional Pentesting comparison infographic
Black arrow icon
Penetration Test Reports & ROI

Continuous Pentesting vs Pentesting as a Service: Spot the Differences

Sherif Koussa
Sherif Koussa
8 min read
March 3, 2026
Black arrow icon
API & Web Application Security Testing

Comparing Website and Web Application Penetration Testing

Sherif Koussa
Sherif Koussa
9 min read
December 10, 2024
Black arrow icon
Penetration Testing Services

Top 10 Penetration Testing Services Companies for 2026 (Ranked & Compared)

Sherif Koussa
Sherif Koussa
9 min read
April 2, 2025

Helping companies identify, understand, and solve their security gaps so their teams can sleep better at night

Book a Consultation
Centralize pentest progress in one place
Canadian based, trusted globally
Actionable remediation support, not just vulnerabilities
Clutch logo
Web, API, Mobile Security
Web App PentestingMobile App PentestingSecure Code Review
Infrastructure & Cloud Security
External Network PentestingInternal Network PentestingSecure Cloud Review
AI, IoT & Hardware Security
AI PentestingIoT PentestingHardware Pentesting
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
More Services
Pentesting as a ServiceSecure Code Training
Industries
Data and AIFinanceHealthcareSecuritySaaS
Compliance
GDPR PentestingHIPAA PentestingISO 27001 PentestingPCI DSS PentestingSOC 2 Pentesting
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
More
PricingPortalPartnersContact UsAbout UsOur TeamCareers
Resources
BlogsCase StudiesEvents & WebinarsCustomer TestimonialsNews & PressWhitepapers
Comparisons
Software Secured vs Cobalt
Security & ComplianceSubprocessorsPrivacy PolicyTerms & Conditions
2026 ©SoftwareSecured