NIST 800-53 Moderate Pentesting Requirements Guide
This guide explains the penetration testing expectations behind NIST 800-53 Moderate, including required controls, typical testing scope, assessor expectations, red team requirements, and the impact of FedRAMP 20x. Whether you're a SaaS provider, MSP, federal contractor, or cloud service provider, this resource helps clarify what security validation activities are expected and how to prepare for assessments.
Key Takeaways
- Understand which NIST 800-53 controls drive penetration testing requirements, including CA-8 and RA-5.
- Learn what systems and environments should typically be included in scope.
- Understand the difference between vulnerability scanning and penetration testing.
- Learn when annual pentests, remediation retesting, and red team exercises are expected.
- See what FedRAMP Moderate assessors commonly look for during reviews.
- Understand how cloud infrastructure, web applications, APIs, and internal networks fit into compliance testing.
- Learn what FedRAMP 20x changes and what remains the same.
- Clarify common misconceptions around pentester independence and U.S.-based testing requirements
A practical guide for IT leaders, MSPs, and SaaS teams navigating FedRAMP Moderate, U.S. federal systems, and regulated environments.
UPDATED AUGUST 2026This guide reflects the FedRAMP Consolidated Rules for 2026 (CR26) and the FedRAMP 20x certification pipeline.
Quick Summary
What IT Leaders Need to Know
If your organization is pursuing FedRAMP Moderate authorization or supporting federal customers, penetration testing is not optional. Here is the simplified version:
AT A GLANCE
What Is FedRAMP Moderate?
Background & Context
FedRAMP Moderate is a U.S. federal security baseline used for cloud service providers (CSPs) handling sensitive but unclassified government information. The framework is built on NIST SP 800-53 security controls and is commonly required for:
As of August 2026, FedRAMP Moderate is represented by two parallel paths: the legacy Rev5 baseline (325 controls) and the new FedRAMP 20x Class C certification, which replaces the Moderate impact level under the Consolidated Rules for 2026. This guide focuses specifically on the penetration testing and security validation expectations behind FedRAMP Moderate.
| Term | Plain English Meaning |
|---|---|
| Authorization Boundary | The systems, applications, cloud infrastructure, and services included in your FedRAMP assessment. |
| CUI | Controlled Unclassified Information — sensitive government-related information requiring protection. |
| CSP | Cloud Service Provider. |
| 3PAO | Third-Party Assessment Organization authorized to perform FedRAMP assessments. |
| CA-8 | The NIST control covering penetration testing. |
| RA-5 | The NIST control covering vulnerability scanning. |
| Red Team Exercise | A simulated adversary exercise focused on testing detection and response capabilities — distinct from a pentest. |
| Class C | The FedRAMP 20x certification class that replaces the Moderate impact level under CR26. |
Required Controls
What Pentesting Is Required for NIST 800-53 Moderate?
NIST 800-53 Moderate does not mandate a specific annual pentest on a fixed schedule. What it requires is penetration testing and vulnerability assessments as part of a continuous monitoring program. Three controls directly drive this. A fourth set indirectly requires testing as part of broader system assurance obligations.
CA-8: Penetration Testing (Core Requirement)
CA-8 is the primary pentesting control. A compliant pentest under CA-8 must:
RA-5: Vulnerability Monitoring & Scanning (Also Required)
RA-5 governs ongoing vulnerability scanning — a distinct activity from pentesting, but the baseline it establishes matters.
Scanning is not Pentesting
Vulnerability scanning identifies potential weaknesses automatically. Penetration testing actively validates whether vulnerabilities can be exploited in real-world attack scenarios. Scans alone do not satisfy the CA-8 requirement — and FedRAMP assessors know the difference.
CA-2: Security Assessments (Pentest Evidence Supports This)
CA-2 requires broader technical evaluation and control validation activities. A pentest report directly contributes evidence for CA-2 compliance, including controls testing, technical evaluation of implemented safeguards, and continuous monitoring evidence.
SI-2, SI-4, SC-7: Controls That Indirectly Trigger Testing
| Control | Why It Matters |
|---|---|
| SI-4 | Validates monitoring and detection effectiveness — pentest results confirm detection capability. |
| SI-2 | Significant infrastructure changes often require a new pentest. |
| SC-7 | Segmentation and boundary protections must be validated through testing. |
Pentest Scope
What Should Be In Scope?
The authorization boundary determines pentest scope. In practice, any system that stores, processes, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) should generally be included.
| Component | Typical Testing Focus |
|---|---|
| External Perimeter | Public-facing assets, IP ranges, DNS infrastructure. |
| Internal Network | Segmentation, lateral movement paths. |
| Web Applications & APIs | Authentication, authorization, business logic, and any app handling FCI/CUI. |
| Cloud Infrastructure | AWS, Azure, GCP — configuration review and exploitation testing. |
| Boundary Protections | WAF, VPN, SSO, IAM — tested for bypass and misconfiguration. |
| Configuration Reviews | Key systems assessed for hardening gaps. |
What FedRAMP Moderate Does Not Explicitly Require
The following are not directly mandated by the standard, though assessors may expect them depending on system complexity or agency requirements:
Important Update: Red Team Exercises (CA-8(2)) Now Required for Moderate
Under NIST 800-53 Rev 5 and the FedRAMP Rev 5 baseline (finalized May 2023), CA-8(2) red team exercises have been added to both the Moderate and High baselines. In addition to the standard annual penetration test, Moderate CSPs must now conduct annual red team exercises that simulate real adversary attempts to compromise organizational systems.
Red team exercises differ from pentests in focus: rather than finding and exploiting as many vulnerabilities as possible, red teams assess detection, defense, and response capabilities.
Pentesting vs. Red Teaming
| Pentesting | Red Teaming |
|---|---|
| Focuses on finding and exploiting vulnerabilities | Focuses on testing detection and response capabilities |
| Usually time-boxed and scoped to specific systems | Simulates realistic adversary behavior across the environment |
| Prioritizes exploit validation and remediation evidence | Prioritizes operational resilience and defensive maturity |
Assessor Expectations
What Auditors Commonly Expect in Practice
Although FedRAMP guidance allows flexibility, most 3PAOs and assessors conducting FedRAMP Moderate reviews expect a practical annual testing package covering the following:
Typically Expected
Commonly Recommended
FedRAMP 20x
What's Changing for Moderate Authorization
UPDATED AUGUST 2026On June 25, 2026, FedRAMP finalized the Consolidated Rules for 2026 (CR26) — a single ruleset that formally establishes FedRAMP 20x as the path forward for Low and Moderate authorizations, replacing the FIPS 199 impact levels with four Certification Classes.
The New Certification Classes
CR26 replaces "FedRAMP Low / Moderate / High" with four Certification Classes:
| Class | What It Means |
|---|---|
| Class A (Pilot) | Entry-level Marketplace listing via SOC 2 Type II; no agency sponsor required. On-ramp only — CSPs have 2 years to reach Class B or higher. |
| Class B (Low) | Replaces the FedRAMP Low impact level. |
| Class C (Moderate) | Replaces the FedRAMP Moderate impact level — the class most commercial SaaS providers land in. |
| Class D (High) | Remains on the Rev5 path for now; a 20x Class D pilot is targeted for FY27. |
2026 Pipeline Dates
| Date | Milestone |
|---|---|
| Aug 3, 2026 | FedRAMP 20x Class A pipeline opens. |
| Aug 10, 2026 | Temporary Rev5 conversion pipelines open for eligible Class B/C providers without an agency sponsor. |
| Aug 31, 2026 | FedRAMP 20x Class B and Class C pipelines open — the major milestone for commercial SaaS. |
| Jan 1, 2027 | CR26 becomes mandatory for all stakeholders; existing Rev5 certifications must adopt the new rules. |
| Jun 11, 2027 | FedRAMP stops accepting new Rev5 certification applications. |
What FedRAMP 20x / CR26 Changes
What FedRAMP 20x Does Not Change
Key Takeaway for IT Leaders & MSPs
Automation is increasing — but manual offensive security validation is not disappearing. CR26 makes the path to Class B/C authorization faster and more automated, but the pentesting requirement is not going away; if anything, folding it into a continuous vulnerability detection obligation raises the bar. Organizations preparing for the Class C pipeline opening August 31, 2026 should treat pentesting as part of an ongoing program — not a once-a-year deliverable — and work with a partner whose reports are detailed, remediation-focused, and retest-confirmed.
Common Question
Do Pentesters Need to Be U.S.-Based?
This is one of the most frequent questions MSPs ask when evaluating pentesting partners for FedRAMP-scoped work.
Short answer: No. FedRAMP itself has no U.S. citizenship or residency requirement for pentesters. The FedRAMP Program Management Office has directly confirmed there is no government-wide citizenship requirement.
What the framework does require:
Agency-Level Exception
Individual agencies may impose their own citizenship or CONUS-location requirements as part of their Authorization to Operate (ATO) contract. This is especially relevant for DoD environments, ITAR/EAR-regulated systems, or agency-specific contracts. Always confirm agency-specific requirements before scoping an engagement.
Resources for MSPs
CMMC & FedRAMP Compliance
| Resource | What It Covers |
|---|---|
| Software Secured: NIST SP 800-115 & Pentesting | Explains how NIST SP 800-115 (the how-to-test standard) relates to 800-53 (the controls standard). |
| DoD CMMC Official FAQs (Q33-Q37) | Primary source for MSP and ESP classification under the CMMC final rule. |
| Secureframe: CMMC Compliance Guide | Covers the CMMC program rule, enforcement timeline, and Level 2 certification requirements. |
| Secureframe: Pocket Guide to CMMC for MSPs | MSP-specific guide to navigating CMMC for clients in the Defense Industrial Base. |
| FedRAMP.gov: Consolidated Rules for 2026 | Official GSA source for CR26, the Certification Classes, and the live Vulnerability Detection and Response rules. |
| FedRAMP.gov: 20x Program Overview | Official GSA roadmap for the FedRAMP 20x modernization and the Class A-D certification system. |
| Secureframe: FedRAMP 20x Roadmap | Practitioner-level breakdown of CR26, the Key Security Indicators, and the deadlines retiring Rev5. |

.avif)

