CMMC penetration testing: who has to do it, and what to buy if you do

By The PenTest Index · Rule text and prices checked October 10, 2026

CMMC penetration testing is required at only one level: Level 3, where the rule says to test at least annually or when significant security changes are made. Level 2 follows NIST SP 800-171 Rev 2, which calls for vulnerability scanning and regular control checks, not a penetration test. At Level 2, testing is your choice unless a separate applicable requirement calls for it, and scope sets the price.

One more thing changes the picture. Since July 13, 2026, the Defense Department has told its program offices not to write Level 3 into contracts. So if someone says "CMMC makes you get a pentest," ask them to show you the clause. Below are the exact rule text, what a sensible test covers, and published prices added up for a small network.

When is CMMC penetration testing required?

Only at Level 3. We read the CMMC rule, 32 CFR 170.14, on October 10, 2026. The word "penetration" appears in one requirement, and it is a Level 3 requirement.

Table columns: CMMC level; Penetration test required by the rule?; What the rule says; Where.
CMMC levelPenetration test required by the rule?What the rule saysWhere
Level 1NoThe 15 basic safeguarding requirements in the federal contract clause32 CFR 170.14(c)(2)
Level 2NoRequirements "are identical to the requirements in NIST SP 800-171 R2"32 CFR 170.14(c)(3)
Level 3Yes"Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts."32 CFR 170.14(c)(4), requirement CA.L3-3.12.1e

Your level is written in your solicitation or contract. If you can't find it, ask your contracting officer or the prime contractor you work under.

What did the July 2026 suspension change?

It took Level 3 out of new contracts for now, without changing the rule. DoD's suspension procedures say program offices "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period" and that "the allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)."

Two details matter if your contract already has Level 3 wording:

  • It doesn't vanish on its own. The procedures tell contracting officers to remove those requirements by contract modification, before the next option period or at the next scheduled administrative change. Until you have that in writing, ask what still applies.
  • Other security duties stay. The same document says the requirements in DFARS 252.204-7012 "remain in effect."

The procedures promised more guidance after a 60-day review. On October 10, 2026, DoD's CMMC page still showed Phase II as suspended and Phase I self-assessments as in effect. We did not find a later change.

Which situation are you in?

Table columns: Your situation; What the evidence supports; Do this next.
Your situationWhat the evidence supportsDo this next
Level 1 or 2, and someone says a pentest is "mandatory" but shows no clauseNot supported by the CMMC ruleSend the question below. Keep doing the scanning and control checks Level 2 does ask for
Level 2, and a customer or prime contract clause plainly requires a pentestSupported, by that clause, not by CMMCWrite down the scope, how often, who gets the report and the deadline. Then compare offers
Your contract still has Level 3 wordingUnresolved until you see the modificationAsk your contracting officer or prime, in writing, what still applies
No one requires it, but you want proof before you sign your scoreYour choice, and a reasonable oneScope it to the network that holds your sensitive data (see below)
Your IT provider already runs a test for youUnresolved until you compare it to the requestCheck its scope and date first. You may not need to buy anything

Here is the question to send when someone tells you a test is required:

Please point me to the contract clause or assessment objective that requires penetration testing, and the CMMC level it applies to. Is the test mandatory or recommended? What systems, methods, frequency and report does it call for? If our contract has a suspended assessment designation, please confirm the modification and what still applies.

What does CMMC Level 2 ask for instead?

Scanning for weaknesses, fixing what matters, and checking that your controls work. The scanning and control checks happen at least once a year. DoD's CMMC Model Overview (version 2.13, checked October 10, 2026) words the three related Level 2 requirements this way:

Table columns: Requirement; DoD's wording; What it means for your budget.
RequirementDoD's wordingWhat it means for your budget
RA.L2-3.11.2"Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified."You need regular scanning. One pentest report doesn't replace it
RA.L2-3.11.3"Remediate vulnerabilities in accordance with risk assessments."Finding problems isn't enough. Track the fixes
CA.L2-3.12.1"Periodically assess the security controls in organizational systems to determine if the controls are effective in their application."You must check that controls work. The text doesn't say how, and it doesn't say "penetration test"

How often is "periodically"? The CMMC rule answers that in 32 CFR 170.14(d): you set the interval, with "an interval length of no more than one year."

A vulnerability scan and a penetration test are different jobs. A scan is software that lists known weak spots. A human-led penetration test (pentest) is people trying to break in, with your written permission, to see which weak spots can really be used and how far an attacker could get. Think of a scan as a list of unlocked doors and a pentest as someone walking through them to see what they can reach. If a quote calls a scan a "CMMC pentest," it's a scan. More on the difference: penetration testing vs vulnerability scanning.

Should you buy a penetration test at Level 2 anyway?

Only if it answers a question you can't answer another way. Three common cases:

  • You sign the score. At Level 2 (Self), your company scores itself and a senior person affirms it. If you want outside proof that your network holds up before you sign, a scoped test is one honest way to get it.
  • A customer asks. A prime or customer can require a test in its own contract. That clause sets the scope, timing and report, so read it before you ask for quotes.
  • You already have one. If your IT provider tested you this year, compare what it covered with the network that holds your sensitive data. If it matches the request, ask whoever wants the report whether it will do.

If none of those fits, you can skip the purchase and put the money into the scanning and fixes Level 2 does name. Your evidence has to meet the applicable CMMC assessment procedures, and a pentest report alone doesn't make you compliant.

What should a penetration test cover for a CUI network?

The systems that hold your controlled data and the things that guard them. CUI means Controlled Unclassified Information, the sensitive government-related data that Level 2 and Level 3 are designed to protect. A test built around it usually has up to four parts. Pick the ones that match your goal.

Table columns: Part; What testers try; Ask for it when.
PartWhat testers tryAsk for it when
Outside (external)Getting in from the internet: VPN, remote access, email gateways, file-sharing portalsAnything that fronts your CUI is reachable from the internet
Inside (internal)Starting from one ordinary computer or account, reaching the CUI systemsYou claim CUI is walled off from the rest of the office. This checks the wall
ApplicationsWeb apps or APIs that store or move CUIYou run or built such an app
Cloud setupYour own settings in your cloud account: sign-in rules, sharing, admin rolesYour CUI lives in a cloud service. You test your settings, not the cloud company

Headcount doesn't set the scope. A 15-person shop with one flat network can be a bigger job than a 200-person firm with CUI in a small, separate set of machines.

Write it down once

A scope brief gives every supplier the same question, so their answers and prices line up. These eight fields are enough to start.

Table columns: Field; What to write.
FieldWhat to write
Who asked, and the exact wordingThe clause, email or goal behind the test
Level and contract statusLevel in your contract, and any modification
What you already haveLast test date, what it covered, any testing your IT provider includes
Systems in scopeWhich of the four parts, how many machines, apps and cloud accounts
Off limitsSystems, hours and third-party services that must not be touched
Who may do the workAny contract limits on tester location, citizenship or data handling
Report and deadlineWho reads it, what it must show, when it's due
Fix-checkingWhen your fixes will be ready and how late you may need a retest

A scope brief is a buying aid. It is not permission to test. Before anyone touches your systems, you need written authorization and agreed rules that name the real targets and activities. See penetration testing rules of engagement.

If you've decided to test, our free tool provides a checklist you can copy or print and send to any provider. No email or sign-up, and nothing goes to providers. Our comparison index mostly covers web app and API offers, so for a network test it gives you the scoping questions and a list of compared offers that state network or host testing.

Build your scope brief

What does a penetration test for a CUI network cost?

Software Secured's published starting prices for the network parts add up to $13,100 for outside plus inside testing, and $19,300 with a cloud review, all from one provider. Those are starting amounts on a pricing page, not a quote for you. Most providers publish no price at all.

To make that useful, we ran six real offers through our Purchase Check: we take one buyer's needs and test each published offer against them, one condition at a time.

The made-up buyer. Say you run a 60-person machine shop. Your contract says Level 2 (Self). Your drawings are export-controlled, so your contract limits who may see them. CUI sits on about 20 computers and one cloud account, behind one VPN. You want outside and inside testing, a cloud setup review, a written report, and a check of your fixes about 45 days after you get the findings. No provider has quoted for this buyer.

Table columns: Offer (A to Z); What the page says it covers; Published price; Fix-checking (retest); Finding for this buyer.
Offer (A to Z)What the page says it coversPublished priceFix-checking (retest)Finding for this buyer
A-LIGN, Premium package"External networks, internal networks, and web applications"None on the pageNot stated on the pageNetwork parts supported. Price, retest and cloud review unresolved
KirkpatrickPrice, network testExternal and internal network testing, with a written reportNone. "Pricing for a penetration test depends on scoping factors""After remediation, our team will retest." Count, window and fee not statedNetwork parts and a retest supported. Day-45 timing and price unresolved
Pivot Point Security, network testVulnerability testing, then exploitation testing, then a quality-checked reportNone on the pageFollow-up calls on your progress. A call is not a retestMethod supported. Outside and inside coverage, retest and price unresolved
Software SecuredExternal network, internal network and Secure Cloud Review, each sold separatelyStarts at $5,400, $7,700 and $6,200External: 1 round over 12 months. Internal and cloud: 3 rounds over 12 monthsAll three parts and 12-month retest windows supported. Starting total $19,300. Day-45 timing and full price unresolved
Stingrai, Autonomous and Hybrid"One web app + APIs"$3,000 and $6,800 per assessmentRetests included for those plansMismatch for a network test. Network work is in its custom-quote Enterprise plan
Synack, SynackSTOne human tester, up to 100 host IPs, five-day windowFrom $10,283 per test; platform is a required separate line item. A no-cost Basic tier is also listed; confirm the applicable tier and feePatch verification listed. Count and window not statedTotal unresolved until the applicable platform tier and fee are confirmed

All terms are provider-published. We read the pages on October 10, 2026. We have not bought or tested these services. Software Secured's page labels some prices "USD" and shows these three with a plain "$"; confirm the currency on your quote.

Which offer deserves a closer look?

Start with the condition that can rule a provider out. For this buyer that's who may see export-controlled data, and no page above answers it. Software Secured's pricing page says its packages include "direct access to our Canadian pentesters," so ask before anything else. Send every provider the same sentence:

Will every person who touches our systems, our data or our report meet the access limits in our contract, and where will they work from? Please confirm in writing.

What the limits are is set by your contract and export rules, not by CMMC. Ask your contracting officer or export counsel if you're unsure. A "no" removes that provider for you, however good the price.

If your data isn't export-controlled, Software Secured is the one offer here you can budget for before a sales call: $13,100 starting for outside plus inside, $19,300 with the cloud review. Watch the retest gap. The outside test lists one round and the others list three.

If you need apps tested along with the network, A-LIGN's Premium package names all three surfaces in one engagement.

If fix-checking matters most, KirkpatrickPrice states a retest after remediation. Get the count, the window and any fee in writing.

If you only have one web app in scope, Stingrai's priced plans fit that job, not a network.

Then get at least two written quotes against the same brief. Our quote comparison guide shows how to line them up, and penetration testing cost covers budgeting in more depth.

See A-LIGN's penetration testing packages

See KirkpatrickPrice's network test

See Pivot Point's network test

See Software Secured's prices

See Stingrai's prices

See Synack's prices

Five things every quote should state

  1. Each part and where testing starts. Outside, inside, apps, cloud.
  2. Every charge. Platform fees, minimum terms and add-ons, with the total.
  3. Two dates. When testing starts and when the final report arrives. They're different.
  4. Retest terms. How many rounds, what starts the clock, the last day to ask, and what it costs after that.
  5. Who does the work. Names or roles, where they work from, and how your findings are stored and deleted.

Buying for Level 3? Check the quote against the rule

The Level 3 sentence asks for four things, and a quote should show all four. This matters if your contract still carries Level 3 after the suspension questions above are settled.

  1. Will testing happen at least once a year?
  2. Will you test again after a significant security change, and what does that cost?
  3. Which automated scanning tools will you use?
  4. Which hands-on tests will your experts run, and who are they?

A scan-only offer misses the fourth. A hands-on test with no tools named leaves the third open. The sentence itself doesn't name an outside firm or a certificate. Whether your own team or a given supplier is acceptable is for DoD's assessors and your contract to decide, so ask before you buy.

Questions people still ask

Is a penetration test required for a C3PAO audit for Level 2 compliance?

No, not by the Level 2 requirements. A C3PAO is a CMMC third-party assessment organization. Level 2's requirements are those of NIST SP 800-171 Rev 2, which name scanning and control checks. If an assessor or consultant asks for a pentest, ask which requirement it is evidence for. Also note that DoD is not writing Level 2 (C3PAO) assessments into contracts during the suspension.

Is a vulnerability scan enough for Level 2?

Scanning is what the Level 2 text names, along with fixing what you find and checking your controls at least yearly. Whether your evidence is enough is decided in your assessment, not by a vendor. A scan is never a pentest, so don't pay pentest prices for one.

Did the 2026 suspension remove the pentest requirement?

No. The Level 3 sentence is still in the rule. What changed is that DoD told its offices not to put Level 3 or Level 2 (C3PAO) into contracts for now. Your own contract controls, so get any change in writing.

Does a penetration test mean we pass?

No. A penetration test is not a CMMC assessment and doesn't give you a CMMC status. It shows what a tester could and couldn't do on the systems in scope, on those dates. Be careful with any provider that promises a pass.

Sources

The PenTest Index is an independent buyer's resource. We don't perform, authorize or certify penetration testing, and we aren't affiliated with the Department of Defense or NIST. Payment plays no part in which offers appear here or in what order.