CMMC penetration testing: who has to do it, and what to buy if you do
By The PenTest Index · Rule text and prices checked October 10, 2026
CMMC penetration testing is required at only one level: Level 3, where the rule says to test at least annually or when significant security changes are made. Level 2 follows NIST SP 800-171 Rev 2, which calls for vulnerability scanning and regular control checks, not a penetration test. At Level 2, testing is your choice unless a separate applicable requirement calls for it, and scope sets the price.
One more thing changes the picture. Since July 13, 2026, the Defense Department has told its program offices not to write Level 3 into contracts. So if someone says "CMMC makes you get a pentest," ask them to show you the clause. Below are the exact rule text, what a sensible test covers, and published prices added up for a small network.
When is CMMC penetration testing required?
Only at Level 3. We read the CMMC rule, 32 CFR 170.14, on October 10, 2026. The word "penetration" appears in one requirement, and it is a Level 3 requirement.
| CMMC level | Penetration test required by the rule? | What the rule says | Where |
|---|---|---|---|
| Level 1 | No | The 15 basic safeguarding requirements in the federal contract clause | 32 CFR 170.14(c)(2) |
| Level 2 | No | Requirements "are identical to the requirements in NIST SP 800-171 R2" | 32 CFR 170.14(c)(3) |
| Level 3 | Yes | "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts." | 32 CFR 170.14(c)(4), requirement CA.L3-3.12.1e |
Your level is written in your solicitation or contract. If you can't find it, ask your contracting officer or the prime contractor you work under.
What did the July 2026 suspension change?
It took Level 3 out of new contracts for now, without changing the rule. DoD's suspension procedures say program offices "may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period" and that "the allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self)."
Two details matter if your contract already has Level 3 wording:
- It doesn't vanish on its own. The procedures tell contracting officers to remove those requirements by contract modification, before the next option period or at the next scheduled administrative change. Until you have that in writing, ask what still applies.
- Other security duties stay. The same document says the requirements in DFARS 252.204-7012 "remain in effect."
The procedures promised more guidance after a 60-day review. On October 10, 2026, DoD's CMMC page still showed Phase II as suspended and Phase I self-assessments as in effect. We did not find a later change.
Which situation are you in?
| Your situation | What the evidence supports | Do this next |
|---|---|---|
| Level 1 or 2, and someone says a pentest is "mandatory" but shows no clause | Not supported by the CMMC rule | Send the question below. Keep doing the scanning and control checks Level 2 does ask for |
| Level 2, and a customer or prime contract clause plainly requires a pentest | Supported, by that clause, not by CMMC | Write down the scope, how often, who gets the report and the deadline. Then compare offers |
| Your contract still has Level 3 wording | Unresolved until you see the modification | Ask your contracting officer or prime, in writing, what still applies |
| No one requires it, but you want proof before you sign your score | Your choice, and a reasonable one | Scope it to the network that holds your sensitive data (see below) |
| Your IT provider already runs a test for you | Unresolved until you compare it to the request | Check its scope and date first. You may not need to buy anything |
Here is the question to send when someone tells you a test is required:
Please point me to the contract clause or assessment objective that requires penetration testing, and the CMMC level it applies to. Is the test mandatory or recommended? What systems, methods, frequency and report does it call for? If our contract has a suspended assessment designation, please confirm the modification and what still applies.
What does CMMC Level 2 ask for instead?
Scanning for weaknesses, fixing what matters, and checking that your controls work. The scanning and control checks happen at least once a year. DoD's CMMC Model Overview (version 2.13, checked October 10, 2026) words the three related Level 2 requirements this way:
| Requirement | DoD's wording | What it means for your budget |
|---|---|---|
| RA.L2-3.11.2 | "Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified." | You need regular scanning. One pentest report doesn't replace it |
| RA.L2-3.11.3 | "Remediate vulnerabilities in accordance with risk assessments." | Finding problems isn't enough. Track the fixes |
| CA.L2-3.12.1 | "Periodically assess the security controls in organizational systems to determine if the controls are effective in their application." | You must check that controls work. The text doesn't say how, and it doesn't say "penetration test" |
How often is "periodically"? The CMMC rule answers that in 32 CFR 170.14(d): you set the interval, with "an interval length of no more than one year."
A vulnerability scan and a penetration test are different jobs. A scan is software that lists known weak spots. A human-led penetration test (pentest) is people trying to break in, with your written permission, to see which weak spots can really be used and how far an attacker could get. Think of a scan as a list of unlocked doors and a pentest as someone walking through them to see what they can reach. If a quote calls a scan a "CMMC pentest," it's a scan. More on the difference: penetration testing vs vulnerability scanning.
Should you buy a penetration test at Level 2 anyway?
Only if it answers a question you can't answer another way. Three common cases:
- You sign the score. At Level 2 (Self), your company scores itself and a senior person affirms it. If you want outside proof that your network holds up before you sign, a scoped test is one honest way to get it.
- A customer asks. A prime or customer can require a test in its own contract. That clause sets the scope, timing and report, so read it before you ask for quotes.
- You already have one. If your IT provider tested you this year, compare what it covered with the network that holds your sensitive data. If it matches the request, ask whoever wants the report whether it will do.
If none of those fits, you can skip the purchase and put the money into the scanning and fixes Level 2 does name. Your evidence has to meet the applicable CMMC assessment procedures, and a pentest report alone doesn't make you compliant.
What should a penetration test cover for a CUI network?
The systems that hold your controlled data and the things that guard them. CUI means Controlled Unclassified Information, the sensitive government-related data that Level 2 and Level 3 are designed to protect. A test built around it usually has up to four parts. Pick the ones that match your goal.
| Part | What testers try | Ask for it when |
|---|---|---|
| Outside (external) | Getting in from the internet: VPN, remote access, email gateways, file-sharing portals | Anything that fronts your CUI is reachable from the internet |
| Inside (internal) | Starting from one ordinary computer or account, reaching the CUI systems | You claim CUI is walled off from the rest of the office. This checks the wall |
| Applications | Web apps or APIs that store or move CUI | You run or built such an app |
| Cloud setup | Your own settings in your cloud account: sign-in rules, sharing, admin roles | Your CUI lives in a cloud service. You test your settings, not the cloud company |
Headcount doesn't set the scope. A 15-person shop with one flat network can be a bigger job than a 200-person firm with CUI in a small, separate set of machines.
Write it down once
A scope brief gives every supplier the same question, so their answers and prices line up. These eight fields are enough to start.
| Field | What to write |
|---|---|
| Who asked, and the exact wording | The clause, email or goal behind the test |
| Level and contract status | Level in your contract, and any modification |
| What you already have | Last test date, what it covered, any testing your IT provider includes |
| Systems in scope | Which of the four parts, how many machines, apps and cloud accounts |
| Off limits | Systems, hours and third-party services that must not be touched |
| Who may do the work | Any contract limits on tester location, citizenship or data handling |
| Report and deadline | Who reads it, what it must show, when it's due |
| Fix-checking | When your fixes will be ready and how late you may need a retest |
A scope brief is a buying aid. It is not permission to test. Before anyone touches your systems, you need written authorization and agreed rules that name the real targets and activities. See penetration testing rules of engagement.
If you've decided to test, our free tool provides a checklist you can copy or print and send to any provider. No email or sign-up, and nothing goes to providers. Our comparison index mostly covers web app and API offers, so for a network test it gives you the scoping questions and a list of compared offers that state network or host testing.
What does a penetration test for a CUI network cost?
Software Secured's published starting prices for the network parts add up to $13,100 for outside plus inside testing, and $19,300 with a cloud review, all from one provider. Those are starting amounts on a pricing page, not a quote for you. Most providers publish no price at all.
To make that useful, we ran six real offers through our Purchase Check: we take one buyer's needs and test each published offer against them, one condition at a time.
The made-up buyer. Say you run a 60-person machine shop. Your contract says Level 2 (Self). Your drawings are export-controlled, so your contract limits who may see them. CUI sits on about 20 computers and one cloud account, behind one VPN. You want outside and inside testing, a cloud setup review, a written report, and a check of your fixes about 45 days after you get the findings. No provider has quoted for this buyer.
| Offer (A to Z) | What the page says it covers | Published price | Fix-checking (retest) | Finding for this buyer |
|---|---|---|---|---|
| A-LIGN, Premium package | "External networks, internal networks, and web applications" | None on the page | Not stated on the page | Network parts supported. Price, retest and cloud review unresolved |
| KirkpatrickPrice, network test | External and internal network testing, with a written report | None. "Pricing for a penetration test depends on scoping factors" | "After remediation, our team will retest." Count, window and fee not stated | Network parts and a retest supported. Day-45 timing and price unresolved |
| Pivot Point Security, network test | Vulnerability testing, then exploitation testing, then a quality-checked report | None on the page | Follow-up calls on your progress. A call is not a retest | Method supported. Outside and inside coverage, retest and price unresolved |
| Software Secured | External network, internal network and Secure Cloud Review, each sold separately | Starts at $5,400, $7,700 and $6,200 | External: 1 round over 12 months. Internal and cloud: 3 rounds over 12 months | All three parts and 12-month retest windows supported. Starting total $19,300. Day-45 timing and full price unresolved |
| Stingrai, Autonomous and Hybrid | "One web app + APIs" | $3,000 and $6,800 per assessment | Retests included for those plans | Mismatch for a network test. Network work is in its custom-quote Enterprise plan |
| Synack, SynackST | One human tester, up to 100 host IPs, five-day window | From $10,283 per test; platform is a required separate line item. A no-cost Basic tier is also listed; confirm the applicable tier and fee | Patch verification listed. Count and window not stated | Total unresolved until the applicable platform tier and fee are confirmed |
All terms are provider-published. We read the pages on October 10, 2026. We have not bought or tested these services. Software Secured's page labels some prices "USD" and shows these three with a plain "$"; confirm the currency on your quote.
Which offer deserves a closer look?
Start with the condition that can rule a provider out. For this buyer that's who may see export-controlled data, and no page above answers it. Software Secured's pricing page says its packages include "direct access to our Canadian pentesters," so ask before anything else. Send every provider the same sentence:
Will every person who touches our systems, our data or our report meet the access limits in our contract, and where will they work from? Please confirm in writing.
What the limits are is set by your contract and export rules, not by CMMC. Ask your contracting officer or export counsel if you're unsure. A "no" removes that provider for you, however good the price.
If your data isn't export-controlled, Software Secured is the one offer here you can budget for before a sales call: $13,100 starting for outside plus inside, $19,300 with the cloud review. Watch the retest gap. The outside test lists one round and the others list three.
If you need apps tested along with the network, A-LIGN's Premium package names all three surfaces in one engagement.
If fix-checking matters most, KirkpatrickPrice states a retest after remediation. Get the count, the window and any fee in writing.
If you only have one web app in scope, Stingrai's priced plans fit that job, not a network.
Then get at least two written quotes against the same brief. Our quote comparison guide shows how to line them up, and penetration testing cost covers budgeting in more depth.
See A-LIGN's penetration testing packages
See KirkpatrickPrice's network test
See Pivot Point's network test
Five things every quote should state
- Each part and where testing starts. Outside, inside, apps, cloud.
- Every charge. Platform fees, minimum terms and add-ons, with the total.
- Two dates. When testing starts and when the final report arrives. They're different.
- Retest terms. How many rounds, what starts the clock, the last day to ask, and what it costs after that.
- Who does the work. Names or roles, where they work from, and how your findings are stored and deleted.
Buying for Level 3? Check the quote against the rule
The Level 3 sentence asks for four things, and a quote should show all four. This matters if your contract still carries Level 3 after the suspension questions above are settled.
- Will testing happen at least once a year?
- Will you test again after a significant security change, and what does that cost?
- Which automated scanning tools will you use?
- Which hands-on tests will your experts run, and who are they?
A scan-only offer misses the fourth. A hands-on test with no tools named leaves the third open. The sentence itself doesn't name an outside firm or a certificate. Whether your own team or a given supplier is acceptable is for DoD's assessors and your contract to decide, so ask before you buy.
Questions people still ask
Is a penetration test required for a C3PAO audit for Level 2 compliance?
No, not by the Level 2 requirements. A C3PAO is a CMMC third-party assessment organization. Level 2's requirements are those of NIST SP 800-171 Rev 2, which name scanning and control checks. If an assessor or consultant asks for a pentest, ask which requirement it is evidence for. Also note that DoD is not writing Level 2 (C3PAO) assessments into contracts during the suspension.
Is a vulnerability scan enough for Level 2?
Scanning is what the Level 2 text names, along with fixing what you find and checking your controls at least yearly. Whether your evidence is enough is decided in your assessment, not by a vendor. A scan is never a pentest, so don't pay pentest prices for one.
Did the 2026 suspension remove the pentest requirement?
No. The Level 3 sentence is still in the rule. What changed is that DoD told its offices not to put Level 3 or Level 2 (C3PAO) into contracts for now. Your own contract controls, so get any change in writing.
Does a penetration test mean we pass?
No. A penetration test is not a CMMC assessment and doesn't give you a CMMC status. It shows what a tester could and couldn't do on the systems in scope, on those dates. Be careful with any provider that promises a pass.
Sources
- 32 CFR 170.14, CMMC Model, eCFR, shown as current through October 7, 2026. Read October 10, 2026.
- CMMC Model Overview, version 2.13, Department of Defense. Level 2 requirement wording. Checked October 10, 2026.
- Cybersecurity Maturity Model Certification Procedures, 26-P-1023, Attachment 1, Department of Defense. Read October 10, 2026.
- DoD CMMC page. Suspension status. Checked October 10, 2026.
- Provider pages for A-LIGN, KirkpatrickPrice, Pivot Point Security, Software Secured and Stingrai. Checked October 10, 2026.
- Synack pricing. Checked October 10, 2026.
The PenTest Index is an independent buyer's resource. We don't perform, authorize or certify penetration testing, and we aren't affiliated with the Department of Defense or NIST. Payment plays no part in which offers appear here or in what order.