FedRAMP penetration testing: what the rules require and who can test
By The PenTest Index · Rules, assessor listings and offer pages checked October 10, 2026
FedRAMP penetration testing is the attack-style test of a cloud service whose penetration-testing controls are assessed yearly under the 2026 Rev5 rules for Class B, C and D. FedRAMP's 2022 guidance puts the test under a 3PAO's responsibility, so a regular pentest company's standalone report does not automatically satisfy the assessment requirements.
Two official rulebooks cover this test right now, and they do not say the same things. The tables below show which one says what, who is allowed to do the work, and what to get in writing before you sign.
Which FedRAMP test do you actually need?
Most teams need one thing: the test that comes with their independent assessment. Some also buy a second, separate test beforehand so nothing surprises them. Find your row.
| Your situation | What you need | Who can supply it | What to do now |
|---|---|---|---|
| First certification requiring a FedRAMP independent assessment, no assessor yet | The assessment and required testing | A recognized assessor, or FedRAMP under the 2026 rules; confirm who does the testing | Shortlist from FedRAMP's own directory |
| You already have an assessor | Probably nothing new | Your assessor | Ask what your signed scope already covers |
| Assessment is booked and you fear surprises | A preparation test before the assessor arrives | A pentest company; check the two-year rule before using your assessor | Write the scope first, then get prices |
| Already certified, with yearly FedRAMP assessment required | The yearly assessment, plus whatever testing you run in between | Assessor or FedRAMP for the assessment. Testing supplier as allowed by your rules | Confirm which rules your next assessment follows |
| You built on a cloud that is already certified | Possibly less. Lower layers already covered may not need retesting | Your assessor decides | Ask which layers you inherit |
| You buy FedRAMP products but do not sell one | No FedRAMP test | Nobody | See which assessment type fits |
If you need an assessor, start with FedRAMP's assessor directory. Use the table view. The default view showed us only a handful of names.
If you already have one, send this before you buy anything else: "Which rules apply to our next assessment, and does our signed scope include the testing and evidence those rules require?"
What does FedRAMP penetration testing require in 2026?
It depends on which rulebook your assessment follows, and during the changeover that can be either one. The older text is the FedRAMP Penetration Test Guidance, version 3.0, dated June 30, 2022. The newer one is the FedRAMP Consolidated Rules for 2026, launched June 24, 2026.
We read both on October 10, 2026. Where the 2026 rules are silent, we say so and do not guess.
| Topic | 2022 guidance (v3.0) | 2026 rules | What it means for you |
|---|---|---|---|
| Status | Still on fedramp.gov with no "replaced" notice. Not in FedRAMP's list of legacy documents | Optional adoption began July 4, 2026. Mandatory dates and grace periods vary by ruleset | Get your assessor to name the rulebook in writing |
| Who performs the test | A 3PAO, with a team lead who holds a recognized pentest credential (section 8) | Rev5 Class C and D require an independent penetration testing agent or team. The formal assessment uses a recognized assessor or FedRAMP | Confirm the testing team and assessment responsibility |
| How often | For initial authorization, within 6 months before SAR submission; then at least every 12 months unless a documented exception is approved (section 7) | Rev5 CA-08 has an organization-defined testing frequency. An independent assessment is required at least once a year for Class B, C and D | Budget for yearly assessment; confirm the testing cadence |
| What the yearly assessment checks | The pentest report goes into the assessment report | Class B: the base pentest control, CA-08. Class C and D: CA-08 (01), independent tester, and CA-08 (02), red team exercises | In Class C or D, ask how the red team item is handled |
| What gets tested | Six named attack paths, each tested or explained in writing (section 3) | The six do not appear. Pentesting is "part of vulnerability detection" | Expect assessors to keep using the six for now. That is our reading, not a FedRAMP statement |
| Where | Production for tenant tests, subject to the section 4 multi-tenancy exception below | Not stated | Plan your test tenants early |
| Rules of engagement | Written by the assessor and approved by the authorizing official before testing (section 5) | CA-08 (02) refers to applicable rules of engagement; no matching v3 approval procedure is stated | Nothing starts without signed approval |
| Reporting | A full pentest report with six required parts (section 6) | A summary in your Security Decision Record. No separate assessment plan or report required | Ask who writes what |
Sources: Penetration Test Guidance v3.0; 2026 control reference for CA-08; independent assessment rules. All checked October 10, 2026.
Three details change the answer for some readers.
Low-impact systems under the older rules. FedRAMP's legacy baseline workbook sets the Low pentest at "at least annually" and says scope "can be limited to public facing applications." The legacy assessment plan template adds that Low and LI-SaaS carry "no requirement for an independent testing team," so the assessor reviews the quality of the test. That does not match the 2022 guidance, which assigns penetration-test activities to the 3PAO. If you are Low or LI-SaaS, ask your assessor which document governs.
Classes are not the old levels renamed. FedRAMP says there is "not a direct correlation" between a certification class and Low, Moderate or High. Don't assume Class B means Low.
There is a version 4 of the guidance, and it is a draft. It is dated March 4, 2024 and marked DRAFT. A draft is not a requirement.
If you are on FedRAMP 20x
The 20x path replaces the control list with Key Security Indicators, and the yearly assessment must cover all of them for Class B, C and D. We searched FedRAMP's published rules data for "penetration," "pen test" and "red team." None of the indicators uses those words.
The one hook we found is the rule called VDR-CSO-DET. It tells you to find vulnerabilities using "appropriate techniques" and names penetration testing as one example alongside scanning and bug bounties. So on 20x, a pentest is one way to meet a wider duty, and your assessor judges whether your methods are enough.
Which dates matter?
| Date | What happens |
|---|---|
| July 4, 2026 | Early adoption of the 2026 rules became optional |
| December 7, 2026 | The vulnerability detection rules apply to anyone obtaining certification. Existing providers should adopt them |
| January 1, 2027 | Overall mandatory adoption milestone, subject to ruleset dates and grace periods. The new Rev5 assessment rules apply from the first independent assessment started after this date |
| March 7, 2027 | Existing providers must have adopted the vulnerability rules. FedRAMP's deadlines page says certification will be revoked otherwise |
| June 11, 2027 | FedRAMP stops accepting applications for new Rev5 certifications |
Sources: FedRAMP important dates and Rev5 deadlines, checked October 10, 2026.
Who can perform a FedRAMP penetration test?
For the formal independent assessment under the 2026 rules, a FedRAMP recognized assessor or FedRAMP; hands-on testing follows the applicable scope and independence rules. The 2022 guidance says all penetration test activities "must be performed by a 3PAO." FedRAMP now calls these firms independent assessment services, "formerly referred to as Third-Party Assessment Organizations or 3PAOs." Each must hold accreditation through the A2LA Cybersecurity Inspection Body Program.
One exception sits in the guidance itself. For a system with a FedRAMP Agency ATO under the 2022 guidance, "3PAO" can mean any assessment organization the agency's authorizing official designates. If an agency sponsors you, ask them.
Can my regular pentest company do it?
Sometimes. Qualified subcontracted testing can be performed under a recognized assessor's responsibility, and the 2026 Rev5 Class C/D control requires an independent agent or team rather than naming a recognized assessor. It can do a preparation test, and that can be money well spent.
Check the claim yourself. Every recognized assessor has a numbered page in FedRAMP's directory. Ask any firm for its Assessor ID and look it up.
Here is why it matters. One vendor's published ranking of "FedRAMP penetration testing companies" describes NetSPI as "an accredited 3PAO." When we went through the table view of FedRAMP's directory on October 10, 2026, we counted 47 named assessors and did not find a NetSPI entry. The same article says its own publisher, Astra, "collaborates with accredited 3PAOs," and we did not find Astra in the table either. A firm can be a good pentest company and still not be the one who can perform the recognized assessment.
Platform status is a different thing again. A security tool that holds its own FedRAMP certification is a certified product. That does not make its maker an assessor.
Can my assessor also help me prepare?
Be careful here, because two rules pull in different directions.
- The two-year rule. An assessor "MUST NOT perform a FedRAMP independent assessment of the same cloud service offering within 2 years after supplying advisory or consulting services for that offering," unless FedRAMP publishes a specific exception.
- The advice rule. During an assessment, assessors "MAY share advice" about techniques and procedures unless doing so "is likely to compromise the objectivity and integrity of the assessment."
We found no FedRAMP text saying whether a preparation pentest counts as "advisory or consulting services." So ask before you sign: "Would a preparation pentest from your firm count as advisory work under REC-IAS-SEP for our offering?" If the answer is yes, buy the preparation test elsewhere. If the answer is no, get that in writing.
Sources: FedRAMP recognition rules for assessors, assessor verification and advice rules and A2LA R311, checked October 10, 2026.
Which recognized assessors say what about testing?
No assessor we checked publishes a price, a retest policy or a delivery date for FedRAMP testing. What their pages do tell you is how each one works, and that is enough to know what to ask.
We looked at three of the 47. We picked them because their public pages say something checkable about testing. This is not a ranking, and the other 44 may suit you as well or better. Listed A to Z.
| Assessor and FedRAMP ID | What FedRAMP's listing shows | What the firm's own page says | Still unresolved | Ask this |
|---|---|---|---|---|
| A-LIGN Compliance and Security, Inc. dba A-LIGN (138665) | Recognized since October 21, 2013. Offers consulting | Cost varies with "whether penetration testing is included." Supports both Rev5 and 20x | Whether testing is in your price. Retest terms. Dates | "Is the testing in this assessment price, or a separate statement of work?" |
| Coalfire Systems, Inc. (138514) | Recognized since July 17, 2015. Offers consulting | The assessment "includes manual control testing, vulnerability scanning, and penetration testing." Mentions "all six attack vectors" and red team assessments | Price. Retest terms. Dates. How the scope changes under the 2026 rules | "How does your test plan change if we adopt the 2026 rules?" |
| Schellman Compliance, LLC (136571) | Recognized since July 27, 2012. "Only performs assessment services, and no consulting services" | Describes itself as an assessment-only provider. Covers Rev5 and 20x | Price. Retest terms. Dates. Who does the hands-on testing | "Who performs the testing, and how is a fix rechecked?" |
All rows provider-published or FedRAMP-listed, checked October 10, 2026. We have not bought from or tested any of these firms.
How to use this. If you want a hard wall between whoever helps you get ready and whoever judges you, Schellman's listing says it does no consulting, so the two-year rule is less likely to bite. If you want one firm for readiness help and assessment, A-LIGN and Coalfire both list consulting, which makes the two-year question the first thing to settle with either. If the six attack paths and a red team exercise matter to your class, Coalfire's page names both. None of this tells you who is cheapest, fastest or best. Only written proposals for the same scope can do that.
See A-LIGN's FedRAMP assessment page
See Coalfire's FedRAMP assessment page
See Schellman's FedRAMP assessment page
What are the six FedRAMP attack vectors?
They are six attack paths the 2022 guidance makes mandatory "regardless of classification." Each must be tested, or the test plan must explain why it does not apply. An attack vector is simply a route an attacker could take in.
| Attack path | Plain meaning | What you have to set up |
|---|---|---|
| 1. External to Corporate | A phishing test against your admins and the people who can influence them | Let the test emails through your filters untouched. The point is to test people, not the spam filter |
| 2. External to CSP Target System | An outsider on the internet attacking your public apps, APIs and services | A full list of public endpoints. Blocking tools such as web application firewalls are bypassed for the test |
| 3. Tenant to CSP Management System | A customer trying to break out into your own admin systems | Accounts with the highest permissions a customer can have, in production |
| 4. Tenant-to-Tenant | One customer trying to reach another customer's data | Two full production customer tenants, or the section 4 arrangement validated by the assessor |
| 5. Mobile Application to Target System | Attacking through your mobile app | A test device. If you have no mobile app, this is marked out of scope |
| 6. Client-side Application or Agents | Attacking through software your customers install | In scope if customers need it to use your service |
Source: Penetration Test Guidance v3.0, sections 3.1.1 to 3.1.6, checked October 10, 2026. The plain meanings are our wording.
Skipping one has a cost. The guidance says an assessor "might see non-conformance to testing a particular attack vector as a High Risk finding." If you decline the phishing test, the assessor must write your reasons into the report.
The 2026 rules do not list these six. Nothing has replaced them as a shared checklist, which is why we expect assessors to keep using them. Confirm with yours.
Can we use a staging environment?
Mostly no under the 2022 guidance. It says development and test copies "are rarely identical to the production deployment" and will not be used as a stand-in for the tenant tests. Section 4 allows one narrow thing: if no suitable tenant exists, you must build a temporary one, and production-to-development instances may be used for multi-tenancy testing if the assessor confirms the attack paths are still tested properly. The 2026 rules say nothing on environment. Write down what you and the assessor agree.
Are mobile apps, agents and other vendors' systems always in scope?
No. Under the 2026 scope rule, you must include everything "likely to handle federal customer data" or likely to affect its security. But software "delivered separately for installation on agency systems and not operated in a shared responsibility model" is "entirely outside the scope of FedRAMP." Your cloud APIs behind that software are still in.
For other vendors' systems, getting permission is your job. The guidance says testing "should not be performed on assets for which permission has not been explicitly documented."
What if we run on a cloud that is already certified?
You may inherit the lower layers. The guidance says attack paths "already addressed by other FedRAMP Authorized services lower in the cloud stack are not required to be re-evaluated." Your own application, roles and APIs still need testing. A certified host is not a pass for what you built on top of it.
How often is the test required, and when should you book it?
Plan on yearly assessment for Class B, C and D; confirm the testing cadence against your applicable rules. The 2022 guidance says the first test must happen "no more than 6 months prior to the submission" of the assessment report, then "at least every 12 months" unless an authorizing body approves otherwise in writing. The 2026 rules set no pentest frequency of their own, but Class B, C and D need an independent assessment "at least once per year," and on Rev5 the pentest controls are on that yearly list.
Here is the six-month rule as a date. Say your initial assessment follows the older process and its SAR submission is due April 30, 2027. Count back six months. A test finished before October 30, 2026 is too old.
That rule is tied to the assessment report. The 2026 rules no longer require a separate report, so if your next assessment starts after January 1, 2027, ask your assessor what date the test evidence is measured against.
A big change to your system can also call for a test outside the yearly cycle. Tell your assessor before the change, not after.
For Class C and D, the yearly list includes red team exercises. FedRAMP adds no guidance or schedule of its own to that control. Ask what exercise is planned and what evidence it produces.
When you book, work backward: report deadline, time to recheck fixes, time to fix, testing, signed rules of engagement, access and tenants ready. Ask for real calendar dates. A stated "testing takes two weeks" is not a reserved slot.
How much does a FedRAMP pentest cost?
There is no honest single number. FedRAMP publishes no prices, and none of the three assessor pages we read gives one. The test is normally priced inside the assessment, and A-LIGN's page says cost varies with "whether penetration testing is included."
What one advisory firm estimates for the whole assessment. stackArmor, which sells FedRAMP help, says a Moderate assessment including the penetration test and report "can vary between $125,000 to $175,000," a low-impact SaaS assessment "might only cost $30,000-$40,000," and yearly assessments run "between $75,000 to $125,000." A reader comment on that page puts the Moderate range at "more like $125-190k depending on the 3PAO." The page says it was updated May 24, 2025. Treat these as one vendor's estimates in US dollars, not a market average and not a quote. stackArmor's cost page, checked October 10, 2026.
What a preparation test costs, where a price is published. These are ordinary commercial web app tests. Neither firm is a FedRAMP assessor, and neither price covers phishing or says it covers tenant-to-tenant testing.
| Offer | Published price (US dollars) | What it covers | Retest | What to confirm |
|---|---|---|---|---|
| Pentest-Tools.com managed web app test, grey box | "Starting from: $3400 + $900/user role." For two roles that is $5,200 as a starting amount | Manual test of one web app with logged-in roles. 4 or more working days, best effort | No retest terms found on the page | API coverage, a second tenant, retest price |
| Astra Pentest Expert | $5,999 per year for 1 target | A manual pentest plus scanning | 2 manual rescans; requests within "30 days from the date the vulnerabilities were reported" | What counts as one target. Whether tenant isolation is tested |
Provider-published prices, checked October 10, 2026. Sources: Pentest-Tools.com; Astra pricing; Astra rescan rules.
That 30-day window is short for a team fixing real findings. If Astra reports findings on March 1, you must ask for the recheck by March 31 unless Astra grants an extension.
One price we could not match. Astra's own article lists its "FedRAMP-focused assessments" as "Starting at $4,999." Its pricing page shows pentest plans at $2,999 and $5,999 a year and no $4,999 pentest plan. Ask which plan that figure refers to before you budget on it.
What moves an assessor's quote. The number of tenants and user roles, whether you have a mobile app or installed agents, how many people the phishing test covers, and how much sits on a cloud that is already certified. For general price evidence, see penetration testing cost.
What should you get in writing before you sign?
Get the rulebook, the scope, the people, the price and the recheck terms on paper. Here is how that plays out on a made-up buyer, using our Purchase Check: we list what the buyer must have, then test each kind of offer against it.
Say you run a 60-person SaaS with one web app, a public API and no mobile app. You are on an initial Rev5 Moderate assessment under the older process, started before January 1, 2027, and your assessment report submission is due April 30, 2027.
| What you must have | Why | Recognized assessor's assessment | Regular pentest package |
|---|---|---|---|
| A test your assessment can rely on | Guidance v3.0, section 8 | Recognition supported once you find the firm's Assessor ID; testing fit unresolved until the scope and qualified team are confirmed | Mismatch as a standalone replacement for the required assessment. Qualified subcontracted work remains the assessor's responsibility |
| Six attack paths tested or explained | Section 3 | Unresolved until the proposal lists them | Not applicable |
| The applicable tenant setup and top customer roles | Sections 3.1.3 and 3.1.4, with the section 4 exception | Unresolved until it is in the test plan | Not applicable |
| A test no older than six months at initial SAR submission | Section 7 | Not before October 30, 2026 | Not applicable |
| Problems found and fixed before the assessor tests | Your choice | Depends on the two-year rule | Unresolved until the proposal covers the web app and API and the fixes and rechecks fit the deadline |
| A complete price | Your budget | Unresolved. No published price found | Published for some offers |
The decision. The independent assessment is the one you need. A regular pentest package cannot replace it by itself, however good the firm; any qualified subcontracted testing must be agreed with the assessor. Whether to add a preparation test is the real choice. It is worth a close look if this is your first assessment or your system changed a lot this year. Skip it if your team already tests tenant isolation seriously and your last assessment was clean.
A scope brief works like asking every supplier the same question, so their answers line up. Send this one to each assessor or tester you are considering.
Subject: Scope and quote request for our FedRAMP assessment
Our cloud service is [name]. We are obtaining / maintaining [Rev5 or 20x, class]. Our next assessment is planned for [date]. Please confirm whether your test plan follows Penetration Test Guidance v3.0, the Consolidated Rules for 2026, or both.
Your FedRAMP Assessor ID is [ask]. Please name the legal entity that will do the testing, the entity that will do the assessment, and any subcontractors.
Our service includes [apps, APIs, user roles, number of tenants]. We [do / do not] ship a mobile app or installed software. We run on [cloud host]. Please list which of the six attack paths you will test, which you will mark out of scope, and why.
For Class C or D: please describe how CA-08 (02), red team exercises, is covered.
Please price testing, assessment and any tools as separate lines. State the currency, fee basis, minimum commitment, billing dates and extras.
Please give testing dates, the date we receive findings, and what you need from us first. State how many rechecks of fixed findings are included, the last day we can ask for one, the cost after that, and whether we get an updated report.
Would any preparation work from your firm count as advisory services under REC-IAS-SEP for our offering?
This brief is a buying tool. It does not authorize anyone to test. Written authorization has to cover the actual targets and activities, and the 2022 guidance has the authorizing official approve the rules of engagement before testing starts.
If you are buying a preparation test, write down the same scope your assessor will test before you ask for prices: the app, the API, the user roles and both tenants. Our free tool turns those into a scope checklist you can copy or print, with no email or sign-up. It covers web app and API tests. It does not pick an assessor for you.
When proposals come back, compare them line by line.
What evidence should you get after the test?
Under the older process, a full pentest report. Under the 2026 rules, the formal record is a summary, so agree up front who gives your engineers the detail.
Older process. The guidance requires the report to cover six things: the scope of the target system, the attack paths assessed, the timeline, the tests performed and their results, findings with evidence, and access paths. An access path is the chain of steps that turns separate weaknesses into one real attack. There is "no template provided." Sensitive data in screenshots must be masked so it cannot be recovered, and passwords must be omitted or masked so they cannot be recreated or guessed.
2026 rules. The assessor writes an assessment summary that you include in your Security Decision Record, the running record of your security decisions and evidence. FedRAMP "does not require a separate Security Assessment Plan or Security Assessment Report" for 20x or Rev5 certifications. Separately, your regular vulnerability reports should include a high-level overview of pentest activity.
Whichever applies, ask for findings your engineers can act on: the target, the role used, what happened, the impact and how a fix will be rechecked. See what a useful pentest report contains.
Does a SOC 2 or commercial pentest count for FedRAMP?
Not automatically as the assessment test. Its scope, qualified testers and evidence must meet the applicable FedRAMP requirements.
It is still worth showing to your assessor. A recent test of the same app can shorten your preparation and shows where you already fixed things. Three outcomes are possible:
- Covered. Your assessor's signed scope already includes the testing. Buy nothing.
- Gap found. Something is missing, such as the second tenant or the phishing test. Scope only that.
- Still unknown. Send the brief above before you choose anyone.
More on the commercial side: SOC 2 penetration testing.
Other questions before you sign
Is a vulnerability scan enough?
No. The 2022 guidance says the test "should not be strictly limited to automated scanning techniques, but manual techniques as well," and defines a penetration test as "a combination of automated and manual testing." See penetration testing vs vulnerability scanning.
Can we refuse the phishing test?
You can request a deviation, but the authorizing official must approve it and it is recorded. Under the 2022 guidance the assessor must document your reasons in the report, and an untested attack path may be rated a high risk.
Does a clean report guarantee an agency will approve us?
No. FedRAMP certification and an agency's own authorization to operate are separate decisions. Your assessor and the agency decide what they accept. Nobody selling you a test can promise that.
Is "3PAO" still the right word?
People still say it, and FedRAMP's own directory still uses it in places. The 2026 rules call these firms independent assessment services or assessors.
Sources and how we checked
The PenTest Index is an independent buyer's index for penetration testing. For this page we read FedRAMP's published rules and guidance, FedRAMP's assessor listings and each provider's own pages on October 10, 2026, and did the date arithmetic ourselves. We ran no tests and bought nothing. We are not affiliated with FedRAMP, GSA or A2LA, and no provider paid to be included. See how we check offers and how we make money. Spotted something out of date? Send a correction.
| Source | What we used it for | Checked |
|---|---|---|
| FedRAMP Penetration Test Guidance v3.0 | Attack paths, who tests, timing, reporting | October 10, 2026 |
| Penetration Test Guidance v4.0 draft | Draft status only | October 10, 2026 |
| FedRAMP Consolidated Rules for 2026 and rules data, version 2026.10.08.01 | Controls, yearly assessment, scope, advice and separation rules | October 10, 2026 |
| FedRAMP important dates and Rev5 deadlines | Dates | October 10, 2026 |
| Vulnerability Detection and Response rules | Pentesting as a detection technique | October 10, 2026 |
| FedRAMP recognition rules and A2LA R311 | A2LA accreditation, two-year rule, qualified subcontracting | October 10, 2026 |
| FedRAMP legacy documents, baseline workbook and assessment plan template | Low and LI-SaaS provisions | October 10, 2026 |
| FedRAMP assessor directory | Assessor names, IDs, recognition dates | October 10, 2026 |
| A-LIGN, Coalfire, Schellman | What each says about its own service | October 10, 2026 |
| stackArmor cost page | One advisory firm's cost estimates | October 10, 2026 |
| Pentest-Tools.com, Astra pricing, Astra rescan rules, Astra's FedRAMP companies article | Published preparation-test prices and terms; the $4,999 and 3PAO statements | October 10, 2026 |