U.S. Department of Defense · CMMC (Cybersecurity Maturity Model Certification)
Does CMMC require a penetration test?
CMMC is the Department of Defense's certification program for contractors handling federal contract information and controlled unclassified information. Levels 1 through 3 set progressively stricter requirements.
The short answer
CMMC does not require penetration testing at Levels 1 or 2. Level 2 assesses against the 110 practices of NIST SP 800-171, which does not contain a penetration testing control. Penetration testing appears as CA-8 in NIST SP 800-53 and in the enhanced requirements of SP 800-172 used at Level 3.
Who it applies to
Defense contractors and subcontractors in the defense industrial base, with the required level set by the contract and the data handled.
In detail
CMMC Level 1 covers basic safeguarding of federal contract information with 15 practices and allows annual self-assessment. Level 2 covers controlled unclassified information against the 110 practices of NIST SP 800-171, assessed either by a certified third-party assessor organization or, for some contracts, by self-assessment. Level 3 adds enhanced requirements drawn from NIST SP 800-172 and is assessed by the government.
The absence of an explicit penetration testing practice at Level 2 surprises people, because so much of the surrounding federal ecosystem requires it. NIST SP 800-171 focuses on protecting controlled unclassified information through access control, configuration management, incident response and the rest, and leaves adversarial testing to the 800-53 and 800-172 tiers.
That said, security assessment requirements at 3.12.1 through 3.12.4 ask for periodic assessment of security controls to determine whether they are effective, and a penetration test is a defensible way to evidence that a control set works in practice rather than on paper.
What to have in scope
- Systems handling controlled unclassified information within the assessment boundary
- Evidence that supports the 3.12 security assessment practices
- Enclave boundaries, where CUI is segmented from the rest of the business
Questions people ask
Does CMMC require a penetration test?
Not at Levels 1 or 2. Level 2 assesses against NIST SP 800-171, which has no penetration testing practice. Level 3 draws on NIST SP 800-172 enhanced requirements, where adversarial testing appears. Testing is still commonly used to evidence the 3.12 security assessment practices.
What is the difference between CMMC and NIST 800-171?
NIST SP 800-171 is the control set. CMMC is the program that verifies a contractor has implemented it, adding assessment and certification requirements on top.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.