ClearPenTest

U.S. General Services Administration · FedRAMP (Federal Risk and Authorization Management Program)

Does FedRAMP require a penetration test?

FedRAMP is the authorization program a cloud service must pass to be sold to United States federal agencies. It is the most demanding framework on this list and the most expensive to reach.

Required by nameNIST SP 800-53 Rev. 5 control CA-8 and the FedRAMP Penetration Test Guidance

The short answer

Yes. FedRAMP requires annual penetration testing performed by an accredited Third Party Assessment Organization, and the FedRAMP Penetration Test Guidance specifies the attack vectors that must be covered rather than leaving the methodology to the tester.

Who it applies to

Cloud service providers selling to federal agencies. State analogs such as StateRAMP and TX-RAMP follow the same shape at lower cost.

In detail

FedRAMP baselines are built on NIST SP 800-53 Rev. 5, with Low, Moderate and High impact levels selecting progressively more controls. Control CA-8 covers penetration testing, and FedRAMP layers its own guidance on top specifying required attack vectors, including external to corporate, external to the cloud system, tenant to tenant, client to cloud, and mobile where applicable.

The testing must be performed by an accredited Third Party Assessment Organization as part of the annual assessment, and the results feed the Security Assessment Report that supports the authorization decision. This is a different commercial model from the rest of this list, because the assessor is accredited into the program rather than chosen freely.

For most startups the realistic path is to build toward a FedRAMP-ready posture while selling under SOC 2, and take on the authorization when a specific agency opportunity justifies the cost. The state programs, StateRAMP and TX-RAMP, are materially cheaper and can be a sensible first step.

What to have in scope

  • The attack vectors named in the FedRAMP Penetration Test Guidance, not a generic methodology
  • Tenant isolation, which is tested explicitly rather than assumed
  • The full authorization boundary as documented in the System Security Plan
  • Annual cadence tied to the continuous monitoring schedule

Questions people ask

Does FedRAMP require penetration testing?

Yes. Penetration testing is required annually under NIST SP 800-53 control CA-8, performed by an accredited Third Party Assessment Organization, following the attack vectors set out in the FedRAMP Penetration Test Guidance.

Can any penetration testing firm do a FedRAMP test?

No. The assessment must be performed by an accredited Third Party Assessment Organization. A standard commercial penetration test is useful preparation but cannot substitute for the 3PAO assessment.

What is the cheaper alternative to FedRAMP?

StateRAMP and TX-RAMP apply the same NIST 800-53 shape to state and local government procurement at significantly lower cost, and are a reasonable first step for a company whose public sector demand is not yet federal.

This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.