logo svg
logo

October 14, 2025

Updated: August 26, 2026

CMMC Penetration Testing in 2026: Requirements, Scope, and Evidence

As of August 2026, CMMC does not explicitly require pentesting at Level 1 or 2, while the Level 3 model does. Here is how the Phase II suspension affects scope, evidence, scanning, timing, and readiness decisions.

Mohammed Khalil

Mohammed Khalil

Featured Image

Last updated: August 26, 2026

Executive Answer

As of August 2026, CMMC does not explicitly require a penetration test at Level 1 or Level 2. Level 2 requires periodic vulnerability scanning and security-control assessment under NIST SP 800-171 Revision 2; a well-scoped pentest can support those activities but does not replace the CMMC assessment. The CMMC Level 3 model explicitly requires penetration testing at least annually and after significant system changes under CA.L3-3.12.1e. However, the Department has paused Phase II and currently permits only Level 1 and Level 2 self-assessment requirements in solicitations and contracts.

2026 Implementation Update

2026 implementation update: On July 13, 2026, the Department of War suspended CMMC Phase II and future milestones. Phase I self-assessments remain in place. The official CMMC program page should be treated as the source of truth for further implementation changes.

That distinction matters. The underlying CMMC model still defines three levels, but the assessment level that a contracting officer may currently place in a solicitation or contract is narrower during the suspension. Older regulations and contract materials may still use “Department of Defense” or “DoD,” while the current program site uses “Department of War” or “DoW.”

Does CMMC Require Penetration Testing?

The accurate answer is level-specific:

A pentest and a CMMC assessment answer different questions. A pentest asks whether an authorized tester can exploit weaknesses in a defined scope. A CMMC assessment asks whether the organization has implemented every applicable practice and can demonstrate that implementation through sufficient evidence. One activity can inform the other, but they are not interchangeable.

For organizations deciding whether testing is appropriate, it helps to begin with the difference between a vulnerability assessment and a penetration test. A scanner identifies potential weaknesses at scale; a pentest uses controlled human analysis to validate exploitability, attack paths, and business impact.

CMMC Levels and Penetration-Testing Requirements in 2026

CMMC levelUnderlying modelAssessment designation allowed during the Phase II suspensionExplicit pentest requirement?
Level 115 FAR 52.204-21 requirementsAnnual self-assessment and annual affirmationNo
Level 2110 NIST SP 800-171 Rev. 2 requirementsSelf-assessment every three years and annual affirmationNo
Level 3Level 2 requirements plus 24 selected NIST SP 800-172 requirementsLevel 3 DIBCAC designation is suspendedYes, in the underlying model

The current model language appears in 32 CFR § 170.14. It identifies the Level 3 requirement as CA.L3-3.12.1e: conduct penetration testing at least annually or when significant security changes are made, using automated scanning tools and ad hoc tests performed by subject-matter experts.

The Level 3 requirement remains in the regulation even though Level 3 assessment designation is currently suspended. Organizations pursuing high-value programs should therefore separate near-term contract obligations from longer-term architecture and readiness planning.

What the Phase II Suspension Changes and What It Does Not

The July 2026 suspension is an implementation change, not a cancellation of CMMC or the defense industrial base’s security obligations.

During the suspension:

The Department’s implementation memorandum also makes clear that NIST SP 800-171 Revision 2 and DFARS 252.204-7012 obligations remain. Contractors should verify the actual language in each solicitation, contract, option, and amendment rather than assuming that a general announcement has already changed a particular instrument.

Self-assessment does not mean “no evidence.” Level 1 and Level 2 organizations still need an accurate scope, implemented requirements, defensible assessment results, and the required affirmation. A pentest can expose implementation weaknesses before those weaknesses undermine the organization’s own assessment, but it does not make the self-assessment complete by itself.

How Penetration Testing Can Support CMMC Level 2

CMMC Level 2 contains no blanket instruction to hire a pentest provider. Its explicit technical requirement is vulnerability scanning under RA.L2-3.11.2: scan periodically and when new vulnerabilities affecting the system are identified. The Level 2 Assessment Guide also notes that analyzing custom-developed software may require a penetration tester to test or validate findings when automated scanners are insufficient.

That nuance is documented in the official CMMC Level 2 Assessment Guide. The guide is clarifying assessment guidance rather than a substitute for the regulation, but it is a useful source for understanding possible evidence and assessment methods.

Level 2 requirementWhat CMMC expectsHow a pentest may helpWhat a pentest cannot prove alone
RA.L2-3.11.2Periodic and event-driven vulnerability scanningValidate exploitability and test areas automated tools cannot adequately analyzeThat required scanning occurs across the defined frequency and scope
RA.L2-3.11.3Remediate vulnerabilities according to risk assessmentsEstablish impact, prioritize fixes, and verify selected remediationThat the organization’s full remediation process operates consistently
CA.L2-3.12.1Periodically assess security controls for effectivenessExercise selected technical controls under realistic attack pathsEffectiveness of all 110 requirements and their assessment objectives
CA.L2-3.12.2Develop and implement plans to correct deficienciesSupply actionable findings, owners, and validation dataEligibility of an item for a CMMC assessment POA&M
CA.L2-3.12.3Monitor controls on an ongoing basisAdd periodic human validation to the monitoring programContinuous or program-wide monitoring by itself
SI.L2-3.14.1Identify, report, and correct system flaws promptlyRetest selected fixes and identify exploitable combinationsThat every flaw is tracked and corrected within the organization’s process

A practical way to express the value is:

Useful Level 2 evidence = correct scope + authorized testing + attributable evidence + owned remediation + retest

Even when all five elements are present, the result is supporting evidence not a CMMC certificate, a guaranteed score, or a substitute for evaluating every applicable objective.

For teams that need the testing work to be repeatable across remediation cycles, a structured penetration testing as a service program can help. The organization should still document how that service fits its vulnerability-management, control-assessment, and evidence-retention processes.

Vulnerability Scanning vs. Pentesting vs. a CMMC Assessment

ActivityPrimary questionTypical methodsTypical outputCMMC role
Vulnerability scanningWhat known weaknesses may be present?Automated authenticated or unauthenticated checksPotential vulnerabilities, missing patches, and configuration findingsExplicit Level 2 requirement when performed periodically and when relevant new vulnerabilities emerge
Penetration testingWhich weaknesses and attack paths can an authorized human tester validate?Manual analysis, exploitation, chaining, and targeted toolingValidated findings, impact evidence, attack paths, and remediation guidanceExplicit at Level 3; optional supporting activity at Levels 1 and 2
CMMC assessmentAre all applicable practices implemented with sufficient evidence?Examine, interview, and test against assessment objectivesMET, NOT MET, or NOT APPLICABLE determinations and an assessment resultThe formal compliance activity; not replaced by scanning or pentesting

Running a scanner and calling the output a pentest weakens both security and evidence quality. Conversely, asking a pentester to “test all of CMMC” creates an undefined engagement: many CMMC objectives concern governance, policy, training, physical protection, and repeatable processes that cannot be established through offensive testing.

How to Scope a CMMC-Focused Penetration Test

The CMMC assessment scope and the pentest scope should inform each other, but they are not automatically identical. Start with the system security plan, asset inventory, network and data-flow diagrams, external service-provider responsibilities, and the paths through which CUI is stored, processed, or transmitted.

The regulation’s CMMC scoping requirements distinguish CUI assets, security protection assets, contractor risk-managed assets, specialized assets, and out-of-scope assets. Those categories affect assessment treatment. The pentest should prioritize CUI assets and security protection assets while also considering credible paths from other reachable systems into the CUI environment.

A useful scoping workshop should answer these questions:

  1. Where does CUI enter, move through, and leave the environment?
  2. Which identities, endpoints, applications, networks, and cloud services protect that flow?
  3. Which internet-facing or internal paths could lead into the CUI enclave?
  4. Which security protection assets could fail in a way that exposes CUI?
  5. What is owned by an external service provider, and who is authorized to test it?
  6. Which systems are excluded, why are they excluded, and is segmentation effective?
  7. What techniques, testing hours, data-handling rules, and stop conditions are authorized?

DeepStrike’s penetration-testing scope guide explains how to turn objectives, boundaries, exclusions, and rules of engagement into a testable statement of work. For a CMMC-focused engagement, that scope should also map each major test path to the relevant system boundary and asset owner.

The test type should follow the attack surface. That may include internal or external network testing, identity and Active Directory paths, web applications and APIs, cloud control planes, remote access, segmentation, or a focused review of custom-developed software. It does not follow that every organization needs every test type.

If CUI-facing applications are central to the boundary, a web application penetration test may be more useful than a broad external network test.

If the enclave relies on cloud identity, storage, or managed services, a separately authorized cloud penetration test may be necessary because provider policies and shared-responsibility boundaries can limit techniques.

How Often Should a CMMC Organization Pentest?

For CMMC Level 3, the model supplies the cadence: at least annually and when significant security changes are made.

For Levels 1 and 2, CMMC does not specify a pentest cadence because it does not explicitly require the activity. The organization should set a risk-based frequency based on its threat model, contract language, customer commitments, architecture, change rate, and findings. An annual test may be a reasonable program choice, but it should not be presented as a universal Level 2 rule.

Consider an additional test after material changes such as:

Between larger tests, focused validation can reduce the time that important findings remain unresolved. A continuous penetration-testing service may fit fast-changing environments, but it still needs a defined scope, authorization, triage process, and evidence-retention plan.

What Evidence Should the Engagement Produce?

A CMMC-focused pentest report should be useful to engineers, control owners, executives, and when appropriate the assessment team. At minimum, retain:

The mapping should say “supports evidence for” rather than “proves compliance with.” An assessor may need only the portions relevant to a particular objective, while sensitive exploit detail may require controlled handling. Agree on evidence access and redaction before testing starts.

A clear penetration-testing contract should define authorization, confidentiality, data retention, third-party approvals, deliverables, and retesting. For CUI environments, those terms are part of risk management, not administrative boilerplate.

Do Pentest Findings Belong on a CMMC POA&M?

Not automatically.

CA.L2-3.12.2 expects an organization to develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities. A contractor can use an operational remediation plan to manage pentest findings under that practice.

A CMMC assessment POA&M is a separate mechanism governed by 32 CFR § 170.21. It applies to eligible NOT MET assessment requirements, is subject to scoring and eligibility constraints, and must be closed within the applicable period. Level 1 does not allow an assessment POA&M; Level 2 permits only a limited one under the rule.

Therefore, do not automatically label every pentest issue a “CMMC POA&M item.” First determine whether the finding indicates that a specific assessment objective is NOT MET. Then document and handle it through the appropriate operational or assessment process.

How to Select a Pentest Provider for a CUI Environment

Choose the provider for its ability to test the actual attack surface safely and produce defensible evidence not because it promises to “make you CMMC compliant.” A pentest company does not award a CMMC status unless it is separately authorized for the relevant assessment role, and those roles should not be casually conflated.

Evaluate:

DeepStrike provides penetration-testing services, so this guide has a commercial connection to the subject. Its requirements analysis is based on the cited official sources. Buying any DeepStrike service does not create or guarantee CMMC status.

A Practical CMMC Pentest Readiness Checklist

  1. Confirm the governing requirement. Read the solicitation, contract, amendments, and current Department guidance.
  2. Validate the CMMC boundary. Reconcile the SSP, inventory, diagrams, CUI flows, and external service providers.
  3. Define the security question. Decide which attack paths, controls, or material changes the test needs to validate.
  4. Authorize a precise scope. Record included systems, exclusions, techniques, timing, third-party approvals, and stop conditions.
  5. Plan evidence handling before testing. Set access, encryption, retention, redaction, and destruction requirements.
  6. Remediate and retest. Assign owners, distinguish operational findings from assessment POA&M items, and retain validation evidence.
  7. Complete the actual CMMC assessment process. Evaluate every applicable objective; do not treat the pentest report as the assessment.

Frequently Asked Questions

Is penetration testing required for CMMC Level 2?

No. CMMC Level 2 explicitly requires periodic vulnerability scanning and scanning when new vulnerabilities affecting the system are identified, but it does not contain a blanket penetration-testing requirement. A pentest may support selected assessment objectives, particularly where manual validation is valuable, but it does not replace the Level 2 assessment.

Did the 2026 Phase II suspension cancel CMMC?

No. Phase I self-assessments remain. During the suspension, new solicitations and contracts may designate Level 1 Self or Level 2 Self, but not Level 2 C3PAO or Level 3 DIBCAC. Other applicable safeguarding and DFARS obligations also remain.

Is the Level 3 pentest requirement still part of CMMC?

Yes. CA.L3-3.12.1e remains in the CMMC model and requires penetration testing at least annually and after significant security changes. What changed is that Level 3 DIBCAC assessment designation is currently suspended during the Phase II pause.

Can vulnerability scanning replace a penetration test?

No. Scanning is broad and repeatable, while a pentest uses authorized human analysis to validate exploitability and combine weaknesses into attack paths. Level 2 explicitly requires vulnerability scanning; adding a pentest does not remove that obligation.

How often should a Level 2 contractor conduct a pentest?

CMMC does not prescribe a Level 2 pentest schedule. Set a defensible cadence based on risk, contractual commitments, architectural change, and exposure. Annual testing and testing after material changes may be reasonable choices, but they are not universal Level 2 requirements.

Must a C3PAO perform the penetration test?

No CMMC rule says a C3PAO must provide an organization’s security pentest. A C3PAO performs authorized CMMC certification assessments when that assessment designation applies. Select a pentest provider based on authorization, technical fit, evidence quality, data handling, and contractual constraints.

Must we give the full pentest report to a CMMC assessor?

Not necessarily. The assessment team needs adequate evidence for the objectives being evaluated, but the exact artifacts and access method should be coordinated with the assessor. Sensitive exploit details should be controlled, and selective evidence must still be sufficient and attributable.

Build Security Evidence Without Confusing It With Certification

CMMC penetration testing is not a universal checklist item. It is an explicit Level 3 model requirement and an optional but potentially valuable security-validation activity at Level 2. In 2026, contractors also need to account for the Phase II suspension without assuming that self-assessment eliminates evidence or security obligations.

Need help defining a CUI-focused scope, validating exploitable attack paths, and producing remediation-ready evidence? DeepStrike can design and execute an authorized penetration test around your actual environment. Your contracting officer, legal counsel, and assessment team should confirm how the resulting evidence fits your specific obligations.

This article is general technical information, not legal, procurement, or certification advice. Current official guidance and the terms of each solicitation and contract control.

About The Author

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us