Skip to content

FedRAMP Penetration Testing: A Readiness Guide

FedRAMP penetration test guidance explained for SaaS vendors: the attack vectors the assessor tests, and how independent readiness testing finds issues first.

Invadel Team9 min read

FedRAMP requires a penetration test. The test that counts toward your authorization is run by a FedRAMP Recognized independent assessor, the organization most people still call a 3PAO. You do not get to pick a friendly tester for that one.

What you can do is find the problems first. A readiness penetration test covers the same attack vectors a few months before the assessor arrives, so the assessor’s test confirms fixes instead of discovering findings.

A plain statement before anything else: Invadel is not a 3PAO and is not a FedRAMP Recognized independent assessment service. We do not issue FedRAMP authorizations or certifications, and our report does not replace the assessor’s penetration test. We run readiness and pre-assessment testing at a fixed price, with a fixed scope and a free retest.

Who runs the FedRAMP penetration test

The FedRAMP Penetration Test Guidance (version 3.0, June 30, 2022) defines a 3PAO as “a FedRAMP recognized 3PAO.” It says a recognized 3PAO is required for a JAB provisional authorization. For an agency authorization, the term may refer to “any assessment organization designated by the agency AO.” (FedRAMP Penetration Test Guidance)

FedRAMP’s 2026 rules tighten the language. To be FedRAMP Recognized, an assessor must hold accreditation through the A2LA Cybersecurity Inspection Body Program, and FedRAMP says it “MUST NOT accept verification, validation, or other attestations from independent assessors who are not FedRAMP Recognized.” (FedRAMP Recognition of Independent Assessment Services)

So a readiness test is for you, not for your package. It tells your engineers what the assessor is likely to find, while there is still time to fix it.

What changed in 2026

FedRAMP published its Consolidated Rules for 2026 on June 25, 2026. The key dates, from FedRAMP’s announcement:

  • FedRAMP 20x is now a widely available certification path, no longer a pilot.
  • Rev5 continues during a transition. FedRAMP will stop accepting new Rev5 applications on June 11, 2027.
  • January 1, 2027 is the date all current certifications must adopt the new rules.

(FedRAMP, Consolidated Rules for 2026 announcement)

Penetration testing stays in both paths:

  • Rev5. Providers with a Class B certification complete an independent verification and validation assessment at least once a year, with a FedRAMP Recognized assessor or with FedRAMP itself. Control CA-08, Penetration Testing, is on the list assessed every year. (Independent Verification and Validation)
  • 20x. The Vulnerability Detection and Response rules require providers to find vulnerabilities persistently and list penetration testing among the techniques to use. FedRAMP lists December 7, 2026 as the date those rules become mandatory for initial certification. (Vulnerability Detection and Response)

The vocabulary is changing too: the 2026 rules talk about “certification” and “independent assessment services” where older documents say “authorization” and “3PAO.” The rules are still settling. Check the current version for your path before you set a date.

The six attack vectors in the guidance

The Penetration Test Guidance lists six mandatory attack vectors for every system, whether it is SaaS, PaaS, IaaS or hybrid. Your test plan must address each one or explain why it does not apply, and deviations must be approved by an authorizing official. The guidance warns that a 3PAO may treat a vector left untested as a high-risk finding. Version 3.0 is the document linked from FedRAMP’s resources; a draft version 4.0 went out for public comment in March 2024.

Here is each vector, and the readiness test we scope to cover it.

# Attack vector What the guidance tests Readiness test Starting price
1 External to Corporate A phishing attack against your system administrators and the managers who can influence them Phishing campaign aimed at the same group $3,600
2 External to CSP Target System An outside attacker against your internet-facing system External network and web application testing $4,200 and $5,200
3 Tenant to CSP Management System A full application test from a tenant account, trying to reach your management plane Web application and API testing from tenant accounts $5,200 and $4,000
4 Tenant-to-Tenant One tenant’s access used to compromise another tenant SaaS tenant isolation testing with two test tenants From $5,200
5 Mobile Application to Target System A mobile app user attacking your system or management plane Mobile application testing, iOS and Android included $6,000
6 Client-side Application and/or Agents to Target System Software you install at the customer: agents, thick clients, browser extensions, appliances Thick-client testing of the component $6,000

Two notes from the guidance. Vector 5 can be marked out of scope when your offering has no mobile app. Vector 6 applies when a client-side component is essential for customers to use your service.

The cloud account that hosts the system is not a vector of its own, but it sits inside the boundary the assessor tests. A cloud penetration test (from $6,800) covers identity, storage and the paths between services.

Scoping a readiness test to your boundary

A readiness test is only useful if it tests what the assessor will test. Four rules from the guidance shape the scope:

  1. Start from your authorization boundary. The guidance expects Section 9 of your System Security Plan to define the boundary in a diagram and in words. We scope from that section.
  2. Do not re-test what you inherit. If you run on a FedRAMP Authorized IaaS or PaaS, the guidance says the lower layer does not need to be penetration tested again, unless your system includes that layer’s security features in its own boundary.
  3. Build a second tenant. For multi-tenant systems, the guidance says you must build a temporary tenant if no suitable one exists. We need the same two tenants for vector 4.
  4. Get permission for third parties. Testing assets you do not own needs documented permission, and the guidance makes obtaining it your responsibility. It names internet service providers, managed security service providers, facility leaseholders and hosting services.

We test the environment that mirrors production. If a test has to touch production, the rules of engagement set the windows, the source addresses and the emergency contacts in writing first.

NIST SP 800-53 CA-8, in brief

FedRAMP builds on NIST SP 800-53. Control CA-8 reads: “Conduct penetration testing [Assignment: organization-defined frequency] on [Assignment: organization-defined system(s) or system components].” Two enhancements matter here: CA-8(1) calls for an independent penetration testing agent or team, and CA-8(2) covers red team exercises.

Our guide to NIST penetration testing requirements covers CA-8 and NIST SP 800-115 in more depth.

GovRAMP and TX-RAMP

State and local sales have their own programs.

  • GovRAMP. StateRAMP announced on February 14, 2025 that it would operate as GovRAMP. It serves state, local, tribal and education buyers. (GovRAMP announcement)
  • TX-RAMP. Texas Government Code section 2054.0593 requires Texas state agencies to enter or renew cloud computing contracts only with services that comply with TX-RAMP, starting January 1, 2022. The Texas Department of Information Resources runs the program. (Texas DIR, TX-RAMP)

Both programs build on the NIST SP 800-53 control families, so readiness testing scoped for FedRAMP carries over. Our Texas penetration testing page covers TX-RAMP for Texas vendors. Vendors that handle criminal justice information for state and local agencies also answer to the FBI’s CJIS Security Policy, now built on the same NIST SP 800-53 controls; see our CJIS compliance checklist.

When to test

Test three to six months before the assessor’s window. That leaves time for the full cycle:

  1. The readiness test, typically one to two weeks of testing for a single application or perimeter.
  2. Your team fixes the findings.
  3. We retest the fixes at no extra cost and update the report.
  4. The assessor runs the official test on a system that has already been through it once.

Repeat the cycle before each annual assessment. Onboarding starts within 24 hours of a signed proposal, and testing usually starts within a week. For cloud providers and government contractors in DC, Virginia and Maryland, testing runs remotely, with on-site work arranged when the scope needs it.

What a readiness test costs

Every price is a published starting price. A typical SaaS scope looks like this:

Test Covers vectors Starting price
Web application 2, 3, 4 $5,200
API 3 $4,000
External network 2 $4,200
Cloud account Boundary components $6,800
Phishing campaign 1 $3,600
Mobile application, if you have one 5 $6,000
Thick-client or agent, if you ship one 6 $6,000

An established product with several roles and an admin panel usually lands in the medium web application tier, from $7,800. A large multi-tenant platform with many roles is the large tier, from $12,500. You get one fixed quote in writing from your scope. Every penetration test includes the free retest. See pricing for every tier.

What you get

  • A report organized by the six attack vectors, with findings rated by severity and reproduction steps your engineers can follow.
  • Retest results that show which findings are closed.
  • An attestation letter stating the scope, the dates and the outcome, and that this was a readiness test by an independent firm, not a FedRAMP assessment.
  • A list of anything we could not test, so you can fix the gap before the assessor finds it.

Frequently asked questions

Can Invadel act as our 3PAO? No. We are not a 3PAO and not a FedRAMP Recognized independent assessment service. We run readiness testing before your assessment.

Will the assessor accept your report instead of its own test? No. The assessor runs its own penetration test. Our report helps you arrive with fewer findings and with evidence that you tested and fixed before the assessment.

Does FedRAMP require a phishing test? Yes. Attack vector 1 in the Penetration Test Guidance is a social engineering (phishing) attack against your system administrators and the managers who can influence them.

Do we have to test our cloud provider? Usually not. If you run on a FedRAMP Authorized IaaS or PaaS, the guidance says the lower layer does not need to be penetration tested again, unless your system includes that layer’s security features in its own boundary.

How often does FedRAMP require penetration testing? Under the 2026 rules, CA-08 penetration testing is part of the annual independent assessment for Rev5 Class B certifications. Plan a readiness test before each annual assessment.

Does this help with GovRAMP or TX-RAMP? Yes. Both build on NIST SP 800-53 controls, so the same readiness test answers most of the same questions.

The short version

The assessor runs the FedRAMP penetration test. Your job is to make that test boring. Map your boundary to the six attack vectors, test them three to six months early, fix what we find, and take the free retest.

Fixed price, fixed scope, free retest. Scope your readiness test, or read how we test cloud environments and web applications.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation